Google Analytics and cookie preferences
The Google Analytics 4 tag (Google; G-13R1XE9ZTL) loads by default when a web page opens. Before an analytics cookie choice, or when declined, analytics_storage=denied permits cookieless measurement signals; this does not mean that no data is sent to Google. Google may process page URLs/titles, referrers, device/browser information and the connection IP address. The connection may involve processing abroad. Account identifiers, portfolio amounts and calculator inputs are not sent as custom analytics parameters. Advertising storage, advertising user data, ad personalization and Google Signals are disabled.
Cookie Preferences shows necessary cookies as always active. The analytics cookie switch in Settings and Accept All allow _ga and _ga_* cookies for at most 180 days; Reject or switching off clears accessible GA cookies while cookieless measurement continues. GPC/DNT disables measurement; the tag file may still load. metrilume:analytics-consent:v1 stores only the choice and timestamp; the choice is requested again after 180 days. If saving fails, analytics cookies stay off in this tab. Earlier accept/decline records are preserved as cookie choices. Cookie Preferences in the footer reopens the panel. Previously received Google data is not retroactively erased; report retention is managed in Google property settings. Native applications and standalone Lume Embed iframes do not load this web tag. External chart providers’ storage controls are subject to their policies and browser settings.
1. Controller and scope
The data controller is AxelVira Teknoloji A.Ş. This notice is addressed to data subjects under Turkish Personal Data Protection Law No. 6698 and, where the GDPR applies because goods or services are offered to people in the EU/EEA or their behavior is monitored, also to those individuals under the GDPR.
Where AxelVira processes data on behalf of a business customer solely on documented instructions, the relevant customer notice and Data Processing Agreement apply instead of the controller provisions of this notice.
2. Core principles
- Compliance with law and good-faith principles; lawfulness, fairness, and transparency under the GDPR.
- Accuracy and, where necessary, keeping data up to date.
- Processing for specified, explicit, and legitimate purposes.
- Using data that is relevant, limited, and proportionate to the purpose.
- Not retaining data longer than necessary for the purpose and applicable law.
- Appropriate security, confidentiality, and accountability.
3. Data subjects and data categories
| Data subject | Data categories |
|---|---|
| Account-free visitor and application user | Network/request security data; language preference; on-device portfolio and saved comparisons; queried fund codes; fund codes and period carried in a sharing URL/query; Lume Scenario name, amounts, rates, duration, and methodology; Lume Journal title, thesis/decision, expectation/assumption, risk/signal, planned review time, review notes/outcome/time, open-reviewed-archived status, record identifiers, and created/decided/updated/store-saved timestamps, together with schema fields for tags and portfolio/scenario references for which the current interface provides no input control; Lume Learn lesson identifier, progress, score, and timestamps; IP/protocol headers, referring origin if sent by the browser, and visible URL configuration in a Lume Embed technical request; mobile installation UUID; and limited first-party product telemetry without a persistent identifier, including daily US research counters by public SEC CIK/ticker, module, filing family, chart symbol and search buckets |
| Account holder (if the feature is enabled) | User identifier, provider identity, encrypted/masked contact information, session and verification records, passkey public key and counter, and cloud portfolio |
| Subscriber or customer (if the feature is enabled) | Plan and price version, order, subscription, invoice, payment-provider reference, cancellation/refund record; excluding card number or CVV |
| Support or rights requester | Identity and contact details, request content, verification information, correspondence, and outcome record |
| Business customer/supplier representative | Business contact information, role/authority, contract, and security and audit communications |
4. Purposes and legal grounds
| Purpose | KVKK legal ground | GDPR legal basis |
|---|---|---|
| Providing the current public website/application tools, Lume Embed iframe, and requested price queries | Legitimate interests of the controller, provided the data subject’s fundamental rights and freedoms are not harmed | Legitimate interests in providing the expressly requested public service (Art. 6(1)(f)) |
| Creating, storing, displaying, and deleting the Lume Scenario, Lume Journal, and Lume Learn records selected by the user only in that user’s browser | Legitimate interests of the controller, provided the data subject’s fundamental rights and freedoms are not harmed | Legitimate interests in operating the expressly requested on-device function without transferring its content to a server (Art. 6(1)(f)) |
| Remembering locale and on-device interface preferences | Legitimate interests of the controller, provided the data subject’s fundamental rights and freedoms are not harmed | Legitimate interests in maintaining the user-selected interface preference (Art. 6(1)(f)) |
| Measuring service quality and research interest through daily aggregate counters without persistent identifiers or cookies, subject to GPC/DNT signals, and publishing thresholded research summaries | Legitimate interests of the controller, provided the data subject’s fundamental rights and freedoms are not harmed | Legitimate interests in measuring and improving service quality (Art. 6(1)(f)) |
| Information security, fraud prevention, auditing, and incident response | Compliance with the controller’s legal obligations, including the safeguards required by KVKK Art. 12 | Compliance with legal obligations concerning the security of processing (Art. 6(1)(c)) |
| Account, authentication, session, and cloud portfolio, only if enabled | Establishment or performance of a contract | Performance of a contract (Art. 6(1)(b)) |
| Orders, subscriptions, payment verification, cancellation, and refunds, only if enabled | Establishment or performance of a contract | Performance of a contract (Art. 6(1)(b)) |
| Maintaining mandatory invoice, tax, accounting, commercial, and consumer-contract records, only if the relevant transaction exists | Compliance with the controller’s legal obligations | Compliance with a legal obligation (Art. 6(1)(c)) |
| Providing customer support for the requested service or an existing contract | Establishment or performance of a contract | Performance of a contract (Art. 6(1)(b)) |
| Receiving, verifying, and responding to data-subject rights requests | Compliance with the controller’s legal obligations | Compliance with a legal obligation (Art. 6(1)(c)) |
| Managing disputes and establishing, exercising, or protecting legal rights | Processing is necessary for the establishment, exercise, or protection of a right | Legitimate interests in establishing, exercising, or defending legal claims (Art. 6(1)(f)); GDPR Art. 9(2)(f) applies only if special-category data is necessarily involved |
| Non-essential cookies, personalization, or electronic marketing, only if introduced | Explicit consent and the conditions of applicable electronic-communications law | Consent (Art. 6(1)(a)) and applicable electronic-communications rules |
Each row applies only where the stated activity exists. When we rely on legitimate interests, we document the purpose and necessity, balance them against your rights and reasonable expectations, and choose a less intrusive method where one is available. Consent is requested only for processing that can be freely chosen, and it is specific and informed; refusing or withdrawing consent does not affect the necessary service.
5. Collection methods and environment
My watchlist and saved research views are held only on this device under metrilume:research-workspace:device:v1, using localStorage on the web and AsyncStorage in the mobile application. The store contains market type, fund code or US ticker, instrument name and time added, together with view identifiers, the view name you provide, supported research selections such as filters/search query, sorting and period, saved timestamps and the store version. Technical limits are up to 200 instrument references, 20 saved views and 256 KiB in total. Instrument references are not price histories or portfolio balances. These records have no MetriLume account or server synchronization, server backup or support recovery. Opening a saved view passes its supported filters and search query into the relevant page’s URL/query parameters and to the MetriLume API to retrieve results; on the web, the URL query string may reach the browser, network/edge layer and server. The view name you provide is not added to these queries and stays on the device. Records remain until you remove the relevant instrument/view in the product or clear browser site data or application storage. Losing or changing a device, changing browsers, uninstalling or reinstalling the application may cause record loss. Deleting an account does not automatically clear these local records.
Data is collected electronically by automatic, partly automatic, or manual means through web and mobile interfaces, necessary cookies and device storage, API/network security, a Lume Embed iframe request, support correspondence, enabled identity/payment-provider responses, and contracting processes. Lume Scenario, Lume Journal, and Lume Learn records are written to localStorage in the user’s browser and are not synchronized with a MetriLume server or account. Unsaved inputs in general calculators, initial-public-offering and dividend tools, and Embed financial widgets are processed only in the memory of the open page/iframe; they are not sent to MetriLume, the website publishing the Embed, or analytics. A US company-name/symbol search reaches the MetriLume API, and SEC EDGAR data is fetched server-side. The TradingView chart or stock screener loads automatically from the provider domain when the web or mobile US Markets Charts module or BIST equities page opens. US research events use module, public SEC CIK/ticker, filing family, chart symbol and search buckets in daily counters retained for 90 days. Raw events, search text, IP address, user agent, referrer, client timestamps and persistent visitor/session identifiers are not retained. GPC/DNT signals suppress this measurement; aggregate research trends may be published after sufficient activity thresholds are met. When an Embed loads, the ordinary HTTP request may process the IP address and protocol headers at the network/edge layer, the referring origin if sent by the browser, and visible title/locale/appearance configuration in the URL. If a rights request is submitted by post, physical documents may also be processed.
6. Recipients and transfer purposes
| Recipient category | Transfer purpose and limit |
|---|---|
| Network and security provider | Technical request data needed to route direct-page and Lume Embed traffic, prevent attacks, and provide edge security, including IP/protocol headers, request path, and referring origin if sent by the browser; financial widget inputs are not included in this transfer |
| SEC EDGAR and TradingView displays in the US Markets Charts module and BIST equities page | The server makes a general symbol-catalog request to the SEC and, when research is selected, a company/financial-statement request using only the CIK; the user’s search text is not sent to the SEC. TradingView may automatically receive a technical request, symbol, market and widget configuration from the browser or in-app WebView when the web or mobile US Markets Charts module or BIST equities page opens; that flow is governed by the provider’s own policy |
| Email transport and mailbox infrastructure | Contact and message data needed to deliver a support or rights-request email to the AxelVira mailbox and transmit the response |
| Identity, OTP, and payment provider (only if enabled) | Minimum data needed to verify the sign-in selected by the user, deliver a verification message, or collect and verify an order |
| Authorized adviser and auditor | Data necessary for legal rights, financial records, security, or independent audit and restricted by confidentiality |
| Authorized public authority and judicial body | Compliance with a statutory notification or a duly issued binding request |
Where a party acts as a processor, its contract must address acting only on instructions, confidentiality, security, deletion/return, and subprocessor controls. This public text does not represent that every current supplier contract has been verified. Independent controllers are responsible for their own purposes and legal obligations.
7. International transfers
The current global network/security flow, a TradingView chart or stock screener loaded automatically when the US Markets Charts module or BIST equities page opens, or an international identity feature selected by a user in the future may create access from abroad. The exact contracting party, access countries, and transfer mechanism for the current Cloudflare flow are not treated as verified by this page; every new flow must undergo data mapping and a transfer assessment before release.
- Under KVKK Art. 9, in addition to a processing condition: an adequacy decision; if none, a standard contract, binding corporate rules, an undertaking approved by the Board, or another appropriate safeguard; a statutory derogation only in limited circumstances.
- Under GDPR Chapter V: an adequacy decision; if none, standard contractual clauses and, where necessary, a transfer impact assessment and supplementary encryption/access measures; a derogation only where its conditions are met.
- Statutory notification and record-keeping processes for KVKK standard contracts that must be notified to the Board.
You may request information about a particular recipient, country, and safeguard by contacting [email protected]. Verified information is provided while protecting trade secrets and the security of others; an unverified contracting party or transfer instrument is not presented as if it existed.
8. Retention criteria
Retention periods follow the purpose- and event-based schedule in the data inventory. Criteria include the account/membership lifetime, security window, statutory financial-record period, request and claim limitation periods, regulatory review, and backup cycle. Lume Scenario, Lume Journal, and Lume Learn records remain only on the device until you delete the relevant record or clear metrilume.com localStorage/site data; the device store accepts up to 12 Lume Scenario scenarios and up to 250 Lume Journal decision entries. There is no server-retention period, support access, or recovery copy for these records. Browser clearing, a device/browser change, or reinstallation may cause loss, and deleting an account does not automatically clear browser localStorage. When the purpose ends, data processed on a server is deleted, destroyed, or irreversibly anonymized; records subject to mandatory retention are separated from active use.
Where a deletion request does not result in immediate physical deletion because of a legal record-keeping duty, the data is retained with restricted access solely for the mandatory purpose. It enters the periodic destruction process when the retention ground ends.
Exact retention periods for current edge/origin security records, limited product events, and email infrastructure must be established from the data inventory and supplier contracts examined during operator fact verification. An unverified period is not presented as final on this page; no new persistent account, payment, or cloud-portfolio flow is enabled until the relevant retention and destruction control is in place.
9. Your rights under the KVKK
Under KVKK Art. 11, you may apply to the controller to:
- Learn whether your personal data is processed and, if so, request information about the processing.
- Learn the purpose of processing and whether the data is used consistently with that purpose.
- Know the third parties to whom it is transferred in Türkiye or abroad.
- Request correction of incomplete or inaccurate data and notification of that correction to disclosed recipients.
- Request deletion or destruction when the statutory conditions are met and notification to disclosed recipients.
- Object to a result against you produced solely through analysis by automated systems.
- Request compensation for damage caused by unlawful processing.
10. Your rights under the GDPR
Where the GDPR applies, and subject to its conditions, you may:
- Access your data and obtain a copy, and correct inaccurate data.
- Request erasure or restriction of processing.
- Receive data processed by automated means on the basis of consent or contract in a structured, commonly used, machine-readable format and transmit it where technically feasible.
- Object, on grounds relating to your particular situation, to processing based on legitimate interests, and object at any time to direct marketing.
- Withdraw consent with future effect.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
- Lodge a complaint with a competent supervisory authority and seek an effective judicial remedy.
MetriLume fund rankings and calculator results are not legal or similarly significant decisions based on your personal profile. If such a decision system is introduced, its logic, significance, and expected consequences will be separately explained, and the necessary right to human intervention will be provided.
11. Request procedure and identity verification
- [email protected] and [email protected] are channels for questions and initial contact. A formal KVKK application may be submitted in writing to the company address, through a verified registered-electronic-mail (KEP) address, with a secure electronic/mobile signature, or from an email address previously notified by the applicant and registered in AxelVira’s system. No address is treated as the KEP channel until it is verified against official records and published on this page.
- State your name, a secure contact channel for the response, the subject of your request, and your relationship with MetriLume.
- If you have account access, the registered channel or in-account tool is preferred. Do not send a full identity document unsolicited; we may request a redacted document containing only fields necessary for verification.
- An authorized representative must include evidence of authority. We do not disclose another person’s data.
KVKK applications are answered as soon as possible and within no more than thirty days. Where the GDPR applies, information on action taken is provided without undue delay and within one month; that period may be extended by two further months where the complexity or number of requests requires it, and the extension and reasons are notified within the first month. Measures permitted by law apply to manifestly unfounded, excessive, or repetitive requests only under the statutory conditions.
12. Complaint channels
Under the KVKK, you may complain to the Turkish Personal Data Protection Board within thirty days after learning our response and, in all cases, within sixty days after applying to the controller; if no timely response is given, the statutory sixty-day outer limit applies. Where the GDPR applies, you may complain to the supervisory authority in the EU/EEA country of your habitual residence, place of work, or the alleged infringement. Contacting us first may speed resolution but does not remove your mandatory right to complain.
13. Special-category data and children
The MetriLume service does not request special-category personal data. Do not place identifying personal or confidential information in a Lume Scenario name or the title/configuration in a Lume Embed URL. Lume Journal may be used for your own ordinary financial decision notes; do not add special-category data, account/access credentials, or unnecessary personal or confidential information about another person to Journal, support, or other free-text fields. If necessary and lawful special-category processing arises, it will not begin until a condition under KVKK Art. 6/GDPR Art. 9, data minimization, and additional technical and organizational measures are in place.
We do not profile or market to children. A new feature that requires age-dependent consent or guardian permission will not be activated without appropriate age assurance and a separate notice.
14. Updates and contact
If a data flow or legal ground changes materially, this notice will be updated; where necessary, additional notice or consent will be provided before processing begins. If targeted EU/EEA service makes a GDPR Article 27 representative mandatory, or the scale/nature of processing requires a data protection officer, the relevant identity and contact details are published before that targeted service launches. The controller’s contact details appear in the corporate section at the bottom of the page.
Contact and data controller
- AxelVira Teknoloji A.Ş.
- İzmir Trade Registry 271455
- Address
- Adalet Mah. Manas Blv. No:47/B Folkart Plaza D:3509, Bayraklı/İzmir, Türkiye
- Tax identification number
- 0991410303
- MERSİS
- 0099141030300001
- Support
- [email protected] · +90 (850) 840 20 83
- Privacy and data requests
- [email protected] · [email protected]