Compliance (KVKK) and consent management (IYS)
Disclosure and consent texts, retention and disposal policy, data subject requests, per-person data package and anonymization, access trail; evidenced IYS consents, automatic consent sources, send gates and the IYS file.
Setup > Compliance#
Three tabs: Controller and Preferences, Disclosure and Consent Texts, Compliance Tools.
Controller and preferences
- Legal name, address, request e-mail, registry number and contact person are merged into the texts.
- Mandatory 2FA and disable AI assistant apply org-wide; with AI off, record data never reaches an AI provider.
Disclosure and explicit consent texts
- The text adds industry paragraphs based on your licensed apps: special-category health data for clinics, identity reporting for hospitality, employee data for HR, professional secrecy for law firms.
- Retention periods come from your Object Manager policy; international transfer from hosting and your AI preference.
- Whenever the text changes on save, a version number increments; IYS consent records carry the version they were given under.
Retention and disposal policy
In Object Manager > object > Retention choose a period (3 months to 10 years) and what happens afterwards: anonymize or delete permanently. The job runs nightly on the server and is written to the audit log as kvkk_saklama. For objects with statutory retention (invoices), set the period accordingly.
Data subject requests (art. 11)
- Under Compliance Tools click Set up the request object: a Requests tab and record form (type, channel, date, related person, outcome) are created.
- Each request has a 30-day counter; requests within 7 days of the deadline or overdue appear in the Platform home Attention list.
- For access and portability requests use Data package (person plus linked tasks, events, cases, opportunities and posts as one JSON); for erasure use Anonymize (personal fields cleared, business records kept). Both are audit-logged.
Record access trail
Who viewed which record and when: the table under Compliance Tools (one entry per user and record per 10 minutes, kept for 2 years). File access is tracked separately under Files.
IYS360: commercial message consents#
Enabled from Marketplace > System Add-ons. The Consents card on contact and lead records manages three channels (call, message/WhatsApp, e-mail).
Evidenced consent record
- Per channel: status (Approved / Refused / Unknown), time of consent, source, the user who entered it, IP and text version.
- Recipient type Individual / Merchant; contacts linked to a company and leads with a company default to Merchant.
Where consent comes from
- Web form: when the consent box in the Web-to-Lead snippet is ticked, the lead's e-mail and message consent become Approved with source Website, IP and timestamp.
- Newsletter360: the subscription form sets the contact's e-mail consent to Approved; the unsubscribe link in mails sets it to Refused.
- Manual: from the card, with sources such as wet signature, call center or event.
Send gates
- Marketing360 bulk e-mail: only recipients with Approved e-mail consent.
- Record e-mail and Newsletter360 sends: recipients with Refused e-mail consent are blocked on the server.
- WhatsApp button: no send when message consent is Refused; a warning when Unknown.
The IYS file
From the IYS card on the Marketing360 home page: Export all or Export changes (since the last file). Columns match the IYS bulk upload: consent type, recipient (+90 phone or e-mail), recipient type, status, timestamped date, source code (HS_*). The card warns when unreported refusals are older than 3 business days.
Recommended order#
- Enter controller details and save the texts (a version is created).
- Set retention periods in Object Manager.
- Enable IYS360, record existing consents from the card or via import, and update the web form snippet with the consent box.
- Only then open bulk sends; export and upload the IYS file regularly.