User Privacy Notice
Privacy Notice Regarding Users' Membership, Service Procurement and/or Corporate Information, Promotion and Commercial Communication Processes
1 Data Controller
Your personal data and the personal data of persons for whom you are the parent/guardian/legal representative are processed by the data controller FitxDiet – Online Fitness Services Platform and Web/Mobile Applications ("Company" or "FitxDiet") within the scope of the Personal Data Protection Law No. 6698 ("KVKK") and within the framework of this Privacy Notice.
Scope of This Privacy Notice
Provided by FitxDiet:
- Online fitness service
- Fitness programs
- Creating membership via mobile and web applications
- Service application, purchase and after-sales support processes
- Corporate information, promotion and commercial communication activities
explains for what purposes and how the personal data collected within this scope is processed.
2 Legal Status of the Data Controller
This Privacy Notice covers only the personal data processing activities carried out by FitxDiet in its capacity as data controller.
3 Categories of Personal Data Processed and the Purposes and Legal Grounds for Processing Personal Data
3.1. Regarding Users
The categories of personal data processed within the framework of your membership relationship with our Company, along with the purposes and legal grounds for processing this data, are explained below.
A Explicitly Stipulated in Laws (KVKK 5/2-a)
- Fulfillment of legal obligations (issuing invoices, retention, keeping financial records)
- Reporting commercial electronic message approvals to the Message Management System (İYS)
- Making tax-related and official notifications
- Retention and archiving processes
B Establishment and Performance of the Contract (KVKK 5/2-c)
- Establishment and execution of the Membership and Service Agreement
- Creation, verification, management, and termination of the membership account
- Billing, payment, and accounting processes
- Online expert counseling service provision
- Service process notifications
- Matching of users with the most suitable expert being carried out
- Operation and supervision of services
- Information security processes
- Retention and archiving processes
C Legal Obligation (KVKK 5/2-ç)
- Making notifications to authorized institutions and organizations
- Conducting legal dispute processes
- Retention and archiving activities
D Legitimate Interest (KVKK 5/2-f)
- Management of user requests and complaints
- Improvement of product/service processes
- Quality control and reporting processes
- Member satisfaction management
- Internal audit processes
- Ethics and abuse investigation processes
- Compliance with company policies
- Retention and archiving processes
- Data security processes
E Processes Requiring Explicit Consent (KVKK 5/1)
- Campaign, advertising, promotion, and promotional messages
- Profile-based targeting, segmentation, and analysis activities
- Surveys and satisfaction measurements
- Digital marketing and social media activities
- Sending commercial electronic messages
- Matching users with a suitable expert
- Creating a profile and preparing a personalized nutrition guide
- Quality management and service improvement
- Internal audit and reporting processes
- Retention and archiving activities
F2 Community (Social Interaction) Data
(username/@username, display name, biography, profile photo, username change history)
User Content(posts, comments, uploaded photos — including before/after images, surveys and votes)
Social Interaction(likes/votes, following and follower relationships, saved posts, reputation score, badges, leaderboard ranking)
Moderation & Notification(block records, complaint/report records, notification preferences, device token for push notifications)
- Provision of the community service — displaying posts, comments, and interactions
- Creating the follow feed, notifications, and leaderboard
- Sending push notifications — follows, comments, likes, mentions, etc.
- Content moderation, enforcement of community rules, complaint and block management
- Prevention of abuse, spam, and fraud; service security
- Service improvement and statistics (aggregated/anonymized)
- Visibility: Your profile and posts are public; the anonymous post option hides your identity from other users.
- Retention: Content is retained until you delete it or your account is deleted.
- Deletion: When you delete a post/comment, the content is removed. In the event of an account deletion request, your community content is permanently deleted or removed by being stripped of your identity (anonymized).
- Exception: Records that must be kept due to moderation and legal obligations (e.g., complaint/violation records) may be retained for the relevant period.
G Live Lesson (Audio/Video Call) Data
During the call, the parties' audio and video stream (not recorded, not stored on servers, flows end-to-end between the parties);
Mandatory for establishing the connection: session ID, user ID (UID), IP address, browser/device information, call start/end time and duration.
- Performance of the live lesson service (audio/video transmission)
- Verification of the parties authorized for the call
- Keeping call participation records (audit log); detection of abuse and rights violations
- Charging for the service and keeping records of session usage
- Technical troubleshooting and improving service quality
- Providing evidence in legal disputes
- Audio/video stream: No recording is made; it only flows over the network during real-time transmission.
- Session metadata (audit log): 10 years after the call is completed (for evidence and audit purposes within the framework of the retention obligations under the Turkish Commercial Code (TTK) and Tax Procedure Law (VUK)).
- IP / device information: For a reasonable period as required by KVKK No. 6698 and Law No. 5651.
Audio/video transmission Agora.io (Agora Lab, Inc.) is carried out end-to-end encrypted over the infrastructure. Agora is FitxDiet's data processor and does not record, store, or share the call content with third parties; only metadata mandatory for transmission is processed. The transfer falls within the scope of transfer abroad; it is carried out in accordance with the provisions of KVKK 9/6 and with the User's explicit consent.
4 Transfer of Your Personal Data to Third Parties Located Domestically and Abroad
Your personal data processed within the scope of each personal data category specified above may be transferred to the following recipient groups in accordance with Articles 8 and 9 of the KVKK, provided that the legal grounds specified for the relevant data category exist:
a) Suppliers and Service Providers
Information technology service providers, data hosting and cloud service providers, legal advisors, audit and consultancy firms, website and mobile application providers, intermediary service providers
Domestic and/or abroadb) Banks
For the purpose of carrying out payment, refund, change, and financial transactions
Domesticc) Business Partners
For the purpose of establishing and maintaining collaborative relationships in service provision
Domestice) Shareholders and Group Companies
For the purpose of managing corporate activities and carrying out reporting, audit, and communication processes
Domesticf) Authorized Public Institutions and Organizations
Institutions such as courts, prosecutors' offices, regulatory-supervisory authorities, the Ministry of Finance, and İYS
Domesticg) Real-Time Communication Infrastructure Provider (Agora.io)
For audio and video communication in the live lesson service, the Agora Lab, Inc. (Agora.io) infrastructure is used. Data is processed only for real-time transmission; content is not recorded or stored. Transfer abroad takes place with the User's explicit consent and in accordance with KVKK 9. Agora's privacy policy: agora.io/en/privacy-policy
Abroad5 Your Rights Under the KVKK
As a personal data owner, you have the following rights under Article 11 of the KVKK:
Application Channels
Merkez Mahallesi Hasat Sk. No:52, 34381 Şişli/İstanbul
info@mdatechnologies.net
Applications will be evaluated in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.
Documents verifying identity in applications must not contain special categories of personal data (e.g., religion, blood type, etc.).