Privacy Policy

Last updated: to be set upon publication

Kiipup — operated by wyzmo.ai L.L.C-FZ


1. Introduction

This Privacy Policy explains how wyzmo.ai L.L.C-FZ ("wyzmo.ai," "we," "us," or "our"), the company behind Kiipup, collects, uses, stores, shares, and protects personal data in connection with the Kiipup platform and related services (collectively, the "Service").

Entity details:

  • Legal name: wyzmo.ai L.L.C-FZ
  • Trade License: 2543059.01 | Formation No: 2543059
  • Registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
  • Manager: Cagatay Guler

Kiipup is a software-as-a-service ("SaaS") platform designed for instructors, coaches, tutors, and similar professionals ("Instructors" or "you") to manage their teaching practice, students, scheduling, and related activities.

This Policy applies to all users of the Service regardless of location. Where specific privacy legislation imposes additional obligations — including the Turkish Personal Data Protection Law No. 6698 ("KVKK"), the EU General Data Protection Regulation ("GDPR"), and the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL") — we address those requirements in the relevant sections below.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.


2. Our Two Roles: Data Controller and Data Processor

Kiipup operates in two distinct data-protection roles depending on whose personal data is being processed:

2.1 Kiipup as Data Controller

We are the data controller for the personal data of Instructors who create accounts on the platform. This includes registration information, billing details, usage data, and any other data you provide directly to us in connection with your own account and use of the Service.

2.2 Kiipup as Data Processor

When an Instructor uses Kiipup to manage information about their students, clients, or other individuals ("Client Data"), the Instructor is the data controller and Kiipup acts as the data processor. We process Client Data solely on the Instructor's instructions and in accordance with our Data Processing Agreement ("DPA"), which forms part of our contractual relationship with the Instructor.

Instructors are responsible for ensuring that they have a lawful basis to collect and process Client Data, for providing appropriate privacy notices to their students and clients, and for obtaining any necessary consents (including parental or guardian consent where the data subjects are minors).


3. Data We Collect as Controller

When you register for and use Kiipup as an Instructor, we may collect the following categories of personal data:

3.1 Identity and Account Data

  • Full name
  • Email address
  • Phone number (if provided)
  • Profile information (professional title, bio, profile photo)
  • Account credentials (passwords are stored in hashed form only)

3.2 Billing and Payment Data

  • Billing name and address
  • Payment method details (processed and stored by Stripe; we do not store full card numbers)
  • Transaction history and invoice records
  • Tax identification numbers (where applicable)

3.3 Usage Data

  • Log-in timestamps and session duration
  • Feature usage patterns and interactions within the platform
  • Device type, browser type, operating system, and IP address
  • Referral source and page-navigation paths

3.4 Cookie and Tracking Data

  • Essential cookies required for authentication and security (see our Cookie Policy for details)
  • Preference cookies for language and UI settings

3.5 AI Feature Metadata

  • When you use AI-powered features within Kiipup, the content you submit is sent to our AI sub-processor (Anthropic) for processing. We apply best-effort identifier redaction before transmission.
  • We may retain metadata related to AI feature usage (e.g., timestamps, feature type, token counts) for service improvement and troubleshooting.

3.6 Communications Data

  • Correspondence you send to us via email, in-app messaging, or support channels
  • Feedback and survey responses

4. Purposes of Processing and Legal Bases

We process your personal data for the purposes set out below. For each purpose, we identify the applicable legal basis under the KVKK, GDPR, and UAE PDPL.

Purpose KVKK Legal Basis (Art. 5) GDPR Legal Basis (Art. 6)
Account creation and management Necessary for the performance of a contract (Art. 5/2(c)) Performance of a contract (Art. 6(1)(b))
Providing and operating the Service Necessary for the performance of a contract (Art. 5/2(c)) Performance of a contract (Art. 6(1)(b))
Processing payments and invoicing Legal obligation (Art. 5/2(ç)); performance of a contract (Art. 5/2(c)) Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Customer support Legitimate interest of the controller (Art. 5/2(f)) Legitimate interests (Art. 6(1)(f))
Service improvement and analytics Legitimate interest of the controller (Art. 5/2(f)) Legitimate interests (Art. 6(1)(f))
AI feature processing Explicit consent (Art. 5/1) Consent (Art. 6(1)(a)) or legitimate interests (Art. 6(1)(f))
Security, fraud prevention, and abuse detection Legitimate interest of the controller (Art. 5/2(f)); legal obligation (Art. 5/2(ç)) Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
Tax, accounting, and regulatory compliance Legal obligation (Art. 5/2(ç)) Legal obligation (Art. 6(1)(c))
Marketing communications (when activated) Explicit consent (Art. 5/1) Consent (Art. 6(1)(a))

Under the UAE PDPL, the corresponding legal bases include consent, contractual necessity, legal obligations, and legitimate interests as recognized under the Decree-Law and its implementing regulations.


5. Service Providers and Sub-Processors

We engage the following third-party service providers ("sub-processors") to help us deliver the Service. Each provider processes data only to the extent necessary for its designated function and is bound by contractual data-protection obligations.

Provider Function Location
Supabase Database hosting, authentication, and backend infrastructure United States
Stripe Payment processing and billing United States
Anthropic AI content generation and processing United States
Vercel Application hosting and content delivery United States
Mailtrap Transactional and system email delivery United States
Sentry Error monitoring and application performance United States

We maintain contractual agreements with each sub-processor that include appropriate data-protection clauses. For Instructor Client Data, the sub-processor list and change-notification obligations are further detailed in our Data Processing Agreement.


6. International Data Transfers

wyzmo.ai L.L.C-FZ is established in the Dubai Free Zone, U.A.E. All of our sub-processors are located in the United States. This means that personal data of users — regardless of their location — is transferred to and processed in the United States.

6.1 Transfers from Turkey (KVKK)

For users located in Turkey, any transfer of personal data to countries that do not have an adequacy determination from the Turkish Personal Data Protection Board constitutes a cross-border transfer under the KVKK. We rely on the following safeguards:

  • Explicit consent of the data subject pursuant to KVKK Article 9, obtained at the time of account registration or prior to the relevant processing activity; and
  • Standard contractual clauses and equivalent contractual safeguards with our sub-processors, where available.

6.2 Transfers from the EU/EEA (GDPR)

For users located in the European Union or European Economic Area, we rely on:

  • Standard Contractual Clauses ("SCCs") adopted by the European Commission as the primary transfer mechanism under GDPR Chapter V; and
  • Supplementary measures where required by the circumstances of the transfer.

6.3 Transfers under UAE PDPL

We comply with the cross-border transfer requirements set out in the UAE PDPL and its implementing regulations, including ensuring that an adequate level of data protection is maintained and that appropriate contractual safeguards are in place.


7. Data Retention

7.1 General Retention Principle

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting obligations.

7.2 Specific Retention Periods

  • Account data: Retained for the duration of the active account and for a reasonable period thereafter to allow for reactivation, unless deletion is requested.
  • Billing and invoice records: Retained for a minimum of ten (10) years from the date of the relevant transaction, as required by applicable tax and commercial law.
  • Usage and log data: Retained for up to twenty-four (24) months for service improvement and security purposes.
  • Marketing consent records: Retained for as long as the consent remains valid, plus any period required to demonstrate compliance.

7.3 Deletion Process

When personal data is no longer required, we follow a soft-delete process: data is first marked as deleted and removed from active systems, then permanently purged through scheduled automated processes. Data subject deletion requests are processed within thirty (30) days of verification, subject to any legal retention obligations.

7.4 Client Data Retention

Client Data is retained on behalf of and at the instruction of the Instructor (as data controller). Upon termination of an Instructor's account, Client Data will be deleted or returned in accordance with the terms of our Data Processing Agreement.


8. Your Rights

Depending on your location and the applicable privacy law, you may have the following rights regarding your personal data. To exercise any of these rights, please contact us at privacy@kiipup.com. We will respond to your request within thirty (30) days.

8.1 Rights under KVKK (Article 11)

If you are located in Turkey or if the KVKK otherwise applies to the processing of your data, you have the right to:

  1. Learn whether your personal data is being processed.
  2. Request information about the processing if your data has been processed.
  3. Learn the purpose of the processing and whether your data is used in accordance with that purpose.
  4. Know the third parties to whom your personal data is transferred, domestically or abroad.
  5. Request rectification of incomplete or inaccurate data.
  6. Request erasure or destruction of your personal data under the conditions set out in Article 7 of the KVKK.
  7. Request notification of rectification or erasure actions to third parties to whom your data has been transferred.
  8. Object to any result that is to your detriment arising from the analysis of your processed data exclusively through automated systems.
  9. Claim compensation for damages arising from the unlawful processing of your personal data.

If your request is not resolved satisfactorily, you may file a complaint with the Turkish Personal Data Protection Board (Kisisel Verileri Koruma Kurulu).

8.2 Rights under GDPR

If you are located in the EU/EEA or if the GDPR otherwise applies, you have the right to:

  • Access your personal data
  • Rectification of inaccurate or incomplete data
  • Erasure ("right to be forgotten")
  • Restriction of processing
  • Data portability (receive your data in a structured, commonly used, machine-readable format)
  • Object to processing based on legitimate interests or direct marketing
  • Withdraw consent at any time (without affecting the lawfulness of prior processing)
  • Lodge a complaint with a supervisory authority

8.3 Rights under UAE PDPL

If the UAE PDPL applies to the processing of your personal data, you have rights including:

  • Access to your personal data
  • Rectification of inaccurate data
  • Erasure or restriction of processing
  • Cessation of automated decision-making in certain circumstances
  • Data portability
  • Lodging a complaint with the UAE Data Office

8.4 How to Exercise Your Rights

Please direct all data-protection requests to:

Email: privacy@kiipup.com

Include your full name, the email address associated with your Kiipup account, and a description of your request. We may need to verify your identity before processing your request.


9. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
  • Encryption at rest: Sensitive data is encrypted at rest within our database infrastructure.
  • Row-Level Security (RLS): Our database architecture enforces tenant isolation through row-level security policies, ensuring that each Instructor's data is logically separated and accessible only to authorized users.
  • Least-privilege access: Internal access to personal data is restricted on a need-to-know basis, with role-based access controls applied across all systems.
  • Audit logging: Access to sensitive data and critical system operations are logged for security monitoring and incident investigation.
  • Regular review: We periodically review and update our security practices in line with industry standards and evolving threats.

No system can guarantee absolute security. If you believe your account has been compromised, please contact us immediately at hello@kiipup.com.


10. Children's Data

10.1 Account Registration

Kiipup accounts are available only to individuals who are at least eighteen (18) years of age. We do not knowingly collect personal data from children for the purpose of account registration. If we become aware that an account has been created by a person under 18, we will take steps to terminate the account and delete the associated data.

10.2 Client Data Involving Minors

Instructors who use Kiipup to manage data about students or clients who are minors bear full responsibility as data controllers for ensuring that:

  • They have obtained valid parental or guardian consent where required by applicable law.
  • They have provided appropriate privacy notices to parents or guardians.
  • They process the minor's data in accordance with applicable child-protection requirements.

Kiipup, as data processor, processes such data solely on the Instructor's documented instructions.


11. Cookies

We use cookies and similar technologies on the Service. For detailed information about the types of cookies we use, their purposes, and how to manage your cookie preferences, please refer to our Cookie Policy, available at the same location as this Privacy Policy.

In summary, Kiipup currently uses only essential cookies required for authentication, security, and core functionality. Should we introduce analytics or non-essential cookies in the future, we will update our Cookie Policy and implement appropriate consent mechanisms.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.

  • Material changes will be communicated to you through a prominent notice on the Service (such as a banner or in-app notification) and/or by email to the address associated with your account, at least fourteen (14) days before the changes take effect.
  • Non-material changes (e.g., formatting, clarifications that do not alter the substance of the Policy) may be made without prior notice and will be indicated by an updated version number and effective date.

We encourage you to review this Privacy Policy periodically.


13. Contact Information and Data Controller Details

13.1 Data Controller

wyzmo.ai L.L.C-FZ Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. Trade License: 2543059.01 | Formation No: 2543059 Manager: Cagatay Guler

13.2 Contact

13.3 VERBiS Representative in Turkey

In accordance with the KVKK requirement for data controllers established outside of Turkey to appoint a representative, we are in the process of designating a VERBiS representative in Turkey. Once appointed, the representative's details will be published here and registered with the Data Controllers' Registry (VERBiS).

VERBiS Representative: To be appointed. This section will be updated with the representative's name, address, and contact information upon appointment.


This Privacy Policy is governed by and construed in accordance with the laws of the United Arab Emirates, without prejudice to the mandatory consumer-protection and data-protection rights afforded to you under the laws of your country of residence.

Privacy Policy | Kiipup