KVKK PRIVACY NOTICE
Privacy & Personal Data Notice
This Notice explains BiteScore's current core processing, its minimum-data 13+ account-age declaration and the separate explicit-consent boundary for optional first-party telemetry. BiteData business access and demographic collection remain off.
Privacy At A Glance
The data controller is Ömer Taha Tonbaklar; legal@bitescore.co is the published Privacy contact. This short layer highlights the points most likely to affect your decision. The numbered sections below remain the complete Notice.
- BiteScore processes the account, security and service records needed to provide and protect its ordinary product-discovery, rating and community functions.
- BiteData business access is currently disabled. No organisation, brand, customer or other external business user receives a BiteData dashboard, export, API, alert, product-intelligence output, public-review text or representative excerpt.
- Reviews and ratings submitted while BiteData is disabled are used only for the ordinary BiteScore service, including core scoring, in-service discovery, security, abuse prevention and moderation. They do not acquire present or future commercial BiteData eligibility from this edition.
- BiteData demographic collection is currently disabled. BiteScore does not offer a new BiteData demographic-consent choice or collect birth year, demographic gender category or province code for that purpose under this edition. Any historical record is not an active BiteData input or permission.
- Optional first-party product-experience telemetry remains a separate choice. It does not authorise BiteData, advertising, cross-service tracking, a data-broker profile or disclosure of review material to an organisation.
- A future BiteData launch requires newly published Terms, Privacy Notice and Community Rules, updated store privacy declarations, a new just-in-time choice wherever consent is relied on, and prospective acceptance before the new processing begins. Accepting this edition cannot activate BiteData.
- Contributions made before a future activation are not retrospectively made commercially eligible by a switch, a threshold being reached or acceptance of future general terms. Commercial eligibility must begin prospectively under the new release and its required contribution flow.
- You can use the in-product export, deletion and optional-telemetry controls and the KVKK application channels described below.
1. Data Controller
The following operator is the data controller for BiteScore's website, mobile application and related services under Turkish Personal Data Protection Law No. 6698 (KVKK).
- Legal name: Ömer Taha Tonbaklar
- Email: legal@bitescore.co
2. Personal Data We Process
- Minimum-data account-age proof: one affirmative confirmation that the account holder is at least 13, the exact age-policy edition carried by the acceptance request and the server acceptance time. The durable current legal-evidence row stores the server timestamp; BiteScore does not collect or derive an age band, full date of birth, birth month or birth year for account eligibility.
- Account and identity data: email, username, account identifiers, authentication provider, password hash and verification status.
- Profile and community content: display name, biography, avatar, reviews, ratings, factor scores, lists, comments, reports, messages and the people or content you interact with.
- Service activity: likes, follows/friendships, votes, gifts, BiteCoin/XP/level activity, notification preferences and account settings.
- Technical and security data: IP address, user agent, device/app version, request and audit logs, session identifiers, push token, crash/security signals and consent records.
- Optional device data: photos selected for an avatar and camera access used locally for barcode scanning. BiteScore does not require microphone access or continuous location data.
- Support data and core-service inferences: support/feedback correspondence, abuse reports, moderation results and product-level insights used inside the ordinary BiteScore scoring and discovery service.
- Optional mobile analytics is available only to an authenticated account with the server-timestamped 13+ affirmation attached to the exact current Terms and Privacy editions, and only after that account holder separately gives explicit consent. Guests and accounts without that current evidence are not shown a grant choice and cannot send analytics. The permitted first-party pipeline records random installation, session and event-deduplication identifiers; event occurrence and server receipt times; the server-verified account link; safe screen and API templates; bounded feature outcomes, counts, duration and latency bands; app/build, platform, OS major, device class, language and coarse client-error/queue-health signals. Raw installation/session/event identifiers are used transiently to derive domain-separated server-HMAC keys; only those pseudonymous keys persist. The client sends no separate batch identifier or client send timestamp. Review/message text, search text, barcodes, photos, audio, location, credentials, request bodies, full URLs, screenshots, tap coordinates and session replay are excluded.
- Core login service metric (independent of optional analytics consent): the successful-login calendar day, total login count and mobile-channel login count are recorded against the authenticated account from the server's own session issuance. This narrow record is used for authentication security, capacity and core-service operation; it is not a browser activity trail and is not used for advertising or cross-site tracking.
- Optional website analytics is available only to an authenticated account with the server-timestamped 13+ affirmation attached to the exact current Terms and Privacy editions, and only after that account holder separately gives explicit consent. Guests and accounts without that current evidence cannot grant or send website analytics. The first-party pipeline uses domain-separated server-HMAC subject, session and event-deduplication keys; safe route templates; bounded feature outcomes, counts, foreground duration and latency bands; coarse build, browser/device class, language, entry-source and reliability signals. It excludes full URLs and referrers, query strings, search or community text, request bodies, credentials, advertising identifiers, screenshots, session replay and tap/click coordinates.
- Inactive BiteData access records: BiteScore does not currently invite, provision or authenticate organisation members for BiteData and does not collect new business-profile, membership, entitlement, product-grant or step-up-session data for that service. Any dormant record is unavailable for commercial access and remains subject to deletion or the applicable minimum security/legal retention rule.
- Core review and scoring data: approved public review text, ratings and factor scores; bounded public engagement, moderation and provenance records; product and taxonomy context; and product-level scores, labels or summaries used only inside the ordinary BiteScore service while BiteData is disabled.
- Inactive BiteData demographic fields: no new birth year, demographic gender category or province code is collected for BiteData under this edition. These fields are not public-profile data. Any historical raw field or consent record is not an active BiteData input and remains subject to the withdrawal, deletion, export and evidence-retention rules stated below. BiteScore does not need an exact date of birth for this purpose.
- Bitescore task-reward record: a versioned, immutable server record created when a concrete platform task was active at initial review submission. It may record the task reference, XP/BiteCoin amount and rating-neutral condition. Only a concrete, known positive task reward produces a public service-reward disclosure; no-task, missing, malformed and legacy-unknown contexts produce no badge.
- BiteScore does not collect purchase receipts or operate purchase, transaction, product-use or gifted-product verification for reviews. It publishes no purchase-verification label or VERIFIED, UNVERIFIED or UNKNOWN purchase status. A separate rating-neutral task-reward disclosure may appear only for a concrete, known positive Bitescore platform task; user-to-user virtual gifts are a separate social feature. Neither proves how a product was obtained.
3. Where The Data Comes From
Data is collected electronically from forms and content you submit, your use of the service and device permissions you choose, authentication providers, cookies/local storage where permitted, and security/server logs. The applicable grounds are listed in section 4; explicit consent is not bundled with this notice.
Before an eligible authenticated 13+ account holder gives consent, the app creates no analytics session/event, optional identifier, queue item or batch. Guest and stale-or-missing-current-evidence collection is disabled. After a grant from an eligible account, events are aggregated in a bounded on-device queue and sent in encrypted API batches; a feed advance never creates its own network request or database row.
For an eligible authenticated 13+ account holder who separately consents, website analytics is collected through a bounded first-party browser queue and encrypted API batches. Before session eligibility and consent are verified, the browser creates no analytics subject/session/event identifier or queue item and sends no analytics event, presence or batch request. Guest and stale-or-missing-current-evidence sessions remain off.
BiteData organisation access is disabled, so BiteScore does not currently collect organisation invitations, memberships, entitlements, product grants or step-up access events for that service.
No demographic value or consent grant is newly collected for BiteData while the feature is disabled. A concrete Bitescore task-reward record comes only from the active task catalogue and reward rules at initial review submission; the reviewer cannot create or rewrite it. BiteScore collects no receipt or other evidence to verify purchase, product use or a gifted product.
BiteScore does not silently observe a member to prepare BiteData. Ordinary service activity, public contributions and optional telemetry are not accumulated as dormant commercial eligibility while BiteData is disabled.
The account holder checks one initially blank 13+ confirmation during sign-up or current legal acceptance. It is a self-declaration used for minimum-age eligibility; it is not identity verification, inferred age, verified parental/legal-representative consent or proof of legal capacity.
4. Why We Process It And The Legal Grounds
- Creating and operating your account; providing profiles, reviews, lists, social functions, gifts and notifications — necessary to establish or perform the user agreement (KVKK 5/2-c).
- Preventing fraud, abuse and unauthorised access; maintaining service security; moderation; establishing and defending legal claims — legitimate interests and establishment/exercise/protection of a right (KVKK 5/2-f and 5/2-e).
- Responding to authorities, retaining legally required records and fulfilling consumer/e-commerce obligations where applicable — legal obligation (KVKK 5/2-ç).
- Optional mobile product analytics and app-reliability measurement described in section 2 — your separately requested, specific explicit consent (KVKK 5/1). Refusing or withdrawing it does not prevent registration or use of any core service. It is not used for advertising, sale of data or cross-app/site tracking.
- Marketing or promotional electronic messages, if introduced — only under a separate, specific opt-in; service and security messages are not marketing.
- Before a mobile choice, the random installation identifier is processed transiently only to bind the notice ticket and protect that choice against forgery or cross-installation use; it is not an analytics event and is not written to the analytics database. This limited preference-security processing supports the secure provision of the requested choice and the controller's proportionate legitimate interests (KVKK 5/2-c and 5/2-f).
- The narrow successful-login service metric described in section 2 — performing and securing the requested account service, capacity planning and the operator's proportionate legitimate interests (KVKK 5/2-c and 5/2-f). It is server-authoritative and independent of the optional website/mobile analytics choices.
- Optional website product analytics and reliability measurement described in section 2 — your separately requested, freely given and specific explicit consent (KVKK 5/1). Refusing or withdrawing it does not prevent registration or use of a core service. It is not used for advertising, sale of data, user scoring, automated decisions or cross-site tracking.
- There is no current purpose of provisioning, authenticating or serving an organisation through BiteData. Dormant access structures do not authorise processing or disclosure.
- Moderating eligible community contributions and transforming them into product scores, discovery signals and privacy-thresholded product insights used inside the ordinary BiteScore service — processing necessary to perform that requested user service (KVKK 5/2-c).
- No product intelligence or public-review material is currently licensed or disclosed to an organisation through BiteData. A future commercial purpose requires the new-edition, store-declaration, just-in-time and prospective-acceptance safeguards stated in sections 5 and 13; this edition supplies no legal basis for that future processing.
- BiteData demographic analytics and its consent-grant collection are inactive. No new demographic value is collected for that purpose under this edition, and accepting this Notice, the Terms, Community Rules or telemetry never creates a future demographic permission.
- Capturing and displaying a concrete Bitescore task-reward disclosure, enforcing rating-neutral task rules and auditing reward integrity are necessary to perform the transparent community/reward service and protect members against misleading or manipulated review practices (KVKK 5/2-c and, where balanced, 5/2-f).
4A. Activity-Based Data, Purpose, Legal Ground And Recipient Map
A recipient does not receive every category listed in this Notice. The following map links each current activity to the data it needs, its specific purpose, the relied-on KVKK ground and the relevant recipient group.
- Account, session and core community service — account identifiers, authentication and verification status, settings and the contributions or relationships you request; to create the account, maintain the session and perform the requested features; KVKK 5/2-c; contracted hosting/database, the sign-in provider you choose and email or push delivery only as needed for that feature.
- Security, abuse prevention and moderation — bounded technical/security logs, account and content identifiers, reports, blocks and the content under review; to prevent fraud or abuse, enforce rules, investigate incidents and establish, exercise or defend rights; separately assessed KVKK 5/2-f and, where applicable, 5/2-ç or 5/2-e; authorised trust-and-safety staff, contracted security processors, advisers and competent authorities only as necessary.
- Optional website or mobile telemetry — the separately described minimised event, coarse device/build and performance fields; to measure and improve the service; KVKK 5/1 explicit consent; only BiteScore and the processors named and verified for that optional purpose. It is not sent to an advertising network or data broker.
- Inactive BiteData demographic activity — no new birth year, demographic gender category or province code is collected for BiteData; no demographic product cohort is produced or sent to an organisation; no current recipient or processing ground is asserted for that inactive purpose.
- Ordinary review processing while BiteData is disabled — approved public reviews, ratings, factors and bounded provenance are used only for core scoring, discovery, security and moderation under the user-service grounds described above; no organisation is a BiteData recipient and no pre-activation contribution becomes commercially eligible.
- AI-assisted moderation — only the submitted review text and bounded product or public-community context required for an approved moderation task may be sent to the specifically documented processor after its legal and transfer safeguards are verified. BiteData product enrichment and organisation delivery are inactive and provide no separate dispatch purpose.
- Rights requests, complaints and legal duties — identity/authority verification, contact, request, delivery and minimum evidence records; to answer the request, comply with law and establish, exercise or defend rights; KVKK 5/2-ç and/or 5/2-e as applicable; authorised staff, delivery providers, advisers, courts and competent authorities only to the extent required.
5. BiteData Is Currently Disabled
BiteData business access and commercial product-intelligence delivery are not part of the currently active service. The name, internal models or dormant administration structures do not create permission to process or disclose data for an inactive purpose.
- No organisation or business user receives a BiteData dashboard, account, invitation, entitlement, export, API, alert, product metric, review text, excerpt, pseudonymous reference, demographic cohort, AI draft or other commercial output.
- Ordinary public reviews remain visible under the community features chosen by the member and may support core scoring, discovery, security and moderation. That ordinary processing is not a dormant commercial licence and does not make a contribution eligible for future BiteData use.
- No new BiteData demographic-consent presentation is issued and no birth year, demographic gender category or province code is collected for BiteData while this edition is current. A historical consent receipt, if any, proves only the historical decision it records and cannot authorise current or future BiteData processing.
- Activation cannot occur merely because a technical switch is changed or a user threshold is reached. Before activation BiteScore must publish new Terms, Privacy Notice and Community Rules, update the applicable App Store and Google Play privacy declarations, complete the recipient, processor and international-transfer controls, and obtain prospective acceptance before the new purpose begins.
- Where future demographic or other consent-based processing is proposed, BiteScore must issue a new, purpose-specific just-in-time presentation and collect a new freely given choice. Acceptance of this edition, an old demographic choice, telemetry consent or ordinary service use is not that permission.
- Reviews and other contributions created before activation will not be made commercially eligible retrospectively by the future switch or by acceptance of future general terms. Eligibility must arise prospectively from a contribution made through the updated, disclosed flow.
- A task-reward disclosure or a review's public availability is not permission to reuse the review, username, name, image or identity in advertising, influencer content or a testimonial. That requires a separate, purpose-specific and auditable lawful authorisation.
6. AI And Automated Processing
Reviews may be checked for abuse and analysed to produce product-level summaries. These tools can be inaccurate. A material account sanction should not be based solely on an automated result; you may object and request human review through the contact address. Product summaries are informational, not health, allergy, nutritional or professional advice.
Before a one-to-one message is delivered, BiteScore applies bounded, deterministic Turkish/English safety rules to the message text to prevent clear abuse. A blocked message is not delivered to the recipient or stored by the server as a message, and this guard does not send the text to an external AI provider. This core messaging-safety processing is independent of optional analytics consent; analytics does not receive message text.
BiteData business outputs and demographic cohort analytics are disabled. Product-level scores, labels or summaries used inside the ordinary BiteScore service do not create a person-level advertising audience or decide a person's eligibility, price, employment, credit, insurance, essential-service or account access.
A service task-reward disclosure communicates only the server's task record and rating-neutral condition. It neither verifies how a product was obtained nor permits reuse of a review, username, name, image or identity in advertising, influencer content or a testimonial; such reuse requires separate, purpose-specific and auditable lawful authorisation.
8. Retention, Deletion And Anonymisation
- Account and community data is kept while the account is active. The in-app deletion flow permanently deletes the account and associated direct data, subject only to data that must be retained or isolated for a legal claim or mandatory retention period.
- Versioned legal-evidence records are detached from your account rather than deleted, and the IP address and device string attached to them are erased at the same moment. Current records cover your acceptance of the Terms and presentation of this Privacy Notice; acceptance of the Community Rules, where applicable, is recorded separately. Evidence created under an older published edition may also retain the timestamp of the minimum-age confirmation that edition requested. What remains is the document version, its content hash, the locale, the source and the relevant timestamps, keyed to a value derived from your identifier under a secret held by the operator. The historical timestamp does not mean that BiteScore currently verifies age or a legal representative's consent or authorisation. The records are retained to establish, exercise and defend a legal claim (KVKK 5/2-e) for ten years after the account is deleted, which is the general limitation period for a contractual claim, and are then destroyed by a scheduled job.
- You can download your own copy of this record, and everything else held for your account, from Settings at any time.
- Verification codes expire after 10 minutes. Security, abuse and audit records are retained for the shortest period justified by risk and applicable limitation/retention rules.
- Backups are rotated on a restricted schedule; deleted data is not restored into the live service except for disaster recovery and is removed through the backup lifecycle.
- Mobile analytics raw events are retained for up to 14 days; app-session presence for 30 days; exact daily active-subject records for 90 days; and protected, low-cardinality hourly aggregates for up to 13 months. A withdrawn consent projection is deleted in the same completion transaction once every identifying child is gone, with no extra retention; only an inactive non-withdrawal orphan projection may remain for up to 90 days. Hourly cells contain no account or installation key but can represent small cohorts: they remain protected analytics, are not claimed to be legally anonymous and stay until their ordinary retention expires, including after withdrawal.
- Withdrawal applies to this app installation; another installation keeps its own separate choice. The app first stops local collection and clears queued events. Solely to retry an interrupted request, it temporarily keeps the minimum exact withdrawal instruction in operating-system-protected storage; the notice copy and one-time presentation ticket are never stored. The instruction is erased last, after the server confirms withdrawal and the app verifies that local analytics data is cleared. Server deletion of pseudonymous events, sessions and exact daily-subject rows may finish later in bounded background steps; once they are gone, the retired consent projection is deleted in that completion transaction with no extra retention. Neither retry nor deletion delay permits new collection.
- A detached, append-only proof record is created only for an accepted grant or the successful withdrawal of its matching active grant; an unknown, already denied or completed subject creates no new long-retention receipt. To establish, exercise or protect legal claims (KVKK 5/2-e and TBK 146), the record is kept for 10 years from the server-recorded decision, then deleted by a bounded job. It contains server-HMAC subject/decision keys, the decision, legal versions and exact Privacy hash, locale, surface, platform, app/build and times, but no raw account/user or installation id, IP address or user agent.
- Exact account-linked daily login-service rows are retained for up to 90 days, then removed by the bounded retention job; only protected aggregate capacity totals may remain for up to 13 months. Account deletion removes the exact rows immediately.
- Website analytics raw events are retained for up to 14 days; browser-session presence for 30 days; exact daily active-subject records for 90 days; and protected, low-cardinality hourly aggregates for up to 13 months. Hourly cells contain no account or browser-subject key but can represent small cohorts, so they remain protected analytics and are not claimed to be legally anonymous.
- Withdrawal applies to this browser. Local collection stops and the queue is cleared before the network request; only the minimum withdrawal instruction and, when browser storage is unavailable, an identifier-free denial-only marker may remain temporarily for idempotent retry. The server marks the retired subject denied immediately, blocks that subject from collection and removes its accessible pseudonymous events, sessions and daily-subject rows in bounded background chunks. The retired consent projection is deleted in the same completion transaction once those identifying children are gone, with no extra post-completion retention. A deliberate later choice uses a new subject and may proceed while the retired subject's purge continues; another browser keeps its independent choice. Protected hourly cells remain until ordinary expiry.
- A detached, append-only website-analytics decision receipt is created only for an accepted grant or the successful withdrawal of its matching active grant. To establish, exercise or protect legal claims (KVKK 5/2-e and TBK 146), this minimal receipt is kept for 10 years from the server-recorded decision and then removed by a bounded job. It contains domain-separated HMAC subject/decision keys, decision, exact notice and legal versions/hashes, locale, surface, deployed artifact and server times, but no raw account/browser identifier, IP address or user agent.
- On account deletion, exact daily login-service rows are removed in the request. A minimum account-HMAC purge tombstone immediately hides account-linked website telemetry from account and admin reads, then the independent worker physically removes matching events, sessions and daily-subject rows in bounded chunks. Its completed status receipt remains for up to 90 days for deletion-operation audit and retry safety, then is deleted. Physical telemetry deletion is therefore bounded and asynchronous, not falsely presented as completing inside the account request.
- No new BiteData verification challenge, organisation session, entitlement or commercial legal-proof eligibility is created while the feature is disabled. Any dormant operational or audit record is withheld from commercial reads and remains subject to its existing shortest deletion, security, contractual-claim or documented legal-hold schedule.
- Ordinary review deletion, correction and moderation controls continue to update core BiteScore scores and product views. No source link, product statistic or historical snapshot is treated as present or future commercial BiteData eligibility while the feature is disabled.
- No new private birth year, demographic gender category or province code is collected for BiteData and no new consent grant is offered while this edition is current. Any historical raw value is not an active BiteData input; withdrawal and account-deletion controls apply, and any detached minimum decision receipt remains only under the evidence schedule stated below.
- The server-authored task-reward snapshot remains attached to the review while the review is retained and is not rewritten when the review is edited. It is deleted with the review/account, except where a separately documented legal hold requires isolation and retention.
- Pending, rejected and unreferenced private photo uploads are removed under the media lifecycle. If a contributed product image has been approved and is published or shared by product records, account deletion removes the member and attribution link; the shared object remains only while a live database reference or documented hold requires it. A minimum promoted-upload or rights/transaction receipt may be isolated without a public identity link for the documented period necessary to establish, exercise or defend legal claims (KVKK 5/2-e; TBK 146 where applicable), and is then destroyed.
- The existing 2026-08-17.1 demographic presentation remains an immutable historical edition only; it is not issued for a new grant while BiteData is disabled. A detached minimum historical grant or withdrawal receipt contains the decision and versioned evidence but never demographic values. It is kept only for the stated legal-claims schedule and cannot authorise current or future processing.
- Current admission is derived from the server-timestamped minimum-age confirmation on the exact current Terms and Privacy evidence. Legacy coarse-band projection fields are cleared and are not used as an active feature tier. When account deletion detaches legal evidence, the timestamped affirmation may remain under the legal-claims schedule in this section; it never gains a birth date or age band.
9. Public Content And Third-Party Sources
New accounts start with a private profile. A private profile can be viewed only by its account holder and accepted friends; it is omitted from stranger profile search, people discovery and public identity rankings. The account holder may choose Public Profile in Settings. Public reviews, ratings and other community contributions keep their own moderation and content-visibility rules, so making a profile private does not retrospectively make an otherwise public contribution private. When a profile is public, its username, avatar and profile details may be visible, shared or indexed. Do not publish sensitive personal data. External links and Open Food Facts content are governed by their respective operators.
An approved public review may contribute to core BiteScore scores, discovery and moderation and may remain visible through the ordinary community service. It is not currently supplied to an organisation through BiteData and does not become commercially eligible for a future BiteData release merely because it was public or submitted before activation. Do not include personal or sensitive information in a public review.
Birth year, demographic gender category, province code and demographic-consent state are private account data and are not included in a public profile response. When a concrete, known positive Bitescore platform-task reward is recorded, the review may show a separate rating-neutral service-reward disclosure; no-task, missing, malformed and legacy-unknown contexts show no badge. The disclosure is not evidence of purchase, product use or how the product was obtained.
10. Children And Age-Related Safeguards
BiteScore does not impose a blanket 18+ threshold for creating an ordinary account. Account eligibility and the products allowed in the general-audience catalogue are separate policies: age-restricted products are outside that catalogue. A member must nevertheless have the legal capacity required by applicable law and obtain a legal representative's consent or authorisation where the law requires it. The current service does not independently verify age, legal capacity or representative authority.
- Ordinary accounts are for people aged 13 or older. Under-13 users must not create or use an account.
- Every supported account holder makes the same single 13+ self-declaration and, where applicable law requires it, confirms that parent or legal-representative permission exists. BiteScore does not verify age, adult action, consent, identity or legal capacity through this checkbox.
- All supported 13+ accounts have access to the same current general-audience community and social features after the required current legal acceptances. Age-appropriate safety, reporting, blocking and moderation controls apply to everyone; suspected child-safety harm may be restricted or removed.
- Optional product-experience telemetry is available to an authenticated account with the current server-timestamped 13+ legal evidence only after its own separate explicit-consent choice. It remains off for guests and accounts without that current evidence. Accepting the Terms, Privacy Notice or Community Rules is not analytics consent.
- BiteData business access and BiteData demographic collection are disabled. Its separate adult-only demographic boundary remains unchanged and cannot be activated by this general 13+ declaration. No member's review or demographic information is used for targeted advertising, a commercial BiteData recipient or a significant person-level decision.
- Restricted products are not published on the public catalogue, search, recommendations, lists, Clash or community surfaces. Their presence in an internal database does not make them available to a child or adult member.
11. Security And Accountability
BiteScore applies controls appropriate to the nature and risk of the processing. No internet service can promise absolute security.
- BiteData organisation admission and commercial legal-proof eligibility fail closed while the feature is disabled. An old account, invitation, role, entitlement, product grant, presentation ticket or legal acceptance cannot open the service.
- Dormant tenant separation, least-privilege, pseudonymisation, masking, release-lineage and small-cohort controls remain defence-in-depth, not an active permission or promise that commercial outputs are available.
- A suspected incident is assessed under the incident-response process; access can be restricted and affected persons or authorities are notified where applicable law requires it. The current processor identity, processing location, retention terms and any international-transfer safeguard must be kept in the processing inventory and made available through the Privacy contact. A new recipient or materially different purpose is disclosed before activation.
12. Your KVKK Rights And Controls
Under KVKK Article 11, you may ask whether your data is processed; request information; learn the purpose and whether it is used accordingly; learn domestic/foreign recipients; request correction, deletion or destruction where conditions are met; request notice of correction/deletion to recipients; object to a result produced exclusively by automated analysis; and claim compensation for unlawful processing.
- legal@bitescore.co is the published privacy contact and preliminary intake channel. An ordinary email is treated as a formal controller application only when it is sent from an address you previously notified to BiteScore and that is registered in the system; otherwise BiteScore may request identity or authority verification and direct you to a method permitted by the Data Controller Application Communiqué. State your name, contact details, requested right and the information needed to identify the relevant processing.
- Requests are answered as soon as possible and no later than 30 days. A fee may be charged only if permitted by the official tariff.
- Settings → Your Data → Download my data starts a direct machine-readable JSON export when available. Authentication, rate, size and temporary service limits may apply; this self-service channel does not restrict your formal KVKK application rights.
- You may also complain to the Turkish Personal Data Protection Board after using the controller application process and within the statutory time limits.
- Guests are ineligible for optional analytics, so no guest analytics grant, capability, event queue or analytics summary is created. Statutory privacy requests remain available through the controller channel.
- The machine-readable account export includes your daily login-service rows and authenticated website analytics linked by the server to your account, including consent state and decision receipts. It never includes guest/shared-browser telemetry merely because it was later seen in the same browser.
- No new BiteData demographic grant is offered. The machine-readable account export includes any historical raw demographic value and decision receipt still associated with the account, together with retained review task-reward snapshots. Withdrawal, correction, deletion and formal KVKK request paths remain available for any retained historical record.
13. Changes And Contact
Material changes will be announced before they take effect where appropriate. BiteData cannot be activated under this edition. A launch requires newly versioned Terms, Privacy Notice and Community Rules, updated store privacy declarations, completed recipient/processor/international-transfer controls, a new purpose-specific just-in-time choice wherever consent is relied on, and prospective acceptance before processing begins. No pre-activation contribution becomes commercially eligible retrospectively. Questions and complaints may be sent to the controller contact details in section 1.