1.Data Controller
The data controller responsible for the processing of your personal data within the meaning of Article 4(7) GDPR is:
| Controller | Etka Ahmet Bulut, trading as "Civesto" (unregistered trade name) |
|---|---|
| Legal form | Sole proprietorship registered in Türkiye |
| Address | Kale Mah. Kavak Sk. Ata Plaza No:1, İç Kapı No:62, 51100 Merkez/Niğde, Türkiye |
| Commercial register | No commercial register number exists, as this legal form is not entered in a commercial register. |
| Tax identification | Turkish Tax ID (VKN) 1891086366 — Niğde Tax Office |
| Contact for all privacy matters | [email protected] |
| Data Protection Officer | No Data Protection Officer has been designated. Privacy enquiries are handled by the controller at the address above. |
| Representative in the EU Art. 27 | Appointment in progress. This entry will be updated once the appointment is completed. |
The controller operates the Civesto mobile application (the "App") and the associated authority web panel (together, the "Service"), which is designed to allow citizens to document alleged traffic violations by photograph and to submit them to the competent authority.
The App is not yet published in any app store, and no integration agreement with any public authority has been concluded.
2.Personal Data We Collect
We collect and process the categories of personal data set out below.
2.1 Account data
- Display name (mandatory)
- Email address (mandatory; used for authentication and service notices)
- Password hash (the plaintext password is never stored)
- Country of residence and preferred language
2.2 Report data
- Photographs of the alleged violation. The Service does not record or upload video.
- Geolocation (latitude, longitude, accuracy radius, timestamp)
- Free-text description and selected violation category (one of 16 categories: six relating to unlawful occupation of road space and ten relating to dangerous driving)
2.3 Technical data
- IP address (processed for security and abuse prevention)
- Device model, operating-system version, App version, locale
- Crash diagnostics (stack traces, no personal content)
- Authentication and security event logs (login time, logout, password change)
2.4 Special categories of personal data
We do not solicit, and we do not knowingly process, biometric facial-identification data, health data, or political opinions.
What the Service does not do. The Service performs no automatic number-plate recognition (no OCR), no automatic detection or blurring of faces, and no automated issuing of penalties. A report consists of the photograph as submitted by the user together with the metadata listed above.
3.Lawful Basis
We process personal data on the following lawful bases under Article 6 GDPR:
| Article | Basis | Applies to |
|---|---|---|
| Art. 6(1)(b) | Performance of a contract | Account creation, authentication, transmission of your reports, customer support. |
| Art. 6(1)(c) | Compliance with a legal obligation | Anti-fraud measures, response to lawful requests from competent authorities, retention of evidence for the period prescribed by national procedural law. |
| Art. 6(1)(e) | Public interest task | Transmission of reports to traffic and road-safety authorities supporting the enforcement of national highway codes. |
| Art. 6(1)(f) | Legitimate interests | Service improvement, abuse detection, network security, aggregated and anonymised statistics. |
| Art. 6(1)(a) | Consent | Optional, non-essential features and communications where these are offered and you have opted in. Consent is freely given, specific, informed and may be withdrawn at any time under Article 7(3) GDPR. |
4.Purposes of Processing
Personal data are processed for the following purposes only:
- To capture a citizen traffic-violation report and prepare it for submission to the authority competent for the place of the alleged violation.
- To verify the authenticity and integrity of submitted reports (anti-fraud, deduplication).
- To comply with legal obligations relating to road-traffic enforcement and to respond to lawful orders of judicial or administrative authorities.
- To improve the Service through aggregated, irreversibly anonymised statistics (Recital 26 GDPR).
- To prevent, detect and respond to security incidents, abuse and unauthorised access.
We do not use personal data for behavioural advertising, profiling with legal effect, or automated decision-making within the meaning of Article 22 GDPR.
5.Recipients and Data Sharing
5.1 Competent authorities
The Service is designed so that a report is made available only to the public authority competent for the location at which the alleged violation took place.
5.2 Sub-processors
We engage the following sub-processors under Article 28 GDPR data-processing agreements:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd | Server hosting, database and file storage | Vilnius, Lithuania (EU) |
The Service uses no payment processor, because it offers no paid features, subscriptions or in-app purchases. Any addition or replacement of a sub-processor is reflected in this Policy; we give at least 30 days' advance notice and you may object on legitimate grounds.
6.International Transfers
The application server, database and file storage are operated by Hostinger International Ltd in Vilnius, Lithuania. Personal data are therefore stored inside the European Union.
The controller is established in Türkiye, which is not the subject of a European Commission adequacy decision. Access to the data by the controller from Türkiye constitutes a transfer to a third country within the meaning of Chapter V GDPR. The corresponding transfer documentation is being put in place as part of the legal review noted at the top of this page, and this section will be updated when it is complete.
Questions about international transfers can be sent to [email protected].
7.Retention Periods
We store personal data only for as long as necessary for the purposes for which they were collected.
| Category | Retention | Reason |
|---|---|---|
| Account data | Until deletion request, then up to 30 days in encrypted backups before complete erasure | Service contract |
| Report metadata (location, timestamp, category, description) | 5 years from submission | Statutory limitation period for road-traffic offences in most EU jurisdictions |
| Report photographs | 2 years from submission | Evidentiary value typically expires once the administrative procedure concludes |
| Authentication and security event logs | Kept no longer than necessary for security purposes; a defined period is being set as part of the legal review | Detection and investigation of unauthorised access and abuse |
| Aggregated, irreversibly anonymised statistics | Indefinite | No longer personal data within the meaning of Recital 26 GDPR |
| Customer support correspondence | 3 years from last contact | Limitation period for contractual claims |
Where you exercise your right to erasure (Article 17 GDPR), we delete or anonymise all data not subject to a stricter retention obligation within 30 days, and we confirm completion in writing.
8.Your Rights
Under Articles 12 to 22 GDPR you have the following rights:
- Right of access Art. 15 — to obtain confirmation as to whether we process personal data concerning you, and a copy of those data.
- Right to rectification Art. 16 — to have inaccurate data corrected without undue delay.
- Right to erasure Art. 17 — the "right to be forgotten", subject to the exceptions listed in Article 17(3).
- Right to restriction Art. 18 — to require us to suspend processing where one of the conditions in Article 18(1) applies.
- Right to data portability Art. 20 — to receive data in a structured, commonly used, machine-readable format and to transmit them to another controller.
- Right to object Art. 21 — to object, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f).
- Right to withdraw consent Art. 7(3) — at any time, without affecting the lawfulness of processing prior to withdrawal.
- Right not to be subject to a decision based solely on automated processing Art. 22 — Civesto does not carry out such processing.
- Right to lodge a complaint with a supervisory authority (see Section 9).
You may exercise any of these rights free of charge by writing to [email protected]. We respond within one month of receipt of the request, extendable by two further months for complex requests under Article 12(3) GDPR; we will inform you of any extension within the first month.
We do not charge a fee unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, in accordance with Article 12(5) GDPR.
9.Data Protection Authorities
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Article 77 GDPR).
The controller is not established in the European Union. The one-stop-shop mechanism therefore does not apply and there is no lead supervisory authority within the meaning of Article 56 GDPR. You may lodge your complaint with the supervisory authority of any Member State.
A current list of all national supervisory authorities is published by the European Data Protection Board at edpb.europa.eu. Users in the United Kingdom may complain to the Information Commissioner's Office at ico.org.uk.
10.Cookies and Similar Technologies
The mobile App does not use cookies. The website at civesto.com uses the following limited categories of cookies and local storage:
- Strictly necessary — session identifier, CSRF token, security flags. No consent required (Article 5(3) of Directive 2002/58/EC, second sentence).
- Preference — language and theme selection. Stored locally; no consent required.
We do not use advertising, profiling, fingerprinting, or social-media tracking cookies. If analytics or any other non-essential cookie is introduced, it will be set only after you have given consent, and this section will be updated first.
11.Children
The Service is intended exclusively for adults (18 years or older), as the act of submitting a traffic-violation report and confirming its accuracy presupposes full legal capacity. We do not knowingly collect personal data from minors.
If we become aware that we have collected personal data from a person under the age of 18, we will delete the relevant account and all associated data without undue delay. If you believe a minor has registered an account, please contact [email protected].
12.Security of Processing
In accordance with Article 32 GDPR, we have implemented appropriate technical and organisational measures, including:
- Encryption in transit using TLS for all connections to the Service.
- Passwords are stored only as salted hashes and are never recoverable in plaintext.
- Role-based access control with least-privilege defaults; access to production data is restricted to the controller.
- Access logging for administrative actions.
- Notification of a personal data breach to the competent supervisory authority within 72 hours where required by Article 33 GDPR, and to affected data subjects where required by Article 34 GDPR.
We hold no security certification and make no claim of one. Security measures are being reviewed and extended before public launch; this section will be updated to reflect the measures actually in place.
13.Changes to this Policy
We may update this Privacy Policy to reflect changes in our processing activities, in applicable law, or in the guidance of supervisory authorities. The current version always carries the date shown at the top of this page.
Material changes — such as a new category of personal data, a new purpose of processing, or a new sub-processor outside the EEA — are notified to registered users at least 30 days in advance by email. Your continued use of the Service after the effective date of the revised Policy constitutes acknowledgement of the changes. Where consent is required under Article 6(1)(a) GDPR, we ask for fresh consent.
Previous versions of this Policy are archived and available on request from [email protected].
14.Contact
| Privacy enquiries | [email protected] |
|---|---|
| General contact | [email protected] |
| Postal address | Etka Ahmet Bulut (Civesto), Kale Mah. Kavak Sk. Ata Plaza No:1, İç Kapı No:62, 51100 Merkez/Niğde, Türkiye |
| Representative in the EU Art. 27 | Appointment in progress. |
When contacting us in relation to your personal data, please indicate the email address associated with your account so that we can identify you. We may ask for additional information where reasonably necessary to confirm your identity (Article 12(6) GDPR).