Your firm is the controller, HukukBis the processor.
Under Law No. 6698 (KVKK) the roles are clear: for client, case and document data your firm is the data controller and HukukBis is the processor. The agreement, data location and data tools work within that frame.
- Data location
- In Turkey MTY Cloud
- AI
- Local model No transfer abroad
- Agreement
- Written Data processing agreement
- Data tools
- Ready Export and deletion request
Who is responsible for what?
Your firm decides the purpose of client and case data; HukukBis processes it only to provide the service, within your instructions. For the data of website visitors and of you as an account holder, HukukBis is the controller; details are in the privacy notice.
| Obligation | Your firm (controller) | HukukBis (processor) |
|---|---|---|
| Purpose of processing and legal basis | Determines and documents them | Processes only as far as the service requires |
| Informing the client | Prepares and delivers the client privacy notice | Provides the fields and the record infrastructure your firm uses |
| Technical and organisational measures | Manages roles, permissions and users | Operates data isolation, access control, encryption and activity records |
| Data subject requests (art. 11) | Receives and answers the request | Eases the answer with export and deletion tools |
| Retention and destruction | Sets the retention period | Applies the set rule and processes the deletion request |
| Use of sub-processors | Reviews the list | Lists sub-processors openly and passes on only the data needed |
Data processing agreement
The relationship between controller and processor is framed by a written agreement: which data is processed, for what purpose and for how long, the measures taken and what happens to the data when the relationship ends.
- Scope
- The categories of data processed, the purpose and period of processing, the instruction framework and the confidentiality duty are in the agreement.
- Measures
- Data isolation, the role and permission model, document scanning and activity records underpin the agreement; the protection layers are described on the security page.
- At the end
- When the service ends you can export your data and then ask for it to be deleted; the retention and destruction rule is written in the agreement.
You can request the agreement text and the signing process through our contact channels. If your firm's legal adviser wants a special clause, we discuss it through the same channel.

Your data stays in Turkey and AI runs locally
HukukBis data is hosted on MTY Cloud inside Turkey. MTY Cloud is our own infrastructure, operated entirely by HukukBis.
- HostingThe application, data and backups are kept on MTY Cloud, inside Turkey.
- AIWhen HukukBis AI is switched on it runs on the local model; no data is sent abroad and client data is not used to train the model.
- Notification channelsEmail, SMS, WhatsApp and push providers are involved only when you use the related feature.
Some notification providers may have systems abroad. Such a transfer is made under art. 9 of KVKK with an adequacy decision or the other safeguards provided for; our statement matches the KVKK privacy notice.
Fact sheet of the processor
- Legal name
- HukukBis
- Sub-processors
The full list of service providers that receive data, the purpose of each and the data passed on is published on the security page.
Handle data subject requests from the application
When a client asks for a copy of their data you export it; when they ask for deletion you process the request on record. Requests are answered within 30 days at the latest, and every action shows in the activity records with the user and time.
The request is recorded
- Data export
- You receive the data subject's data as a file.
- Deletion request
- The request is recorded, processed and its result marked.
- Retention period
- Documents past their period are cleared by rule.
- Activity records
- Who did what and when: traceable.
For data migration and role management see the data migration and roles and permissions pages.
If a breach happens, our process has three steps
Article 12 of the Law requires a controller to notify the data subject and the Board when personal data is unlawfully obtained by others. So that your firm can meet this duty, the process works as follows.
- 01/03
Detection and containment
The incident is examined, the affected scope is determined and its spread is stopped.
- 02/03
Notice to the firm
As controller your firm is informed without delay; the notice period is written in the data processing agreement.
- 03/03
Information and record
The affected data, the cause and the measures taken are passed to your firm with the activity records; the Board notification is prepared together with your firm.
What is asked about KVKK?
- 01/05
Who is the controller and who the processor at HukukBis?
For client, case and document data your firm is the controller and HukukBis the processor. For the data of website visitors and of you as an account holder HukukBis is the controller; details are in the privacy notice.
- 02/05
Do I need to sign a data processing agreement?
A controller asks the party that processes data on its behalf to provide safeguards and frames the relationship in an agreement. Write to our contact channels for the agreement text and the signing process.
- 03/05
Is my data transferred abroad?
Data is hosted on MTY Cloud inside Turkey. AI runs on the local model and makes no transfer abroad. The statement on provider-dependent transfers in notification channels matches the privacy notice.
- 04/05
What do I do when a client asks for their data to be deleted?
You record and process the deletion request in the application. For data under a legal retention duty your retention rule applies; every action shows in the activity records.
- 05/05
Will I be informed if there is a data breach?
Yes. As controller your firm is informed without delay; the notice period is written in the data processing agreement. Rights and the application procedure are described in the KVKK compliance guide.
