Privacy Policy
Data Controller
Within the scope of this document, your personal data is processed as the data controller under the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and the European Union General Data Protection Regulation (GDPR) by the following organisation:
- Data Controller: VisiBack Official
- E-mail: support@visiback.com
- Web: visiback.com
Purpose
This Privacy Policy explains how VisiBack Official processes and protects the personal data it collects through its website and services, and what rights you have over that data. The Policy has been prepared to be compliant with the KVKK and the GDPR.
Categories of Data Processed, Purpose, Legal Basis and Retention
Within the scope of the service, the following categories of data are processed with the purpose, legal basis and retention period stated against each:
- Identity and contact data (full name, e-mail, phone, title, company name) — Purpose: account creation, authentication and communication; Basis: performance of a contract and legitimate interest; Retention: while the account is active and for statutory periods.
- Device and inventory data (device name, operating system, hardware identifier, IP, agent version, disk/application inventory) — Purpose: device management and security; Basis: performance of a contract; Retention: for the duration of the service.
- Activity data (open and focused applications, active time, sign-in/sign-out events, productivity signals) — Purpose: productivity analysis and reporting; Basis: performance of a contract and legitimate interest / explicit consent; Retention: for the defined analysis window.
- Screen and image data (activity-triggered screenshots / continuous screen archive, camera snapshots where the add-on is enabled) — Purpose: auditing and security; Basis: explicit consent and/or the employer's legitimate interest; Retention: for the defined archive period (e.g. 7 days).
- Network and connection data (local IP, VPN status, SMB/network shares, local-network membership) — Purpose: network management and security; Basis: performance of a contract; Retention: for the duration of the service.
- Technical and log data (IP address, User-Agent, timestamps, error and audit logs) — Purpose: security, accountability and legal evidence; Basis: legal obligation and legitimate interest; Retention: for statutory periods.
- Cookies and similar technologies (necessary, functional, analytics, marketing cookies) — Purpose: website functionality and optional analytics; Basis: legitimate interest for necessary cookies, explicit consent for the others; Retention: for the periods stated in the Cookie Policy.
Data is processed and analysed only for the purposes above and strictly within the scope of the company it belongs to; isolation between companies is fundamental. Data is used only for analytics and for product/service improvement and is never sold to third parties.
How Data Is Processed and Analysed
Collected data is processed for device management, security, productivity reporting and improvement of the service. Activity data is analysed in aggregate and limited to the scope of the company. Raw screen or keystroke data is presented only to the authorised users of the relevant company and within defined access rules; it is never shared with a different company.
International Transfers
For the provision of infrastructure services such as hosting and object storage, your data may be processed under the safeguards required by the KVKK and the GDPR (appropriate technical/administrative measures and contractual obligations). Such transfers are made only to the extent necessary to maintain the service.
Children's Privacy
The Service is intended for corporate device management and is not directed at children; personal data of children is not knowingly collected.
Data Sharing, Transfer and Isolation
None of the collected data is shared, rented or sold to third parties for marketing, advertising or profit. Your data is transferred only in the following cases and only to the extent necessary:
- Where there is a lawful and duly-made request from legally authorised public authorities, courts, or judicial/administrative bodies, solely within the scope of the relevant legal obligation;
- With infrastructure providers that are technically required to deliver the service and act solely as data processors (hosting, e-mail delivery, object storage, etc.), under contractual confidentiality and data-security obligations.
Per-company isolation: All collected data is processed strictly within the scope of the company (tenant) it belongs to. Data of different companies is logically isolated from one another; no company's data is shown to or shared with any other company. Data is used only for analytics and for product/service improvement, within the scope of the company concerned.
Data Security Measures
Appropriate administrative and technical measures are taken to protect your data against unlawful access, loss, disclosure or alteration:
- TLS encryption in transit and storage encryption for sensitive fields;
- Role- and permission-based access control (RBAC) with the least-privilege (need-to-know) principle;
- Audit logging of critical operations for accountability;
- Per-company logical isolation and access gates;
- Regular security reviews, secure backups and access logging.
Retention Period and Erasure
Your personal data is retained for as long as necessary for the purposes for which it is processed and for the mandatory retention periods prescribed by applicable law. When the purpose ceases to exist or the retention period expires, your data is deleted, destroyed or anonymised in accordance with the KVKK and applicable law. Consent records that constitute legal evidence (including technical information such as IP, User-Agent and timestamp) are retained for the duration of the burden-of-proof and statutory limitation periods.
Rights of the Data Subject (KVKK art. 11 / GDPR)
Under Article 11 of the KVKK and the GDPR (access, rectification, erasure, objection to processing, portability), as a data subject you have the following rights:
- To learn whether your personal data is being processed and, if so, to request information about it;
- To learn the purpose of processing and whether the data is used in accordance with that purpose;
- To know the third parties to whom your data is transferred, domestically or abroad;
- To request rectification of incomplete or inaccurately processed data;
- To request erasure or destruction of your data under Article 7 of the KVKK (right to be forgotten);
- To request that rectification, erasure or destruction be notified to third parties to whom the data has been transferred;
- To object to any adverse result arising solely from automated analysis of your data;
- To claim compensation for damages arising from unlawful processing;
- To additionally exercise your rights of access, data portability and objection to processing under the GDPR.
Applications and Contact
To exercise the rights above or to submit requests regarding your personal data, you may contact support@visiback.com. For suspected personal-data breaches, complaints or objections, you may also apply through the Breach Notification Form available on our website. Your applications are handled free of charge, as soon as possible and in any case within the periods prescribed by law (a maximum of 30 days under the KVKK).
Notification of Changes
This text may be revised in line with changes in legislation or updates to our services. The current version is always published at visiback.com; material changes are announced through appropriate channels (in-app notification or e-mail) and, where necessary, your renewed consent is requested.
Governing Law
This text is governed by the laws of the Republic of Türkiye and is interpreted primarily in accordance with Law No. 6698 (KVKK) and related secondary legislation. For data subjects located in the European Union, the provisions of the GDPR also apply. The Istanbul (Çağlayan) Courts and Enforcement Offices have jurisdiction over any disputes arising from the application of this text.