Skip to content
Legal

KVKK Information Notice

Last updated: 9 August 2026

This is a courtesy translation of the Turkish original (“YazBunu Aydınlatma Metni”). In case of any discrepancy, the Turkish text prevails.

1. Identity of the Data Controller

This Information Notice has been prepared by Peracom Yazılım Danışmanlık A.Ş., which operates the YazBunu mobile application on iPhone and Android phones and the Apple Watch and CarPlay extensions connected to iPhone, in accordance with the Turkish Personal Data Protection Law no. 6698 (“KVKK”).

Peracom Yazılım Danışmanlık A.Ş. may be contacted in its capacity as data controller at destek@peracom.net.

YazBunu is currently a mobile application distributed in Türkiye only. The service runs on iPhone and Android phones; on iPhone it additionally offers extra recording channels through the Apple Watch and CarPlay extensions. A desktop or web application is not within the current scope of this Information Notice. The way audio is processed differs depending on the platform used.

YazBunu is a digital note-taking and transcription service that allows the user to create voice content on iPhone, Android phones, Apple Watch or CarPlay, convert audio content into text for certain types of recording, edit notes, generate summaries, decisions, tasks and follow-up items from transcripts and text content, prepare e-mail drafts, optionally back up selected text content in end-to-end encrypted form, and manage notes within the application.

This Information Notice covers YazBunu’s individual usage scenarios, daily and work notes, Meeting Mode, recordings made via CarPlay and Apple Watch, text structuring features, optional cloud backup and synchronisation services, e-mail sending flows, technical support processes and the service providers used to operate the application technically.

Where a recording is made through Meeting Mode, CarPlay or Apple Watch, not only the user’s own voice and content but also the voices, speech content, names, contact details, roles, opinions and decisions of other persons participating in the meeting, interview or recording, and other personal data appearing in the transcript, summary, decisions, tasks or follow-up e-mail drafts generated as a result of the meeting, may be processed.

The user who starts the meeting or recording is responsible for fulfilling their own legal obligations to the extent that they may be regarded as a data controller or independent data controller in respect of creating the meeting content, notifying participants, sharing the content and their own purpose of use. This Information Notice explains the data processing activities carried out by Peracom Yazılım Danışmanlık A.Ş. within the scope of the YazBunu service and does not remove any independent obligations the user may have in respect of data belonging to other persons.

2. Categories of Personal Data Processed

The following categories of personal data may be processed while using YazBunu, only to the extent required by the features you use:

YazBunu does not create, collect, store as separate data, or use for such purposes any voiceprint, biometric voice profile or biometric voice template.

When the user wishes to share a diagnostic log, masking is applied on the device; the masked version prepared for sharing does not contain note text, transcripts, participant names, audio file paths or the user identifier. The raw log remaining on the device is kept solely for local fault diagnosis and does not leave the device unless the user shares it. These logs contain limited technical information used to understand the technical state of the application’s recording and connection pipeline.

On-device diagnostic logs do not leave the device by themselves; they are not uploaded to the server, are not included in the cloud backup and are not sent automatically in the background. If the user wishes to share these logs, masking is carried out on the device, the masked content is displayed in full before sharing, and separate approval is obtained for each act of sharing.

As a rule, only data required by the feature you use and connected to the purpose are processed. Data processing activities that do not require explicit consent for the operation of the application’s basic service may rely on other applicable legal grounds.

3. Methods by which Personal Data are Obtained

Your personal data may be obtained through:

Your personal data may be obtained directly from you, from technical records generated automatically by your device, or from the service providers you use and authorise.

Where Meeting Mode, CarPlay or Apple Watch is used, data belonging to other meeting participants may not be obtained directly from those persons; such data may be obtained indirectly within the audio recording, transcription process, notes, summaries or e-mail content.

4. Purposes of Processing Personal Data

Your personal data may be processed for the following purposes:

Where data need to be processed for a new purpose, the necessary information will be provided in respect of that purpose. Where explicit consent is also required due to the nature of the processing, explicit consent is obtained separately and independently of this Information Notice.

Depending on the nature of the processing activity, your personal data may be processed on one or more of the following legal grounds:

In this context:

Explicit consent is a legal act distinct from the Information Notice. Providing an information notice does not by itself mean that explicit consent has been obtained. Likewise, obtaining explicit consent does not remove the data controller’s obligation to provide an information notice.

If you do not give explicit consent, only the features that rely on explicit consent cannot be used or the relevant processing activity is not carried out. The provision of basic services that do not require explicit consent continues as a rule where the relevant legal ground exists.

The creation of a recording via Meeting Mode, CarPlay or Apple Watch, its transmission for transcription, the processing of text with artificial intelligence and the sharing of meeting outputs are processing activities that must be assessed separately. In respect of these activities, performance of a contract, legitimate interest, explicit consent or other appropriate legal grounds may apply depending on the circumstances.

Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation.

6. Special Categories of Personal Data

YazBunu is not designed to process special categories of personal data. Nevertheless, special categories of personal data may be present within the audio recorded by the user, the notes created, transcripts or meeting content.

In this context, health information, religious or philosophical beliefs, political opinions, trade union or association membership, information relating to sexual life, information relating to criminal convictions and security measures, or other data regulated as special categories under the legislation may appear within the content.

YazBunu does not aim to collect or classify special categories of personal data for an independent purpose. However, if the user records such data, includes it in a meeting recording or keeps it in the text content generated, that data may enter the relevant technical processing flow of the service.

The processing of special categories of personal data is subject to the conditions set out in the applicable legislation. Users must not record special categories of personal data unless necessary, must not include them in meeting content, and must review such data before sharing and, where possible, delete or mask it.

YazBunu does not make the processing of special categories of personal data an independent purpose of the basic service and does not retain such data for longer than necessary.

7. Meeting Mode, CarPlay and Apple Watch Recordings

Meeting Mode, CarPlay and Apple Watch are recording channels that allow the user to create an audio recording in a meeting, interview, training session, negotiation, workplace meeting, online meeting, in-vehicle conversation or similar multi-party conversation environment, and to convert the selected recording into text.

Where these channels are used, not only the user’s own voice but also the voices and speech of other persons participating in the recording may be processed. In addition, personal data, tasks, contact details or other information relating to persons who are mentioned in the meeting but do not participate in it may appear within the transcript, summary, task list or e-mail draft.

The principal data that may be processed within the scope of Meeting Mode, CarPlay and Apple Watch are:

7.1. How Audio is Processed

In YazBunu, audio processing is carried out through different paths depending on the platform used and the type of recording:

Type of recording Where and how the audio is processed What remains on the device
Daily or work note on iPhone (live recognition) Audio may be processed using Apple’s on-device or Apple speech recognition services. Apple’s own privacy rules and policies may also apply to this process. The m4a audio file remains on the device.
Meeting Mode, CarPlay and Apple Watch The audio file is uploaded temporarily to the YazBunu server for transcription purposes. The temporary audio file is held on Supabase Storage in the Frankfurt/European Union region and converted to text via AssemblyAI’s European region endpoint api.eu.assemblyai.com. It is deleted once processing is complete and in any event within 24 hours at the latest from its upload to the server. The m4a audio file may also remain on the device.
All recordings created on Android phones (daily, work note and meeting) Because on-device Turkish speech recognition is not available on Android devices, the audio file is uploaded temporarily to the YazBunu server for transcription purposes regardless of the type of recording, and is subject to the same rules as the meeting flow. The m4a audio file may also remain on the device.
Text structuring with artificial intelligence Only the transcript or the selected text content is sent in order to generate summaries, decisions, tasks, classifications or similar outputs. No audio file is sent at this stage. The m4a file and local text content on the device remain on the device according to the device and application settings.

The temporary audio file obtained from Meeting Mode, CarPlay, Apple Watch or Android recordings is not included in the end-to-end encrypted cloud backup. The cloud backup may contain only the note texts, transcripts and other appropriate text content selected by the user.

No voiceprint, biometric voice profile or biometric voice template is created, collected or stored in any of these processes.

7.2. Informing Participants

The user must inform participants about the recording before a meeting or multi-party conversation is recorded. The notice should explain that the meeting will be recorded, that the audio may be converted to text, that it may be transferred temporarily to the server, that a meeting summary or task list may be generated, and that the meeting outputs may be shared by the user.

The user who starts a meeting recording is not authorised to give explicit consent on behalf of other participants. The user must carry out the necessary information and permission processes separately, according to the nature of the meeting.

In particular, for workplace meetings, whether explicit consent has been given freely must be separately assessed because of the nature of the relationship between employer and employee. Recording a meeting covertly, failing to inform participants or using the recording outside its purpose may create legal risk.

8. Audio Recordings and the Transcription Process

In live recognition of daily or work notes on iPhone, audio may be processed using Apple’s on-device or Apple speech recognition services. In this type of recording the m4a audio file remains on the device.

In Meeting Mode, CarPlay and Apple Watch recordings, and in all recordings made on Android phones, the audio file may be uploaded temporarily to the YazBunu server for transcription purposes. This temporary audio file:

Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation.

No audio file is sent when structured outputs such as summaries, decisions, tasks or classifications are generated with artificial intelligence. Only the transcript or the text content selected by the user is processed at that stage.

The period for which m4a audio files remain on the device depends on the user’s device and application use. The user may delete these files from the device. For audio files temporarily uploaded to the server, an absolute upper limit of 24 hours applies.

9. Artificial Intelligence Supported Processing

YazBunu may process the transcript, note or text content selected by the user with artificial intelligence supported systems in order to summarise, structure, classify, title or tag it, or to turn it into task and decision outputs.

As a rule, the following are processed at this stage, rather than the audio file:

No audio file is sent at this stage. YazBunu does not create voiceprints or biometric voice templates.

Google Gemini may be used in the text structuring service. Depending on the technical structure of the service or the product configuration, alternative artificial intelligence service providers such as OpenAI or Anthropic may also be used. The data sent to the provider used is limited to the selected processing purpose.

The accuracy, completeness or full contextual suitability of outputs generated by artificial intelligence is not guaranteed. Summaries, decisions, tasks or e-mail drafts must be reviewed by the user before being shared, sent or used in an important transaction.

Artificial intelligence outputs do not in themselves constitute legal, financial, medical or professional advice. The user must not use an artificial intelligence output as the sole basis for decisions with significant consequences.

10. Optional Cloud Backup and Cross-Device Synchronisation

Where the user chooses separately to enable it, YazBunu may provide an end-to-end encrypted cloud backup and cross-device synchronisation service.

The following data may be processed in this context:

Only the appropriate text content selected by the user is included in the end-to-end encrypted cloud backup. Audio files, m4a recordings and raw audio files processed temporarily on the server for transcription purposes are not included in the cloud backup.

Supabase’s authentication, encrypted backup and storage services may be used for the cloud backup and synchronisation service. The temporary audio file storage infrastructure is located in the Frankfurt/European Union region.

Within the scope of end-to-end encryption, the decryption key is protected by the user. The user should be aware that if they lose the encryption password or the necessary recovery information, Peracom Yazılım Danışmanlık A.Ş. cannot view, store or regenerate that password, and that it may therefore be technically impossible to restore the encrypted backup.

The cloud backup feature is not a mandatory part of the application’s basic local note-taking function. Users who do not enable this feature may, as a rule, continue to benefit from the basic local note-taking functions provided that the other legal and technical conditions are met.

11. Optional Personalisation and Usage Analysis

Where the user separately opts in, YazBunu may process the following data in order to personalise the application experience and produce limited usage statistics:

Personalisation and usage analysis are not necessary for the provision of the basic local note-taking service. These activities are carried out according to a separate preference and permission flow offered within the application.

Within the scope of personalisation or usage analysis, audio files, voiceprints, full transcripts or user content are not used for advertising purposes. User content is not used to train artificial intelligence models outside the purpose of the service.

Subscription status and in-app purchase information may be managed through RevenueCat. The information transferred to RevenueCat is limited to what is necessary to determine subscription status and to operate the related in-app services.

12. Cross-Border Transfers

Within YazBunu’s technical infrastructure, certain personal data may be processed through service providers located abroad or operated by companies abroad.

The principal services that may give rise to cross-border transfers are:

The providers used and the purposes of the services are as follows:

Cross-border transfers are carried out in accordance with the cross-border transfer provisions of the KVKK and other applicable legislation, according to the nature of the transfer. Transfers are made in compliance with the principles of purpose limitation, data minimisation, proportionality and security.

The transfer of an audio file and the transfer of text content are different. In Meeting Mode, CarPlay and Apple Watch recordings, and in Android recordings, the audio file may be processed temporarily for transcription purposes only. At the artificial intelligence structuring stage no audio file is sent; only the transcript or the text selected by the user is processed.

13. Transfer of Personal Data

Your personal data may be transferred to the following recipient groups, only to the extent connected with and necessary for the relevant processing purpose:

The scope of a transfer is limited to the data required by the feature used. For example, using only the artificial intelligence text structuring feature does not result in the audio file being sent to AssemblyAI. The temporary upload of audio to the server and its transfer to the transcription service is assessed separately in respect of the Meeting Mode, CarPlay or Apple Watch recording process, or recording on an Android phone.

Where meeting results are shared by e-mail, the meeting summary, transcript, decisions, task list, e-mail draft and the personal data contained in that content may be transferred to the recipients determined by the user. The application does not automatically send this content to recipients unless the user expressly approves before sending.

Depending on the nature of the relevant processing activity, the service providers to which transfers are made may be regarded as data processors or as independent data controllers. Each provider’s own service terms and privacy arrangements may also apply.

14. Retention Periods

Your personal data are retained only for the period required by the purpose of processing. When determining the retention period, the data category, the purpose of processing, legal obligations, the risk of dispute, security requirements and the principle of data minimisation are taken into account.

Type of data or record Retention period and operation applied
Temporary audio file on the server Kept temporarily for transcription purposes. Deleted once processing is complete and in any event within a maximum of 24 hours from its upload to the server. The clean-up mechanism runs hourly.
m4a audio file on the device May be kept on the device depending on the user’s device and application use. May be deleted from the device by the user. Not included in the cloud backup.
Note text and transcript Kept according to the user’s local storage and end-to-end encrypted cloud backup preferences. Placed in the deletion process when deleted by the user or when the retention purpose ends.
Meeting summary, decisions, tasks and e-mail drafts Kept according to the user’s storage preference on the device or in the selected end-to-end encrypted backup. Placed in the deletion process when deleted by the user or when the retention purpose ends.
Error and crash records Kept for a maximum of 90 days and deleted by an automatic deletion mechanism.
Support and feedback records together with attached screenshots Kept for a maximum of 90 days and deleted by an automatic deletion mechanism.
On-device diagnostic logs Kept on the device within a limit of approximately 1.5 MB. When the limit is reached, the oldest records are deleted. The logs are deleted from the device when the application is removed.
Subscription and transaction records Kept for the periods required under the Apple App Store, Google Play, RevenueCat and the relevant accounting, consumer or legal obligations.
E-mail sending records Kept for a period limited to what is necessary for carrying out the sending operation, security, support and legal requirements.
Account and contact data Kept while the account is active and, after account closure or deletion, for a period limited to what is necessary for the applicable legal obligations and the management of disputes.

For temporary audio files on the server, 24 hours is an absolute upper limit. The hourly clean-up mechanism is applied in order to prevent this period from being exceeded.

Audio files, m4a recordings and raw audio files processed temporarily on the server for transcription purposes are not included in the end-to-end encrypted cloud backup. Only the note texts, transcripts and other appropriate text content selected by the user may be stored within the cloud backup.

Where the retention period expires or the processing purpose ceases to exist, personal data are deleted, destroyed or anonymised. Where there is a statutory retention obligation or an ongoing dispute, the relevant data may be kept only for the necessary period and with restricted access.

15. Diagnostic Logs Kept on the Device

YazBunu may keep limited diagnostic logs on the device so that recording and connection errors can be examined technically.

diag.log may be used for the application recording pipeline and carplay.log for vehicle connection and CarPlay processes.

These logs:

When the user wishes to share a log, masking is applied on the device; the masked version prepared for sharing is protected by technical tests so as not to contain:

The total size of the diagnostic logs is limited to approximately 1.5 MB (up to 512 KB per log file). When this limit is reached, the oldest log records are deleted automatically. If the application is removed from the device, the logs are also deleted from the device.

If the user wishes to share a diagnostic log for technical support purposes:

No “do not ask again” option is offered for sharing diagnostic logs. Approval is obtained again for each act of sharing. If the user does not give approval, the log does not leave the device.

16. Processing Relating to Children

YazBunu is not a service designed specifically for children. Where children’s personal data are processed, additional safeguards may be required within the framework of the applicable legislation and application store rules. Where it is understood that a child’s data are being processed, the necessary technical and administrative measures may be applied.

Age thresholds that vary by country are taken into account in the processing of children’s data; where the legislation of the relevant country provides for a higher age limit, that limit applies. Where necessary, the approval of a parent or legal representative is required for children’s personal data to be processed.

Where a situation requiring age verification or representative approval is identified within YazBunu, access to the relevant features may be technically restricted or blocked entirely. The principles of data minimisation, purpose limitation and short retention periods are applied strictly to children’s data.

17. Security Measures

Peracom Yazılım Danışmanlık A.Ş. applies appropriate technical and administrative measures to prevent personal data from being unlawfully processed, accessed, disclosed, altered or lost.

Depending on the nature of the service and the technical infrastructure, these measures may include:

When cloud backup is enabled, the selected note and transcript content may be encrypted end to end on the device. The decryption key is protected by the user. In an end-to-end encryption structure designed so that Peracom Yazılım Danışmanlık A.Ş. cannot access that key, the company may be technically unable to read the encrypted content.

Audio files kept temporarily on the server are retained only for the period necessary for transcription and are deleted within 24 hours at the latest.

On-device diagnostic logs are not sent to the server by themselves. Where they are shared by the user, a masking and separate approval flow applies.

No electronic system offers an absolute guarantee of security. Users must protect their devices, account details, passwords, recovery information and end-to-end encryption passwords.

18. Your Rights under the KVKK

Under Article 11 of the KVKK you have the right to:

In addition to these rights, through the relevant functions within the application you may:

Deleting the account from within the application starts the deletion process for the relevant account and user content. However, subscription and transaction records held by the Apple App Store, Google Play or RevenueCat and records that must be retained by law may be kept separately for as long as the relevant legal or financial obligations continue.

19. The User’s Responsibilities in Meeting and Sharing Processes

When using YazBunu services, the user is obliged to:

YazBunu does not undertake to verify automatically, completely and conclusively the lawfulness of the meeting content recorded by the user. Depending on the circumstances, the user may be responsible for the lawfulness of the recording and sharing decision, for informing meeting participants and for obtaining the necessary permissions.

20. Application Procedure

To exercise your rights under the KVKK you may submit your applications through the following channels:

Your application must:

Applications are assessed within the procedures and time limits set out in the KVKK and the relevant secondary legislation. Additional information may be requested where deemed necessary for identity verification or security.

This Information Notice is separate from the explicit consent text and from the in-app consent screens.

The Information Notice explains for which purposes, with which categories of data, on which legal grounds and to which recipient groups your personal data may be processed and transferred.

Consent is obtained separately and independently for processing activities that require explicit consent. Separate consent options may be offered within the application in respect of recording and transcription via Meeting Mode, CarPlay and Apple Watch, text structuring with artificial intelligence, optional end-to-end encrypted cloud backup, certain services requiring cross-border transfers, personalisation and similar activities.

Giving consent for one feature does not mean that consent has been given for other features. If you do not give explicit consent, only the feature relying on that consent is disabled or the relevant processing activity is not carried out. Basic services that do not require explicit consent continue as a rule where the applicable legal ground exists.

You may withdraw your explicit consent at any time through in-app settings, the relevant permission screens or by applying to the data controller. Withdrawal affects future processing activities; it does not retroactively invalidate processing lawfully carried out before the date of withdrawal.

22. Effective Date and Updates

This Information Notice may be updated in the event of changes to the technical infrastructure, the service providers used, the purposes of data processing, the application’s features or the applicable legislation.

The updated text is published within the application or through the official communication channels relating to the application. Depending on the nature of the change, users may be notified separately and, where necessary, a further information notice or a new explicit consent process may be carried out.

Effective Date: 9 September 2026

Last Updated: 9 September 2026

Data Controller: Peracom Yazılım Danışmanlık A.Ş.

Address: Gülbahar Mahallesi, Avni Dilligil Sokak, Çelik İş Blokları A Blok, No: 11 Floor: 4 Office: 417, Şişli / İstanbul, Türkiye

E-mail: destek@peracom.net

Telephone: +90 212 243 10 80