Legal

Privacy Policy

Version 1.0, effective 10 October 2026.

This policy explains the personal data Kaabist processes as a controller: about the people who use the panel, the API and the docs. The data your programs collect from websites is yours, and Kaabist processes it for you as a processor under the Data Processing Agreement.

1. Controller

Kaabist Bilişim ve Yazılım Hizmetleri Limited Şirketi, Sinpaş Flatofis, Defterdar, Otakçılar Cd. Blok No: 75, İç Kapı No: 94, 34050 Eyüpsultan, İstanbul, Türkiye, tax number 4842191056 ("Kaabist"). Contact: [email protected].

2. What we process, why, and on what basis

DataPurposeLegal basis
Account: name, e-mail address, password (stored only as a hash), sign-in method (e-mail link, GitHub, Google), two-factor settings (secret encrypted)Creating and securing your accountContract; legitimate interest (security)
Organisation membership and role, invitations (invitee e-mail)Letting teams share workContract
Sessions: IP address, user agent, timesKeeping you signed in, detecting misuseLegitimate interest (security)
Audit log: who did what (approvals, takeovers, key and role changes, billing changes, exports, deletions), IP address, user agentAccountability and security of your organisationLegitimate interest; legal obligation where applicable
Billing: plan, credit ledger, Paddle customer referenceCharging for the serviceContract; legal obligation (accounting)
Service logs and traces (no page content, no secrets)Running and debugging the serviceLegitimate interest
Messages you send us (support, abuse, security reports)Answering youLegitimate interest; contract
Docs feedback ("Was this helpful?")Improving the docsAnonymous: no account, IP address or user agent is stored

We do not sell personal data, use it for advertising, or profile you. Payment card details are handled by Paddle and never reach Kaabist.

3. How long we keep it

DataKept for
Account dataUntil you ask [email protected] to delete your account, then removed (audit entries keep a pseudonym)
Sessions30 days from sign-in, or until you sign out
Audit logKept; when an organisation is deleted every person in it is replaced by a pseudonym
Credit ledger and payment recordsAs long as accounting law requires
Service logs30 days; traces 14 days
Support and abuse correspondence2 years from the last message

What happens to your organisation's work data is on the data retention page.

4. Who receives it

Our sub-processors (hosting, e-mail delivery, payments through Paddle, and the services listed there), within the limits of their contracts. Members of your organisation see its audit log. We disclose data to authorities only when the law requires it.

5. Where it is processed

Kaabist runs in the European Union (Hetzner, Germany). Some sub-processors are outside the EU or Türkiye; the sub-processor list names the transfer mechanism for each.

6. Your rights

You may ask for access to, correction of, deletion of, and a copy of your personal data, object to processing based on legitimate interest, and restrict processing. Under KVKK you also have the rights in Art. 11. Write to [email protected]; we answer within 30 days. You may complain to your data protection authority (in Türkiye, the Kişisel Verileri Koruma Kurumu).

7. Security

Secrets are encrypted with a key per organisation, wrapped by a master key held separately; API keys are stored only as a hash; access to the platform is logged. See the security policy for how to report a vulnerability.

8. Cookies

See the Cookie Policy: Kaabist uses only cookies that are strictly necessary.

9. Changes

We announce material changes by e-mail and in the panel before they apply.

Opening soon

Kaabist is getting ready for launch. The panel, the docs and the status page open on launch day.