Home Features All Modules MissClicks MissHud API Contact Discord Sign in with Kick Sign in with Twitch
Personal Data

KVKK and GDPR Privacy Notice

Activity-based notice about our processing under Article 10 of Turkish Law No. 6698 and applicable privacy law.

Last updated: August 4, 2026

Important: Notice and consent are separate. Where consent is required, it is requested through a distinct and freely given choice.

1. Controller

Controller: XsystemSoft Software Services (MissXss). Privacy and KVKK requests: [email protected]. Website: https://missxss.com.tr.

2. Data and purposes

  • Identity, contact and profile data for account administration, authentication, support, notices and preferences.
  • Platform and OAuth data for connecting user-selected services and acting within granted scopes.
  • Chat, stream, content and configuration data for bots, TTS, AI, moderation, alerts, games, API, widgets and overlays.
  • IP, session, device/browser, access, error, security and audit records for security, abuse prevention, debugging and capacity.
  • If premium sales launch, order, plan, payment-result, billing and accounting data. Full card data is handled by the payment institution.
  • Legal records for authority requests, disputes and establishment, exercise or defence of claims.

3. Collection methods

Data is collected wholly or partly by automated means through forms, account/support actions, API requests, cookies/local storage, server/security logs, enabled third-party APIs and webhooks and, after premium launch, payment or invoicing providers.

4. Legal bases

  • Performance or formation of a contract; compliance with legal obligations; establishment, exercise or defence of rights; and legitimate interests balanced against fundamental rights under Article 5(2) KVKK.
  • Consent under Article 5(1) where no other condition covers an optional activity.
  • Special-category data is not intentionally collected. If unavoidable, current Article 6 conditions and additional safeguards apply.
  • Where GDPR applies, corresponding bases may include contract, legal obligation, legitimate interests and consent.

5. Recipients and purposes

  • Hosting, database, security, email, AI/TTS and support vendors for service operation and security.
  • User-selected streaming, social, donation and OAuth platforms for the requested connection and action.
  • After premium launch, payment, e-document, accounting and professional advisers for collection and legal records.
  • Authorized public bodies, courts and legal advisers for compliance and protection of rights.

6. International transfers

Use of global platforms, cloud, AI, TTS or delivery providers may require transfers outside Türkiye. We rely on a mechanism available under Article 9 KVKK, such as adequacy, appropriate safeguards including standard contracts, or an applicable incidental-transfer case; consent is obtained where required.

Where GDPR applies, transfers outside the EEA use an available adequacy decision, contractual safeguard or statutory derogation as applicable.

7. Retention and security

Data is kept only for its purpose, contractual relationship, security need and applicable legal retention or limitation period, then deleted, destroyed or anonymized. Risk-based controls include access restriction, encryption in transit, monitoring, backups, updates and incident response.

8. Your rights

  • Under Article 11 KVKK: confirmation, information, purpose, recipients, correction, deletion/destruction, recipient notification, objection to solely automated adverse results and compensation for unlawful processing.
  • Where GDPR applies: access, correction, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority, subject to legal conditions.

9. How to apply

Submit a request in writing or through a method accepted by KVKK rules, including registered email, secure electronic/mobile signature, your email already registered in our system or a dedicated application channel. You may currently write from your registered account email to [email protected].

Include identifying and contact information required by law and a clear description of the request. Requests are answered as soon as possible and no later than 30 days, normally free of charge. You may complain to the Turkish Personal Data Protection Board within statutory time limits after first applying to the controller.