Skip to content
← Back to home

Privacy Policy

Last updated: 25 September 2026

This Privacy Policy explains how Polatof, trading as Edunison, handles personal data. It is written to meet Regulation (EU) 2016/679 ("GDPR") and Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), which impose materially similar duties on us. Where you are reading the Turkish version of this page, that version is the operative text for services sold in Türkiye.

1. Who we are, and in which role

The company behind Edunison:

Polatof Yapı Üretim Sanayi Ticaret Anonim Şirketi, a joint stock company incorporated in the Republic of Türkiye ("Polatof", "we", "us"), trading as Edunison.

Registered address: Şirinevler Mah., Meriç Sk. Özgül No:17 İç Kapı No:11, 34188 Bahçelievler/İstanbul, Türkiye.

MERSIS: 0732198180300001 · Tax ID: 7321981803 (Kocasinan Tax Office) · Trade registry: Istanbul Chamber of Commerce, No. 1028656.

Contact: support@edunison.com · +90 555 650 41 11.

Edunison is school and course management software delivered as a service. Our role under data protection law depends on whose data is involved, and the distinction decides who you should approach:

**Controller.** For the account, contact, billing and usage data of the institution that buys Edunison and of the staff who use it, we decide why and how the data is processed. We are the controller and we answer requests directly.

**Processor.** For the personal data an institution enters about its students, parents, guardians and staff, the institution decides why and how it is processed. The institution is the controller; we act only on its documented instructions. If you are a student or a parent, your first point of contact is your school, not us — we will forward requests we receive to the institution concerned.

We do not sell personal data, we do not use it for advertising or profiling, and we do not use customer content to train machine learning models.

2. Categories of personal data

As controller, for our customers and their staff:

Identity and contact data: name, surname, job title, email address, telephone number, postal address.

Account data: username, role and permission assignments, login and session records, language preference.

Billing data: institution name, tax identifiers, subscription and payment records. We never receive or store full card numbers; card payments are handled by our payment institution.

Technical data: IP address, device and browser information, application logs, error reports.

As processor, on behalf of the institution, the categories its own configuration determines — typically:

Student and guardian identity and contact data, including data about children.

Academic records: classes, timetables, attendance, homework, examinations and results.

Financial records relating to tuition: fee schedules, instalments, payments and receipts.

Any files or free text the institution chooses to upload.

3. Why we process it, and on what legal basis

As controller, we rely on the following legal bases under Article 6(1) GDPR (and the corresponding grounds in Articles 5 and 6 KVKK):

**Performance of a contract** (Article 6(1)(b)): creating and running the institution's account and subdomain, delivering the software, providing support, and handling subscriptions, invoicing and payments.

**Legal obligation** (Article 6(1)(c)): retaining accounting, tax and commercial records as Turkish law requires, and responding to lawful requests from competent authorities.

**Legitimate interests** (Article 6(1)(f)): keeping the service secure and available, preventing abuse, diagnosing faults and improving the product. We balance these against your interests and you may object as described in section 8.

**Consent** (Article 6(1)(a)): analytics cookies on our public marketing pages, and nothing else. Consent can be withdrawn at any time without affecting the service.

As processor, the legal basis for student and guardian data is determined by the institution acting as controller, not by us.

4. Who we share it with

We use a small number of service providers ("sub-processors") to run Edunison. Each is bound by a written agreement, may process personal data only on our instructions, and is listed here so you can assess them:

**Vercel Inc.** (United States) — application hosting and delivery.

**Neon Inc.** (United States) — managed PostgreSQL database. The database that holds customer data is provisioned in the **European Union (Frankfurt, eu-central-1)**.

**Vercel Blob** (region **fra1**, Frankfurt, European Union) — storage for files uploaded through the product.

**Resend** (United States) — transactional email delivery (password resets, notifications).

**Functional Software, Inc. d/b/a Sentry** (United States) — application error monitoring.

**iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. ("iyzico")** (Türkiye) — payment processing. Card data is captured and stored by iyzico, never by us.

**ImprovMX** (France) — inbound email forwarding for our support address.

**Google Ireland Limited** — Google Analytics, on our public marketing pages only and only with your consent. It is not present in the administration panel or the family portal.

We also disclose personal data to competent public authorities where we are legally required to do so, and to professional advisers under a duty of confidentiality. If we are ever involved in a merger or sale of the business, personal data may transfer to the acquirer, subject to this policy.

We give reasonable prior notice of a new or replacement sub-processor to customers who ask to be notified, so that they can object.

5. International transfers

We are established in Türkiye, and some of our providers are established in the United States. Personal data is therefore transferred outside the European Economic Area and, in some cases, outside Türkiye.

Where personal data is transferred out of the EEA, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as incorporated into our agreements with the providers named above, together with the supplementary technical measures described in section 7 — in particular encryption in transit and storage of customer data inside the European Union. Where the recipient is certified under the EU-U.S. Data Privacy Framework, we may rely on that adequacy decision instead.

Transfers out of Türkiye are made in accordance with Article 9 KVKK, on the basis of the undertakings, standard contracts or explicit consent that the legislation requires.

You may request a copy of the relevant transfer safeguards by writing to support@edunison.com.

6. How long we keep it

**Customer and account data:** for the life of the subscription and for as long afterwards as we need it to resolve disputes or enforce our agreements.

**Accounting, invoicing and tax records:** ten (10) years, as Turkish commercial and tax legislation requires.

**Data we hold as processor:** for the duration of the subscription. On termination we return or delete it within thirty (30) days, at the institution's choice, except where law requires us to keep it longer.

**Database backups:** our managed database keeps a rolling point-in-time recovery window of approximately six (6) hours; deleted data may persist within that window before it is overwritten.

**Security and error logs:** kept only as long as needed for diagnosis and abuse prevention.

7. How we protect it

We apply technical and organisational measures appropriate to the risk, including:

All traffic encrypted in transit over TLS; data at rest encrypted by our hosting providers.

Passwords stored only as bcrypt hashes; password reset links stored as hashes, valid once and for sixty (60) minutes; changing a password invalidates every existing session.

Strict separation of each institution's data: every query against customer-owned tables is scoped to the institution it belongs to, and that scoping is enforced by automated tests that fail the build if a new query omits it.

Role-based access control with per-user permission overrides, each recorded with its reason and an audit trail.

Scheduled jobs and internal endpoints authenticated by secret; administrative functions reachable only on a separate console host.

Continuous error monitoring, dependency review, and an automated test suite that must pass before any change reaches production.

No system is perfectly secure. If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where the GDPR requires it, notify affected institutions without undue delay so they can meet their own obligations, and notify individuals directly where the law requires.

8. Your rights

Where we act as controller and the GDPR applies to you, you have the right to: access your personal data and receive a copy (Article 15); have inaccurate data corrected (Article 16); have data erased (Article 17); restrict processing (Article 18); receive your data in a portable format (Article 20); object to processing based on our legitimate interests, including at any time (Article 21); and not be subject to decisions based solely on automated processing producing legal or similarly significant effects (Article 22) — we do not make such decisions.

Where Turkish law applies, Article 11 KVKK gives you materially the same rights, including the right to learn whether your data is processed, to request correction or erasure, to learn the third parties to whom it has been transferred, and to claim compensation for damage caused by unlawful processing.

Where processing rests on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before it.

To exercise any of these rights, write to support@edunison.com or to the postal address above. We will respond within one (1) month under the GDPR and within thirty (30) days under the KVKK. We may ask for information to verify your identity, and we will not charge a fee unless your request is manifestly unfounded or excessive.

If your request concerns data an institution holds about a student or parent, we will refer you to that institution, which is the controller.

9. Children

Edunison is sold to institutions, not to children, and we have no direct relationship with students. Where the platform holds data about children, it does so on the instructions of the school or course provider, which is the controller and is responsible for the legal basis — including any parental consent its national law requires — and for deciding what is entered.

We apply the same security measures to children's data as to all other customer data, and we do not use it for any purpose of our own.

10. Complaints

If you believe we have handled your personal data unlawfully, please contact us first at support@edunison.com so that we can put it right.

You also have the right to lodge a complaint with a supervisory authority — in the EEA, the authority of the country where you live, work, or where the alleged infringement took place; in Türkiye, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr).

11. Changes to this policy

We may update this policy as the product or the law changes. The date at the top of this page shows when it was last revised. If a change materially affects how we handle personal data, we will tell our customers by email before it takes effect.