# Kaabist Privacy Policy

*Version 1.0, effective 10 October 2026.*

This policy explains the personal data Kaabist processes **as a controller**: about the people who
use the panel, the API and the docs. The data your programs collect from websites is yours, and
Kaabist processes it for you as a processor under the [Data Processing Agreement](dpa.md).

## 1. Controller

Kaabist Bilişim ve Yazılım Hizmetleri Limited Şirketi, Sinpaş Flatofis, Defterdar, Otakçılar Cd.
Blok No: 75, İç Kapı No: 94, 34050 Eyüpsultan, İstanbul, Türkiye, tax number 4842191056
("Kaabist"). Contact: **privacy@kaab.ist**.

## 2. What we process, why, and on what basis

| Data | Purpose | Legal basis |
|---|---|---|
| Account: name, e-mail address, password (stored only as a hash), sign-in method (e-mail link, GitHub, Google), two-factor settings (secret encrypted) | Creating and securing your account | Contract; legitimate interest (security) |
| Organisation membership and role, invitations (invitee e-mail) | Letting teams share work | Contract |
| Sessions: IP address, user agent, times | Keeping you signed in, detecting misuse | Legitimate interest (security) |
| Audit log: who did what (approvals, takeovers, key and role changes, billing changes, exports, deletions), IP address, user agent | Accountability and security of your organisation | Legitimate interest; legal obligation where applicable |
| Billing: plan, credit ledger, Paddle customer reference | Charging for the service | Contract; legal obligation (accounting) |
| Service logs and traces (no page content, no secrets) | Running and debugging the service | Legitimate interest |
| Messages you send us (support, abuse, security reports) | Answering you | Legitimate interest; contract |
| Docs feedback ("Was this helpful?") | Improving the docs | Anonymous: no account, IP address or user agent is stored |

We do not sell personal data, use it for advertising, or profile you. Payment card details are
handled by Paddle and never reach Kaabist.

## 3. How long we keep it

| Data | Kept for |
|---|---|
| Account data | Until you ask privacy@kaab.ist to delete your account, then removed (audit entries keep a pseudonym) |
| Sessions | 30 days from sign-in, or until you sign out |
| Audit log | Kept; when an organisation is deleted every person in it is replaced by a pseudonym |
| Credit ledger and payment records | As long as accounting law requires |
| Service logs | 30 days; traces 14 days |
| Support and abuse correspondence | 2 years from the last message |

What happens to your organisation's work data is on the
[data retention page](https://docs.kaab.ist/concepts/data-retention).

## 4. Who receives it

Our [sub-processors](subprocessors.md) (hosting, e-mail delivery, payments through Paddle, and
the services listed there), within the limits of their contracts. Members of your organisation see
its audit log. We disclose data to authorities only when the law requires it.

## 5. Where it is processed

Kaabist runs in the European Union (Hetzner, Germany). Some sub-processors are outside the EU or
Türkiye; the [sub-processor list](subprocessors.md) names the transfer mechanism for each.

## 6. Your rights

You may ask for access to, correction of, deletion of, and a copy of your personal data, object to
processing based on legitimate interest, and restrict processing. Under KVKK you also have the
rights in Art. 11. Write to privacy@kaab.ist; we answer within 30 days. You may complain to your
data protection authority (in Türkiye, the Kişisel Verileri Koruma Kurumu).

## 7. Security

Secrets are encrypted with a key per organisation, wrapped by a master key held separately; API
keys are stored only as a hash; access to the platform is logged. See the
[security policy](../../SECURITY.md) for how to report a vulnerability.

## 8. Cookies

See the [Cookie Policy](cookie-policy.md): Kaabist uses only cookies that are strictly necessary.

## 9. Changes

We announce material changes by e-mail and in the panel before they apply.
