Extrais — Privacy Policy
1. Who is responsible (controller)
The data controller (GDPR) and data controller / veri sorumlusu (KVKK) is TABA Tasarım İnşaat Anonim Şirketi ("TABA"), Republic of Türkiye, info@vitamedas.com. For privacy requests, email us with "Privacy" in the subject.
2. The data we collect
| Category | Examples |
|---|---|
| Account | Email, name, role (Client/Pro), preferred language, country, avatar. |
| Pro verification | Identity document and trade authorisation (autorisation d'établissement) images, verification status. These can include a special category of data (an ID); we process them only with your explicit consent to verify you. |
| Jobs & quotes | Category, structured options, photos, a short note, quotes and prices, and the approximate job location — captured only when you take an action that needs it. |
| Communications | In-app chat content (deleted 24 hours after a job ends) and in-app calling metadata. We never exchange real phone numbers between users. |
| Transactions | Records of digital credit purchases and the credit ledger. Payment itself is handled by Apple/Google; we do not receive your card details. |
| Device & usage | Push token, app version, device type, language, and — only if you consent — product analytics and crash diagnostics. |
| Support | Messages you send us and any information you include. |
3. Why we use it, and our legal basis
| Purpose | GDPR basis (Art. 6) / KVKK basis (Art. 5) |
|---|---|
| Create and run your account; connect Clients and Pros; deliver the core service | Performance of a contract / necessary for a contract. |
| Pro identity & permit verification | Explicit consent (GDPR Art. 9(2)(a) / KVKK Art. 6) — you choose to submit documents and can withdraw. |
| Trust & safety, fraud prevention, enforcing our Terms, handling reports | Legitimate interests, and compliance with legal obligations. |
| Push notifications about your jobs, messages, and account | Performance of a contract; service-operation legitimate interest. |
| Product analytics, crash reporting, marketing emails | Consent — off by default; you can withdraw anytime. |
| Keeping records and meeting tax, accounting, and legal duties | Legal obligation. |
4. Who we share it with
- Other users, as needed for the service: a Pro's public profile is shown to Clients; a Client's job is shown to matched Pros. We do not show your email or phone number to other users.
- Processors who act on our instructions: our cloud/database and storage provider (Supabase, hosted in the EU), our push providers (Apple APNs, Google FCM), our transactional-email provider, and — only with your consent — analytics/crash-reporting (Google/Firebase). They may only process data to provide their service to us, under a data-processing agreement.
- Apple / Google for in-app purchases, under their own terms.
- Authorities where required by law, or to protect rights, safety, or the integrity of the Service.
- We never sell your personal data, never "share" it for cross-context behavioural advertising, and do not use it for third-party advertising.
5. International transfers
Core data is hosted in the European Union. Because TABA is established in Türkiye and some processors operate internationally, your data may be accessed from or transferred to countries outside your own. Where this happens, we rely on appropriate safeguards — for GDPR/UK GDPR, the EU/UK Standard Contractual Clauses or an adequacy decision; for the Swiss FADP, the Swiss SCCs or an adequacy recognition by the Federal Council; and for KVKK, the conditions for cross-border transfer, including your explicit consent or the other bases permitted by Article 9 of the KVKK.
6. How long we keep it
- Account data: while your account is active.
- In-app chat: deleted 24 hours after a job ends.
- Verification documents: retained only as long as needed for the review and removed when the review is complete or your account is deleted.
- Transaction/credit and legally required records: kept for the period required by tax and accounting law.
- When you delete your account, we erase your personal data, including uploaded files, except where we must keep limited records to meet a legal obligation or defend a legal claim.
7. Your rights
Under the GDPR and the KVKK you have the right to: access your data and obtain information about its processing; receive a copy / portability; rectify inaccurate data; erase ("right to be forgotten"); restrict or object to processing; withdraw consent at any time (without affecting prior processing); and not be subject to solely automated decisions with legal effect (we do not carry out such decision-making). Under the KVKK you may also request that we notify third parties of any correction or erasure, and object to a result that is to your detriment.
You can exercise most rights directly in the App (Settings → Manage data: export or delete) or by emailing info@vitamedas.com. We respond within the legal time limits (one month under the GDPR; 30 days under the KVKK) and do not charge a fee unless a request is manifestly unfounded or excessive.
8. Your regional privacy rights
Depending on where you live, additional or specific rights apply. This section supplements the rest of this policy; if there is any conflict, the rule most protective of you in your region prevails. To exercise any right, email info@vitamedas.com with "Privacy" in the subject, or use Settings → Manage data in the App. We verify requests using the information already associated with your account and do not discriminate against you for exercising a right.
8.1 United States
There is no single federal privacy law in the United States. The rights below come from state laws and apply according to your state of residence. We are a privacy-by-design service: we do NOT sell your personal information, and we do NOT "share" it for cross-context behavioural (targeted) advertising, as those terms are defined under U.S. state law. We also do not use or disclose sensitive personal information to infer characteristics about you. Because we do not sell or share, we do not need to offer a separate "Do Not Sell or Share My Personal Information" mechanism, but you may still confirm or object by contacting us.
California (CCPA/CPRA). California residents have specific rights regarding their personal information. The table below maps the statutory categories of personal information we have collected in the preceding 12 months — and the categories we disclosed for a business purpose — to the data described in Section 2.
| CCPA/CPRA category | Collected? | Examples (see Section 2) | Disclosed for a business purpose to processors? |
|---|---|---|---|
| Identifiers | Yes | Email, name, account ID, device/push token, country. | Yes — hosting, email, push, (with consent) analytics. |
| Customer records (Cal. Civ. Code §1798.80) | Yes | Name and contact details associated with your account. | Yes — hosting, email providers. |
| Commercial information | Yes | Credit purchase records, credit ledger, quotes. | Yes — hosting; Apple/Google handle payment. |
| Internet/network activity | Yes (consent only) | App version, device type, product analytics, crash diagnostics. | Yes — analytics/crash provider, only if you opt in. |
| Geolocation data | Yes | Approximate job location, captured only on an explicit action. | Yes — hosting provider. |
| Audio/electronic information | Yes | In-app chat content (auto-deleted 24h after a job ends) and calling metadata. | Yes — hosting/real-time provider. |
| Sensitive personal information | Yes (consent only) | Pro identity/permit documents, which may include a government ID — processed only with explicit consent, solely to verify you. | Yes — secure storage provider, for verification only. |
| Professional/employment information | Yes (Pros) | Trade authorisation status and verification details for Pros. | Yes — hosting/storage provider. |
| Inferences | No | We do not build profiles or infer characteristics for advertising. | No. |
| Biometric / education / certain financial card data | No | We do not collect card numbers (Apple/Google process payment) or biometric data. | No. |
We collect this information for the business and commercial purposes in Section 3 (operating the Service, trust & safety, legal compliance, and — only with consent — analytics and verification). California residents have the right to: know/access the categories and specific pieces of personal information we hold and our sources and purposes; delete personal information, subject to legal exceptions; correct inaccurate personal information; opt out of any sale or sharing for cross-context behavioural advertising (we do neither); limit the use of sensitive personal information (we already limit it to verifying you); and to receive these rights free of non-discrimination or retaliation. You may use an authorised agent to submit a request on your behalf, provided we can verify the agent's authority and your identity. Under California's "Shine the Light" law (Civ. Code §1798.83), we confirm that we do not disclose personal information to third parties for their own direct-marketing purposes.
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA). If you are a resident of these states, you have analogous rights to access/confirm processing of your personal data, delete it, correct it (except Utah, which does not provide a correction right), obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and (where applicable) profiling that produces legal or similarly significant effects — none of which we perform. Where required (Virginia, Colorado, and Connecticut), you also have the right to appeal a refusal of your request by replying to our decision; if we deny the appeal, we will tell you how to contact your state Attorney General.
8.2 Canada
If you are in Canada, we handle your personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and its fair-information principles — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. You may access and correct your personal information and challenge our handling of it by contacting us; you may also complain to the Office of the Privacy Commissioner of Canada (OPC).
If you are a Québec resident, Law 25 (the Act to modernize legislative provisions as regards the protection of personal information) gives you additional rights, including the right to be informed of the collection and purposes, the right of access and rectification, the right to withdraw consent, the right to data portability (to receive computerised personal information in a structured, commonly used technological format), and the right to be informed when a decision about you is based exclusively on automated processing. We confirm that we do not make decisions about you based solely on automated processing. Québec residents may also contact the Commission d'accès à l'information du Québec (CAI).
8.3 United Kingdom
If you are in the UK, our processing is governed by the UK GDPR and the Data Protection Act 2018. You have the same core rights described in Section 7 (access, rectification, erasure, restriction, objection, portability, and rights regarding automated decision-making, which we do not perform). The supervisory authority is the Information Commissioner's Office (ICO), with which you may lodge a complaint.
8.4 Switzerland
If you are in Switzerland, our processing is governed by the revised Federal Act on Data Protection (revFADP / nLPD). You have rights of access, rectification, erasure, objection, and data portability comparable to those in Section 7. The supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), to which you may refer a matter.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, row-level access controls on our database, restricted access to verification documents, private (non-public) storage for sensitive files, and server-authoritative checks on sensitive actions. No system is perfectly secure, but we work to protect your data and to notify you and the regulator of a breach where the law requires.
10. Cookies & analytics
The mobile App uses no advertising cookies. Product analytics and crash reporting are off until you opt in, and can be turned off again in Settings. Our website uses only essential cookies plus, with your consent, analytics; you control this through the cookie banner. For details, see our Cookie Policy.
11. Children
Extrais is for adults. It is not directed to anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.
12. Complaints & supervisory authorities
You can always contact us first at info@vitamedas.com. You also have the right to lodge a complaint with a supervisory authority in your region:
- Luxembourg (launch market): Commission nationale pour la protection des données (CNPD).
- EU/EEA: the data-protection authority of your member state of residence (for example, the Belgian Autorité de protection des données / Gegevensbeschermingsautoriteit).
- United Kingdom: Information Commissioner's Office (ICO).
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC).
- Türkiye: Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK Kurumu).
- Canada: Office of the Privacy Commissioner of Canada (OPC); in Québec, the Commission d'accès à l'information du Québec (CAI).
- United States: your state Attorney General (for example, the California Attorney General) where your state law provides for it.
13. Changes
We may update this policy. We will post the new version with an updated date and, for material changes, ask you to re-acknowledge it in the App.
14. Contact
TABA Tasarım İnşaat A.Ş. — info@vitamedas.com
