1. Personal Data Collected
The following personal data may be collected while you use our platform:
Account Information
- First name, surname, email address and password (stored encrypted)
- Profile photo (optional)
- Phone number (optional)
- Date of birth (optional)
Usage Data
- Learning progress on the platform and completed courses
- Assessment results and certificate details
- Page view and click data
- Sign-in times and IP address
- Device, browser and operating system information
Payment Information
Payments are processed through a PCI-DSS compliant third-party payment infrastructure. Your card details are not stored on Derin Akademi servers.
2. How the Data Is Used
Personal data collected is used only for the following purposes:
- To create and manage your account
- To provide access to the courses and services you have purchased
- To offer an AI-supported personalised learning experience
- To provide technical support and customer service
- To keep the platform secure and prevent fraud
- To send campaign and announcement emails where you have consented
- To meet legal obligations
3. Sharing With Third Parties
Your personal data is not shared with third parties for commercial purposes without your explicit consent. Data may be shared only in the following cases:
- Service providers: our contracted partners for payment processing, email infrastructure, cloud storage and analytics
- Legal obligation: where required by a court order or by law
- Business transfer: in the event of a merger or acquisition, with prior notice
4. Cookies and Tracking Technologies
Our platform uses various cookies. For details please see our Cookie Policy. Essential cookies are required for the service to function and cannot be disabled; analytics and marketing cookies can be managed from your browser settings.
5. Data Security
We apply industry-standard security measures to protect your data:
- All data transfers are protected with SSL/TLS encryption
- Passwords are stored hashed with the bcrypt algorithm
- Our servers are hosted in ISO 27001 certified data centres
- Regular security audits and penetration tests are carried out
- Employees can access only the data their role requires
6. Retention Periods
Your personal data is retained while your account is active, and for a further period after you delete it in line with statutory retention obligations:
- Account information: 3 years from the date of account deletion
- Payment records: 10 years (required by tax legislation)
- Log records: 2 years
- Marketing data: deleted on the date you unsubscribe
7. Your Rights
Under Turkish Personal Data Protection Law No. 6698 you have the rights below. For details please visit our Data Protection Notice:
- The right to learn whether your personal data is being processed
- The right to request information about the data processed
- The right to learn the purpose of processing and whether it is used accordingly
- The right to learn the third parties in Türkiye or abroad to whom the data has been transferred
- The right to request correction of incomplete or inaccurate data
- The right to request erasure where the statutory conditions are met
- The right to object to processing
8. Contact
For questions about our privacy policy or your personal data:
Your request will be answered within 30 days at the latest once your identity has been verified.