Morvero — Privacy Policy & KVKK Aydınlatma Metni

v1.0 — Effective date: 2026-07-05 · Part A: Privacy Policy (English) · Part B: KVKK Aydınlatma Metni (Türkçe)

DRAFT TEMPLATE — NOT YET IN FORCE. This document is a draft prepared for founder review. It is a template, not legal advice, and must be reviewed and adapted by qualified counsel before production use. Bracketed items [like this] are open decisions.
TASLAK ŞABLON: Bu metin kurucu incelemesi için hazırlanmış bir taslaktır; yayımlanmadan önce alanında yetkin bir avukat tarafından incelenmesi ve uyarlanması zorunludur.

Part A — Privacy Policy (English)

1. Who we are, and the two roles we play

[Morvero legal entity name, registered address, registry/MERSİS number] ("Morvero", "we") operates the Morvero feedback and product-usage analytics platform. Morvero processes personal data in two distinct roles:

2. What we collect

Account Data (Morvero as controller):

Visitor Data (Morvero as processor for the Customer):

3. Anonymity by design; Do Not Track

4. Purposes and legal bases (Account Data)

PurposeDataLegal basis (GDPR / KVKK)
Creating and operating the workspace; authentication (sign-in links, passkeys, SSO)Email, name, role, credentials, sessionsContract performance (GDPR art. 6(1)(b); KVKK md. 5/2-c)
Service email: verification links, sign-in links, invitations, security notices, requested digestsEmail, digest preferenceContract performance; legitimate interest for security notices
Security, abuse prevention, audit trailAudit logs, rate-limit countersLegitimate interest (GDPR art. 6(1)(f); KVKK md. 5/2-f); legal obligation where applicable
Plan administration and, once live, billing and invoicingPlan, billing recordsContract performance; legal obligation (tax/bookkeeping)
Marketing email (none today)Only with prior consent / opt-in if ever introduced

Visitor Data is processed only on the Customer's documented instructions to provide the Service; the Customer is responsible for its lawful basis.

5. Retention

6. Subprocessors and international transfers

Morvero uses the following subprocessors. All of them are located in the United States, which means personal data is transferred outside Türkiye and outside the EU/EEA. Transfer safeguards: [GDPR: EU Standard Contractual Clauses; KVKK md. 9: standard contract notified to the Turkish DPA — execution in progress; verify before publication].

ProviderLocationPurposeData shared
Postmark (ActiveCampaign, LLC)USATransactional email delivery: verification and sign-in links, team invitations, digestsRecipient email address, email content
Anthropic, PBC and/or OpenAI, L.L.C.USAOptional AI feedback analysis (theme summaries, backlog suggestions) — Growth/Enterprise only, only when enabledFeedback ratings, page paths and comment text only. Screenshots and form-value attachments are never sent to AI providers.

Customer-connected integrations (not Morvero subprocessors): if a Customer connects its own Atlassian Jira Cloud or Microsoft Azure DevOps instance, the feedback and backlog items the Customer chooses to export are sent to the Customer's own instance, on the Customer's instruction and under the Customer's own agreement with that provider.

We will update this list before adding or replacing a subprocessor [notice mechanism to be finalized — see DPA].

7. Your rights and how to exercise them

Workspace users (Account Data — Morvero is controller): depending on your jurisdiction (GDPR arts. 15–21, KVKK md. 11) you may request access, correction, deletion, restriction, portability, and object to processing, and you may lodge a complaint with your supervisory authority (in Türkiye: Kişisel Verileri Koruma Kurumu; in the EU: your local DPA). Contact [privacy@morvero.example]. Workspace owners can additionally export the entire workspace as JSON in-product.

Visitors (Visitor Data — the website operator is controller): direct your request to the operator of the website where you used the feedback widget. Because Morvero stores no name, email or IP for visitors, the only key to your data is the random identifier in your own browser: open the site, read the fbk_visitor value from localStorage, and send it to the website operator. Their workspace includes Visitor data rights tools that export or permanently erase everything tied to that identifier; both actions are audit-logged. If a visitor contacts Morvero directly, we will forward the request to the relevant Customer where we can identify them.

8. Cookies and localStorage

Morvero uses only functional storage — no advertising, analytics or tracking cookies, and no third-party cookies:

NameKind / wherePurposeLifetime
fbk_sessionHttpOnly cookie — Morvero console (app) onlyKeeps a signed-in workspace user's session; strictly necessary for loginSession (deleted on logout / expiry)
fbk_visitorlocalStorage — set by the widget on the Customer's siteRandom anonymous visitor identifier so repeated visits and feedback can be counted without identifying anyone; also used to cap how often the feedback prompt appearsUntil the visitor clears site data (or erasure via the Customer)

The widget sets no cookies at all. Honoring DNT/GPC (Section 3) applies to the widget's tracking. Customers remain responsible for the cookie/consent rules that apply to their own sites where the widget runs.

9. Security

Passwordless authentication (passkeys / single-use links), per-page signed submission tokens, per-IP and per-visitor rate limits, per-product domain allowlists and kill switches, strict payload validation, automatic scrubbing of sensitive form fields, role-based access with a full audit log, and owner-consented time-boxed platform-support access. See the Documentation. No system is perfectly secure; we will notify affected Customers and authorities of personal-data breaches as required by law (KVKK Board decision 2019/10: within 72 hours to the Kurul; GDPR art. 33).

10. Children; changes; contact

The Service is B2B and not directed to children. Customers must not deploy the widget on child-directed properties. We may update this policy; material changes will be notified to workspace owners and the version/date above will change. Contact: [privacy@morvero.example — postal address to be added].

Bölüm B — Türkçe: 6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") md. 10 uyarınca aydınlatma metni. Bu bölüm, yukarıdaki İngilizce politikanın yerine değil, KVKK kapsamındaki aydınlatma yükümlülüğünü karşılamak üzere onunla birlikte yayımlanır.

Bölüm B — Kişisel Verilerin İşlenmesine İlişkin Aydınlatma Metni (KVKK md. 10)

B.1. Veri sorumlusu

Bu aydınlatma metni, veri sorumlusu sıfatıyla [Morvero tüzel kişi unvanı] (adres: [adres], MERSİS No: [MERSİS], e-posta: [privacy@morvero.example]) ("Morvero") tarafından, Morvero geri bildirim ve kullanım analitiği platformunun ("Hizmet") müşteri çalışma alanı kullanıcılarına (workspace sahibi, yönetici, üye ve izleyici rolleri) yönelik olarak hazırlanmıştır.

Önemli ayrım — ziyaretçi verileri: Morvero widget'ının kurulu olduğu web sitesi ve uygulamaların son kullanıcı ziyaretçilerine ait veriler bakımından veri sorumlusu, ilgili web sitesini işleten Morvero müşterisidir; Morvero bu veriler bakımından KVKK anlamında veri işleyen konumundadır ve verileri yalnızca müşterinin talimatları doğrultusunda işler. Bir web sitesinde Morvero widget'ını kullanan ziyaretçiler, o sitenin işletmecisinin kendi aydınlatma metnine bakmalı ve taleplerini ona iletmelidir (bkz. B.7).

B.2. İşlenen kişisel veriler

Ziyaretçilere ilişkin olarak Morvero, müşteri adına yalnızca anonim rastgele bir ziyaretçi kimliği (tarayıcı localStorage'ında fbk_visitor), sayfa görüntüleme ve işlev kullanım olayları, 1–5 puan/NPS puanı, serbest metin yorumlar ile ziyaretçinin her seferinde ayrıca onay verdiği ekran görüntüsü ve hassas alanları otomatik ayıklanmış form değerlerini işler; ziyaretçilerden ad, e-posta, IP adresi veya parmak izi alınmaz. Serbest metin yorumlara ziyaretçinin kendisinin yazabileceği kişisel veriler, müşterinin veri sorumlusu olduğu geri bildirim verisi kapsamında işlenir.

B.3. İşleme amaçları

B.4. Hukuki sebepler (KVKK md. 5)

B.5. Kişisel verilerin aktarılması (KVKK md. 8–9)

Kişisel verileriniz, aşağıdaki alt işleyicilere, belirtilen amaçlarla sınırlı olarak aktarılır. Bu alt işleyiciler Amerika Birleşik Devletleri'nde yerleşiktir; dolayısıyla yurt dışına veri aktarımı söz konusudur (KVKK md. 9):

AlıcıÜlkeAmaçAktarılan veri
Postmark (ActiveCampaign, LLC)ABDİşlemsel e-posta gönderimi (doğrulama/giriş bağlantıları, davetler, özetler)Alıcı e-posta adresi ve e-posta içeriği
Anthropic, PBC ve/veya OpenAI, L.L.C.ABDİsteğe bağlı yapay zekâ geri bildirim analizi (Growth/Enterprise planları, yalnızca etkinse)Yalnızca puanlar, sayfa yolları ve yorum metinleri; ekran görüntüleri ve form değerleri hiçbir zaman aktarılmaz

Müşterinin kendi Jira Cloud veya Azure DevOps ortamını bağlaması hâlinde, dışa aktarılmasını seçtiği kayıtlar müşterinin talimatıyla müşterinin kendi ortamına iletilir.

Yurt dışına aktarım, KVKK md. 9'da öngörülen mekanizmalara dayanılarak yapılır: [ilgili alıcılarla Kurul tarafından ilan edilen standart sözleşmenin imzalanması ve imzalanmasından itibaren beş iş günü içinde Kuruma bildirilmesi / yeterli korumanın bulunduğu ülke kararı / Kurul izinli taahhütname — hangi mekanizmanın tamamlandığı yayımdan önce teyit edilmeli ve burada açıkça belirtilmelidir].

B.6. Toplama yöntemi ve hukuki sebep özeti (KVKK md. 10/1-ç)

Kişisel verileriniz, kayıt formu, hizmetin kullanımı, e-posta doğrulama akışı ve sistem kayıtları üzerinden elektronik ortamda, otomatik veya kısmen otomatik yollarla, yukarıda B.4'te belirtilen hukuki sebeplere dayanılarak toplanır. Konsolda yalnızca oturum yönetimi için zorunlu fbk_session çerezi kullanılır; reklam veya izleme çerezi kullanılmaz. Widget çerez kullanmaz; ziyaretçi tarayıcısında yalnızca işlevsel fbk_visitor localStorage kaydı tutulur.

B.7. İlgili kişinin hakları (KVKK md. 11) ve başvuru yolu

KVKK md. 11 uyarınca; kişisel verilerinizin işlenip işlenmediğini öğrenme, işlenmişse buna ilişkin bilgi talep etme, işlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme, yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme, eksik veya yanlış işlenmişse düzeltilmesini isteme, md. 7 çerçevesinde silinmesini veya yok edilmesini isteme, bu işlemlerin aktarıldığı üçüncü kişilere bildirilmesini isteme, münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme ve kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme haklarına sahipsiniz.

Başvuru: Taleplerinizi, Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ'e uygun olarak [şirket adresi] adresine yazılı olarak, [KEP adresi] KEP adresine veya sistemimizde kayıtlı e-posta adresinizle [privacy@morvero.example] adresine iletebilirsiniz. Başvurular en geç 30 gün içinde ücretsiz olarak sonuçlandırılır; başvurunuzun reddi hâlinde Kişisel Verileri Koruma Kurulu'na şikâyette bulunma hakkınız saklıdır.

Ziyaretçiler için: Morvero widget'ının bulunduğu bir sitede verdiğiniz geri bildirime ilişkin talepler, veri sorumlusu olan site işletmecisine yapılmalıdır. Sizi tanımlayan tek anahtar tarayıcınızdaki fbk_visitor değeridir; bu değeri site işletmecisine ilettiğinizde, işletmeci Hizmet içindeki Visitor data rights araçlarıyla bu kimliğe bağlı tüm verileri dışa aktarabilir veya kalıcı olarak silebilir.