FastDocument

KVKK / GDPR Privacy Notice

Last updated: 2026-07-18

This notice explains, in accordance with Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR), how personal data is processed on the FastDocument platform, for which purposes and on which legal bases, to whom it may be transferred, and the rights you hold in this respect.

1. Identity of the Data Controller and the Dual-Role Explanation

FastDocument is a multi-tenant SaaS platform providing two services to businesses (referred to in this notice as the "Brand"): secure document collection through a brand-specific subdomain, and remote identity verification (KYC). Because of this structure, two distinct roles apply to the processing of personal data, and understanding this distinction matters so that you can direct your rights requests to the correct party.

  • End User flows (document upload, identity verification): In these flows your personal data is processed on behalf of, and under the instructions of, the Brand that requested the service from you. The Brand is the data controller and FastDocument acts as the data processor.
  • Areas where FastDocument is the data controller: data relating to visitors of the fastdocument.net website, administration panel (backoffice) user accounts, and account, contract, and billing data of Brand customers.

This notice primarily covers the processing activities FastDocument carries out in its capacity as data controller. Information about End User flows is provided to transparently describe the nature of the processing we perform as a data processor; the primary duty to inform for those flows rests with the relevant Brand. The identity and contact details of FastDocument as data controller are available in the contact details at the bottom of this page.

2. Categories of Personal Data Processed

Depending on the service you use, the following categories of personal data are processed on the platform:

  • Identity verification (KYC) data: front and back images of the identity document; fields read from the document (full name, Turkish ID number or document number, date of birth, expiry date, nationality, gender); a selfie photograph and a short liveness video.
  • Document collection data: files you submit through the upload form at the Brand’s request, together with any information you declare in the form.
  • Contact and verification data: e-mail address and/or telephone number used for one-time password (OTP) verification.
  • Transaction security data: technical device and browser signals, IP address, access and activity logs.
  • Customer (Brand) account data: authorised user name, business e-mail address, account and billing information. No payment is collected from End Users and no End User payment data is processed.

3. Special Categories of Personal Data and Explicit Consent (KVKK Art. 6)

The facial imagery in the selfie photograph and liveness video captured during the identity verification flow may qualify as biometric data, since it is processed for face matching and anti-spoofing analysis. Biometric data is a special category of personal data under Article 6 of the KVKK, and its processing is based on your explicit consent.

Your explicit consent is obtained through a separate, informed step within the verification flow, before processing begins. If you do not give explicit consent, remote identity verification is not performed; in that case you may contact the relevant Brand regarding any alternative verification methods it offers. You may withdraw your explicit consent at any time; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

4. Purposes of Processing

Your personal data is processed for the following purposes:

  • Securely collecting the documents requested by the Brand, running uploaded files through automated security processing (sanitisation/CDR), and delivering them securely to the Brand.
  • Performing remote identity verification: live scanning of the identity document, OCR/MRZ reading and checksum validation, face matching against the selfie, liveness checking, and anti-spoofing analysis; presenting the results to the Brand as a decision-support report.
  • Verifying access to the flow and preventing abuse (OTP verification, bot protection, signed single-use links).
  • Ensuring platform security, keeping access logs, and maintaining an audit trail.
  • Establishing and performing contracts with Brand customers, account management, billing, and compliance with legal obligations.

5. Legal Bases for Processing

Your personal data is processed on the following legal bases set out in Articles 5 and 6 of the KVKK:

  • Processing being directly related to the establishment or performance of a contract (KVKK Art. 5/2-c): performance of the service agreement between the Brand and FastDocument; operation of the document collection and verification flows.
  • Processing being necessary for compliance with a legal obligation of the data controller (KVKK Art. 5/2-ç): invoicing and accounting records, responding to requests from competent authorities.
  • Legitimate interest, provided it does not harm the fundamental rights and freedoms of the data subject (KVKK Art. 5/2-f): ensuring platform security, preventing abuse and fraud, access logging and audit trail.
  • Explicit consent (KVKK Art. 6): processing of facial imagery that may qualify as biometric data for identity verification purposes is based solely on the explicit consent obtained separately within the flow.

For users within the scope of the GDPR, these bases correspond respectively to Article 6(1)(b) (contract), 6(1)(c) (legal obligation), 6(1)(f) (legitimate interests), and 9(2)(a) (explicit consent) of the GDPR.

6. Method of Collection

Your personal data is collected entirely by electronic means: through the upload forms on the brand-specific subdomain; through live document scanning and selfie/liveness capture via your device’s camera during the verification flow; through the e-mail address or telephone number you provide during OTP verification; and through technical records required for the platform to operate (device/browser signals, access logs). Fields read from the document are obtained through automated OCR/MRZ reading performed on the uploaded images.

7. Transfers of Personal Data and Categories of Recipients

Your personal data may be transferred, only to the extent required by the purposes above, to the following categories of recipients:

  • The relevant Brand: document collection outputs and identity verification results are delivered to the Brand that requested the service in its capacity as data controller.
  • Sub-processor service providers: application hosting (Vercel), database (Supabase), object storage (Contabo — EU/Germany data centre), bot protection (Cloudflare Turnstile), Brand payments (Stripe — no payment is collected from End Users), operational notifications (Slack), and e-mail/WhatsApp verification message providers.
  • Competent public authorities: where required to comply with legal obligations, upon request and to the extent provided by law.

Data is hosted predominantly in data centres within the European Union. However, due to the infrastructure of the service providers listed above, your personal data may be transferred abroad. International transfers are carried out in accordance with the conditions of Article 9 of the KVKK and, for transfers within the scope of the GDPR, the safeguards of Chapter V (such as appropriate safeguards including standard contractual clauses).

8. Retention Periods

Your personal data is retained for as long as required by the processing purpose and in line with minimum periods prescribed by applicable law:

  • Raw images and videos captured during identity verification (document images, selfie, liveness video) are automatically deleted after 7 days by default.
  • The verification result and the fields extracted from the document are retained for audit purposes.
  • Files uploaded through the document collection flow are removed from the platform within a defined period after delivery to the Brand.
  • Brand account and billing data is kept for the duration of the contractual relationship and for the statutory retention periods required by commercial and tax legislation.

Retention periods may vary according to the configuration chosen by the Brand acting as data controller; for the specific periods applied to End User data, please refer to the relevant Brand’s privacy notice. Data whose retention period has expired is deleted, destroyed, or anonymised.

9. Data Security Measures, Cookies and Local Storage

FastDocument implements appropriate technical and organisational measures to prevent unlawful processing of and access to personal data and to ensure its safekeeping. These include mandatory HTTPS encryption on all connections, signed single-use upload links, automated security processing (sanitisation/CDR) of uploaded files, access logging, and access control based on the principle of least privilege.

No cookies are used on the platform for advertising, tracking, or analytics purposes. Only technical cookies strictly necessary for the service are present: the administration panel session cookie (administrator users only), Cloudflare Turnstile’s short-lived technical cookie/storage for bot protection, and the technical cookies of the hosting infrastructure (Vercel). Browser local storage (localStorage) is used solely for technical necessities. For details, please see the Cookie Policy.

10. Automated Processing and Decision-Support Nature

In the identity verification flow, OCR/MRZ reading, checksum validation, face matching, liveness checking, and anti-spoofing analysis are performed by automated means. However, the output of this processing is a decision-support report: the final accept or reject decision rests with the relevant Brand, and human review is part of the process. Your right to object to a result arising against you exclusively through analysis by automated systems (KVKK Art. 11/1-g) is reserved; in this context you may request human intervention and review.

11. Your Rights under Article 11 of the KVKK and How to Apply

Under Article 11 of the KVKK, you have the following rights by applying to the data controller:

  • To learn whether your personal data is being processed,
  • To request information about the processing if your personal data has been processed,
  • To learn the purpose of the processing and whether your data is used in line with that purpose,
  • To know the third parties to whom your personal data is transferred, in Türkiye or abroad,
  • To request correction of your personal data if it is incomplete or inaccurate,
  • To request deletion or destruction of your personal data under the conditions set out in Article 7 of the KVKK,
  • To request that correction, deletion, and destruction operations be notified to third parties to whom the data has been transferred,
  • To object to a result arising against you through analysis of your processed data exclusively by automated systems,
  • To claim compensation for damage suffered as a result of unlawful processing of your personal data.

You may submit your requests, in accordance with the Communiqué on the Principles and Procedures for Application to the Data Controller, together with information verifying your identity, to the e-mail address provided in the contact details at the bottom of this page. Your request will be concluded free of charge within thirty days at the latest; where the operation entails an additional cost, the fee set in the tariff determined by the Turkish Personal Data Protection Board may be charged. If your request is rejected, the response is found insufficient, or no response is given in time, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board (KVKK Board).

Important: since the relevant Brand is the data controller for End User flows (document upload, identity verification), you should direct rights requests concerning those flows primarily to the relevant Brand. FastDocument, as data processor, provides reasonable assistance by forwarding such requests to the relevant Brand and supporting the Brand in fulfilling them.

12. GDPR Addendum: Additional Rights for EU Users

If you are located in the European Union and the processing falls within the scope of the GDPR, you have the following rights in addition to those under Article 11 of the KVKK:

  • Right to data portability (GDPR Art. 20): to receive data processed by automated means on the basis of consent or contract in a structured, commonly used, machine-readable format, and to have it transmitted to another controller.
  • Right to object (GDPR Art. 21): to object, on grounds relating to your particular situation, to processing based on legitimate interests.
  • Right to restriction of processing (GDPR Art. 18) and the right to withdraw consent at any time (GDPR Art. 7(3)).
  • Right to lodge a complaint with a supervisory authority (GDPR Art. 77): with the data protection supervisory authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.

Regarding automated decision-making and profiling (GDPR Art. 22): the automated analyses in the verification process are decision-support in nature; no final decision producing legal effects concerning you, or similarly significantly affecting you, is taken solely by automated processing. The final decision rests with the relevant Brand and human review is part of the process; you also have the right to obtain human intervention, to express your point of view, and to contest the decision.

13. Changes and Contact

This notice may be revised in line with legislative changes or updates to the scope of the service; the current version is always published on this page together with the update date shown at the top. For questions about this notice and for applications under the KVKK/GDPR, please use the contact details at the bottom of this page. For the general framework on the processing of personal data, please also see the Privacy Policy and the Cookie Policy.

Contact & Data Controller Details

You can direct any requests regarding this document to the channels below.

FastDocument — [ŞİRKET UNVANI GÜNCELLENECEK]
[ADRES GÜNCELLENECEK], Türkiye
E-posta: info@fastdocument.net
Privacy/data protection requests: kvkk@fastdocument.net
KVKK / GDPR Privacy Notice — FastDocument