Skip to content
Cogitave

LEGAL DOCUMENT

Account Privacy Notice

Activity-specific KVKK notice for Cogitave customer registration, authentication, recovery, security, and account self-service.

Last updated: August 21, 2026

Activity-specific notice: This document explains the customer-account processing activity. It is presented during registration independently from the Account Terms and is not consent to advertising or marketing.

1. Data controller

Cogitave Yazılım ve Danışmanlık Ltd. Şti. acts as data controller under Turkish Personal Data Protection Law No. 6698 (KVKK).

Brand
Cogitave
Legal name
Cogitave Yazılım ve Danışmanlık Ltd. Şti.
MERSIS
0211155769500001
TIN / Tax office
2111557695 / Tepecik
Registered office
Ovacık Mahallesi, Kavakçılık Caddesi, No: 29, Duo Life Residence A Blok, Kat: 2, Daire: 43, Başiskele/Kocaeli, Türkiye
Phone
+90 552 599 40 41
E-mail
hello@cogitave.com

2. Data categories and sources

We collect the following data directly from you through customer-account forms and automatically from account requests:

  • Identity and contact: first name, last name, e-mail address, and an optional international-format phone number;
  • Optional address book: a user-selected label, billing-address lines, district, city, postal code, country, default-address choice, and record timestamps. Address contents are encrypted at rest and are stored only when you choose to save them;
  • Authentication: an Argon2id password hash, e-mail-verification state, and password-change state. Cogitave does not store your plaintext password;
  • Transaction security: one-way hashes of session, verification, recovery, and browser-profile credentials; session creation, expiry, and last-activity times; the five most recent sign-in outcomes and a general browser/device label; failed-login count and temporary lock time;
  • Legal acknowledgement: the version and timestamp of the notice presented and Account Terms accepted;
  • Commerce association: a keyed, one-way lookup value derived from the verified e-mail address is attached to new eligible order and subscription records so that the authenticated customer can view their own transaction history without storing an additional plaintext e-mail index;
  • Account operations: profile updates, session revocation, data export, and account-deletion state.

Payment-card data is not collected or stored by the customer-account system. Billing, order, accounting, and payment-provider records are separate transaction records.

3. Purposes and legal grounds

Processing purposeKVKK legal ground
Create and operate the account, verify the e-mail address, authenticate the member, recover access, maintain optional contact details and billing addresses, and prefill user-selected details into a supported checkout form.Necessary to establish or perform the Account Terms and the user-requested service transaction under Article 5/2(c).
Associate eligible service orders and recurring engagements with the verified customer identity and display their amount, provider, and status in the private account portal.Necessary to perform the applicable service or distance contract under Article 5/2(c), and necessary to comply with transaction-record obligations under Article 5/2(ç).
Prevent account takeover, investigate abuse, apply rate limits and temporary locks, preserve service integrity, and establish or defend legal claims.Necessary for the controller’s legitimate interests without harming fundamental rights under Article 5/2(f), and for establishment, exercise, or protection of a right under Article 5/2(e).
Respond to data-subject applications and comply with binding requests from authorised public bodies.Necessary to comply with legal obligations under Article 5/2(ç).

No marketing profile or commercial electronic-message permission is created through account registration. If Cogitave later offers marketing communication, it will use a separate, optional, unselected permission process.

4. Recipients and transfer purposes

Account data is disclosed only as necessary to infrastructure and hosting processors for secure storage and API operation; the configured transactional e-mail processor for verification, recovery, and security notifications; professional legal or security advisers where required to protect a right; and legally authorised public bodies for their lawful requests. Service providers act only for the stated operational purpose.

If a configured processor handles data outside Türkiye, activation must be preceded by the applicable KVKK cross-border transfer mechanism and safeguards. The production processor inventory and this notice must remain aligned; a provider change requires review before the new transfer begins.

5. Retention

  • An unverified registration is erased after 48 hours;
  • An e-mail verification link expires after 24 hours;
  • A password-reset link expires after 30 minutes;
  • An authenticated session expires after 12 hours and may be revoked sooner;
  • Authentication security events are retained for 90 days, while the account remains active, then erased automatically;
  • An active profile and optional saved billing addresses are retained until you delete the relevant data, delete the account, or another applicable erasure condition occurs;
  • After account deletion, the profile and access data are anonymised and sessions are revoked. Separate order, contract, invoice, tax, accounting, fraud-prevention, and dispute records remain only for their applicable statutory or legal-claims periods.

6. Automated processing

Automated controls validate form fields, verify token hashes, rate-limit requests, and temporarily lock sign-in after repeated failures. They do not create marketing profiles or make a legal or similarly significant decision about you.

7. Your rights and account controls

Under Article 11 of KVKK, you may learn whether and how your data is processed, learn recipients, request correction, request erasure or destruction where legal conditions apply, request notification of correction or erasure to recipients, object to an adverse result produced solely by automated analysis, and claim compensation for unlawful processing.

The account page provides direct controls to view eligible order and subscription status, update or remove optional phone and saved billing-address data, choose a default address, review and revoke sessions, change the password, download the account record, and delete the account. These controls do not limit your statutory application rights.

8. Applications

Send a request with sufficient information to verify your identity to the registered office shown above or to hello@cogitave.com. Requests are answered as soon as possible and no later than the statutory thirty-day period. Additional information may be requested only where necessary to verify identity and prevent disclosure to another person.

9. Version

Notice version: 2026-08-21. The version presented at registration is recorded so Cogitave can demonstrate which activity-specific notice was supplied.