FastDocument

Privacy Policy

Last updated: 2026-07-18

This policy explains in which roles, for which purposes, on which legal bases and with which safeguards FastDocument processes your personal data. It is prepared primarily under the Turkish Data Protection Law (KVKK, Law No. 6698) with the GDPR also taken into account.

1. Overview and Scope

FastDocument (fastdocument.net) is a multi-tenant SaaS platform offering two services to businesses: secure document collection through a brand-specific subdomain, and remote identity verification (KYC). In the document collection service, uploaded files pass through automated security processing (sanitisation/CDR) before being delivered to the business. In the KYC service, the front and back of an identity document are scanned live, a selfie photo and a short liveness video are captured, and OCR/MRZ reading, checksum validation, face matching and anti-spoofing analysis are performed.

This Privacy Policy covers visitors of the main fastdocument.net site, customer (Brand) accounts and users of the administration panel (backoffice). It also explains the data processor role we assume in End User flows and directs End Users to the correct point of contact.

2. Our Roles: Data Controller and Data Processor

On our platform, "Brand" means the business that is a customer of FastDocument, and "End User" means the person who uploads documents or verifies their identity at a Brand’s request. This distinction determines our data protection roles:

  • In End User flows (document upload and KYC), the relevant Brand is the data controller; FastDocument processes this data as a data processor, on behalf of the Brand and in line with the Brand’s instructions.
  • For visitors of the main fastdocument.net site, Brand account and billing data, and data of backoffice users, FastDocument is the data controller.

If you are an End User, the primary duty to inform you about the processing of your data rests with the Brand on whose behalf the verification or document collection is carried out; we recommend consulting the relevant Brand’s privacy notice first. A summary of the processing performed on FastDocument’s side is also available in the KVKK / GDPR Privacy Notice.

3. Categories of Personal Data We Process

Data we process as data controller:

  • Brand account data: the authorised user’s name, email address, session information and account security records.
  • Billing and payment data: invoicing details and payment transaction records; payment card details are not stored by FastDocument, payments are collected via Stripe.
  • Main site visit data: limited technical data contained in server logs, such as IP address and browser and device information.

End User data we process as data processor, on behalf of the Brand:

  • Document collection: files uploaded through the Brand’s form and any personal data those files contain.
  • KYC: images of the front and back of the identity document.
  • KYC: fields read from the document — full name, Turkish ID number or document number, date of birth, expiry date, nationality and gender.
  • KYC: selfie photo and short liveness video.
  • Email address and/or phone number used for OTP verification.
  • Technical device and browser signals used in security and fraud analysis.

4. Data That May Qualify as Biometric, and Explicit Consent

The facial imagery in the selfie and liveness video captured during the KYC flow may qualify as special category personal data (biometric data) under Article 6 of the KVKK. This data is processed solely on the basis of your explicit consent; explicit consent is requested in a separate step within the verification flow, before any imagery is captured.

If you do not give explicit consent, remote identity verification cannot be completed; in that case you may contact the relevant Brand.

Raw images and videos are automatically deleted after 7 days by default; details are set out in the Retention Periods and Deletion section.

5. Purposes of Processing and Legal Bases

We process personal data for the following purposes:

  • Providing the services: document collection, security processing of files (sanitisation/CDR) and delivery to the Brand; producing the decision-support result in identity verification.
  • Creating, managing and billing Brand accounts.
  • Platform security: bot protection, abuse prevention and keeping access logs.
  • Complying with legal obligations and responding to lawful requests from competent authorities.
  • Necessary operational communication related to the service (e.g. verification messages, service notices).

Where we act as data controller, we rely on the following legal bases: formation and performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)), compliance with a legal obligation (KVKK Art. 5/2-ç; GDPR Art. 6(1)(c)) and legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)). Data that may qualify as biometric is processed solely on the basis of explicit consent (KVKK Art. 6; GDPR Art. 9(2)(a)).

For End User data, the purposes and legal bases of processing are determined by the Brand in its capacity as data controller; FastDocument processes this data only to the extent required by the service and on the Brand’s instructions.

6. Sub-Processors and Data Sharing

To deliver the service we work with a limited number of service providers (sub-processors):

  • Application hosting: Vercel.
  • Database: Supabase.
  • Object storage: Contabo (EU/Germany data centre).
  • Bot protection: Cloudflare Turnstile.
  • Brand payments: Stripe. No payment is ever collected from End Users; Stripe processes Brand payments only.
  • Operational notifications: Slack (internal notifications with limited content).
  • Verification messages: email and WhatsApp message providers for OTP delivery.

We do not sell or rent your personal data, and we do not share it for advertising purposes. Beyond the above, data is shared only where a legal obligation so requires or upon lawful requests from competent public authorities.

7. International Data Transfers

Data is hosted predominantly in data centres in the EU region; object storage is located in Germany (Contabo). However, due to the nature of the service, some of the providers listed above may process data outside Türkiye and/or the EU; personal data may therefore be transferred abroad.

Transfers from Türkiye abroad are carried out in accordance with the procedures set out in Article 9 of the KVKK; for data originating in the EU, transfers rely on the safeguards under Chapter V of the GDPR (such as adequacy decisions or standard contractual clauses).

8. Retention Periods and Deletion

  • Raw KYC images and videos (identity document images, selfie, liveness video): automatically deleted after 7 days by default.
  • The verification result and the fields read from the document: retained for audit purposes.
  • Document collection files: removed within a defined period after delivery to the Brand.
  • Account and billing records: kept for the statutory retention periods under applicable law.
  • Access and security logs: kept for a limited period as needed for security and audit.

The periods above may vary depending on the configuration chosen by the Brand as data controller. Once the applicable period expires, data is deleted, destroyed or anonymised.

9. Security Measures

The principal technical and organisational measures we take to protect personal data:

  • Mandatory HTTPS on all connections (encryption in transit).
  • Signed, single-use upload links.
  • Automated security processing (sanitisation/CDR) of uploaded files.
  • Keeping of access logs and application of the least-privilege principle.

No system can guarantee absolute security; however, we regularly review our measures to maintain protection proportionate to the risk.

10. Automated Processing, Decision Support and Human Review

In the KYC service, OCR/MRZ reading, checksum validation, face matching and anti-spoofing analysis are carried out by automated means. The output of this processing is decision support in nature: the final decision to accept or reject belongs to the relevant Brand, and human review is part of the process.

If you believe a result unfavourable to you has arisen from the analysis of your data by automated systems, you have the right to object to that result and to request human intervention under Article 11(g) of the KVKK and Article 22 of the GDPR. If you are an End User, you may direct this request primarily to the relevant Brand; if it reaches us, we will forward it to the Brand and support the review process.

11. Cookies and Similar Technologies

FastDocument does not use advertising or tracking cookies, nor analytics cookies. Only technical cookies strictly necessary for the service are used: the backoffice session cookie (administrators only), Cloudflare Turnstile’s short-lived technical cookie/storage for bot protection, and the technical cookies of the hosting infrastructure (Vercel). localStorage is used only for technical necessities. For details, see the Cookie Policy.

12. Your Rights as a Data Subject

Under Article 11 of the KVKK, you have the following rights:

  • To learn whether your personal data is processed and, if so, to request information about it.
  • To learn the purpose of processing and whether the data is used in line with that purpose.
  • To know the third parties to whom the data is transferred, in Türkiye or abroad.
  • To request the correction of incomplete or inaccurate data and, where the conditions are met, its deletion or destruction, and to request that these operations be notified to the third parties to whom the data was transferred.
  • To object to a result that arises against you due to analysis performed exclusively by automated systems.
  • To claim compensation if you suffer damage due to unlawful processing.

Users covered by the GDPR additionally have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and the right to lodge a complaint with the supervisory authority in their country. In Türkiye, data subjects may lodge a complaint with the Turkish Personal Data Protection Board.

You may submit requests concerning matters where FastDocument is the data controller using the contact details at the bottom of this page. For requests relating to End User flows, the primary addressee is the relevant Brand; we forward such requests to the Brand without delay and support the Brand in responding.

13. Changes to This Policy

We may update this policy to reflect changes in our services or in applicable law. The current version is always published on this page, and the "last updated" date at the top reflects any change. We endeavour to communicate material changes through reasonable means (e.g. a notice on the site or an email to account holders).

Contact & Data Controller Details

You can direct any requests regarding this document to the channels below.

FastDocument — [ŞİRKET UNVANI GÜNCELLENECEK]
[ADRES GÜNCELLENECEK], Türkiye
E-posta: info@fastdocument.net
Privacy/data protection requests: kvkk@fastdocument.net
Privacy Policy — FastDocument