Privacy Policy

Last Update: October 7, 2026

MobiKreş and Renkli Kalem are management software used by preschools to run their student, parent and staff processes; below we refer to both of them simply as the "App". This document is both a privacy policy and a disclosure notice under Turkish Personal Data Protection Law No. 6698 (KVKK) and serves as our transparency notice under the GDPR.

In short

  • The data controller for student data is the institution your child is enrolled in; MobiKreş processes that data on the institution's behalf.
  • Student records, daily reports, messages, photos and videos are hosted in Europe.
  • Authentication and push notification infrastructure are Google's global services; data is transferred abroad for these two paths. The full list is in section 5.
  • Your data is never sold, never used for advertising, and never used to train artificial intelligence models.
  • Card details are never collected; no credit card payment is processed through the App.

1. Who is the data controller?

The law distinguishes two roles: the data controller, who decides why and how data is processed, and the data processor, who processes it according to those instructions.

2. Personal data processed

3. Purposes and legal grounds

Data is processed on the grounds of performance of the contract between the institution and the parent (KVKK Art. 5/2-c), compliance with the institution's legal obligations (Art. 5/2-ç) and legitimate interest in the security of the service (Art. 5/2-f). Health data and the sharing of a child's photos or videos additionally require explicit consent (Art. 6/2). Consent is obtained separately from this notice, and only by the institution.

4. Health data, photos and videos

Allergy, medication and growth measurements are necessary for a child's safety, yet they belong to the most strictly protected category of personal data. Therefore:

Activity photos are shown only to the parents of the class the institution shared them with and to authorised staff; they are never published at a publicly reachable address. If you do not want your child's photo shared, informing your institution is enough; explicit consent can be withdrawn at any time.

The App is not directed at children; it is used by parents, teachers and institution administrators.

5. Recipients and international transfers

Data is never sold and never shared with third parties for advertising or marketing. Only the infrastructure providers below are used, purely to operate the service:

Data Provider and purpose Location
Records, reports, messagesGoogle Cloud Firestore — databaseEurope
Photos, videos, documentsCloudflare R2 — file storageEurope
Server logic (notifications, reporting)Google Cloud FunctionsEurope
Email, phone, hashed passwordFirebase Authentication — identityOutside Europe
Notification token and notification textFirebase Cloud Messaging — push notificationsOutside Europe
Text or document sent to AIGoogle Vertex AI — only when institution staff use the featureOutside Europe
Name and email (password notice, invitation, support)Resend — email deliveryOutside Europe

Transfers marked "Outside Europe" fall under Article 9 of the KVKK and are necessary for the service to work; these providers process the data solely to deliver that service. Information may also be shared where a lawful request from a competent authority creates a legal obligation.

Cookies: the mobile app contains no analytics, advertising or crash-reporting tools. Google Analytics, the Google Ads conversion tag and Microsoft Clarity are used only on this website for visitor statistics and advertising measurement. You can block cookies through your browser settings.

6. Retention and deletion

A parent or institution may request deletion of their account and their student's data. Simply send your request to destek@mobikres.com; it is completed within 30 days at the latest. Since the institution is the controller of student data, a deletion request concerning a currently enrolled student is fulfilled with the institution's approval.

7. Your rights and how to reach us

Under Article 11 of the KVKK you have the right to learn whether your personal data is processed, to request information about it, to learn the purpose of processing, to know the third parties to whom it is transferred at home or abroad, to request correction if it is incomplete or inaccurate, to request erasure where the conditions are met, to request that these actions be notified to the parties the data was transferred to, to object to a result against you produced solely by automated analysis, and to claim compensation for damages.

Requests concerning student data should first be addressed to the institution your child is enrolled in, as it is the data controller. If your request reaches us directly, we inform the institution in our capacity as processor and provide the support needed to fulfil it.

This document is updated whenever the infrastructure used or the applicable legislation changes; the update date appears at the top of the page.

Our technical and security practices (optional reading)
  • Each institution's data is held in its own space; a user of one institution cannot reach another institution's data.
  • Permissions are role-based (administrator, teacher, parent) and access decisions are made by server-side rules.
  • All traffic is encrypted with TLS; data is stored encrypted at rest by the providers.
  • Access to and changes in sensitive records are written to an activity log.
  • Setting a strong password at first sign-in is mandatory; passwords are stored irreversibly and cannot be seen by anyone, including MobiKreş.
  • Database backups are kept in Europe: point-in-time for 7 days, daily for 30 days, weekly for 98 days.
  • While photos and videos are being viewed, a copy of the file is cached on the server nearest to the device for up to 7 days.
Go Back