Last Update: October 7, 2026
MobiKreş and Renkli Kalem are management software used by preschools to run their student, parent and staff processes; below we refer to both of them simply as the "App". This document is both a privacy policy and a disclosure notice under Turkish Personal Data Protection Law No. 6698 (KVKK) and serves as our transparency notice under the GDPR.
In short
- The data controller for student data is the institution your child is enrolled in; MobiKreş processes that data on the institution's behalf.
- Student records, daily reports, messages, photos and videos are hosted in Europe.
- Authentication and push notification infrastructure are Google's global services; data is transferred abroad for these two paths. The full list is in section 5.
- Your data is never sold, never used for advertising, and never used to train artificial intelligence models.
- Card details are never collected; no credit card payment is processed through the App.
1. Who is the data controller?
The law distinguishes two roles: the data controller, who decides why and how data is processed, and the data processor, who processes it according to those instructions.
- For student, parent and staff data, the data controller is the institution the child is enrolled in (the preschool). The institution decides what data is collected; informing parents and obtaining the required explicit consent are its responsibility. MobiKreş processes this data only on the institution's instructions and only as far as the service requires.
- For website visits, contact form submissions, demo requests and support correspondence, MobiKreş is the data controller.
2. Personal data processed
- Identity: student's and parent's name, date of birth, class; staff name, title and field.
- Contact: email address, phone number.
- Education and daily tracking: attendance, pickup and handover records, sleep and nutrition information, end-of-day report, activity and development observations.
- Photos and videos: classroom activity footage, profile photo, documents shared by the institution.
- Payments and collections: fee plan, payment records. Card number, CVC or bank credentials are never collected at any stage.
- Read status: when you first open an announcement or survey. Only the school's management and the staff member who published the announcement can see it; other parents cannot.
- Technical and security records: sign-in records, session information, the device's notification token, and activity logs showing who accessed which record.
- Health (special category data): allergy and allergen information, the name, dose and time of medication handed to the institution, height and weight measurements, and health notes entered by the institution.
3. Purposes and legal grounds
- Enabling the institution to run its student, class, staff and attendance processes,
- Keeping parents informed about their child's day and allowing communication with the institution,
- Managing the secure pickup flow (who is authorised to collect the child),
- Tracking fees and collections,
- Delivering health-related precautions on time (allergen warning, medication reminder),
- Service security and compliance with legal obligations.
Data is processed on the grounds of performance of the contract between the institution and the parent (KVKK Art. 5/2-c), compliance with the institution's legal obligations (Art. 5/2-ç) and legitimate interest in the security of the service (Art. 5/2-f). Health data and the sharing of a child's photos or videos additionally require explicit consent (Art. 6/2). Consent is obtained separately from this notice, and only by the institution.
4. Health data, photos and videos
Allergy, medication and growth measurements are necessary for a child's safety, yet they belong to the most strictly protected category of personal data. Therefore:
- These fields are filled in by the institution only with the parent's explicit consent; without consent they are left empty and the rest of the service continues to work.
- Health data is accessible only to the child's own parent and to staff authorised by the institution.
- Allergen warnings are sent only to the parent of the child concerned and to authorised staff.
- This data is never used for advertising, profiling or analytics, and is shared with no one other than the infrastructure providers listed in section 5.
- Please note: push notifications reach your device through Google's notification infrastructure, and the notification text may contain your child's name and the subject of the warning.
Activity photos are shown only to the parents of the class the institution shared them with and to authorised staff; they are never published at a publicly reachable address. If you do not want your child's photo shared, informing your institution is enough; explicit consent can be withdrawn at any time.
The App is not directed at children; it is used by parents, teachers and institution administrators.
5. Recipients and international transfers
Data is never sold and never shared with third parties for advertising or marketing. Only the infrastructure providers below are used, purely to operate the service:
| Data |
Provider and purpose |
Location |
| Records, reports, messages | Google Cloud Firestore — database | Europe |
| Photos, videos, documents | Cloudflare R2 — file storage | Europe |
| Server logic (notifications, reporting) | Google Cloud Functions | Europe |
| Email, phone, hashed password | Firebase Authentication — identity | Outside Europe |
| Notification token and notification text | Firebase Cloud Messaging — push notifications | Outside Europe |
| Text or document sent to AI | Google Vertex AI — only when institution staff use the feature | Outside Europe |
| Name and email (password notice, invitation, support) | Resend — email delivery | Outside Europe |
Transfers marked "Outside Europe" fall under Article 9 of the KVKK and are necessary for the service to work; these providers process the data solely to deliver that service. Information may also be shared where a lawful request from a competent authority creates a legal obligation.
Cookies: the mobile app contains no analytics, advertising or crash-reporting tools. Google Analytics, the Google Ads conversion tag and Microsoft Clarity are used only on this website for visitor statistics and advertising measurement. You can block cookies through your browser settings.
6. Retention and deletion
- Data is retained while the institution's subscription and the child's enrolment continue.
- Once a deletion request is fulfilled, data is removed from live systems; copies in technical backups are deleted within 98 days at the latest.
- Records for which legislation requires a longer retention period (e.g. financial records) are kept for that period.
A parent or institution may request deletion of their account and their student's data. Simply send your request to destek@mobikres.com; it is completed within 30 days at the latest. Since the institution is the controller of student data, a deletion request concerning a currently enrolled student is fulfilled with the institution's approval.
7. Your rights and how to reach us
Under Article 11 of the KVKK you have the right to learn whether your personal data is processed, to request information about it, to learn the purpose of processing, to know the third parties to whom it is transferred at home or abroad, to request correction if it is incomplete or inaccurate, to request erasure where the conditions are met, to request that these actions be notified to the parties the data was transferred to, to object to a result against you produced solely by automated analysis, and to claim compensation for damages.
Requests concerning student data should first be addressed to the institution your child is enrolled in, as it is the data controller. If your request reaches us directly, we inform the institution in our capacity as processor and provide the support needed to fulfil it.
- ✉️ Email: destek@mobikres.com
- 📍 Web: www.mobikres.com
This document is updated whenever the infrastructure used or the applicable legislation changes; the update date appears at the top of the page.
Our technical and security practices (optional reading)
- Each institution's data is held in its own space; a user of one institution cannot reach another institution's data.
- Permissions are role-based (administrator, teacher, parent) and access decisions are made by server-side rules.
- All traffic is encrypted with TLS; data is stored encrypted at rest by the providers.
- Access to and changes in sensitive records are written to an activity log.
- Setting a strong password at first sign-in is mandatory; passwords are stored irreversibly and cannot be seen by anyone, including MobiKreş.
- Database backups are kept in Europe: point-in-time for 7 days, daily for 30 days, weekly for 98 days.
- While photos and videos are being viewed, a copy of the file is cached on the server nearest to the device for up to 7 days.