Privacy Notice on The Processing of Personal Data

Doktar Teknoloji Anonim Şirketi (“Doktar”, “we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Notice explains how we collect, use, disclose, retain, and protect your personal data when you use the Application, including both its mobile (iOS/Android) and web-based platforms.

This Privacy Notice is provided separately from any explicit consent you may give for specific data processing activities (e.g., marketing communications). Consent is not required to agree to this notice.

1. Who We Are

  1. Data Controller:
    Doktar Teknoloji Anonim Şirketi
    Reşitpaşa Mahallesi Katar Caddesi İTÜ Arı Teknokent 3 Binası No: 4 İç Kapı No: B301 Sarıyer/İstanbul (post: 34467)
    MERSIS number:0309-0343-8730-0011
  2. Contact Details:
  3. Scope:
    This Privacy Notice applies to personal data collected through the Application, including both mobile and web-based platforms. For more details about how your data is handled in the context of our broader services (e.g., website visits, offline interactions), please refer to any additional privacy statements we may provide.

2. What Personal Data We Collect

Depending on how you use the mobile or web-based Application, we may collect the following categories of personal data:

  1. Identity Data: Name, surname, user ID, or other identifiers.
  2. Contact Data: Email address, phone number, mailing address.
  3. Account Credentials: Login credentials (phone number or other System Access Tools).
  4. Field & Location Data: GPS coordinates, field information, or other geographic details to provide satellite imagery and agronomic recommendations.
  5. Device & Usage Data:
  6. Payment & Transaction Data (if you subscribe to paid services): Payment card details (tokenized by the app store or payment processor), transaction history, invoicing information.
  7. Marketing & Communication Preferences: Records of your opt-ins or opt-outs for receiving marketing or commercial communications.

Sensitive Personal Data: We generally do not request or require sensitive data (e.g., health information, race, religion). If you choose to provide it, you do so under your own responsibility. We will handle it under this Privacy Notice as applicable.

3. How We Collect Your Personal Data

We collect personal data about you from various sources and through different methods, depending on how you interact with the Application (both mobile and web-based platforms). These methods include:

1. Directly from You (User-Provided Information):

· When you register for an account via the mobile or web platform.

· When you submit information by filling out forms within the Application (e.g., field details, crop types, contact details).

· When you contact us for support, provide feedback, or communicate with Doktar via email, chat, or phone.

· When you participate in surveys, promotions, or marketing campaigns we organize (if you opt in).

2. Automatically Collected Through Technology:

· When you access or use the Application, we automatically collect certain technical data and usage information, including:

o Device information (device type, operating system, device identifiers).

o IP address and location data (based on IP or device settings).

o Log and event data (e.g., login timestamps, feature usage logs).

o Clickstream data and interaction records within the mobile and web-based Application.

· We collect this data using cookies, SDKs , pixels, log files, and similar tracking technologies integrated into both the mobile and web versions of the Application.

3. From Third Parties and External Sources:

· When you log in using third-party services (if applicable), such as app stores (Apple App Store, Google Play) or social login providers (when enabled).

4. Purposes and Legal Bases for Processing

We process your personal data under one or more of the following legal bases (as defined by GDPR Article 6 and Turkish Law No. 6698 (“KVKK”) where relevant):

  1. Performance of a Contract (GDPR Art. 6(1)(b))
  2. Legitimate Interests (GDPR Art. 6(1)(f))
  3. Consent (GDPR Art. 6(1)(a))
  4. Legal Obligations (GDPR Art. 6(1)(c))

Below is a breakdown of the personal data categories we process, their purposes, and the corresponding legal bases under GDPR and PDPR.

Personal Data Category

Purpose of Processing

Legal Basis for Processing

Identity Data (name, surname, user ID)

To create and manage your user account; verify your identity when logging in; provide customer support.

Performance of a Contract (GDPR Art. 6(1)(b); KVKK Art. 5/2(c))

Contact Data (email address, phone number)

To communicate with you regarding service updates, account status, and transaction information; provide customer support.

Performance of a Contract (GDPR Art. 6(1)(b); KVKK Art. 5/2(c))

Contact Data (email address, phone number)

To send marketing communications (promotions, newsletters), if you have opted in.

Explicit Consent (GDPR Art. 6(1)(a); KVKK Art. 5/1)

Field & Location Data (GPS coordinates, field information)

To provide location-based services such as satellite imagery, crop monitoring, and agronomic recommendations.

Performance of a Contract (GDPR Art. 6(1)(b); KVKK Art. 5/2(c))

Device & Usage Data (device type, IP address, session logs)

To analyze and improve application performance and user experience; to detect and prevent fraud.

Legitimate Interests (GDPR Art. 6(1)(f); KVKK Art. 5/2(f))

Payment & Transaction Data (tokenized payment card data, transaction history)

To process subscription fees and issue invoices; to comply with accounting and tax obligations.

Performance of a Contract (GDPR Art. 6(1)(b); KVKK Art. 5/2(c)) and Legal Obligation (GDPR Art. 6(1)(c); KVKK Art. 5/2(ç))

Marketing & Communication Preferences (opt-ins/opt-outs)

To manage your preferences for receiving marketing communications and surveys.

Explicit Consent (GDPR Art. 6(1)(a); KVKK Art. 5/1)

Log & Session Data (login timestamps, feature usage logs)

To monitor service integrity and security; to detect unauthorized access and prevent misuse of the system.

Legitimate Interests (GDPR Art. 6(1)(f); KVKK Art. 5/2(f))

5. How We Use Your Personal Data

  1. Providing the Service:
  2. Account Management & Support:
  3. Analytics & Improvements:
  4. Marketing & Communications (if you opt in):
  5. Compliance & Protection:

6. Disclosures Of Your Personal Data

We only share personal data with third parties in the following circumstances:

  1. Service Providers: We may share data with trusted vendors (e.g., hosting providers, analytics platforms, payment processors) who process data on our behalf and under our instructions.
  2. Affiliates / Group Companies: For internal administrative purposes or to provide integrated services, subject to the same security and privacy obligations.
  3. Legal Obligations: We may disclose data if required by law or if necessary to respond to lawful requests by public authorities (e.g., courts, regulatory agencies).
  4. Business Transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the relevant third party.
  5. With Your Consent: We may share data for other purposes if you expressly consent.

We do not sell or rent your personal data to third parties. For information about cross-border transfers, please see Section 7.

7. International Data Transfers

Doktar processes and stores your personal data on Microsoft Azure servers located within the European Union. We do not transfer your personal data outside the European Economic Area (EEA) or Turkey.

If we need to transfer your personal data outside of the EEA or Turkey in the future, such transfers will be conducted in compliance with applicable data protection laws, including GDPR and KVKK. Appropriate safeguards, such as Standard Contractual Clauses (SCCs), will be implemented where necessary.

8. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including the provision of our services, compliance with legal, accounting, and reporting requirements, and protection of our legitimate interests.

The exact duration for which we retain personal data depends on several factors, including:

Once the retention period ends, or where you request deletion and there is no overriding legal basis for continued retention, we securely delete or anonymize your personal data.

For more detailed information about our data retention criteria or to request deletion of your personal data, you can contact us at: support@doktar.com.

9. Your Rights (GDPR & KVKK)

Depending on the applicable law (GDPR, KVKK), you may have the following rights:

1. Right of Access:You have the right to request confirmation of whether we process your personal data and access to that data.

2. Right to Rectification:You have the right to request the correction of inaccurate or incomplete personal data.

3. Right to Erasure: You may request the deletion of your personal data under certain conditions (e.g., when it is no longer necessary for the purpose it was collected).

4. Right to Restrict Processing:ou can request that we restrict processing of your personal data where you contest its accuracy, object to processing, or believe processing is unlawful.

5. Right to Data Portability:You can request your personal data in a structured, commonly used, and machine-readable format, and to have it transferred to another controller.

6. Right to Object:You have the right to object to our processing of your personal data where processing is based on legitimate interests or for direct marketing purposes.

7. Account Deletion Request:You can request the deletion of your account.

8. Rights Related to Automated Decision-Making:You can request not to be subject to decisions based solely on automated processing.

9.1. How to Exercise Your Rights

You can submit a request to exercise your rights by contacting us via one of the following methods:

For KVKK requests, you can submit your application in accordance with Article 13 of the Law and the Communiqué on the Procedures and Principles of Application to the Data Controller.

We will respond to your request as soon as possible and within one month at the latest (or within 30 days for KVKK applications), in accordance with applicable data protection laws.

If we reject your request, we will inform you of the reasons in writing or electronically.

9.2. Complaints

If you believe that we have not adequately addressed your request or if you are concerned about how we process your personal data, you have the right to lodge a complaint with:

10. Security Measures

We take the protection of your personal data seriously and implement appropriate technical and organizational measures to ensure its security, confidentiality, integrity, and availability, in accordance with Article 32 of the GDPR and Article 12 of the KVKK.

Our security measures include, but are not limited to:

Technical Measures:

Organizational Measures:

Although we implement and maintain reasonable security measures to protect your personal data, no system is completely secure. If you believe your personal data has been compromised, please contact us immediately at support@doktar.com.

11. Third-Party Links & Features

The Application may contain links to third-party websites or integrations with third-party services. We are not responsible for the privacy practices of such third parties. We encourage you to review their privacy policies before providing any personal data.

12. Updates To This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our data practices or legal obligations. We will notify you of material changes by posting the revised notice in the Application or via other appropriate channels. The Effective Date at the top indicates when the notice was last updated.

13. Contact Us

If you have any questions, concerns, or wish to exercise your rights regarding your personal data, please contact us at:

We will do our best to address your inquiry promptly.