1. Data controller
The data controller under this policy is [COMPANY LEGAL NAME] (“CM Apps”), address: [ADDRESS], email: [EMAIL]. For data subjects established in the European Union, where required under Article 27 of the GDPR, the EU representative is: [EU REPRESENTATIVE].
Where we process data belonging to our customers’ own end users through our Products, CM Apps acts as a “data processor”; this relationship is governed by the Data Processing Agreement.
2. Data we process
Identity and contact details (first name, last name, email, phone, job title, company), account and usage data (login records, preferences, in-product activity), commercial information (quotations, contracts, invoices), technical data (IP address, device and browser information, cookie identifiers) and support correspondence.
We do not process special categories of personal data unless it is necessary for the service and we have your explicit consent.
3. Purposes of processing and legal bases
Formation and performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b): account creation, provision of the service, invoicing. Compliance with legal obligations (KVKK Art. 5/2-ç; GDPR Art. 6/1-c): tax, accounting and record-keeping obligations. Legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6/1-f): security, fraud prevention, service improvement. Explicit consent (KVKK Art. 5/1; GDPR Art. 6/1-a): marketing communications and non-essential cookies.
4. Cookies and similar technologies
Our website may use essential, preference, analytics and marketing cookies. Non-essential cookies operate only with your consent. Details are set out in the Cookie Policy.
5. Sharing of data
Your data is shared with sub-processors that provide hosting, email, payment, analytics and support tools, to the extent necessary to deliver the service. The current list is published in the Sub-processor List.
Data may be shared with competent public authorities where legally required, and with the relevant parties in the event of a merger, acquisition or transfer of assets, subject to confidentiality obligations.
6. International transfers
For data subjects established in Türkiye, transfers abroad are carried out in accordance with KVKK Art. 9, using whichever of the following mechanisms is appropriate: an adequacy decision, standard contractual clauses or explicit consent.
For data subjects established in the EU, transfers outside the EEA are made under Chapter V of the GDPR with appropriate safeguards such as an adequacy decision (GDPR Art. 45) or Standard Contractual Clauses (GDPR Art. 46). The mechanism used and the location of each sub-processor are specified in the Sub-processor List.
7. Retention periods
We retain data for as long as required by the purpose of processing and by statutory retention obligations. Commercial books and invoice records are kept for [10] years; contract records for the limitation period; account data for [90] days after the account is closed; marketing consents until withdrawn. At the end of the period, data is deleted, destroyed or anonymized.
8. Security
We protect your data against unauthorized access, loss and misuse through technical and organizational measures such as access control, encryption, backups, logging and staff training. In the event of a data breach, we notify within the periods prescribed by law (KVKK: the Board within 72 hours; GDPR Art. 33: the supervisory authority within 72 hours).
9. Your rights
Under KVKK Art. 11 and GDPR Articles 15 to 22, you have the right to access, rectify and erase your data, to restrict processing, to object, to data portability and to withdraw consent you have given.
You may submit your requests in writing to [EMAIL] or to [ADDRESS]. Requests are concluded within 30 days at the latest (1 month under the GDPR). You may lodge a complaint with the Personal Data Protection Board in Türkiye; data subjects established in the EU may complain to the supervisory authority of their country.
10. Children
Our services are not directed at persons under 18; we do not knowingly collect data from children.
11. Updates
This policy was updated on [13 September 2026]. Changes are published on the website; material changes are also notified separately.
