PRIVACY AND SECURITY POLICY
Bandırma Sportif Faaliyetler İnşaat ve Ticaret Anonim Şirketi (the “Company”) provides membership, booking, fitness, wellness, store, notification, and club access services through the InBordo mobile application (the “Application”), its website, and related digital services.
This Privacy and Security Policy has been prepared to explain what personal data may be collected, accessed, processed, stored, shared, and protected within the scope of the Application.
The Company processes personal data in accordance with applicable legislation, primarily the Turkish Personal Data Protection Law No. 6698 (“KVKK”).
1. Personal, Account, and Contact Data
The Application may process the following data for the purposes of creating and managing user accounts, administering memberships, providing services, and communicating with users:
- Full name
- Email address
- Telephone number
- Account ID
- Member ID
- Profile information
- Profile photo
- Branch information
- Membership status, membership history, and membership entitlements
- Membership package information
- Membership application records and application status information
- Address information
- Billing address
- Shipping address
- Other contact information provided by the user
This data is processed for account management, user authentication, membership services, customer support, order and delivery management, and communication with users.
2. Authentication, Security, and Technical Data
The Application may process the following data for security purposes and to ensure uninterrupted service delivery:
- Login and authentication records
- OTP verification data
- Account verification information
- Session tokens
- Security logs
- Device verification information
- Registered device history
- Device removal or revocation records
- Account recovery records
- Device model and manufacturer information
- Operating system information
- Application version and build information
- Technical identifiers generated by the Application
- Connection logs
- Error reports
- Diagnostic and performance data
The Application may also locally store the following information on the user’s device:
- Secure session information
- Authentication status
- Onboarding status
- Reminder preferences
- Search history
- User interface preferences
- Locally stored guest checkout information
- Local notification history
- Health synchronization status
- Health synchronization metadata
- Cached records
This data is used to protect account security, prevent unauthorized access, resolve technical issues, ensure service continuity, and improve user experience.
3. Health and Wellness Data
If the user connects Health Connect, Apple Health, or another supported health platform and grants the required permissions, the Application may access, display, process, and synchronize, where necessary, the following health and wellness data:
- Step count
- Heart rate
- Resting heart rate
- Active calorie data
- Basal calorie data
- Total calories burned
- Distance data
- Sleep data
- Exercise and workout data
- Height information
- Weight information
- Blood oxygen information
- Blood pressure information
The Application may also process the following health profile and synchronization data:
- Age information
- User-entered height and weight information
- Health connection status
- Health synchronization metadata
- Health history synchronization status records
This data is processed solely for providing fitness and wellness services, generating health dashboards and summaries, displaying current and historical health trends, supporting training activities, and enabling wellness-related features within the Application. Health data is not used for medical diagnosis, treatment, clinical assessment, emergency services, insurance activities, or scientific research. Health data is not sold or shared with third parties for advertising, marketing, or user profiling purposes. Health data and synchronized health summaries are retained only for as long as necessary to provide the relevant services or as required under applicable laws. Where necessary for the provision of services, health data may be processed solely by service providers acting as data processors on behalf of the Company. Users may revoke health-related permissions at any time through their device settings or the relevant health platform.
4. Booking, Training, Membership, and Contract Data
The Application may process the following service-related data:
- Class bookings
- Personal Training (PT) bookings
- Session date and time information
- Attendance records
- Cancellation records
- Booking history
- Reminder records
- Training plans
- Exercise logs
- Performance tracking data
- Training progress records
- Membership credits and usage history
- Contract records
- Contract approval records
- Contract decision status information
- User consent records
- Privacy consent records
- Health data processing consent records
- Marketing preferences
This data is processed for managing bookings, administering memberships, fulfilling contractual obligations, and planning service operations.
5. Store, Order, and Payment Data
Where users utilize store services, the following data may be processed:
- Shopping cart contents
- Wishlist items
- Order records
- Order history
- Guest checkout profile information
- Billing information
- Shipping information
- Customer information
- Company information
- Tax office information
- Tax identification information
- Payment transaction status
- Payment session status
- Order payment status
- Transaction reference numbers
Payment card information is not directly stored by the Application and is processed by authorized payment service providers. This data is used for order creation, payment processing, delivery management, and customer support services.
6. Notification, Media, Calendar, and Access Data
The Application may process the following data:
- Push notification tokens
- Notification preferences
- Notification history
- Reminder and alert records
- Membership notifications
- Booking notifications
- PT notifications
- Order notifications
- Stock notifications
- Profile photographs
- Media content uploaded by users
- Photo and video usage consent records
- Calendar event records
- Membership QR codes
- QR verification requests
- Access verification statuses
- Club entry verification records
This data is processed for sending notifications, adding bookings to calendars, verifying memberships, and providing related services.
7. Third-Party Services and Permissions
The Application may utilize the following third-party services:
- Health Connect
- Apple Health
- Firebase Cloud Messaging (FCM)
- Payment providers and payment pages
- External web content
- External links
- Third-party authentication services
The Application may request the following permissions in order to provide its functionality:
- Health data permissions
- Physical activity permissions
- Sensor permissions
- Notification permissions
- Camera permissions
- Photo selection permissions
- Calendar permissions
- Location permissions where required by health integration flows.
Location data is not actively monitored, continuously tracked, or retained by the Application.
8. Purposes of Processing Personal Data
Personal data may be processed for the following purposes:
- Creating and managing user accounts
- Managing membership and contractual processes
- Providing booking and PT services
- Delivering fitness and wellness services
- Processing store and order transactions
- Performing user authentication
- Ensuring account and system security
- Sending notifications and reminders
- Providing customer support
- Maintaining operational records
- Complying with legal obligations
9. Data Retention, Sharing, and International Transfers
Personal data is retained only for as long as necessary for the purposes for which it is processed and in accordance with retention periods prescribed by applicable laws.
Personal data may be shared, where legally permissible, with:
- Service providers
- Technical infrastructure providers
- Payment service providers
- Business partners providing services on behalf of the Company
- Competent public authorities and governmental institutions
Personal data is not transferred to third parties for advertising, marketing, or data sale purposes.
Where technical infrastructure or cloud services are located outside the user’s country, personal data may be transferred internationally in accordance with applicable laws and appropriate security measures.
10. Data Security
The Company implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure, or unlawful processing.
11. User Rights and Contact Information
Subject to applicable laws, users have the right to:
- Access their personal data
- Request correction of their personal data
- Request deletion of their personal data
- Request restriction of processing
- Withdraw their consent
- Request information regarding data sharing and retention practices
Any questions, requests, or applications regarding the processing of personal data may be submitted through the Company’s official communication channels.
COMPANY NAME: Bandırma Sportif Faaliyetler İnşaat Ticaret ve Sanayi A.Ş.
E-MAIL: info@bordosportif.com
ADDRESS: Paşakent Mahallesi, Şehit Cem Güçlü Caddesi No:25, Bandırma, Balıkesir, Türkiye
TELEPHONE: +90 266 713 55 55



