Skip to main content

Privacy Policy and GDPR

Last Updated: November 03, 2025

1. Data Controller In accordance with the General Data Protection Regulation (GDPR), your personal data may be processed by Numistr.org ("Numistr", "Site", or "Application") as the data controller, within the scope described below.

2. Purpose of Personal Data Processing Your collected personal data will be processed by Numistr for the following purposes, as part of the necessary work carried out by our business units to enable you to benefit from the products and services offered, and to execute the relevant business processes:

  • Provision of Services: To create, verify, and manage your membership (Subscription) registration.

  • Communication: To contact you via email or in-app notifications regarding updates to our services, user support, and informational messages.

  • Service Improvement: To evaluate anonymized or aggregated usage data for the purpose of analyzing the performance of our website and mobile applications, improving the user experience, and developing new features.

  • Academic Collaboration: To confirm the student status of users applying under the "Student Subscription" and to manage academic contribution processes.

  • API Services: To manage the subscriptions of developers or institutions receiving "API Subscription" services and to provide technical support.

  • Legal Obligations: To fulfill our legal obligations arising from relevant legislation and to make necessary notifications to authorized institutions and organizations.

3. Personal Data Processed and Method of Collection Depending on your use of our services, the following personal data is collected through electronic means (website registration forms, mobile application, email) by automatic or partially automatic methods:

  • Identity and Contact Information: Name, surname, email address (via membership and contact forms).

  • Academic Information (for Student Subscription): Documents confirming academic status submitted during the application, such as university, department information, and student ID.

  • Transaction Security Information: IP address, device information, browser information, site and in-app navigation data, cookies.

  • User Data: Data created by you while using features such as collection management, which may contain personal information.

4. To Whom and for What Purpose Personal Data May Be Transferred As a rule, your personal data is not shared with third parties without your explicit consent. However, for the fulfillment of legal obligations and in situations necessary for the provision of our services, data may be transferred to the following parties:

  • Authorized Public Institutions and Organizations: With courts and other public institutions, in line with legal requests.

  • Service Providers: With third-party service providers, located domestically or abroad, from whom we receive technical services such as server (hosting), email delivery, and payment infrastructure, to the extent necessary for the service and within the framework of confidentiality agreements and data processing agreements.

5. Legal Basis for Collecting Personal Data Your personal data is collected and processed based on the legal grounds specified in Article 6 of the GDPR:

  • The processing is necessary for the establishment or performance of a contract (e.g., your membership agreement).

  • It is necessary for compliance with a legal obligation to which the data controller is subject.

  • Processing is necessary for the purposes of the legitimate interests pursued by the data controller, provided that such processing does not harm the fundamental rights and freedoms of the data subject.

Separate information will be provided for situations requiring your explicit consent.

6. Rights of the Data Subject (under GDPR) As a data subject, you have the following rights:

  • To learn whether your personal data is being processed (Right of Access).

  • To request information if your personal data has been processed (Right of Access).

  • To learn the purpose of the processing and whether it is used in accordance with that purpose.

  • To know the third parties to whom your data has been transferred, domestically or abroad.

  • To request the correction (rectification) of your personal data if it is incomplete or incorrectly processed (Right to Rectification).

  • To request the deletion or destruction of your personal data within the framework of the conditions stipulated in relevant legislation (Right to Erasure / 'Right to be Forgotten').

  • To request that correction, deletion, or destruction operations be notified to third parties to whom your data has been transferred (Right to Notification).

  • To object to any unfavorable outcome against you resulting solely from the analysis of processed data via automated systems (Rights related to Automated Decision Making).

  • To demand compensation for damages in case you suffer a loss due to the unlawful processing of your personal data (Right to an Effective Remedy).

To exercise these rights, you may send your requests to the email address This email address is being protected from spambots. You need JavaScript enabled to view it..

7. Data Security Numistr undertakes to take all necessary technical and administrative security measures to prevent the unlawful processing of and access to your personal data, and to ensure the preservation of the data.

This Privacy Policy may be updated in line with legislative changes or innovations in our services.