Home / Legal / KVKK Information Notice

Information Notice under the Personal Data Protection Law (KVKK)

Last updated: 9 October 2026

Note: This is an unofficial English translation provided for your convenience. The Turkish version is the legally binding text; in case of any discrepancy, the Turkish text prevails.

As YCT Sağlık Hizmetleri Ltd. Şti. ("Company"), acting as the data controller, we would like to inform you as follows about the processing of your personal data, within the scope of KVKK (Turkey's Personal Data Protection Law No. 6698) and other applicable legislation.

1. Data Controller

The company information holding the capacity of data controller is as follows:

Field Information
Company YCT Sağlık Hizmetleri Ltd. Şti.
Address Alacaatlı Mah. Park Cad. No: 15/15, Çankaya / Ankara
Tax ID (VKN) 9460568946
Registration (MERSİS) 0946056894600001
Email [email protected]
Phone +90 546 233 77 87

2. Personal Data Processed and Their Categories

The following personal data of yours is processed within the scope of your use of LA Fish services:

Data Category Data Processed
Identity Data First and last name
Contact Data Email address
Sign in with Apple / Google Data (only if this sign-in method is used) First and last name provided by the provider (Apple Inc. or Google LLC) (with Apple, only on the first sign-in and only if the user shares it), email address (with Apple, a private relay address created by Apple if the user chooses to hide their email) and the user identifier at the provider. The purpose is to create the account and enable sign-in; when the account is deleted, this data is deleted as well and the link with Apple is also removed on Apple's side.
Financial Data Billing information (for subscription invoicing: first and last name, address, tax ID number, or — for individual e-invoicing — national ID number (TCKN) used as tax ID); the payment token generated by the payment institution and the card's last 4 digits (the full card number and CVC are not stored)
Transaction Security Session information, IP address, device type, browser information; application error/crash logs and diagnostic logs (for stability and security purposes)
Customer Transaction Data Subscription type, payment history, usage statistics (number of receipts, features used)
Optional Usage Statistics (mobile app only, if permitted) Feature-usage events chosen from a fixed list (e.g. a receipt was added and how it was added: manually or by scanning) and the platform (iOS or Android). No account, email, device or advertising ID, time, app version, device model or record content is sent; the server does not store individual events, keeps only daily totals, and does not write the IP address to these counts.
Receipt/Document Data (Cloud Archive) Receipt fields archived only with explicit consent (merchant name, date, time, receipt number, amount/tax base/VAT, payment type, category), the tax ID number or national ID number (if any), stored encrypted, and, optionally, an encrypted image of the receipt
Home/Vehicle Memory Data (Home Memory — all plans, including Free) Home/vehicle and item information entered by the user themselves: home address and vehicle information (license plate, make/model, chassis/serial number) — stored encrypted; item records (brand, model, serial number, purchase and warranty/maintenance dates); uploaded documents such as warranty certificates and insurance/casco policies (encrypted); the payment source used for the expense (bank name and the card's LAST 4 digits — the full card number is NEVER stored) and installment plan information; when "Add From Card Statement" is used, the transaction lines read from the card statement (date, description, amount), the bank name, the card's last 4 digits and the statement closing and payment due days (the full card number is not stored). This data is visible only to the relevant user; its purpose is to remind the user of important dates such as warranty/maintenance/inspection/emission-test and policy dates, and, at the user's request, to generate a transferable summary for selling or renting a home/vehicle.
Advertising Data (Free tier only) The device's advertising identifier (on iOS only if tracking permission is granted), IP address, device and app information, ad view/tap information. This data is collected by the advertising provider Google AdMob; receipt/document contents, name, email, and payment information are not shared with the advertising provider.
Marketing Communication preferences (only with explicit consent)

Special note on receipt images: Processing and storage of receipt/invoice images takes place in three different ways depending on the feature you choose:

  • Standard on-device processing: The receipt/invoice image is processed only on the user's device and is not transmitted to the server.
  • "AI reading" (all plans; temporary server-side processing): With explicit consent, the image is transmitted to the server solely for reading purposes; as soon as processing is complete it is permanently deleted and is not retained in any database.
  • Cloud Archive with explicit consent (permanent storage): Only if you give explicit consent, the receipt fields that have been read are permanently stored on our servers in Turkey. Archiving the receipt image is optional; stored images and the tax ID/national ID number are kept encrypted. This storage is based on an explicit consent that is separate and independent from the consent given for cross-border processing under "AI reading." You may withdraw your consent at any time; once withdrawn, your new receipts will not be archived.

Accounting software credentials: LA Fish does not store on its servers the account credentials (username, password, etc.) used when sending data to accounting software. This information is used only for instantaneous transmission.

Method of Collecting Personal Data

Your personal data is collected electronically through our website and our desktop and mobile applications, partly directly through your own declarations (registration, subscription purchase, contact/support forms), through the relevant provider when you use Sign in with Apple or Sign in with Google, and partly through automatic means while you use the service (logging in, security logs, error/crash logs; if permitted, the mobile app's usage statistics; on the Free tier, the advertising provider's in-app software). The legal grounds underlying the processing of this data are set out in Section 4 below.

3. Purposes of Processing Personal Data

  • Establishing and performing the service agreement (membership, subscription management, technical support),
  • Carrying out payment and invoicing transactions,
  • Fulfilling legal obligations (tax legislation, commercial law, consumer protection legislation),
  • Providing information to authorized public institutions and organizations,
  • Ensuring application security and integrity,
  • Improving services and developing new features (aggregate statistics; the mobile app's usage statistics only if permitted),
  • Detecting and fixing errors (error/crash reports),
  • On the Free tier: showing ads, measuring ad delivery, and preventing fraudulent traffic,
  • Where explicit consent is given: permanent storage of receipts in the cloud archive, multi-device access, search, and export,
  • Where explicit consent is given: sending commercial electronic messages (campaigns, announcements, informational notices).

4. Legal Grounds for Processing Personal Data

Processing Purpose Legal Ground (KVKK Art. 5)
Membership and subscription management Establishment or performance of a contract (Art. 5/2-c)
Invoicing and payment Performance of a contract + legal obligation (Art. 5/2-a, c)
Statutory retention obligations Legal obligation (Art. 5/2-a)
Security and abuse prevention Legitimate interest (Art. 5/2-f)
Showing and measuring ads on the Free tier Showing and measuring ads: legitimate interest (Art. 5/2-f). Personalised ads: explicit consent (Art. 5/1) — on iOS the app tracking permission, on Android the in-app permission, in the EEA/UK/Switzerland Google's consent form
Marketing messages Explicit consent (Art. 5/1)
Cloud receipt archive (permanent storage) Explicit consent (Art. 5/1)
Cross-border transfer (AI reading of receipts/invoices and card statements) Explicit consent or adequate protection / appropriate safeguards (Art. 9)

5. Parties to Whom Personal Data Is Transferred

5.1 Domestic Transfer

Your personal data may be transferred to authorized public institutions and organizations (tax offices, courts, law enforcement) as required by legal obligation. Within the scope of payment infrastructure services, data is shared with PCI-DSS compliant payment institutions; these institutions do not transmit full card number information to us.

5.2 Cross-Border Transfer

We work with a limited number of service providers (processors) to be able to provide the service; some of them are located abroad. The following transfers are carried out based on the data subject's explicit consent and/or the appropriate safeguards in the data processing agreements (DPA) concluded with the processors, in accordance with Article 9 of the KVKK:

Recipient / Service Data Transferred Purpose and Location
Google Cloud EMEA Limited (Vertex AI) Receipt/invoice image and card statement (PDF or image): the merchant, amount, date and tax number on them, if any; on a statement, the bank name, the card's last 4 digits and the transaction lines ("AI reading" only) Automatic reading, with AI (Gemini model), of the amount, date, VAT and merchant, and of the transaction lines on a statement; Ireland / EU (processing on servers in the EU). Inputs are not used for model training; images and files are not stored permanently by Google. Carried out only with explicit consent.
Brevo SAS First and last name, email address Transactional emails (verification, password reset, renewal notice) and, with consent, marketing emails; France / EU.
Cloudflare, Inc. IP address, connection and security metadata Content delivery network (CDN), bot/automation protection (Turnstile), and DDoS security; requests to our website and app server (including usage statistics and error reports) pass through this service; USA / global edge servers.
Sentry (Functional Software, Inc.) — only versions of the mobile app older than 1.1.2 Error/crash logs and diagnostic metadata Monitoring application stability and error diagnosis; EU (Frankfurt) region, 90 days. Version 1.1.2 and later of the mobile app and our server send error logs to the error-tracking system running on our own server in Istanbul.
Google (AdMob advertising service) Advertising identifier (on iOS only with tracking permission), IP address, device and app information, ad interactions — Free tier only Showing and measuring ads and preventing fraudulent traffic; Google's global servers (including the USA).
Google LLC (address suggestion service) The search text typed when searching for an address in My Space — name, email and IP address are not sent; only when searching for an address Finding address suggestions that match the typed text; Google's global servers (including the USA).

Transfer to Vertex AI (Google Cloud) takes place only when the "AI reading" feature (including adding from a card statement) is used and only with explicit consent obtained; after the transfer is complete, the image is not retained by us, and its content is not kept in any database. For a card statement, the file itself is not stored either; the transaction lines read from the statement are kept as an encrypted draft until the user saves them, and the draft is deleted once saved (see 6). Reading card statements requires accepting the current version of the explicit consent text that covers card statements; consent given earlier remains valid for receipt reading. Google does not store images or files permanently either, nor does it place them in a temporary cache; only where abuse is suspected may the relevant record be kept for up to 90 days in the same region (EU). Transfers to Brevo and Cloudflare, and the transfer to Sentry from versions of the mobile app older than 1.1.2, on the other hand, are necessary for the performance and security of the service and are carried out within the scope of the safeguards in the agreements concluded with the relevant processors. The AdMob transfer takes place only on the Free tier; on paid plans (Standard, Premium and Premium Office), during the trial, and after the "Remove Ads" purchase, the advertising service is not started in the app. You can manage your advertising identifier under Settings > Privacy & Security > Tracking on iOS and Settings > Google > Ads on Android; you can withdraw permission for personalised ads in the app under Account > Data & Storage > Ads. The address suggestion transfer takes place only when you search for an address in My Space. When you use Use My Location, your location is read once and converted to an address on your device; we do not store it and it is not sent to our servers. The mobile app's optional usage statistics are not sent to any service provider abroad; they are counted only on our server in Istanbul, and the request passes through the Cloudflare service above. You can turn this permission off at any time in the app under Account > Data & Storage > Usage Analytics; while it is off, no usage data is sent.

6. Retention and Destruction Period of Personal Data

Data Retention Period
Membership and account information Until account deletion request + 3 years (commercial litigation statute of limitations)
Payment and invoice records 10 years from the last transaction (Tax Procedure Law)
Receipt image (AI reading) Deleted immediately from our server once processing is complete; not stored permanently by Google (see 5.2)
Card statement file (PDF or image) Not stored; processed only for reading. Not stored permanently by Google (see 5.2)
Transaction lines read from a statement and not yet saved (draft) Encrypted, until the user saves them or deletes the draft; the draft is deleted once saved
Expenses saved from a statement Subject to the same rule as receipt data archived in the cloud receipt archive (on our servers in Türkiye) (next row)
Archived receipt data and image (explicit consent) Until consent is withdrawn, the user deletes the receipt, or the account is deleted; images are subject to the plan quota and the "auto-delete oldest image" preference
Session and security logs 2 years
Error/crash logs and diagnostic logs 60 days on our own server; those sent to Sentry from versions of the mobile app older than 1.1.2, 90 days
Optional usage statistics (mobile app) Individual events are not stored; daily raw counters are deleted at the end of the day. Daily aggregate tables, in which numbers smaller than five are never published, 24 months
Marketing communication preferences Until consent is withdrawn

Once the retention period has expired, personal data is securely deleted, destroyed, or anonymized within the framework of our destruction policy.

7. Rights of the Data Subject (KVKK Art. 11)

Under Article 11 of the KVKK, you have the following rights:

  1. To learn whether your personal data is being processed,
  2. To request information about it if it has been processed,
  3. To learn the purpose of processing and whether the data is used in accordance with that purpose,
  4. To learn the third parties to whom the data is transferred domestically or abroad,
  5. To request correction if the data has been processed incompletely or incorrectly,
  6. To request erasure or destruction of the data within the framework of the Law and applicable legislation,
  7. To request that correction/erasure be notified to third parties to whom the data has been transferred,
  8. To object to a result that is to your detriment arising from the exclusive analysis of processed data through automated systems,
  9. To request compensation for damages if you suffer harm due to unlawful processing.

8. Method of Application

You may submit your requests regarding the rights specified above, together with information verifying your identity, through one of the following methods, in accordance with the "Communiqué on the Procedures and Principles of Application to the Data Controller":

  • In writing (mail): by a wet-signed petition to Alacaatlı Mah. Park Cad. No: 15/15, Çankaya / Ankara,
  • Email: from your email address registered in our system to [email protected] with the subject line "KVKK Application",
  • By email, signed with a secure electronic signature or mobile signature.

Your application will be concluded within thirty (30) days at the latest, in accordance with Article 13 of the KVKK; we may need to verify your identity in order to conclude your application. Applications are free of charge as a rule; if the transaction requires an additional cost, a fee may be charged according to the tariff determined by the Personal Data Protection Board.

If your application is rejected, if you find our response insufficient, or if no response is given within the time limit, you have the right to lodge a complaint with the Personal Data Protection Board within thirty (30) days from the date you learn of the response, and in any event within sixty (60) days from the date of application.

9. Cookies

For detailed information about the cookies used on the LA Fish website, please review the Cookie Policy.

10. Changes

This disclosure notice may be revised due to changes in legislation or updates made to our services. In the event of significant changes, users are notified by a notification email and/or an in-app alert. The current text is always published on this page.