ENA Feedback
Settings

Privacy & Compliance

GDPR and KVKK compliance in Enafeedback — data retention, anonymisation, PII handling, and deletion requests.

Last updated on

Enafeedback is designed for compliance with European GDPR and Turkish KVKK (Kişisel Verilerin Korunması Kanunu) data protection regulations.

Legal documents

Full legal texts are published on EnaSpace: Privacy Policy, KVKK Notice, Cookie Policy, Security, and Terms of Service. Turkish versions use /tr/legal/* on the same domain.

Data categories collected

CategorySourceContains PII?
Survey responsesVisitorsOnly if a question explicitly asks for name/email/phone
Hygiene assessmentsVisitorsNo
Feedback ticketsVisitorsOnly if the contact field is filled
Cleaning logsStaff (via personnel code)Staff name linked to code
Visitor analytics eventsServer-sideNo — no IP, no fingerprint
Audit logAdmin actionsAdmin email and IP address

Enafeedback does not use cookies for visitor-facing forms. The visitor analytics event tracking is server-side and does not require a consent banner.

For survey or feedback forms that collect identifiable information (email, phone, name), you are responsible for displaying the appropriate privacy notice to visitors. Enafeedback provides a configurable privacy link that can be shown in the form footer.

Data retention policy

Configure your workspace retention policy in Global Settings → Privacy:

PeriodDescription
Default24 months
Minimum6 months
Maximum60 months

After the retention period expires, feedback content is anonymised:

  • Text responses: replaced with [ANONYMISED]
  • Contact fields: replaced with [REDACTED]
  • Aggregate scores: preserved for analytics

Anonymisation is irreversible.

Manual anonymisation

To anonymise a specific ticket immediately (e.g., in response to a KVKK Article 7 deletion request):

  1. Open the ticket or submission.
  2. Click Anonymise (requires platform:owner role).
  3. Confirm.

The content is immediately replaced. The audit log records that anonymisation occurred but not the original content.

Data cleaning

Global Settings → Data Cleaning lets you run bulk anonymisation of data older than a specified date across all modules. This is useful for periodic compliance cleanup.

  1. Select the cutoff date.
  2. Preview the count of records that will be affected.
  3. Click Run cleaning.

Cleaning runs in the background. You receive an email summary when complete.

Data export (subject access request)

To fulfill a data subject access request (KVKK Article 11 / GDPR Article 15), you can export all data linked to a specific contact (email or phone number):

  1. Navigate to Privacy → Data export.
  2. Enter the contact identifier.
  3. The system searches all submissions for matching contact fields.
  4. Download the export as JSON or PDF.

Sub-processors

Enafeedback uses the following sub-processors:

Sub-processorPurposeLocation
Google GeminiAI Insights, Transcription, TranslationEU / US
Configured SMS providerSMS notificationsVaries
Email providerTransactional emailEU

Data sent to Google Gemini is anonymised before transmission (PII replaced with tokens). See AI Insights for details.