Manage Your KVKK and GDPR Compliance on a Single Platform
Data inventory, consent management, Data Controllers Registry Information System (VERBİS) notification, privacy notices and data subject rights. Manage all your personal data protection obligations — from Türkiye to the EU — with AI support.
Trusted by leading companies
The GDPR Compliance Challenge
Without proper compliance management, organizations face significant regulatory risks
The data inventory lives in Excel and is out of date — the VERBİS notification no longer reflects reality
Privacy notices are outdated, each channel has a different version, and no one knows which is current
Consent records are scattered or nonexistent — there is no evidence to present during an audit
Data subject requests arrive by email and the 30-day statutory deadline cannot be tracked
Data Processing Agreements (DPA) are missing or not KVKK/GDPR compliant
There is no breach procedure — the 72-hour notification obligation cannot be met
KVKK and GDPR require separate management, and the two processes cannot run in parallel
Powerful Features
Everything you need for complete cookie compliance
Personal Data Inventory & VERBİS / RoPA
The data inventory — a core requirement of both KVKK and GDPR — is kept central and current in JUS. Changes to your data are reflected in reports instantly.
- Categorize every personal data processing activity: purpose, legal basis, retention period and recipient categories
- Reports in the VERBİS notification format are generated automatically — the report is ready as soon as data is entered
- The GDPR RoPA is produced automatically from the same inventory
- Data flow maps: visually track where data comes from and where it goes
- VERBİS/RoPA update automatically whenever the inventory changes
Consent Management
Central management and provable recording of consents collected across all digital and physical channels.
- Every consent record is stored with date, time, IP, device, consent text version and a unique reference number
- Consent withdrawal processes are managed automatically — relevant systems are notified
- Granular consent: separate approval/rejection tracking for each processing purpose
- Audit trails are immutable — legally valid evidence
Privacy Notice Management
A separate privacy notice for each channel and processing activity. Dynamic publishing with version management and web frame integration.
- Notices tailored to different channels: website, mobile app, physical form and email
- Dynamic version management: which notice was shown to which user is recorded automatically
- Notice update alerts when regulations change
- Web frame integration: can be embedded directly into sites via link or iframe
- Translation support in 25+ languages
Data Subject Access Request (DSAR) Management
Central, deadline-driven management of access, rectification, erasure, data portability and objection requests.
- Request portal: data subjects submit requests directly, with identity verification included
- The 30-day statutory deadline is tracked automatically, with reminders sent as it approaches
- Template responses and approval workflows — fast, consistent replies
- Full audit trail: the entire process from request to response is logged
Data Breach Management
A structured process to meet the 72-hour notification obligation. Every step from breach detection to closure is traceable.
- Breach record form: detection date, affected data categories, likely consequences and measures taken
- Automatic countdown and reminders for the 72-hour Board/DPA notification window
- Whether affected individuals must be notified is determined through a risk assessment
- Template notification texts: separate formats for the KVKK Board and GDPR supervisory authorities
- Breach closure and corrective action tracking
Data Processor & Vendor Management
Management of every third party you share personal data with. DPA agreements, risk assessments and continuous monitoring.
- Data processor inventory: which data is transferred to which vendor and for what purpose
- KVKK-compliant DPA templates — including GDPR SCC templates
- Vendor risk scoring: security, compliance and contract criteria
- Contract renewal tracking: automatic alerts as the deadline approaches
VED / DPIA — Data Protection Impact Assessment
Manage the Data Protection Impact Assessment process — mandatory for high-risk data processing — with a structured workflow.
- Risk threshold test: automatically assesses whether a processing activity requires a VED/DPIA
- Step-by-step VED/DPIA workflow: risk identification, assessment and mitigation measures
- Risk scoring: a visual risk map using a likelihood × impact matrix
- DPO / legal department approval workflow
- Detection of when consultation with the supervisory authority is required
Compliance Dashboard & Reporting
- Real-time compliance score: separate, color-coded risk indicators for KVKK and GDPR
- Missing processes, expiring contracts and unanswered requests are surfaced
- An executive compliance summary — a single page, enough to act on
- Audit readiness mode: all records and evidence for a chosen period are exported as a package
Technical Specifications
Enterprise-grade infrastructure built for scale and security
Integration
Performance
Security
Frequently Asked Questions
Find answers to common questions about our cookie consent solution
Ready to Make Your Website Compliant?
Start with a 14-day free trial. No credit card required.