All legal documents

Privacy Policy

Explains which personal data we process, why and how; and your rights under GDPR, KVKK and CCPA.

Effective date: 2026-06-25 · Operator: Desk Fabrika

1. Data Controller

This policy concerns personal data processed by [Yasal Unvan — süper admin paneli > Uyumluluk’tan doldurun] (“we”, the “Company”), which provides the Desk Fabrika service (https://www.deskfabrika.com). Contact: merhaba@deskaxe.com · Türkiye · [Telefon].

For the purposes of the EU General Data Protection Regulation (GDPR), the controller is [Yasal Unvan — süper admin paneli > Uyumluluk’tan doldurun].

2. Data We Process

Account data: name, email, password (encrypted), company/organization details.

Usage data: sign-in logs, IP address, device/browser information, page views.

Content data: the business data you enter (customers, invoices, tickets, notes, etc.) — you are the controller of this; we store it as a processor.

Payment data: plan/subscription and billing records (card data is held by the payment provider; we do not store it).

3. Purposes

To provide the service, manage your account and offer support; to ensure security and prevent abuse; to meet legal obligations; to improve the product and (subject to your consent) to communicate/market.

4. Legal Bases

GDPR Art. 6: performance of a contract, legitimate interest, legal obligation, and consent (e.g. marketing, optional cookies).

KVKK Art. 5/6: establishment/performance of a contract, legal obligation, legitimate interest, and explicit consent where required.

5. Sharing and Transfers

We do not sell data. We share it only where necessary to provide the service and under confidentiality obligations with sub-processors (hosting, email, payment, analytics).

Where transfers abroad are required, GDPR Standard Contractual Clauses (SCC) and safeguards required by KVKK apply.

6. Retention

We keep data only for as long as necessary for the purpose and applicable legal retention periods. When you close your account, data is deleted or anonymized within a reasonable time (legal exceptions reserved).

7. Security

Sensitive data (passwords, API keys) is encrypted; transport is protected with TLS; access is limited by authorization. No system is 100% secure, but we apply industry-standard measures.

8. Your Rights

GDPR: access, rectification, erasure (right to be forgotten), restriction, portability, objection and not being subject to automated decisions.

KVKK Art. 11: request information, rectification, deletion/destruction, transfer information, objection and remedy of damages.

US/CCPA: rights to know, delete, opt out of sale (we do not sell your data) and non-discrimination.

For requests, write to kvkk@deskaxe.com or use the “Data Request” form; we respond within 30 days at the latest.

9. Cookies

See our separate Cookie Policy for cookies and similar technologies. Optional cookies run only with your consent.

10. Children

The service is not directed at individuals under 18; we do not knowingly collect children’s data.

11. Changes

We may update this policy and will announce material changes appropriately. Effective date: 2026-06-25.

This document is a general-information template and does not constitute legal advice. We recommend consulting a lawyer to tailor it to your business. For questions write to kvkk@deskaxe.com or create a data request.