Privacy Notice (Protection of Personal Data)
MarineHero — PERA Nautica Denizcilik A.Ş.
This Privacy Notice has been prepared, in accordance with the Personal Data Protection Law No. 6698 (the “Law” / “KVKK”) and the relevant legislation, by PERA Nautica Denizcilik A.Ş. (the “Company” / “PERA Nautica”) as the data controller, in order to disclose the details regarding the processing of the personal data of users of the MarineHero mobile application (the “Application”) and the Website.
MarineHero is an intermediary digital platform that brings together yacht and boat owners (the “Customer”) and captain, crew, cook, fuel, maintenance-repair, cleaning, security, medical personnel, concierge and similar marine service providers (the “Service Provider”). The collection of the service fee is mediated through the platform; payments are received through the virtual POS infrastructure of an authorized payment/electronic money institution.
This English text is a courtesy translation. In case of any discrepancy, the Turkish version (“Aydınlatma Metni”) shall prevail.
1. Data Controller
The data controller for personal data collected through the platform is PERA Nautica Denizcilik A.Ş., which operates the MarineHero platform.
İVEDİKOSB MAH. 2224 CAD. Door No: 1 Apartment No: 116 YENİMAHALLE / ANKARAMERSİS No: 0728084781800001
Tax Office / No: İVEDİK / 7280847818
Contact / KVKK Application E-mail: support@peranautica.com
2. Categories of Personal Data Processed
Your personal data is processed by classifying it under the following categories according to your account type (Customer or Service Provider) and the way you use the Application:
- Identity Information
- Name-surname, account (user) name, profile photo.
- Contact Information
- Mobile phone number, e-mail address.
- Marine Vessel Information (Customer)
- Yacht/boat name, type, length, registration number, flag, mooring (home) port, marine vessel image.
- Professional and Service Provider Information (Service Provider)
- Company/business name, service description, business/trade licence information, insurance information, certifications, years of experience, service areas, languages spoken, service type and hourly rate information.
- Visual and Audio Data
- Profile photo; photos, videos, documents and audio files shared as part of in-app chat and service requests.
- Customer Transaction and Content Information
- Service requests, request descriptions, chat messages, reviews and ratings.
- Transaction Security and Technical Data
- Application logs, IP address, device information and device identifiers, push notification device token, password (irreversibly encrypted/hashed), session (JWT) information, last login and last seen times.
- Location Data
- Real-time location (GPS coordinate) information obtained from your device or through the system for the purpose of service matching and execution (Service Provider location; Customer/vessel location at the time the service request is created).
- Financial Information / Payment Information
- Your card’s masked number (first 6 and last 4 digits / BIN), cardholder’s name and surname, masked IBAN, transaction/order number, transaction amount and currency, payment/refund and payout records and commission information. Your card’s full number (PAN), expiration date and CVV/CVC information are not seen, recorded or stored by our Company; this information is transmitted directly to the virtual POS infrastructure of the authorized payment institution in accordance with PCI-DSS standards with the 3D Secure security protocol.
3. Purposes of Processing Personal Data
Your personal data is processed in accordance with the general principles in Article 4 of the Law for the following purposes:
- Membership and Contract Processes
- Creation of user registration, identity verification, matching of Customer and Service Provider, management of service requests and provision of services within the scope of the “MarineHero Terms of Use / User Agreement”.
- Operational Management
- Locating nearby Service Providers based on location, routing service requests, providing real-time location and notification services.
- Communication
- Operating the in-app chat infrastructure, sending push notifications and providing information about the service.
- Financial Transactions and Collection
- Collection of the service fee through the Platform, realization of payment and financial transactions, payment to the Service Provider by deducting commission, execution of refund and chargeback processes, and resolution of payment disputes.
- Security, Fraud Prevention and Legislation
- Within the scope of establishing account and system security, prevention of abuse and fraud, identity verification and legal compliance; fulfilling obligations arising from tax, accounting and relevant legislation and making legal notifications.
- Improvement and Statistics
- Measuring service quality by anonymizing data, evaluating and improving platform performance.
4. Personal Data Collection Method and Legal Reason
Your personal data is collected through the Application, the Website and support channels.
- Method
- It is collected by fully or partially automatic means (electronically) and provided that it is part of a data recording system.
- General Legal Reason
- Pursuant to Article 5 of the Law; “being mandatory for the establishment or performance of a contract”, “fulfilling the legal obligations of the Company”, “being mandatory for the establishment, exercise or protection of a right” and “data processing being mandatory for the legitimate interests of the Company”.
- Legal Reason for Payment Transactions
- Collection of the service fee and progress payments are subject to Article 5/2-(c) of the Law (establishment/performance of the contract); tax and accounting obligations to Article 5/2-(ç) (legal obligation of the data controller); prevention of fraud is based on the legal reason in Article 5/2-(f) (legitimate interest).
These transactions are not based on explicit consent and are carried out without seeking explicit consent; therefore, there is no explicit consent given for processing within this scope, nor any withdrawal of it.
In cases requiring explicit consent, such as processing location data, transferring personal data abroad and sending commercial electronic messages (if any), the processing is also carried out based on your explicit consent obtained within the scope of the Explicit Consent Text.
5. Transfer of Personal Data
Since the platform acts as an intermediary and the technical infrastructure is operated through third-party service providers, your data may be shared with the following parties:
- Other Users (Other Party)
- As a requirement of service matching, the Service Provider’s professional profile information (name/business name, service area, rating, location) is shared with the Customer seeking service, and information about the service request is shared with the relevant Service Provider.
- Infrastructure and Cloud Service Providers
- Third-party software/infrastructure companies used for storing, processing and transmitting data — Cloudflare R2 (file/media storage), Google Cloud (database infrastructure), Expo (push notification delivery) and map service providers (Apple Maps / Google Maps).
- Payment Institutions and Banks
- For the purpose of making the payment, your financial information is shared with authorized payment and electronic money institutions operating in accordance with Law No. 6493 and the banks/member merchants with which they have agreements. These organizations act as an independent data controller in terms of payment transactions at the card network, and as a data processor only in terms of transactions carried out with documented instructions of our Company (e.g. tokenized data regarding progress payments).
- Tax Authorities
- The Ministry of Treasury and Finance (Revenue Administration) and authorized tax offices within the scope of invoice and financial notification obligations.
- Authorized Public Institutions and Organizations
- Within the scope of audit, reporting and notification obligations arising from the legislation; upon request, relevant public institutions, courts, prosecutors’ offices and competent authorities for the purpose of ensuring maritime security/public order (e.g. Coast Guard Command, Port Authorities).
- Transfer Abroad
- Your personal data may be transferred abroad due to the fact that the servers of infrastructure providers (Cloudflare R2, Google Cloud, Expo, map services) may be located abroad. These transfers are carried out on the basis of your explicit consent or appropriate safeguards stipulated in accordance with Article 9 of the Law (e.g. adequacy decision, standard contract/undertaking, binding corporate rules). In terms of your card and payment data, since the information systems of authorized payment institutions are kept in Türkiye in accordance with Law No. 6493 and CBRT regulations, as a rule no transfers are made abroad.
6. Data Retention Period and Destruction
The Company stores personal data for the period required by the purpose of processing and for the minimum/maximum periods stipulated in the relevant legislation. At the end of the period, the data is deleted, destroyed or anonymized in accordance with the Company’s KVKK Personal Data Storage and Destruction Policy.
In accordance with tax and financial legislation, financial records (invoices, payment/progress payment records and related financial notifications) are kept for 10 years from the end of the accounting period to which they relate, by evaluating the provisions of the Tax Procedure Law No. 213 (5 years) and Article 82 of the Turkish Commercial Code No. 6102 (10 years) together.
Data security: Financial data is encrypted in transit and at rest; all interfaces, reports, exports and logs are masked; it is only accessible to authorized personnel and accesses are logged (Article 12 of the Law).
7. Cookies and Similar Technologies
On our website and mobile application, mandatory, functional and analytical cookies and similar technologies (device identifiers, secure local storage) are used to improve user experience, maintain sessions, support payment security (3D Secure) and fraud prevention, and measure system performance. For detailed information, you can review the Cookie Policy.
8. Rights of the Person Concerned
Users have the right, in accordance with Article 11 of the Law, to learn whether their personal data has been processed; to request information if it has been processed; to learn the purpose of processing and whether it is used in accordance with that purpose; to know the third parties to whom it is transferred domestically or abroad; to request the correction of incomplete or incorrectly processed data; to request deletion/destruction within the framework of the conditions stipulated in the Law; to request notification of these transactions to third parties to whom the data has been transferred; to object to a result arising against them from analysis carried out exclusively by automated systems; and to demand compensation for damage due to unlawful processing.
You can submit your applications in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. You can send them to the address of the Company stated above in writing, or via support@peranautica.com.
Last Updated / Effective Date: 25.06.2026 · MarineHero — PERA Nautica