Legal
Privacy Policy
Version 1.0, effective 10 October 2026.
This policy explains the personal data Kaabist processes as a controller: about the people who use the panel, the API and the docs. The data your programs collect from websites is yours, and Kaabist processes it for you as a processor under the Data Processing Agreement.
1. Controller
Kaabist Bilişim ve Yazılım Hizmetleri Limited Şirketi, Sinpaş Flatofis, Defterdar, Otakçılar Cd. Blok No: 75, İç Kapı No: 94, 34050 Eyüpsultan, İstanbul, Türkiye, tax number 4842191056 ("Kaabist"). Contact: [email protected].
2. What we process, why, and on what basis
| Data | Purpose | Legal basis |
|---|---|---|
| Account: name, e-mail address, password (stored only as a hash), sign-in method (e-mail link, GitHub, Google), two-factor settings (secret encrypted) | Creating and securing your account | Contract; legitimate interest (security) |
| Organisation membership and role, invitations (invitee e-mail) | Letting teams share work | Contract |
| Sessions: IP address, user agent, times | Keeping you signed in, detecting misuse | Legitimate interest (security) |
| Audit log: who did what (approvals, takeovers, key and role changes, billing changes, exports, deletions), IP address, user agent | Accountability and security of your organisation | Legitimate interest; legal obligation where applicable |
| Billing: plan, credit ledger, Paddle customer reference | Charging for the service | Contract; legal obligation (accounting) |
| Service logs and traces (no page content, no secrets) | Running and debugging the service | Legitimate interest |
| Messages you send us (support, abuse, security reports) | Answering you | Legitimate interest; contract |
| Docs feedback ("Was this helpful?") | Improving the docs | Anonymous: no account, IP address or user agent is stored |
We do not sell personal data, use it for advertising, or profile you. Payment card details are handled by Paddle and never reach Kaabist.
3. How long we keep it
| Data | Kept for |
|---|---|
| Account data | Until you ask [email protected] to delete your account, then removed (audit entries keep a pseudonym) |
| Sessions | 30 days from sign-in, or until you sign out |
| Audit log | Kept; when an organisation is deleted every person in it is replaced by a pseudonym |
| Credit ledger and payment records | As long as accounting law requires |
| Service logs | 30 days; traces 14 days |
| Support and abuse correspondence | 2 years from the last message |
What happens to your organisation's work data is on the data retention page.
4. Who receives it
Our sub-processors (hosting, e-mail delivery, payments through Paddle, and the services listed there), within the limits of their contracts. Members of your organisation see its audit log. We disclose data to authorities only when the law requires it.
5. Where it is processed
Kaabist runs in the European Union (Hetzner, Germany). Some sub-processors are outside the EU or Türkiye; the sub-processor list names the transfer mechanism for each.
6. Your rights
You may ask for access to, correction of, deletion of, and a copy of your personal data, object to processing based on legitimate interest, and restrict processing. Under KVKK you also have the rights in Art. 11. Write to [email protected]; we answer within 30 days. You may complain to your data protection authority (in Türkiye, the Kişisel Verileri Koruma Kurumu).
7. Security
Secrets are encrypted with a key per organisation, wrapped by a master key held separately; API keys are stored only as a hash; access to the platform is logged. See the security policy for how to report a vulnerability.
8. Cookies
See the Cookie Policy: Kaabist uses only cookies that are strictly necessary.
9. Changes
We announce material changes by e-mail and in the panel before they apply.