Privacy Policy

Sivas Cumhuriyet University — CU Mobile and CU Alumni mobile apps
Effective date: 22 September 2026

Türkçe sürüm

This policy explains how the CU Mobile (edu.cumhuriyet.app) and CU Alumni (edu.cumhuriyet.graduate) mobile apps published by Sivas Cumhuriyet University, and the university server they connect to (cumobile.cumhuriyet.edu.tr), process personal data. The data controller is Sivas Cumhuriyet University. If the two versions differ, the Turkish version prevails.

1. Data the apps send to the university server

DataPurpose
CU Mobile sign-in: username (student number, staff registry number, national ID number or institutional e-mail) and password Authentication. The password is sent only with the sign-in request and is passed to the university's identity system for verification; it is stored neither on the phone nor on the server.
CU Alumni sign-in: national ID number and date of birth; with ID card sign-in, the card's chip data (see section 3) Authentication. No password is requested.
Device information: a device identifier generated by the app, platform, device model, operating system and app version, whether notifications are allowed, notification token (FCM) Binding the session to the device, sending notifications, fixing device- or version-specific problems
The moment a notification reaches your phone and is opened Measuring whether notifications are delivered
Your survey answers Taking part in the survey. Who gave the answer is stored encrypted, so the same survey cannot be answered twice.
Your requests, suggestions and complaints: the unit you choose, the request type and your message, together with your name Forwarding the message to the relevant unit and answering it
With every request: IP address, time and the operation performed Security, abuse prevention, error diagnosis

2. Other processing on the server and retention

3. Signing in with a Turkish ID card (CU Alumni)

ID card sign-in is optional. The machine-readable zone on the back of the card is decoded with the camera on your phone, offline; it is used only to open a secure channel with the card's chip. The card image and the text of this zone never leave your phone and are not stored.

Only the identity data group (DG1: national ID number, name, surname, date of birth, sex, nationality, document number and expiry date) and the security data that prove the card is genuine (SOD and DG15) are read from the chip; the card also signs a one-time value sent by the server. Your photograph (DG2) and other personal details (DG11) are not read.

This data is sent to the university server to verify that the card is a genuine, unaltered Turkish ID card. The server checks the signatures and completes the sign-in with your national ID number and date of birth; it does not store the chip data or the signature.

4. Data that stays on your phone

5. Third parties

Google Firebase (both apps)

Cloud Messaging (notification delivery), Crashlytics (crash reports), Analytics (usage analytics), Performance Monitoring, Remote Config (remote settings), App Check (verifying the app is genuine) and In-App Messaging. Data sent to Firebase:

Google acts as a processor on behalf of the university for the Firebase services.

Google ML Kit (CU Alumni only)

The text recognition component that reads the card's machine-readable zone runs on the phone; camera images are not sent to Google. When the component is used, usage information such as device and app information, a per-installation identifier and performance metrics goes to Google, which uses it to diagnose and improve ML Kit.

Talsec freeRASP (CU Mobile only)

A component that checks the security of the phone and the app: root access or jailbreak, debuggers, tampering and whether the app is a modified copy. It sends the check results, the security state of the app and device, and anonymous app and device identifiers to Talsec; Talsec may derive an approximate location (country, region, city) and the network operator from the IP address of this request. Your name, number and the information in the app are not sent to Talsec. Talsec uses this data for security reporting, abuse detection and improving its own product.

Under the Firebase, ML Kit and Talsec services, this data may be processed on servers outside Türkiye. The apps show no advertising and do not collect the advertising id; data is not used for advertising and is not sold. University web pages opened inside the app (such as the OBS portal) connect directly to the university system concerned.

6. Security

7. Permissions

Location, microphone, contacts, calendar, photos and file access are never requested.

8. Your rights

The apps do not create a separate account; you sign in with your existing university record. At any time, from inside the app, you can:

To exercise your rights under Article 11 of the Turkish Personal Data Protection Law No. 6698 (KVKK), such as learning whether your data is processed or asking for it to be corrected or deleted, use the application form on the university's Personal Data Protection page or write to bidb@cumhuriyet.edu.tr. The university's data protection policy and its Retention and Destruction Policy are also published on that page.

The deletion steps and how to request deletion are described in detail on the Account and Data Deletion page.

9. Children's data

The apps are intended for university students, staff and alumni. They are not directed at children and do not knowingly collect data from children.

10. Changes

When this policy is updated, the new version is published on this page and the effective date is revised.

11. Contact

Sivas Cumhuriyet University — Department of Information Technologies
Daire Başkanlıkları Binası A Blok, 58050 Yenişehir / Sivas, Türkiye
bidb@cumhuriyet.edu.tr