SOE Hybrid Athletics
Türkçe

Privacy Policy

Applies to the SOE Hybrid Athletics mobile app and its membership services · FitApp

This privacy policy explains how your personal data is processed within the membership services of SOE Hybrid Athletics and the SOE Hybrid Athletics mobile application used to access those services. The app is published by FitApp and the underlying software platform is provided by FitApp. Under Turkish Personal Data Protection Law No. 6698 (KVKK), the data controller is SOE Hybrid Athletics, the facility where your membership is held; FitApp acts solely as a data processor, on the instructions of the facility and for the purposes described in this policy. FitApp does not use member data for its own commercial purposes, does not combine it across facilities, never sells it, and never transfers it to third parties for advertising.

The data processed in order to deliver the service is as follows: identity data (first name, surname, date of birth, gender and, where issuing an invoice legally requires it, national identity number); contact data (phone number, e-mail address, postal address, province and district); membership and transaction data (the package purchased, payment method, order and invoice records, appointments, group class bookings, remaining class and session entitlements); facility entry records (the date, time and branch of each turnstile pass); an optional profile photograph; and technical data (push notification address, device identifier, IP address and sign-in records). The legal grounds for processing are the conclusion and performance of the membership contract, the legitimate interest in maintaining the security of the facility, and legal obligations arising from tax and commercial legislation.

Height, weight, body measurements, body mass index, health declarations and the nutrition and training programmes prepared specifically for you constitute special categories of personal data under Article 6 of the Law. Such data is processed only where you have given explicit consent and only to deliver the service you requested; it is never used for marketing, profiling or any purpose beyond your own care. You may withdraw your consent at any time, in which case the related records are deleted and measurement tracking and personalised programme services can no longer be provided. Within the facility, your health data is accessible only to the staff actually delivering the service (trainer, dietitian, physiotherapist) and to authorised management; access is limited by a role and permission matrix, and every critical operation is written to an immutable audit log so that it can be reviewed afterwards.

At no point do we see, record or store your card number, expiry date or security code. Card payments are completed on the 3D Secure page of the bank or payment institution; only the outcome of the transaction, its amount and any instalment information is returned to us. Invoice and accounting records are retained for the mandatory periods laid down by Turkish tax and commercial law and cannot be deleted before those periods expire.

Your personal data is shared, only to the extent the service requires and strictly for the relevant purpose, with the following parties: the SMS service provider used to deliver verification and information messages, Google Firebase Cloud Messaging for app notifications, the mail server used for e-mail delivery, the e-invoicing integrator used to issue electronic invoices, the bank payment infrastructure used for card payments, and competent public authorities where disclosure is required by law. If you choose to use the AI-assisted nutrition or training suggestion feature, the minimum information required for that feature to work (such as your goal and general body measurements) is transmitted to an artificial intelligence service provider located abroad. Because the notification and AI services run on servers outside Türkiye, these transfers rely on your explicit consent and appropriate safeguards under Article 9 of the Law; you may choose not to use those features, and the remainder of your membership services will be unaffected.

Commercial electronic messages containing campaigns, discounts or announcements are sent only to members who have given consent; if no consent has been given, no campaign message is sent. You may withdraw your consent at any time through the app or by contacting the facility. Service messages such as appointment reminders, booking confirmations, membership expiry warnings and payment notifications are not commercial messages and will continue to be sent for as long as your membership is active.

Your data is retained for the duration of your membership and, after it ends, for the limitation and retention periods prescribed by the applicable legislation; once those periods expire it is deleted, destroyed or anonymised. Passwords are stored in an irreversible form (using the argon2id algorithm) and cannot be seen by any member of staff. Third-party service credentials held in the system are stored encrypted, all traffic between the app and the server is protected with TLS, and layered authorisation is applied against unauthorised access.

Under Article 11 of the Law you have the right to learn whether your personal data is being processed, to request information where it has been, to learn the purpose of processing and whether it is used in accordance with that purpose, to know the third parties to whom the data is transferred in Türkiye or abroad, to request the correction of incomplete or inaccurate data, to request its erasure or destruction, to request that such actions be notified to the third parties to whom the data was transferred, to object to a result to your detriment arising from analysis carried out solely by automated systems, and to claim compensation if you suffer damage due to unlawful processing. You may submit your requests using the contact details at the foot of this page; your request will be concluded within thirty days at the latest.

You may request the deletion of your account and personal data at https://soe-hybrid.fitapp.com.tr/hesap-silme without needing to sign in to the app. Your request is delivered to the facility management panel; once your identity is verified, your access to the app is closed and the record is deleted, rendering your identifying details unreadable. After deletion, only the invoice and accounting records required by law continue to be retained, in a form that cannot be linked to your identity.

Our services are not designed for persons under the age of eighteen; members under eighteen may only be registered with the knowledge and approval of a parent or legal guardian. Records found to have been created without such approval are deleted. The app is distributed through the Apple App Store and Google Play; any data collected by the store from which you downloaded the app is subject to that store’s own privacy policy and falls outside the scope of this document.

This policy may be revised from time to time in response to changes in legislation or updates to our services. The current text is always published at this address and takes effect upon publication; where a material change is made, members are additionally informed through the app.

Last updated: 20 August 2026