This policy explains how we process your personal data when you use Qodify+. It is also our information notice under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK").
This is an English version of the Turkish text. If the two differ, the Turkish text prevails.
1. Scope
This policy applies to:
- the qodifyplus.com website,
- the app.qodifyplus.com web app and the api.qodifyplus.com API,
- the Qodify+ mobile apps, once they are released,
- our app on Meta (Facebook and Instagram), shown as “Qodify Plus”.
It covers:
- people who sign up for and use Qodify+: our individual customers and the users of our business and agency customers,
- people named in billing details,
- people who contact us by email or otherwise,
- visitors to our website.
Our Cookie Policy covers cookies and similar technologies, and our Data Deletion Instructions explain how to ask us to delete your data.
2. Data controller
The data controller for your personal data is Hodox Bilişim ve Yazılım Hizmetleri Limited Şirketi. "Qodify+", "we" and "us" in this policy mean this company.
- Trade name: Hodox Bilişim ve Yazılım Hizmetleri Limited Şirketi
- Address: Kavaklı Mah. Yaman Sk. A No: 19 İç Kapı No: 15, Beylikdüzü/İstanbul
- MERSİS number: 0463143178400001
- Trade registry number: Istanbul Trade Registry Office, 473879-5
- Tax office and number: Beylikdüzü Tax Office, 4631431784
- Phone: +90 537 664 41 03
- Personal data requests: kvkk@qodifyplus.com
- Support: destek@qodifyplus.com
3. The short version
- We process only the data we need to provide the service, keep it secure and meet our legal obligations.
- We do not sell your personal data or use it for advertising.
- We use the advertising data we receive from Meta only to serve you.
- We store your password only as a one-way hash.
- Your card details go from your browser straight to the payment provider; they never reach our servers.
- We never send your name, contact or billing details, password or access tokens to AI providers.
- Our server is in Germany and the AI providers are in the United States, so your data is transferred abroad (section 12).
- To exercise your rights, write to kvkk@qodifyplus.com (sections 15 and 16).
4. The personal data we process
| Category | Data | Source |
|---|---|---|
| Identity and contact | Your name, email address and Turkish mobile number | You |
| Account | A hash of your password, when your phone number was verified, the language of your account emails, your organization's name and type, your organization and workspace memberships and roles | You; your organization's admins |
| Acceptance records | The versions of the terms of use you accepted and of this notice you confirmed reading, with the time; the versions of the pre-contract information form and distance sales contract you confirmed when buying, with the time; if you buy as an individual, your consent to the service starting at once | You |
| Sessions and security | When your sessions started, were last used and ended; the IP address and browser details in our server logs; keyed hashes of your IP address, phone number and email address, used to limit abuse | Your device, automatically |
| Usage and audit records | Important actions in your organization and who took them (such as opening the account, connecting or disconnecting Meta, package changes); credit use (operation type and amount) | Your use of the service, automatically |
| Assistant conversations | What you write to the assistant, its answers and the advertising data used for them | You and the service |
| Meta connection | The ID and name of the Meta business portfolio you connected, the permissions granted, an encrypted copy of the access token and its expiry, who made the connection and when | Meta and you |
| Billing and payments | Billing type (individual or company), name or company name, contact person's first and last name, Turkish ID number or tax ID number and tax office, email, phone, address, city, country and postal code; amounts, dates and status of payments; the payment provider's references; invoices; if you pay with PayTR, the stored card's brand (such as Visa), last four digits and expiry, PayTR's references to the card and the IP address you paid from | You and the payment provider |
| Contact and support | Emails and requests you send us, and our replies | You |
- We never see or store your card number or security code. If you pay with PayTR, we keep the stored card's brand, last four digits and expiry, which PayTR gives us, to show you the card and to remind you before it expires.
- We do not process special categories of personal data (such as health or biometric data). Please do not include them in messages to the assistant or to support.
- Section 8 covers the advertising data we receive from Meta.
5. Purposes and legal bases
We process your data for the purposes below, on the legal bases in Article 5(2) of the KVKK. The letters are explained under the table.
| Purpose | Data | Legal basis |
|---|---|---|
| Opening your account, verifying your phone number, signing you in, managing your organization and workspaces | Identity and contact, account, sessions | (c) |
| Resetting your password with an SMS code and telling you when it changes | Identity and contact, account | (c) |
| Preventing fake sign-ups and SMS abuse; allowing one account and one trial per phone number | Phone number and its keyed hash; keyed hashes of IP and email addresses | (f) |
| Recording the versions of the documents you confirmed, and proving them if needed | Acceptance records | (c), (e) |
| Connecting Meta, syncing your advertising data and reporting on it | Meta connection, advertising data | (c) |
| Letting the assistant answer your questions | Assistant conversations | (c) |
| Trials, packages, credits, payments and invoices | Billing and payments, identity and contact | (c), (f); for issuing and keeping invoices, (a) and (ç) |
| Charging the monthly renewals to the card PayTR stores, and reminding you before it expires | Billing and payments: the stored card's details, PayTR's references to it and the IP address you paid from | (c) |
| Service emails and notices (such as the welcome email, password changes, package and billing notices) | Identity and contact | (c) |
| Keeping the service secure, preventing unauthorised access and abuse, fixing errors, recording important actions | Sessions and security, usage and audit records | (f); where the law requires it, (ç) |
| Answering your support requests and opening a support session where needed | Contact and support; the data of the workspace concerned | (c), (f) |
| Measuring and improving the service | Usage records, aggregated wherever possible | (f) |
| Remembering your language and appearance choices | Preference cookies | (c) |
| Meeting legal obligations and answering requests from authorities | The data required | (ç) |
| Protecting our rights in a dispute | The data required | (e) |
- (a) It is expressly provided for by law.
- (c) It is necessary to process the personal data of the parties to a contract, provided that it is directly related to entering into or performing that contract.
- (ç) It is necessary for us to comply with a legal obligation.
- (e) It is necessary to establish, exercise or protect a right.
- (f) It is necessary for our legitimate interests, provided that it does not harm your fundamental rights and freedoms.
We do not rely on your explicit consent for any of this. Confirming at sign-up that you have read this notice is not consent; it records that you were informed. We do not send promotional commercial messages (section 18).
6. How we collect data
We collect your data electronically, by fully or partly automated means, from these sources:
- You: through the sign-up form, the web app, the billing details form and email.
- Your organization: when an admin adds you to an organization or workspace.
- Meta: when you connect your Meta account and grant access, through Meta's APIs.
- The payment provider: payment results and references; with PayTR, the stored card's brand, last four digits and expiry.
- Automatically: session and server logs created while you use the service, cookies and similar technologies.
Our website sets no cookies, runs no analytics and loads nothing from other sites. When you visit it, our server processes technical data such as your IP address in order to deliver the page.
7. The AI assistant
- Software does the maths. Our software calculates figures such as spend, cost per purchase and return on ad spend; the AI explains the results.
- Providers: we use the API services of Anthropic, OpenAI and Google (Gemini). These companies are in the United States and process data on our behalf, as our processors. We decide which provider answers a question; if one cannot answer, the question may go to another. We never send your real data to Google's free tier.
- What we send: your question, the latest messages of the conversation, the answer language, the date and time, and the advertising data the answer needs (such as ad account and campaign names, spend and purchase figures).
- What we never send: your name, email address, phone number, billing details, password or access tokens. We do not process the personal data of the people who buy from your store at all (section 9).
- Training and retention: we work with the providers under terms that do not allow them to use data sent through their APIs to train their models. We use the most restrictive retention options they offer; for example, we ask them not to store answers. The providers may keep data for a limited period set out in their terms, for example to monitor abuse.
- Your conversations: the master copy of each conversation is in our database and is kept until you delete it. Only you can see your conversations; your organization's owners, other users and our support team cannot. When you delete a conversation, its questions and answers are deleted for good.
- Answers are suggestions. They may be wrong or incomplete. The assistant cannot change anything in your ad accounts.
- No automated decisions. The assistant assesses advertising data, not people, and makes no automated decision about you that affects you.
Please do not write other people's personal data or special categories of personal data to the assistant.
8. Data from Meta (the “Qodify Plus” app)
We start receiving data from Meta when an owner or admin of your organization connects a Meta account through Facebook Login for Business and grants the “Qodify Plus” app access.
Permissions: today we ask only for read permissions: ads_read and business_management. We will ask for ads_management, which allows changes to your ad accounts, only when features for changes that you approve become available.
The data we receive:
- the ID and name of the business portfolio that granted access,
- ad accounts: name, currency, time zone and status,
- campaigns, ad sets and ads: structural details such as name, status, objective and budget,
- ad creatives: headline, text, link and image or video references,
- daily performance data: spend, impressions, reach, clicks, link clicks and conversions such as purchases and their value.
Most of this data belongs to your business. Purchase figures are aggregates and identify no one. Ad content may include people's names or images.
How we use it: only to serve you: to sync the data, show your reports and let the assistant answer your questions. In addition:
- We do not sell, rent or license data we receive from Meta.
- We do not use one customer's data for another customer or for our own purposes.
- We do not use this data to build profiles of people or for retargeting, and we do not pass it to ad networks or data brokers.
- We do not use it for eligibility decisions such as housing, employment, credit or insurance.
Separation: each organization's Meta data is kept apart from every other organization's. If the same ad account is connected to two organizations, each gets its own copy with its own access token, and data fetched with one organization's token is never shown to the other. Within your organization, only users who can reach the workspaces an ad account is assigned to can see its data.
The access token: we store the Meta access token encrypted. It is never sent to AI models, never written to logs and never sent to your browser.
Retention and deletion: we keep Meta data while the connection lasts. When you disconnect, we delete our copy of the access token at once, ask Meta to revoke it, and delete the advertising data that came through the connection in a background job that starts straight away. Step-by-step instructions: Data Deletion Instructions.
9. Data we process for our customers
- Qodify+ does not process the personal data of the people who buy from your store (your end customers) today. The integration with Qodify store data is not available yet; we will update this policy before it is.
- Where your advertising data contains personal data (such as a person shown in a creative), we process it on our customer's behalf and on its instructions. Agencies are responsible for having the necessary agreements with their own clients.
- A data processing agreement for our business and agency customers will be prepared and published separately.
10. Who receives your data
We do not sell your personal data. We share it only with the recipients below, for the stated purpose and only as much as needed.
| Recipient | Purpose | Data | Location |
|---|---|---|---|
| Authorised users in your organization | Teamwork | Your name, email address, role and actions in the organization | — |
| Hetzner Online GmbH | Hosting our server | All data processed in the service is stored on this server | Germany |
| Anthropic, OpenAI and Google | Assistant answers | The data listed in section 7 | United States |
| NetGSM | Sending verification and password reset codes by SMS | Your phone number and the SMS text | Türkiye |
| Our mail server | Sending service emails | Your email address and the content of the email | Germany |
| The payment provider (PayTR or iyzico; the payment page names the one in use) | Taking payments, storing your card and charging the monthly renewals | Your billing details, the amount, the package's name and your IP address; your card details go from your browser to the provider | Türkiye |
| Our accountants, lawyers and auditors | Accounting, tax and legal obligations | The data required | Türkiye |
| The Turkish Revenue Administration, public authorities and courts | e-Fatura and e-Arşiv invoices; legal obligations and official requests | The data required | Türkiye |
- Processors: the providers of hosting, AI, SMS and email services process data only on our behalf and on our instructions.
- The payment provider is an independent controller of payment data, and its own privacy policy also applies.
- Meta is the source of the advertising data and an independent controller of the data on its platform. Our requests to Meta only read the data you gave us access to; they do not pass our users' personal data to Meta.
- Business changes: in a merger, demerger or transfer of the business, your data may pass to the new controller, limited to the purposes in this policy. We will tell you in advance.
11. Access by our staff
- Our staff have no standing access to customer data.
- To grant trials and credits, authorised administrators see only an organization's package, subscription status, period and credit balance.
- Staff who issue invoices see your billing details and the amount for the invoice they issue. Every view is recorded.
- If support needs access to your data, a support session is opened that records the reason, is limited to one workspace, lasts at most 4 hours and allows reading only. Opening the session and every request in it are recorded. Support sessions cannot see your assistant conversations. Organization owners can ask us for the list of support sessions opened.
- Our staff sign in with a password and a second factor. Their actions are kept in a separate audit log for at least a year.
12. Transfers abroad
The following are transfers abroad under Article 9 of the KVKK:
- Our server is in Germany, in a data centre of Hetzner Online GmbH. All personal data processed in the service is stored on this server.
- The AI providers Anthropic, OpenAI and Google are in the United States.
- Our mail server is also in Germany; your email address and the content of emails are processed on it.
We base these transfers on the standard contracts published by the Personal Data Protection Board. Standard contracts are notified to the Personal Data Protection Authority within five business days of signing. We do not rely on your explicit consent for these regular transfers.
We keep transferred data to a minimum and encrypt it in transit. You can ask us which safeguard we rely on for each transfer.
13. How long we keep data
We keep data for as long as the purpose requires and for any period the law requires. After that we delete, destroy or anonymise it.
| Data | Retention |
|---|---|
| Unverified sign-up forms | 30 minutes; expired ones are deleted every hour |
| SMS verification codes | Valid for 3 minutes; only their hashes are stored, and they are deleted regularly |
| Account details | While your account is open; deleted within 30 days of your deletion request |
| Keyed hash of your phone number (for the trial rule) | 2 years after your account is deleted |
| Sessions | At most 30 days; a session unused for 7 days ends. Records of ended sessions are deleted regularly |
| Keyed hashes used for abuse limits | At most 1 day |
| Server logs (may contain IP addresses and browser details) | At most 1 year |
| Data of an organization whose subscription or trial has ended | Kept read-only for 90 days after the end, then deleted after a notice |
| Assistant conversations | Until you delete them; deleted with the organization |
| Meta access token | While the connection lasts; our copy is deleted as soon as you disconnect |
| Advertising data from Meta | While the connection lasts; deleted after you disconnect, in a background job that starts straight away |
| Invoices, billing details and payment records | For the period tax and commercial law requires: 10 years |
| The stored card's details and PayTR's references to it, with the IP address you paid from | While the card pays your renewals; deleted at PayTR and here when the subscription ends or another card replaces it |
| The IP address on a card payment | Until PayTR reports the payment's result, at most 1 day; afterwards kept only with the stored card |
| Acceptance records for the terms of use and this notice | While your account exists |
| Acceptance records for purchases | The same period as invoices: 10 years |
| Audit records | While the organization exists; afterwards kept stripped of personal data |
| Support correspondence | 2 years after the request is closed |
| Recipient addresses in the email queue | Deleted once the email is sent or delivery attempts end (within 24 hours at most) |
| Backups | Overwritten on a rolling basis within 7 days |
| Cookies | As set out in the Cookie Policy |
14. How we protect your data
- Customer separation: each organization's data is separated from all others by row-level security in the database.
- Encryption: access tokens and other secrets are stored encrypted. All connections are encrypted with TLS.
- Passwords and codes: passwords are hashed with Argon2id. Verification codes, and the phone numbers in trial records, are stored as keyed hashes.
- Sessions: sessions are kept on the server. Your browser holds only an httpOnly, Secure, SameSite=Strict session cookie.
- Access control: we use role-based access; users see only the data they are allowed to access.
- Audit trail: important actions are recorded in records that cannot be altered.
- Card data: your card number and security code go from your browser straight to the payment provider. With PayTR, our card page sends them to PayTR without our servers receiving them, and the page loads nothing from other sites. PayTR's references to a stored card are stored encrypted.
- Breach notification: if a personal data breach occurs, we notify the Personal Data Protection Board and the people affected within the period the law requires.
No system is completely secure. Do not reuse your password on other services, and write to destek@qodifyplus.com straight away if you notice anything suspicious.
15. Your rights
Under Article 11 of the KVKK, you have the right to:
- learn whether we process your personal data,
- request information about that processing,
- learn the purpose of the processing and whether your data is used accordingly,
- know the third parties in Türkiye or abroad to whom your data has been transferred,
- ask us to correct your data if it is incomplete or inaccurate, and to pass the correction on to those third parties,
- ask us to delete or destroy your data under the conditions in Article 7 of the KVKK, and to pass this on to those third parties,
- object to a result against you that arises solely from automated analysis of your data,
- claim compensation if you suffer damage because your data was processed unlawfully.
You can do some of this directly in the web app: change your password, delete your assistant conversations and disconnect Meta. Our Data Deletion Instructions explain how to ask us to delete your account or your data.
16. How to make a request
You can send your request, in Turkish, in any of these ways:
- Email: from the email address registered with us, to kvkk@qodifyplus.com.
- With a secure electronic or mobile signature: send the application you signed with one of them to kvkk@qodifyplus.com.
- In writing: a signed letter to Kavaklı Mah. Yaman Sk. A No: 19 İç Kapı No: 15, Beylikdüzü/İstanbul, delivered by hand, through a notary or by registered mail with return receipt.
Your request must include:
- your first and last name, and your signature for written requests,
- your Turkish ID number if you are a Turkish citizen; otherwise your nationality and your passport number or national ID number, if any,
- your residential or business address for official notices,
- your email address, phone and fax number for notifications, if any,
- what you are asking for.
We may ask for more information to verify your identity. We answer as quickly as the request allows and within 30 days at the latest, free of charge. If the request involves an additional cost, we may charge the fee set by the Personal Data Protection Board.
If we reject your request, if you find our answer insufficient, or if we do not answer in time, you can complain to the Personal Data Protection Board within 30 days of learning our answer, and in any case within 60 days of your request.
17. Children
Qodify+ is not intended for anyone under 18. We do not knowingly collect children's data; if we find any, we delete it.
18. Promotional messages
We send only service messages, such as verification codes, account and security notices, and package and billing notices. We do not send promotional commercial messages. If we ever want to, we will do so only with your consent and in line with the law.
19. Changes to this policy
We update this policy when the service, the law or our processing changes. The date of each version is shown on this page, together with a list of earlier versions. We will tell you about significant changes by email or in the web app before they take effect.
20. Contact
- Questions and requests about your personal data: kvkk@qodifyplus.com
- Other questions: destek@qodifyplus.com
- Post: Hodox Bilişim ve Yazılım Hizmetleri Limited Şirketi, Kavaklı Mah. Yaman Sk. A No: 19 İç Kapı No: 15, Beylikdüzü/İstanbul
Related documents: Terms of Use, Cookie Policy and Data Deletion Instructions.
Version of this policy: 2 October 2026.