Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how "Kelan" ("Platform") collects, uses, and protects the personal information of its users.
1. Our Core Privacy Principles
- Data Minimization: We collect only the minimum data necessary to run the booking system: the name, surname, phone and email you enter on the booking form, plus information about the appointment itself (the slot you chose and how it turned out — see KVKK Notice §2).
- Zero Advertising / Tracking: The Platform contains no ad networks, analytics profiling tools, or third-party tracking scripts. Appointment conduct records are shown only to the provider you booked with; they are never used for advertising, sold, or shared with other providers.
- Local and Secure Storage: All user data and databases are stored on servers located in Turkey.
2. Data Controller
The person responsible for the security of your personal data is Öncüm Korkmaz Yılmaz, the developer of the Platform.
3. How We Process Your Data
- Service Provider flow: When a professional signs in via Google or Apple, their identity is verified and they are granted access to create their booking calendar.
- Service Recipient flow: When a client books an appointment, they enter their details. To prevent fraudulent or erroneous bookings, the system sends a one-time verification code (OTP) to their email address.
- Cancellation flow: A client can view and cancel their appointment through a link unique to that booking, sent to their email. If the provider's free cancellation window has passed, the cancellation still goes through and is recorded on the appointment as a last-minute cancellation, which the provider can see.
- Notification flow: Automated emails are sent to both parties upon booking confirmation, rejection, and as a reminder 24 hours before the appointment. All of these are performed in the context of contract performance.
4. Technical Security and Logging
Our servers perform automatic logging for cybersecurity purposes. These records include IP addresses and request timestamps.
In the event of a data breach, the developer is legally required to notify Turkey's Personal Data Protection Authority and affected users within 72 hours.
5. Data Deletion and Your Right to Erasure
Service Providers can permanently close their account at any time by tapping "Delete Account" in the app's Settings. Once triggered, all user and appointment data — except backup cycles and legally mandated logs — will be permanently and irreversibly deleted or anonymized from our servers within 30 days.
Appointment conduct records (cancelled / cancelled last-minute / did not attend) are not stored separately; they are part of the appointment record and are deleted with it. Providers are shown only the last 12 months of that history.
6. Age Restriction
The Platform is intended for adult professionals and clients who are of legal age to manage their own appointments. Individuals under 18 should not book directly; a parent or guardian should assist where required.
7. Policy Changes
This privacy policy may be updated periodically to reflect changes in law or new platform features. Significant updates will be communicated to users through the platform's interfaces.