Document 01 · KVKK and privacy

Privacy Notice and Policy

Last updated: 6 August 2026Version: 2026-08-06App: Aris · com.alsen.appController: ALSEN DIGITAL LTD
In briefAris processes data needed to provide financial tracking and analysis. We do not sell personal data. Optional analytics, advertising or marketing requires separate explicit consent; refusal does not affect core service. In the in-app Privacy Centre you can inspect, export and correct data and submit rights requests.

1. Controller and contact

The controller under Türkiye's Personal Data Protection Law No. 6698 (KVKK) is ALSEN DIGITAL LTD. Registered address: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, GB. Contact info@alsendigital.net for privacy questions and data-subject applications.

2. Scope

This notice covers the Aris Android and iOS apps, the server services used by the mobile app, and this legal centre. The legal site needs no sign-in, cannot access your Aris account or financial records, and uses no advertising or analytics cookies.

3. Categories of personal data

Account and profile

Email address, identity-provider identifier, display name, username, profile image, language, country and preferences.

Financial and user-provided content

Portfolio assets, transactions, cash and liabilities, income and expenses, budgets, goals, notes, community content, and images or documents you upload.

Exchange connections

If you connect Binance or Bybit, Aris processes a read-only API credential, balance records, and trade records. The provider verifies the key; keys with trading, transfer, or withdrawal access are rejected.

Open Banking

If you choose and separately authorise the feature, connection, account, balance and transaction data may be processed through a licensed provider. Aris does not see or retain your online-banking password.

Subscription and store

App user identifier, product, entitlement and store transaction identifiers. Full card details are processed by Apple or Google and are not stored by Aris.

Device, communications, security and diagnostics

App version, device and operating-system details, push tokens, IP and request logs, session/integrity signals, security events, support messages and error records. Feedback retains only coarse browser, operating-system, device/screen class, language and generalised app section; full user-agent strings, device models and query-bearing page URLs are not retained.

On-device preferences and offline state

The offline community feed, local copies of saved posts, upvote references, and language, appearance, and navigation preferences may be held only on your device.

Optional measurement, advertising and marketing

Usage events or promotional communications you select are processed only after separate explicit consent. Analytics retains only the language and coarse application section; it sends no query, username, asset symbol, record ID or nested route, and never measures authentication or administrator screens. This release uses no in-app advertising SDK or cross-app tracking. Before such technology is introduced, this notice, store declarations and the consent flow will be updated.

4. Purposes and legal bases

  • Account creation, authentication, portfolio/budget/goal features and support: processing necessary to enter into or perform the service contract.
  • Subscription validation, accounting and lawful authority requests: compliance with the controller's legal obligations.
  • Session security, abuse prevention, debugging and service integrity: legitimate interests that do not override your fundamental rights and, where applicable, legal obligations.
  • Open Banking: performance of the service at your request plus any separate authorisation required by the provider.
  • Optional analytics, personalised advertising or marketing: specific, informed and withdrawable explicit consent.

You may withdraw consent in the Privacy Centre at any time. Withdrawal does not affect earlier lawful processing and does not disable core account functionality.

5. Recipients and disclosure purposes

We do not sell personal data for advertising. Where a feature is enabled and necessary, limited data may be disclosed to:

  • Vercel processes authenticated application requests and responses at runtime for application hosting, delivery and security, and provides measurement only when consented. Private portfolio calculations are not written to the shared application data cache.
  • Neon for account, profile and application-record storage.
  • UploadThing for user-uploaded profile, community and receipt files.
  • Apple and Google for sign-in, stores, purchase verification, device integrity and push delivery. For private financial, account, or community notifications, the provider receives a generic envelope and random notification ID rather than the detail; the signed-in app retrieves that detail.
  • RevenueCat processes the app user identifier, email address, display name and subscription/purchase state for customer association, subscription entitlement and purchase-state management.
  • Resend for verification, security, rights-request and support emails.
  • Salt Edge only for Open Banking connections you initiate.
  • Binance or Bybit only for a provider-verified read-only portfolio connection you initiate.
  • Amazon Web Services (Rekognition), when enabled, to moderate community images for safety.
  • Upstash, when enabled, for rate limiting, security state and a one-way deletion record that prevents a restored backup from recreating a deleted account.
  • Google Books, Apple iTunes, TMDB, and Semantic Scholar, only when external library lookup is separately enabled, to search a book, podcast, movie, or publication term you enter without adding your Aris account identifier.
  • Competent authorities, courts, and legal or financial advisers where required by law.

Recipients enabled in the production configuration—their names, countries, roles, data categories, purposes and transfer mechanisms—appear in Privacy Centre → My data and transfer information. Records for services you connected are included in your data export. If you cannot access the app, request this information by email.

6. International transfers

Some providers may be located outside Türkiye or process data abroad. A transfer takes place only where an applicable KVKK condition and safeguard exists, such as an adequacy decision, Board-approved binding corporate rules, a duly executed standard contract, or a statutory exceptional case. Explicit consent is sought separately only when it is genuinely appropriate and the other conditions are unavailable.

Active destination countries and the mechanism used are generated from the configured transfer register shown in the Privacy Centre. Where a standard contract is used, its signing and Authority-notification dates are also recorded; the release gate rejects undocumented transfers.

7. Retention, erasure and destruction

Account and financial records remain while your account is active or until you delete them earlier. Feedback and its coarse diagnostic fields are retained only as long as needed to handle the support matter and are removed earlier if the account is deleted. A transient external catalogue search does not create a separate stored copy of the search text; a content-free account record identifying the recipient and fixed purpose remains while the account is active and is deleted with it. Unfinished form and community drafts remain only for the current app/browser session; portfolio values are not written to persistent browser storage. The on-device offline community feed is kept for at most 7 days; saved-post copies and upvote references remain until the user removes them, signs out, resets data, or deletes the account. A data-export file created in the device cache for sharing is deleted when the share sheet closes. Session and security credentials are removed when they expire. Salt Edge webhook-deduplication summaries are retained for at most 30 days, and Open Banking synchronisation and error logs for at most 90 days. Verified uploads left unattached or removed from a profile, community post, or receipt record are deleted from the file provider within at most 7 days. Limited evidence of consents, notices, requests and deletion operations is retained with restricted access only for as long as needed and is not used for marketing or profiling.

After verified account deletion, active database records, files you own, push links and supported external-provider identities/authorisations are erased or irreversibly anonymised. Account-derived device caches and session drafts are cleared on sign-out, data reset, or account erasure. Copies in encrypted backups are destroyed through the normal cycle within at most 30 days. A restricted deletion record containing only a one-way user hash and deletion time prevents a backup restore from reviving the account.

See Account and Data Deletion for process details and the route available outside the app.

8. Your rights under KVKK Article 11

You may apply to the controller to:

  1. learn whether your personal data is processed,
  2. request information if it has been processed,
  3. learn the purpose of processing and whether it is used consistently with that purpose,
  4. know the third parties to whom it is transferred in Türkiye or abroad,
  5. request correction of incomplete or inaccurate data,
  6. request erasure or destruction under the conditions in KVKK Article 7,
  7. request that correction and erasure/destruction operations be notified to recipients,
  8. object to an adverse result arising from analysis exclusively by automated systems, and
  9. claim compensation for damage caused by unlawful processing.

Aris makes no legal or similarly significant adverse decision based solely on automated processing. Portfolio insights are informational. Human review and an objection channel will be provided before any such feature is introduced.

9. How to exercise your rights

If signed in, use the Privacy Centre to access/export, correct, erase or destroy data, withdraw consent, learn recipients, object to an automated result, or submit another request. If you cannot sign in, email info@alsendigital.net from your registered address and state your request, contact details and the right you wish to exercise.

We may proportionately verify identity and account ownership to avoid disclosing someone else's data. Applications are answered free of charge as soon as possible and no later than 30 days; only a fee permitted by the Turkish Data Protection Board tariff may be charged if the operation creates additional cost. If you find the response inadequate, you may complain to the Turkish Data Protection Board within the statutory time limits.

10. Security and administrative access

We use technical and organisational measures such as HTTPS/TLS, segregated access, least privilege, session and device-integrity controls, logging/monitoring, backups and appropriate encryption. Production-data administrator access is role-based, requires an approved purpose and support/incident ticket, and creates a user-specific audit record. Database operations and administrative roles are separated. Technical capability to access data does not authorise unrestricted use.

No system can guarantee absolute security. Please report suspected issues to the contact address.

11. Changes

This notice is versioned when the product, recipients, purposes, retention periods or legal requirements change. Material changes are communicated through an appropriate channel before they take effect, and renewed explicit consent is obtained where required. The notice version presented and consent choices are recorded per account.

External App Attest verifierIf a separate verifier is configured, iOS app/device-integrity proof and a one-way session-binding hash are sent to that service provider. Its actual legal name, country and transfer mechanism appear in the Privacy Centre; the built-in verifier creates no separate recipient.
Privacy-operations emailThe operations-team alert is only a generic action signal and contains no request ID, type, status, deadline, content, or user contact information. Ordinary privacy responses and request details are not sent to the email provider; they are shown in the signed-in Privacy Centre. Because sign-in is unavailable after account deletion, only a fixed, detail-free deletion result notice is included in the full-account-deletion email.
Logo.dev logo providerWhen Logo.dev is configured, only a verified domain or standard asset symbol is sent to retrieve a displayed institution or asset logo; the Aris account identifier and free text are not added. Before a new external request, a content-free account record of recipient and purpose is retained. The country and transfer mechanism appear in the Privacy Centre.
Market-data providersOnly a standard asset symbol, fund code, or currency pair is sent to Yahoo Finance and TEFAS and, when configured, Financial Modeling Prep and Alpha Vantage. The value may relate to an asset in your portfolio or a search; no Aris account identifier or free text is added. Each enabled provider's country and transfer mechanism appear in the Privacy Centre.