Last updated: August 21, 2026
This policy explains how Kodventure Teknoloji Anonim Şirketi ("TurniGym") processes personal data across its website, administration panel, and TurniGym Üye mobile application. Please also review the KVKK Privacy Notice for detailed legal information under Turkish data protection law.
Information processed
- name, email, telephone, password hash, role, and account preferences;
- business, branch, staff, member, plan, credit, collection, appointment, and QR check-in records;
- optional profile photo, blood group, body measurements, and health notes;
- IP address, device and notification token, session, error, audit, and security logs;
- order number, selected plan, amount, payment status, and billing information;
- support requests and communications.
TurniGym does not store card numbers, expiry dates, or CVV data on its servers. Card payments are processed on PayTR's secure payment interface.
Purposes
Data is used to create accounts and subscriptions, provide the service, manage transactions between businesses and members, administer payments and billing, provide support, protect security and tenant isolation, prevent misuse, comply with legal duties, and improve service quality. Marketing communications are sent only with valid permission; essential service messages are not marketing.
Data protection roles
TurniGym acts as data controller for its own account, security, subscription, payment, and support operations. Sports businesses may act as independent controllers for their member and staff data and for membership, appointment, and access operations; TurniGym may host and process such data on their instructions as a processor. The relevant sports business's own privacy notices also apply.
Sharing and transfers
Where necessary to provide the service, data may be shared with the relevant sports business, PayTR, hosting, email/SMS, notification, security and support providers, professional advisers, and legally authorized authorities. Personal data is not sold. Where an international transfer occurs, applicable KVKK transfer conditions and safeguards are used.
Retention and deletion
Account and operational data is retained during the service relationship and relevant claim/limitation periods; financial and commercial records for legally required periods, where applicable up to 10 years; and security logs for a period proportionate to risk and legal duties. Data is then deleted, destroyed, or anonymized.
A TurniGym Üye account can be deleted directly under Profile > Permanently delete account. Account, profile, and access data not subject to a legal retention duty is deleted; mandatory records are isolated and retained only for the applicable purpose and period.
Security and choices
We use risk-appropriate technical and organizational safeguards such as access controls, authorization, logging, encryption, and backups. Users should keep account information current and not share credentials. Privacy requests may be sent to info@turnigym.com or Tahtakale Mah. Ayçiçeği Sok. No:2/6 İç Kapı No: 2 Avcılar / İstanbul.