PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
This notice has been prepared for the purpose of informing FESİN GSN Club users about the processing of their personal data within the scope of Article 10 of the Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu).
Identity of the Data Controller
The data controller is FESİN EĞİTİM HİZMETLERİ LTD. ŞTİ., which operates the FESİN GSN Club platform.
Data Controller: FESİN EĞİTİM HİZMETLERİ LTD. ŞTİ.
Address: ACIBADEM MAH. ACIBADEM CAD. NO: 56/2 KADIKÖY/İSTANBUL, TÜRKİYE
E-mail: info@fiin.com.tr
Categories of Personal Data Processed
Depending on the use of the platform, the following data categories may be processed: identity; contact; personnel file/professional information; user transaction; transaction security; training/participation/certification; examination and assessment; visual and audio records; forum/community and user content; requests/complaints; legal proceedings; and, where applicable, user content that may contain special categories of personal data.
The principal purpose of the platform is not to process student data.
|
Processing Activity / Purpose |
Main Data Categories |
Legal Ground (draft) |
Method of Collection |
|
Creation of membership, account and access management |
Identity, contact, institution/position, user account |
KVKK Art. 5/2-c: being directly related to the conclusion or performance of a contract; depending on the specific relationship, Art. 5/2-f legitimate interest |
Entry by the user into form fields; authorized set-up by the institution/Company |
|
Training access, participation, progress, examination, certification |
Identity, professional information, training/transaction records |
KVKK Art. 5/2-c and/or Art. 5/2-f; to be confirmed according to the applicable legal relationship |
Platform use and system records |
|
Forum, community and content sharing |
Profile, comments, documents, interactions, user content |
Art. 5/2-c with respect to the provision of the service; Art. 5/2-f for moderation/security; third-party data uploaded by the user are assessed separately |
User posts and system records |
|
User support requests |
Identity, contact, requests/complaints, transaction records |
KVKK Art. 5/2-c, Art. 5/2-e and/or Art. 5/2-f |
E-mail, form, support channel |
|
Platform security, logging, detection of breaches and misuse |
Transaction security, IP/log, user transaction |
KVKK Art. 5/2-ç where a legal obligation exists; Art. 5/2-e establishment/protection of rights; Art. 5/2-f legitimate interest |
Automated system records |
|
Fulfilment of legal obligations and requests from competent authorities |
The relevant data categories |
KVKK Art. 5/2-ç and/or Art. 5/2-e |
Records kept pursuant to legislation, official requests |
|
Image/audio or webinar recording |
Visual and audio records |
The processing condition under Art. 5 must be determined separately according to the necessity and scope of the activity; explicit consent for non-mandatory use |
Live training/webinar system |
|
Exceptional content containing special categories of personal data |
Health data or other special categories of data |
The appropriate processing condition under KVKK Art. 6 must be determined separately in the specific case; as a rule, the platform does not request such data to be uploaded |
Inadvertent/exceptional sharing by the user |
Transfer of Personal Data
To the extent necessary for the operation of the platform, personal data may be transferred to information technology/hosting/cloud, video and webinar, e-mail and notification, technical support, security, backup and document management service providers; and, in the event of a legal obligation or a dispute, to competent public institutions and organizations, courts, enforcement authorities and authorized advisers.
Transfers are carried out limited to the relevant legal ground and purpose.
Transfer Abroad
Where the technology providers used are located abroad, where data are hosted on servers abroad or where data are accessed from abroad, personal data may be transferred abroad. Any such transfer is made solely on the basis of the appropriate condition among those set out in Article 9 of Law No. 6698 and by providing the necessary safeguards.
Where necessary, your personal data may be transferred to affiliated headquarters, branches, institutions or authorized users located in Finland and the United Kingdom for the purposes of carrying out the international training and professional development activities of FESİN GSN Club, enabling use of the platform, managing training processes and allowing authorized users to benefit from the platform’s functions.
Method of Collecting Personal Data
Personal data may be collected by wholly or partly automated means through membership and profile forms, content uploaded or entered onto the platform by users, institution/authorized-user set-ups, training and webinar participation, examination/assessment transactions, support channels, the website/mobile application, cookies and similar technologies, and automated system/log records; and, where necessary, by non-automated means through physical or electronic documents.
Rights of the Data Subject
Within the scope of Article 11 of the Law, data subjects have the right to: learn whether their personal data are processed; request information if such data have been processed; learn the purpose of processing and whether the data are used in accordance with that purpose; know the third parties to whom the data are transferred domestically or abroad; request rectification if the data are processed incompletely or inaccurately; request erasure or destruction of the data under the conditions stipulated in the Law; request that rectification/erasure/destruction operations be notified to the third parties to whom the data have been transferred; object to a result adverse to the data subject arising from analysis carried out exclusively by automated systems; and claim compensation for damage suffered as a result of unlawful processing.
Application Method
Requests within the scope of Article 11 of the Law may be submitted to the Company using the appropriate method among those stipulated in the Communiqué on the Procedures and Principles of Application to the Data Controller (Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ). Applications are concluded as soon as possible and, in any case, within thirty days at the latest, depending on their nature.
Data Controller: FESİN EĞİTİM HİZMETLERİ LTD. ŞTİ.
Address: ACIBADEM MAH. ACIBADEM CAD. NO: 56/2 KADIKÖY/İSTANBUL, TÜRKİYE
E-mail: info@fesin.fi
FESİN GSN CLUB PRIVACY POLICY
Purpose and Scope
This Privacy Policy (the “Policy”) has been prepared for the purpose of setting out the general principles governing the protection of the privacy of users and of other individuals whose personal data are processed within the FESİN GSN Club professional development platform operated by FESİN EĞİTİM HİZMETLERİ LTD. ŞTİ. (FESİN Education Services Ltd. Co., the “Company”).
FESİN GSN Club is a platform that provides forums, community areas, document and resource sharing, interactive and online training, webinars and professional development content to teachers and other education professionals who work at institutions affiliated with the network and/or who have received training through the Company or through authorized institutions.
The Policy covers the website, the mobile application, user accounts, forums and communities, training modules, document sharing areas, messaging and connected systems.
Relationship with Other Legal Documents
This Policy governs the general privacy and data security approach of FESİN GSN Club. Detailed information regarding the purposes of processing personal data, the legal grounds, the methods of collection, the recipient groups to which data are transferred and the rights of data subjects under Law No. 6698 (Kanun – the Law) is set out in the FESİN GSN Club Privacy Notice on the Processing of Personal Data (Aydınlatma Metni).
Separate explicit consent forms may be used for processing activities that must be based on explicit consent.
Transfers of data abroad are separately assessed within the framework of the conditions and safeguards set out in Article 9 of the Law. This Policy does not replace the aforementioned legal documents and mechanisms.
Fundamental Principles
The Company adopts as its basis the principles of lawfulness and fairness; accuracy and, where necessary, being up to date; processing for specified, explicit and legitimate purposes; being relevant, limited and proportionate to the purposes of processing; retention for the period required; data minimization; user privacy; content and access security; data integrity; and the prevention of unauthorized access.
The Company takes the necessary technical and administrative measures appropriate to the nature of the data processed and to the relevant risks in order to prevent the unlawful processing of and unlawful access to personal data and to ensure the safekeeping of such data.
Information That May Be Processed Within the Scope of the Platform
Depending on the actual use of the platform, the following may be processed: identity and contact information; user account and profile information; institution/position/subject area and professional information; training attendance and progress records; examination and assessment information; certificate and participation information; forum topics/comments/replies; community interactions; document and content sharing records; upload/download information; image and audio data; webinar and live training recordings; platform usage and log information; and other necessary information provided by the user within the scope of the platform’s intended use. Image and audio recordings are processed only to the extent required by the nature of the relevant activity and by informing the data subjects in advance.
Purposes for Which the Information Is Used
Provided that they are necessary and proportionate with respect to the relevant processing activity, personal data may be processed for the purposes of managing membership; creating a professional profile; providing access to training content and monitoring participation and progress; certification/completion processes; forum and community activities; the sharing of professional knowledge and experience; document and resource sharing; interactive training; user support; platform security and content integrity; the detection of uses contrary to the law or to the platform rules; improving platform performance and the user experience; and statistical reporting and institutional planning relating to training participation/platform use.
In reporting and analyses that do not require personal data, anonymized or aggregated data are preferred to the extent possible.
Privacy of Forum, Community and User Content
Users may be enabled to share forum posts, comments, replies, documents, images, videos or other content. Depending on the visibility settings of the relevant area, content may be visible to all platform users, to certain user groups, to the members of certain institutions/communities, or only to authorized users.
Users must take into account the visibility scope of the area in which they post and must not share personal or confidential information that they do not wish to disclose.
Before sharing personal data belonging to third parties, users must ensure that the relevant processing is lawful.
The responsibilities of users do not eliminate the Company’s obligations arising from Law No. 6698 and the relevant legislation.
User Account, Profile and Access Rights
User accounts, profiles and platform access rights are personal to the individual user.
The visibility of profile information is limited to the scope necessary for the functions of the platform and for the user’s role. It is a fundamental principle that users’ personal information is not made available to other users unnecessarily.
Access to training content, private communities, documents and other areas may be differentiated according to institution, user group, training status or user role.
Sharing account and password information is prohibited.
Log, Training and Interaction Records
Log-ins/log-outs, training participation, progress and completion, content views, document uploads/downloads, forum posts/comments, assessment and examination transactions, user access events and security incidents may be recorded on the platform.
Such records are kept only to the extent necessary for ensuring security, carrying out the services, resolving technical issues, documenting training activities, reporting/auditing and fulfilling legal obligations.
Third-Party Services and Integrations
Within the scope of the platform, use may be made of online training and webinar, video hosting, cloud/hosting, document management, e-mail/notification, technical support, security and backup services.
The Company may transfer personal data to the third parties from which it procures services, or enable such parties to access data, only to the extent required by the service. Access is kept limited to the purpose; the necessary confidentiality, data security and contractual obligations are established. Current recipient groups and transfer purposes are explained in the Privacy Notice (Aydınlatma Metni).
Transfer of Data Abroad
Where the cloud, hosting, video, webinar, communication or other technology services used within the scope of the platform are provided from abroad, or where personal data are accessed from abroad, a transfer of personal data abroad may occur.
Such transfers are carried out on the basis of the appropriate condition among those stipulated in Article 9 of Law No. 6698 and by providing the necessary safeguards.
The FESİN GSN Club platform may also be used by teachers, education professionals and authorized personnel working at the headquarters, branches or units of the Company and/or of the institutions within the same organizational structure located in Finland and the United Kingdom. In this context, where personal data on the platform are accessed from outside Türkiye or personal data are shared with such users, a transfer of personal data abroad may take place. Such transfers are carried out in accordance with the conditions stipulated in Article 9 of Law No. 6698 and with appropriate safeguard mechanisms, taking into account the purpose and scope of the transfer, the data categories, the groups of data subjects and the legal status of the recipient party.
Information notices concerning transfers abroad do not replace the transfer conditions and safeguards set out in Article 9 of the Law.
Student Data and Special Categories of Personal Data
FESİN GSN Club is a professional development platform created for teachers and education professionals; its principal purpose is not to collect personal data relating to students.
When sharing forum posts, training materials, documents or sample practices, users must not share, in the absence of the necessary legal ground, students’ names and surnames, photographs/videos, contact information, health information, special education/special needs information that may qualify as special categories of personal data, or other data that render a student directly or indirectly identifiable.
Where it is necessary to share a professional example or case, it is a fundamental principle to use content that has been anonymized so as not to allow the direct or indirect identification of the student or of a third party.
A platform user’s own explicit consent does not constitute permission to process personal data on behalf of students or other third parties.
Data Security
The Company implements technical and administrative measures appropriate to the nature and scope of the personal data processed and to the relevant risks, including but not limited to access and authorization controls, passwords and authentication, role-based access, logging, backup, content/file access controls, system and network security, security updates, user awareness and confidentiality obligations imposed on service providers.
Retention, Erasure and Anonymization
Personal data are retained for periods determined by taking into account the period required by the relevant processing purpose, the legal retention obligations to which the Company is subject, dispute and statute-of-limitation periods, and the nature of the data category.
Where the reasons for processing cease to exist and no other valid ground for retention is present, personal data are erased, destroyed or anonymized.
In the event that a user account is closed, data relating to active use are destroyed once the necessary processes have been completed; records that must be kept due to a legal obligation, the establishment/exercise/protection of a right or other valid legal grounds may be retained until the end of the relevant period.
The User’s Privacy and Content Responsibility
The user is responsible for the security of their account; for the nature of the content they share in forums/communities; for ensuring that the necessary legal grounds exist before sharing data belonging to third parties; for protecting the privacy of students and other third parties; for not sharing unauthorized or unnecessary personal data; for not sharing content to which they have been granted individual access with unauthorized persons; and for reporting security/privacy breaches to the relevant unit.
These obligations do not eliminate or limit the obligations of the Company in its capacity as data controller.
Data Subject Rights and Contact
Data subjects may submit their requests concerning the rights set out in Article 11 of Law No. 6698 to the data controller by the methods specified in the FESİN GSN Club Privacy Notice (Aydınlatma Metni) and the Data Subject Application Form (İlgili Kişi Başvuru Formu).
Data Controller: FESİN EĞİTİM HİZMETLERİ LTD. ŞTİ.
Address: ACIBADEM MAH. ACIBADEM CAD. NO: 56/2 KADIKÖY/İSTANBUL, TÜRKİYE
E-mail: info@fesin.fi info@fesin.fi
Cookies and Similar Technologies
Cookies, SDKs, local storage technologies or similar technologies may be used on the website and the mobile application in order to provide the services securely and effectively.
The use of non-mandatory technologies is made subject to the user’s preference or explicit consent, depending on the nature of such technologies and the applicable legal conditions.
Detailed information is provided in the Cookie and Similar Technologies Policy.
Data Breach
In the event that personal data are unlawfully obtained by third parties or a breach affecting data security occurs, the Company carries out the necessary assessment, response and notification processes within the scope of Law No. 6698 and the relevant regulations of the Personal Data Protection Board (Kurul).
Updates and Entry into Force
The Company may update the Policy in the event of changes to the platform’s features, the training services, the technologies used or the applicable legislation.
The current text is published in an accessible manner on the platform. In the case of material changes, users are informed by appropriate means.
Effective Date: 10.09.2026
Last Updated: 10.09.2026