Product Pricing Terms
EN TR
Login Book demo
Legal

Privacy Policy

What personal data we hold, why we hold it, where it physically sits, who else touches it, how long it stays, and how you make us do something about it. It also serves as our clarification text (aydınlatma metni) under the KVKK.

Version 1.0 Last revised 14 August 2026 Effective on publication Contact [email protected]

Draft: facts still to fill in

Replace every highlighted placeholder below and in the Terms of Service, remove the noindex tag from both files, confirm the backup bucket's region in §8, and make sure [email protected] actually receives mail before this page tells anyone to write to it.

Contents
1 · Two different roles 2 · Who we are 3 · Visiting this website 4 · Having a Solmex account 5 · Data inside a workspace 6 · Why we are allowed to 7 · Cookies and storage 8 · Who else processes it 9 · Where it sits 10 · How long we keep it 11 · Your rights 12 · Security 13 · The mobile app 14 · Children 15 · Changes

01Two different roles, and the difference matters

Solmex handles personal data in two capacities, and which one applies changes who you should ask about it.

We are the controller of the data we collect for ourselves: website visitors, signup and demo enquiries, the account and billing contacts of our customers, and support correspondence. Sections 3, 4 and 7 cover this.

We are a processor for everything inside a customer's workspace: the personnel records, documents, readings and messages their people put in. The customer is the controller there. We act on their instructions and do not decide what goes in or why. Section 5 covers this. If you are an employee of a Solmex customer asking about your own record, your employer is the party to ask, and we will help them answer you.

02Who we are

The data controller is [REGISTERED COMPANY NAME], a [COMPANY FORM] registered in Türkiye at [REGISTERED ADDRESS], registration number [MERSIS / TAX NO].

For anything in this document, including a request to exercise your rights, write to [email protected].

03Visiting this website

This site carries no analytics, no advertising tags and no tracking pixels. We do not know who you are when you read it, and there is no cookie banner because there is nothing to consent to.

Three things still happen when a page loads:

  • Our infrastructure logs the request. Cloudflare, which sits in front of the site, records the IP address, the page requested, the time and the user agent, to serve the page and block abuse.
  • Fonts load from Google Fonts, which means your browser contacts Google's servers and they see your IP address.
  • Forms are protected by Cloudflare Turnstile, which checks that a submission comes from a browser rather than a script. It sets a token for that check and does not profile you across sites.

If you book a demo or send an enquiry, we keep what you type (typically a name, a work email address, a company name and your message) to answer you and to follow up about Solmex.

04Having a Solmex account

When you sign up, or when an administrator creates an account for you, we hold:

  • Account details: name, username, work email address, the role assigned to you, your language preference, and a profile picture if you upload one. Passwords are stored only as salted hashes and cannot be read back, by us or by anyone.
  • Signup details, when a company signs itself up: the email address, the company name and desired address, the invite code used, the IP address the request came from, and the record that our terms were accepted, with the version and timestamp.
  • Access records: a row per session with the time it started and was last active, whether it came from the web or the mobile app, the IP address and the browser's user agent. This tells an administrator who has been using the system; it is not a log of the pages you visit.
  • Change records: an audit trail of who changed which record, when, and what the value was before and after. It exists so that maintenance and cost records can be trusted, and it cannot be edited by users.
  • Error reports: when something breaks, a diagnostic report goes to Sentry. It may include your user id, the page you were on and the technical trace.
  • Correspondence: emails we send you (invitations, password resets, notifications) and support threads.

05Personal data inside a customer workspace

Here we are the processor and the customer is the controller. What a workspace contains depends on which modules that customer uses; across the product it can include:

  • Workforce records: names, employee numbers, nationality, phone numbers and email addresses, emergency contacts, hire dates, position, department and team, supervisor, accommodation address, and notes.
  • Documents and certifications: uploaded files such as certificates, licences and identity documents, along with their expiry dates.
  • Blood group, where the customer chooses to record it. Under KVKK Article 6 and GDPR Article 9 this is special-category data. It is optional in the product, and a customer recording it must have its own lawful basis and explicit consent where required.
  • Operational attribution: who logged a reading, who fuelled a machine, who signed a work permit, who approved a request, who took a photograph.
  • Photographs attached to breakdowns, inspections, work orders and purchase lines, which may show identifiable people.
  • Messages exchanged in the in-app chat, including moderated and deleted messages, which are retained in a hidden state for the customer's own audit purposes.
  • Timesheets and leave records.

We do not use any of it for our own purposes. We do not sell it, we do not share it with advertisers, and we do not use it to train machine learning models.

06Why we are allowed to hold it

WhatPurposeBasis (KVKK Art. 5 / GDPR Art. 6)
Account dataProviding the Service you or your employer contracted forNecessary for a contract: KVKK 5/2(c); GDPR 6(1)(b)
Access and change recordsSecurity, accountability, investigating misuseLegitimate interest: KVKK 5/2(f); GDPR 6(1)(f)
Signup and terms evidenceProving what was agreed and by whomLegal obligation and legitimate interest: KVKK 5/2(ç), 5/2(f); GDPR 6(1)(c), 6(1)(f)
Error diagnosticsKeeping the Service workingLegitimate interest: KVKK 5/2(f); GDPR 6(1)(f)
Demo and enquiry detailsAnswering you and following upSteps prior to a contract, and consent for marketing: KVKK 5/1, 5/2(c); GDPR 6(1)(b), 6(1)(a)
Invoicing recordsTax and commercial lawLegal obligation: KVKK 5/2(ç); GDPR 6(1)(c)
Workspace contentWhatever our customer determinesDetermined by the customer as controller; we process on instructions

07Cookies and browser storage

We use no advertising or analytics cookies anywhere. What the application sets is strictly what it needs to work:

NameTypeWhat it doesLife
zf_access_tokenCookie, HttpOnlyKeeps you signed in. Not readable by scripts.24 hours
zf_user:v1, zf_permissions:v1Local storageRenders your name and menu before the server answersUntil sign-out
zf_lang:v1Local storageRemembers your language so the first screen is not in the wrong oneUntil sign-out
mercon_sidebar_collapsed, dashboard layoutLocal storageYour own interface preferencesUntil you clear them
Cloudflare TurnstileCookie / tokenConfirms a form was submitted by a person, not a scriptShort-lived

Signing out clears the session cookie and the cached identity, including the language cache: the preference belongs to a person, not to a machine.

08Who else processes it

We use a small number of sub-processors. Each is contracted, each gets only what its job requires, and we remain responsible for them.

ProviderWhat forWhat it seesWhere
OVHcloudHosting the application and databaseAll service data, at rest and in processingEuropean Union (France / Germany)
CloudflareDNS, CDN, firewall, bot protection (Turnstile)Request metadata in transit: IP, URL, user agentGlobal edge network
Backblaze B2Off-site encrypted backupsBackup copies of the database and uploaded files[BUCKET REGION: CONFIRM]
ResendSending transactional emailRecipient address and message contentUnited States / EU
SentryError monitoringTechnical traces, user id, page contextEuropean Union
Google FontsWeb fonts on this marketing siteVisitor IP addressGlobal

We will publish changes to this list here before a new sub-processor starts handling customer data. Customers who want advance notice by email can ask at [email protected].

09Where the data physically sits

The application, the database and uploaded files are hosted in the European Union. Backups are copied to an off-site bucket in [BUCKET REGION: CONFIRM].

Where a transfer outside Türkiye or the EEA takes place (for example email delivery or edge caching), it is made under the safeguards those laws require: standard contractual clauses, adequacy, or the undertakings and consent mechanisms of KVKK Article 9, as applicable.

10How long we keep it

WhatKept for
Workspace dataAs long as the customer's account is open. After the agreement ends: 30 days available for export, then deleted from live systems within 90 days
Backups14 days, then overwritten
Account and access recordsAs long as the account exists, and up to 12 months afterwards for security investigation
Audit trail of changesThe life of the workspace; it is the record maintenance decisions rest on
Unfinished signup requestsDeleted within 180 days, automatically, by the database itself
Error reports90 days
Demo and enquiry correspondence24 months from the last contact, unless you ask us to erase it sooner
Invoices and their supporting records10 years, as Turkish commercial and tax law requires

11Your rights, and how to use them

Under KVKK Article 11 and, where it applies, Chapter III of the GDPR, you may ask us: whether we hold data about you; what it is and why; who it has been passed to; to correct it if it is wrong; to erase it or block it; to have a correction or erasure passed on to anyone we shared it with; to object to a decision made purely by automated analysis; and to be compensated for damage caused by unlawful processing. Where the GDPR applies you also have the right to a portable copy and, where processing rests on consent, to withdraw that consent.

Write to [email protected]. We answer within 30 days and free of charge, unless the request is manifestly excessive or repetitive. We may ask you to confirm your identity first, so that a request about your data is not answered to somebody else.

If your data is in your employer's workspace, ask your employer. We cannot correct or erase an employee record on the instruction of anyone other than the customer who controls it, and doing so would let a stranger alter another organisation's records. Write to us anyway if your employer will not act, and we will make contact with them.

If you are not satisfied, you may complain to the Turkish Personal Data Protection Authority (KVKK Kurumu) or, where the GDPR applies, to your local supervisory authority.

12How we protect it

  • Each customer's workspace is isolated by the database itself, through row-level security enforced under the database's own privileges, not only by application code. A query that does not name a tenant fails rather than returning the wrong customer's rows.
  • Traffic is encrypted in transit with TLS.
  • Passwords are stored as salted hashes, never in a form anyone can read back.
  • Sign-in is rate limited per address and per network, and protected against automated attempts by Cloudflare Turnstile.
  • The application connects to the database as an unprivileged role that cannot bypass those isolation rules.
  • Access to production systems is limited to those who need it, over key-based authentication only.
  • Changes to key records are audited, and access sessions are recorded.
  • Backups are taken daily, copied off site, and their restorability is verified automatically.

If a breach affects personal data, we will notify the affected customers without undue delay and support them in meeting their own notification duties. Where we are the controller we will notify the authority and, where required, the individuals, within the time the law allows.

13The mobile app

The Solmex mobile app asks for camera access, used to scan QR labels on equipment and to attach photographs to a record. Photographs you take are uploaded to your employer's workspace.

The app does not collect device location, does not read your contacts, and contains no advertising or third-party analytics software. It keeps a sign-in token on the device so you are not asked to sign in every day; signing out removes it.

14Children

Solmex is a workplace tool sold to organisations and is not directed at children. Accounts are for people aged 18 or over. If we learn that we hold a child's data without a lawful basis, we will erase it.

15Changes to this policy

We will publish any revision here with a new version number and date. Where a change materially affects how we handle personal data, we will tell account administrators by email before it takes effect.

Solmex Privacy Policy, version 1.0. Data protection contact: [email protected]. See also the Terms of Service.

Asset management and maintenance, CMMS and EAM in one. One record per asset, run from the field.

Features
Asset Management Work Orders Warehouse Costs & Fuel
Industries
Fleets & construction Production plants Hotels & resorts Residential complexes All industries
Company
Pricing Book demo Contact About Terms of Service Privacy Policy
© 2026 Solmex Built for the field.