Your Privacy Matters
At HelpSteps, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application. This policy also serves as the Data Protection Clarification Text (Aydınlatma Metni) required under Turkish Personal Data Protection Law No. 6698 (KVKK) and complies with the European Union General Data Protection Regulation (GDPR).
📋 Data Protection Clarification Text (KVKK Aydınlatma Metni)
Pursuant to Article 10 of Turkish Personal Data Protection Law No. 6698
Data Controller
PYUA DİJİTAL YAZILIM SANAYİ ve TİCARET A.Ş.
Address: Ümit mah. 2479 cad. No:2/3 Çankaya/Ankara, Turkey
Phone: +90 850 308 33 58
Email: [email protected]
Categories of Personal Data Processed
- Identity Data: Name, surname, username, profile photo
- Contact Data: Email address, phone number
- Account Data: User ID, password (encrypted), account preferences
- Activity Data: Step counts, distance traveled, active minutes, calories burned
- Health Data: Physical activity metrics synchronized from health platforms
- Location Data: GPS coordinates (only when permission is granted)
- Device Data: Device type, operating system, unique identifiers
- Usage Data: App interactions, features used, session duration
Purposes of Data Processing
- Providing step tracking and activity monitoring services
- Facilitating charitable donation calculations based on user activity
- Managing user accounts and authentication
- Enabling participation in challenges, teams, and leaderboards
- Communicating service updates and promotional materials (with consent)
- Analyzing and improving application performance
- Ensuring platform security and preventing fraud
- Fulfilling legal and regulatory obligations
Methods of Data Collection
Personal data is collected through: mobile application registration, device sensors (pedometer, accelerometer), third-party health platform integrations (Apple Health, Google Fit), direct user input, and automated tracking technologies.
Legal Basis for Processing (KVKK Article 5)
- Explicit Consent: For health data, marketing communications, and optional features
- Contract Performance: For providing core application services
- Legal Obligation: For compliance with applicable laws
- Legitimate Interest: For fraud prevention, security, and service improvement
Data Recipients and Transfers
Personal data may be shared with: cloud service providers, analytics services, corporate program sponsors (aggregated data only), charitable partners (donation attribution), and legal authorities when required by law. International transfers are conducted with appropriate safeguards.
Your Rights Under KVKK Article 11
You have the right to: learn whether your data is processed; request information about processing; learn the purpose and whether data is used accordingly; know third parties to whom data is transferred; request correction of incomplete or inaccurate data; request deletion or destruction under legal conditions; request notification of corrections to third parties; object to processing results against your interests; and claim compensation for damages from unlawful processing.
To exercise your rights: Contact us at [email protected] or submit a written request to our address.
1. Data Controller Information
2. Overview and Scope
2.1 About This Policy
This Privacy Policy describes how PYUA DİJİTAL YAZILIM SANAYİ ve TİCARET A.Ş. ("Company," "we," "us," or "our") collects, uses, discloses, and protects the personal information of users ("you" or "your") of the HelpSteps mobile application ("Application" or "App").
2.2 Scope of Application
This Policy applies to:
- All users of the HelpSteps mobile application;
- Visitors to our website and related services;
- Participants in corporate wellness programs through HelpSteps;
- Individuals who interact with us through customer support.
2.3 Legal Framework
This Policy is designed to comply with:
- KVKK: Turkish Personal Data Protection Law No. 6698;
- GDPR: European Union General Data Protection Regulation;
- CCPA: California Consumer Privacy Act (for California residents);
- Other applicable data protection laws and regulations.
3. Data We Collect
3.1 Information You Provide Directly
| Data Category |
Examples |
Purpose |
| Identity |
Name, username, profile photo |
Account creation and identification |
| Contact |
Email address, phone number |
Communication and account recovery |
| Profile |
Age, gender, height, weight |
Personalization and activity calculations |
| Preferences |
Selected charities, notification settings, language |
Service customization |
| Content |
Team names, challenge descriptions, comments |
Community features |
| Support |
Correspondence, feedback, inquiries |
Customer service |
3.2 Information Collected Automatically
| Data Category |
Examples |
Purpose |
| Activity |
Step counts, distance, active time, calories |
Core service functionality |
| Device |
Device model, OS version, unique identifiers |
Technical support and optimization |
| Usage |
Features accessed, session duration, interactions |
Service improvement |
| Location |
GPS coordinates (when permitted) |
Route tracking and localization |
| Technical |
IP address, browser type, crash logs |
Security and debugging |
3.3 Information from Third Parties
- Health Platforms: Data synchronized from Apple Health, Google Fit, or similar services (with your permission);
- Social Login: Basic profile information if you sign in using Google or Apple;
- Corporate Programs: Employee information provided by participating employers;
- Payment Processors: Transaction confirmation (we do not store payment card details).
4. Purposes of Processing
4.1 Core Service Delivery
- Tracking and recording your physical activity;
- Calculating step-based donations to charitable organizations;
- Managing your account and preferences;
- Enabling participation in challenges, teams, and leaderboards;
- Synchronizing data with connected health platforms.
4.2 Service Improvement
- Analyzing usage patterns to enhance features;
- Conducting research and analytics (using aggregated data);
- Testing new features and functionality;
- Troubleshooting technical issues.
4.3 Communication
- Sending service-related notifications;
- Responding to your inquiries and support requests;
- Providing updates about your charitable impact;
- Sending marketing communications (with your consent).
4.4 Security and Compliance
- Detecting and preventing fraud and unauthorized access;
- Ensuring the security of our systems;
- Complying with legal obligations and responding to legal requests;
- Enforcing our Terms of Service.
5. Legal Basis for Processing
We process your personal data based on the following legal grounds:
| Legal Basis |
Description |
Examples |
| Consent |
You have given explicit consent for processing |
Health data access, marketing emails, location tracking |
| Contract |
Processing necessary to fulfill our agreement with you |
Account management, step tracking, donation calculations |
| Legal Obligation |
Processing required to comply with law |
Tax records, responding to legal requests |
| Legitimate Interest |
Processing for our legitimate business interests |
Fraud prevention, security, analytics |
5.1 Consent Withdrawal
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal. You can manage your consents through the Application settings or by contacting us.
6. Health and Activity Data
Special Category Data: Activity and health-related data may be considered "special category" personal data under GDPR and "sensitive personal data" under KVKK. We process this data only with your explicit consent and apply enhanced protection measures.
6.1 Types of Health Data
- Step counts and walking/running activity;
- Distance traveled and active minutes;
- Estimated calories burned;
- Data synchronized from health platforms (heart rate, sleep, etc., if permitted).
6.2 Health Data Consent
Before accessing your health data, we will request your explicit consent through:
- Clear consent prompts during app setup;
- Permission requests for device sensor access;
- Authorization dialogs for health platform integrations.
6.3 Health Data Protection
We protect your health data by:
- Encrypting data in transit and at rest;
- Limiting access to authorized personnel only;
- Not selling health data to third parties;
- Not using health data for advertising purposes;
- Allowing you to delete your data at any time.
6.4 Apple Health and Google Fit
When you connect to Apple Health or Google Fit:
- We access only the data categories you authorize;
- Health data is used solely for app functionality;
- We do not share raw health data with third parties;
- You can revoke access at any time through device settings.
7. Cookies and Tracking Technologies
7.1 Technologies We Use
- Device Identifiers: We use device-specific identifiers for app functionality and analytics;
- Analytics SDKs: We use analytics tools to understand app usage;
- Crash Reporting: We collect crash logs to improve app stability;
- Push Notifications: We use tokens to deliver notifications you've enabled.
7.2 Third-Party Analytics
We may use third-party analytics services such as:
- Firebase Analytics (Google)
- Amplitude
- Mixpanel
These services may collect information about your app usage. You can opt out of personalized tracking through your device settings.
7.3 Advertising
We do not currently serve third-party advertisements in the Application. If this changes, we will update this Policy and obtain necessary consents.
8. Data Sharing and Disclosure
8.1 Service Providers
We share data with trusted service providers who assist us in operating the Application:
- Cloud Hosting: Data storage and processing infrastructure;
- Analytics: Usage analysis and improvement;
- Email Services: Transactional and marketing communications;
- Customer Support: Help desk and support tools.
All service providers are contractually bound to protect your data and use it only for specified purposes.
8.2 Charitable Partners
We share aggregated, anonymized step data with charitable partners to facilitate donations. Individual user data is not disclosed to charities without explicit consent.
8.3 Corporate Program Sponsors
For corporate wellness program participants:
- Aggregated team statistics may be shared with your employer;
- Individual data is only shared with your explicit consent;
- Employers cannot access individual health data without permission.
8.4 Legal Requirements
We may disclose your data when required by law or to:
- Comply with legal processes or government requests;
- Protect our rights, property, or safety;
- Prevent fraud or abuse;
- Enforce our Terms of Service.
8.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the business transaction. We will notify you of any such change.
8.6 No Sale of Personal Data
We Do Not Sell Your Personal Data. We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
9. International Data Transfers
9.1 Transfer Locations
Your data may be processed in countries other than your country of residence, including Turkey, countries within the European Economic Area (EEA), and the United States. These countries may have different data protection laws than your jurisdiction.
9.2 Transfer Safeguards
When transferring data internationally, we implement appropriate safeguards:
- Standard Contractual Clauses: EU-approved contract terms with data recipients;
- Adequacy Decisions: Transfers to countries recognized as providing adequate protection;
- Binding Corporate Rules: Internal policies for intra-group transfers;
- Explicit Consent: Where legally required and appropriate.
9.3 Turkish Data Protection Board
For transfers from Turkey, we comply with KVKK requirements and any decisions of the Turkish Personal Data Protection Board regarding international transfers.
10. Data Retention
10.1 Retention Periods
| Data Type |
Retention Period |
Basis |
| Account Information |
Duration of account + 2 years |
Service provision |
| Activity Data |
Duration of account + 1 year |
Historical records |
| Health Data |
Until consent withdrawn or account deleted |
Consent-based |
| Usage Analytics |
2 years (aggregated indefinitely) |
Service improvement |
| Support Communications |
3 years |
Customer service records |
| Legal/Tax Records |
10 years |
Legal obligation |
10.2 Deletion
Upon account deletion or retention period expiry, we will:
- Delete or anonymize your personal data;
- Retain only data required by law;
- Remove data from active systems within 30 days;
- Remove data from backup systems within 90 days.
11. Data Security
11.1 Technical Measures
- Encryption: TLS encryption for data in transit; AES-256 encryption for data at rest;
- Access Controls: Role-based access with strong authentication;
- Secure Infrastructure: Hosted on certified cloud platforms;
- Regular Testing: Periodic security assessments and penetration testing;
- Monitoring: Continuous security monitoring and logging.
11.2 Organizational Measures
- Employee training on data protection;
- Confidentiality agreements with staff;
- Data protection policies and procedures;
- Vendor security assessments;
- Incident response plans.
11.3 Data Breach Response
In the event of a data breach:
- We will investigate and contain the breach promptly;
- We will notify the relevant supervisory authority within 72 hours (where required);
- We will inform affected users if the breach poses high risk to their rights;
- We will take steps to mitigate harm and prevent recurrence.
12. Your Rights
📋 Your Data Protection Rights
Depending on your location, you may have the following rights regarding your personal data:
12.1 Rights Under GDPR (EU/EEA Residents)
- Right of Access: Obtain confirmation of processing and access your data;
- Right to Rectification: Correct inaccurate or incomplete data;
- Right to Erasure: Request deletion of your data ("right to be forgotten");
- Right to Restriction: Limit processing of your data;
- Right to Data Portability: Receive your data in a portable format;
- Right to Object: Object to processing based on legitimate interests;
- Right to Withdraw Consent: Withdraw previously given consent;
- Right to Lodge a Complaint: File a complaint with a supervisory authority.
12.2 Rights Under KVKK (Turkish Residents)
As per Article 11 of KVKK, you have the right to:
- Learn whether your personal data is processed;
- Request information about processing if your data has been processed;
- Learn the purpose of processing and whether data is used accordingly;
- Know the third parties to whom your data is transferred domestically or abroad;
- Request rectification of incomplete or inaccurate data;
- Request deletion or destruction of data under Article 7;
- Request notification of rectification/deletion to third parties;
- Object to results arising from automated processing;
- Claim compensation for damages from unlawful processing.
12.3 Exercising Your Rights
To exercise your rights:
- In-App: Use the privacy settings within the Application;
- Email: Contact [email protected];
- Written Request: Send a signed request to our registered address.
We will respond to your request within 30 days (or as required by applicable law). We may request verification of your identity before processing your request.
12.4 Supervisory Authorities
Turkey: Kişisel Verileri Koruma Kurumu (KVKK) - www.kvkk.gov.tr
EU: Contact your local Data Protection Authority
13. Children's Privacy
13.1 Age Restrictions
The Application is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, please contact us immediately.
13.2 Parental Consent
For users between 13 and 18 years of age (or the age of majority in their jurisdiction), parental or guardian consent may be required. Parents or guardians may contact us to review, delete, or manage their child's data.
14. Third-Party Services
14.1 Third-Party Links
The Application may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
14.2 Social Features
If you share content through social media or connect social accounts, the respective platform's privacy policy applies to that interaction.
14.3 Health Platform Integrations
Apple Health and Google Fit integrations are governed by Apple and Google's respective privacy policies. We access only authorized data and comply with their developer guidelines.
15. Changes to This Policy
15.1 Policy Updates
We may update this Privacy Policy from time to time. Changes will be effective upon posting the revised Policy within the Application or on our website. The "Last Updated" date at the top indicates when the Policy was last revised.
15.2 Notification of Changes
For material changes, we will provide notice through:
- In-app notification;
- Email notification;
- Prominent posting on our website.
15.3 Continued Use
Your continued use of the Application after changes are posted constitutes your acceptance of the revised Policy. If you do not agree with the changes, you should discontinue use of the Application.
Your Trust Matters: We are committed to protecting your privacy and being transparent about our data practices. If you have any concerns about how we handle your personal data, please do not hesitate to contact us. We value your trust and take your privacy seriously.