Skip to content
  • How it works
  • Pricing
  • FAQ
  • Contact
TürkçeSign inTry it free
  • How it works
  • Pricing
  • FAQ
  • Contact
Try it freeSign inTürkçe

Legal

Privacy Policy and Information Notice

Earlier version: October 1, 2026

This is an earlier version of the text. Read the current version

Contents

  1. 1. Scope
  2. 2. Data controller
  3. 3. The short version
  4. 4. The personal data we process
  5. 5. Purposes and legal bases
  6. 6. How we collect data
  7. 7. The AI assistant
  8. 8. Data from Meta (the “Qodify Plus” app)
  9. 9. Data we process for our customers
  10. 10. Who receives your data
  11. 11. Access by our staff
  12. 12. Transfers abroad
  13. 13. How long we keep data
  14. 14. How we protect your data
  15. 15. Your rights
  16. 16. How to make a request
  17. 17. Children
  18. 18. Promotional messages
  19. 19. Changes to this policy
  20. 20. Contact
Contents
  1. 1. Scope
  2. 2. Data controller
  3. 3. The short version
  4. 4. The personal data we process
  5. 5. Purposes and legal bases
  6. 6. How we collect data
  7. 7. The AI assistant
  8. 8. Data from Meta (the “Qodify Plus” app)
  9. 9. Data we process for our customers
  10. 10. Who receives your data
  11. 11. Access by our staff
  12. 12. Transfers abroad
  13. 13. How long we keep data
  14. 14. How we protect your data
  15. 15. Your rights
  16. 16. How to make a request
  17. 17. Children
  18. 18. Promotional messages
  19. 19. Changes to this policy
  20. 20. Contact

This policy explains how we process your personal data when you use Qodify+. It is also our information notice under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK").

This is an English version of the Turkish text. If the two differ, the Turkish text prevails.

1. Scope

This policy applies to:

  • the qodifyplus.com website,
  • the app.qodifyplus.com web app and the api.qodifyplus.com API,
  • the Qodify+ mobile apps, once they are released,
  • our app on Meta (Facebook and Instagram), shown as “Qodify Plus”.

It covers:

  • people who sign up for and use Qodify+: our individual customers and the users of our business and agency customers,
  • people named in billing details,
  • people who contact us by email or otherwise,
  • visitors to our website.

Our Cookie Policy covers cookies and similar technologies, and our Data Deletion Instructions explain how to ask us to delete your data.

2. Data controller

The data controller for your personal data is Hodox Bilişim ve Yazılım Hizmetleri Limited Şirketi. "Qodify+", "we" and "us" in this policy mean this company.

  • Trade name: Hodox Bilişim ve Yazılım Hizmetleri Limited Şirketi
  • Address: Kavaklı Mah. Yaman Sk. A No: 19 İç Kapı No: 15, Beylikdüzü/İstanbul
  • MERSİS number: 0463143178400001
  • Trade registry number: Istanbul Trade Registry Office, 473879-5
  • Tax office and number: Beylikdüzü Tax Office, 4631431784
  • Phone: +90 537 664 41 03
  • Personal data requests: kvkk@qodifyplus.com
  • Support: destek@qodifyplus.com

3. The short version

  • We process only the data we need to provide the service, keep it secure and meet our legal obligations.
  • We do not sell your personal data or use it for advertising.
  • We use the advertising data we receive from Meta only to serve you.
  • We store your password only as a one-way hash.
  • You enter your card details on the payment provider's page; they never reach us.
  • We never send your name, contact or billing details, password or access tokens to AI providers.
  • Our server is in Germany and the AI providers are in the United States, so your data is transferred abroad (section 12).
  • To exercise your rights, write to kvkk@qodifyplus.com (sections 15 and 16).

4. The personal data we process

CategoryDataSource
Identity and contactYour name, email address and Turkish mobile numberYou
AccountA hash of your password, when your phone number was verified, the language of your account emails, your organization's name and type, your organization and workspace memberships and rolesYou; your organization's admins
Acceptance recordsThe versions of the terms of use you accepted and of this notice you confirmed reading, with the time; the versions of the pre-contract information form and distance sales contract you confirmed when buying, with the time; if you buy as an individual, your consent to the service starting at onceYou
Sessions and securityWhen your sessions started, were last used and ended; the IP address and browser details in our server logs; keyed hashes of your IP address, phone number and email address, used to limit abuseYour device, automatically
Usage and audit recordsImportant actions in your organization and who took them (such as opening the account, connecting or disconnecting Meta, package changes); credit use (operation type and amount)Your use of the service, automatically
Assistant conversationsWhat you write to the assistant, its answers and the advertising data used for themYou and the service
Meta connectionThe ID and name of the Meta business portfolio you connected, the permissions granted, an encrypted copy of the access token and its expiry, who made the connection and whenMeta and you
Billing and paymentsBilling type (individual or company), name or company name, contact person's first and last name, Turkish ID number or tax ID number and tax office, email, phone, address, city, country and postal code; amounts, dates and status of payments; the payment provider's references; invoicesYou and the payment provider
Contact and supportEmails and requests you send us, and our repliesYou
  • We never see or store your card number, expiry date or security code.
  • We do not process special categories of personal data (such as health or biometric data). Please do not include them in messages to the assistant or to support.
  • Section 8 covers the advertising data we receive from Meta.

5. Purposes and legal bases

We process your data for the purposes below, on the legal bases in Article 5(2) of the KVKK. The letters are explained under the table.

PurposeDataLegal basis
Opening your account, verifying your phone number, signing you in, managing your organization and workspacesIdentity and contact, account, sessions(c)
Resetting your password with an SMS code and telling you when it changesIdentity and contact, account(c)
Preventing fake sign-ups and SMS abuse; allowing one account and one trial per phone numberPhone number and its keyed hash; keyed hashes of IP and email addresses(f)
Recording the versions of the documents you confirmed, and proving them if neededAcceptance records(c), (e)
Connecting Meta, syncing your advertising data and reporting on itMeta connection, advertising data(c)
Letting the assistant answer your questionsAssistant conversations(c)
Trials, packages, credits, payments and invoicesBilling and payments, identity and contact(c), (f); for issuing and keeping invoices, (a) and (ç)
Service emails and notices (such as the welcome email, password changes, package and billing notices)Identity and contact(c)
Keeping the service secure, preventing unauthorised access and abuse, fixing errors, recording important actionsSessions and security, usage and audit records(f); where the law requires it, (ç)
Answering your support requests and opening a support session where neededContact and support; the data of the workspace concerned(c), (f)
Measuring and improving the serviceUsage records, aggregated wherever possible(f)
Remembering your language and appearance choicesPreference cookies(c)
Meeting legal obligations and answering requests from authoritiesThe data required(ç)
Protecting our rights in a disputeThe data required(e)
  • (a) It is expressly provided for by law.
  • (c) It is necessary to process the personal data of the parties to a contract, provided that it is directly related to entering into or performing that contract.
  • (ç) It is necessary for us to comply with a legal obligation.
  • (e) It is necessary to establish, exercise or protect a right.
  • (f) It is necessary for our legitimate interests, provided that it does not harm your fundamental rights and freedoms.

We do not rely on your explicit consent for any of this. Confirming at sign-up that you have read this notice is not consent; it records that you were informed. We do not send promotional commercial messages (section 18).

6. How we collect data

We collect your data electronically, by fully or partly automated means, from these sources:

  • You: through the sign-up form, the web app, the billing details form and email.
  • Your organization: when an admin adds you to an organization or workspace.
  • Meta: when you connect your Meta account and grant access, through Meta's APIs.
  • The payment provider: payment results and references.
  • Automatically: session and server logs created while you use the service, cookies and similar technologies.

Our website sets no cookies, runs no analytics and loads nothing from other sites. When you visit it, our server processes technical data such as your IP address in order to deliver the page.

7. The AI assistant

  • Software does the maths. Our software calculates figures such as spend, cost per purchase and return on ad spend; the AI explains the results.
  • Providers: we use the API services of Anthropic, OpenAI and Google (Gemini). These companies are in the United States and process data on our behalf, as our processors. We decide which provider answers a question; if one cannot answer, the question may go to another. We never send your real data to Google's free tier.
  • What we send: your question, the latest messages of the conversation, the answer language, the date and time, and the advertising data the answer needs (such as ad account and campaign names, spend and purchase figures).
  • What we never send: your name, email address, phone number, billing details, password or access tokens. We do not process the personal data of the people who buy from your store at all (section 9).
  • Training and retention: we work with the providers under terms that do not allow them to use data sent through their APIs to train their models. We use the most restrictive retention options they offer; for example, we ask them not to store answers. The providers may keep data for a limited period set out in their terms, for example to monitor abuse.
  • Your conversations: the master copy of each conversation is in our database and is kept until you delete it. Only you can see your conversations; your organization's owners, other users and our support team cannot. When you delete a conversation, its questions and answers are deleted for good.
  • Answers are suggestions. They may be wrong or incomplete. The assistant cannot change anything in your ad accounts.
  • No automated decisions. The assistant assesses advertising data, not people, and makes no automated decision about you that affects you.

Please do not write other people's personal data or special categories of personal data to the assistant.

8. Data from Meta (the “Qodify Plus” app)

We start receiving data from Meta when an owner or admin of your organization connects a Meta account through Facebook Login for Business and grants the “Qodify Plus” app access.

Permissions: today we ask only for read permissions: ads_read and business_management. We will ask for ads_management, which allows changes to your ad accounts, only when features for changes that you approve become available.

The data we receive:

  • the ID and name of the business portfolio that granted access,
  • ad accounts: name, currency, time zone and status,
  • campaigns, ad sets and ads: structural details such as name, status, objective and budget,
  • ad creatives: headline, text, link and image or video references,
  • daily performance data: spend, impressions, reach, clicks, link clicks and conversions such as purchases and their value.

Most of this data belongs to your business. Purchase figures are aggregates and identify no one. Ad content may include people's names or images.

How we use it: only to serve you: to sync the data, show your reports and let the assistant answer your questions. In addition:

  • We do not sell, rent or license data we receive from Meta.
  • We do not use one customer's data for another customer or for our own purposes.
  • We do not use this data to build profiles of people or for retargeting, and we do not pass it to ad networks or data brokers.
  • We do not use it for eligibility decisions such as housing, employment, credit or insurance.

Separation: each organization's Meta data is kept apart from every other organization's. If the same ad account is connected to two organizations, each gets its own copy with its own access token, and data fetched with one organization's token is never shown to the other. Within your organization, only users who can reach the workspaces an ad account is assigned to can see its data.

The access token: we store the Meta access token encrypted. It is never sent to AI models, never written to logs and never sent to your browser.

Retention and deletion: we keep Meta data while the connection lasts. When you disconnect, we delete our copy of the access token at once, ask Meta to revoke it, and delete the advertising data that came through the connection in a background job that starts straight away. Step-by-step instructions: Data Deletion Instructions.

9. Data we process for our customers

  • Qodify+ does not process the personal data of the people who buy from your store (your end customers) today. The integration with Qodify store data is not available yet; we will update this policy before it is.
  • Where your advertising data contains personal data (such as a person shown in a creative), we process it on our customer's behalf and on its instructions. Agencies are responsible for having the necessary agreements with their own clients.
  • A data processing agreement for our business and agency customers will be prepared and published separately.

10. Who receives your data

We do not sell your personal data. We share it only with the recipients below, for the stated purpose and only as much as needed.

RecipientPurposeDataLocation
Authorised users in your organizationTeamworkYour name, email address, role and actions in the organization—
Hetzner Online GmbHHosting our serverAll data processed in the service is stored on this serverGermany
Anthropic, OpenAI and GoogleAssistant answersThe data listed in section 7United States
NetGSMSending verification and password reset codes by SMSYour phone number and the SMS textTürkiye
Our mail serverSending service emailsYour email address and the content of the emailGermany
The payment provider (currently iyzico)Taking payments, storing your card and charging monthly renewalsYour billing details, the amount and, for some payments, your IP addressTürkiye
Our accountants, lawyers and auditorsAccounting, tax and legal obligationsThe data requiredTürkiye
The Turkish Revenue Administration, public authorities and courtse-Fatura and e-Arşiv invoices; legal obligations and official requestsThe data requiredTürkiye
  • Processors: the providers of hosting, AI, SMS and email services process data only on our behalf and on our instructions.
  • The payment provider is an independent controller of payment data, and its own privacy policy also applies.
  • Meta is the source of the advertising data and an independent controller of the data on its platform. Our requests to Meta only read the data you gave us access to; they do not pass our users' personal data to Meta.
  • Business changes: in a merger, demerger or transfer of the business, your data may pass to the new controller, limited to the purposes in this policy. We will tell you in advance.

11. Access by our staff

  • Our staff have no standing access to customer data.
  • To grant trials and credits, authorised administrators see only an organization's package, subscription status, period and credit balance.
  • Staff who issue invoices see your billing details and the amount for the invoice they issue. Every view is recorded.
  • If support needs access to your data, a support session is opened that records the reason, is limited to one workspace, lasts at most 4 hours and allows reading only. Opening the session and every request in it are recorded. Support sessions cannot see your assistant conversations. Organization owners can ask us for the list of support sessions opened.
  • Our staff sign in with a password and a second factor. Their actions are kept in a separate audit log for at least a year.

12. Transfers abroad

The following are transfers abroad under Article 9 of the KVKK:

  • Our server is in Germany, in a data centre of Hetzner Online GmbH. All personal data processed in the service is stored on this server.
  • The AI providers Anthropic, OpenAI and Google are in the United States.
  • Our mail server is also in Germany; your email address and the content of emails are processed on it.

We base these transfers on the standard contracts published by the Personal Data Protection Board. Standard contracts are notified to the Personal Data Protection Authority within five business days of signing. We do not rely on your explicit consent for these regular transfers.

We keep transferred data to a minimum and encrypt it in transit. You can ask us which safeguard we rely on for each transfer.

13. How long we keep data

We keep data for as long as the purpose requires and for any period the law requires. After that we delete, destroy or anonymise it.

DataRetention
Unverified sign-up forms30 minutes; expired ones are deleted every hour
SMS verification codesValid for 3 minutes; only their hashes are stored, and they are deleted regularly
Account detailsWhile your account is open; deleted within 30 days of your deletion request
Keyed hash of your phone number (for the trial rule)2 years after your account is deleted
SessionsAt most 30 days; a session unused for 7 days ends. Records of ended sessions are deleted regularly
Keyed hashes used for abuse limitsAt most 1 day
Server logs (may contain IP addresses and browser details)At most 1 year
Data of an organization whose subscription or trial has endedKept read-only for 90 days after the end, then deleted after a notice
Assistant conversationsUntil you delete them; deleted with the organization
Meta access tokenWhile the connection lasts; our copy is deleted as soon as you disconnect
Advertising data from MetaWhile the connection lasts; deleted after you disconnect, in a background job that starts straight away
Invoices, billing details and payment recordsFor the period tax and commercial law requires: 10 years
Acceptance records for the terms of use and this noticeWhile your account exists
Acceptance records for purchasesThe same period as invoices: 10 years
Audit recordsWhile the organization exists; afterwards kept stripped of personal data
Support correspondence2 years after the request is closed
Recipient addresses in the email queueDeleted once the email is sent or delivery attempts end (within 24 hours at most)
BackupsOverwritten on a rolling basis within 7 days
CookiesAs set out in the Cookie Policy

14. How we protect your data

  • Customer separation: each organization's data is separated from all others by row-level security in the database.
  • Encryption: access tokens and other secrets are stored encrypted. All connections are encrypted with TLS.
  • Passwords and codes: passwords are hashed with Argon2id. Verification codes, and the phone numbers in trial records, are stored as keyed hashes.
  • Sessions: sessions are kept on the server. Your browser holds only an httpOnly, Secure, SameSite=Strict session cookie.
  • Access control: we use role-based access; users see only the data they are allowed to access.
  • Audit trail: important actions are recorded in records that cannot be altered.
  • Card data: processed only on the payment provider's page.
  • Breach notification: if a personal data breach occurs, we notify the Personal Data Protection Board and the people affected within the period the law requires.

No system is completely secure. Do not reuse your password on other services, and write to destek@qodifyplus.com straight away if you notice anything suspicious.

15. Your rights

Under Article 11 of the KVKK, you have the right to:

  • learn whether we process your personal data,
  • request information about that processing,
  • learn the purpose of the processing and whether your data is used accordingly,
  • know the third parties in Türkiye or abroad to whom your data has been transferred,
  • ask us to correct your data if it is incomplete or inaccurate, and to pass the correction on to those third parties,
  • ask us to delete or destroy your data under the conditions in Article 7 of the KVKK, and to pass this on to those third parties,
  • object to a result against you that arises solely from automated analysis of your data,
  • claim compensation if you suffer damage because your data was processed unlawfully.

You can do some of this directly in the web app: change your password, delete your assistant conversations and disconnect Meta. Our Data Deletion Instructions explain how to ask us to delete your account or your data.

16. How to make a request

You can send your request, in Turkish, in any of these ways:

  • Email: from the email address registered with us, to kvkk@qodifyplus.com.
  • With a secure electronic or mobile signature: send the application you signed with one of them to kvkk@qodifyplus.com.
  • In writing: a signed letter to Kavaklı Mah. Yaman Sk. A No: 19 İç Kapı No: 15, Beylikdüzü/İstanbul, delivered by hand, through a notary or by registered mail with return receipt.

Your request must include:

  • your first and last name, and your signature for written requests,
  • your Turkish ID number if you are a Turkish citizen; otherwise your nationality and your passport number or national ID number, if any,
  • your residential or business address for official notices,
  • your email address, phone and fax number for notifications, if any,
  • what you are asking for.

We may ask for more information to verify your identity. We answer as quickly as the request allows and within 30 days at the latest, free of charge. If the request involves an additional cost, we may charge the fee set by the Personal Data Protection Board.

If we reject your request, if you find our answer insufficient, or if we do not answer in time, you can complain to the Personal Data Protection Board within 30 days of learning our answer, and in any case within 60 days of your request.

17. Children

Qodify+ is not intended for anyone under 18. We do not knowingly collect children's data; if we find any, we delete it.

18. Promotional messages

We send only service messages, such as verification codes, account and security notices, and package and billing notices. We do not send promotional commercial messages. If we ever want to, we will do so only with your consent and in line with the law.

19. Changes to this policy

We update this policy when the service, the law or our processing changes. The date of each version is shown on this page, together with a list of earlier versions. We will tell you about significant changes by email or in the web app before they take effect.

20. Contact

  • Questions and requests about your personal data: kvkk@qodifyplus.com
  • Other questions: destek@qodifyplus.com
  • Post: Hodox Bilişim ve Yazılım Hizmetleri Limited Şirketi, Kavaklı Mah. Yaman Sk. A No: 19 İç Kapı No: 15, Beylikdüzü/İstanbul

Related documents: Terms of Use, Cookie Policy and Data Deletion Instructions.

Version of this policy: 1 October 2026.

Qodify+

Intelligence for your ads, a plus for your sales.

This site sets no cookies and does not track your visit.

Product

  • How it works
  • Pricing
  • FAQ
  • Contact

Legal

  • Privacy policy and notice
  • Terms of use
  • Cookie policy
  • Data deletion instructions
  • Distance sales contract
  • Pre-contract information form
  • Cancellation and refund terms

Company

Hodox Bilişim ve Yazılım Hizmetleri Limited ŞirketiKavaklı Mah. Yaman Sk. A No: 19 İç Kapı No: 15, Beylikdüzü/İstanbulMERSİS: 0463143178400001Phone: +90 537 664 41 03Support: destek@qodifyplus.com

© 2026 Qodify+. All rights reserved.

Türkçe