KVKK Privacy Notice
Last updated: October 4, 2026
This Privacy Notice, prepared under Law No. 6698 on the Protection of Personal Data ("KVKK"), explains which personal data FoundrOne processes as data controller and for what purposes.
FoundrOne is currently not operated under a company legal entity. The data controller and operator of the platform is the individual operator of FoundrOne.
Data Controller
Data Controller: İrfan Semih Doğru
Address: Bursa / Osmangazi
Email: destek@foundr.one
KVKK application email: kvkk@foundr.one
The current identity and address information of the data controller is stated at the beginning of this document.
1. Personal Data Processed
The following categories of personal data may be processed during the use of FoundrOne:
Identity information
- First name
- Last name
User account information
- Username
- Email address
- Account information
- Email verification information
- The necessary information provided through a Google account
Profile information
- Profile photo
- Bio
- Information the user creates on their profile at their own request
Content created by the user
- Posts
- Comments
- Upvote information
- Startup/product information
- Product name
- Product description
- Pricing information
- Product status
- Product images
- Build Push titles
- Build Push descriptions
- Links the user publishes on the platform
- Commercial information the user voluntarily shares
Revenue, user counts, investment amounts or similar commercial information shared by the user on the platform may be processed to the extent it is voluntarily provided by the user.
Transaction security and technical data
Technical data may be processed for the security of the platform, the protection of accounts, the prevention of misuse and the operation of the service.
Depending on the technical structure of the system, this may include IP address, User-Agent, session information, login/logout records, failed login attempts and security logs. The scope of this data may vary depending on the technical systems used.
2. Purposes of Processing Personal Data
Personal data may be processed for the following purposes:
- Creating and managing a user account
- Verifying the email address
- Performing password reset operations
- Enabling sign-in with Google
- Creating the user profile
- Ensuring the platform works
- Publishing user content
- Providing the post, comment, upvote, startup and Build Push features
- Enabling users to view each other's content
- Maintaining community order
- Evaluating complaints
- Preventing misuse
- Combating fraud and forgery
- Ensuring security and preventing unauthorized access
- Detecting and resolving technical problems
- Measuring platform performance
- Fulfilling legal obligations
- Meeting the requests of authorized public institutions and organizations
- Responding to user requests
- Evaluating applications within the scope of KVKK
3. Legal Bases for Processing Personal Data
Personal data may be processed within the scope of the legal bases regulated in Article 5 of KVKK, depending on the nature of the specific data processing activity.
- Being clearly stipulated by law
- Being directly related to the establishment or performance of a contract
- Enabling the data controller to fulfill its legal obligation
- Being made public by the data subject themselves
- The establishment, exercise or protection of a right
- The legitimate interest of the data controller
- The explicit consent of the data subject when necessary
The appropriate legal basis is separately evaluated for each data processing activity. Explicit consent is not unnecessarily obtained from the user for transactions that do not require it.
4. Transfer of Personal Data
Personal data may be shared with the following service providers to the extent necessary for providing the service and operating the technical infrastructure:
- MongoDB Atlas
- Cloudflare
- Cloudflare R2
- Resend
In addition, data may be shared with public institutions and organizations authorized by law, within the scope of fulfilling legal obligations.
5. Transfer of Data Abroad
Personal data may be transferred abroad because the third-party infrastructure services used by FoundrOne may be located abroad, or because data may be processed on systems located abroad.
Transfers abroad are carried out in accordance with the conditions regulated in Article 9 of KVKK and applicable appropriate safeguard mechanisms. FoundrOne evaluates the applicable transfer mechanism according to the nature of the service provider receiving the transfer and the relevant data flow. Where necessary, standard contracts accepted by KVKK or other appropriate safeguard methods may be used.
6. Method of Collecting Personal Data
Personal data;
- FoundrOne membership forms
- The user account
- Google OAuth
- Content created by the user
- Email verification and password reset operations
- User interactions on the platform
- Technical systems and logs
- User support requests
may be collected electronically by means of.
7. Retention of Personal Data
Personal data may be retained for the period required by the purposes of processing and for the retention periods stipulated in the relevant legislation. When the retention period ends, the data is deleted, destroyed or anonymized in accordance with the relevant legislation.
When a user account is deleted, the necessary data may be deleted or anonymized depending on the nature of the account and its content. Previously published content may be displayed under an anonymized account view such as "deleted account" after the user account is deleted.
8. Rights of the Data Subject
Within the scope of Article 11 of KVKK, data subjects;
- Learn whether their personal data is processed
- Request information about the processed data if it has been processed
- Learn the purpose of processing and whether it is used in accordance with that purpose
- Know the third parties to whom personal data is transferred domestically or abroad
- Request the correction of incomplete or incorrectly processed data
- Request the deletion or destruction of personal data in case the legal conditions are met
- Request that correction, deletion or destruction be notified to the third parties to whom the data has been transferred
- Object to a result that is detrimental to them as a result of analysis carried out exclusively by automated systems
- Request compensation for damages in case they suffer harm due to unlawful data processing
have the right to.
9. KVKK Applications
Requests within the scope of KVKK can be sent to kvkk@foundr.one. While evaluating applications, the necessary information may be requested in order to verify the identity of the applicant.
10. Notification Obligation
This Privacy Notice is not a contract acceptance or an explicit consent text. The notification obligation is fulfilled independently of the legal basis of the personal data processing activity.
If there is a separate data processing activity requiring explicit consent, this consent is obtained separately from the Privacy Notice.
General support: destek@foundr.one
KVKK applications: kvkk@foundr.one