Datenschutz
VALIZU
Privacy Policy
Data Controller: Percon Bilişim Çözümleri ve Danışmanlık A.Ş. (Percon Information Solutions and Consulting Inc.)
Address: Büyükdere Cad. Meydan Sok. No:1 Beybi Giz Plaza Floor:15, Maslak, Sarıyer/İstanbul, Türkiye
Application: Valizu mobile application (iOS / Android)
Effective Date: 1.5.2026
I. Introduction
This Privacy Policy (“Policy”) sets out the principles applied by Percon Bilişim Çözümleri ve Danışmanlık A.Ş. (Percon Information Solutions and Consulting Inc.) (“Percon”, “we”) to the processing of personal data within the Valizu mobile application. It is based on the EU GDPR, the UK GDPR, the CCPA/CPRA and Turkish Law No. 6698 (KVKK). A concise, user-facing summary is also provided in our Privacy Notice. In the event of any conflict, applicable mandatory law prevails.
II. Controller, Representatives and Regulatory Status
Data Controller: Percon Bilişim Çözümleri ve Danışmanlık A.Ş. (Percon Information Solutions and Consulting Inc.), Büyükdere Cad. Meydan Sok. No:1 Beybi Giz Plaza Floor:15, Maslak, Sarıyer/İstanbul, Türkiye.
EU Representative (GDPR Art. 27): Ender Ekinci (citizen of the Federal Republic of Germany), [Full address of the EU Representative in Germany to be inserted here].
UK Representative (UK GDPR Art. 27): Ender Ekinci (citizen of the Federal Republic of Germany), [full UK contact address to be inserted].
Turkish VERBİS: Percon does not exceed the employee-count and balance-sheet thresholds set out in the Turkish Data Controllers' Registry Regulation and is therefore not required to register with VERBİS. This does not affect Percon's other obligations under the KVKK, with which it complies.
III. Data Protection Principles
We process personal data in line with the principles of: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
IV. Categories of Data and Data Subjects
We process the personal data of App users and prospective users. The categories of data are described in the Privacy Notice (identity & profile, contact, account & transaction, location, travel, luggage content, transaction security, customer support and – with consent – marketing data). Employee and visitor data are governed by a separate internal policy.
V. Purposes and Legal Bases
Personal data are processed for service delivery, account management, subscription and payment, support, security and legal compliance, and – with consent – analytics and marketing. Each purpose is mapped to a legal basis under GDPR Art. 6 (and Art. 9 for special categories). Consent-based processing is governed by the Consent Declaration and may be withdrawn at any time.
VI. Special Categories of Data
We do not, as a rule, process special categories of data. If a user voluntarily uploads documents such as a passport, visa or health certificate to the image-upload areas of the App, such data is processed solely on the basis of the user's explicit consent, for the purpose of organising travel documents and limited to that purpose. We advise users not to upload such documents.
VII. International Transfers
Because we use cloud infrastructure, payment intermediaries and technical support providers, personal data is transferred to the United States and the European Union via Google LLC (Firebase), RevenueCat Inc., ipinfo.io, Apple Inc. and Google Play. A detailed transfer table appears in the Privacy Notice. Transfers rely on the EU SCCs (Module 2) and, where applicable, the EU-U.S. Data Privacy Framework; for transfers governed by Turkish law, on the standard contract published by the Turkish Data Protection Board, notified to it within five business days. We carry out Transfer Impact Assessments for U.S. transfers.
VIII. Retention and Erasure
We retain personal data for the periods set out in the Privacy Notice and conduct a periodic erasure process at least every six months. Data whose retention period has expired is deleted, destroyed or anonymised.
IX. Security
We apply appropriate technical and organisational measures under GDPR Art. 32 and KVKK Art. 12, including least-privilege access controls, encryption, firewalls and malware protection, regular backups, written DPAs with processors, staff confidentiality undertakings and training, and logging.
X. Data Breach Management
On detecting a personal data breach, we notify the competent supervisory authority within 72 hours and, where there is a high risk to individuals' rights and freedoms, notify affected data subjects without undue delay via in-app notification and email. Breach records are retained for at least five years.
XI. Cookies and Mobile Identifiers
Our website and App use essential, functional, analytics and marketing cookies and SDKs. Non-essential technologies are activated only after consent. See the Cookie Policy.
XII. Rights and Complaints
Data subjects may exercise their rights under GDPR/UK GDPR Art. 15-22, KVKK Art. 11 and the CCPA/CPRA by contacting privacy@valizu.com. EU/UK residents may lodge a complaint with their local supervisory authority; California residents may contact the California Privacy Protection Agency or the California Attorney General; Turkish residents may apply to the Turkish Data Protection Board.
XIII. Children
Valizu is intended for users aged 18+. Children's services are provided through the separate Ferientiger application, which has its own privacy notice and verifiable parental consent process.
XIV. Governance and Contact
For all data protection queries: privacy@valizu.com | general contact: info@valizu.com | phone: +90 536 327 59 91. We update this Policy as needed and publish the current version in the App.
