Effective 28 July 2026 · Version 1.0
1. Data controller and contact
The data controller for ekbe.net is EKBE, the operator of the EKBE Sports Intelligence platform. Privacy requests can be sent to [email protected]. We may request proportionate information to verify identity before acting on a request.
2. Data categories
- Account: username, email address, password hash and salt, email-verification status, age/terms confirmations and timestamps.
- Security: session identifiers, hashed IP and user-agent values, failed-login and security-event records.
- Wallet and use: Coin balance, ledger entries, unlocked event identifiers and analysis versions.
- Orders: Shopier order number, package, amount/currency, status and a hashed buyer-email value. EKBE does not receive or store card details.
- Technical: essential storage required for age choice and secure sign-in. Non-essential analytics are not enabled in this release.
3. Purposes, collection method and legal grounds
Data is collected electronically from account forms, security headers, platform actions and Shopier's signed paid-order notifications. It is processed to create and secure accounts, automatically match a purchase to the verified account email, perform the requested digital service, maintain a correct Coin ledger, prevent duplicate credit and abuse, respond to rights and support requests, establish or defend legal claims, and meet applicable legal obligations.
Depending on the activity, processing is based on performance of a contract, legal obligation, establishment or protection of a right, and legitimate interests that do not override fundamental rights under Turkish Law No. 6698. Where consent is legally required, it is requested separately from this information notice.
4. Recipients and service providers
Necessary data may be processed by Cloudflare for hosting, database and security; Shopier for checkout and order handling; and the configured transactional-email provider for one-time account messages. Data may also be disclosed to authorised public bodies when lawfully required. Providers receive only the data necessary for their function and are subject to their own terms and safeguards.
Some infrastructure providers may process data outside Türkiye. Applicable cross-border transfer requirements and safeguards must be assessed and maintained for each active provider.
5. Retention and security
Data is kept only for the period required by the service, security, payment records, limitation periods and applicable law. Expired sessions are invalidated; one-time codes expire after 10 minutes; passwords are stored only as salted PBKDF2 hashes; secret keys remain server-side; payment-card data is not collected by EKBE. When a lawful retention ground ends, data is deleted, destroyed or anonymised under the applicable retention process.
6. Your rights
Under Article 11 of Law No. 6698, you may ask whether personal data is processed, request information, learn the purpose and recipients, request correction, deletion or destruction where conditions apply, request notification of such actions to recipients, object to certain solely automated outcomes, and seek compensation where legally available. Send a clear request to [email protected].
For authoritative guidance, see the Turkish Personal Data Protection Authority’s information on the duty to inform.