Last updated: 2 September 2026

Privacy Policy

1. Controller and EU Representative

The controller responsible for the processing of personal data is:

IQRA GROUP TEKNOLOJİ EĞİTİM HİZMETLERİ VE TİCARET LİMİTED ŞİRKETİKavaklıdere Mah. Atatürk Blv. No: 185/6Çankaya/AnkaraTürkiye

Email: info@iqra-akademie.com

Representative in the European Union pursuant to Art. 27 GDPR:

Cloudkasten GmbHSeestr. 20 G50374 ErftstadtGermany

Email: iqra-group@rep4.eu

2. Scope

This Privacy Policy provides information about the processing of personal data in connection with our websites and online services, our customer and teaching portal, our customer support, and the organisation and provision of our online lessons.

It also provides information about essential external services through which customers interact directly with us or with a service provider used by us.

When using external websites or services, the privacy information of the respective provider may additionally apply.

3. General Legal Bases

We process personal data only where there is a legal basis for doing so.

Depending on the processing activity, processing is carried out in particular:

  • for the performance of a contract or to take steps prior to entering into a contract pursuant to Art. 6(1)(b) GDPR,
  • for compliance with a legal obligation pursuant to Art. 6(1)(c) GDPR,
  • on the basis of consent pursuant to Art. 6(1)(a) GDPR,
  • or on the basis of our legitimate interests or the legitimate interests of third parties pursuant to Art. 6(1)(f) GDPR, provided that such interests are not overridden by the interests, fundamental rights or freedoms of the data subject.

Where certain personal data is required for entering into or performing a contract, the relevant service may not be provided, or may only be provided in part, if this data is not made available.

4. Hosting and Technical Provision

Our website and customer portal are provided using a professional hosting service provider on server infrastructure within the European Union.

The hosting service provider processes personal data on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place for this purpose.

When our websites are accessed, the following technical data in particular may be processed:

  • IP address,
  • date and time of access,
  • page or resource accessed,
  • browser and device information,
  • technical error and security information.

The processing serves the secure, stable and technically reliable provision of our online services and the detection and prevention of abusive or unlawful access.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of our online services.

In accordance with our deletion policy, technical log data is generally retained for no longer than 90 days. Longer retention takes place only where this is necessary to investigate a specific technical, misuse-related or security-related incident.

5. Cookies and Similar Technologies

Based on the current status of our technical review, we currently do not use our own analytics or advertising cookies on the public pages of our website.

Information may be stored temporarily in the browser for technically necessary functions.

When accessing external services, for example WhatsApp, Google Forms, Zoom or external payment pages, the respective providers may use their own cookies or comparable technologies in accordance with their privacy information.

6. Contact and Customer Communication

To provide an easy means of contacting us, we make available on our website, among other things, a communication widget provided by a European service provider.

When this element is loaded, technically necessary connection data may be processed, in particular:

  • IP address,
  • browser information,
  • device information,
  • technical connection information.

Where the service provider acts on our behalf, it processes this data within the framework of a data processing relationship.

The purpose of the processing is to provide prospective and existing customers with an easily accessible means of communication.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in simple and efficient communication with prospective and existing customers.

WhatsApp

We offer communication via WhatsApp.

If you choose to contact us via WhatsApp, the following data in particular may be processed:

  • telephone number,
  • profile and account information,
  • communication content,
  • any files and attachments you may provide.

When WhatsApp is used, the respective WhatsApp provider also processes data in accordance with its own privacy policy.

Depending on the purpose of the communication, our processing is carried out for pre-contractual measures or the performance of a contract pursuant to Art. 6(1)(b) GDPR, or on the basis of our legitimate interest in efficient communication pursuant to Art. 6(1)(f) GDPR.

In accordance with our deletion policy, ordinary customer communication is generally deleted no later than two years after completion of the matter or the end of the customer relationship, unless statutory retention obligations, outstanding claims, legal claims or other lawful reasons require longer retention.

7. Communication by Email

If you contact us by email, we process in particular:

  • your email address,
  • your name, where applicable,
  • the content of your message,
  • any additional information and attachments you provide, where applicable.

For our business email and office communication, we use a cloud-based service provider.

Where required, appropriate data protection agreements are in place with the service providers used for these purposes.

Depending on the purpose of the communication, processing is carried out pursuant to Art. 6(1)(b) GDPR for pre-contractual measures or the performance of a contract, or pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in handling general enquiries.

Ordinary customer communication is generally deleted no later than two years after completion of the matter or the end of the customer relationship.

Business, tax-related or legally relevant emails may be retained for longer in accordance with applicable statutory retention and documentation obligations.

Where contact data is still stored in a communication system used previously or in addition to our current systems, such data is retained only for as long as there is an existing communication, contractual, documentation or other lawful purpose.

8. Forms for Trial Lessons and Free Offers

For enquiries about trial lessons and registrations for certain free offers, we use Google Forms.

The following data in particular may be collected:

  • name,
  • email address,
  • telephone number,
  • information about the requested offer.

For enquiries connected with a potential contractual relationship, processing is carried out in particular pursuant to Art. 6(1)(b) GDPR.

Where processing serves solely to organise a free offer, it is carried out on the basis of our legitimate interest in organising and providing the respective offer pursuant to Art. 6(1)(f) GDPR.

The data is generally retained for no longer than six months after the relevant purpose has ceased to apply and is then deleted, unless there is another specific purpose, a subsequent customer relationship or a statutory or other lawful basis for longer retention.

When accessing a Google Form, Google also processes data directly in accordance with its own privacy information.

9. Customer and Teaching Portal

We operate our own customer and teaching portal for the administration of customer, student, teacher and lesson data.

Depending on the contractual and user relationship, the following data in particular may be processed:

  • name,
  • address,
  • email address,
  • telephone number,
  • year of birth,
  • gender,
  • family or assignment information,
  • user account and role status,
  • course and lesson data,
  • assigned students and teachers,
  • lesson dates and lesson duration,
  • pauses, rescheduling and cancellations,
  • status information,
  • tariffs and prices,
  • internal organisational information.

For teachers, the following information in particular may additionally be processed:

  • qualifications,
  • languages,
  • teaching subjects,
  • availability.

For invoice overviews, certain data from our invoicing system may be provided, for example:

  • invoice number,
  • invoice date,
  • due date,
  • invoice amount,
  • payment status.

Invoice documents may be retrieved from the invoicing system for display when required.

Credit or debit card data is not stored in our customer portal.

Access to the portal is role-based.

Customers generally only receive access to their own information and information relating to members of their family. Teachers receive access to the information required for their teaching activities. Internal employees receive access according to their respective responsibilities.

Processing is carried out in particular for the performance of a contract pursuant to Art. 6(1)(b) GDPR.

Where data must be retained due to statutory requirements, processing is additionally carried out pursuant to Art. 6(1)(c) GDPR.

Customer, student and portal data is generally deleted or anonymised no later than two years after the end of the customer or contractual relationship, unless statutory retention obligations, outstanding claims, legal claims or other lawful reasons require longer retention.

10. Online Lessons via Zoom

We use Zoom to provide our online lessons.

When Zoom is used, the following data in particular may be processed:

  • name or display name,
  • profile and participant information,
  • IP address,
  • device and technical data,
  • audio and video data,
  • meeting and chat content,
  • exchanged files,
  • usage and connection data.

The general use of Zoom for online lessons is carried out for the performance of our teaching contract pursuant to Art. 6(1)(b) GDPR.

Depending on the service used and the technical provision of the service, personal data may also be processed outside the European Economic Area. Where the GDPR applies, the respective applicable legal transfer mechanisms are used.

Recordings for Internal Quality Control

Individual lessons may be recorded for internal quality control.

We provide information about the possibility of recordings in our contractual terms or terms of participation.

Before a specific recording begins, the affected participants are additionally informed about the recording.

Where consent is required, it is obtained separately. Any consent given may be withdrawn at any time with effect for the future.

Under our current configuration, cloud recordings are generally deleted automatically after a short period. Temporary technical retention in a recycle bin or recovery area may subsequently still take place.

11. Invoicing and Accounting

For the creation, administration and retention of invoices, we use a specialised invoicing and accounting service provider.

Depending on the transaction, the following data in particular may be processed:

  • name,
  • address,
  • email address,
  • telephone number, where applicable,
  • service and contractual data,
  • invoice data,
  • payment information.

Where the service provider processes personal data exclusively on our behalf, a data processing agreement is in place.

The legal basis for invoicing is in particular Art. 6(1)(b) GDPR and, where statutory retention and documentation obligations apply, Art. 6(1)(c) GDPR.

Invoice, accounting and tax-related records are retained in accordance with the respectively applicable statutory retention periods. Under our current retention policy, such records may generally be retained for up to ten years.

Other customer data is deleted or anonymised where it is no longer required and no statutory retention obligations or other lawful reasons require longer retention.

12. Card Payments via PayTR

For certain card payments, we use external payment links provided by PayTR.

PayTR is not technically integrated into our website.

In particular:

  • there is no PayTR API integration on our website,
  • there is no PayTR iframe on our website.

We manually create the relevant payment link in the PayTR merchant portal and then manually send it to the customer.

When creating a payment link, we may provide PayTR with the following information in particular:

  • payment amount,
  • currency,
  • service or payment description,
  • email address, where applicable,
  • telephone number, where applicable.

Only when you access the external PayTR payment link does PayTR directly process additional information.

This may include in particular:

  • payment and transaction data,
  • card information,
  • IP address,
  • device and technical data,
  • security and risk data,
  • internal transaction or reference numbers.

iQRA does not receive or store credit or debit card data.

Card data is entered directly on the payment page provided by PayTR.

The transfer initiated by us for payment processing is generally carried out for the performance of a contract pursuant to Art. 6(1)(b) GDPR.

PayTR performs automated security, fraud and risk checks. These may take into account, in particular, IP addresses, device information, transaction behaviour and other risk indicators.

Payments may be automatically rejected or held as part of these checks.

Suspicious transactions may additionally be reviewed by employees or security teams.

Depending on the specific processing activity, PayTR may process data on our behalf or under its own data protection responsibility due to its own legal, regulatory or security-related obligations.

For certain contractual, information and record-keeping documents, PayTR applies retention periods of up to ten years.

We do not have a single specific retention period applicable to all customer data processed by PayTR.

13. Payment Reconciliation via Komfortkasse

For payments by invoice, we use Komfortkasse, a service provided by LTC Information Services GmbH, Amraser Str. 119, 6020 Innsbruck, Austria.

Komfortkasse reconciles incoming payments on our behalf with the corresponding payment transactions.

Depending on the services we have commissioned, Komfortkasse may also send payment information and handle payment reminders, dunning notices and refunds.

Komfortkasse acts as our processor; we remain responsible for the processing.

In rare cases, a payment cannot be automatically allocated and the name of the person making the payment differs from the name of the person liable for payment – for example, because a family member or employer has paid on their behalf. In such cases, Komfortkasse may clarify the individual case using publicly accessible sources.

Komfortkasse also statistically evaluates incoming payments on our behalf. The results consist exclusively of aggregated metrics without personal reference, which Komfortkasse may also use to further develop its service and may partly publish.

The legal basis for clarifying payments that cannot be automatically allocated and for the statistical evaluation is Art. 6(1)(f) GDPR.

Our legitimate interest is to allocate incoming payments correctly and quickly to the appropriate payment transaction. Otherwise, a payment that has already been made might not be correctly allocated, payment reminders or dunning notices might be sent despite payment having been made, or the payment might have to be returned to the sender's account.

For the statistical evaluation, our legitimate interest lies in measuring and improving the quality of this payment reconciliation process.

Komfortkasse explains which sources are used and which are excluded, how artificial intelligence is used in this context, which data is processed in detail, where it originates, how long it is stored and to whom it is disclosed in its privacy policy at:

https://komfortkasse.eu/datenschutz

14. Applications

Applications may in particular be submitted by email or via the communication channels specified by us.

We process the data provided by the applicant, including in particular:

  • name and contact details,
  • CV,
  • qualifications,
  • professional information,
  • other application documents,
  • communication content.

Processing is carried out for the application procedure and/or pre-contractual measures pursuant to Art. 6(1)(b) GDPR.

If an application is unsuccessful, application data is generally deleted no later than six months after completion of the application process, unless lawful reasons require longer retention.

If an applicant is hired, only the data required for the employment relationship is transferred to the relevant personnel records. Application documents that are no longer required are deleted.

15. Recipients and Processors

Personal data is disclosed to third parties only where this is necessary for the provision of our services, the performance of a contract, compliance with a legal obligation, on the basis of valid consent or on another lawful basis.

Depending on the processing activity, this may in particular include providers or recipients from the following categories:

  • hosting and IT infrastructure,
  • email, cloud and office communication,
  • video conferencing and online teaching,
  • customer communication,
  • invoicing and accounting,
  • payment processing and financial institutions,
  • payment reconciliation,
  • professional advisers and auditors,
  • public authorities and other legally authorised bodies.

Where service providers process personal data exclusively on our behalf, appropriate data processing agreements pursuant to Art. 28 GDPR are in place where required.

For certain processing activities, individual providers may act as independent controllers due to their own legal or regulatory obligations.

16. International Data Processing and Third-Country Transfers

As our company is established in Türkiye and we partly use internationally operating service providers, personal data may also be processed outside the European Economic Area.

This may include processing in Türkiye, the United States and other countries.

Where a transfer of personal data under the GDPR requires a specific transfer mechanism, the transfer is carried out on the basis of the respectively applicable legal requirements.

These may include in particular:

  • an adequacy decision of the European Commission,
  • Standard Contractual Clauses,
  • other appropriate safeguards,
  • or, in legally provided individual cases, an applicable derogation.

You may request further information about a specific transfer mechanism by contacting info@iqra-akademie.com.

17. Retention and Deletion

Personal data is generally retained only for as long as it is required for the relevant purpose or where statutory or other lawful reasons require continued retention.

Our internal deletion and retention policy provides in particular for the following standard periods:

  • invoice, accounting and tax-related records: in accordance with the respectively applicable statutory retention periods and, under our current retention policy, generally for up to 10 years,
  • customer, student and portal data: generally for no longer than 2 years after the end of the customer or contractual relationship,
  • data from enquiries about trial lessons and free offers where no subsequent customer relationship is established: generally for no longer than 6 months after the relevant purpose has ceased,
  • unsuccessful applications: generally for no longer than 6 months after completion of the application process,
  • ordinary customer communication: generally for no longer than 2 years after completion of the matter or the end of the customer relationship,
  • technical log data: generally for no longer than 90 days.

Backups are maintained on a rotating basis. Under our deletion policy, overwriting or deletion within a period of generally no more than 90 days is intended where technically feasible.

Longer retention may in particular be necessary where:

  • statutory retention obligations apply,
  • outstanding claims exist,
  • legal disputes are ongoing,
  • data is required for the establishment, exercise or defence of legal claims,
  • an authority or court requires continued retention.

We regularly review the scheduled deletion of personal data.

18. Automated Decision-Making and Profiling

We currently do not make any solely automated decisions in our own customer portal that produce legal effects concerning customers or similarly significantly affect them.

The external payment provider PayTR uses automated security, fraud and risk checks.

These checks may affect the processing of a payment. For example, a payment may be rejected or held.

Unusual or suspicious transactions may additionally be subject to human review.

Automated processes, including artificial intelligence, may be used as supporting tools in payment reconciliation by Komfortkasse.

Further details about processing by Komfortkasse are provided in Section 13 and in the Komfortkasse privacy policy linked there.

19. Your Data Protection Rights

Where the applicable legal requirements are met, you have in particular the following rights:

  • right of access to personal data concerning you,
  • right to rectification of inaccurate or incomplete data,
  • right to erasure,
  • right to restriction of processing,
  • right to data portability,
  • right to object to certain processing activities,
  • right to withdraw consent with effect for the future.

Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

Where personal data is processed for direct marketing purposes, you may object to the processing of your personal data for this purpose at any time.

To exercise your rights, you may contact us at:

Email: info@iqra-akademie.com

You may also contact our representative in the European Union:

Cloudkasten GmbHSeestr. 20 G50374 ErftstadtGermany

Email: iqra-group@rep4.eu

20. Right to Lodge a Complaint

If you believe that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent data protection supervisory authority.

In accordance with the GDPR, you may in particular contact a supervisory authority in the Member State of your habitual residence, your place of work or the place of the alleged infringement.

For data protection-related matters, you may also contact our representative in the European Union referred to in Section 1.

21. Changes to this Privacy Policy

We review and update this Privacy Policy where our processing activities, services used or legal requirements change materially.

The version currently published on our website applies.

Kurse

  1. Qurankurse
    1. Quranlesen für Anfänger Online
    2. Quranlesefestigung Online
    3. Quranlesekorrektur Online
  2. Arabischkurse
    1. Arabisch für Anfänger Online
    2. Arabisch für Fortgeschrittene Online
  3. Tajweedkurse
    1. Tajweed Theorie Online

Kontakt

IQRA GROUP TEKNOLOJİ EĞİTİM
HİZMETLERİ VE TİCARET LİMİTED ŞİRKETİ
Kavaklıdere Mah. Atatürk Blv. No: 185/6
Çankaya/Ankara
info@iqra-akademie.com
© 2026 IQRA GROUP
TEKNOLOJİ EĞİTİM HİZMETLERİ VE TİCARET LİMİTED ŞİRKETİ