1. Controller and contact
The controller under Türkiye's Personal Data Protection Law No. 6698 (KVKK) is ALSEN DIGITAL LTD. Registered address: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, GB. Contact info@alsendigital.net for privacy questions and data-subject applications.
2. Scope
This notice covers the Aris Android and iOS apps, the server services used by the mobile app, and this legal centre. The legal site needs no sign-in, cannot access your Aris account or financial records, and uses no advertising or analytics cookies.
3. Categories of personal data
Account and profile
Email address, identity-provider identifier, display name, username, profile image, language, country and preferences.
Financial and user-provided content
Portfolio assets, transactions, cash and liabilities, income and expenses, budgets, goals, notes, community content, and images or documents you upload.
Exchange connections
If you connect Binance or Bybit, Aris processes a read-only API credential, balance records, and trade records. The provider verifies the key; keys with trading, transfer, or withdrawal access are rejected.
Open Banking
If you choose and separately authorise the feature, connection, account, balance and transaction data may be processed through a licensed provider. Aris does not see or retain your online-banking password.
Subscription and store
App user identifier, product, entitlement and store transaction identifiers. Full card details are processed by Apple or Google and are not stored by Aris.
Device, communications, security and diagnostics
App version, device and operating-system details, push tokens, IP and request logs, session/integrity signals, security events, support messages and error records. Feedback retains only coarse browser, operating-system, device/screen class, language and generalised app section; full user-agent strings, device models and query-bearing page URLs are not retained.
On-device preferences and offline state
The offline community feed, local copies of saved posts, upvote references, and language, appearance, and navigation preferences may be held only on your device.
Optional measurement, advertising and marketing
Usage events or promotional communications you select are processed only after separate explicit consent. Analytics retains only the language and coarse application section; it sends no query, username, asset symbol, record ID or nested route, and never measures authentication or administrator screens. This release uses no in-app advertising SDK or cross-app tracking. Before such technology is introduced, this notice, store declarations and the consent flow will be updated.
4. Purposes and legal bases
- Account creation, authentication, portfolio/budget/goal features and support: processing necessary to enter into or perform the service contract.
- Subscription validation, accounting and lawful authority requests: compliance with the controller's legal obligations.
- Session security, abuse prevention, debugging and service integrity: legitimate interests that do not override your fundamental rights and, where applicable, legal obligations.
- Open Banking: performance of the service at your request plus any separate authorisation required by the provider.
- Optional analytics, personalised advertising or marketing: specific, informed and withdrawable explicit consent.
You may withdraw consent in the Privacy Centre at any time. Withdrawal does not affect earlier lawful processing and does not disable core account functionality.
6. International transfers
Some providers may be located outside Türkiye or process data abroad. A transfer takes place only where an applicable KVKK condition and safeguard exists, such as an adequacy decision, Board-approved binding corporate rules, a duly executed standard contract, or a statutory exceptional case. Explicit consent is sought separately only when it is genuinely appropriate and the other conditions are unavailable.
Active destination countries and the mechanism used are generated from the configured transfer register shown in the Privacy Centre. Where a standard contract is used, its signing and Authority-notification dates are also recorded; the release gate rejects undocumented transfers.
7. Retention, erasure and destruction
Account and financial records remain while your account is active or until you delete them earlier. Feedback and its coarse diagnostic fields are retained only as long as needed to handle the support matter and are removed earlier if the account is deleted. A transient external catalogue search does not create a separate stored copy of the search text; a content-free account record identifying the recipient and fixed purpose remains while the account is active and is deleted with it. Unfinished form and community drafts remain only for the current app/browser session; portfolio values are not written to persistent browser storage. The on-device offline community feed is kept for at most 7 days; saved-post copies and upvote references remain until the user removes them, signs out, resets data, or deletes the account. A data-export file created in the device cache for sharing is deleted when the share sheet closes. Session and security credentials are removed when they expire. Salt Edge webhook-deduplication summaries are retained for at most 30 days, and Open Banking synchronisation and error logs for at most 90 days. Verified uploads left unattached or removed from a profile, community post, or receipt record are deleted from the file provider within at most 7 days. Limited evidence of consents, notices, requests and deletion operations is retained with restricted access only for as long as needed and is not used for marketing or profiling.
After verified account deletion, active database records, files you own, push links and supported external-provider identities/authorisations are erased or irreversibly anonymised. Account-derived device caches and session drafts are cleared on sign-out, data reset, or account erasure. Copies in encrypted backups are destroyed through the normal cycle within at most 30 days. A restricted deletion record containing only a one-way user hash and deletion time prevents a backup restore from reviving the account.
See Account and Data Deletion for process details and the route available outside the app.
8. Your rights under KVKK Article 11
You may apply to the controller to:
- learn whether your personal data is processed,
- request information if it has been processed,
- learn the purpose of processing and whether it is used consistently with that purpose,
- know the third parties to whom it is transferred in Türkiye or abroad,
- request correction of incomplete or inaccurate data,
- request erasure or destruction under the conditions in KVKK Article 7,
- request that correction and erasure/destruction operations be notified to recipients,
- object to an adverse result arising from analysis exclusively by automated systems, and
- claim compensation for damage caused by unlawful processing.
Aris makes no legal or similarly significant adverse decision based solely on automated processing. Portfolio insights are informational. Human review and an objection channel will be provided before any such feature is introduced.
9. How to exercise your rights
If signed in, use the Privacy Centre to access/export, correct, erase or destroy data, withdraw consent, learn recipients, object to an automated result, or submit another request. If you cannot sign in, email info@alsendigital.net from your registered address and state your request, contact details and the right you wish to exercise.
We may proportionately verify identity and account ownership to avoid disclosing someone else's data. Applications are answered free of charge as soon as possible and no later than 30 days; only a fee permitted by the Turkish Data Protection Board tariff may be charged if the operation creates additional cost. If you find the response inadequate, you may complain to the Turkish Data Protection Board within the statutory time limits.
10. Security and administrative access
We use technical and organisational measures such as HTTPS/TLS, segregated access, least privilege, session and device-integrity controls, logging/monitoring, backups and appropriate encryption. Production-data administrator access is role-based, requires an approved purpose and support/incident ticket, and creates a user-specific audit record. Database operations and administrative roles are separated. Technical capability to access data does not authorise unrestricted use.
No system can guarantee absolute security. Please report suspected issues to the contact address.
11. Changes
This notice is versioned when the product, recipients, purposes, retention periods or legal requirements change. Material changes are communicated through an appropriate channel before they take effect, and renewed explicit consent is obtained where required. The notice version presented and consent choices are recorded per account.