PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
Last updated: 16 September 2026
About this translation
This is an English translation provided for convenience. The binding text is the Turkish original. In the event of any discrepancy, the Turkish text prevails.
1. Data Controller
This Privacy Notice has been prepared by MOZ TEKNOLOJİ VE TASARIM TİCARET LİMİTED ŞİRKETİ ("SUFLOR" or the "Company") under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), in order to inform you about the personal data processed within the SUFLOR mobile application and its connected digital services.
Information about the data controller
Name: MOZ TEKNOLOJİ VE TASARIM LİMİTED ŞİRKETİ
Address: Topçular mahallesi, Saray Bosna caddesi, Altındoğa Sitesi, C Blok D:1 Gölcük/Kocaeli, Türkiye
Email: suflorapp@gmail.com
MERSIS No: 0623212323100001
Tax No: 6232123231
VERBİS registration: Under Decision No. 2018/87 of the Personal Data Protection Board dated 19.07.2018 (as updated by Decision No. 2023/1154 dated 25.07.2023), the Company is exempt from the obligation to register with the Data Controllers' Registry (VERBİS), as it meets all of the following criteria together: fewer than 50 employees per year, an annual financial balance sheet total below 100 million Turkish Lira, and a principal activity that does not consist of processing special categories of personal data. (This exemption does not remove any of the other KVKK obligations described in this Privacy Notice.)
2. Personal Data Processed
Depending on the features you use and the actions you take, the following personal data may be processed:
2.1. Identity and Contact Data
• First and last name
• Email address
• Where you sign in with an Apple or Google account, the necessary account identifiers transferred to SUFLOR by that provider
Your Apple or Google account passwords are never received or seen by SUFLOR.
2.2. Account and Usage Data
• User account information
• Account creation and account deletion information
• Transaction and usage records within the application
• The record of acceptance of the agreement and its version (this record contains no IP address)
• Transaction records necessary for the use of the service
2.3. Technical Data, Device Identifiers and IP Address
• A device identifier generated on your device and stored on your device — this identifier is not sent to SUFLOR's servers and is not stored in the Company's own database
• Push notification identifiers / notification tokens
• Session and transaction security records
• Technical records necessary for the application to function
SUFLOR does not separately record your IP address in its own database for the purpose of processing personal data. That said, service providers used to deliver the service — such as Sentry (error monitoring), OneSignal (notifications), RevenueCat (purchase management) and Supabase (infrastructure) — may technically see your IP address while a connection is established and may process it within their own connection logs, subject to their own policies.
In addition, some providers such as Sentry and OneSignal may use device or session identifiers they generate themselves in order to run their services; these identifiers are created by the provider, not by SUFLOR.
2.4. User Content
• PDF, Word or similar script and text files you upload to SUFLOR
• Structured data created from that content, such as characters and lines
• Text created or edited by you inside the application
2.5. Voice Data
If you use the microphone-assisted rehearsal and line-tracking features, the speech captured through the microphone while you read your own lines may be processed.
This voice data may be used for speech recognition and line detection in order to run that feature, and may be transferred to the Deepgram service as part of the necessary technical workflow.
SUFLOR does not use this voice data to uniquely identify or authenticate the user.
Assessment of the nature of the voice data: this voice data is not treated as a special category of personal data (biometric data) under Article 6 of the KVKK. Specifically: (i) the voice data is processed only to determine whether the line has been read correctly and to transcribe speech into text, as a temporary technical operation; (ii) no unique biometric template (voiceprint) is derived from the user's voice pattern, and the data is at no stage used to identify or verify the user; (iii) the technology provider concerned (Deepgram) also processes the voice data solely for speech recognition and does not provide a separate biometric authentication service. Since the element the Personal Data Protection Board relies on when assessing biometric data — the purpose of uniquely identifying or verifying a person — is absent from this processing activity, the voice data is processed as ordinary personal data and therefore does not require separate explicit consent.
2.6. Purchase and Transaction Data
For in-app purchases, the information necessary in relation to the purchase, credits and transaction status may be processed, including through RevenueCat, which provides purchase and subscription management.
Payment card and similar payment details are not received directly by SUFLOR or RevenueCat; they are processed through the app store's payment infrastructure.
2.7. Self-Tape / Video
Video recordings created with SUFLOR's self-tape feature are not uploaded to SUFLOR's servers and are not kept by SUFLOR as a video archive on any server.
Video recordings are stored on the user's own device, through the recording and gallery mechanism provided by the device's operating system.
2.8. Error Monitoring Data
Where the application or server functions malfunction, technical error records, a screenshot of the moment of the error and session replay data may be processed through the Sentry service in order to detect and resolve the fault.
Text and visual content that could appear in these records is masked; your script and other user content therefore does not appear in a readable form in them.
2.9. Ad Attribution Data
In order to measure the effect of advertising campaigns, limited and aggregated attribution data may be processed through Apple's AdServices API, which does not use the IDFA (advertising identifier) and requires no separate permission. SUFLOR uses no other third-party analytics SDK.
3. Data Processed Through Artificial Intelligence and Other Technical Services
SUFLOR uses third-party artificial intelligence and technology services in order to run certain features.
3.1. Google Gemini
The Google Gemini Developer API is used for the purposes of:
• detecting the language of the uploaded script,
• analysing the script,
• splitting out characters and lines,
• processing scene and context information.
In the technical workflow, the uploaded document may first be processed as a whole for language detection, and then in parts for analysis.
No user voice is sent to Gemini within this workflow; what is processed is essentially script and text content.
SUFLOR uses the paid Gemini API service. Under Google's applicable service terms, API prompts and the responses generated are not used to improve Google products. Google may nevertheless keep technical records for service security, abuse detection or legal obligations.
3.2. ElevenLabs
ElevenLabs is used for the purpose of:
• having the lines of the other characters you select voiced by artificial intelligence.
The whole script is not sent to ElevenLabs.
Only the lines belonging to the other characters that need to be voiced are sent.
The lines belonging to the user's own character are not sent to ElevenLabs for this voicing purpose.
SUFLOR uses the ElevenLabs service with the "Improve the models for everyone" option switched off.
Technical records that ElevenLabs may keep in the course of providing the service may nevertheless be subject to ElevenLabs' own terms and policies.
Generated audio clips may be held in a shared technical cache in order to avoid regenerating the same line text with the same voice selection. Records in this cache are stored under a technical key derived from the line text and the selected voice; they are not associated with a user account and do not identify the user. This cache is hosted on Cloudflare R2 storage infrastructure (see Art. 3.7).
3.3. Deepgram
Deepgram is used for the purposes of:
• detecting speech while the user reads their own lines,
• converting speech into text,
• running the line-tracking feature.
In this context, the voice data captured while the user reads their own lines may be transferred to the Deepgram service.
In SUFLOR's use of Deepgram Nova-3, the opt-out setting that prevents data from being used for model improvement is enabled.
The user's microphone audio is not intended to be sent to Deepgram while the AI characters are speaking.
3.4. Sentry
Sentry is used to detect and resolve errors that may occur in the mobile application and in server-side functions.
In the production environment, screenshot capture at the moment of an error and session replay are enabled; text and visual content in these records is masked, and your script content does not appear in a readable form in them.
Sentry may access the IP address and its own technical identifiers during the connection; this data is subject to Sentry's own policies.
3.5. RevenueCat
RevenueCat is used to manage in-app purchases and subscriptions. In this context, the technical data necessary in relation to purchase, transaction and subscription status may be transferred to RevenueCat. Your payment card details are not received by RevenueCat.
3.6. Apple AdServices
Apple's AdServices API may be used for ad attribution. This measurement does not use the IDFA and is Apple's attribution method that requires no separate permission. SUFLOR uses no other analytics SDK; the standard app analytics offered through App Store Connect applies separately.
3.7. Cloudflare R2
Cloudflare R2 is used to store the AI voice clips generated by ElevenLabs (the shared technical cache described in Art. 3.2).
The content held in this storage is not the user's own voice; it consists solely of AI-generated voice recordings stored under a technical key derived from the line text and the selected voice, and not associated with a user account.
Cloudflare may access the IP address and its own technical identifiers during the connection in the course of providing the service; this data is subject to Cloudflare's own policies.
4. Purposes of Processing
Your personal data may be processed for the following purposes:
• creating and managing a SUFLOR user account,
• user verification and account security,
• providing script upload, storage, analysis and rehearsal services,
• carrying out character and line splitting,
• performing AI-assisted script analysis,
• providing AI-assisted voice generation,
• running speech recognition and line-tracking features,
• sending in-app notifications,
• carrying out credit and in-app purchase or subscription transactions,
• operating the service technically,
• detecting and resolving errors and technical problems,
• measuring advertising performance,
• ensuring security and preventing abuse,
• responding to user support requests,
• fulfilling legal obligations,
• managing disputes and establishing, exercising or protecting rights,
• fulfilling retention and record-keeping obligations arising from legislation.
5. Legal Grounds for Processing
Your personal data is processed under Article 5 and, to the extent applicable, Article 6 of the KVKK, on the following legal grounds according to the nature of the processing activity:
• Conclusion or performance of a contract: account creation and management; transferring data to Google Gemini, ElevenLabs and Deepgram in order to provide the services you request, such as script upload, analysis, voicing and line tracking. This falls within that ground and requires no separate explicit consent, because the processing is necessary for the performance of the service you have requested.
• Compliance with a legal obligation: record-keeping and retention obligations arising from legislation, and notifications to competent authorities.
• Necessity for the establishment, exercise or protection of a right: dispute management and defence against legal claims.
• Legitimate interest: ensuring the security of the service, preventing abuse (including error and security monitoring with Sentry), resolving technical problems, and measuring advertising performance (Apple AdServices) — these activities are carried out in a way that does not harm your fundamental rights and freedoms and in accordance with the principle of proportionality.
• Explicit consent: in the specific cases where none of the above legal grounds applies and the law requires explicit consent, your explicit consent is obtained for that particular operation through a separate Explicit Consent Text.
Because the transfer of your voice data to Deepgram and ElevenLabs is necessary for the performance of the rehearsal and voicing service you have requested, that transfer requires no separate explicit consent. Obtaining explicit consent does not change the legal basis of other processing activities that do not require it.
6. Recipients of Personal Data and Purposes of Transfer
Your personal data may be transferred to the following groups of recipients, limited to and proportionate with the purpose of processing:
Apple
The data and technical identifiers necessary for:
• Sign in with Apple,
• in-app purchases,
• operating the app and device notification infrastructure,
• ad attribution through the AdServices API.
The data necessary for:
• Sign in with Google,
• script and text analysis through the Google Gemini API.
ElevenLabs
• Only the text and lines necessary in order to have the other characters' lines voiced by artificial intelligence.
Cloudflare (R2)
• The data necessary to store the AI voice clips generated by ElevenLabs (which are not the user's own voice) in the shared technical cache.
Deepgram
• The voice data captured while the user reads their own lines, in order to run speech recognition and the line-tracking feature.
Supabase
• The user account,
• structured data relating to scripts and lines,
• storage and processing of the technical data necessary for the service to function.
OneSignal or similar notification services
The device and notification identifiers necessary for:
• sending push notifications,
• operating the notification infrastructure.
Sentry
• The technical error records, masked screenshot and session replay data, and connection information necessary to detect and resolve application and server errors.
RevenueCat
• The transaction data necessary to manage in-app purchases and subscriptions.
Competent public authorities
Transfers may be made to legally competent courts, enforcement offices, regulatory bodies, administrative authorities, law enforcement units and other competent public institutions, to the extent required under a legal power or obligation.
The current list of the service providers named above, together with links to their terms of use, privacy policies and data processing agreements, is published on the separately and independently maintained "Third-Party Services Used" page.
7. Transfer of Personal Data Abroad
Because some of the service providers SUFLOR uses (such as Google, ElevenLabs, Deepgram, Sentry, RevenueCat, Cloudflare and Apple) are located abroad or process data abroad, your personal data may be transferred abroad.
Transfers abroad are made on the basis of whichever of the transfer conditions set out in Article 9 of the KVKK and the related secondary legislation applies to the specific case. Where applicable, the following legal mechanisms may be relied on:
• an adequacy decision,
• standard contracts published by the Board,
• binding corporate rules,
• the exceptional transfer situations provided for in the Law.
The fact that a transfer abroad takes place is not in itself treated as a situation requiring separate explicit consent from the user; the applicable Article 9 mechanism governs the transfer, and explicit consent is a route available only for incidental (non-continuous) situations and in exceptional cases where none of the other mechanisms can be applied.
The fact that SUFLOR's technical infrastructure (Supabase) is located in the European Union / Frankfurt region does not in itself mean that the transfer is exempt from the appropriate safeguards or other transfer conditions under Article 9 of the KVKK. Since, as at the date this Privacy Notice is published, the Personal Data Protection Board has not declared an official "adequacy decision" for any country, all transfers abroad — including to the European Union — are subject to the same legal regime (appropriate safeguard mechanisms or exceptional transfer situations).
8. Method of Collection
Your personal data may be collected by electronic and automated means through:
• the mobile application,
• account creation and sign-in screens,
• Apple and Google sign-in services,
• your inputs inside the application,
• script upload operations,
• microphone and device permissions,
• in-app purchases,
• technical system and transaction records,
• the push notification infrastructure,
• the error monitoring infrastructure,
• support and communication channels.
9. Retention Periods
Your personal data is kept for as long as necessary for the relevant processing purpose, taking into account the retention periods prescribed by applicable legislation. The approximate framework by category is as follows:
• The original uploaded PDF or Word script file: marked for complete deletion from SUFLOR's temporary storage immediately after the analysis and the creation of the necessary structured data.
• Characters, lines and similar structured data created from the script: may be kept in SUFLOR's systems until the relevant script or the account is deleted.
• Account information: for as long as the account is active, and thereafter for the statutory retention periods following a deletion request.
• Sentry error records and session replay data: all data types on the Sentry plan SUFLOR uses are retained for a maximum of 30 days.
• RevenueCat transaction records: may be kept for as long as your account or subscription is active and, from the end of the service relationship between RevenueCat and SUFLOR, for up to 6 years for the resolution of potential legal disputes; upon your account deletion request, data that directly identifies you is deleted within a reasonable period.
When an account or a script is deleted, the data held by SUFLOR is deleted, destroyed or anonymised, save for data that must be retained by law.
Where data transferred to third-party service providers is held in those providers' technical systems or records, the provider's own retention policies and legal obligations may apply.
10. Security of Personal Data
SUFLOR aims to apply technical and administrative measures appropriate to the nature of the service in order to prevent the unlawful processing of, unlawful access to, loss of, or unauthorised use of personal data.
10.1 Where a breach of personal data security occurs and that breach is capable of producing adverse consequences for the data subjects, SUFLOR notifies the Personal Data Protection Board without delay and at the latest within 72 hours of becoming aware of the situation, and the affected data subjects within the shortest reasonable time, pursuant to Article 12 of the KVKK and the Board's Decision No. 2019/10 dated 24.01.2019.
11. Privacy Notice and Explicit Consent Are Separate
This Privacy Notice serves to inform you of the purposes for which, the legal grounds on which, and the scope within which your personal data is processed.
Accepting this Privacy Notice, or confirming that you have read it, does not amount to general approval or explicit consent to the processing of your personal data.
Where a specific processing activity legally requires explicit consent, that consent is obtained through a separate text and a separate declaration of intent.
Withholding explicit consent does not affect processing activities carried out on another legal ground under the KVKK rather than on consent.
Explicit consent that has been given may be withdrawn by the data subject with effect for the future. The lawfulness of operations carried out on the basis of that consent before the date of withdrawal is unaffected.
12. Rights of the Data Subject
Under Article 11 of the KVKK, in relation to your personal data you have the right to:
• learn whether your personal data is processed,
• request information if it has been processed,
• learn the purpose of processing and whether the data is used in accordance with that purpose,
• know the third parties, in Türkiye or abroad, to whom the data has been transferred,
• request rectification where the data has been processed incompletely or inaccurately,
• request erasure or destruction within the conditions set out in the KVKK,
• request that rectification, erasure or destruction be notified to the third parties to whom the data has been transferred,
• object to a result against you arising from analysis carried out solely by automated systems,
• claim compensation where you suffer damage due to unlawful processing.
13. Users Who Are Minors
13.1. Legal framework. Under Turkish law, the age of majority is 18 pursuant to Article 11 of the Turkish Civil Code No. 4721 ("TCC"); cases of majority acquired through marriage under Article 12 of the TCC are reserved. Under Articles 13-16 of the TCC, minors are subject to different regimes of capacity to act depending on whether or not they have the power of discernment: minors without the power of discernment have no capacity to act, and the authority to act on their behalf belongs to their legal representatives (parent or guardian); minors who have the power of discernment are treated as having limited incapacity and, as a rule, cannot incur obligations through their own transactions without the consent of their legal representative (Art. 16 TCC). The KVKK does not set a separate age threshold or a separate consent regime for children; the processing of minors' personal data is therefore governed by the general civil law provisions above, together with the principles of the "best interests of the child", "minimum data processing" and "heightened care" emphasised by the Personal Data Protection Board in its awareness work on the protection of children's personal data.
13.2. The mechanism SUFLOR applies. Because SUFLOR does not directly manage the account creation and sign-in process (see Art. 5.2 of the Agreement) and receives no independent, verified age information from the Apple/Google authentication systems, the User is asked, on a separate screen within the application's own interface immediately after their first sign-in, to declare whether they are over 18 (Art. 6.6 of the Agreement).
13.3. Users who declare that they are minors. Where a User declares on that screen that they are under 18:
a) Pursuant to Articles 13 et seq. of the TCC, for minors without the power of discernment the declaration of intent regarding the use of SUFLOR and, to the extent legally required, explicit consent, must in principle be given by the legal representative (parent or guardian) and with their knowledge.
b) For minors who may be considered to have the power of discernment, transactions that are not strictly personal and that may result in incurring an obligation (for example purchasing paid credits or a subscription) may not bind the minor without the permission of the legal representative under Article 16 of the TCC; such transactions must be carried out with the knowledge and approval of the legal representative.
c) In this framework, a User who declares that they are under 18 is presented with a separate checkbox containing the statement "I am using the app with the knowledge and supervision of my parent or legal guardian"; use of the application cannot continue unless this box is ticked.
13.4. Limits of the mechanism. Because SUFLOR manages account creation through the Apple/Google authentication systems, this mechanism does not guarantee independent and definitive verification of the legal representative's identity. It is nevertheless a reasonable, good-faith and proportionate measure within the available technical means; SUFLOR's liability for consequences that may arise from the impossibility of absolutely verifying the parent's or guardian's identity is limited, without prejudice to the obligations imposed on the Company by applicable mandatory legislation (see Art. 6.3 of the Agreement).
13.5. Data processing principles. Personal data belonging to minor Users is processed within the categories, purposes and legal grounds described in this Privacy Notice, having regard to the best interests of the child, to the narrowest possible extent and for the shortest possible period.
13.6. Operations requiring explicit consent. Where a processing activity requiring explicit consent arises in respect of a minor User, that consent is obtained from the legal representative for minors without the power of discernment and, for minors with the power of discernment, so far as possible with the knowledge of both the minor and their legal representative. Where in doubt, SUFLOR may make the operation conditional on the separate approval of the legal representative.
13.7. Right of the legal representative to apply. Legal representatives may apply to SUFLOR in relation to the processing of personal data belonging to a minor in their custody or guardianship, using the procedures set out in Article 11 of the KVKK and in Article 14 of this Privacy Notice; upon request, the minor's account is closed and the data deleted, without prejudice to statutory retention obligations.
14. How to Apply
You may submit requests relating to your rights under the KVKK through the following channels, pursuant to Article 13 of the KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller:
• Email: suflorapp@gmail.com (for electronic applications)
• Written application: by registered letter with return receipt to Topçular mahallesi, Saray Bosna caddesi, Altındoğa Sitesi, C Blok D:1 Gölcük/Kocaeli, Türkiye
Depending on the nature of your request, SUFLOR may ask for the identity verification procedures prescribed by legislation to be applied (for example confirmation of your identity details); this is intended to ensure that your application is concluded securely and for the correct person.
Applications are concluded within the period prescribed by legislation and, as a rule, within 30 days at the latest.
15. Updates
SUFLOR may update this Privacy Notice because of changes in its technical infrastructure, in the service providers it uses, in its data processing activities, or in applicable legislation.
The current text is made available through the mobile application and/or SUFLOR's relevant digital channels.