[Morvero legal entity name, registered address, registry/MERSİS number] ("Morvero", "we") operates the Morvero feedback and product-usage analytics platform. Morvero processes personal data in two distinct roles:
Account Data (Morvero as controller):
Visitor Data (Morvero as processor for the Customer):
v_k3j9x…) generated in the visitor's browser and kept in localStorage under fbk_visitor. It contains no personal details and is not derived from the device or the person.data-feedback-ignore.| Purpose | Data | Legal basis (GDPR / KVKK) |
|---|---|---|
| Creating and operating the workspace; authentication (sign-in links, passkeys, SSO) | Email, name, role, credentials, sessions | Contract performance (GDPR art. 6(1)(b); KVKK md. 5/2-c) |
| Service email: verification links, sign-in links, invitations, security notices, requested digests | Email, digest preference | Contract performance; legitimate interest for security notices |
| Security, abuse prevention, audit trail | Audit logs, rate-limit counters | Legitimate interest (GDPR art. 6(1)(f); KVKK md. 5/2-f); legal obligation where applicable |
| Plan administration and, once live, billing and invoicing | Plan, billing records | Contract performance; legal obligation (tax/bookkeeping) |
| Marketing email (none today) | — | Only with prior consent / opt-in if ever introduced |
Visitor Data is processed only on the Customer's documented instructions to provide the Service; the Customer is responsible for its lawful basis.
Morvero uses the following subprocessors. All of them are located in the United States, which means personal data is transferred outside Türkiye and outside the EU/EEA. Transfer safeguards: [GDPR: EU Standard Contractual Clauses; KVKK md. 9: standard contract notified to the Turkish DPA — execution in progress; verify before publication].
| Provider | Location | Purpose | Data shared |
|---|---|---|---|
| Postmark (ActiveCampaign, LLC) | USA | Transactional email delivery: verification and sign-in links, team invitations, digests | Recipient email address, email content |
| Anthropic, PBC and/or OpenAI, L.L.C. | USA | Optional AI feedback analysis (theme summaries, backlog suggestions) — Growth/Enterprise only, only when enabled | Feedback ratings, page paths and comment text only. Screenshots and form-value attachments are never sent to AI providers. |
Customer-connected integrations (not Morvero subprocessors): if a Customer connects its own Atlassian Jira Cloud or Microsoft Azure DevOps instance, the feedback and backlog items the Customer chooses to export are sent to the Customer's own instance, on the Customer's instruction and under the Customer's own agreement with that provider.
We will update this list before adding or replacing a subprocessor [notice mechanism to be finalized — see DPA].
Workspace users (Account Data — Morvero is controller): depending on your jurisdiction (GDPR arts. 15–21, KVKK md. 11) you may request access, correction, deletion, restriction, portability, and object to processing, and you may lodge a complaint with your supervisory authority (in Türkiye: Kişisel Verileri Koruma Kurumu; in the EU: your local DPA). Contact [privacy@morvero.example]. Workspace owners can additionally export the entire workspace as JSON in-product.
Visitors (Visitor Data — the website operator is controller): direct your request to
the operator of the website where you used the feedback widget. Because Morvero stores no name,
email or IP for visitors, the only key to your data is the random identifier in your own
browser: open the site, read the fbk_visitor value from localStorage, and send it
to the website operator. Their workspace includes Visitor data rights tools that export
or permanently erase everything tied to that identifier; both actions are audit-logged. If a
visitor contacts Morvero directly, we will forward the request to the relevant Customer where we
can identify them.
Morvero uses only functional storage — no advertising, analytics or tracking cookies, and no third-party cookies:
| Name | Kind / where | Purpose | Lifetime |
|---|---|---|---|
fbk_session | HttpOnly cookie — Morvero console (app) only | Keeps a signed-in workspace user's session; strictly necessary for login | Session (deleted on logout / expiry) |
fbk_visitor | localStorage — set by the widget on the Customer's site | Random anonymous visitor identifier so repeated visits and feedback can be counted without identifying anyone; also used to cap how often the feedback prompt appears | Until the visitor clears site data (or erasure via the Customer) |
The widget sets no cookies at all. Honoring DNT/GPC (Section 3) applies to the widget's tracking. Customers remain responsible for the cookie/consent rules that apply to their own sites where the widget runs.
Passwordless authentication (passkeys / single-use links), per-page signed submission tokens, per-IP and per-visitor rate limits, per-product domain allowlists and kill switches, strict payload validation, automatic scrubbing of sensitive form fields, role-based access with a full audit log, and owner-consented time-boxed platform-support access. See the Documentation. No system is perfectly secure; we will notify affected Customers and authorities of personal-data breaches as required by law (KVKK Board decision 2019/10: within 72 hours to the Kurul; GDPR art. 33).
The Service is B2B and not directed to children. Customers must not deploy the widget on child-directed properties. We may update this policy; material changes will be notified to workspace owners and the version/date above will change. Contact: [privacy@morvero.example — postal address to be added].
Bu aydınlatma metni, veri sorumlusu sıfatıyla [Morvero tüzel kişi unvanı] (adres: [adres], MERSİS No: [MERSİS], e-posta: [privacy@morvero.example]) ("Morvero") tarafından, Morvero geri bildirim ve kullanım analitiği platformunun ("Hizmet") müşteri çalışma alanı kullanıcılarına (workspace sahibi, yönetici, üye ve izleyici rolleri) yönelik olarak hazırlanmıştır.
Önemli ayrım — ziyaretçi verileri: Morvero widget'ının kurulu olduğu web sitesi ve uygulamaların son kullanıcı ziyaretçilerine ait veriler bakımından veri sorumlusu, ilgili web sitesini işleten Morvero müşterisidir; Morvero bu veriler bakımından KVKK anlamında veri işleyen konumundadır ve verileri yalnızca müşterinin talimatları doğrultusunda işler. Bir web sitesinde Morvero widget'ını kullanan ziyaretçiler, o sitenin işletmecisinin kendi aydınlatma metnine bakmalı ve taleplerini ona iletmelidir (bkz. B.7).
Ziyaretçilere ilişkin olarak Morvero, müşteri adına yalnızca anonim rastgele bir ziyaretçi
kimliği (tarayıcı localStorage'ında fbk_visitor), sayfa görüntüleme ve işlev
kullanım olayları, 1–5 puan/NPS puanı, serbest metin yorumlar ile ziyaretçinin her seferinde
ayrıca onay verdiği ekran görüntüsü ve hassas alanları otomatik ayıklanmış form değerlerini
işler; ziyaretçilerden ad, e-posta, IP adresi veya parmak izi alınmaz. Serbest metin
yorumlara ziyaretçinin kendisinin yazabileceği kişisel veriler, müşterinin veri sorumlusu olduğu
geri bildirim verisi kapsamında işlenir.
Kişisel verileriniz, aşağıdaki alt işleyicilere, belirtilen amaçlarla sınırlı olarak aktarılır. Bu alt işleyiciler Amerika Birleşik Devletleri'nde yerleşiktir; dolayısıyla yurt dışına veri aktarımı söz konusudur (KVKK md. 9):
| Alıcı | Ülke | Amaç | Aktarılan veri |
|---|---|---|---|
| Postmark (ActiveCampaign, LLC) | ABD | İşlemsel e-posta gönderimi (doğrulama/giriş bağlantıları, davetler, özetler) | Alıcı e-posta adresi ve e-posta içeriği |
| Anthropic, PBC ve/veya OpenAI, L.L.C. | ABD | İsteğe bağlı yapay zekâ geri bildirim analizi (Growth/Enterprise planları, yalnızca etkinse) | Yalnızca puanlar, sayfa yolları ve yorum metinleri; ekran görüntüleri ve form değerleri hiçbir zaman aktarılmaz |
Müşterinin kendi Jira Cloud veya Azure DevOps ortamını bağlaması hâlinde, dışa aktarılmasını seçtiği kayıtlar müşterinin talimatıyla müşterinin kendi ortamına iletilir.
Yurt dışına aktarım, KVKK md. 9'da öngörülen mekanizmalara dayanılarak yapılır: [ilgili alıcılarla Kurul tarafından ilan edilen standart sözleşmenin imzalanması ve imzalanmasından itibaren beş iş günü içinde Kuruma bildirilmesi / yeterli korumanın bulunduğu ülke kararı / Kurul izinli taahhütname — hangi mekanizmanın tamamlandığı yayımdan önce teyit edilmeli ve burada açıkça belirtilmelidir].
Kişisel verileriniz, kayıt formu, hizmetin kullanımı, e-posta doğrulama akışı ve sistem
kayıtları üzerinden elektronik ortamda, otomatik veya kısmen otomatik yollarla, yukarıda
B.4'te belirtilen hukuki sebeplere dayanılarak toplanır. Konsolda yalnızca oturum yönetimi için
zorunlu fbk_session çerezi kullanılır; reklam veya izleme çerezi kullanılmaz.
Widget çerez kullanmaz; ziyaretçi tarayıcısında yalnızca işlevsel fbk_visitor
localStorage kaydı tutulur.
KVKK md. 11 uyarınca; kişisel verilerinizin işlenip işlenmediğini öğrenme, işlenmişse buna ilişkin bilgi talep etme, işlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme, yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme, eksik veya yanlış işlenmişse düzeltilmesini isteme, md. 7 çerçevesinde silinmesini veya yok edilmesini isteme, bu işlemlerin aktarıldığı üçüncü kişilere bildirilmesini isteme, münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme ve kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme haklarına sahipsiniz.
Başvuru: Taleplerinizi, Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ'e uygun olarak [şirket adresi] adresine yazılı olarak, [KEP adresi] KEP adresine veya sistemimizde kayıtlı e-posta adresinizle [privacy@morvero.example] adresine iletebilirsiniz. Başvurular en geç 30 gün içinde ücretsiz olarak sonuçlandırılır; başvurunuzun reddi hâlinde Kişisel Verileri Koruma Kurulu'na şikâyette bulunma hakkınız saklıdır.
Ziyaretçiler için: Morvero widget'ının bulunduğu bir sitede verdiğiniz geri bildirime
ilişkin talepler, veri sorumlusu olan site işletmecisine yapılmalıdır. Sizi tanımlayan tek
anahtar tarayıcınızdaki fbk_visitor değeridir; bu değeri site işletmecisine
ilettiğinizde, işletmeci Hizmet içindeki Visitor data rights araçlarıyla bu kimliğe bağlı
tüm verileri dışa aktarabilir veya kalıcı olarak silebilir.