ENTWURF – nicht freigegeben, rechtlich prüfen lassenDRAFT – not yet approved, must be reviewed by a lawyer.
Privacy policy (GDPR and KVKK)
How HicretYolu.app processes personal data – privacy information under Art. 13 and 14 GDPR and information notice under Art. 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK).
Draft date: Oct 7, 2026
Controller and contact
Controller under Art. 4 (7) GDPR and data controller (veri sorumlusu) under Art. 3 KVKK for the platform’s own processing:
- [[Firmenname]], [[Rechtsform]], [[Anschrift (Straße, PLZ, Ort, Land)]]
- Email: [[E-Mail-Adresse Kontakt]]
- Privacy contact: [[Datenschutzkontakt (E-Mail)]]
- Data protection officer: [[Datenschutzbeauftragter, falls bestellt]]
- VERBİS registration: [[VERBİS-Kayıt No]]
- KEP address: [[KEP-Adresse]]
Roles of the platform and the agencies
HicretYolu.app is a software platform (SaaS) for Umrah and Hajj travel agencies in Turkey and Germany, currently in a closed beta for invited agencies only.
We are controller for agency accounts and applications, invitations, platform invoices, visits to public pages, the Kaswa chat on the platform home page, beta feedback, technical logs and security.
Data that an agency processes about its customers and pilgrims (bookings, travellers including passport data, documents, payments, Kafile messages, reviews, Kaswa conversations and leads of the agency) is processed on behalf of that agency. The agency is the controller and we are its processor (Art. 28 GDPR, Art. 12 KVKK). Please address requests about such data to the agency.
Data we process
Data is collected electronically through your input, the input of agencies and automatically when pages are accessed.
- Accounts: email address, password (stored only as a scrypt hash), role.
- Agency applications: company, contact person, email, phone, short name.
- Bookings: name, email and phone of the booking person; travellers with date of birth, passport or ID number and, where applicable, Turkish ID number (T.C. Kimlik No).
- Documents: passport and visa scans (PDF, JPG, PNG, WebP, up to 5 MB).
- Payments: amount, date and method; no card data.
- Kaswa chat: questions and answers; optional contact request (lead) with name and contact details.
- Web push endpoint, reviews, anonymous survey answers, beta feedback.
- Technical data: IP address only as a short-lived hash for rate limits, request ID in logs, error reports.
Purposes and legal bases
Accounts, contracts and bookings: Art. 6 (1) (b) GDPR, Art. 5 (2) (c) KVKK. Legal obligations: Art. 6 (1) (c) GDPR, Art. 5 (2) (ç) KVKK. Security, abuse prevention, error analysis and beta feedback: Art. 6 (1) (f) GDPR, Art. 5 (2) (f) KVKK. Web push and Kaswa contact requests: consent, Art. 6 (1) (a) GDPR, explicit consent under Art. 5 (1) KVKK. Kaswa chat on the platform home page: [[Rechtsgrundlage Kaswa-Chat]].
Booking an Umrah or Hajj trip may reveal religious beliefs (Art. 9 GDPR, Art. 6 KVKK): [[Bewertung Art. 9 DSGVO / KVKK m. 6 durch Rechtsberatung]].
Cookies and local storage
We use no analytics, advertising, tracking or third-party cookies, so no consent banner is shown (Section 25 (2) No. 2 TDDDG). Strictly necessary cookies:
- app_session: sign-in for agency and platform accounts; HttpOnly, Secure, SameSite=Lax; 7 days.
- pilgrim_session: sign-in to the pilgrim area; same properties; 7 days.
- admin_active_tenant: platform administrators only, selected agency.
- NEXT_LOCALE: selected language; session cookie.
- localStorage (does not leave your device by itself): Kaswa conversation ID, saved packages, anonymous survey ID, onboarding seen, audience choice, notification read status.
Recipients and sub-processors
No payment service provider is used. We use:
- Vercel: frontend hosting, function region Frankfurt (fra1); US company.
- Railway: API, PostgreSQL, Redis; region [[Region Railway]]; US company.
- Cloudflare R2: object storage for images, encrypted documents and encrypted backups; [[Standort/Jurisdiktion R2]].
- Resend: email delivery from mail.hicretyolu.app; [[Region Resend]].
- Sentry: error reports, EU data region, no session replay, personal data removed before sending.
- Langfuse (Langfuse Cloud EU): traces of Kaswa answers; email, phone and IBAN masked, agency pseudonymised.
- Anthropic: language model for Kaswa answers (question and conversation history); US company.
- OpenAI: embeddings for the Kaswa knowledge base search, only if configured; US company.
- Browser vendors’ web push services (e.g. Google, Mozilla, Apple), only after your consent.
- GitHub Actions: running the encrypted backup jobs.
International transfers
Transfers to the USA (Art. 44 et seq. GDPR): Vercel [[Rechtsgrundlage Drittlandübermittlung Vercel]], Railway [[Rechtsgrundlage Drittlandübermittlung Railway]], Anthropic [[Rechtsgrundlage Drittlandübermittlung Anthropic]], OpenAI [[Rechtsgrundlage Drittlandübermittlung OpenAI]], GitHub [[Rechtsgrundlage Drittlandübermittlung GitHub]].
Under Art. 9 KVKK every transfer from Turkey abroad, including to the EU, is a cross-border transfer: [[Übermittlungsmechanismus nach KVKK m. 9]].
Retention
Agencies can erase a person’s data and export it for access requests in their console. Deleted data may remain in backups until they expire.
- Kaswa conversations: 90 days.
- Kaswa contact requests (leads) and beta feedback: 365 days.
- Email queue: content and links cleared after sending, at the latest after 24 hours; recipient replaced by an irreversible hash.
- Sessions 7 days; sign-in link 15 minutes; password reset 30 minutes; approval link for new agencies 72 hours.
- Weekly encrypted backup in Cloudflare R2: deleted after 90 days.
- Audit log: [[Aufbewahrungsdauer Audit-Protokoll]]; booking data: as long as the agency needs it or must keep it by law.
Security
TLS/HTTPS with HSTS, AES-256-GCM encryption of personal fields, tenant separation and roles, audit log without content, rate limits and account lockout, encrypted backups (GPG AES256) with restore tests, internal API key, security headers and CSP.
Your rights
Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability and objection (Art. 15 to 21), may withdraw consent at any time and may lodge a complaint with a supervisory authority (Art. 77): [[zuständige Aufsichtsbehörde]].
Under Art. 11 KVKK you have the rights listed there. Applications under Art. 13 KVKK are answered within 30 days at the latest; you may complain to the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
No automated decisions, changes
We make no decisions based solely on automated processing (Art. 22 GDPR). Kaswa provides information, sets no prices and decides nothing.
We update this policy when functions, providers or the law change. The version published on this page applies.