1. Data controller and scope
Metazen Bilişim ve Danışmanlık Ltd. Şti., the publisher of KriptoMeta, is the data controller for the activities described here. This notice is provided under Article 10 of Turkish Personal Data Protection Law No. 6698 (KVKK) for visitors, members and people contacting us. Current contact channels appear in the publisher and data controller section on this page.
2. Data we process and why
- Membership and accounts: Name, email address, securely hashed password, account status and activity timestamps are used to create and secure accounts, authenticate users and handle password resets. Optional profile information and photos are used for the profile features you choose.
- Personal lists: Saved articles, watchlist assets, their order, addition timestamps and prices are associated with your account to provide your reading and market watchlists.
- Enquiries, corrections and partnerships: Name, reply email, subject and message are used to assess and respond to your request. Company name, telephone number and attachments are optional. Avoid including unnecessary personal data about others or sensitive information in attachments.
- Team applications: Name, email, selected areas, message and optional portfolio/CV link or attachment are used to evaluate your application and respond. Submission does not automatically add you to a permanent talent pool or marketing list.
- Optional analytics: With your permission and when enabled, Google Analytics processes page visits, referring site domains, visit times, device/browser information and cookie identifiers to measure readership. Google may receive your IP address when a connection is made. Form responses, email addresses and private account details are not added to analytics events. Your cookie choice, notice version and choice date are remembered in this browser for 180 days.
- Internal view counter: A daily keyed technical digest helps measure aggregate readership and reduce repeat counts. This counter sends no data to third-party analytics, sets no tracking cookies and stores no raw IP address or browser string in its counter tables. Server security logs are separate.
- Security and technical operation: IP address, request time, browser/device information, session identifiers and security logs may be processed to prevent misuse, diagnose errors and protect the service.
3. Collection methods and legal grounds
We collect data electronically through account and contact forms, account activity, email correspondence, server logs and necessary session technologies.
- Account creation, personal lists and requested services: Article 5(2)(c), where processing is directly related to establishing or performing a contract.
- Assessing an application to establish a working or contribution relationship you request: Article 5(2)(c); necessary enquiry management and limited internal view counting: Article 5(2)(f), subject to your fundamental rights and freedoms.
- Optional technologies such as Google Analytics: explicit consent under Article 5(1). The service does not start if you decline. Your preference record is kept to honour your choice. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Legal requests, corrections and disputes: Article 5(2)(e), where necessary to establish, exercise or protect a right.
- General enquiries and service security: Article 5(2)(f), legitimate interests that do not harm your fundamental rights and freedoms.
- Mandatory records and lawful authority requests: Articles 5(2)(a) and 5(2)(ç), as applicable to the legal obligation.
Where a separate activity requires explicit consent, we request it separately. Reading this notice, registering or sending an enquiry does not constitute consent to advertising, marketing or optional tracking.
4. Recipients and international transfers
Data may be shared, where necessary, with hosting and technical support providers, email delivery providers, security providers and legally authorised authorities. Enquiries and team applications are accessible to the relevant authorised team. We do not sell personal data. When permitted analytics is enabled, Google receives technical visit data. Forms using Cloudflare Turnstile may send IP, browser and verification data to its infrastructure. External file delivery and embedded-content providers can also receive technical information when your browser requests their resources.
A provider’s infrastructure may involve processing outside Türkiye. Any such transfer requires an applicable mechanism under Article 9 of KVKK; this notice alone is not a transfer authorisation or explicit consent. You can request information about providers and transfers through our contact channel.
5. Retention and deletion
Account and list data are retained to provide the service. Enquiries and applications are retained to assess, respond to and follow up requests and protect relevant rights. Application data is deleted when that purpose ends unless another valid retention basis applies; a separate talent pool for future opportunities is outside the scope of this form. Security logs, backups and email copies are assessed according to their respective retention needs. Data is deleted, destroyed or anonymised when its purpose and lawful basis no longer apply.
You can use “Delete my account” in your account settings. Limited deletion records, which do not directly contain your name but allow account matching, help prevent deleted accounts from being restored from old backups. A legal obligation or ongoing dispute may require certain relevant records to be retained separately.
6. Your rights under KVKK
Under Article 11, you may learn whether your data is processed, request information about processing, learn its purpose and whether it is used accordingly, and learn the recipients inside or outside Türkiye. You may request correction of incomplete or inaccurate data, deletion or destruction where the conditions apply, and notification of those actions to recipients. You may object to an adverse result based solely on automated analysis and seek compensation for damage caused by unlawful processing.
7. Making a request
Use your email address registered with us to contact the privacy email shown on this page, with “KVKK Request” as the subject. Include your name, reply details, the request and the relevant account or transaction. We may request additional information to verify your identity securely and meet the applicable application requirements. Never send your password or wallet recovery phrase.
Valid requests are answered as soon as possible and within 30 days. If additional costs arise, the tariff established by the Authority may apply. See the Turkish Personal Data Protection Authority’s guidance on responses and complaints.















