Back to Login
Legal Document

Privacy and Data Protection Policy

At MyPedigre we take the privacy of your personal data seriously. This policy explains what data we collect, how we use it, and your rights.

Last updated: April 1, 2025
English
~5 min read

1. Personal Data We Collect

When you use the MyPedigre platform, we may collect the following categories of personal data:

Data Type Examples Requirement
Identity Information First name, last name, username Required
Contact Information Email address, phone number Required
Account Information Password (encrypted), preferences, language selection Required
Pigeon Records Pigeon details, pedigree records, photos Optional
Technical Data IP address, browser type, session information Automatic
Payment Information Subscription plan (card details are not stored) Optional

Your credit or debit card details are never stored on our servers. Payments are handled through PCI-DSS compliant third-party payment providers.

2. Purposes of Data Use

We use the data we collect for the following lawful purposes:

  • To create, verify and manage your account
  • To deliver and improve MyPedigre services
  • To create and store your pedigree records
  • To manage subscriptions and payments
  • To provide technical support and customer service
  • To ensure platform security and prevent fraud
  • To comply with our legal obligations
  • To send service updates and announcements where you have opted in

We never sell or rent your data to third parties for advertising. Our data processing is performed under Turkish KVKK (Law No. 6698) and the GDPR.

3. Data Security

We apply industry-standard technical and organisational safeguards to keep your data secure:

  • SSL/TLS Encryption: All data transmission is encrypted over HTTPS
  • Bcrypt Password Hashing: Passwords are stored using a one-way hash algorithm
  • Firewall: Our servers are protected by a multi-layered firewall
  • Regular Backups: Your data is backed up on a regular schedule
  • Session Security: Brute-force protection and session locking mechanisms are active
  • Access Control: Only authorised personnel can access your data

If a security breach is suspected, we will notify the Personal Data Protection Authority within 72 hours as required by law (KVKK art. 12) and inform you without undue delay.

4. Cookies and Tracking

Our platform uses various cookies to improve your experience:

  • Essential Cookies: Required for session management and security. Cannot be disabled.
  • Functional Cookies: Used to remember your preferences (language, theme).
  • Analytics Cookies: Help us understand platform performance and usage statistics. (Requires consent)

You can manage cookies from your browser settings and disable optional cookies. Disabling essential cookies may prevent the platform from working properly.

5. Data Sharing with Third Parties

In the following limited cases we may share your data with third parties:

  • Service Providers: Business partners providing services such as email delivery, hosting and payment processing (acting as data processors under KVKK)
  • Legal Obligations: Pursuant to a court order or a request from a competent authority
  • Business Transfers: In the event of a merger or acquisition, data may be transferred under this policy

All third-party service providers are selected on condition that they are KVKK- and/or GDPR-compliant, and data processing agreements are signed.

6. Your Rights Under Data Protection Law

Under Turkey's Personal Data Protection Law No. 6698 (KVKK) and the GDPR, you have the following rights:

  • Right to Information: To learn whether your personal data is being processed
  • Right of Access: To request access to data being processed
  • Right to Rectification: To request correction of inaccurate or incomplete data
  • Right to Erasure: To request deletion or destruction of your data
  • Right to Object: To object to decisions made against you by automated systems
  • Right to Data Portability: To receive your data in a structured format
  • Right to Restrict Processing: To request restriction of processing under certain conditions

To exercise your rights you may submit a written request to kvkk@mypedigre.com. Requests are answered within 30 days. If you are not satisfied with our response, you may file a complaint with the Turkish Personal Data Protection Authority (kvkk.gov.tr).

7. Data Retention Periods

We retain your personal data only for as long as necessary:

  • Account Data: For the lifetime of your account + 3 years
  • Transaction Records: Payment and subscription records kept for 10 years (legal requirement)
  • Session Logs: 90 days
  • Support Tickets: 2 years after closure
  • Marketing Consent: Until consent is withdrawn

Data whose retention period has expired is securely destroyed or anonymised.

8. Policy Changes

We may update this privacy policy from time to time. When material changes are made:

  • We publish a visible notice on the platform
  • We send a notification to your registered email address
  • We update the "Last updated" date at the top of the page

Continuing to use the platform after changes means you accept the updated policy.

Any questions?

Contact us for any questions or requests regarding our privacy policy or your personal data.

kvkk@mypedigre.com

© 2026 MyPedigre — All rights reserved.  |  kvkk@mypedigre.com