Bengü İl

Gizlilik Politikası

Yürürlük tarihi: 6 Ekim 2026 · English version below

Bu metin, Bengü İl oyununun (mobil uygulama, masaüstü web sürümü ve benguil.com sitesi) hangi kişisel verileri işlediğini, neden işlediğini, ne kadar sakladığını ve haklarınızı anlatır. 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamında aydınlatma metni, Avrupa Birliği kullanıcıları için ise GDPR kapsamında bilgilendirme niteliğindedir.

Oyun şu an geliştirme aşamasındadır. Bu politika, bugün gerçekten çalışan özellikleri anlatır. Henüz çalışmayan bir özellik (anlık bildirim, mağaza satın alımı, Google ile giriş gibi) devreye alınmadan önce bu metin güncellenir.

1. Veri sorumlusu

Veri sorumlusu: KutsGames (Süleyman Sefa Kartaloğlu) (bundan sonra "biz").

İletişim: destek@benguil.com

2. Hangi verileri işliyoruz

Oyunu oynamak için bir hesap gerekir. Hesap, misafir (cihaz) hesabı ya da e-posta ve şifre ile açılır. Apple ve Google ile giriş kodu hazırdır ancak şu an kapalıdır; açıldığında bu metin güncellenir.

VeriNe zaman oluşurNot
Hesap bilgisi: rastgele hesap kimliği, oluşturulma zamanı, dil, durum (etkin veya askıda)Hesap açılırkenHer hesapta vardır.
Cihaz kimliği ve cihaz sırrı (misafir girişi)İlk açılışta, cihazda rastgele üretilirSunucuda yalnız sırrın SHA-256 özeti tutulur. Reklam kimliği ya da donanım kimliği değildir.
E-posta adresi ve şifre özetiE-posta ile kayıttaŞifre düz metin olarak saklanmaz, tuzlu PBKDF2-SHA256 özeti saklanır. Doğrulama ve şifre sıfırlama kodları yalnız HMAC özeti olarak tutulur.
Oturum belirteçleri: yenileme belirteci özeti, oturum kimliği, cihaz kimliği, düzenlenme ve bitiş zamanıHer girişteBelirtecin kendisi değil, özeti saklanır. Yenileme belirteci 60 gün geçerlidir.
Başarısız giriş sayaçlarıHatalı giriş denemesindeE-posta ya da cihaz bilgisinin özeti anahtardır; adresin kendisi bu tabloda tutulmaz.
Oyuncu profili: oyuncu adı, medeniyet, şehirler, kaynaklar, nüfus, puanlar, son etkinlik zamanıBir krallığa katılıncaOyun adınız diğer oyunculara görünür. Gerçek adınızı kullanmanız gerekmez.
Oyun eylemleri: binalar, işçi atamaları, birlikler, seferler, savaş ve casusluk raporları, Pazar ilanları ve takaslarOynarkenRaporlar saklama süresi sonunda silinir (bkz. 4).
Sohbet (Dünya ve birlik kanalı)Mesaj gönderinceKüfür süzgeci mesajı maskeleyebilir; maskelenen mesajın özgün hali yalnız moderasyon kanıtı olarak saklanır ve oyunculara gösterilmez.
Posta (oyuncu, birlik ve sistem postaları)Posta gönderinceGönderen, alıcı, konu ve metin. Süzgeç burada da özgün metni kanıt olarak saklayabilir.
Birlik bilgisi: üyelik geçmişi, rol, davetler, birlik adı ve etiketiBirliğe girince ya da kuruncaÜyelik geçmişi satır olarak silinmez; ayrılınca kapatılır.
Şikâyet ve engelleme: şikâyet nedeni, kısa not, şikâyet edilen metnin kopyası; kimin kimi engellediğiBir mesajı ya da postayı şikâyet edince, birini engelleyinceKanıt kopyası, asıl satır süresi dolsa bile moderasyon için saklanır.
Yaptırımlar: yasak, susturma, nedeni ve süresiBir kural ihlalindeKaldırılan yaptırım silinmez, geçmiş olarak kalır.
Elmas defteri: Elmas bakiyesi ve hareketleri (kalkan satın alma, yönetici verme)Elmas hareketindeDeğiştirilemeyen defter satırlarıdır. Mağaza henüz açık değildir.
Yönetici denetim kaydı: yönetici işlemleri (örn. yasaklama), hedef hesap kimliği, gerekçeYönetici bir işlem yapıncaYalnız yetkili yöneticilere görünür.
IP adresiHer istekteGiriş denemelerini sınırlamak (kötüye kullanım ve kaba kuvvet koruması) için bellekte anlık işlenir; oyuncu veritabanına yazılmaz. Yalnız yönetim panelinin oturum ve denetim kaydında, panel kullanıcılarının IP adresi saklanır.
Sunucu günlükleriSürekliTeknik JSON günlükleri hesap kimliğini ve maskelenmiş e-postayı (örn. a***@örnek.com) içerir; şifre, belirteç ve kod yazılmaz.

Toplamadıklarımız: konum, rehber, kamera, mikrofon, fotoğraf, reklam kimliği, ödeme kartı bilgisi. Uygulama ayrıca cihazınızda yerel bildirim gösterebilir (örn. inşaat bitti); bu bildirimler cihazın içinde zamanlanır, bizim sunucumuza veri göndermez. Oturum belirteçleriniz cihazınızın yerel depolamasında saklanır.

3. Amaçlar ve hukuki sebepler

AmaçKVKK m.5 / GDPR m.6
Hesap açmak, giriş yaptırmak, oyunu çalıştırmak ve oyuncular arası özellikleri (harita, sefer, birlik, sohbet, posta, sıralama) sunmakSözleşmenin kurulması ve ifası (KVKK m.5/2-c; GDPR m.6/1-b)
Hesap güvenliği, hileli ya da kötüye kullanım amaçlı girişimlerin engellenmesi, moderasyon (şikâyet, yasak, susturma), hata ayıklamaMeşru menfaat (KVKK m.5/2-f; GDPR m.6/1-f)
Yasal yükümlülükler (yetkili makam talepleri, ileride satın alma kayıtlarının tutulması)Hukuki yükümlülük (KVKK m.5/2-ç; GDPR m.6/1-c)
İsteğe bağlı bildirimler ya da gelecekte eklenecek, açık rıza gerektiren işlemlerAçık rıza (KVKK m.5/1; GDPR m.6/1-a); rızayı istediğiniz zaman geri alabilirsiniz

Verilerinizi pazarlama amacıyla üçüncü taraflara satmayız ve profil çıkarma ya da yalnız otomatik karara dayalı hukuki sonuç doğuran işlem yapmayız. Sohbet ve posta süzgeci yalnız küfür içeren sözcükleri maskeler.

4. Saklama süreleri

  • Hesap, kimlik, profil ve oyun durumu: hesap silinene kadar. Misafir hesabı da silme talebine kadar saklanır.
  • Sohbet: yaklaşık 30 gün (30 günlük bölümler halinde, süresi dolan bölüm toptan silinir; fiilen 30-60 gün).
  • Posta: yaklaşık 60 gün.
  • Savaş ve casusluk raporları: 45 gün (fiilen 45-75 gün).
  • Şikâyet kanıtları: ilgili sezon boyunca; sezon sonunda krallığın arşivi ile birlikte kaldırılır.
  • Yaptırım geçmişi, yönetici denetim kaydı, Elmas defteri: hesap silinene kadar; yasal bir saklama süresi varsa o süre kadar.
  • Yenileme belirteci: en çok 60 gün; çıkışta ya da şifre değişince hemen iptal edilir.
  • Veritabanı yedekleri: günlük yedek alınır ve 14 gün sonra silinir. Silinen veri en geç bu süre içinde yedeklerden de çıkar.

5. Paylaşım ve hizmet sağlayıcılar

Verilerinizi satmayız. Yalnız hizmetin çalışması için gerekli sağlayıcılarla (veri işleyen sıfatıyla) paylaşırız:

  • Bulutova (Türkiye): oyun sunucusu ve veritabanının, ayrıca bu web sitesinin barındırıldığı sağlayıcı. E-postalar (doğrulama ve şifre sıfırlama) bu sağlayıcının SMTP sunucusu üzerinden, noreply@benguil.com adresinden gönderilir.
  • Google: yalnız Google Play üzerinden uygulamayı indirirseniz (Google Play'in kendi gizlilik politikası geçerlidir) ve ileride "Google ile giriş" açılıp siz kullanırsanız.
  • Yetkili makamlar: yasal bir zorunluluk olduğunda.

Oyun içinde diğer oyuncular şunları görür: oyun adınız, medeniyetiniz, birlik etiketiniz, puanlarınız, haritadaki şehir konumlarınız ve herkese açık sohbet mesajlarınız. E-posta adresiniz hiçbir oyuncuya gösterilmez.

Unity Analytics, Unity Ads, başka bir reklam ağı ya da davranış analizi hizmeti uygulamada kapalıdır.

6. Yurt dışına aktarım

Sunucularımız Türkiye'dedir. Sizi sunucuya bağlayan internet trafiği, bulunduğunuz ülkeden Türkiye'ye gider; Türkiye dışından oynayan oyuncuların verileri bu nedenle Türkiye'de işlenir. Google Play ya da (ileride) Google ile giriş kullanırsanız, bu hizmetler kendi politikalarına göre Türkiye dışında veri işleyebilir. Yurt dışına aktarım gerektiren başka bir hizmet kullanmıyoruz; kullanacak olursak KVKK m.9 ve GDPR m.44 ve devamı kapsamındaki güvenceleri sağlar ve metni güncelleriz.

7. Güvenlik

  • İstemci ile sunucu arasındaki trafik HTTPS ve TLS ile şifrelenir.
  • Şifreler tuzlu PBKDF2-SHA256 özeti olarak, yenileme belirteçleri, cihaz sırları ve kodlar yalnız özet olarak saklanır; yaygın ve zayıf şifreler reddedilir.
  • Oturum belirteçleri kısa ömürlüdür (erişim belirteci 15 dakika), yenileme belirteci her kullanımda döndürülür ve yeniden kullanım denemesi tüm oturum ailesini iptal eder.
  • Hatalı girişler ve IP başına istekler sınırlanır.
  • Yönetim paneli ayrı bir bağlantı noktasındadır; iki aşamalı doğrulama, rol tabanlı yetki ve her işlemin denetim kaydı ile korunur.
  • Sunucuya SSH yalnız anahtarla yapılır, güvenlik duvarı ve saldırı engelleme yazılımı kullanılır.

Hiçbir sistem tamamen güvenli değildir. Bir veri ihlali olursa, KVKK ve GDPR'ın öngördüğü süre ve yöntemle ilgili kişilere ve kurumlara bildirim yaparız.

8. Çocuklar

Bengü İl 13 yaşından küçük çocuklara yönelik değildir. 13 yaşından küçük olduğunu öğrendiğimiz bir kişinin hesabını ve verilerini sileriz. Ebeveynler çocuklarının hesabının silinmesini destek@benguil.com adresinden isteyebilir. Avrupa Birliği'nde dijital rıza yaşı 13'ten yüksek olan ülkelerde, o yaşın altındaki kullanıcıların hesap açması için ebeveyn onayı gerekir. Bilerek çocuklardan reklam kimliği ya da konum toplamayız.

9. Haklarınız

KVKK m.11 ve GDPR m.15-22 uyarınca şu haklara sahipsiniz:

  • Verilerinizin işlenip işlenmediğini öğrenme ve bilgi talep etme (erişim),
  • İşleme amacını ve amaca uygun kullanılıp kullanılmadığını öğrenme,
  • Yanlış ya da eksik verilerin düzeltilmesini isteme,
  • Verilerin silinmesini ya da yok edilmesini isteme (hesap silme sayfası),
  • İşlemenin kısıtlanmasını ve itiraz etme hakkı; rızaya dayalı işlemede rızayı geri alma,
  • Verilerinizi yapılandırılmış, yaygın bir biçimde alma (veri taşınabilirliği, GDPR),
  • Düzeltme, silme ve aktarımların üçüncü kişilere bildirilmesini isteme,
  • Otomatik sistemlerle yapılan işlemler sonucunda aleyhinize bir sonuç doğmasına itiraz etme,
  • Haksız işleme nedeniyle zarara uğramanız halinde tazminat talep etme.

Başvurunuzu destek@benguil.com adresine, hesabınıza ait e-posta adresinden ya da oyuncu adınız ve krallık adınızla gönderin. Başvuruyu en geç 30 gün içinde yanıtlarız. Yanıtımızdan memnun kalmazsanız Türkiye'de Kişisel Verileri Koruma Kurumu'na, Avrupa Birliği'nde ikamet ediyorsanız yerel veri koruma otoritenize şikâyette bulunabilirsiniz.

10. Uygulama içi satın almalar

Tasarımda Elmas adlı oyun içi para birimi ve Elmasla alınan saldırı koruması (kalkan) bulunur. Mağaza henüz açık değildir; bugün gerçek parayla yapılan bir satın alma yoktur. Açıldığında ödemeler Google Play tarafından işlenir. Ödeme kartı ya da hesap bilgilerinizi biz hiçbir zaman görmeyiz ve saklamayız; yalnız mağazanın bize ilettiği satın alma kaydını (ürün ve işlem kimliği) Elmas defterine yazarız. Oyunda ücretli güç çarpanı, askersiz nüfus ya da kaynak paketi satılmaz.

11. Çerezler, reklam ve izleme

benguil.com sitesi çerez kullanmaz, analiz ya da izleme aracı içermez, üçüncü taraf içerik yüklemez. Mobil uygulamada reklam yoktur ve uygulama sizi uygulamalar ya da siteler arasında izlemez. Masaüstü web sürümünde oturum bilgileri tarayıcınızın yerel depolamasında tutulur.

12. Değişiklikler ve iletişim

Bu politika değiştiğinde yeni yürürlük tarihiyle bu sayfada yayımlanır; önemli değişiklikleri uygulama içinden de duyururuz. Sorularınız için: destek@benguil.com.


Privacy Policy

Effective date: 6 October 2026 · Türkçe sürüm yukarıda

This policy explains what personal data the game Bengü İl (the mobile app, the desktop web build and the benguil.com website) processes, why, for how long, and what rights you have. It serves as the information notice under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and under the EU General Data Protection Regulation (GDPR).

The game is in development. This policy describes features that actually run today. Before a feature that is not live yet (push notifications, store purchases, Google sign-in) goes live, this policy will be updated.

1. Data controller

Data controller: KutsGames (Süleyman Sefa Kartaloğlu) ("we").

Contact: destek@benguil.com

2. Data we process

You need an account to play. An account is either a guest (device) account or an email and password account. Sign-in with Apple and Google is implemented but currently switched off; this policy will be updated when it is enabled.

DataWhen it arisesNote
Account record: random account ID, creation time, language, status (active or suspended)When the account is createdEvery account has one.
Device ID and device secret (guest sign-in)Randomly generated on your device at first launchThe server keeps only a SHA-256 hash of the secret. It is not an advertising ID or a hardware ID.
Email address and password hashWhen you register with emailThe password is never stored in clear text, only a salted PBKDF2-SHA256 hash. Verification and password-reset codes are kept only as HMAC hashes.
Session tokens: refresh-token hash, session ID, device ID, issue and expiry timeAt every sign-inOnly a hash of the token is stored. A refresh token is valid for 60 days.
Failed-sign-in countersOn a failed attemptKeyed by a hash of the email or device identifier; the address itself is not kept in this table.
Player profile: player name, civilization, cities, resources, population, scores, last activity timeWhen you join a kingdomYour in-game name is visible to other players. You do not need to use your real name.
Game actions: buildings, worker assignments, troops, marches, battle and espionage reports, market listings and tradesWhile playingReports are deleted after the retention period (see 4).
Chat (World and alliance channels)When you send a messageA profanity filter may mask a message; the original of a masked message is kept only as moderation evidence and is never shown to players.
Mail (player, alliance and system mail)When you send mailSender, recipient, subject and text. The filter may keep the original text as evidence here too.
Alliance data: membership history, role, invitations, alliance name and tagWhen you create or join an allianceMembership history rows are not deleted; leaving closes the row.
Reports and blocks: report reason, short note, a copy of the reported text; who blocked whomWhen you report a message or mail, or block a playerThe evidence copy is kept for moderation even after the original row has expired.
Sanctions: bans, mutes, reason and durationOn a rule violationA lifted sanction is not deleted; it stays as history.
Elmas ledger: Elmas balance and movements (shield purchases, administrator grants)On an Elmas movementImmutable ledger rows. The store is not live yet.
Administrator audit log: administrator actions (e.g. a ban), target account ID, reasonWhen an administrator actsVisible only to authorised administrators.
IP addressOn every requestProcessed transiently in memory to rate-limit sign-in attempts (abuse and brute-force protection); it is not written to the player database. Only the admin panel's session and audit records store the IP address of panel users.
Server logsContinuouslyTechnical JSON logs contain the account ID and a masked email (e.g. a***@example.com); passwords, tokens and codes are never logged.

What we do not collect: location, contacts, camera, microphone, photos, advertising ID, payment card data. The app may show local notifications on your device (e.g. a construction finished); these are scheduled on the device and send no data to our servers. Your session tokens are kept in your device's local storage.

3. Purposes and legal bases

PurposeKVKK art. 5 / GDPR art. 6
Creating accounts, signing you in, running the game and its player-to-player features (map, marches, alliances, chat, mail, rankings)Performance of a contract (KVKK 5/2-c; GDPR 6(1)(b))
Account security, preventing cheating and abuse, moderation (reports, bans, mutes), debuggingLegitimate interests (KVKK 5/2-f; GDPR 6(1)(f))
Legal obligations (requests from competent authorities, and keeping purchase records once a store exists)Legal obligation (KVKK 5/2-ç; GDPR 6(1)(c))
Optional notifications or processing added in future that requires consentConsent (KVKK 5/1; GDPR 6(1)(a)); you can withdraw consent at any time

We do not sell your data, we do not use it for marketing by third parties, and we do not carry out profiling or decisions with legal effect based solely on automated processing. The chat and mail filter only masks profane words.

4. Retention

  • Account, identities, profile and game state: until the account is deleted. A guest account is also kept until you ask for deletion.
  • Chat: about 30 days (stored in 30-day partitions; an expired partition is dropped as a whole, so in practice 30-60 days).
  • Mail: about 60 days.
  • Battle and espionage reports: 45 days (in practice 45-75 days).
  • Report evidence: for the season; removed with the kingdom's archive when the season ends.
  • Sanction history, administrator audit log, Elmas ledger: until the account is deleted, or for any longer period required by law.
  • Refresh tokens: at most 60 days; revoked immediately on sign-out or password change.
  • Database backups: daily backups are kept for 14 days. Deleted data leaves the backups within that period at the latest.

5. Sharing and processors

We do not sell your data. We share it only with providers needed to run the service (as processors):

  • Bulutova (Türkiye): hosts the game server and database, and this website. Emails (verification and password reset) are sent through this provider's SMTP server from noreply@benguil.com.
  • Google: only if you download the app through Google Play (Google Play's own privacy policy applies) and, in future, if "Sign in with Google" is enabled and you use it.
  • Competent authorities: where the law requires it.

Other players can see: your in-game name, civilization, alliance tag, scores, the positions of your cities on the map and your public chat messages. Your email address is never shown to any player.

Unity Analytics, Unity Ads, any other ad network or behavioural analytics service is switched off in the app.

6. International transfers

Our servers are in Türkiye. Network traffic from wherever you play travels to Türkiye, so the data of players outside Türkiye is processed in Türkiye. If you use Google Play or (in future) Sign in with Google, those services may process data outside Türkiye under their own policies. We use no other service that requires a transfer abroad; if we do, we will provide the safeguards required by KVKK art. 9 and GDPR art. 44 et seq. and update this policy.

7. Security

  • Traffic between the client and the server is encrypted with HTTPS and TLS.
  • Passwords are stored as salted PBKDF2-SHA256 hashes; refresh tokens, device secrets and codes are stored only as hashes; common and weak passwords are rejected.
  • Session tokens are short-lived (access token 15 minutes), the refresh token rotates on every use, and replaying an old token revokes the whole session family.
  • Failed sign-ins and requests per IP are rate-limited.
  • The admin panel runs on a separate port and is protected by two-factor authentication, role-based permissions and an audit record of every action.
  • SSH access to the server is key-only, with a firewall and intrusion-prevention software.

No system is perfectly secure. If a data breach occurs, we will notify the persons and authorities concerned in the manner and within the time required by KVKK and GDPR.

8. Children

Bengü İl is not directed at children under 13. If we learn that a user is under 13, we delete the account and its data. Parents can request deletion of a child's account at destek@benguil.com. In EU countries where the age of digital consent is above 13, users below that age need parental consent to create an account. We do not knowingly collect advertising IDs or location from children.

9. Your rights

Under KVKK art. 11 and GDPR arts. 15-22 you have the right to:

  • learn whether your data is processed and request information (access),
  • learn the purpose of processing and whether it is used accordingly,
  • have inaccurate or incomplete data corrected,
  • have your data erased or destroyed (account deletion page),
  • restrict processing and object to it; withdraw consent where processing is based on consent,
  • receive your data in a structured, commonly used format (portability, GDPR),
  • have corrections and deletions notified to third parties the data was passed to,
  • object to an outcome against you that results from automated processing,
  • claim compensation for damage caused by unlawful processing.

Send your request to destek@benguil.com from the email address of your account, or quoting your player name and kingdom. We answer within 30 days at the latest. If you are not satisfied, you can complain to the Turkish Personal Data Protection Authority (KVKK), or, if you live in the EU, to your local data protection authority.

10. In-app purchases

The design includes an in-game currency called Elmas and an attack protection (shield) bought with Elmas. The store is not live yet; no real-money purchase exists today. Once it opens, payments will be processed by Google Play. We never see or store your card or payment account details; we only record the purchase receipt the store gives us (product and transaction ID) in the Elmas ledger. The game does not sell paid power multipliers, population-free troops or resource packs.

11. Cookies, ads and tracking

The benguil.com website uses no cookies, contains no analytics or tracking tools and loads no third-party content. The mobile app has no ads and does not track you across apps or websites. In the desktop web build, session data is kept in your browser's local storage.

12. Changes and contact

When this policy changes, the new version is published on this page with a new effective date; we will also announce significant changes in the app. Questions: destek@benguil.com.