Data Controller
Pursuant to the Law on the Protection of Personal Data No. 6698 ("KVKK") and international privacy principles, your personal data is processed by Operis Teknoloji Anonim Sirketi ("Platform" or "Company") as data controller within the scope detailed below.
Processed Personal Data and Data Minimization
Under strict privacy-by-design and data minimization principles, the Platform processes exclusively necessary data:
- 1Identity Data: Legal first name, legal last name, date of birth (to verify 18+ age majority).
- 2Contact Data: Country and city of residence, verified email address, verified mobile phone number.
- 3Technical & Audit Logs: Salted Scrypt password derivation hashes, session tokens, IP addresses, legal consent timestamps, and statutory access logs.
- 4Data Strictly Never Collected: National ID numbers (TCKN), government ID scans, criminal background records, religion, biometric or genetic data, and special category personal data are strictly never requested, collected, or stored on our servers.
Legal Grounds and Processing Purposes
Your data is processed under legitimate statutory grounds:
- 1Contractual Performance: Account provisioning, listing and private offer workflows; disclosing verified contact information to counterparties only after a mutual match is confirmed.
- 2Legal Obligations: Complying with telecommunications log retention statutes and commercial electronic message consent preservation.
- 3Legitimate Security Interests: Defending against DDoS attacks, preventing automated credential stuffing, identity fraud, and maintaining infrastructure integrity.
Cryptographic Safeguards: Encryption & Blind Indexing
- 1Application-Level Encryption: Sensitive database fields (names, phone numbers) are encrypted using AES-256-GCM before database persistence. Physical database intrusion yields unintelligible ciphertext.
- 2HMAC-SHA256 Blind Indexing: Mobile phone uniqueness checks are performed cryptographically using keyed HMAC-SHA256 blind indexes without decrypting persistent records.
- 3Password Security: Cleartext passwords are never stored or transmitted; salted Scrypt key derivation functions are strictly enforced.
Third-Party Transfers and Non-Sale of Data
- 1Zero Data Monetization: The Platform strictly never sells, leases, or trades user personal data to marketing brokers or advertising networks.
- 2Match-Gated Disclosure: Contact details remain shielded from all users until mutual offer acceptance. Upon matching, contact details are disclosed solely for bilateral contract performance.
- 3Statutory Disclosure: Disclosures occur strictly in response to binding, written court orders, public prosecutorial warrants, or mandatory statutory mandates.
Data Retention and Erasure
Personal data is retained throughout account activity and following termination for statutory limitation periods (10 years) to defend against potential legal claims. Upon expiration, data is irreversibly erased, destroyed, or anonymized during regular purge cycles.
Data Subject Rights
Under Article 11 of the KVKK and GDPR, you possess the right to learn whether your data is processed, request information, request correction of inaccurate records, and request deletion or destruction. Inquiries may be addressed to kvkk@operis.pro. Requests are concluded free of charge within 30 days.