Privacy Policy
We transparently explain what data AktEdu collects, why we collect it, how we protect it and every decision that affects you.
1. Scope and Purpose
This Privacy Policy covers all parties using the cloud-based educational tracking and analysis services provided by AktEdu (“Platform”, “we”) — educational institution administrators, teachers, students and parents. The Platform provides mock exam analysis, weekly planning, guidance tracking and institutional reporting through a SaaS model.
This document provides a technical explanation of privacy. For a detailed explanation of your legal rights, please review the KVKK Privacy Notice.
2. Data We Collect
Data processed on the platform is divided into the following categories by data subject group:
| Category | Example Data Elements | Data Subject |
|---|---|---|
| Identity Details | First name, surname, username, institution reference number (external_no) | Student, Teacher, Parent |
| Contact Details | Mobile phone number, email address (for parents and staff) | Parent, Teacher, Administrator |
| Education Level | Class/group/level, subject stream preference (SAY/SÖZ/EA/DİL), target exam type (YKS) | Student |
| Academic Performance | Mock exam results, correct/incorrect/net scores, learning outcome analysis by subject, scores, rankings, question counts | Student |
| Guidance Records | Consultation notes, follow-up records, weekly study schedules, homework tracking, one-to-one study session records | Student, Guidance Teacher |
| System Security | Login time, IP address, device information, audit trails (audit logs) | All Users |
3. How Do We Collect Data?
- Direct entry: Institution administrators and teachers manually enter or update student records through the platform interface.
- Bulk import: Optical answer sheet result files and exam data in Excel/CSV format are uploaded by institution administrators.
- User interaction: Interaction logs generated during sessions in student, parent and teacher portals are recorded automatically.
- Athena AI chat: Conversations that guidance teachers and administrators conduct with Athena, and the student data queried, are processed.
4. Why Do We Process Data?
- Institution-level tracking and analysis of students' academic progress.
- Guidance teachers' digital management of personalised plans and consultation notes.
- Transparent sharing of academic status in parent and student portals.
- Providing guidance staff with AI-supported insights and recommendations through Athena.
- Ensuring institutional permission isolation, access auditing and account security.
- Retention of system access logs for the statutory period under Law No. 5651.
5. Infrastructure and Security Architecture
Database and Server
All user and institutional data is hosted on Supabase PostgreSQL infrastructure in Frankfurt (eu-central-1, European Union). This regional choice ensures that educational data is processed in a GDPR-compliant data centre.
Encryption
- In transit: All client–server traffic is protected by end-to-end 256-bit encryption over TLS 1.3 / HTTPS.
- At rest: Database disks are encrypted with AES-256.
- Passwords: User passwords are stored as one-way bcrypt hashes; they are never stored in plain text.
Access Control and Isolation
- Database Row-Level Security technically prevents data access between institutions.
- Teachers can see only their assigned classes/groups; parents can see only their own child's data.
- All critical actions are recorded in timestamped audit logs.
Backup
The database is backed up continuously through Point-in-Time Recovery (PITR). In the event of an outage, the system can be restored to its last stable state within minutes.
6. Athena AI and Anthropic (Claude) Data Processing
Important: Enterprise AI Infrastructure and Data Protection
The Athena academic decision assistant integrates with Anthropic (Claude) enterprise API infrastructure. Under the enterprise API agreement, the academic data submitted is never used to train publicly available AI models (model training / fine-tuning).
Access Authorisation
Only guidance teachers and institution administrators can use Athena. Students and parents cannot access the Athena dashboard directly.
Scope of Data Submitted to the Anthropic Enterprise API
When an authorised user requests analysis or recommendations from Athena, only the academic data needed for that query is submitted for immediate processing:
- First name, surname, class/group, student number
- Mock exam results, net scores, class performance and target comparison
- Topic and learning outcome analysis, question-solving statistics
- Weekly study plan data and homework statuses
- Guidance consultation summaries and follow-up notes
Data Security and Zero-Training Policy
Unlike consumer models, the platform uses Anthropic Enterprise Commercial API infrastructure. Within this infrastructure:
- Student and exam data is never used to train or develop publicly available AI models.
- Data is not transferred or sold to third-party advertising or marketing systems.
- Queries are transmitted with end-to-end TLS 1.3 encryption and returned to the institution's isolated database after immediate inference.
Assessment under KVKK
Under Article 9 of KVKK Law No. 6698, cloud/API processing through servers abroad generally relies on explicit consent or appropriate safeguards prescribed by legislation. This Privacy Policy, accepted at platform login, and SaaS agreements signed with institutions include information and authorisation provisions concerning this enterprise API data flow.
7. Data Transfers and Third Parties
AktEdu never sells or rents the personal data it processes to third parties for commercial or advertising purposes. Sharing takes place only with the following parties and within the specified limits:
| Recipient | Purpose of Transfer | Location |
|---|---|---|
| Supabase Inc. | Database hosting, authentication, real-time data transmission | EU — Frankfurt (eu-central-1) |
| Anthropic (Claude - Athena AI) | AI-supported guidance and academic decision support (authorised user queries only; model training is disabled) | USA — Anthropic Enterprise Servers |
| n8n (automation platform) | Secure orchestration of Athena AI queries and workflow automation | Europe (cloud) |
| Educational Institution and Teachers | Only academic tracking data for authorised groups | Türkiye |
| Parent | Only their own child's reports and academic tracking data | Türkiye |
| Authorised Public Institutions | Sharing with relevant authorities in the event of a legal obligation or court order | Türkiye |
8. Retention and Deletion
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Student academic records | Agreement term + 5 years | KVKK, National Education Legislation |
| System access logs (IP, session) | 2 years | Law No. 5651 |
| Financial records | 10 years | Tax Procedure Law |
| Guidance consultation notes | Agreement term + 3 years | Legitimate interest, limitation periods |
| Query data submitted through the Anthropic API | Only during immediate inference (model training is disabled) | Anthropic Commercial Terms & Zero Retention |
Data whose retention period has expired is securely destroyed under the KVKK Regulation on the Deletion, Destruction or Anonymisation of Personal Data. If the educational institution terminates the agreement, its data is provided in a portable format upon request and then removed from the system within a maximum of 90 days.
9. Your Rights
You have the following rights under Article 11 of KVKK:
- Access to information: Learn which data about you is processed.
- Access: Request a copy of your personal data that is processed.
- Rectification: Request that incorrect or incomplete data be updated.
- Deletion / Destruction: Request deletion of your data when the purpose of processing no longer applies.
- Objection to processing: Object to processing of data processed on the basis of legitimate interests.
- Portability: Request your data in a structured, machine-readable format.
- Right to complain: Lodge a complaint with the Personal Data Protection Authority (KVKK).
You can submit your requests to info@aktedu.com using the application template in the KVKK Privacy Notice. Requests are answered free of charge within 30 days.
10. Contact and Updates
This policy may be updated in line with legal requirements or platform changes. Significant changes are communicated to relevant users by email or in-platform notification. The current version is always available at aktedu.com/gizlilik.