Privacy Policy
This document explains how the HazırTest software processes personal data within the scope of the Turkish Personal Data Protection Law No. 6698 ("KVKK"). It covers both the HazırTest desktop application and the HazırTest mobile application (together, the "Applications"). The two applications use the same account, the same licence and the same back-end infrastructure, and are therefore described in a single policy. Matters that apply to only one of the applications are stated separately in the relevant article.
1. Data Controller and Contact
Serhat Demirok E-mail: destek@hazirtest.com Web: https://www.hazirtest.com
2. Two Different Roles: When We Are the Data Controller and When We Are the Data Processor
The data processed in the Applications falls into two groups, and our role differs in each group. This distinction matters because it determines who bears which obligations.
- For student and class data: the data controller is the teacher who enters the data, or the school/institution to which the teacher belongs; HazırTest is the data processor. The teacher decides whose student data will be entered, for what purpose it will be processed and for how long it will be retained. HazırTest stores and processes such data solely on the teacher's instructions, in order to provide the service.
- For the teacher's own account data: HazırTest is the data controller. Name and surname, e-mail address, subscription status, quota counters and technical error records are processed within the framework determined by HazırTest for the purposes of providing the service, billing and preventing misuse.
Because HazırTest itself determines purposes such as ensuring the security of the service, preventing misuse, resolving technical faults and complying with legal obligations, HazırTest acts as data controller with regard to these limited activities. The authority to decide for what purpose and for how long student and class data is processed, on the other hand, rests with the teacher/school.
3. Personal Data Processed and the Purposes of Processing
3.1. Account data (data controller: HazırTest)
- Name and surname, and e-mail address Purpose: creating an account, signing in, communication. Legal basis (KVKK art. 5): establishment and performance of a contract.
- Identity information received from the provider when signing in with Google or Apple Purpose: creating an account and signing in; verifying your identity without a password. The provider tells us only your e-mail address and, where it shares one, your name. The only thing sent to the provider is the sign-in request: none of your HazırTest data is transferred, and no access is requested to anything else in your account with that provider (contacts, files, calendar). If you choose "Hide My Email" when signing in with Apple, your real address never reaches us: your account is created with a relay address generated by Apple (@privaterelay.appleid.com) and the e-mails we send are forwarded to you through Apple. That choice makes the account a separate one; if the same person signs in both this way and with an e-mail address, two separate accounts are created. Legal basis (KVKK art. 5): establishment and performance of a contract.
- Licence/subscription status, scope and expiry date, monthly quota counters Purpose: licence verification, subscription management, enforcement of usage limits. Legal basis: performance of a contract and legitimate interest (prevention of misuse).
- A one-way digest (hash) of your device identifier, the device type, and monthly per-device counters Purpose: preventing misuse of the free usage allowance. The free monthly allowance is tied to the device; otherwise a person who exhausted it could reset the limit an unlimited number of times by registering with a new e-mail address. Your device's identifier never reaches us in plain form: it is converted on the device into a digest that cannot be reversed, and only that digest is transmitted. The digest is not used to recognise you in other contexts, to build a profile of you, or for advertising purposes. Legal basis: legitimate interest (prevention of misuse).
3.2. Student and examination data (data controller: teacher/school, data processor: HazırTest)
- Student's name, surname, student number and class information
- Parent's telephone number and student e-mail address, where the teacher chooses to enter them
- Examination, booklet and course definitions, answer keys, optical reading results Purpose: provision of the service; creating examinations, reading forms, producing results and report cards, synchronising between the user's devices. Legal basis: processing on the instructions of the data controller (teacher/school).
This data is stored solely in connection with your account and is protected by row-level access restrictions; no other user can see it. The sole exception is mock exam results that the teacher expressly chooses to publish (clause 3.4).
3.3. Technical data (data controller: HazırTest)
- Crash and error records (error message, software version, operating system type, technical log) Purpose: improving the stability and security of the software and fixing errors. Legal basis: legitimate interest.
The aim is not to collect personal data in crash and error records: your account identity (name and surname, e-mail, user number) is not added to these records by us, and the records are not intended to contain students' personal data. However, depending on the configuration of the technical service provider used, information such as device type, operating system, application version, error message and technical log may be processed, together with installation/session identifiers generated by the provider. Error messages may contain technical details such as file paths.
3.4. School Results Portal (data controller: school/teacher, data processor: HazırTest)
A teacher covered by a school licence may publish, on behalf of the school, the results of a multi-subject mock exam read in the desktop application by choosing "Publish on the web". Each publication is a separate and express decision of the teacher for that exam; nothing is published automatically. Students view the published results at https://sonuc.hazirtest.com using the school's institution code and their own student number.
- Published data: the student number; correct, wrong and blank answers, net score and score, per section and in total. Depending on the settings the teacher leaves enabled when publishing, additionally: name-surname and class, rank within the class and the school, and the answers the student gave together with the correct answers. Information that is switched off is never sent to the server.
- Who can see it: no password is required to open the page; anyone who knows the institution code and the student number can see that student's published results. For this reason the teacher can switch off the display of names and can withdraw the publication at any time. Rankings never show other students' numbers or names. The school administrator can see and withdraw every publication made on behalf of the school from the school panel.
- Prevention of misuse: the number of queries is limited in order to slow down number guessing. For this purpose a salted one-way digest of the IP address and the queried institution code–number pair are kept for at most 1 day; the IP address itself is not stored in plain form. Purpose: enabling the student to access their own results and progress. Legal basis: processing on the instructions of the data controller (school/teacher).
4. Data That Remains on Your Device and Is Never Sent to Our Servers
The following data is processed and stored solely on your own device:
- Optical form images and camera photographs. In the Applications, form reading, image processing and text recognition are performed entirely on the device; images that are captured or scanned are not uploaded to any server. Cloud backup and synchronisation features carry only data records in text form; they do not carry images.
- Question banks, generated form images and application logs. The sole exception is the Online Test feature of the desktop application: if you choose to publish an examination online, only the question content of that test (including any images contained in the questions) is uploaded to our servers under your account so that students can take the test. This is an express user action; if you delete the test, the uploaded content is also deleted from the server.
5. Differences Between the Applications
- Backup: in the mobile application, a signed-in user may, if they wish, upload a full backup of their data to the cloud area linked to their account; this backup consists of data records in text form and does not contain form images. The desktop application has no cloud backup; data is kept solely on your own device and backing it up is the user's responsibility.
- Crash reporting: the desktop application uses Sentry and the mobile application uses Firebase Crashlytics. In neither case is the account identity added to the records by us (see article 3.3).
- Purchases: in the mobile application, subscriptions are purchased through the Apple App Store or Google Play. On the desktop, the licence is issued through the website or by means of a school/institution code.
6. Use Without an Account (Guest)
When the Applications are used without an account, the data you enter (student, examination, question bank) is not sent to our servers; it remains on your device. There are two exceptions to this:
- Crash and error records: these may be sent even when you are not signed in, in order to monitor the stability of the application; their scope is explained in article 3.3.
- The one-way digest of your device identifier: because the free monthly usage allowance is tied to the device rather than to an account, this digest is also transmitted to the server for test generation and optical reading performed without an account, and the monthly counter is kept there (article 3.1). Without this exception, a person using the Applications without an account would have unlimited use, and a user who had exhausted their allowance could exceed the limit simply by signing out.
7. Method of Collecting Data
Data is collected electronically during registration and sign-in, through the user's own entries while the application is being used, and automatically while the application is running (technical error records, together with the digest of the device identifier described in article 3.1).
8. Service Providers (Sub-processors) and Transfer Abroad
The following third-party providers are used in order to provide the service. Each provider has access only to the data necessary for its own function:
- Supabase — account authentication, database and file hosting. Data transferred: account data and application data synchronised to the cloud. Servers: European Union.
- Sentry — desktop crash/error reporting. Data transferred: technical error records. Servers: Germany (European Union).
- RevenueCat — verification and management of mobile subscription status. Data transferred: user identifier, subscription/purchase status and device-level technical identifiers generated by the SDK (no advertising identifier/IDFA is collected). Servers: United States of America.
- Firebase Crashlytics — mobile crash/error reporting. Data transferred: technical error records and installation identifier. Servers: United States of America.
- Google and Apple (authentication) — only for users who choose to use "Continue with Google" or "Continue with Apple"; verification of the sign-in. Data transferred: the sign-in request. In return the provider reports the e-mail address and, where available, the name. If you do not use these options, no data whatsoever is transferred to these providers. Servers: United States of America.
- Apple App Store and Google Play — payment and subscription transactions in the mobile application. Data transferred: purchase and subscription information. Servers: United States of America.
- Cloudflare Turnstile — filtering automated (bot) submissions on the bank transfer notification form at hazirtest.com. Data transferred: IP address and verification data generated by the browser. No cookies are placed, visitors are not profiled and the form content itself is not transferred. Servers: United States of America.
- Vercel — hosting of the school administration panel (okul.hazirtest.com), the School Results Portal (sonuc.hazirtest.com, section 3.4) and the online test pages (test.hazirtest.com). Data transferred: requests to these pages (IP address, browser information and the requested address; on the School Results Portal the institution code and student number are part of the address) and the data shown on the page (student results, online test questions and answers). This data is not stored at Vercel; it is read from the database during the request, rendered into the page and sent. The provider's own technical request logs are kept for the period determined by the provider. Servers where the pages are generated: Germany (European Union); requests pass through the edge location nearest to the visitor. Vercel Inc. is established in the United States of America.
Student and examination data is stored solely on the Supabase infrastructure (European Union). Vercel processes this data only while generating pages, without storing it; no student data is transferred to RevenueCat, Apple, Google or Cloudflare.
Some of the providers listed above are established outside Türkiye; the relevant data is therefore transferred abroad. Article 9 of Law No. 6698 requires a condition to be met for transfers abroad (an adequacy decision, appropriate safeguard mechanisms, or the other cases enumerated in the law). Deciding which of these conditions will be relied upon, and ensuring that it is satisfied, is the responsibility of the data controller of the relevant data group:
- For student and examination data, the data controller is the teacher/school. By entering this data into the Applications, the teacher processes it in the knowledge that it will be hosted and processed on the servers specified above (located in the European Union); satisfying the transfer condition and providing the necessary disclosure is the responsibility of the teacher/school.
- For the account and technical data in respect of which HazırTest is the data controller, satisfying the transfer condition is HazırTest's responsibility.
For information about the legal basis of the transfer you may contact destek@hazirtest.com.
9. Payment Information
Information relating to credit cards, debit cards or other means of payment never reaches HazırTest. For mobile purchases, payment is handled entirely by Apple or Google; only the information as to whether the subscription is valid is communicated to us.
10. No Secondary Use of Data
Student data is processed solely in order to provide the service. This data is not used for advertising purposes, is not sold to or transferred to third parties for marketing purposes, is not used in the training of artificial intelligence models, and is not used for profiling.
11. Retention Period
- Account and licence data: retained for as long as the account is active and for the period required by the applicable legislation.
- Student and examination data: retained until the teacher deletes it or closes their account; the deletion instruction comes from the teacher as data controller.
- Online test student responses: the answers students give in the browser are kept on our servers while the test is published. If you unpublish a test and do not publish it again for 12 months, the student sessions belonging to that test (name, student number and the answers given) are deleted from the server automatically. If you chose to collect results, the scores already transferred to your own grade book are not affected by this deletion; they remain with you and are deleted only on your instruction.
- Results published on the School Results Portal (clause 3.4): every publication has an end date; if the teacher does not choose one, it is 12 months after publication. On the end date the results stop being visible to students and 30 days later they are deleted from the server automatically. When the teacher withdraws the publication or deletes the exam in the application, and when the school administrator deletes the publication from the panel, the results are deleted without waiting. If the teacher leaves the school licence, their publications stop being visible to students and are deleted in the same way according to their end date.
- Technical error records: kept for a limited period within the framework of the service provider's policies.
- Digest of the device identifier and monthly per-device counters: retained only for the duration of the current calendar month. When the month ends, both the counters and the device record are deleted automatically; they are not retained for any longer period.
- Record remaining after account deletion: the audit record of the deletion operation, together with a one-way digest of your e-mail address, your licence type and your licence expiry date, is retained. The purpose is to be able to restore an unexpired licence for a user who deletes their account by mistake, and to prove the deletion request in the event of a dispute. This record does NOT contain your name, your e-mail address in plain form, or your student or examination data; the record is deleted automatically 6 months after the licence expires (or, where there is no licence, after the date of deletion).
12. Deleting Your Account and Your Data
You may delete your account from within either application: on the desktop from Settings > Account, and on mobile from the account screen. The deletion covers all data linked to your account; your account record, your licence and usage information, your examination, student, course and reading-result data synchronised to the cloud, and the mock exam results you published on the School Results Portal are permanently deleted. You may also submit the same request at https://www.hazirtest.com/hesap-silme or via destek@hazirtest.com.
The "Delete all data" option in the desktop application deletes only the local data on your device; it does not close your account. Data stored locally on your device is deleted from the device when you uninstall the application or delete it from within the application.
There are two exceptions to deletion, and neither carries your identity:
- The deletion record described in article 11: a one-way digest of your e-mail address, your licence type, your licence expiry date and the date of deletion. It exists so that the licence of a user who deletes their account by mistake can be restored; it is deleted automatically once it expires. Your identity cannot be derived from this record — a match can be made only when you write your own e-mail address in your support request.
- Records that legislation requires us to retain (e.g. invoice/payment records) are retained for the statutory limitation period, in order to comply with legal obligations and to serve as evidence in any dispute.
Records of purchases made through the stores are held by Apple and Google; we have no authority to delete those records, and you must direct your request to the relevant store.
13. Data Security
Reasonable technical and administrative measures are taken to secure the personal data processed; data is encrypted in transit and protected by account-based access restrictions. It should nevertheless be understood that no transmission over the internet or electronic storage is 100% secure. The User is responsible for the security and regular backup of the local data on their own device.
14. The Teacher's Responsibility
Since the data controller for student data is the teacher/school, it is the teacher's obligation to provide the necessary disclosure to students and parents, to satisfy the legal conditions required for the processing of personal data, to ensure data security and the exercise of data subject rights, and to use the data in accordance with school legislation. Explicit consent may not be required for every processing activity; which processing condition is relied upon is a matter for the data controller's assessment. HazırTest processes this data solely on the teacher's instructions.
15. Cookies
The desktop and mobile applications do not use cookies for marketing purposes. The website https://www.hazirtest.com may use cookies for functionality and measurement purposes; the details are explained in the cookie notice on the site.
16. Rights of the Data Subject (KVKK art. 11)
As a data subject you have the following rights under article 11 of the Law:
- to learn whether your personal data is being processed;
- to request information if it has been processed;
- to learn the purpose of processing and whether the data is used in accordance with that purpose;
- to know the third parties in Türkiye or abroad to whom your data is transferred;
- to request rectification if the data has been processed incompletely or incorrectly;
- to request erasure or destruction within the conditions laid down in the Law;
- to request that rectification, erasure and destruction operations be notified to the third parties to whom the data has been transferred;
- to object to a result to your detriment arising from the analysis of the processed data exclusively by automated systems;
- to claim compensation for damage suffered as a result of unlawful processing.
To exercise these rights you may contact destek@hazirtest.com. Requests are concluded within the periods laid down in the KVKK.
With regard to student data, in respect of which HazırTest acts as data processor, requests are to be directed to the teacher/school as data controller; HazırTest provides the necessary support for such requests on the data controller's instructions. With regard to the activities in respect of which HazırTest is the data controller (account data, technical records, security and prevention of misuse), data subjects may apply directly to HazırTest.
17. Changes
This Privacy Policy may be updated from time to time. The current version is always published at https://www.hazirtest.com/gizlilik-politikasi; significant changes are notified to the User.
18. Contact
Serhat Demirok E-mail: destek@hazirtest.com Web: https://www.hazirtest.com
Gizlilik Politikası
Bu belge, HazırTest yazılımının kişisel verileri nasıl işlediğini 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamında açıklar. Belge, HazırTest masaüstü uygulaması ile HazırTest mobil uygulamasının (birlikte "Uygulamalar") tamamını kapsar. İki uygulama aynı hesabı, aynı lisansı ve aynı arka uç altyapısını kullanır; bu nedenle tek bir politika ile açıklanır. Yalnızca bir uygulamaya özgü hususlar, ilgili maddede ayrıca belirtilmiştir.
1. Veri Sorumlusu ve İletişim
Serhat Demirok E-posta: destek@hazirtest.com Web: https://www.hazirtest.com
2. İki Farklı Rol: Ne Zaman Veri Sorumlusuyuz, Ne Zaman Veri İşleyeniz
Uygulamalar'da işlenen veriler iki gruba ayrılır ve her grupta rolümüz farklıdır. Bu ayrım, yükümlülüklerin kime ait olduğunu belirlediği için önemlidir.
- Öğrenci ve sınıf verileri bakımından: Veri sorumlusu, verileri giren öğretmen ya da bağlı olduğu okul/kurumdur; HazırTest veri işleyendir. Hangi öğrencinin verisinin gireceğine, hangi amaçla işleneceğine ve ne kadar saklanacağına öğretmen karar verir. HazırTest bu verileri yalnızca öğretmenin talimatı doğrultusunda, hizmeti sunmak için saklar ve işler.
- Öğretmenin kendi hesap verileri bakımından: HazırTest veri sorumlusudur. Ad-soyad, e-posta, abonelik durumu, kota sayaçları ve teknik hata kayıtları; hizmetin sunulması, faturalandırma ve kötüye kullanımın önlenmesi amacıyla HazırTest'in belirlediği çerçevede işlenir.
Hizmetin güvenliğinin sağlanması, kötüye kullanımın önlenmesi, teknik arızaların giderilmesi ve yasal yükümlülüklerin yerine getirilmesi gibi amaçları HazırTest kendisi belirlediğinden, bu sınırlı faaliyetler bakımından HazırTest veri sorumlusu sıfatıyla hareket eder. Öğrenci ve sınıf verilerinin hangi amaçla ve ne kadar süreyle işleneceğine karar verme yetkisi ise öğretmen/okuldadır.
3. İşlenen Kişisel Veriler ve Amaçları
3.1. Hesap verileri (veri sorumlusu: HazırTest)
- Ad-soyad ve e-posta adresi Amaç: Hesap oluşturma, giriş, iletişim. Hukuki sebep (KVKK m.5): Sözleşmenin kurulması ve ifası.
- Google veya Apple ile giriş kullanıldığında sağlayıcıdan alınan kimlik bilgisi Amaç: Hesap oluşturma ve giriş; parola girmeden kimliğin doğrulanması. Sağlayıcı bize yalnızca e-posta adresinizi ve (paylaşıyorsa) ad-soyadınızı bildirir. Sağlayıcıya gönderilen tek şey giriş talebidir: HazırTest'teki verileriniz aktarılmaz ve sağlayıcıdaki başka hiçbir bilginize (kişi listesi, dosyalar, takvim) erişim istenmez. Apple ile girişte "E-postamı gizle" seçilirse gerçek adresiniz bize hiç ulaşmaz: hesabınız Apple'ın ürettiği bir yönlendirme adresiyle (@privaterelay.appleid.com) açılır ve size gönderdiğimiz e-postalar Apple üzerinden iletilir. Bu seçim hesabınızı ayrı bir hesap yapar; aynı kişi hem bu yolla hem e-posta adresiyle giriş yaparsa iki ayrı hesap oluşur. Hukuki sebep (KVKK m.5): Sözleşmenin kurulması ve ifası.
- Lisans/abonelik durumu, kapsam ve bitiş tarihi, aylık kota sayaçları Amaç: Lisans doğrulama, abonelik yönetimi, kullanım sınırlarının uygulanması. Hukuki sebep: Sözleşmenin ifası ve meşru menfaat (kötüye kullanımın önlenmesi).
- Cihaz tanımlayıcısının tek yönlü özeti (hash), cihaz türü ve aylık cihaz sayaçları Amaç: Ücretsiz kullanım hakkının kötüye kullanılmasını önlemek. Ücretsiz aylık hak cihaza bağlıdır; aksi hâlde hakkını dolduran bir kişi yeni bir e-posta ile hesap açarak sınırı sınırsız kez sıfırlayabilirdi. Cihazınızın kimliği bize düz hâliyle hiçbir zaman ulaşmaz: cihazda geri çevrilemez bir özete dönüştürülür ve yalnızca bu özet iletilir. Özet, sizi başka bağlamlarda tanımak, profilinizi çıkarmak veya reklam amacıyla kullanılmaz. Hukuki sebep: Meşru menfaat (kötüye kullanımın önlenmesi).
3.2. Öğrenci ve sınav verileri (veri sorumlusu: öğretmen/okul, veri işleyen: HazırTest)
- Öğrenci adı, soyadı, öğrenci numarası ve sınıf bilgisi
- Öğretmenin isteğe bağlı olarak girdiği veli telefonu ve öğrenci e-posta adresi
- Sınav, kitapçık ve ders tanımları, cevap anahtarları, optik okuma sonuçları Amaç: Hizmetin sunulması; sınav oluşturma, form okuma, sonuç ve karne üretimi, kullanıcının cihazları arasında eşitleme. Hukuki sebep: Veri sorumlusunun (öğretmen/okul) talimatı doğrultusunda işleme.
Bu veriler yalnızca hesabınıza bağlı olarak saklanır ve satır bazlı erişim kısıtlarıyla korunur; başka bir kullanıcı bu verileri göremez. Tek istisna, öğretmenin açıkça yayınlamayı seçtiği deneme sonuçlarıdır (madde 3.4).
3.3. Teknik veriler (veri sorumlusu: HazırTest)
- Çökme ve hata kayıtları (hata mesajı, yazılım sürümü, işletim sistemi türü, teknik günlük) Amaç: Yazılım kararlılığını ve güvenliğini artırmak, hataları gidermek. Hukuki sebep: Meşru menfaat.
Çökme ve hata kayıtlarında kişisel veri toplanmaması hedeflenir: hesabınızın kimliği (ad-soyad, e-posta, kullanıcı numarası) bu kayıtlara tarafımızca eklenmez ve kayıtlar öğrenci kişisel verilerini içermeyi amaçlamaz. Bununla birlikte, kullanılan teknik hizmet sağlayıcının yapılandırmasına bağlı olarak cihaz türü, işletim sistemi, uygulama sürümü, hata mesajı ve teknik günlük gibi bilgiler ile sağlayıcı tarafından üretilen kurulum/oturum tanımlayıcıları işlenebilir. Hata mesajları, dosya yolu gibi teknik ayrıntılar içerebilir.
3.4. Okul Sonuç Portalı (veri sorumlusu: okul/öğretmen, veri işleyen: HazırTest)
Okul lisansı kapsamındaki bir öğretmen, masaüstü uygulamasında okuduğu çok dersli bir denemenin sonuçlarını "Web'de yayınla" diyerek okul adına yayınlayabilir. Yayın her deneme için ayrı ve açık bir öğretmen kararıdır; kendiliğinden yapılmaz. Yayınlanan sonuçları öğrenciler https://sonuc.hazirtest.com adresinde, okulun kurum kodu ve kendi öğrenci numaralarıyla görür.
- Yayınlanan veriler: Öğrenci numarası; bölüm bölüm ve toplamda doğru, yanlış, boş, net ve puan. Öğretmenin yayın sırasında açık bıraktığı ayara göre ayrıca: ad-soyad ve sınıf, sınıf ve okul içi sıra, öğrencinin verdiği cevaplar ile doğru cevaplar. Kapatılan bilgi sunucuya hiç gönderilmez.
- Kimler görebilir: Sayfaya giriş için şifre istenmez; kurum kodunu ve öğrenci numarasını bilen herkes o öğrencinin yayınlanmış sonuçlarını görebilir. Öğretmen bu nedenle ad-soyad gösterimini kapatabilir ve yayını dilediği an kaldırabilir. Sıralamada başka öğrencilerin numarası veya adı gösterilmez. Okul yöneticisi, okulu adına yapılmış bütün yayınları okul panelinden görebilir ve kaldırabilir.
- Kötüye kullanımın önlenmesi: Numara taramasını yavaşlatmak için sorgu sayısı sınırlanır. Bunun için IP adresinin tuzlanmış tek yönlü özeti ve sorgulanan kurum kodu–numara ikilisi en fazla 1 gün tutulur; IP adresinin düz hâli saklanmaz. Amaç: Öğrencinin kendi sonucuna ve gelişimine erişmesi. Hukuki sebep: Veri sorumlusunun (okul/öğretmen) talimatı doğrultusunda işleme.
4. Cihazınızda Kalan ve Sunucularımıza Hiç Gönderilmeyen Veriler
Aşağıdaki veriler yalnızca kendi cihazınızda işlenir ve saklanır:
- Optik form görüntüleri ve kamera fotoğrafları. Uygulamalar'da form okuma, görüntü işleme ve metin tanıma tamamen cihaz üzerinde yapılır; çekilen veya taranan görüntüler hiçbir sunucuya yüklenmez. Bulut yedekleme ve eşitleme özellikleri yalnızca metin biçimindeki veri kayıtlarını taşır, görüntü taşımaz.
- Soru bankaları, üretilen form görüntüleri ve uygulama günlükleri. Tek istisna, masaüstü uygulamasındaki Çevrimiçi Test özelliğidir: bir sınavı çevrimiçi yayımlamayı seçerseniz, öğrencilerin testi çözebilmesi için yalnızca o testin soru içeriği (varsa sorulardaki görseller dahil) hesabınıza bağlı olarak sunucularımıza yüklenir. Bu, açık bir kullanıcı eylemidir; testi sildiğinizde yüklenen içerik sunucudan da silinir.
5. Uygulamalar Arasındaki Farklar
- Yedekleme: Mobil uygulamada, giriş yapmış kullanıcı isterse verilerinin tam yedeğini hesabına bağlı bulut alanına yükleyebilir; bu yedek metin biçiminde veri kayıtlarından oluşur, form görüntüleri içermez. Masaüstü uygulamasında bulut yedeği yoktur; veriler yalnızca kendi cihazınızda tutulur ve yedeklenmesi kullanıcının sorumluluğundadır.
- Çökme raporlaması: Masaüstü uygulaması Sentry, mobil uygulama Firebase Crashlytics kullanır. Her ikisinde de hesap kimliği kayıtlara tarafımızca eklenmez (bkz. madde 3.3).
- Satın alma: Mobil uygulamada abonelik Apple App Store veya Google Play üzerinden alınır. Masaüstünde lisans, web sitesi üzerinden ya da okul/kurum kodu ile tanımlanır.
6. Hesap Açmadan (Misafir) Kullanım
Hesap açmadan kullanımda girdiğiniz veriler (öğrenci, sınav, soru bankası) sunucularımıza gönderilmez; cihazınızda kalır. Bunun iki istisnası vardır:
- Çökme ve hata kayıtları: Uygulamanın kararlılığını izlemek için oturum açılmasa da gönderilebilir; kapsamı madde 3.3'te açıklanmıştır.
- Cihaz tanımlayıcısının tek yönlü özeti: Ücretsiz aylık kullanım hakkı hesaba değil cihaza bağlı olduğundan, hesap açmadan yapılan test üretimi ve optik okuma işlemlerinde de bu özet sunucuya iletilir ve aylık sayaç orada tutulur (madde 3.1). Bu istisna olmasaydı hesap açmadan kullanan bir kişi sınırsız kullanır, hakkını dolduran bir kullanıcı da çıkış yaparak sınırı aşabilirdi.
7. Verilerin Toplanma Yöntemi
Veriler; kayıt ve giriş sırasında elektronik ortamda, uygulama kullanılırken kullanıcının kendi girişleriyle ve uygulama çalışırken otomatik olarak (teknik hata kayıtları ile madde 3.1'de açıklanan cihaz tanımlayıcısı özeti) toplanır.
8. Hizmet Sağlayıcılar (Alt İşleyenler) ve Yurt Dışına Aktarım
Hizmeti sunmak için aşağıdaki üçüncü taraf sağlayıcılar kullanılır. Her sağlayıcı yalnızca kendi işlevi için gerekli veriye erişir:
- Supabase — hesap kimlik doğrulama, veritabanı ve dosya barındırma. Aktarılan: hesap verileri ve buluta eşitlenen uygulama verileri. Sunucular: Avrupa Birliği.
- Sentry — masaüstü çökme/hata raporlaması. Aktarılan: teknik hata kayıtları. Sunucular: Almanya (Avrupa Birliği).
- RevenueCat — mobil abonelik durumunun doğrulanması ve yönetimi. Aktarılan: kullanıcı kimliği, abonelik/satın alma durumu ve SDK'nın ürettiği cihaz düzeyinde teknik tanımlayıcılar (reklam kimliği/IDFA toplanmaz). Sunucular: Amerika Birleşik Devletleri.
- Firebase Crashlytics — mobil çökme/hata raporlaması. Aktarılan: teknik hata kayıtları ve kurulum tanımlayıcısı. Sunucular: Amerika Birleşik Devletleri.
- Google ve Apple (kimlik doğrulama) — yalnızca "Google ile devam et" veya "Apple ile devam et" seçeneğini kullanmayı tercih eden kullanıcılar için; girişin doğrulanması. Aktarılan: giriş talebi. Sağlayıcı karşılığında e-posta adresini ve varsa ad-soyadı bildirir. Bu seçenekleri kullanmazsanız bu sağlayıcılara hiçbir veri aktarılmaz. Sunucular: Amerika Birleşik Devletleri.
- Apple App Store ve Google Play — mobil uygulamada ödeme ve abonelik işlemleri. Aktarılan: satın alma ve abonelik bilgisi. Sunucular: Amerika Birleşik Devletleri.
- Cloudflare Turnstile — hazirtest.com üzerindeki havale bildirim formunda otomatik (bot) gönderimlerin ayıklanması. Aktarılan: IP adresi ve tarayıcının ürettiği doğrulama verisi. Çerez yerleştirilmez, ziyaretçi profillenmez ve form verisinin kendisi aktarılmaz. Sunucular: Amerika Birleşik Devletleri.
- Vercel — okul yönetim paneli (okul.hazirtest.com), Okul Sonuç Portalı (sonuc.hazirtest.com, madde 3.4) ve online test sayfalarının (test.hazirtest.com) barındırılması. Aktarılan: bu sayfalara gelen istekler (IP adresi, tarayıcı bilgisi ve istenen adres; Okul Sonuç Portalı'nda kurum kodu ve öğrenci numarası adresin parçasıdır) ile sayfada gösterilen veriler (öğrenci sonuçları, online test soruları ve yanıtları). Bu veriler Vercel'de saklanmaz; istek sırasında veritabanından okunur, sayfaya dönüştürülür ve gönderilir. Sağlayıcının kendi teknik istek kayıtları, sağlayıcının belirlediği süre boyunca tutulur. Sayfaların üretildiği sunucular: Almanya (Avrupa Birliği); istekler ziyaretçiye en yakın uç noktadan geçer. Vercel Inc. Amerika Birleşik Devletleri'nde yerleşiktir.
Öğrenci ve sınav verileri yalnızca Supabase altyapısında (Avrupa Birliği) saklanır. Vercel bu verileri yalnızca sayfa üretilirken, saklamadan işler; RevenueCat, Apple, Google ve Cloudflare'e öğrenci verisi aktarılmaz.
Yukarıdaki sağlayıcıların bir kısmı Türkiye dışında yerleşiktir; bu nedenle ilgili veriler yurt dışına aktarılmaktadır. 6698 sayılı Kanun'un 9. maddesi, yurt dışına aktarım için bir şart aranmasını öngörür (yeterlilik kararı, uygun güvence mekanizmaları veya kanunda sayılan diğer haller). Bu şartın hangisine dayanılacağına karar vermek ve sağlamak, ilgili veri grubunun veri sorumlusuna aittir:
- Öğrenci ve sınav verileri bakımından veri sorumlusu öğretmen/okuldur. Bu verileri Uygulamalar'a girmekle, verilerin yukarıda belirtilen (Avrupa Birliği'nde bulunan) sunucularda barındırılacağını ve işleneceğini bilerek işlemiş olur; aktarım şartını sağlamak ve gerekli aydınlatmayı yapmak öğretmenin/okulun sorumluluğundadır.
- HazırTest'in veri sorumlusu olduğu hesap ve teknik veriler bakımından aktarım şartını sağlamak HazırTest'e aittir.
Aktarımın hukuki dayanağı hakkında bilgi almak için destek@hazirtest.com adresine başvurabilirsiniz.
9. Ödeme Bilgileri
Kredi kartı, banka kartı veya diğer ödeme araçlarına ilişkin bilgiler HazırTest'e hiçbir zaman ulaşmaz. Mobil satın almalarda ödeme tamamen Apple veya Google tarafından yürütülür; bize yalnızca aboneliğin geçerli olup olmadığı bilgisi iletilir.
10. Verilerin İkincil Kullanımı Yoktur
Öğrenci verileri yalnızca hizmeti sunmak için işlenir. Bu veriler reklam amacıyla kullanılmaz, üçüncü taraflara satılmaz veya pazarlama amacıyla aktarılmaz, yapay zekâ modeli eğitiminde kullanılmaz ve profilleme yapılmaz.
11. Saklama Süresi
- Hesap ve lisans verileri: Hesap etkin olduğu sürece ve ilgili mevzuatın gerektirdiği süre boyunca saklanır.
- Öğrenci ve sınav verileri: Öğretmen silene ya da hesabını kapatana kadar saklanır; silme talimatı veri sorumlusu olan öğretmenden gelir.
- Online test öğrenci yanıtları: Öğrencilerin tarayıcıda verdiği cevaplar, test yayında olduğu sürece sunucuda saklanır. Testi yayından kaldırdıktan sonra 12 ay boyunca yeniden yayına almazsanız, o teste ait öğrenci oturumları (ad-soyad, öğrenci numarası ve verilen cevaplar) sunucudan otomatik olarak silinir. Sonuçları toplamayı seçtiyseniz kendi not defterinize aktarılmış puanlar bu silmeden etkilenmez; onlar sizde kalır ve silinmesi sizin talimatınıza bağlıdır.
- Okul Sonuç Portalı'nda yayınlanan sonuçlar (madde 3.4): Her yayının bir bitiş tarihi vardır; öğretmen seçmezse yayın tarihinden 12 ay sonradır. Bitiş tarihinde sonuçlar öğrencilere görünmez olur, 30 gün sonra da sunucudan otomatik olarak silinir. Öğretmen yayını kaldırdığında ya da denemeyi uygulamadan sildiğinde ve okul yöneticisi yayını panelden sildiğinde sonuçlar beklemeden silinir. Öğretmen okul lisansından ayrılırsa yayınları öğrencilere görünmez olur ve bitiş tarihine göre aynı şekilde silinir.
- Teknik hata kayıtları: Hizmet sağlayıcının politikaları çerçevesinde sınırlı bir süre tutulur.
- Cihaz tanımlayıcısının özeti ve aylık cihaz sayaçları: Yalnızca içinde bulunulan takvim ayı boyunca saklanır. Ay bittiğinde hem sayaçlar hem de cihaz kaydı otomatik olarak silinir; daha uzun süre saklanmaz.
- Hesap silindikten sonra kalan kayıt: Silme işleminin denetim kaydı ile e-postanızın tek yönlü özeti, lisans tipiniz ve lisans bitiş tarihiniz saklanır. Amaç, hesabını yanlışlıkla silen bir kullanıcının süresi dolmamış lisansını geri verebilmek ve olası uyuşmazlıklarda silme talebini kanıtlayabilmektir. Bu kayıtta adınız, e-postanızın düz hâli, öğrenci veya sınav veriniz BULUNMAZ; kayıt lisans bitişinden (lisans yoksa silme tarihinden) 6 ay sonra otomatik olarak silinir.
12. Hesabınızı ve Verilerinizi Silme
Hesabınızı her iki uygulamada da uygulama içinden silebilirsiniz: masaüstünde Ayarlar > Hesap bölümünden, mobilde hesap ekranından. Silme işlemi hesabınıza bağlı tüm verileri kapsar; hesap kaydınız, lisans ve kullanım bilgileriniz ile buluta eşitlenmiş sınav, öğrenci, ders ve okuma sonucu verileriniz ile Okul Sonuç Portalı'nda yayınladığınız deneme sonuçları kalıcı olarak silinir. Aynı talebi https://www.hazirtest.com/hesap-silme adresinden veya destek@hazirtest.com üzerinden de iletebilirsiniz.
Masaüstü uygulamasındaki "Tüm verileri sil" seçeneği yalnızca cihazınızdaki yerel verileri siler, hesabınızı kapatmaz. Cihazınızda yerel olarak saklanan veriler, uygulamayı kaldırdığınızda ya da uygulama içinden sildiğinizde cihazdan silinir.
Silmenin iki istisnası vardır ve ikisi de kimliğinizi taşımaz:
- Madde 11'de anlatılan silme kaydı: e-postanızın tek yönlü özeti, lisans tipiniz, lisans bitiş tarihiniz ve silme tarihi. Hesabını yanlışlıkla silen kullanıcının lisansını geri verebilmek içindir; süresi dolduğunda otomatik silinir. Bu kayıttan kimliğinize ulaşılamaz — yalnızca destek talebinizde kendi e-postanızı yazdığınızda eşleşme yapılabilir.
- Mevzuatın saklamamızı zorunlu kıldığı kayıtlar (ör. fatura/ödeme kayıtları), yasal yükümlülüklerin yerine getirilmesi ve olası uyuşmazlıklarda delil olmak üzere kanuni zamanaşımı süresince saklanır.
Mağaza üzerinden yapılan satın almaların kayıtları Apple ve Google tarafında tutulur; bu kayıtlar üzerinde silme yetkimiz yoktur, talebinizi ilgili mağazaya iletmeniz gerekir.
13. Veri Güvenliği
İşlenen kişisel verilerin güvenliği için makul teknik ve idari tedbirler alınır; veriler aktarım sırasında şifrelenir ve hesap bazlı erişim kısıtlarıyla korunur. Ancak internet üzerinden hiçbir aktarımın veya elektronik saklamanın %100 güvenli olmadığı bilinmelidir. Kullanıcı, kendi cihazındaki yerel verilerin güvenliği ve düzenli yedeklenmesinden sorumludur.
14. Öğretmenin Sorumluluğu
Öğrenci verileri bakımından veri sorumlusu öğretmen/okul olduğundan; öğrenci ve velilere gerekli aydınlatmanın yapılması, kişisel verilerin işlenmesi için gerekli hukuki şartların sağlanması, veri güvenliğinin ve ilgili kişi haklarının yerine getirilmesi ile verilerin okul mevzuatına uygun kullanılması öğretmenin yükümlülüğündedir. Her işleme faaliyeti için açık rıza gerekmeyebilir; hangi işleme şartına dayanılacağı veri sorumlusunun değerlendirmesine bağlıdır. HazırTest, bu verileri yalnızca öğretmenin talimatıyla işler.
15. Çerezler
Masaüstü ve mobil uygulamalar pazarlama amaçlı çerez kullanmaz. https://www.hazirtest.com web sitesi, işlevsellik ve ölçümleme amacıyla çerez kullanabilir; ayrıntılar sitedeki çerez bildiriminde açıklanır.
16. İlgili Kişinin Hakları (KVKK m.11)
Kişisel veri sahibi olarak Kanun'un 11. maddesi uyarınca şu haklara sahipsiniz:
- Kişisel verinizin işlenip işlenmediğini öğrenme;
- İşlenmişse buna ilişkin bilgi talep etme;
- İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme;
- Yurt içinde veya yurt dışında verilerinizin aktarıldığı üçüncü kişileri bilme;
- Eksik veya yanlış işlenmişse düzeltilmesini isteme;
- Kanun'da öngörülen şartlar çerçevesinde silinmesini veya yok edilmesini isteme;
- Düzeltme, silme ve yok etme işlemlerinin, verilerin aktarıldığı üçüncü kişilere bildirilmesini isteme;
- İşlenen verilerin münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç ortaya çıkmasına itiraz etme;
- Kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme.
Bu haklarınızı kullanmak için destek@hazirtest.com adresine başvurabilirsiniz. Talepler, KVKK'da öngörülen süreler içinde sonuçlandırılır.
HazırTest'in veri işleyen olarak hareket ettiği öğrenci verileri bakımından talepler, veri sorumlusu olan öğretmen/okula yöneltilir; HazırTest bu taleplerde veri sorumlusunun talimatı doğrultusunda gerekli desteği sağlar. HazırTest'in veri sorumlusu olduğu faaliyetler (hesap verileri, teknik kayıtlar, güvenlik ve kötüye kullanımın önlenmesi) bakımından ise ilgili kişiler doğrudan HazırTest'e başvurabilir.
17. Değişiklikler
Bu Gizlilik Politikası zaman zaman güncellenebilir. Güncel sürüm her zaman https://www.hazirtest.com/gizlilik-politikasi adresinde yayımlanır; önemli değişiklikler Kullanıcı'ya bildirilir.
18. İletişim
Serhat Demirok E-posta: destek@hazirtest.com Web: https://www.hazirtest.com