0. Introduction / Parties
This Data Sharing Agreement ("Agreement") regulates the framework regarding the sharing of personal data between Mentoris and the trainers and students using the platform ("Parties"). By using the platform, you are deemed to have accepted this Agreement.
1. Definitions
Data Controller/Processor: Meanings as defined in KVKK and (if applicable) GDPR. Mentoris may act as a data controller or data processor depending on the nature of the product.
2. Purposes of Sharing
- Account creation, login, and authorization
- Keeping and sharing measurements, health data, programs, progress records within the scope of trainer-student relationship
- Notifications, contract and policy updates
- Security, debugging, support, hosting, and backup
- Analytics and product development (anonymized/pseudonymized)
3. Data Categories Shared
- Identity and contact data (name, surname, email, phone, etc.)
- Account and usage data (session, device, operation logs)
- Payment and billing data (via payment providers)
- Content/profile data (photos, videos, goals, surveys)
- Health data (height, weight, medical condition declaration, etc.) – based on explicit consent or appropriate processing conditions in legislation.
4. Legal Basis
Data is processed within the scope of one/more of the legal reasons: performance of the contract, legitimate interest, legal obligation, or explicit consent.
5. Obligations of Parties
- Processing and sharing only for the specified purposes
- Conducting disclosure and consent processes; responding to rights requests
- Appropriate technical and administrative security measures
- Contractual confidentiality/security conditions with sub-suppliers
- Notification and cooperation without delay in case of violation
6. Security and Breach Notification
Security Measures: TLS/SSL encryption, access restrictions, authorization, logging/monitoring, and regular tests are applied.
Data Breach Notification: In case of a personal data breach, the relevant party and, if necessary, the supervisory authority are informed in accordance with the legislation and as soon as possible.
7. Transfers
Transfer is made to service providers such as hosting, email/SMS, analytics, payment institutions; only to the extent necessary for the service and with contractual assurances. Compliance mechanisms with KVKK/GDPR are applied in transfers abroad.
8. Retention
It is stored during the account period and for the period required by legislation; at the end of the period, it is deleted/anonymized.
9. Rights and Liability
Data subjects can exercise their rights of access, correction, deletion, objection, data portability via [email protected].
Parties are responsible for damages arising from the violation of this agreement in proportion to their fault. Mentoris is an intermediary platform and is not responsible for content and results between users.
10. Dispute Resolution and Contact
Turkish law applies; Istanbul (Central) Courts and Enforcement Offices are authorized.
Contact: [email protected]