Bu politika; GriFlo mobil uygulamasının ve grifloapp.com adresinin kişisel verileri hangi amaçlarla işlediğini, kimlerle paylaştığını, ne kadar süreyle sakladığını ve kullanıcının haklarını açıklar.
1. Veri sorumlusu
Veri sorumlusu GriFlo'dur. Bu politikaya ilişkin talep ve sorular support@grifloapp.com adresine iletilir.
2. İşlenen kişisel veriler
- Kimlik ve iletişim: ad, e-posta adresi, profil görseli ve hesap kimliği.
- Sağlık verileri: boy, kilo, vücut ölçüleri, hedefler, öğün ve aktivite kayıtları ile kullanıcının kendi isteğiyle yüklediği vücut fotoğrafları.
- Kullanım verileri: uygulama içi ilerleme, bildirim kaydı ve özellik kullanım sayaçları.
- Tercihler: ülke, para birimi, dil ve bildirim ayarları.
- Destek yazışmaları: uygulama içinden iletilen mesajlar ve bunlara ilişkin hesap bilgileri.
- Teknik kayıtlar: hata ve çökme kayıtları.
- Bekleme listesi (web sitesi): grifloapp.com üzerindeki formla bırakılan e-posta adresi, onay tarihi ve onaylanan metnin sürümü. Kötüye kullanımı sınırlamak için IP adresinden türetilen bir özet kısa süreliğine tutulur: e-posta adresinizle ilişkilendirilmez ve süresi dolunca (en geç yaklaşık bir gün içinde) kendiliğinden silinir; IP adresinin kendisi saklanmaz. Bu adrese yalnızca iki e-posta gönderilir: kaydın alındığına dair bilgilendirme ve yayın günü indirme bağlantısı.
Uygulama konum, rehber ve takvim verisi işlemez. Kamera ve galeri erişimi yalnızca kullanıcının kendi başlattığı fotoğraf işlemleri için kullanılır.
3. İşleme amaçları ve hukuki dayanak
- Hizmetin sunulması: hesap oluşturma, kayıtların saklanması, cihazlar arası eşitleme ve hesaplama. Dayanak: sözleşmenin ifası.
- Sağlık verilerinin işlenmesi: takip ve analiz özelliklerinin çalışması. Dayanak: açık rıza.
- Bildirim gönderimi: hatırlatma ve bilgilendirme. Dayanak: açık rıza.
- Destek: talebin yanıtlanması. Dayanak: sözleşmenin ifası.
- Yayın bildirimi: bekleme listesine kaydolan kişiye kaydın alındığının bildirilmesi ve uygulama yayınlandığında indirme bağlantısının iletilmesi. Bunların dışında ileti gönderilmez. Dayanak: açık rıza.
- Güvenlik ve kötüye kullanımın önlenmesi: kullanım sınırlarının uygulanması ve hata kayıtları. Dayanak: meşru menfaat.
Açık rızaya dayanan işlemelerde rıza her zaman geri alınabilir. Geri alma, o tarihe kadar gerçekleştirilen işlemenin hukuka uygunluğunu etkilemez.
4. Paylaşım ve yurt dışına aktarım
Sağlık verileri varsayılan olarak gizlidir ve diğer kullanıcılara gösterilmez. Sosyal özelliklerde yalnızca kullanıcının paylaşmayı seçtiği sınırlı bilgiler görünür.
Kişisel veriler pazarlama amacıyla üçüncü taraflara satılmaz veya devredilmez. Veriler; barındırma, kimlik doğrulama, bildirim ve hata takibi amacıyla Google Firebase altyapısında işlenir. Hesaba giriş için Google ve Facebook kimlik doğrulama hizmetleri kullanılır; bu hizmetlere yalnızca girişin gerçekleşmesi için gerekli bilgiler iletilir. Bekleme listesi e-postaları Resend e-posta gönderim hizmetiyle iletilir; bu hizmete yalnızca e-posta adresi ve ileti içeriği aktarılır. Site kullanım ölçümü, izin verilmesi hâlinde Google Analytics ile yapılır. Bu hizmetler yurt dışındaki sunucularda çalıştığından işleme yurt dışına aktarım içerir.
5. Yapay zekâ ile işleme
Bazı özellikler, kullanıcının gönderdiği içeriği çözümlemek üzere Google'ın yapay zekâ hizmetine (Gemini) iletir. İletilen içerik yalnızca ilgili isteğin yanıtlanması amacıyla kullanılır ve ad, e-posta gibi kimlik bilgileriyle birlikte gönderilmez. Üretilen sonuçlar tahmini niteliktedir.
6. Saklama süreleri
Kişisel veriler hesap var olduğu sürece saklanır. Hesap silindiğinde veriler aktif sistemlerden kaldırılır; yedeklerde kalan kopyalar en geç otuz gün içinde silinir. Mevzuat uyarınca saklanması zorunlu kayıtlar bu sürelerden bağımsızdır.
Bekleme listesindeki e-posta adresleri, yayın bildirimi gönderildikten sonra en geç otuz gün içinde silinir. Bildirimden önce silinmesini istemek için support@grifloapp.com adresine yazmanız yeterlidir.
Satın alma ve iade kayıtları, ödemelerin doğrulanabilmesi ve aynı satın almanın yeniden kullanılmasının önlenmesi için hesap silindikten sonra da saklanır. Bu kayıtlar ödeme ve iade bilgisinden ibarettir; sağlık, ölçüm ve beslenme verisi içermez.
7. Kullanıcının hakları
Kullanıcı; kişisel verilerinin işlenip işlenmediğini öğrenme, bunlara erişme, düzeltilmesini, silinmesini veya işlenmesinin kısıtlanmasını isteme, işlemeye itiraz etme ve verilerinin aktarılmasını talep etme haklarına sahiptir.
Hesap ve verilerin silinmesi uygulama içinden doğrudan yapılabilir; adımlar Veri Silme sayfasında açıklanmıştır. Diğer talepler yukarıdaki adrese iletilir ve en geç otuz gün içinde yanıtlanır. Kullanıcı, yetkili veri koruma makamına şikâyette bulunma hakkına da sahiptir.
8. Güvenlik
Veriler iletim sırasında ve saklandıkları yerde şifrelenir. Hesap verilerine erişim, sunucu tarafında tanımlı yetkilendirme kurallarıyla hesap sahibiyle sınırlandırılmıştır. Parolalar tarafımızca görülmez ve saklanmaz.
9. Çerezler (web sitesi)
grifloapp.com, sitenin çalışması için gerekli tercih kayıtlarını (çerez tercihi ve görünüm seçimi) yalnızca tarayıcıda saklar. Kullanıcı izin verdiğinde, Google Analytics ile IP adresi anonimleştirilerek kullanım ölçümü yapılır; izin verilmezse Google Analytics hiç yüklenmez. Pazarlama çerezi kullanılmaz. Tercih, sitedeki "Çerez Tercihleri" bağlantısından her zaman değiştirilebilir.
10. Çocukların gizliliği
Uygulama 13 yaşın altındaki kişilere yönelik değildir ve bu yaş grubundan bilerek veri toplanmaz. Böyle bir kaydın bulunduğu tespit edilirse hesap ve ilgili veriler silinir.
11. Değişiklikler
Bu politika güncellenebilir. Güncel sürüm bu sayfada yayımlanır ve yukarıdaki tarih buna göre değiştirilir.
12. İletişim
Talep ve sorular için support@grifloapp.com.
This policy explains the purposes for which the GriFlo mobile application and grifloapp.com process personal data, with whom such data is shared, how long it is retained, and the rights of the user.
1. Data controller
The data controller is GriFlo. Requests and questions regarding this policy are to be sent to support@grifloapp.com.
2. Personal data processed
- Identity and contact: name, email address, profile image and account identifier.
- Health data: height, weight, body measurements, goals, meal and activity records, and body photographs uploaded at the user's own initiative.
- Usage data: in-app progress, notification registration and feature usage counters.
- Preferences: country, currency, language and notification settings.
- Support correspondence: messages submitted from within the application and the related account information.
- Technical records: error and crash logs.
- Waiting list (website): the email address submitted through the form on grifloapp.com, the date of consent and the version of the consent text. To limit misuse, a digest derived from the IP address is kept for a short time: it is not linked to your email address and is deleted automatically when it expires (within about one day at the latest); the IP address itself is not stored. Only two emails are sent to this address: a confirmation that the sign-up was received and the download link on launch day.
The application does not process location, contacts or calendar data. Camera and gallery access is used solely for photo operations initiated by the user.
3. Purposes and legal bases
- Provision of the service: account creation, storage of records, synchronisation across devices and calculation. Basis: performance of a contract.
- Processing of health data: operation of tracking and analysis features. Basis: explicit consent.
- Notifications: reminders and information. Basis: explicit consent.
- Support: responding to requests. Basis: performance of a contract.
- Launch notification: confirming the sign-up to people on the waiting list and sending them the download link when the application is released. No other messages are sent. Basis: explicit consent.
- Security and prevention of misuse: enforcement of usage limits and error logging. Basis: legitimate interest.
Where processing is based on explicit consent, that consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Sharing and international transfer
Health data is private by default and is not displayed to other users. In social features, only the limited information the user chooses to share is visible.
Personal data is not sold or transferred to third parties for marketing purposes. Data is processed on Google Firebase infrastructure for hosting, authentication, notification and error monitoring. Google and Facebook authentication services are used for account sign-in; only the information required to complete sign-in is shared with them. Waiting-list emails are delivered through the Resend email service; only the email address and the message content are transferred to it. Where consent is given, website usage is measured with Google Analytics. As these services operate on servers located abroad, the processing involves an international transfer.
5. Processing by artificial intelligence
Certain features transmit content submitted by the user to Google's artificial intelligence service (Gemini) for analysis. Transmitted content is used solely to respond to the relevant request and is not sent together with identity information such as name or email. Results produced are estimates.
6. Retention periods
Personal data is retained for as long as the account exists. Upon deletion of the account, data is removed from active systems; copies remaining in backups are deleted within thirty days at the latest. Records whose retention is mandatory under applicable law are not subject to these periods.
Email addresses on the waiting list are deleted within thirty days at the latest after the launch notification is sent. To have your address removed earlier, write to support@grifloapp.com.
7. Rights of the user
The user has the right to learn whether personal data is processed, to access such data, to request its rectification, erasure or restriction of processing, to object to processing, and to request the portability of the data.
Deletion of the account and data can be carried out directly from within the application; the steps are set out on the Data Deletion page. Other requests are to be sent to the address above and are answered within thirty days at the latest. The user also has the right to lodge a complaint with the competent data protection authority.
8. Security
Data is encrypted in transit and at rest. Access to account data is restricted to the account holder by authorisation rules defined on the server. Passwords are not visible to us and are not stored by us.
9. Cookies (website)
grifloapp.com stores only the preference records necessary for the operation of the site (cookie preference and appearance selection) in the browser. Where the user consents, usage is measured with Google Analytics with the IP address anonymised; without consent, Google Analytics is not loaded at all. Marketing cookies are not used. The preference can be changed at any time via the "Çerez Tercihleri" (Cookie Preferences) link on the site.
10. Children's privacy
The application is not directed at persons under the age of 13, and data is not knowingly collected from that age group. If such a record is identified, the account and the related data are deleted.
11. Changes
This policy may be updated. The current version is published on this page and the date above is amended accordingly.
12. Contact
For requests and questions: support@grifloapp.com.