Privacy policy
This policy explains how personal data is processed on the fincodelabs.com website, in the Fiva mobile app and in communication with Fincode by email or WhatsApp, in accordance with Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where applicable, the EU General Data Protection Regulation (“GDPR”).
Last updated: October 10, 2026. This is a translation of the Turkish version, which prevails in case of any discrepancy.
Data controller
Your personal data is processed by Fincode Yazılım ve Teknoloji A.Ş. (“Fincode”) as the data controller.
Address: Mecidiyeköy Fulya Mah. Büyükdere Cad. Torun Center D Blok No:74D Kat:10 İç Kapı No:43, Şişli, Istanbul, Türkiye
Email: info@fincodelabs.com
Personal data processed
Website visitors
fincodelabs.com has no forms, user accounts, advertising or analytics cookies, and Fincode does not track visitors. The site is hosted on Cloudflare. To deliver pages and protect the site against attacks, Cloudflare processes technical records such as IP address, browser and device information, the page visited and the time of access. Fincode sees these records only as aggregate statistics (for example, daily visit counts).
People who contact Fincode
When you contact Fincode by email or WhatsApp, your name, email address, phone number, company and any project details you share in your message are processed.
Startups applying for funding
Names, contact details, education and experience of the applicants and of the founders and team members named in the pitch deck, as well as information about the startup, are processed. If the pitch deck contains personal data of other people, the applicant is responsible for informing them.
Fiva users
- Account data: username, email address and the authentication data required to sign in.
- In-app data: watchlists, price alerts, notes, portfolio information and conversations with Fiva AI.
- Community data: profile information, posts and forecasts. Content shared in the community can be seen by other users.
- Device and usage data: device model, operating system and app version, push notification token, IP address and error logs.
Fiva does not connect to bank or brokerage accounts, does not ask for their passwords and does not execute trades. Fincode does not process special categories of personal data such as health or biometric data; such information should not be shared in community posts or Fiva AI conversations.
Purposes of processing
- Operating the website and keeping it secure
- Answering questions and requests, preparing proposals, and entering into and performing project contracts
- Evaluating funding applications
- Creating Fiva accounts and providing features such as watchlists, alerts, notifications, the community and Fiva AI
- Detecting errors, improving the security and quality of the services and preventing misuse
- Complying with legal obligations and responding to requests from competent authorities
- Protecting legal rights in the event of disputes
Fincode does not sell or rent personal data and does not share it with third parties for advertising.
Collection method and legal bases
Personal data is collected electronically, partly by automated means, through the website, the Fiva app, email and WhatsApp. It is processed on the following legal bases under Article 5 of the KVKK (with the corresponding GDPR provision where the GDPR applies):
- Entering into or performing a contract (GDPR Art. 6(1)(b)): providing the Fiva account and its features, project proposals and contracts, and evaluating funding applications.
- Compliance with legal obligations (Art. 6(1)(c)): commercial, tax and accounting records and requests from competent authorities.
- Establishing, exercising or defending legal rights (Art. 6(1)(f)): potential disputes.
- Fincode's legitimate interests, provided they do not override your fundamental rights and freedoms (Art. 6(1)(f)): website and app security, error logs, answering requests and improving the services.
Where none of these legal bases applies, for example for promotional notifications, your explicit consent is obtained separately (Art. 6(1)(a)). You can withdraw your consent at any time.
Recipients of personal data
Personal data may be shared with the following recipients, only for the purposes above and only to the extent necessary:
- Service providers: website hosting and security (Cloudflare), business email (Google Workspace), app distribution and notifications (Apple: App Store, TestFlight and Apple Push Notification Service), messaging (WhatsApp, Meta), Fiva's server infrastructure and the AI service provider that generates Fiva AI's answers.
- Advisors: legal, accounting and audit advisors.
- Authorities: public authorities and courts with legal authority to request the data.
Messages written to Fiva AI and the portfolio information needed to answer them are sent to the AI service provider only to generate the answer. Do not enter ID numbers, passwords or bank details in Fiva AI.
Some of these service providers process data on servers outside Türkiye. Transfers abroad are carried out in accordance with Article 9 of the KVKK, with appropriate safeguards provided for by law, such as the standard contracts published by the Turkish Personal Data Protection Board. Messages sent via WhatsApp are also subject to Meta's privacy terms.
Retention periods
- Correspondence: 2 years from the last message for requests that do not lead to a contract; 10 years for contracts and business correspondence, as required by the Turkish Commercial Code and tax legislation.
- Funding applications: pitch decks and documents of applications that do not result in an investment are deleted within 1 year of the evaluation at the latest. You can request earlier deletion.
- Fiva account data: for as long as the account exists. You can delete your account in the app or by writing to destek@fincodelabs.com; data is deleted or anonymized within 30 days of account deletion.
- Security and error logs: up to 2 years.
When the retention period ends, data is deleted, destroyed or anonymized. Longer retention periods required by law remain unaffected.
Data security
Fincode takes appropriate technical and organizational measures to prevent unlawful processing of and unauthorized access to personal data. Data is transmitted over encrypted connections (HTTPS/TLS), access is limited to people who need it for their work, and service providers are selected with confidentiality obligations in mind.
Cookies
fincodelabs.com does not use advertising, analytics or tracking cookies. Cloudflare may set strictly necessary security cookies (such as __cf_bm) to identify malicious traffic; these cookies are not used to build profiles. For this reason, the site does not ask for cookie consent.
Links to other websites
The site links to third-party services such as Instagram, X, WhatsApp and TestFlight. The privacy policies of those companies apply when you use their services.
Your rights under the KVKK
Under Article 11 of the KVKK, you have the right to:
- learn whether your personal data is processed,
- request information about the processing,
- learn the purpose of the processing and whether the data is used accordingly,
- know the third parties in Türkiye or abroad to whom the data is transferred,
- request correction of incomplete or inaccurate data,
- request deletion or destruction of the data under the conditions set out in Article 7 of the KVKK,
- request that third parties to whom the data was transferred be notified of any correction, deletion or destruction,
- object to a result to your detriment arising from analysis of the data exclusively by automated systems,
- claim compensation for damage caused by unlawful processing.
Additional information for users in the EU and EEA (GDPR)
Where the GDPR applies, you additionally have the right to restriction of processing, to data portability and to object to processing based on legitimate interests (Art. 18, 20 and 21 GDPR), as well as the right to lodge a complaint with a supervisory authority, in particular in the EU or EEA member state where you live.
Fincode is based in Türkiye, a country for which there is no EU adequacy decision. When you contact Fincode or submit an application, your data is transferred to Türkiye because this is necessary to answer your request or to take steps prior to entering into a contract (Art. 49(1)(b) GDPR). Service providers in the United States process data on the basis of the EU–US Data Privacy Framework or standard contractual clauses.
How to submit a request
You can send requests in writing to the address above or by email to info@fincodelabs.com from an email address you have previously used with Fincode.
Please include your full name, Turkish ID number (nationality and passport number for foreign nationals), postal address, email address and phone number if available, and the subject of your request. Fincode answers as soon as possible and within 30 days at the latest, free of charge; if the request involves additional costs, the fee set by the Turkish Personal Data Protection Board may be charged. If your request is rejected, if you find the answer insufficient or if no answer is given in time, you can file a complaint with the Turkish Personal Data Protection Board.
Age limit
Fiva is not intended for people under the age of 18.
Changes
This policy may be updated to reflect changes in legislation or in the services. The current version is always published on this page, and Fiva users are informed separately of significant changes.