Bu politika, 6698 sayılı Kişisel Verilerin Korunması Kanunu (“KVKK”) uyarınca, SanvoBI mobil uygulaması ve web paneli (“Uygulama”) kapsamında işlenen kişisel verilere ilişkindir.
SanvoBI, kurumsal kullanıcıların kendi şirketlerinin ERP/veritabanı sistemlerindeki raporlara mobil cihazlarından erişmesini sağlayan bir iş zekâsı uygulamasıdır. Rapor içerikleri (satış, ciro, stok, cari vb. ticari veriler) Sanvo sunucularına kopyalanmaz. Bu veriler, şirketinizin kendi sunucusunda çalışan “SanvoBI Bağlayıcı” yazılımından, şifreli ve sertifika doğrulamalı (TLS + sertifika sabitleme) bir bağlantıyla doğrudan cihazınıza iletilir. Sanvo bulut sistemi yalnızca hesap, yetki ve rapor tanımlarını barındırır.
| Veri | Amaç | Hukuki sebep |
|---|---|---|
| Ad, soyad, kurumsal e-posta | Hesabın oluşturulması, kimlik doğrulama, yetkilendirme | Sözleşmenin ifası (KVKK m.5/2-c) |
| Parola (geri döndürülemez özet olarak) | Kimlik doğrulama | Sözleşmenin ifası |
| Cihaz bilgisi (model, işletim sistemi, cihaz adı) | Yeni cihaz onayı güvenliği, oturum yönetimi, destek | Meşru menfaat (KVKK m.5/2-f) |
| Oturum jetonları | Oturumun sürdürülmesi (yalnızca cihazın güvenli deposunda) | Sözleşmenin ifası |
| Geri bildirim içeriği + uygulama sürümü/cihaz modeli | Kullanıcının gönderdiği hata/öneri bildirimlerinin değerlendirilmesi | Açık rıza (gönderim isteğe bağlıdır) |
İşlemediklerimiz: Konum, rehber, fotoğraf/galeri, takvim verisi toplanmaz. Uygulamada reklam, reklam kimliği (IDFA/AAID) kullanımı, üçüncü taraf analitik veya davranışsal takip YOKTUR.
Sesli soru özelliğini kullandığınızda ses kaydınız, metne çevrilmek üzere cihazınızın işletim sistemi konuşma tanıma servisine (Apple Speech / Google konuşma tanıma) iletilir; bu işleme ilgili sağlayıcının gizlilik koşulları uygulanır. Sanvo'ya yalnızca metne çevrilmiş soru iletilir ve rapor eşleştirmesi için kullanılır. Mikrofon yalnızca siz butona bastığınızda etkinleşir.
Anlık bildirim özelliği etkinleştirildiyse, bildirim iletimi için OneSignal altyapısı üzerinden anonim bir bildirim jetonu işlenir. Bildirim izni tamamen isteğe bağlıdır ve işletim sistemi ayarlarından her zaman kapatılabilir.
Kişisel verileriniz üçüncü kişilere satılmaz ve pazarlama amacıyla paylaşılmaz. Sınırlı aktarımlar: (a) bölüm 5 kapsamında konuşma tanıma sağlayıcısı, (b) bölüm 6 kapsamında bildirim altyapısı, (c) yasal yükümlülük hâlinde yetkili kurumlar. Barındırma: Türkiye.
Hesap verileri, kurumsal üyeliğiniz devam ettiği sürece; hesabın kapatılması hâlinde ilgili mevzuattaki zamanaşımı süreleri boyunca saklanır ve ardından silinir veya anonim hâle getirilir. Cihazdaki oturum ve önbellek verileri çıkış yapıldığında silinir.
SanvoBI hesapları kurumsal aboneliğiniz kapsamında şirket yöneticiniz tarafından oluşturulur ve yönetilir. Hesabınızın ve kişisel verilerinizin silinmesini şirket yöneticinizden ya da doğrudan [email protected] adresine e-posta göndererek talep edebilirsiniz. Talepler en geç 30 gün içinde sonuçlandırılır.
KVKK m.11 uyarınca; verilerinizin işlenip işlenmediğini öğrenme, bilgi talep etme, işlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme, aktarıldığı üçüncü kişileri bilme, eksik/yanlış işlenmişse düzeltilmesini isteme, silinmesini/yok edilmesini isteme, otomatik sistemlerce analiz sonucu aleyhinize bir sonucun ortaya çıkmasına itiraz etme ve zarara uğramanız hâlinde tazminat talep etme haklarına sahipsiniz. Başvurularınızı [email protected] adresine iletebilirsiniz.
Veriler aktarım sırasında TLS ile şifrelenir; bağlayıcı bağlantılarında ek olarak sertifika sabitleme uygulanır. Oturum bilgileri cihazın güvenli deposunda (iOS Keychain / Android Keystore) tutulur. Parolalar geri döndürülemez algoritmalarla özetlenerek saklanır.
Bu politika güncellenebilir; güncel sürüm her zaman bu sayfada yayınlanır. Önemli değişiklikler uygulama içinden duyurulur.
This policy explains, in accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK"), how personal data is processed within the SanvoBI mobile application and web panel (the "App").
SanvoBI is a business-intelligence application that lets corporate users access reports from their own company's ERP/database systems on their mobile devices. Report contents (sales, revenue, stock, receivables and other commercial data) are never copied to Sanvo servers. This data travels directly to your device from the "SanvoBI Connector" software running on your company's own server, over an encrypted, certificate-pinned (TLS) connection. The Sanvo cloud stores only accounts, permissions and report definitions.
| Data | Purpose | Legal basis |
|---|---|---|
| Name, surname, corporate e-mail | Account creation, authentication, authorization | Performance of contract (KVKK art. 5/2-c) |
| Password (stored only as an irreversible hash) | Authentication | Performance of contract |
| Device information (model, OS, device name) | New-device approval security, session management, support | Legitimate interest (KVKK art. 5/2-f) |
| Session tokens | Maintaining your session (kept only in the device's secure storage) | Performance of contract |
| Feedback content + app version/device model | Evaluating bug reports and suggestions you choose to send | Explicit consent (submission is optional) |
What we do NOT process: Location, contacts, photos/gallery and calendar data are not collected. The App contains NO advertising, no advertising identifiers (IDFA/AAID), no third-party analytics and no behavioral tracking.
When you use the voice question feature, your audio is sent to your device operating system's speech recognition service (Apple Speech / Google speech recognition) to be converted to text; that processing is subject to the respective provider's privacy terms. Only the transcribed text of your question is sent to Sanvo, where it is used solely to match you with a report. The microphone is active only while you hold the button.
If push notifications are enabled, an anonymous push token is processed through the OneSignal infrastructure to deliver notifications. Notification permission is entirely optional and can be turned off at any time in your operating-system settings.
Your personal data is never sold and never shared for marketing purposes. Limited transfers: (a) the speech-recognition provider described in section 5, (b) the notification infrastructure described in section 6, and (c) competent authorities where legally required. Hosting: Türkiye.
Account data is kept for as long as your corporate subscription remains active; if the account is closed, data is retained for the limitation periods required by applicable law and then deleted or anonymized. Session and cache data on your device is deleted when you sign out.
SanvoBI accounts are created and managed by your company administrator under your corporate subscription. You may request deletion of your account and personal data from your company administrator or directly by e-mailing [email protected]. Requests are completed within 30 days at the latest.
Under article 11 of KVKK you have the right to learn whether your data is processed, to request information, to learn the purpose of processing and whether data is used accordingly, to know the third parties to whom it is transferred, to request correction of incomplete/inaccurate data, to request deletion or destruction, to object to results produced by automated analysis that adversely affect you, and to claim compensation for damages. You may submit requests to [email protected].
Data is encrypted in transit with TLS; connector connections additionally use certificate pinning. Session credentials are kept in the device's secure storage (iOS Keychain / Android Keystore). Passwords are stored only as irreversible hashes.
This policy may be updated; the current version is always published on this page. Material changes are announced within the App.