Who We Are
We are Ornitorenk Dijital Hizmetler Anonim Şirketi, a legal entity incorporated and operating under the laws of Republic of Türkiye and with the below contact information.
Title: Ornitorenk Dijital Hizmetler Anonim Şirketi
Address: Maslak Mah. Taşyoncası Sk. Maslak 1453 Sitesi No:1g/45 Sarıyer İstanbul
MERSIS: 0647037223400001
Email: gdpr@kompanionapp.com
“Controller” is any natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data. We are the Controller of your personal data.
Data Protection Officer
We appointed a Data Protection Officer “DPO” for the protection of your data.
You can reach our DPO at any time here:
gdpr@kompanionapp.com
General Information on our Data Processing
Before we process any personal data, we make sure if it is necessary and it is for providing our website and apps [Fasting Kompanion, Heart Rate Kompanion, Fitness Kompanion and Period Kompanion apps (together the “Kompanion Apps”)] in a proper and user-friendly manner, as well as for the provision of our products and services.
We process your contact information, usage data and other information that you provide to us. The purposes for which we process such data, as well as their legal bases, are set out in the below table unless otherwise described in this Privacy Policy or to you. We only process your data when it is necessary for the specified purposes.
Data |
Purpose |
Legal Basis |
- Contact Data
(e.g. name, address, e-mail)
- Other Contract Data (e.g. purchases)
|
Concluding and maintaining a contractual relationship and ensuring its performance |
Performance of a contract
[Art. 6 (1) b) GDPR] |
- Contact Data
- Contract Data
- Usage Data
|
Quality assurance and marketing |
Legitimate interests
[Art. 6 (1) f) GDPR] |
- Data that you provide on the basis of consent
(e.g. within the scope of registration)
|
For the purposes stated when giving your consent; this applies, for example, to the data you provide voluntarily |
Consent
[Art. 6 (1) a) GDPR] |
In order to maintain a high level of protection for your personal data, we are actively seeking for and taking the most effective, appropriate, and commercially reasonable security measures. These measures are designed not only to prevent unauthorized access to your personal data, but also to prevent their accidental loss, alteration, and disclosure. In accordance with these measures, we consider data minimization principle at all times, including when it is necessary to transfer or disclose your personal data to third parties. This means that, where possible, we anonymize or pseudonymize your information. Pseudonymized data means data where your information, like your name and email address, are replaced with a token ID.
There are third-party providers who process data on our behalf, such as hosting companies, mailing services, etc. The data processing agreements we conclude with those third parties ensure an adequate level of protection in accordance with Art. 28 GDPR.
When we transfer or disclose your personal data to third parties, based on your consent or another legal basis, we always observe applicable privacy regulations. We act diligently when looking out for service providers who take all appropriate technical and organizational measures, identical to or equal to those required from us, before transferring your personal data.
We may transfer your personal data to the servers outside the country of your domicile, when needed, provided that it is in accordance with European data protection standards. If we are transferring your personal data outside the European Economic Area (EEA) we ensure that it is necessary, we aim to conclude standard contractual clauses with the respective providers, and we carry out an individual risk analysis before transfer.
When You Register to Kompanion Apps
You may register on our website or through any of the Kompanion Apps in order to use our services. The account created upon your registration can be used to log in to any of the Kompanion Apps.
We process the data you share with us in the registration process based on your consent or, if applicable, to fulfill our contract with you:
Data |
Purpose |
Legal Basis |
- Registration / login data
(e.g., name, date of birth, email address, password)
|
Fulfillment of our contract |
Performance of a contract
[Art. 6 (1) b) GDPR] |
Enabling you to register |
Consent
[Art. 6 (1) a) GDPR] |
When You Use Kompanion Apps
When you use any of the Kompanion Apps, we collect the personal data described below in order to provide you user-friendly functions.
Data |
Purpose |
Legal Basis |
- IP address
- Device type
- Unique device identifiers
- Date and time of the request
- Time zone
- Contents of the request
- Access status/HTTP status code
- Amount of data transferred in each case
- Website from which the request originates
- Browser
- Browser language
- Operating system and its interface
- Language and version of the browser software
- Unique number of the terminal (IMEI)
- Unique number of the network subscriber (IMSI)
- Mobile phone number (MSISDN)
- MAC address
- Name of your mobile terminal
- Email address
|
Providing our services |
Performance of a contract
Art. 6 (1) b) GDPR |
Maintaining the functionality and stability of Kompanion Apps. |
Legitimate interests
Art. 6 (1) f) GDPR |
In addition to the above, cookies are stored on your device when you use Kompanion Apps. Cookies are small text files that are stored in the device memory of your mobile device and assigned to the Kompanion App you are using, and they allow certain information to flow to the location that sets the cookie. If you do not wish to allow cookies, you may always change the settings on your device. Please know that Kompanion Apps may not function properly and in a user-friendly way if you disable cookies.
When You Use Our Services
As part of our services, we provide customized content, individual insights, reminders, suggestions, as well as nutrition plans, workout plans and/or other plans. These are created or personalized for you based on your personal information by utilizing algorithms which may be regarded as automated individual decision-making methods.
For providing you with customized nutrition and workout plans, we ask you for some of your personal data such as where you live, your gender, fitness goal, weight, height, age, fitness and activity levels and related information (duration, intensity, type, location), burned calories, target weight, exercising days, sleep duration and quality, motivation level, fatigue level, and your diet. You may share this information with us by answering our questionaries or by filling in the relevant sections on the relevant Kompanion App. We may also receive some this information from Apple Health Kit and/or Google Fit (please see below). Unless otherwise specified in this Privacy Policy, we process this information only to provide you with our products and services. Our legal basis for processing this information is Art. 6 (1) b) GDPR (performance of a contract).
Some of the information we process for the provision of our products and services, like your cycle information (the date, length and flow level of your period, your discharge and pain levels, and your mood) may be regarded as sensitive personal data, such as data concerning your health. We only process this information with your explicit consent (Art. 9 (2) a) GDPR), and only for the purpose of providing you with our products and services, inter alia, through any of the Kompanion Apps. Notwithstanding anything to the contrary hereunder, this information is never used for marketing, advertising, or use-based data mining purposes or for any other reason than your wellbeing.
We may invite you to complete a form or a survey, share your testimony, or participate in a promotion (like a contest or challenge) either through our services or a third-party platform, such as Typeform. If you participate, we will collect and store the information you provide as part of participating, such as your name, email address, date of birth, phone number and photograph. If you compete in a competition or challenge as part of our services (against other users or yourself), this allows us to disclose your username, trophies, achievements, rankings, and other related information. Our legal basis for processing this information is Art. 6 (1) b) GDPR (performance of a contract). Provided that you have given your consent, we may collect, store, and publish your photograph, for the purpose of sharing your testimony with others on our websites, Kompanion Apps, email bulletin, or other media. Our legal basis for processing this information is Art. 6 (1) a) GDPR (consent).
We work with a third-party payment processor for the purposes of payments. We may utilize Kompanion LTD, a private limited company incorporated in the UK, to process and/or receive payments. We work with third-party payment processors for payments either directly or indirectly through Kompanion LTD. Regarding payment processing, neither we nor Kompanion LTD retains any financial information, such as credit card numbers. All such information is provided directly by you to our third-party processor, which stores your payment information on our behalf. We may access and store your payment information only to the extent necessary to confirm or refund your payments, related actions, or for legal reasons (e.g., the last four digits of your credit card). Our legal basis for processing this information is Art. 6 (1) b) GDPR (performance of a contract).If you contact us for support, help, to report a problem, or share a concern, we collect and store your personal data, including your contact information, messages, name, location, device and software information, IP address, and any other data you provide or that we collect automatically. We need this data to respond to you and better understand your question or concern. Our legal basis for processing this information is Art. 6 (1) b) GDPR (performance of a contract). In relation to process payments, we do not retain any financial information such as credit card numbers; but all such information is provided directly to our third-party processor by you; and the third-party service provider stores your payment information on our behalf. However, we may access and store your payment information only to the extent it is necessary to confirm or refund your payments, related actions, or for legal reasons, such as the last four digits of your credit card. Our legal basis for processing this information is Art. 6 (1) b) GDPR (performance of a contract).
If you contact us for support or help, or to report a problem or share a concern, we collect and store your personal data, such as your contact information, messages, name, location, device and software information, IP address, and any other data you provide or that we collect automatically. We need this data to respond to you and to have a better understanding of your question or concern. Our legal basis for processing this information is Art. 6 (1) b) GDPR (performance of a contract).
Apple Health
We use Apple’s HealthKit framework, which provides a central repository for health and fitness data on iPhone and Apple Watch and – with your consent – lets apps communicate with the HealthKit to access and share this data. If you download our Apple Watch app when it will be available, and use Apple Watch, we may collect and process your heart rate data, obtained through the HealthKit framework and the Apple CoreMotion framework. New data attributes may be added to the HealthKit framework, which will be portrayed in the relevant Kompanion App.
If you grant the relevant Kompanion App access to HealthKit, it can add information to certain sections of HealthKit, i.e. adding your steps and burned calories into the relevant section in HealthKit. We do not connect and share your information with HealthKit and your HealthKit information is not shared with us, unless you give your consent, which you can always withdraw by changing the settings of your mobile device.
The information you provide to HealthKit will be governed by the Apple Terms and Conditions and Privacy Policy. We may analyze the data shared by HealthKit for research purposes designed to provide a personalized experience and motivate engagement in healthy habits, and for providing our products and services.
We do not use information gained through the HealthKit framework for marketing, advertising or use-based data mining and we do not transfer that information to third parties for those purposes.
Google Fit
We use Google Fit SDK which is an open platform that lets users control their fitness data. Like HealthKit, if you have given your consent, Google Fit may share certain information with us, and we may add your information to certain sections of Google Fit. We may analyze the data shared by Google Fit for research purposes designed to provide a personalized experience and motivate engagement in healthy habits, and for providing our products and services.
We do not use information gained through the HealthKit framework for marketing, advertising or use-based data mining and we do not transfer that information to third parties for those purposes.
Informational Emails
Following your registration on the website or through one of the Kompanion Apps, we may send you informational emails about our similar products or services, such as other Kompanion Apps, and our offers. If you do not wish to receive such emails you can always click on the unsubscribe button at the end of any such email or let us know by email.
Data |
Purpose |
Legal Basis |
- Contact data
- Technical data
(e.g., device name, country code if applicable, language, name of operating system and version)
- Usage data
- Connection data (e.g., IP address, mail provider)
|
- To carry out a contractual relationship
- Our legitimate marketing interests
|
Art. 6 (1) b) or f) GDPR, Art. 6 (1) a) GDPR |
Social Media
We are on several social media platforms. We process personal data to communicate with users active on those platforms and to offer them information about our products and services. Personal data within this framework is usually processed within social networks for market research and advertising purposes. You may refer to the privacy policies of the respective social networks to learn more about the forms of processing and options to object such processing.
Data |
Purpose |
Legal Basis |
- Inventory data (e.g. names, addresses)
- Contact data (e.g. email, telephone numbers)
- Content data (e.g. text entries, photographs, videos)
- Usage data (e.g. websites visited, interest in content, access times)
- Meta/communication data (e.g. device information, IP addresses)
|
- Contact requests and communication
- Tracking (e.g. interest/behavioral profiling, use of cookies)
- Remarketing,
- Reach measurement (e.g. access statistics, recognition of returning visitors)
- Affiliate tracking
|
Legitimate interest
Art. 6 (1) f). GDPR |
Services used and service providers:
Platform |
Company Name |
Address |
Domain |
Privacy Policy |
Settings |
Data Information |
Pinterest |
Pinterest Inc |
505 Brannan Street San Francisco, CA 94107 United States |
https://www.pinterest.com/ |
https://policy.pinterest.com/en/privacy-policy |
https://www.pinterest.com/settings |
https://www.pinterest.com/settings/privacy |
Twitter |
Twitter Inc |
1355 Market Street, Suite 900, San Francisco, CA 94103, USA |
https://twitter.com/ |
https://twitter.com/en/privacy |
https://twitter.com/settings/account/personalization |
https://twitter.com/settings/your_twitter_data |
Google |
Google LLC |
1600 Amphitheatre Parkway, Mountain View, California , U.S. |
https://www.google.com/ |
https://policies.google.com/privacy |
https://support.google.com/chrome/answer/114836?hl=en&co=GENIE.Platform%3DAndroid&oco=1 |
|
Youtube |
Google LLC |
1600 Amphitheatre Parkway, Mountain View, California , U.S. |
www.youtube.com |
https://policies.google.com/privacy |
https://support.google.com/chrome/answer/114836?hl=en&co=GENIE.Platform%3DAndroid&oco=1 |
|
Snapchat |
Snap Inc |
3000 31st Street Santa Monica, CA 90405, U.S.A. |
https://www.snapchat.com/ |
https://values.snap.com/privacy/privacy-policy |
https://help.snapchat.com/hc/en-us/sections/5690164367636-Privacy-Settings |
|
Reddit |
Reddit Inc |
420 Tyalor Street San Francisco, CA 94102 USA |
https://www.reddit.com/ |
https://www.reddit.com/policies/privacy-policy |
https://www.reddit.com/settings/privacy |
|
TikTok |
TikTok Inc |
5800 Bristol Pkwy Culver City, CA 90230 |
https://www.tiktok.com/ |
https://www.tiktok.com/legal/page/row/privacy-policy/en |
https://support.tiktok.com/en/account-and-privacy/account-privacy-settings |
|
Line |
Line Corporation |
Yotsuya Tower 23rd FL., 1-6-1 Yotsuya, Shinjuku-ku, Tokyo, 160-0004, Japan |
https://line.me/ |
https://line.me/en/terms/policy/ |
|
https://help.line.me/line/?contentId=20002865 |
Sign-on and other third-party services
We also integrate with some of social networks and other online accounts to provide you with additional ways of creating or signing into a Kompanion account. We may obtain certain information through your social media profiles or other online accounts you have permitted to be connected to our websites or Kompanion Apps. If you login via Facebook or another third-party platform or service, we ask for your permission to access certain information which is already given under that account, such as your name, profile picture, account ID number, email address, location, physical location of your access devices, and birthday. Those platforms and services make information available to us through their APIs, and therefore, the information given to us is limited with the scope of your privacy settings in the platform or service. If you access or use our products or services through a third-party platform or service, the collection, usage, and sharing of your data will also be subject to the privacy policies and other agreements of that third party. We may also obtain information through third parties, which we have a business or legal relationship with, such as business partners, technical, payment and delivery service subcontractors, advertising networks, analytics providers, or search information providers.
Cookies
We use cookies to access information when you sign in, store your preferences, to keep you logged in, and to store a limited amount of behavioral data. A cookie is a small file that is stored on the end device used and saved by the browser. There are different types of cookies that are used for different purposes.
The cookies listed below for tracking, targeting, analysis and marketing purposes are only used on our website with your express consent. When you visit our website, you will see a cookie pop-up. Through this pop-up, you will have the choice of agreeing which types of cookies you give consent for. If you want to manage your consent or receive further information on the cookies used on our website, click
here .
Name, Provider |
Purpose |
Legal Basis |
Further information /
OPT-OUT |
pll_language, Polylang Language |
To remember the last language visited. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
.AspNetCore.Antiforgery.# |
To prevent forgery attacks. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
firebase_remote_config#app_namespace_store, Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
To dynamically configure website UI components from a remote source to be A/B tested (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
firebase_remote_config#firebase-installations-store, Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
To dynamically configure website UI components from a remote source to be A/B tested (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
firebase-installations-database#firebase-installations-store, Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
To dynamically configure website UI components from a remote source to be A/B tested (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
test_cookie |
To check if the user’s browser supports cookies (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
_ga, Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
Tracking and analysis (Statistics Cookie) |
Art. 6 (1) a) GDPR |
OPT-OUT: http://tools.google.com/dlpage/gaoptout?hl=en
Google privacy policy: https://www.google.com/policies/privacy/ |
_ga#, Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
Tracking and analysis (Statistics Cookie) |
Art. 6 (1) a) GDPR |
OPT-OUT: http://tools.google.com/dlpage/gaoptout?hl=en
Google privacy policy: https://www.google.com/policies/privacy/ |
_gat, Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
Tracking and analysis (Statistics Cookie) |
Art. 6 (1) a) GDPR |
OPT-OUT: http://tools.google.com/dlpage/gaoptout?hl=en
Google privacy policy: https://www.google.com/policies/privacy/ |
_gid, Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
Tracking and analysis (Statistics Cookie) |
Art. 6 (1) a) GDPR |
OPT-OUT: http://tools.google.com/dlpage/gaoptout?hl=en
Google privacy policy: https://www.google.com/policies/privacy/ |
_fbp, Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour Dublin 2 , Ireland) |
Advertising Cookie |
Art. 6 (1) a) GDPR |
Facebook privacy policy: https://www.facebook.com/privacy/policies/cookies |
_fbc, Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour Dublin 2 , Ireland) |
Advertising Cookie |
Art. 6 (1) a) GDPR |
Facebook privacy policy: https://www.facebook.com/privacy/policies/cookies |
fbssls_#, Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour Dublin 2 , Ireland) |
Targeting (Advertising Cookie) |
Art. 6 (1) a) GDPR |
Facebook privacy policy: https://www.facebook.com/privacy/policies/cookies |
_gcl_au, Google Adsense (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
Advertising Cookie |
Art. 6 (1) a) GDPR |
OPT-OUT: http://tools.google.com/dlpage/gaoptout?hl=en
Google privacy policy: https://www.google.com/policies/privacy/ |
IDE, Google Doubleclick (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
Targeting (Advertising Cookie) |
Art. 6 (1) a) GDPR |
Facebook privacy policy: https://www.facebook.com/privacy/policies/cookies |
pagead/1p-user-list/#, Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, Mountain View, CA, USA) |
Tracking (Advertising Cookie) |
Art. 6 (1) a) GDPR |
OPT-OUT: http://tools.google.com/dlpage/gaoptout?hl=en
Google privacy policy: https://www.google.com/policies/privacy/ |
_ttp, TikTok Pte. Ltd. (1 Raffles Quay, #26-10, South Tower, Singapore 048583) |
Advertising Cookie |
Art. 6 (1) a) GDPR |
Tiktok cookie policy: https://www.tiktok.com/legal/page/global/cookie-policy/en |
cmplz_banner-status, Complianz |
To store if the cookie banner has been dismissed. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
cmplz_preferences, Complianz |
To store cookie consent preferences. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
cmplz_statistics, Complianz |
To store cookie consent preferences. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
cmplz_marketing, Complianz |
To store cookie consent preferences. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
cmplz_functional, Complianz |
To store cookie consent preferences. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
cmplz_policy_id, Complianz |
To store accepted cookie policy ID. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
cmplz_consented_services, Complianz |
To store cookie consent preferences. (Functional Cookie) |
Art. 6 (1) f) GDPR |
– |
Age Limit for Processing
None of our products or services is directed to or structured to attract children under the age of 13 years. In accordance with that, we do not intend to collect personal data from anyone we know to be under 13 years of age.
Notwithstanding the above, you must be at least 16 years old to use our Period Kompanion App in European Economic Area and UK.
If we find out that personal data of anyone under 13 years old (16 in EEA and UK for Period Kompanion App) has been collected without verifiable parental consent, we will take the appropriate steps to delete it. If you are the parent of such person, or if you have any questions or suggestions about implementation of this policy, please contact us at
gdpr@kompanionapp.com.
Storage of Personal Data
We retain your personal data as long as it is required to fulfill purposes specified in this Privacy Policy, unless we are required to retain this information for a longer period of time to comply with our legal obligations, enforce our legal agreements and policies, and resolve disputes.
Your Rights
Subject to limitations in applicable law, you are entitled to request the restriction of processing of your personal data, to request access to, rectification, erasure, and portability of your personal data and to revoke your consent with effect for the future. You also have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) e) or f) GDPR; this also applies to profiling based on these provisions.
To make a request concerning your rights, you may simply send an e-mail to
gdpr@kompanionapp.com. We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
Should you wish to send your questions, opinions, concerns or recommendations regarding privacy and any other issue, please do not hesitate to contact us. You may always send us an email at
gdpr@kompanionapp.com.