KVKK and Privacy
EvimAI Privacy Policy and KVKK Disclosure Notice
This text has been prepared in order to fulfil our disclosure obligation under art. 10 of Personal Data Protection Law No. 6698 ("KVKK") with respect to personal data processed through the EvimAI mobile application and website (the "Platform") operated by WBPS Teknoloji ve Danışmanlık Anonim Şirketi.
Effective date: 10 August 2026 · Last updated: 11 August 2026
Pre-publication note: This text will be reviewed and approved by a legal counsel before commercial launch and customer onboarding. Official registry information of the data controller, such as the tax office/number, MERSİS number (Turkish central trade registry number), KEP address (registered electronic mail address) and VERBİS (the Turkish data controllers' registry) registration number, will be added to this text before commercial launch.
In short: We process the data necessary to verify your identity, enable you to manage the tenancy relationship, collect payments and fulfil our legal obligations. We do not sell your data. You can delete your account and your data from within the app.
1. Identity of the data controller
Data controller:
- Trade name: WBPS Teknoloji ve Danışmanlık Anonim Şirketi ("WBPS Teknoloji ve Danışmanlık A.Ş.")
- Application / brand operated: EvimAI
- Address: Istanbul, Türkiye
- KVKK application e-mail: kvkk@evimai.com
- General contact / support: destek@evimai.com
The tax office and tax number, MERSİS number, KEP address, VERBİS registration number and full postal address will be added to this section before commercial launch. Until this information is completed, you can reach the data controller through the e-mail addresses above.
2. Scope
This policy applies to the personal data of landlords, tenants, prospective tenants and property managers who register on the Platform, as well as of other persons who visit the Platform.
Third-party services accessed through the Platform (e.g. e-Devlet, Findeks) are subject to their own privacy policies. This text covers the data that we process.
3. Personal data we process
3.1. Identity and contact data
- Full name, e-mail address, mobile phone number
- Profile photo (if you choose to upload one)
- Turkish national ID number (within the scope of tenant applications, identity verification and drawing up the tenancy agreement)
- City / address information
- Your role on the Platform (landlord, tenant, property manager, administrator)
3.2. Identity verification (KYC) and biometric data
- The image of your identity document and the information on the document
- Your facial image and liveness verification record
- Verification result, verification date, reason for rejection
Facial verification data is special categories of personal data within the meaning of art. 6 of KVKK and is processed only with your explicit consent. The raw form of this data is held by our identity verification provider; our system stores the verification result, reference number and status information.
3.3. Data relating to the property, the listing and the tenancy relationship
- Property address, location coordinates, title deed/real estate information, photographs
- Listing content, rent amount, deposit amount
- The text of the tenancy agreement and the parties' details in the agreement (including Turkish national ID numbers), inventory list
- Rent schedule, payment tracking records, fault/repair requests
- Messages between the parties and support requests
3.4. Tenant application and assessment data
When you apply as a prospective tenant and/or take part in tenant screening at a landlord's invitation:
- Occupation, monthly income / income range, additional income, income type (salaried, self-employed, retired, other), employer name
- Marital status, household size, number of adults and children, pet information
- Documents you upload such as proof of income, social security (SGK) documents, Findeks report, copy of your ID
- Findeks credit score and credit card utilisation rate (see 3.5 below)
- The calculated TRE (tenant resilience) score and the breakdown of its components
- The landlord's and the manager's assessment notes on the application
3.5. Findeks data
Your Findeks credit score and related financial indicators are included in the application only with the Findeks sharing consent code you provide and with your explicit consent. If you do not give consent, the tenant screening is carried out without this data and no score is generated.
3.6. Payment data
- Payment amount, currency, transaction number, payment status, payment date
- Which service the payment relates to (repair, Care Plus, rent/agreement, tenant screening, etc.)
- Masked card information relating to your saved cards
We do not store your card number, expiry date or CVV. This data is processed directly on the infrastructure of the payment institution (Paycell / Turkcell Ödeme Hizmetleri); saved cards are held in the payment institution's wallet.
3.7. Device, usage and technical data
- Device type, operating system, application version
- IP address and connection information
- Device notification token and platform information for push notification registration
- Error/crash records and performance measurements
- In-app usage events (such as which screens were opened and which actions were completed)
3.8. Address and map data
We do not collect your device's precise or approximate location and we do not request location permission. To search for and display the property address on the map we use only the address text you type; we may derive location coordinates from that address.
4. Which data we process, for which purpose and on which legal basis
The processing purpose and the legal basis under art. 5/6 of KVKK are set out below for each data category.
Identity and contact data
- Purpose: To create your account, identify you, reach you and provide the service.
- Legal basis: Establishment and performance of a contract (art. 5/2-c); legitimate interest (art. 5/2-f).
Phone number and SMS verification code
- Purpose: To verify that the number belongs to you and to prevent fake accounts and fraud.
- Legal basis: Performance of a contract (art. 5/2-c); legitimate interest (art. 5/2-f).
Identity document and facial/liveness data (KYC)
- Purpose: To verify the user's real identity and to prevent fraud in tenancy agreement and payment processes.
- Legal basis: Explicit consent (art. 6/2); additionally legal obligation and the establishment/protection of a right (art. 5/2-ç and art. 5/2-e).
Turkish national ID number
- Purpose: Drawing up the tenancy agreement, identifying the parties, tenant assessment.
- Legal basis: Performance of a contract (art. 5/2-c); legal obligation (art. 5/2-ç).
Property, listing and tenancy relationship data
- Purpose: To publish listings, prepare tenancy agreements, track rent and payments, and carry out fault/repair processes.
- Legal basis: Performance of a contract (art. 5/2-c).
Tenant application, income and Findeks data, TRE score
- Purpose: To help the landlord assess the prospective tenant.
- Legal basis: Explicit consent; being directly related to the establishment of a contract (art. 5/2-c).
Payment data
- Purpose: To collect the fees for paid services, manage refunds and objections, and keep accounting and tax records.
- Legal basis: Performance of a contract (art. 5/2-c); being expressly provided for by law and legal obligation (art. 5/2-a and art. 5/2-ç).
Device notification token
- Purpose: To send you notifications about your transactions.
- Legal basis: Performance of a contract (art. 5/2-c); explicit consent for marketing notifications.
Error, crash and performance records
- Purpose: To keep the application running, fix errors and ensure security.
- Legal basis: Legitimate interest (art. 5/2-f).
Usage/analytics data
- Purpose: To improve the product and understand which features are used.
- Legal basis: Explicit consent (if your analytics permission is off, we do not process this data).
Address and map data
- Purpose: To search for, verify and display on the map the property address you enter.
- Legal basis: Establishment and performance of a contract (art. 5/2-c).
Messages and support records
- Purpose: To enable communication between the parties, resolve support requests and create evidence in the event of a dispute.
- Legal basis: Performance of a contract (art. 5/2-c); establishment and protection of a right (art. 5/2-e).
5. Device permissions requested by the application
Each permission is requested only when you use the relevant feature and you may refuse it. If you refuse, only that feature will not work. The application does not request location permission; the property address is shown on the map based on the address text you enter.
- Camera: Capturing your identity document and your face during identity verification; uploading property photos.
- Microphone: Audio recording during video liveness verification.
- Photo library / storage: Uploading identity documents, proof of income, property photos and profile photos.
- Notifications: Sending notifications about payments, applications, agreements and rent reminders.
- Internet access: Required for the application to work.
6. To whom we transfer your personal data
We do not sell your data. Transfers to the parties below are made solely for the stated purpose and with the minimum data necessary.
Transfers between Platform users
- When you apply as a prospective tenant, your application details and, if any, your assessment report are shown to the landlord of the listing you applied to and, if any, to the property manager.
- Once a tenancy relationship is established, your details included in the agreement are visible to the other party.
- The user you exchange messages with sees the messages and files you send.
Our service providers
- Supabase — The application's database, file storage, identity management and server infrastructure. The majority of the processed data is hosted on this infrastructure.
- Didit — Identity verification and liveness (KYC) service. Identity documents and facial images are transmitted directly to this provider.
- Paycell / Turkcell Ödeme Hizmetleri — Card payments, 3D Secure verification, saved card storage and refund transactions.
- NetGSM — Phone number verification and sending informational SMS messages.
- Google (Firebase Cloud Messaging) — Sending push notifications.
- Google (Places API) — Address search and autocomplete. The address text you type is transmitted to this service.
- Google (Gemini API) — The in-app artificial intelligence assistant. The messages you write to the assistant and the account content the assistant needs in order to generate a response are transmitted to this service. We recommend that you do not share sensitive information.
- Sentry — Error and crash reporting. It is configured with personal data transmission disabled; only the user ID and e-mail address are associated.
- Mixpanel — Application usage analytics. Runs only when analytics permission is enabled.
- OpenStreetMap — Serving map imagery.
- Republic of Türkiye Ministry of Trade — Electronic Listing Verification System (EİDS) and the e-Devlet Gateway — Verification of the property and of the authority to publish a listing.
- Findeks / KKB — Inclusion of credit score information in the application solely with the consent code you provide.
Competent authorities We share information, to the extent required by legislation, in response to duly made requests from courts, public prosecutors and public authorities empowered by law.
7. Transfers abroad
The servers of the following service providers are located outside Türkiye, and transfers to these providers are deemed transfers abroad:
- Supabase — database, file storage and server infrastructure
- Didit — identity verification and liveness (KYC) service
- Google (Firebase Cloud Messaging) — sending push notifications
- Google (Places API) — address search and autocomplete
- Google (Gemini API) — the in-app artificial intelligence assistant
- Sentry — error and crash reporting
- Mixpanel — application usage analytics
These transfers are carried out on the basis of your explicit consent within the scope of art. 9 of KVKK. Your explicit consent is obtained during account creation through a separate approval field, after the disclosure has been made and independently of other approvals. You may withdraw your explicit consent at any time; if you withdraw it, you may not be able to use features that require transfers abroad.
Should transfers abroad in the future be based on another mechanism envisaged by the Board (standard contract, undertaking or adequacy decision), this section will be updated and the change will be announced to you in the manner set out in section 15.
8. Retention periods
We retain your data for as long as the processing purpose requires and for the minimum periods prescribed by legislation:
- Account and profile data: For as long as your account is open; deleted or anonymised when you delete your account.
- Payment and invoice records: 10 years pursuant to the Tax Procedure Law and the Turkish Commercial Code. These records are retained even where an account deletion is requested; however, their link to your identity is severed (they are anonymised).
- Tenancy agreements and agreement annexes: For the statute of limitations period following the end of the contractual relationship (as a rule 10 years).
- Identity verification (KYC) records: The verification result and reference for as long as your account is open; raw documents and biometric data are subject to the retention policy of the verification provider.
- Messages: As this is two-sided content, it remains in the other party's records for as long as the other party exists.
- Error and crash records: Maximum 90 days.
- Analytics data: Maximum 24 months.
- SMS verification codes: For the validity period of the code; deleted shortly afterwards.
9. Your right to delete your account and your data
You can delete your account from within the app: Profile → Delete My Account (or the "More" menu → Delete My Account).
For an account deletion request via the web: https://evimai.com/hesap-sil
What happens when you request account deletion:
- Your profile, your identity verification records, the files you uploaded yourself and your session information are permanently deleted.
- If you signed in with Apple, your authorisation token on Apple's side is revoked.
- Payment and booking records are not deleted, because tax and accounting legislation requires these records to be retained. The identity link in these records is severed and the personal information fields within them are cleared; what remains is financial information such as the amount, transaction number and status.
- Two-sided content is not deleted. Tenancy agreement documents and message attachments remain in the other party's records for as long as the other party exists. Only the files you uploaded yourself are deleted.
Deletion cannot be undone. You can register again with the same e-mail address as the deleted account; however, your old data will not be restored.
10. Your rights under art. 11 of KVKK
By applying to the data controller, you have the right to:
- 1Learn whether your personal data is being processed,
- 2Request information if it has been processed,
- 3Learn the purpose of processing and whether the data is used in accordance with that purpose,
- 4Know the third parties within the country or abroad to whom the data has been transferred,
- 5Request rectification if it has been processed incompletely or inaccurately,
- 6Request erasure or destruction within the framework of the conditions set out in art. 7 of KVKK,
- 7Request that rectification, erasure and destruction operations be notified to the third parties to whom the data has been transferred,
- 8Object to a result arising against you through analysis carried out exclusively by automated systems,
- 9Claim compensation if you suffer damage due to unlawful processing
these rights.
How to apply: You can send your requests, together with information substantiating your identity, by e-mail to kvkk@evimai.com. The KEP address and the postal address for wet-signed petitions will be announced in this section before commercial launch. Your application will be concluded free of charge within 30 days at the latest; if the process entails an additional cost, the fee set out in the tariff determined by the Board may be charged.
11. Cookies and similar technologies
Cookies in the classic sense are not used in the mobile application; secure local storage and identity tokens on your device are used to maintain your session.
On our website:
- Strictly necessary cookies: Required for sign-in and security; they cannot be turned off.
- Analytics cookies: Run only when you give consent.
You can change your analytics preference at any time from the application settings or from the cookie preference panel on the website.
12. Automated assessment and tenant scoring
Within the scope of tenant screening, a TRE (tenant resilience) score is calculated based on the prospective tenant's income, household and Findeks data.
- The score is presented to the landlord solely as decision support; the landlord makes the letting decision. The score is not on its own a binding decision.
- The components that make up the score and the contribution of each component are recorded; the breakdown will be explained to you upon your request.
- If any of the required data is missing, no score is generated; no estimated score is displayed with incomplete data.
- Pursuant to art. 11/1-g of KVKK, if you believe that this assessment has produced a result against you, you have the right to object.
13. Children's data
The Platform is not designed for persons under the age of 18 and we do not knowingly collect personal data from persons under 18. Since we provide a service that requires the legal capacity to enter into a tenancy agreement, a user opening an account must have completed the age of 18.
If we determine that data belonging to a user under the age of 18 is being processed, we close the relevant account and delete the data. If you become aware of such a situation, please notify kvkk@evimai.com.
The number of children declared as part of household size in a tenant application is numerical data that contains no identity information.
14. Data security
- All network traffic is encrypted with TLS.
- Identity tokens are kept in secure storage on the device (iOS Keychain / Android Keystore).
- Database access is restricted by row level security (RLS) policies; a user sees only the records they are authorised to see.
- Invitation and verification codes are stored in the database in hashed form, not as plain text.
- Card data is never present in our systems.
Nevertheless, no transmission over the internet is 100% secure. In the event of a data breach, we notify the Board and the relevant data subjects as soon as possible pursuant to art. 12/5 of KVKK.
15. Changes to this policy
We may change this policy due to legislative changes or updates to our services. We announce material changes at least 15 days before they take effect via an in-app notification or e-mail. The current version is always available in the app on this screen.
16. Contact
For any questions, requests and complaints relating to privacy:
- Data controller: WBPS Teknoloji ve Danışmanlık A.Ş. (operator of the EvimAI application)
- KVKK applications: kvkk@evimai.com
- Support: destek@evimai.com
- Address: Istanbul, Türkiye (full address will be added before commercial launch)
If you are not satisfied with the outcome of your application, you reserve the right to lodge a complaint with the Personal Data Protection Board.