What personal data we hold, why we hold it, where it physically sits, who else touches it, how long it stays, and how you make us do something about it. It also serves as our clarification text (aydınlatma metni) under the KVKK.
Replace every highlighted placeholder below and in the Terms of Service, remove the noindex tag from both files, confirm the backup bucket's region in §8, and make sure [email protected] actually receives mail before this page tells anyone to write to it.
Solmex handles personal data in two capacities, and which one applies changes who you should ask about it.
We are the controller of the data we collect for ourselves: website visitors, signup and demo enquiries, the account and billing contacts of our customers, and support correspondence. Sections 3, 4 and 7 cover this.
We are a processor for everything inside a customer's workspace: the personnel records, documents, readings and messages their people put in. The customer is the controller there. We act on their instructions and do not decide what goes in or why. Section 5 covers this. If you are an employee of a Solmex customer asking about your own record, your employer is the party to ask, and we will help them answer you.
The data controller is [REGISTERED COMPANY NAME], a [COMPANY FORM] registered in Türkiye at [REGISTERED ADDRESS], registration number [MERSIS / TAX NO].
For anything in this document, including a request to exercise your rights, write to [email protected].
This site carries no analytics, no advertising tags and no tracking pixels. We do not know who you are when you read it, and there is no cookie banner because there is nothing to consent to.
Three things still happen when a page loads:
If you book a demo or send an enquiry, we keep what you type (typically a name, a work email address, a company name and your message) to answer you and to follow up about Solmex.
When you sign up, or when an administrator creates an account for you, we hold:
Here we are the processor and the customer is the controller. What a workspace contains depends on which modules that customer uses; across the product it can include:
We do not use any of it for our own purposes. We do not sell it, we do not share it with advertisers, and we do not use it to train machine learning models.
| What | Purpose | Basis (KVKK Art. 5 / GDPR Art. 6) |
|---|---|---|
| Account data | Providing the Service you or your employer contracted for | Necessary for a contract: KVKK 5/2(c); GDPR 6(1)(b) |
| Access and change records | Security, accountability, investigating misuse | Legitimate interest: KVKK 5/2(f); GDPR 6(1)(f) |
| Signup and terms evidence | Proving what was agreed and by whom | Legal obligation and legitimate interest: KVKK 5/2(ç), 5/2(f); GDPR 6(1)(c), 6(1)(f) |
| Error diagnostics | Keeping the Service working | Legitimate interest: KVKK 5/2(f); GDPR 6(1)(f) |
| Demo and enquiry details | Answering you and following up | Steps prior to a contract, and consent for marketing: KVKK 5/1, 5/2(c); GDPR 6(1)(b), 6(1)(a) |
| Invoicing records | Tax and commercial law | Legal obligation: KVKK 5/2(ç); GDPR 6(1)(c) |
| Workspace content | Whatever our customer determines | Determined by the customer as controller; we process on instructions |
We use no advertising or analytics cookies anywhere. What the application sets is strictly what it needs to work:
| Name | Type | What it does | Life |
|---|---|---|---|
| zf_access_token | Cookie, HttpOnly | Keeps you signed in. Not readable by scripts. | 24 hours |
| zf_user:v1, zf_permissions:v1 | Local storage | Renders your name and menu before the server answers | Until sign-out |
| zf_lang:v1 | Local storage | Remembers your language so the first screen is not in the wrong one | Until sign-out |
| mercon_sidebar_collapsed, dashboard layout | Local storage | Your own interface preferences | Until you clear them |
| Cloudflare Turnstile | Cookie / token | Confirms a form was submitted by a person, not a script | Short-lived |
Signing out clears the session cookie and the cached identity, including the language cache: the preference belongs to a person, not to a machine.
We use a small number of sub-processors. Each is contracted, each gets only what its job requires, and we remain responsible for them.
| Provider | What for | What it sees | Where |
|---|---|---|---|
| OVHcloud | Hosting the application and database | All service data, at rest and in processing | European Union (France / Germany) |
| Cloudflare | DNS, CDN, firewall, bot protection (Turnstile) | Request metadata in transit: IP, URL, user agent | Global edge network |
| Backblaze B2 | Off-site encrypted backups | Backup copies of the database and uploaded files | [BUCKET REGION: CONFIRM] |
| Resend | Sending transactional email | Recipient address and message content | United States / EU |
| Sentry | Error monitoring | Technical traces, user id, page context | European Union |
| Google Fonts | Web fonts on this marketing site | Visitor IP address | Global |
We will publish changes to this list here before a new sub-processor starts handling customer data. Customers who want advance notice by email can ask at [email protected].
The application, the database and uploaded files are hosted in the European Union. Backups are copied to an off-site bucket in [BUCKET REGION: CONFIRM].
Where a transfer outside Türkiye or the EEA takes place (for example email delivery or edge caching), it is made under the safeguards those laws require: standard contractual clauses, adequacy, or the undertakings and consent mechanisms of KVKK Article 9, as applicable.
| What | Kept for |
|---|---|
| Workspace data | As long as the customer's account is open. After the agreement ends: 30 days available for export, then deleted from live systems within 90 days |
| Backups | 14 days, then overwritten |
| Account and access records | As long as the account exists, and up to 12 months afterwards for security investigation |
| Audit trail of changes | The life of the workspace; it is the record maintenance decisions rest on |
| Unfinished signup requests | Deleted within 180 days, automatically, by the database itself |
| Error reports | 90 days |
| Demo and enquiry correspondence | 24 months from the last contact, unless you ask us to erase it sooner |
| Invoices and their supporting records | 10 years, as Turkish commercial and tax law requires |
Under KVKK Article 11 and, where it applies, Chapter III of the GDPR, you may ask us: whether we hold data about you; what it is and why; who it has been passed to; to correct it if it is wrong; to erase it or block it; to have a correction or erasure passed on to anyone we shared it with; to object to a decision made purely by automated analysis; and to be compensated for damage caused by unlawful processing. Where the GDPR applies you also have the right to a portable copy and, where processing rests on consent, to withdraw that consent.
Write to [email protected]. We answer within 30 days and free of charge, unless the request is manifestly excessive or repetitive. We may ask you to confirm your identity first, so that a request about your data is not answered to somebody else.
If your data is in your employer's workspace, ask your employer. We cannot correct or erase an employee record on the instruction of anyone other than the customer who controls it, and doing so would let a stranger alter another organisation's records. Write to us anyway if your employer will not act, and we will make contact with them.
If you are not satisfied, you may complain to the Turkish Personal Data Protection Authority (KVKK Kurumu) or, where the GDPR applies, to your local supervisory authority.
If a breach affects personal data, we will notify the affected customers without undue delay and support them in meeting their own notification duties. Where we are the controller we will notify the authority and, where required, the individuals, within the time the law allows.
The Solmex mobile app asks for camera access, used to scan QR labels on equipment and to attach photographs to a record. Photographs you take are uploaded to your employer's workspace.
The app does not collect device location, does not read your contacts, and contains no advertising or third-party analytics software. It keeps a sign-in token on the device so you are not asked to sign in every day; signing out removes it.
Solmex is a workplace tool sold to organisations and is not directed at children. Accounts are for people aged 18 or over. If we learn that we hold a child's data without a lawful basis, we will erase it.
We will publish any revision here with a new version number and date. Where a change materially affects how we handle personal data, we will tell account administrators by email before it takes effect.
Solmex Privacy Policy, version 1.0. Data protection contact: [email protected]. See also the Terms of Service.