1. Data controller
Under Law No. 6698 on the Protection of Personal Data (“KVKK”), the data controller for personal data processed in connection with the Projectman cloud platform and related marketing websites is:
- Monovi Bilgi Teknolojileri Yayıncılık San. Tic. A.Ş. (“Monovi” / “we”)
- Address: Gulbahce Mahallesi Teknopark Izmir Building A10 No:1/40 Office: 19, Urla 35430, İzmir, Turkey
- Contact: [email protected] · +90 232 502 5645
- Product: Projectman — project delivery, CRM, customer portal, and support workspace (projectman.monovi.com.tr and related domains).
2. Scope of this notice
This disclosure applies when you visit our public websites, create or use a Projectman user account, are invited to an organization workspace, access the customer portal, or otherwise interact with Monovi in the context of Projectman.
If your employer or client organization uses Projectman to manage its own customers, that organization may be an independent data controller for the business data it enters (for example CRM records or portal contacts). In those cases, Monovi typically acts as a data processor on the organization’s instructions. This notice still applies to account, authentication, security, billing, and platform-operation data for which Monovi is controller.
3. Personal data categories we may process
- Identity & contact: name, surname, work email, phone number (if provided), job title, organization name.
- Account & authentication: hashed credentials, session identifiers, login timestamps, password-reset tokens, optional “remember me” preference.
- Professional & usage: role assignments, project membership, permissions, in-app activity metadata, audit events attributable to a user.
- Customer operations data you or your organization enter: support ticket content, attachments, CRM customer/contact records, contract and invoice details, portal messages — processed to provide the service.
- Technical & security: IP address, browser and device type, operating system, referral URL, approximate location derived from IP, server and application logs, anti-abuse signals.
- Billing & legal: subscription or commercial terms references, tax identifiers where provided, invoice delivery details, correspondence related to contracts or compliance.
- Cookies and similar technologies — see our Cookie Policy for details.
4. Purposes of processing
- Providing, operating, maintaining, and improving the Projectman platform and customer portal.
- User registration, authentication, authorization, organization and project access control.
- Delivering features you request: boards, work items, QA, CRM, invoicing, support tickets, notifications, and reporting.
- Security, fraud prevention, abuse detection, incident response, and service integrity.
- Customer support, troubleshooting, and communication about service changes or critical incidents.
- Compliance with applicable law, tax, and accounting obligations; establishment, exercise, or defense of legal claims.
- Analytics limited to aggregated or pseudonymized service metrics where configured — not sold as standalone personal-data products.
5. Collection methods and legal grounds (KVKK Art. 5 & 6)
Personal data is collected electronically through the website, web application, APIs, email, support channels, and automated logging when you use Projectman.
- Performance of a contract or pre-contractual steps at your request (KVKK Art. 5/2-c): account creation, delivering subscribed features, portal access.
- Legal obligation (Art. 5/2-ç): tax, commercial record-keeping, lawful requests from authorities where applicable.
- Establishment, exercise, or protection of a right (Art. 5/2-e): dispute handling, enforcing Terms of Service.
- Legitimate interest balanced against your rights (Art. 5/2-f): platform security, minimal operational analytics, service reliability — where not overridden by your interests.
- Explicit consent where required (Art. 5/1): optional marketing communications or non-essential cookies when consent mechanisms are presented.
6. Recipients and international transfers
Personal data may be shared only to the extent necessary with:
Some providers may process data outside Turkey. Where required by KVKK, transfers rely on adequate safeguards such as standard contractual clauses, explicit consent, or other mechanisms recognized under applicable law. You may request information about safeguards by contacting us.
- Infrastructure and hosting providers operating database, storage, and application hosting for Projectman (including Supabase and related cloud infrastructure).
- Email and notification delivery providers used to send transactional messages (invitations, password reset, ticket updates).
- Google reCAPTCHA (Alphabet Inc.) when bot protection is enabled on authentication flows — subject to Google’s policies.
- Professional advisers (legal, accounting) under confidentiality where required.
- Public authorities when legally compelled and proportionate.
7. Retention periods
- Account and profile data: retained while your account or organization membership is active, then deleted or anonymized within a reasonable period after closure unless longer retention is required by law.
- Commercial and tax records (invoices, contracts): retained for periods required under Turkish commercial and tax legislation (typically up to 10 years where applicable).
- Security and access logs: typically 90 days to 24 months depending on severity and legal need, then deleted or aggregated.
- Support tickets: retained while the ticket lifecycle and legitimate business need require, then archived or deleted per organization settings and legal limits.
8. Your rights under KVKK (Art. 11)
As a data subject, you may apply to Monovi to:
- Learn whether your personal data is processed.
- Request information if processed.
- Learn the purpose of processing and whether data is transferred domestically or abroad.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction under KVKK Art. 7 conditions.
- Request notification of correction or deletion to third parties to whom data was transferred.
- Object to results arising solely from automated analysis where applicable.
- Claim compensation for damages due to unlawful processing.
9. How to submit a request
- 1
Prepare your application
Send a written request to [email protected] with the subject “KVKK Application”. Include your full name, contact email, and a clear description of your request. Attach identity verification documents where necessary to prevent unauthorized disclosure.
- 2
Response timeline
We respond within 30 days at the latest as a rule under KVKK, unless the request is rejected with justified reasons or complexity requires a limited extension communicated to you.
- 3
Personal Data Protection Board
If your request is denied, insufficiently answered, or not handled in time, you may lodge a complaint with the Turkish Personal Data Protection Board (KVKK Kurulu) under applicable procedures.
10. Security measures
Monovi implements technical and organizational measures appropriate to the nature of Projectman, including access controls, encryption in transit (TLS), role-based permissions, tenant isolation, logging, and staff confidentiality obligations. No method of transmission or storage is 100% secure; we continuously work to reduce risk.
11. Updates to this notice
We may update this disclosure when our processing activities, legal requirements, or platform features change. The “Last updated” date at the top reflects the latest revision. Material changes may additionally be communicated through the application or email where appropriate.
Privacy & data protection contact
For KVKK and privacy requests, email us with the subject line “KVKK / Privacy request”.
[email protected]
