How this document applies
English privacy notice covering account, purchase, payment-result, learning, support, security, cookie and user-request data processed through Mortanas Academy. International Paddle merchant-of-record roles, tax, buyer-document and refund handling are clarified.
Order processing roles
The detailed policy below remains in full. The following route-specific allocation clarifies which statements apply to a Türkiye/iyzico order and which apply to an eligible international order processed through Paddle.
Scope note: This allocation applies only to an order actually processed through Paddle. Another payment method retains the roles shown for that route. A planning or availability request is not an order or charge. Live, one-to-one, consulting or corporate human-service programmes are not routed to Paddle unless Paddle has approved that offering in writing.
Privacy Policy
Effective date: 27 July 2026 · English document version: 2026.07.27-en-v1
This Privacy Policy explains how personal data is processed when you visit mortanasacademy.com, create or use an account, purchase or access a course or other digital product, attend a live session, contact support, or otherwise use Mortanas Academy services. The version label is an internal publication identifier; it is not an external legal-compliance certification.
1. Data controller and service operator
- Data controller, platform operator, seller and invoice issuer for Turkish sales: Mortanas Yapay Zeka Teknolojileri Sanayi Limited Şirketi
- Brand: Mortanas Academy
- Tax office / tax number: Maltepe Tax Office / 6211247357
- Contact/office address: Koç İkiz Kuleleri, Söğütözü, Söğütözü Cd. No:2, 06530 Çankaya/Ankara, Türkiye
- E-mail: info@mortanasacademy.com
- Telephone: +90 554 013 9999
MORTANAS COMPANY LIMITED, registered in the United Kingdom under company number 16705479, is a separate legal entity. It is not the seller, payment recipient, invoice issuer or Turkish data controller for Mortanas Academy sales made and invoiced by the Turkish company identified above.
2. Scope and categories of personal data
Depending on the service you use, the data processed may include:
- Identity and contact data: name, surname, e-mail address, telephone number and address information you choose or are required to provide.
- Account and authentication data: account identifier, password hash, sign-in records, session information, verification and password-recovery records, and, where selected and configured, information returned through Google sign-in.
- Customer and transaction data: order number, products, price, currency, coupon, invoice information, payment-result status, refund or charge-review records and transaction timestamps.
- Learning and service data: enrolled courses, protected-document access, progress, quiz or assessment results, notes, completion decisions and certificate records.
- Support and complaint data: messages, attachments, support category, order association, troubleshooting records and dispute correspondence.
- Security and technical data: IP address, browser or user-agent information, device and session data, access logs, error records, consent timestamps and security-event information.
- Preference and communication data: language, currency, cookie choices and, only where a valid separate permission exists, newsletter or commercial-message preferences.
3. Purposes and legal grounds
Personal data may be processed for the following purposes and on the legal grounds available under applicable law, including the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where relevant, the GDPR:
- creating and operating an account, forming and performing a contract, delivering purchased content and providing customer support;
- processing and reconciling orders, payment results, invoices, cancellations, refunds and access records;
- maintaining learning progress, assessments, notes and completion records requested as part of the service;
- complying with tax, accounting, consumer-protection, recordkeeping and lawful public-authority obligations;
- preventing fraud, protecting accounts and the platform, diagnosing faults and establishing, exercising or defending legal claims;
- measuring and improving service quality where this can be done consistently with users' fundamental rights; and
- sending optional newsletters or personalised commercial communications only where the legally required consent or permission has been obtained.
Where processing is necessary for contract performance, a legal obligation, a legal claim or a legitimate interest that does not override your rights, consent is not presented as the mandatory basis. Where consent is the proper basis, it may be withdrawn for future processing without affecting processing already lawfully carried out.
4. How data is collected
Data is collected directly from registration, checkout, account, contact and support forms; from actions taken in the learning platform; from cookies, browser storage and server logs; and from transaction-result messages returned by the selected payment provider. Documents or information you voluntarily submit in a support or legal request may also be processed by non-automated means as part of a filing system.
If you choose Google sign-in and that option is configured, the relevant Google OAuth endpoints are contacted. If you actively invoke the translation function in the protected reader, the text you select may be sent to the Google Translate endpoint for that requested translation. These conditional functions are not described as active when you do not select them.
5. Payment information
Card checkout is processed through the iyzico Checkout Form when that payment method is selected. Mortanas Academy does not store the full card number, expiry date or CVV. The platform records the minimum payment-result and evidence fields reasonably required to confirm the order, reconcile the amount and currency, investigate duplicate or suspicious transactions, administer access, and handle a refund or dispute.
A provider response is not treated as proof of a refund until a verified refund result has been received. The current checkout-result record also does not, by itself, prove card country or that mandatory 3-D Secure authentication occurred; any such authentication may depend on the payment provider, bank and merchant configuration.
6. Recipients, service providers and international transfers
Data is disclosed only to the extent necessary for the relevant purpose. Recipient categories may include the selected payment institution, hosting and security providers, an SMTP transport configured in the site settings for transactional or support e-mail, professional accounting or legal advisers, and competent public authorities. A provider name is not inferred where the underlying service is not configured or verifiable.
Some pages reference external asset hosts, including Google Fonts, cdnjs, jsDelivr, unpkg, Plyr's CDN and remote image sources. When a page actually references such an asset, the browser may connect to that host and disclose ordinary request information such as IP address and user-agent data. These asset requests are not represented here as optional analytics or marketing trackers merely because they are third-party requests.
If a transfer outside Türkiye or another relevant jurisdiction occurs, it is handled under the then-applicable transfer rules and an available legal mechanism, safeguard or exception. This Policy does not claim that a particular provider, destination or safeguard is in use unless it is actually configured for the relevant processing.
7. Retention, review and deletion
Retention depends on the record category, processing purpose, contract, tax and accounting rules, consumer-law obligations, security needs and any live dispute. The current operational framework targets a ten-year retention period for principal order, explicit acceptance, payment-evidence, invoice-work, refund-review, completion-decision and access-evidence records. Support records receive an initial retention review three years after creation. A legal hold may be applied only to records relevant to an open dispute or legal obligation.
At the end of the applicable period, an authorised deletion, anonymisation or continued-retention review is performed. This statement does not claim that one blanket period applies to all data or that every record is removed by an automatic deletion job. Backup-cycle limitations and legally required retention may affect the final disposal date.
8. Security
Proportionate technical and organisational measures may include role-based access, password hashing, secure session settings, encryption in transit, logging, backup, integrity checks, restricted administrative access and review of suspicious payments or account activity. No internet service can promise absolute security. Suspected unauthorised use or a security incident may be reported to info@mortanasacademy.com.
9. Your rights and how to exercise them
Subject to the conditions and exceptions in applicable law, you may have rights to learn whether your data is processed, obtain information or access, request correction, request deletion or destruction, learn the recipients of transfers, request notice of correction or deletion to relevant recipients, object to a result produced exclusively by automated analysis, restrict or object to certain processing, receive portable data where applicable, and claim compensation for unlawful processing.
Send a request that identifies the right concerned and includes enough information to verify your identity to info@mortanasacademy.com or to the contact/office address above. Additional proportionate verification may be requested to protect your account. KVKK applications are answered as soon as possible and no later than 30 days, subject to the statutory procedure and any fee permitted by the official tariff.
10. Cookies, choices and changes
Necessary cookies and browser storage support sessions, security, language, currency and other requested functions. Optional analytics or marketing technologies must be governed by the available preference mechanism and a valid legal basis. Continuing to browse, by itself, is not treated as consent to non-essential cookies. See the Cookie Policy for the current names, purposes and configured durations.
This Policy may be updated when law, the service or verified operational practices change. The current effective date and version are published with the text. Material changes may also be communicated through the account or registered contact channel where appropriate.
11. Contact and publication record
Questions, privacy requests and complaints may be sent to info@mortanasacademy.com or +90 554 013 9999. A version number or SHA-256 record is an internal publication and integrity record only; it does not constitute approval by a public authority or an external compliance certificate.
Effective: 9 August 2026 · Version: EN-2026.08.09-paddle3
International Paddle checkout privacy
Controlling route clarification: For an eligible international order actually processed through Paddle, statements elsewhere on this English page that identify the Turkish company, iyzico, or a Mortanas entity as the payment recipient or buyer transaction-document issuer apply only to the Türkiye/iyzico route and do not describe the Paddle transaction. MORTANAS COMPANY LIMITED (UK company no. 16705479), trading as Mortanas Academy, creates, owns, supplies and fulfils the digital education products. The applicable Paddle contracting entity is determined by the buyer’s purchase location as set out in the Paddle Buyer Terms. That Paddle entity is the authorised reseller, legal seller and merchant of record.
Necessary checkout and order data is submitted directly to Paddle so it can operate checkout, process payment, prevent fraud, calculate applicable transaction taxes, issue the buyer transaction document, provide billing support and administer refunds. Paddle then shares the order, fulfilment and support information reasonably required by MORTANAS COMPANY LIMITED to create the learner account, provide access, deliver the product and support the buyer. Paddle and MORTANAS COMPANY LIMITED each act as independent data controllers for their respective processing activities. Card details are entered with Paddle and are not stored on Mortanas Academy servers. See the Paddle Privacy Notice.