Privacy Notice (KVKK Information Notice)
Last updated: 27 September 2026
This notice explains how your personal data is processed when you use the Zeki Smart Accountant (“Zeki”) web app and the getzeki.xyz website. It is prepared under Article 10 of Turkey’s Personal Data Protection Law No. 6698 (“KVKK”) and the Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform. We do not ask for your explicit consent for the core service; we process your data on the legal grounds set out below.
Data controller
Data controller: Nefarius Apps Bilgi Teknolojileri Limited Şirketi (“Nefarius” or “we”).
Address: Fatih Sultan Mehmet Mah. Balkan Cad. Meydan İstanbul AVM No:62A 34771 Ümraniye/İstanbul. Email: [email protected].
Scope and our roles
This notice covers your account, the financial records you enter in Zeki, security logs and cookies. Nefarius is the data controller for this data.
For the contact records you enter about your own customers or suppliers, you are the data controller. Nefarius is only a data processor for this data, acting on your behalf and only to provide the service. You are responsible for informing these people and for having a valid legal basis to enter their data in Zeki.
Zeki is intended for adults and businesses and does not serve anyone under 18. If we learn that an account belongs to someone under 18, we will close it.
Personal data we process
When you use Zeki, we process the following data:
- Account data: email address, password, optional full name, locale, language (Turkish or English), default currency, role, account status, and sign-up and update times. Your password is stored hashed by the authentication service; we never see it.
- Financial records: wallets (name, personal or company kind, company type, currency, VAT and income-tax rates), bank accounts and credit cards (a name you choose, opening balance, credit limit), categories, tags, and income and expense entries (amount, VAT, date, optional name, note, installment details). We do not ask for or store account numbers or card numbers.
- Contact records: the name of your customers and suppliers, whether they are a person or a company and, optionally, their tax ID or Turkish ID number, email, phone and a note.
- Security (audit) logs: for sign-ins, sign-ups and the creation, update and deletion of the records above, who performed the action, the action type, the record concerned, the IP address and the time.
- Cookie and browser data: session cookies, a language cookie and your theme choice kept in your browser’s local storage (see “Cookies and local storage”).
How we collect data
We collect your data electronically, directly from you, through the sign-up and in-app forms in Zeki. IP addresses, action times and cookie data are generated automatically when you use the service.
We obtain contact records from the user who enters them in Zeki, not from the people concerned.
We calculate usage figures (for example sign-ups, active users and entries per day) from our own database; we do not use any analytics, advertising or tracking tools for this.
Purposes and legal bases
We process your data only for the purposes below and on the legal bases listed in KVKK Art. 5(2). We do not rely on your explicit consent for this processing.
- Creating your account, managing your session, showing your wallets, entries and estimates, applying your language and currency choices, and sending account emails (such as password reset): establishing and performing the contract (Art. 5(2)(c)).
- Keeping the service secure, detecting and preventing unauthorised access and misuse, answering support requests and calculating aggregate usage figures to improve the service: our legitimate interest, provided it does not harm your fundamental rights and freedoms (Art. 5(2)(f)).
- Meeting our obligations under the law and responding to lawful requests from competent public authorities: legal obligation (Art. 5(2)(ç)).
- Establishing, exercising or defending our rights in a possible dispute or legal claim (for example, keeping security logs as evidence): establishment, exercise or protection of a right (Art. 5(2)(e)).
- Storing and showing contact records on your behalf: the legal basis you rely on as the controller of that data applies; as processor, we act only on your instructions.
Who can access and receive data
Only authorised team members who need your data for their work can access it. Our support team can view your account, entries and security logs read-only for support and security; they cannot change your records. They can suspend an account if the Terms of Use are breached or there is a security risk.
To provide the service, we share data with the service providers below, who act on our behalf and on our instructions, and with authorities where required. We do not sell your data or share it with anyone for marketing.
- Hosting: our own servers in a data centre in the European Union, which run our database, API and apps.
- Cloudflare: network and security services. Our database administration traffic is also tunnelled through Cloudflare.
- Resend: sending account emails (such as password reset).
- Courts and competent public authorities: only where the law requires it and only to the extent requested.
Transfer abroad
Because our servers are in the European Union, your personal data is stored and processed outside Turkey. Cloudflare and Resend may also process data in other countries, such as the United States, where they or their sub-processors operate.
These transfers fall under KVKK Art. 9. The Personal Data Protection Board has not issued an adequacy decision for these countries. We therefore make these transfers on the legal bases in KVKK Art. 5(2) and by signing, with the relevant service providers, the standard contracts announced by the Board under Art. 9(4)(c). Standard contracts are notified to the Personal Data Protection Authority within five business days of signature.
For these transfers, we put in place the safeguards KVKK requires so that you can exercise your rights and seek effective legal remedies. To ask about these safeguards, write to [email protected].
Cookies and local storage
Zeki uses only cookies that are strictly necessary for the service to work. We use no analytics, advertising or tracking cookies and no third-party trackers.
These cookies are strictly necessary to provide the service you ask for and do not require explicit consent. You can delete them in your browser settings, but you will then be signed out and your language choice will be reset.
- Access cookie (httpOnly): authenticates your session and confirms that requests come from you.
- Refresh cookie (httpOnly): lets you renew your session without signing in again; valid for up to 30 days.
- NEXT_LOCALE: remembers the language you chose.
- Theme choice: not a cookie; kept in your browser’s local storage.
How long we keep data
We keep data only as long as needed for the purpose it was processed for. When that period ends, data is deleted, destroyed or anonymised in line with the Regulation on the Deletion, Destruction or Anonymisation of Personal Data. The main periods are:
- Account data, financial records and contact records: for as long as your account is open. When you ask us to delete your account, this data is deleted within 30 days of verifying your request. Any backup copies are removed in the normal backup cycle.
- Security logs: up to 2 years from creation. When your account is deleted, the link to your user is removed from these logs; the IP address, action and time are kept for security until the end of this period.
- Data the law requires us to keep longer, or data needed for a dispute: for the statutory period or until the dispute is resolved.
Data security
We take appropriate technical and organisational measures under KVKK Art. 12 to protect your data. These include storing passwords only in hashed form, keeping session cookies out of reach of browser scripts (httpOnly), limiting access to team members who need it for their work, read-only support access, monitoring actions through security logs, and running database administration traffic through a Cloudflare tunnel.
If your data is unlawfully obtained by others, we will notify you and the Personal Data Protection Board as soon as possible.
To keep your account safe, we recommend a strong password that you do not use anywhere else.
Your rights under KVKK
Under KVKK Art. 11, you can apply to us to exercise the following rights:
For contact records, the data controller is the user who entered them in Zeki. We pass requests from these people on to that user and help the user respond.
- To learn whether your personal data is processed.
- If it is, to request information about it.
- To learn the purpose of processing and whether data is used for that purpose.
- To know the third parties in Turkey or abroad to whom it is transferred.
- To ask for it to be corrected if it is incomplete or inaccurate.
- To ask for it to be deleted or destroyed under the conditions in KVKK Art. 7.
- To ask that corrections, deletions or destruction be notified to third parties to whom the data was transferred.
- To object to a result against you that arises solely from analysis of your data by automated systems.
- To claim compensation if you suffer damage because of unlawful processing.
How to apply and complain
To exercise your rights under the Communiqué on the Procedures and Principles of Application to the Data Controller, you can send your application in writing to Fatih Sultan Mehmet Mah. Balkan Cad. Meydan İstanbul AVM No:62A 34771 Ümraniye/İstanbul, or email [email protected] from the email address registered in your Zeki account.
Under the Communiqué, your application must include your full name, your signature if the application is in writing, your Turkish ID number (or, if you are a foreign national, your nationality and passport number or ID number if any), your address for notifications, your email address, phone and fax number if any, and the subject of your request.
We will conclude your application free of charge as soon as possible and within 30 days at the latest, depending on the nature of the request. If the action involves a separate cost, only the fee in the Board’s tariff may be charged.
If your application is rejected, you find our answer insufficient or we do not answer in time, you can complain to the Personal Data Protection Board within 30 days of learning of our answer, and in any case within 60 days of your application.
Users in the European Union (GDPR)
If you use Zeki from the European Union or the European Economic Area and the General Data Protection Regulation (GDPR) applies to the processing of your data, we process it under GDPR Art. 6(1) on the bases of performance of a contract (b), legal obligation (c) and legitimate interests (f).
In that case you have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and you can complain to the data protection authority in your country. You can send requests to [email protected].
Changes to this notice
We may update this notice to reflect changes in the service or the law. The current version is always on this page with its update date. We will announce significant changes by email or in-app notice before they take effect.
This notice is published in Turkish and English. If the two versions differ, the Turkish version prevails.