Privacy & Data Protection Notice (GDPR · KVKK)
Last updated: 2026-08-26
Data controller: Kalynda Teknoloji Havacılık ve Turizm Limited Şirketi, established in Türkiye — info@metarandtaf.com · https://kalyndagroup.com · +90 540 481 48 48. This notice covers the website and apps of metarandtaf.com and is written to satisfy both the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK) together with its secondary legislation.
Categories of data we process
- Account and identity data — e-mail address, password hash (we never store the password itself), plan, subscription start/end and trial status; only if you create an account.
- Transaction security data — sign-in timestamps, failed-attempt counters, rate-limit counters and audit records. Your IP address is used for abuse protection and, as part of visitor measurement (below), is recorded together with the approximate location derived from it.
- Usage events — which feature was opened (map, meteogram, 3D, briefing), counted without cookies, without advertising identifiers, without cross-site tracking, and stored in aggregate.
- Device location — read when you press “use my location” (processed in your browser to centre the map or rank nearest airports) and, if you accept your browser’s permission prompt, also recorded as part of visitor measurement together with its accuracy in metres. If you decline, no location is collected, you are not asked again, and the site works normally; you may withdraw the permission at any time in your browser’s site settings.
- Weather query coordinates — the point you tap is sent to weather sources to fetch data for that spot; queries are not linked to your account in the analytics store.
- Support correspondence — if you contact us, the messages you send and the address you send them from.
- Visitor measurement — a cookieless first-party counter (Kalynda Analytics) records the pages you view, the approximate location derived from your IP (country, city, postal code, internet provider) and device/browser characteristics (operating system, browser, screen size, graphics adapter, language, time zone, connection type), on the basis of legitimate interest. Kept for at most 24 months, never sold or shared with ad networks. Full notice: analitik.kalyndatech.com/legal/ziyaretci-aydinlatma.
What we do NOT do
- No sale or rental of personal data; no profiling and no automated decisions producing legal effects; no processing of special categories of data.
- Advertising (Google AdSense) — pages are ad-supported for signed-out visitors. Google and its partners may store or read cookies and device identifiers on your device to serve, cap and measure ads. In the EEA, UK and Switzerland this happens only with the consent you give on Google's consent screen, and without consent no personalised advertising is used. Signed-in members see no ads and the ad script is not even loaded. You can manage your choices at myadcenter.google.com and read Google's own notice at policies.google.com/technologies/partner-sites.
- The service is not directed at children under 16; do not create an account if you are younger.
Purposes and legal bases
- Providing the service, your account and subscription — performance of a contract (GDPR Art. 6/1-b; KVKK Art. 5/2-c).
- Security, fraud and abuse prevention, service diagnostics — legitimate interest (GDPR Art. 6/1-f; KVKK Art. 5/2-f).
- Invoicing and mandatory bookkeeping — legal obligation (GDPR Art. 6/1-c; KVKK Art. 5/2-ç).
- Cookieless aggregate analytics — legitimate interest; the data cannot identify you.
Recipients
Personal data is disclosed only to: (a) our infrastructure processor Cloudflare, Inc. (hosting, CDN, storage); (b) app stores and payment institutions that process your subscription payment — card data is handled by them, never by us; (c) competent authorities where the law requires it.
International transfers
Our infrastructure runs on Cloudflare's global network, so data may be processed outside your country and outside Türkiye. Transfers rely on the safeguards of GDPR Chapter V (standard contractual clauses of the processor) and are carried out in accordance with KVKK Art. 9. By creating an account you are informed of, and where required consent to, this transfer.
Retention
- Account data — for the life of the account; deleted or anonymised within 30 days after account deletion.
- Security and audit logs — up to 12 months.
- Payment and invoice records — for the period required by tax and commercial law (in Türkiye up to 10 years).
- Aggregate statistics — indefinitely; they contain no personal data.
Security measures
TLS encryption in transit, salted password hashing, role-based access control, two-factor authentication on administrative access, rate-limiting, audit logging and periodic backups.
Your rights (GDPR Art. 15–21 · KVKK Art. 11)
You may ask: whether we process your data; access to it and a copy; rectification; erasure; restriction of processing; portability; objection to processing based on legitimate interest; and information about recipients. Applications are answered free of charge within 30 days (KVKK) / one month (GDPR). If you are not satisfied you may complain to the Turkish Data Protection Board (KVKK Kurulu) or the supervisory authority of your country of residence.
How to apply
Send your request through the contact channels above (info@metarandtaf.com · https://kalyndagroup.com · +90 540 481 48 48) with enough information to verify your identity. We may ask for additional verification before disclosing data; requests concerning someone else's data require proof of authority.