Insights

KVKK and GDPR for SaaS built in Turkey

A SaaS product built in Istanbul often touches people in Turkey and people in the EU. KVKK and GDPR are legal regimes. This page is the engineering we put in place so counsel’s decisions can actually be carried out. It is not legal advice.

Your lawyer decides whether you are a controller, a processor, or both, and which lawful basis applies. We do not make that call, and we do not publish a template privacy policy as a substitute for one. What we do is build the controls a written instruction can point at: where data sits, who can read it, how long it is kept, how a person is exported or deleted, and which subprocessors ever see it.

Start with a data map, not a banner

A cookie banner does not describe a SaaS product. The map we ask for in discovery is a list of personal data the product stores: account emails, names, support transcripts, files a tenant uploaded, usage events, and anything a model provider would receive. For each item we write the purpose, the store, the region, and the retention. If a field has no purpose, it does not ship.

Turkish data subjects bring KVKK questions. EU data subjects bring GDPR questions. A product can face both at once when a Turkish company sells to an EU customer, or when an EU company uses a product operated from Istanbul. The engineering response is the same shape: know the record, know the region, and do not send it somewhere the instruction forbids. The legal response is counsel’s. We implement the instruction they sign.

Region is a deployment fact

If a contract says personal data of EU customers is processed in the EU, the database, the object store, the backups, and the log pipeline that contains those fields run there. A config flag that nobody tests is not residency. Backups are the usual leak: a primary in Frankfurt and a nightly copy in another region is still a transfer. We name the backup region in the design.

Hosting choices we actually use are Cloudflare, AWS, and GCP. The region is selected per product, not because the company letterhead is in Şişli. The studio is in Istanbul. The data plane is wherever the instruction and the latency budget say it is.

Access, deletion, and the tenant boundary

A deletion request has to reach the tenant’s rows, the search index, the object store, and the backups’ retention clock. “We deleted the user row” is not enough if the file they uploaded is still in a bucket and a warehouse export. We design the delete as a job with a record of what it touched. Export is the same job in the other direction: a machine-readable copy of that person’s data, not a screenshot.

Tenant isolation, described in the multi-tenant architecture note, is also a privacy control. Another customer’s admin must not be a backdoor. Support access, if it exists, is an audited impersonation, not a shared password.

Subprocessors, models, and logs

Email delivery, error tracking, payments, and model APIs are subprocessors whether or not the architecture diagram drew them. Each one gets a named purpose and a field list. A support widget that ships the whole DOM to a third party is a product decision, and we will flag it. An LLM call is the same kind of decision: the prompt is a transfer. We do not send a tenant’s documents to a provider you have not named. Retrieval stays on the documents you are allowed to use. That boundary is the one on the enterprise AI page.

Logs are personal data when they contain emails, IP addresses, or request bodies. We keep them for a written period and we keep them out of screenshots in chat tools. Production access is limited to the people operating the system.

What we will not pretend

We implement the control your counsel named. We do not invent the legal role, the lawful basis, or a cross-border mechanism.

Standard contractual clauses, a KVKK verbis or an equivalent filing, and a data processing agreement are documents. We can build to the technical annex — encryption in transit and at rest, access logs, a list of regions, a deletion path. We do not sign them in place of your counsel, and we do not tell you that “hosting in the EU” ends the analysis. A first SaaS slice still fits the 10–16 week planning band when the data map is short. A product that cannot name its stores will not.

If you want the delivery sequence, read how we work. If you want the product page, read SaaS platform development. Bring the questions your counsel already asked; discovery is shorter when the data map is started.