Ask a Turkish SME how it complies with KVKK and the answer is usually a privacy notice written by a lawyer. That notice matters, but Law No. 6698 on the Protection of Personal Data also expects the data controller to keep information secure through suitable technical and administrative safeguards, and those live in your IT rather than in a PDF. The gap tends to show at the worst possible time. A patient from two years ago files a request to see her records. A clerk sends the payroll sheet to an outside address by mistake. The Board writes after a complaint and wants to know how access is controlled. If nobody can point to the systems involved or name the people with access, the notice alone will not carry you. This service covers the technical half. We locate personal data across your systems, restructure permissions, turn on logging and give your staff a clear routine for a breach. We are not lawyers, and we say so plainly: legal opinions, final notice wording and contracts remain with your counsel or KVKK consultant. What we hand them is solid, dated evidence of how your systems behave, produced entirely over remote sessions.
Protection should match what is at stake. Marketing email addresses for a web shop are one thing; patient files at a dental practice are special category data under KVKK and call for stricter handling. We scale the effort to your data and do not sell you controls your risk does not need.
Customer cards in Logo or Mikro, the payroll tool, CRM, booking software, SharePoint, OneDrive, file shares, inboxes and that exported spreadsheet sitting on a sales laptop. We record each location, the categories of data it holds and who can reach it, which is exactly what your KVKK inventory needs.
Notice versus reality
Your website forms, cookie banner and booking pages collect data every day. We check what they gather, whether explicit consent is a genuine separate tick box and where proof of that consent is stored, then report the mismatches to the person who drafts your notices.
Processor access review
Accountants, payroll bureaus, software vendors and shipping integrators often connect with accounts nobody remembers creating. We catalogue those connections, shut the stale ones and describe the safeguards your data processing agreements should reference.
Permissions by job role
Payroll figures are for HR, medical notes are for clinicians. Access is assigned to groups in Entra ID or Google Workspace, so when someone joins, moves or leaves, their rights follow the role rather than lingering.
Audit trails
Microsoft 365 auditing and file server access logs are switched on and retained long enough that, weeks later, you can still see which account opened a given document.
Retention in practice
If your retention and destruction policy promises a deletion period, mail and document retention rules should enforce it. We configure those rules and decide how proof of each periodic deletion gets recorded.
Breach routine
A single page covering the opening hours of an incident: the person who triages, the logs that must be frozen, the facts the Board notification will require and the way affected individuals will be told.
How we approach the job, from first call to handover
Cheap, high-impact fixes come first. Deeper restructuring waits until those are done.
01
Initial review
One video meeting with your KVKK contact and a remote look at your tenant and servers. Output: a list of personal data systems and the protection each currently has.
02
Immediate clean-up
Dormant accounts of former staff, shared usernames and logins protected only by a password are dealt with during week one.
03
Safeguards
Encrypted laptop drives, logging, a role-based access model and restrictions on sharing with outsiders, introduced in stages so that no department suddenly loses access to its work.
04
Evidence pack
Each safeguard is written up with its date and owner, in wording you can paste into the inventory, a VERBİS entry or a response to the Board.
Regulators care less about which products you own and more about what you can demonstrate. Following a complaint or incident, the useful questions are factual: which accounts could open the data, from what date, what record confirms it and when the setup was last checked. An undocumented control is very hard to defend, which is why everything we change is logged with a date.
Frequently asked questions
Board decisions set out who must register and who is exempt, taking into account things like staff numbers, financial thresholds and the nature of the data. That is a legal question for your adviser. Where registration is required, we extract the categories, retention periods and safeguards from the inventory so the entry can be completed quickly.
Start from the inventory: booking tool, patient software, mailboxes, shared folders and backups. A Microsoft 365 eDiscovery query will pull up messages and files mentioning her name or ID number in minutes. You have thirty days at most to respond, and counsel should see the answer before it is sent.
Write to support@apply.tr immediately, or helpme@apply.tr if you have a contract with us. We attempt a message recall, secure the relevant logs and pin down what data left the building. Your legal adviser then decides whether a Board notification is needed; the 72 hours run from the moment you learned of the incident.
KVKK treats that as an international transfer and attaches conditions to it. Choosing the right legal basis, for example standard contracts, is your lawyer's job. Ours is to confirm in which countries your mail, backups and apps physically reside and to record it for the inventory, which also helps with GDPR if you sell to EU customers.
No, that is legal work. We test whether your systems behave as the notice claims. Suppose the notice promises deletion after two years: we look for a retention rule in the mail system and CRM that actually does that, and flag it if there is none.
Availability Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls By video, over Microsoft Teams or Google Meet
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
Filling the gaps. If we need more information to judge the job, we send questions by email or propose a quick Teams or Google Meet call.
A written quote. It lists the scope, a euro price excluding VAT and a realistic start date. No hidden clauses, no items that appear later.
Your decision. The quote arrives by email. Take whatever time you need, raise questions on any line, and decide when you are ready.
Where are you based?
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.