Privacy policy
Updated:
This notice explains how the Saha web app, the public QR pages, the iPhone and Android technician apps and the saha.sayfa.app website handle personal data. It is the English version of our information notice under Article 10 of Turkey’s Personal Data Protection Law No. 6698 (KVKK).
In short
- Saha is a maintenance and field-service platform. It keeps organizations’ locations, assets, employees and work records on their behalf.
- No ads, no ad tracking, no third-party analytics, and we never sell your data.
- Product usage events are kept only on our own server, under a pseudonymous identifier and without names, texts or phone numbers.
Data controller
The data controller for your account data is Saha (saha.sayfa.app). For any question about this notice or your data: saha@sayfa.app.
Organization data: who is responsible
The records an organization enters into Saha (locations, assets, employees, work orders, requests, photos and the rest) belong to that organization. The organization is the data controller for the personal data in those records; Saha is a data processor that handles them only on the organization’s behalf and to provide the service. For example, for the phone number in a company’s employee record, contact that company; if you send your request to us, we pass it on to the organization.
What we process
When you create an account
- Account data: your name, e-mail address, language and when your e-mail was verified. Your password is stored only as a one-way hash (argon2id).
- Session and security records: the IP address, browser or device details (user agent) and times of use of your sessions; successful and failed sign-in attempts (e-mail address, IP address, browser details, time).
- Notifications: to send notifications to the mobile app, your phone’s push token, its platform and the app version.
- Memberships: which organizations you belong to and in which role.
When your organization uses Saha
On the organization’s behalf and on its instructions we store: the organization’s details and logo; locations (including address, coordinates, contact name and phone); assets and their service history; employee records (first and last name, phone, e-mail, job title, department, region, skills, photo); teams; service requests; work orders, notes, checklists and measurements; part requests and part usage; meter readings; inspections; uploaded photos and documents; Excel or CSV files imported; and audit records of who did what and when (including IP address and browser details).
Embedded metadata of uploaded photos, such as location and camera details, is removed on the server.
When you report a fault on a public QR page
The fault type you choose, your description, the photos you add and, optionally, your name and phone number are passed to the organization that receives the report. To prevent abuse, your IP address is used for rate limiting and the form is protected by Cloudflare Turnstile.
Product usage events
The apps and the server record events such as “app opened”, “work order completed” or “QR scanned” on our own server. Each event carries the organization, a pseudonymous identifier derived from you with a secret key held on the server (a hash), the platform, the app version and details made only of numbers or short fixed values; never names, texts, phone numbers or descriptions. We use them to improve the product and to compute the operational indicators shown to your organization. We use no third-party analytics or advertising tools.
Cookies
The web app uses only the two cookies needed to keep you signed in: the session cookie and a cookie that protects against cross-site request forgery (CSRF). Your theme choice is stored in your browser. The saha.sayfa.app website sets no analytics or advertising cookies.
When you pay for your organization
- Paying on the web: the payment is taken by Polar Software Inc. as the merchant of record. Your name, e-mail address, billing address and card details are entered directly on Polar’s checkout page and processed by Polar and its payment provider Stripe under Polar’s privacy policy. Your card details never reach us. Polar tells us only the customer id, the e-mail address, the chosen plan, the subscription’s status and its period dates.
- Paying in the apps: the payment is taken by Apple or Google and processed under their own privacy policies. Store subscriptions are verified through RevenueCat, Inc.; the only user id RevenueCat receives is the organization’s id, never your name or e-mail. RevenueCat tells us the subscription’s plan, status and period dates.
- What we keep: the organization’s plan, subscription status, source (web, App Store or Google Play), period dates and the subscription ids at Polar or the store.
When you e-mail us
Your e-mail address, name and message, used only to reply.
What we do not collect
We do not track your phone’s location. The camera is used only when you scan a QR label or take a photo. We do not store national identity numbers.
Why, and on which legal basis
| Purpose | KVKK Art. 5(2) |
|---|---|
| Creating your account, signing you in, storing the organization’s records and syncing them between devices | (c) performance of a contract |
| Sending invitations, e-mail verification, password resets and work notifications | (c) performance of a contract |
| Security, preventing abuse, finding errors, audit records | (f) legitimate interest |
| Improving the product with usage events | (f) legitimate interest |
| Running the organization’s subscription and plan, verifying payments | (c) performance of a contract |
| Lawful requests from public authorities | (ç) legal obligation |
| Answering support and deletion requests | (c) performance of a contract |
We do not use your data for marketing, profiling or advertising, and we do not sell it.
Where it is stored and who receives it
- Our servers: the database and the application run in Hetzner Online GmbH’s data centre in Helsinki, Finland, inside the European Union.
- Cloudflare, Inc.: carries and protects the traffic of saha.sayfa.app and saha-api.sayfa.app; stores uploaded photos and documents and the database backups in Cloudflare R2 object storage in its Eastern Europe region; provides the Turnstile check on the QR form; forwards e-mail sent to saha@sayfa.app.
- Amazon Web Services (Amazon SES): sends invitation, verification, password reset and digest e-mails from its Ireland region in the EU (eu-west-1), processing the recipient address and the e-mail’s content.
- Apple (Apple Push Notification service) and Google (Firebase Cloud Messaging): deliver notifications to the iPhone and Android apps. A notification carries only a short title and the record’s identifier.
- Apple App Store and Google Play: distribute the apps and take in-app subscription payments; they process data under their own privacy policies.
- Polar Software Inc. (USA): sells subscriptions bought on the web as the merchant of record, takes the payment through Stripe, calculates tax and sends the receipt and invoice. Polar is the controller for the buyer’s payment data under its own privacy policy.
- RevenueCat, Inc. (USA): verifies App Store and Google Play subscriptions and reports their status to us; it receives no personal data beyond the organization’s id.
Because some of these providers are outside Turkey, this is a transfer abroad under KVKK Article 9. The providers process data only on our behalf and for the purposes in this notice.
How long we keep it
| Data | Retention |
|---|---|
| Account data, sessions and push tokens | While your account exists; deleted as soon as you delete the account |
| Organization records | While the organization uses the service; as the organization decides |
| Subscription records (plan, status, dates, subscription ids) | As long as the organization exists |
| Copies in database backups | At most 30 days |
The account deletion page explains how to delete your account.
Your rights
Under KVKK Article 11 you can ask us to:
- tell you whether we process your personal data and, if so, give you information about it,
- tell you the purpose of processing and whether the data is used accordingly,
- tell you the third parties in Turkey or abroad that receive it,
- correct it if it is incomplete or wrong,
- delete or destroy it under the conditions of KVKK Article 7,
- notify third parties that received the data of any correction or deletion,
- object to a result against you that comes solely from automated analysis,
- compensate damage you suffered from unlawful processing.
Send your request from your account’s e-mail address to saha@sayfa.app. We answer free of charge within 30 days. If you are not satisfied with our answer, you can complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurulu). If you are in the European Economic Area, you also have the rights of the GDPR, including a complaint to your local supervisory authority.
Children
Saha is a business app and is not directed at people under 18.
Changes
When we change this notice we update the date on this page. We also announce important changes in the app.