Last Updated: February 24, 2026
At Documentiq (“Platform”, “Service”, “We”, “Our”), we respect your privacy and take all necessary measures to protect your personal information. This Privacy Policy explains the information we collect, how we use it, share it, and protect it while you use the Platform.
By reading this policy and using the Platform, you are deemed to have accepted the practices described herein.
1. Data Controller
The data controller responsible for processing your personal data is:
-
Company Name: Albert Yazılım A.Ş.
-
Address: Istanbul, Turkey
-
Email: privacy@documentiq.io
-
Website: https://documentiq.io
2. Information Collected
We collect the following information while you use the Platform:
2.1 Account Information
-
First and last name
-
Email address
-
Phone number
-
Password (stored encrypted/hashed)
2.2 Sign-in with Google (OAuth)
When you log in to the Platform using your Google account, we receive the following information from Google:
-
Email address: The primary email associated with your Google account.
-
Profile information: Name, surname, and profile picture.
-
OpenID identifier: For authentication purposes.
Note: Your Google password is never shared with us. We only request access to the basic information mentioned above via the Google OAuth 2.0 protocol. We do not access other data in your Google account (Drive files, calendar, contacts, etc.).
2.3 Business and Organizational Information
-
Organization name
-
Industry information
-
Number of employees
-
City information
2.4 Financial Data
-
Valuable paper information (checks, promissory notes, bonds)
-
Loan information and payment records
-
Letters of guarantee information
-
Entity (company, bank) information
2.5 Usage and Technical Data
-
Transactions performed on the Platform and access times
-
IP address, browser type, and version
-
Device information (operating system, screen resolution)
-
Cookies and session information
-
Log files and error reports
3. Purposes of Data Usage
We use the collected information for the following purposes:
-
Service Provision: To provide core functions, create and manage your account.
-
Authentication: To ensure secure login via email/password or Google OAuth.
-
Customer Support: To answer your questions and manage support requests.
-
Security: To prevent unauthorized access and detect fraud.
-
Improvement: To analyze platform usage and increase service quality.
-
Notifications: To send due date reminders, payment notifications, and system announcements.
-
Legal Obligations: Mandatory reporting and record-keeping as per legislation.
4. Sharing of Information
We do not share your personal information with third parties except in the following cases:
4.1 Service Providers
-
Supabase: Database management and authentication infrastructure.
-
Google: OAuth login service (for authentication purposes only).
-
Resend: Email delivery service.
-
NetGSM: SMS notification service.
-
OneSignal: Push notification service.
-
PostHog: Anonymous usage analysis.
4.2 Legal Requirements
We may share your information in accordance with court orders, legal regulations, or public safety requirements.
4.3 Business Transfers
Your information may be transferred in cases of merger, acquisition, or asset transfer. We will notify you in advance in such cases.
Important: We do not sell or share your information with third parties for advertising or marketing purposes.
5. Google OAuth Usage & Data Disclosure
When you log in to the Platform with your Google account:
-
We only request access to basic profile information (name, email, profile photo).
-
We do not have access to your Google account password.
-
We do not access files, calendars, contacts, or other data in your Google account.
-
You can revoke your Google OAuth permission at any time via the Google Account Settings page.
-
Google’s Privacy Policy: https://policies.google.com/privacy
6. Data Security
We take industry-standard technical and organizational measures to ensure the security of your data:
-
SSL/TLS Encryption: All data transfers are protected with 256-bit encryption.
-
Row Level Security (RLS): Data for each organization is isolated from others.
-
Secure Infrastructure: Enterprise-level security with Supabase cloud infrastructure.
-
Access Control: Role-based authorization system.
-
Regular Backups: Automated backups and disaster recovery plans.
-
Password Security: Passwords are stored hashed using the bcrypt algorithm.
While we take all reasonable precautions, no data transmission over the Internet is 100% secure.
7. Cookies and Tracking Technologies
| Cookie Type | Purpose | Duration |
| Strictly Necessary | Session management, authentication | Session |
| Functional | Language preference, theme settings | 1 Year |
| Analytical | Anonymous usage statistics (PostHog) | 1 Year |
8. User Rights (GDPR & KVKK)
Under the GDPR and KVKK (Law No. 6698), you have the following rights:
-
Right of Access: To learn whether your data is processed and request access.
-
Right to Rectification: To request correction of inaccurate or incomplete data.
-
Right to Erasure: To request the deletion or destruction of your personal data.
-
Right to Object: To object to the processing of your data.
-
Right to Data Portability: To receive your data in a structured format.
-
Right to Withdraw Consent: To withdraw your consent at any time.
To exercise these rights, please contact us at privacy@documentiq.io. Your request will be answered within 30 days.
9. Data Retention
-
Account Data: Retained as long as your account is active.
-
Financial Data: May be stored for 10 years after account deletion due to legal retention obligations.
-
Log Data: Stored for 12 months.
-
Cookie Data: Session duration or up to 1 year depending on the type.
Upon account deletion, all personal data outside of legal retention periods will be securely deleted within 30 days.
10. Children’s Privacy
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from individuals under 18.
11. International Data Transfer
Your data may be processed in different countries through our service providers’ servers. In this case, we ensure that your data is protected at standards compliant with KVKK and GDPR.
12. Policy Changes
We may update this Privacy Policy from time to time. In case of significant changes, we will:
-
Post a notification on the Platform.
-
Send a notification to your registered email address.
13. Contact
For questions or requests regarding our privacy policy:
-
Email: privacy@documentiq.io
-
Website: https://documentiq.io