KVKK Information Notice
Last updated: 9 August 2026
This is a courtesy translation of the Turkish original (“YazBunu Aydınlatma Metni”). In case of any discrepancy, the Turkish text prevails.
1. Identity of the Data Controller
This Information Notice has been prepared by Peracom Yazılım Danışmanlık A.Ş., which operates the YazBunu mobile application on iPhone and Android phones and the Apple Watch and CarPlay extensions connected to iPhone, in accordance with the Turkish Personal Data Protection Law no. 6698 (“KVKK”).
Peracom Yazılım Danışmanlık A.Ş. may be contacted in its capacity as data controller at destek@peracom.net.
YazBunu is currently a mobile application distributed in Türkiye only. The service runs on iPhone and Android phones; on iPhone it additionally offers extra recording channels through the Apple Watch and CarPlay extensions. A desktop or web application is not within the current scope of this Information Notice. The way audio is processed differs depending on the platform used.
YazBunu is a digital note-taking and transcription service that allows the user to create voice content on iPhone, Android phones, Apple Watch or CarPlay, convert audio content into text for certain types of recording, edit notes, generate summaries, decisions, tasks and follow-up items from transcripts and text content, prepare e-mail drafts, optionally back up selected text content in end-to-end encrypted form, and manage notes within the application.
This Information Notice covers YazBunu’s individual usage scenarios, daily and work notes, Meeting Mode, recordings made via CarPlay and Apple Watch, text structuring features, optional cloud backup and synchronisation services, e-mail sending flows, technical support processes and the service providers used to operate the application technically.
Where a recording is made through Meeting Mode, CarPlay or Apple Watch, not only the user’s own voice and content but also the voices, speech content, names, contact details, roles, opinions and decisions of other persons participating in the meeting, interview or recording, and other personal data appearing in the transcript, summary, decisions, tasks or follow-up e-mail drafts generated as a result of the meeting, may be processed.
The user who starts the meeting or recording is responsible for fulfilling their own legal obligations to the extent that they may be regarded as a data controller or independent data controller in respect of creating the meeting content, notifying participants, sharing the content and their own purpose of use. This Information Notice explains the data processing activities carried out by Peracom Yazılım Danışmanlık A.Ş. within the scope of the YazBunu service and does not remove any independent obligations the user may have in respect of data belonging to other persons.
2. Categories of Personal Data Processed
The following categories of personal data may be processed while using YazBunu, only to the extent required by the features you use:
- Identity and account data: First name, surname, account identifier, username and the information provided when creating or managing an account.
- Contact data: E-mail address, contact details shared in support requests, recipient addresses used in the e-mail sending feature and communication preferences.
- Audio data: Audio recordings taken via iPhone, Android phone, Apple Watch or CarPlay, technical information about the audio file and the limited technical data required to convert audio into text.
- Transcript and content data: The transcript, note, title, tag, meeting summary, decisions, to-do list, task assignments, follow-up e-mail draft, meeting date, time, duration, title and participant information generated as a result of converting an audio recording into text.
- Artificial intelligence processing data: Notes, transcripts or text excerpts selected by the user for structuring with artificial intelligence.
- Cloud backup data: Note texts, transcripts, folders, tags and other text content selected by the user within the scope of the end-to-end encrypted cloud backup.
- Subscription and transaction data: Subscription status, purchase and renewal information, refund information and transaction identifiers generated by the Apple App Store, Google Play or RevenueCat.
- Device and technical data: Device model, operating system version, application version, session information, performance data, error and crash records, connection information and security logs.
- Usage and preference data: In-app settings, feature preferences, enabled or disabled functions and limited feature usage information.
- Support and feedback data: Messages sent to the support team, requests, complaints, feedback, error descriptions and any files or screenshots the user chooses to attach.
- On-device diagnostic logs: The limited technical records kept on the device under the names diag.log for the application recording pipeline and carplay.log for vehicle connection and CarPlay processes.
- E-mail data: The recipient address, subject, body, attachments, sending preference and sending result of the e-mail the user chooses to send.
- Data belonging to meeting participants: During a Meeting Mode, CarPlay or Apple Watch recording, the voices, speech, names, roles, opinions, contact details and other personal data of other persons in the context of the meeting.
- Content that may include special categories of personal data: Where health data, religious or philosophical beliefs, political opinions, trade union or association membership, sexual life, criminal convictions and security measures, or similar special categories of personal data appear within the audio, notes, transcripts, meeting summaries or other text content recorded by the user.
YazBunu does not create, collect, store as separate data, or use for such purposes any voiceprint, biometric voice profile or biometric voice template.
When the user wishes to share a diagnostic log, masking is applied on the device; the masked version prepared for sharing does not contain note text, transcripts, participant names, audio file paths or the user identifier. The raw log remaining on the device is kept solely for local fault diagnosis and does not leave the device unless the user shares it. These logs contain limited technical information used to understand the technical state of the application’s recording and connection pipeline.
On-device diagnostic logs do not leave the device by themselves; they are not uploaded to the server, are not included in the cloud backup and are not sent automatically in the background. If the user wishes to share these logs, masking is carried out on the device, the masked content is displayed in full before sharing, and separate approval is obtained for each act of sharing.
As a rule, only data required by the feature you use and connected to the purpose are processed. Data processing activities that do not require explicit consent for the operation of the application’s basic service may rely on other applicable legal grounds.
3. Methods by which Personal Data are Obtained
Your personal data may be obtained through:
- downloading, installing and using the YazBunu application on your iPhone or Android phone,
- creating an account or logging into your account,
- entering information into fields within the application,
- starting an audio recording on your iPhone or Android phone,
- enabling Meeting Mode,
- starting a recording via a CarPlay connection,
- starting a recording via Apple Watch,
- processing voice content in the nature of daily or work notes with the live recognition feature,
- using the speech-to-text feature,
- choosing the artificial intelligence supported editing, summarising, structuring or classification feature,
- enabling the end-to-end encrypted cloud backup or cross-device synchronisation feature,
- creating an e-mail draft or initiating an e-mail sending operation,
- changing your in-app settings and permission preferences,
- contacting the support team,
- creating an error, crash or feedback report,
- carrying out a subscription or in-app purchase transaction,
- technical records, error and crash records generated automatically within the application,
- masked diagnostic logs that the user expressly chooses to share,
- limited subscription, technical or transaction data received from service providers you have chosen and authorised.
Your personal data may be obtained directly from you, from technical records generated automatically by your device, or from the service providers you use and authorise.
Where Meeting Mode, CarPlay or Apple Watch is used, data belonging to other meeting participants may not be obtained directly from those persons; such data may be obtained indirectly within the audio recording, transcription process, notes, summaries or e-mail content.
4. Purposes of Processing Personal Data
Your personal data may be processed for the following purposes:
- installing, operating and providing the basic functions of the YazBunu application,
- creating, verifying and managing the user account,
- account security, session management, verification and security notifications,
- creating local audio recordings and local storage on an iPhone or Android phone,
- converting voice content in the nature of daily or work notes into text through live recognition,
- temporarily processing and transcribing audio recordings taken via Meeting Mode, CarPlay and Apple Watch, and audio recordings made on Android phones,
- creating transcripts, notes, titles, tags and text content,
- creating meeting summaries, decisions, action items and task lists,
- summarising, structuring, classifying or tagging the text content selected by the user with artificial intelligence support,
- preparing a follow-up e-mail draft based on the meeting content,
- allowing the user to view, edit, delete and store the content they have created,
- allowing the user to share meeting outputs by e-mail where the user approves before sending,
- backing up the note texts and transcripts selected by the user in end-to-end encrypted form,
- synchronising selected text content between authorised devices,
- ensuring that audio files and m4a recordings are not included in the cloud backup,
- managing subscription and in-app purchase status,
- sending account e-mails and carrying out e-mail sending initiated by the user,
- monitoring application performance and the connection and recording pipeline,
- detecting and resolving errors, crashes and performance problems,
- preventing misuse, unauthorised access, fraud and security breaches,
- assessing support requests, complaints and feedback,
- improving the user experience,
- carrying out limited personalisation and usage analysis where the user opts in,
- fulfilling legal obligations,
- responding to requests from competent authorities,
- managing disputes and establishing, exercising or protecting a right,
- ensuring information security, data security and business continuity.
Where data need to be processed for a new purpose, the necessary information will be provided in respect of that purpose. Where explicit consent is also required due to the nature of the processing, explicit consent is obtained separately and independently of this Information Notice.
5. Legal Grounds for Processing Personal Data
Depending on the nature of the processing activity, your personal data may be processed on one or more of the following legal grounds:
- express provision in the law,
- direct connection with the establishment or performance of a contract,
- necessity for the data controller to fulfil a legal obligation,
- necessity of processing for the establishment, exercise or protection of a right,
- necessity of processing for the legitimate interests of the data controller,
- the explicit consent of the data subject.
In this context:
- the establishment or performance of a contract may be the legal ground for providing the basic functions of the application, managing the account and delivering the service requested by the user;
- in respect of the temporary upload of the audio file to the server for transcription on Android phones, because that operation is technically necessary for the service to be provided on Android, the legal ground is the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation;
- legal obligation may be the legal ground for transactions connected with tax, accounting, consumer transactions, information security or requests from competent authorities;
- the legitimate interests of the data controller may be the legal ground for security, error detection, prevention of misuse and technical improvement of the service;
- the establishment, exercise or protection of a right may be the legal ground for managing disputes and protecting rights;
- explicit consent may be the legal ground for optional features chosen by the user, such as cloud backup, personalisation, usage analysis or other operations requiring separate approval.
Explicit consent is a legal act distinct from the Information Notice. Providing an information notice does not by itself mean that explicit consent has been obtained. Likewise, obtaining explicit consent does not remove the data controller’s obligation to provide an information notice.
If you do not give explicit consent, only the features that rely on explicit consent cannot be used or the relevant processing activity is not carried out. The provision of basic services that do not require explicit consent continues as a rule where the relevant legal ground exists.
The creation of a recording via Meeting Mode, CarPlay or Apple Watch, its transmission for transcription, the processing of text with artificial intelligence and the sharing of meeting outputs are processing activities that must be assessed separately. In respect of these activities, performance of a contract, legitimate interest, explicit consent or other appropriate legal grounds may apply depending on the circumstances.
Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation.
6. Special Categories of Personal Data
YazBunu is not designed to process special categories of personal data. Nevertheless, special categories of personal data may be present within the audio recorded by the user, the notes created, transcripts or meeting content.
In this context, health information, religious or philosophical beliefs, political opinions, trade union or association membership, information relating to sexual life, information relating to criminal convictions and security measures, or other data regulated as special categories under the legislation may appear within the content.
YazBunu does not aim to collect or classify special categories of personal data for an independent purpose. However, if the user records such data, includes it in a meeting recording or keeps it in the text content generated, that data may enter the relevant technical processing flow of the service.
The processing of special categories of personal data is subject to the conditions set out in the applicable legislation. Users must not record special categories of personal data unless necessary, must not include them in meeting content, and must review such data before sharing and, where possible, delete or mask it.
YazBunu does not make the processing of special categories of personal data an independent purpose of the basic service and does not retain such data for longer than necessary.
7. Meeting Mode, CarPlay and Apple Watch Recordings
Meeting Mode, CarPlay and Apple Watch are recording channels that allow the user to create an audio recording in a meeting, interview, training session, negotiation, workplace meeting, online meeting, in-vehicle conversation or similar multi-party conversation environment, and to convert the selected recording into text.
Where these channels are used, not only the user’s own voice but also the voices and speech of other persons participating in the recording may be processed. In addition, personal data, tasks, contact details or other information relating to persons who are mentioned in the meeting but do not participate in it may appear within the transcript, summary, task list or e-mail draft.
The principal data that may be processed within the scope of Meeting Mode, CarPlay and Apple Watch are:
- audio recordings,
- meeting conversations,
- transcripts,
- the meeting summary,
- decisions,
- action items,
- to-do lists,
- task assignments,
- participant information,
- meeting date, time, duration and title,
- data relating to persons mentioned in the meeting,
- follow-up e-mail drafts,
- the limited technical information required to operate the service technically.
7.1. How Audio is Processed
In YazBunu, audio processing is carried out through different paths depending on the platform used and the type of recording:
| Type of recording | Where and how the audio is processed | What remains on the device |
|---|---|---|
| Daily or work note on iPhone (live recognition) | Audio may be processed using Apple’s on-device or Apple speech recognition services. Apple’s own privacy rules and policies may also apply to this process. | The m4a audio file remains on the device. |
| Meeting Mode, CarPlay and Apple Watch | The audio file is uploaded temporarily to the YazBunu server for transcription purposes. The temporary audio file is held on Supabase Storage in the Frankfurt/European Union region and converted to text via AssemblyAI’s European region endpoint api.eu.assemblyai.com. It is deleted once processing is complete and in any event within 24 hours at the latest from its upload to the server. | The m4a audio file may also remain on the device. |
| All recordings created on Android phones (daily, work note and meeting) | Because on-device Turkish speech recognition is not available on Android devices, the audio file is uploaded temporarily to the YazBunu server for transcription purposes regardless of the type of recording, and is subject to the same rules as the meeting flow. | The m4a audio file may also remain on the device. |
| Text structuring with artificial intelligence | Only the transcript or the selected text content is sent in order to generate summaries, decisions, tasks, classifications or similar outputs. No audio file is sent at this stage. | The m4a file and local text content on the device remain on the device according to the device and application settings. |
The temporary audio file obtained from Meeting Mode, CarPlay, Apple Watch or Android recordings is not included in the end-to-end encrypted cloud backup. The cloud backup may contain only the note texts, transcripts and other appropriate text content selected by the user.
No voiceprint, biometric voice profile or biometric voice template is created, collected or stored in any of these processes.
7.2. Informing Participants
The user must inform participants about the recording before a meeting or multi-party conversation is recorded. The notice should explain that the meeting will be recorded, that the audio may be converted to text, that it may be transferred temporarily to the server, that a meeting summary or task list may be generated, and that the meeting outputs may be shared by the user.
The user who starts a meeting recording is not authorised to give explicit consent on behalf of other participants. The user must carry out the necessary information and permission processes separately, according to the nature of the meeting.
In particular, for workplace meetings, whether explicit consent has been given freely must be separately assessed because of the nature of the relationship between employer and employee. Recording a meeting covertly, failing to inform participants or using the recording outside its purpose may create legal risk.
8. Audio Recordings and the Transcription Process
In live recognition of daily or work notes on iPhone, audio may be processed using Apple’s on-device or Apple speech recognition services. In this type of recording the m4a audio file remains on the device.
In Meeting Mode, CarPlay and Apple Watch recordings, and in all recordings made on Android phones, the audio file may be uploaded temporarily to the YazBunu server for transcription purposes. This temporary audio file:
- may be held on Supabase Storage in the Frankfurt/European Union region,
- may be converted to text via AssemblyAI’s European region endpoint api.eu.assemblyai.com,
- is deleted from the server once processing is complete and in any event within 24 hours at the latest from the date of upload,
- is not included in the end-to-end encrypted cloud backup,
- is not used to create a voiceprint or biometric voice profile.
Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation.
No audio file is sent when structured outputs such as summaries, decisions, tasks or classifications are generated with artificial intelligence. Only the transcript or the text content selected by the user is processed at that stage.
The period for which m4a audio files remain on the device depends on the user’s device and application use. The user may delete these files from the device. For audio files temporarily uploaded to the server, an absolute upper limit of 24 hours applies.
9. Artificial Intelligence Supported Processing
YazBunu may process the transcript, note or text content selected by the user with artificial intelligence supported systems in order to summarise, structure, classify, title or tag it, or to turn it into task and decision outputs.
As a rule, the following are processed at this stage, rather than the audio file:
- the transcript text,
- notes entered directly by the user,
- text excerpts selected by the user,
- the limited meeting information required for structuring,
- the content required to generate a summary, decision, task or e-mail draft.
No audio file is sent at this stage. YazBunu does not create voiceprints or biometric voice templates.
Google Gemini may be used in the text structuring service. Depending on the technical structure of the service or the product configuration, alternative artificial intelligence service providers such as OpenAI or Anthropic may also be used. The data sent to the provider used is limited to the selected processing purpose.
The accuracy, completeness or full contextual suitability of outputs generated by artificial intelligence is not guaranteed. Summaries, decisions, tasks or e-mail drafts must be reviewed by the user before being shared, sent or used in an important transaction.
Artificial intelligence outputs do not in themselves constitute legal, financial, medical or professional advice. The user must not use an artificial intelligence output as the sole basis for decisions with significant consequences.
10. Optional Cloud Backup and Cross-Device Synchronisation
Where the user chooses separately to enable it, YazBunu may provide an end-to-end encrypted cloud backup and cross-device synchronisation service.
The following data may be processed in this context:
- note texts selected by the user,
- transcripts,
- folders,
- tag structure,
- other selected text content,
- account matching and authentication information,
- the limited technical information required to carry out synchronisation.
Only the appropriate text content selected by the user is included in the end-to-end encrypted cloud backup. Audio files, m4a recordings and raw audio files processed temporarily on the server for transcription purposes are not included in the cloud backup.
Supabase’s authentication, encrypted backup and storage services may be used for the cloud backup and synchronisation service. The temporary audio file storage infrastructure is located in the Frankfurt/European Union region.
Within the scope of end-to-end encryption, the decryption key is protected by the user. The user should be aware that if they lose the encryption password or the necessary recovery information, Peracom Yazılım Danışmanlık A.Ş. cannot view, store or regenerate that password, and that it may therefore be technically impossible to restore the encrypted backup.
The cloud backup feature is not a mandatory part of the application’s basic local note-taking function. Users who do not enable this feature may, as a rule, continue to benefit from the basic local note-taking functions provided that the other legal and technical conditions are met.
11. Optional Personalisation and Usage Analysis
Where the user separately opts in, YazBunu may process the following data in order to personalise the application experience and produce limited usage statistics:
- in-app preferences and settings,
- enabled features,
- frequency of feature use,
- session and usage durations,
- the limited technical information required for application and device compatibility.
Personalisation and usage analysis are not necessary for the provision of the basic local note-taking service. These activities are carried out according to a separate preference and permission flow offered within the application.
Within the scope of personalisation or usage analysis, audio files, voiceprints, full transcripts or user content are not used for advertising purposes. User content is not used to train artificial intelligence models outside the purpose of the service.
Subscription status and in-app purchase information may be managed through RevenueCat. The information transferred to RevenueCat is limited to what is necessary to determine subscription status and to operate the related in-app services.
12. Cross-Border Transfers
Within YazBunu’s technical infrastructure, certain personal data may be processed through service providers located abroad or operated by companies abroad.
The principal services that may give rise to cross-border transfers are:
- processing of audio files for transcription in Meeting Mode, CarPlay and Apple Watch recordings and in Android recordings,
- structuring of transcripts or text with artificial intelligence,
- e-mail sending,
- server hosting,
- subscription management,
- authentication,
- technical support and security services.
The providers used and the purposes of the services are as follows:
- Supabase: Authentication, encrypted cloud backup and temporary audio file storage services. The temporary audio file storage infrastructure is in the Frankfurt/European Union region.
- AssemblyAI: Transcription of meeting, CarPlay, Apple Watch and Android recordings. The operation is carried out via the European region endpoint api.eu.assemblyai.com. Because AssemblyAI’s corporate headquarters may be located in the United States of America, the relevant transfer must also be assessed in terms of the provider’s corporate structure, sub-processors and applicable transfer mechanisms.
- Google Gemini: Structuring of transcripts or text content selected by the user with artificial intelligence.
- OpenAI or Anthropic: Artificial intelligence services that may be used as an alternative to Google Gemini for text structuring, depending on the product configuration or technical requirements.
- RevenueCat: Management of subscription status and in-app purchase information.
- Railway: Server hosting and technical operation of the application.
- Resend: Sending of account e-mails.
- The user’s own SMTP account: Where the user uses the in-app e-mail sending feature, the e-mail is sent through the user’s own SMTP account. The recipient, subject and body of the e-mail and the connection details of the e-mail account pass through the YazBunu server so that the sending can be carried out and are not stored on the server.
Cross-border transfers are carried out in accordance with the cross-border transfer provisions of the KVKK and other applicable legislation, according to the nature of the transfer. Transfers are made in compliance with the principles of purpose limitation, data minimisation, proportionality and security.
The transfer of an audio file and the transfer of text content are different. In Meeting Mode, CarPlay and Apple Watch recordings, and in Android recordings, the audio file may be processed temporarily for transcription purposes only. At the artificial intelligence structuring stage no audio file is sent; only the transcript or the text selected by the user is processed.
13. Transfer of Personal Data
Your personal data may be transferred to the following recipient groups, only to the extent connected with and necessary for the relevant processing purpose:
- Supabase and similar authentication, storage and cloud service providers,
- transcription and speech recognition service providers such as AssemblyAI,
- artificial intelligence service providers such as Google Gemini, OpenAI or Anthropic,
- server hosting and application infrastructure providers such as Railway,
- subscription and in-app purchase services such as RevenueCat, the Apple App Store and Google Play,
- e-mail sending services: Resend for account e-mails, and the user’s own e-mail (SMTP) service provider for sending initiated by the user,
- technical support, security, error detection and infrastructure service providers,
- legal, financial or technical advisers,
- competent public institutions and organisations,
- in the event of a dispute, the relevant parties, judicial authorities and legally competent bodies,
- where corporate services are offered in the future, the authorised company units limited to the scope of the relevant corporate service.
The scope of a transfer is limited to the data required by the feature used. For example, using only the artificial intelligence text structuring feature does not result in the audio file being sent to AssemblyAI. The temporary upload of audio to the server and its transfer to the transcription service is assessed separately in respect of the Meeting Mode, CarPlay or Apple Watch recording process, or recording on an Android phone.
Where meeting results are shared by e-mail, the meeting summary, transcript, decisions, task list, e-mail draft and the personal data contained in that content may be transferred to the recipients determined by the user. The application does not automatically send this content to recipients unless the user expressly approves before sending.
Depending on the nature of the relevant processing activity, the service providers to which transfers are made may be regarded as data processors or as independent data controllers. Each provider’s own service terms and privacy arrangements may also apply.
14. Retention Periods
Your personal data are retained only for the period required by the purpose of processing. When determining the retention period, the data category, the purpose of processing, legal obligations, the risk of dispute, security requirements and the principle of data minimisation are taken into account.
| Type of data or record | Retention period and operation applied |
|---|---|
| Temporary audio file on the server | Kept temporarily for transcription purposes. Deleted once processing is complete and in any event within a maximum of 24 hours from its upload to the server. The clean-up mechanism runs hourly. |
| m4a audio file on the device | May be kept on the device depending on the user’s device and application use. May be deleted from the device by the user. Not included in the cloud backup. |
| Note text and transcript | Kept according to the user’s local storage and end-to-end encrypted cloud backup preferences. Placed in the deletion process when deleted by the user or when the retention purpose ends. |
| Meeting summary, decisions, tasks and e-mail drafts | Kept according to the user’s storage preference on the device or in the selected end-to-end encrypted backup. Placed in the deletion process when deleted by the user or when the retention purpose ends. |
| Error and crash records | Kept for a maximum of 90 days and deleted by an automatic deletion mechanism. |
| Support and feedback records together with attached screenshots | Kept for a maximum of 90 days and deleted by an automatic deletion mechanism. |
| On-device diagnostic logs | Kept on the device within a limit of approximately 1.5 MB. When the limit is reached, the oldest records are deleted. The logs are deleted from the device when the application is removed. |
| Subscription and transaction records | Kept for the periods required under the Apple App Store, Google Play, RevenueCat and the relevant accounting, consumer or legal obligations. |
| E-mail sending records | Kept for a period limited to what is necessary for carrying out the sending operation, security, support and legal requirements. |
| Account and contact data | Kept while the account is active and, after account closure or deletion, for a period limited to what is necessary for the applicable legal obligations and the management of disputes. |
For temporary audio files on the server, 24 hours is an absolute upper limit. The hourly clean-up mechanism is applied in order to prevent this period from being exceeded.
Audio files, m4a recordings and raw audio files processed temporarily on the server for transcription purposes are not included in the end-to-end encrypted cloud backup. Only the note texts, transcripts and other appropriate text content selected by the user may be stored within the cloud backup.
Where the retention period expires or the processing purpose ceases to exist, personal data are deleted, destroyed or anonymised. Where there is a statutory retention obligation or an ongoing dispute, the relevant data may be kept only for the necessary period and with restricted access.
15. Diagnostic Logs Kept on the Device
YazBunu may keep limited diagnostic logs on the device so that recording and connection errors can be examined technically.
diag.log may be used for the application recording pipeline and carplay.log for vehicle connection and CarPlay processes.
These logs:
- do not leave the device by themselves,
- are not uploaded to the server,
- are not included in the cloud backup,
- are not sent automatically in the background,
- are not transmitted to Peracom without a separate act of sharing by the user.
When the user wishes to share a log, masking is applied on the device; the masked version prepared for sharing is protected by technical tests so as not to contain:
- note text,
- transcript,
- meeting summary,
- participant name,
- audio file path,
- user identifier.
The total size of the diagnostic logs is limited to approximately 1.5 MB (up to 512 KB per log file). When this limit is reached, the oldest log records are deleted automatically. If the application is removed from the device, the logs are also deleted from the device.
If the user wishes to share a diagnostic log for technical support purposes:
- the log is masked on the device,
- the masked content is displayed on screen in full before sharing,
- separate approval is obtained from the user for each act of sharing,
- the user chooses the application through which the masked log will be sent.
No “do not ask again” option is offered for sharing diagnostic logs. Approval is obtained again for each act of sharing. If the user does not give approval, the log does not leave the device.
16. Processing Relating to Children
YazBunu is not a service designed specifically for children. Where children’s personal data are processed, additional safeguards may be required within the framework of the applicable legislation and application store rules. Where it is understood that a child’s data are being processed, the necessary technical and administrative measures may be applied.
Age thresholds that vary by country are taken into account in the processing of children’s data; where the legislation of the relevant country provides for a higher age limit, that limit applies. Where necessary, the approval of a parent or legal representative is required for children’s personal data to be processed.
Where a situation requiring age verification or representative approval is identified within YazBunu, access to the relevant features may be technically restricted or blocked entirely. The principles of data minimisation, purpose limitation and short retention periods are applied strictly to children’s data.
17. Security Measures
Peracom Yazılım Danışmanlık A.Ş. applies appropriate technical and administrative measures to prevent personal data from being unlawfully processed, accessed, disclosed, altered or lost.
Depending on the nature of the service and the technical infrastructure, these measures may include:
- encryption,
- end-to-end encryption,
- authorisation,
- access control,
- the principle of least privilege,
- authentication,
- security logs,
- error and access monitoring,
- software and infrastructure security testing,
- backup security,
- provider and sub-processor assessments,
- confidentiality and data security obligations,
- restriction of access,
- automatic deletion and data destruction mechanisms.
When cloud backup is enabled, the selected note and transcript content may be encrypted end to end on the device. The decryption key is protected by the user. In an end-to-end encryption structure designed so that Peracom Yazılım Danışmanlık A.Ş. cannot access that key, the company may be technically unable to read the encrypted content.
Audio files kept temporarily on the server are retained only for the period necessary for transcription and are deleted within 24 hours at the latest.
On-device diagnostic logs are not sent to the server by themselves. Where they are shared by the user, a masking and separate approval flow applies.
No electronic system offers an absolute guarantee of security. Users must protect their devices, account details, passwords, recovery information and end-to-end encryption passwords.
18. Your Rights under the KVKK
Under Article 11 of the KVKK you have the right to:
- learn whether your personal data are processed,
- request information if your personal data have been processed,
- learn the purpose of processing of your personal data and whether they are used in accordance with that purpose,
- know the third parties in Türkiye or abroad to whom your personal data are transferred,
- request the correction of your personal data if they have been processed incompletely or incorrectly,
- request the erasure or destruction of your personal data within the conditions set out in the KVKK,
- request that correction, erasure or destruction operations be notified to third parties to whom your personal data have been transferred,
- object to an outcome adverse to you arising from analysis of processed data exclusively by automated systems,
- claim compensation where you suffer damage due to unlawful processing of your personal data.
In addition to these rights, through the relevant functions within the application you may:
- delete your account,
- delete your local content,
- turn off cloud backup and synchronisation,
- change your separate consent preferences,
- withdraw your explicit consent,
- refuse support or technical log sharing.
Deleting the account from within the application starts the deletion process for the relevant account and user content. However, subscription and transaction records held by the Apple App Store, Google Play or RevenueCat and records that must be retained by law may be kept separately for as long as the relevant legal or financial obligations continue.
19. The User’s Responsibilities in Meeting and Sharing Processes
When using YazBunu services, the user is obliged to:
- inform meeting or interview participants about the recording,
- obtain permission or explicit consent from the relevant persons where necessary,
- explain the scope and purpose of the meeting recording to participants,
- review the content before sharing a meeting summary, transcript, decisions or task list,
- delete or mask unnecessary personal data,
- avoid including special categories of personal data in a recording as far as possible,
- send meeting content only to the necessary recipients,
- check recipient addresses and content before sending an e-mail,
- ensure device and account security,
- protect the encryption password and recovery information,
- not use the application for unlawful purposes,
- not infringe the personality rights, private life, confidentiality of communications or personal data of third parties.
YazBunu does not undertake to verify automatically, completely and conclusively the lawfulness of the meeting content recorded by the user. Depending on the circumstances, the user may be responsible for the lawfulness of the recording and sharing decision, for informing meeting participants and for obtaining the necessary permissions.
20. Application Procedure
To exercise your rights under the KVKK you may submit your applications through the following channels:
- E-mail: destek@peracom.net
- The application or support form provided within the application for this purpose,
- An application made from the e-mail address registered in our system,
- Other application methods suitable for identity verification.
Your application must:
- be clear and comprehensible,
- state which right you wish to exercise,
- include information enabling verification of your identity,
- provide as much explanatory information as possible about your request.
Applications are assessed within the procedures and time limits set out in the KVKK and the relevant secondary legislation. Additional information may be requested where deemed necessary for identity verification or security.
21. Relationship with Explicit Consent
This Information Notice is separate from the explicit consent text and from the in-app consent screens.
The Information Notice explains for which purposes, with which categories of data, on which legal grounds and to which recipient groups your personal data may be processed and transferred.
Consent is obtained separately and independently for processing activities that require explicit consent. Separate consent options may be offered within the application in respect of recording and transcription via Meeting Mode, CarPlay and Apple Watch, text structuring with artificial intelligence, optional end-to-end encrypted cloud backup, certain services requiring cross-border transfers, personalisation and similar activities.
Giving consent for one feature does not mean that consent has been given for other features. If you do not give explicit consent, only the feature relying on that consent is disabled or the relevant processing activity is not carried out. Basic services that do not require explicit consent continue as a rule where the applicable legal ground exists.
You may withdraw your explicit consent at any time through in-app settings, the relevant permission screens or by applying to the data controller. Withdrawal affects future processing activities; it does not retroactively invalidate processing lawfully carried out before the date of withdrawal.
22. Effective Date and Updates
This Information Notice may be updated in the event of changes to the technical infrastructure, the service providers used, the purposes of data processing, the application’s features or the applicable legislation.
The updated text is published within the application or through the official communication channels relating to the application. Depending on the nature of the change, users may be notified separately and, where necessary, a further information notice or a new explicit consent process may be carried out.
Effective Date: 9 September 2026
Last Updated: 9 September 2026
Data Controller: Peracom Yazılım Danışmanlık A.Ş.
Address: Gülbahar Mahallesi, Avni Dilligil Sokak, Çelik İş Blokları A Blok, No: 11 Floor: 4 Office: 417, Şişli / İstanbul, Türkiye
E-mail: destek@peracom.net
Telephone: +90 212 243 10 80