Privacy Notice
This notice explains who processes your personal data when you use MapFirms, for what purposes and how. It serves as the information notice required by Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK) and as the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
1. Controller and scope
Controller: Hakan Demirbilek (MapFirms), Türkiye. E-mail: destek@mapfirms.com.
This notice covers the MapFirms desktop program, the MapFirms Mobile phone app, the websites mapfirms.com and app.mapfirms.com, the account, licensing and phone sync services, and support correspondence. For the company data that you collect with MapFirms, see section 9: you are the controller of that data.
MapFirms is a product for businesses; it is not directed at children.
2. Data that stays on your computer
The program's database (companies, contacts, notes, quotes, contact history), your settings (including your company details and pairing keys; the keys are protected by Windows data protection), log and error files, backups, the files you export and the records of the documents you accepted in the installer or the program (document versions, language and time of acceptance) are kept only on your computer. This data is not sent to us and we have no access to it.
The program contains no usage statistics collection or advertising tracking, and error reports are not sent automatically. Error logs reach us only if you send them to us yourself. MapFirms Mobile keeps the data you send to your phone in the storage of the browser on your phone.
3. Personal data we process and how it is collected
- Account data: your username or e-mail address; your name and company name, if you provide them; a salted one-way hash of your password (we cannot see the password itself); account role and status, subscription and license status, expiry date, device limit, creation and last sign-in times; notes that we add to your account for support and administration.
- Device and session data: a device code derived one-way from your Windows installation identifier and your Windows user name, the computer name, the program version, first and last use times; session records (hashed access tokens and their times).
- Security data: failed sign-in counters (with the time of the last failed attempt) and daily counters keyed by a one-way hash of your IP address, used to prevent abuse and password-guessing attacks.
- Account activity log: a list of events that our account, payment and sync services already see, kept with your account so that we can protect it, answer support questions and prevent abuse (our legitimate interests, see section 4). It records the time and type of: the account's creation and the linking of a purchase to it; sign-ins (with the computer name and program version), refused sign-ins and wrong-password attempts (only how many, never what was typed); the first session renewal of each day; devices added or removed; password changes and resets; subscription events reported by Paddle (purchase, renewal, cancellation, failed payment, refund); days on which your computer uploaded an encrypted phone sync package (at most one entry per day); and changes we make to your account (for example, full-version access granted or removed, account disabled, archived or restored). It contains no passwords, access tokens, IP addresses, e-mail addresses or content of your data, and the program sends nothing extra for it.
- Phone sync data: packages that are end-to-end encrypted on your computer (the companies you send to your phone and search requests from your phone), with the related pairing space code, hashed access tokens and timestamps. Our server links each pairing space to your account ID and to the device code of the computer that set it up, and keeps a list of your account's pairing space codes; this is what allows your phone sync data to be deleted together with your account. We cannot read the content of the packages.
- Order data: the data we receive from Paddle, namely your name, e-mail address, country, your company name and tax number if you provide them, the plan purchased, amount and currency, transaction and subscription numbers and their status. Our purchase page also attaches the following to the order, and we can see it in Paddle's transaction record: the versions of the End User License Agreement, the Refund Policy and the Pre-contract Information and Terms of Sale that you accepted, your declaration that you want access to start immediately, the time shown by your browser when you accepted, the page language and a random verification code that links the payment to the account you then open; of these, our server stores only the verification code and the language, with the transaction record. Your card details do not reach us.
- Correspondence: e-mails you send to destek@mapfirms.com and their attachments (including error logs you choose to send).
- Optional YouTube check: this social profile check is off by default and works only when you are signed in with an account (full version). If you turn it on, the program sends the YouTube channel identifier or handle found on a company's website to our server (app.mapfirms.com), together with your license document and the program version. The license document is the record that our account service signs when you sign in; it contains your account ID, your name and company name if you provided them, your account role, the end date of your account or subscription, your device code and the document's validity times. Our server uses the document only to verify that the request comes from a full-version account with a valid license document and to limit the number of requests per account; for this it keeps a one-way hash of your account ID, together with request counts, in the server's memory. It does not use your name, company name or device code to identify you or to limit requests. Your IP address also reaches our server with the request; our service's own code likewise uses it only as a one-way hash in the server's memory to limit the number of requests. Our hosting provider also uses your IP address for its own platform limit on the number of requests and processes it in its standard server logs together with the requested address, which contains the channel identifier or handle (see Technical access data below). Apart from these server logs, our service does not write the license document, the IP address or the request to permanent storage or to logs; the hashes and counts in memory are deleted at the latest when the server instance handling the requests shuts down. Our server forwards only the channel identifier or handle, and nothing about you, to Google's YouTube API Services (YouTube Data API) and returns the answer (the channel's public name, handle and country, its subscriber and video counts, and the domain names of the web addresses in its description) to the program. To avoid repeating the same query, answers are reused from the server's memory for at most 6 hours (1 hour if no channel was found) and are not written to permanent storage; in the program they are kept on your computer for at most 30 days.
- Technical access data: when the program checks for updates or uses our online services, when you download files or when you visit our websites, our hosting provider processes technical data such as IP address, time, requested address and browser or program version in server logs. Our websites themselves do not set cookies or use visitor analytics; only your language preference is kept in your browser's local storage. The purchase page, however, loads Paddle's script (Paddle.js) as soon as it opens in order to show the price in your currency, so Paddle receives your IP address and browser data when you open that page. On that page and in the Paddle checkout, Paddle applies its own privacy and cookie policy.
This data is collected electronically: automatically through the program and the websites, from you when you create an account or write to us, and through Paddle when you make a purchase.
4. Purposes and legal bases
- Opening and managing your account, activating and checking the license, enforcing the device limit, providing phone sync and the optional YouTube check: conclusion and performance of the contract (KVKK Art. 5(2)(c); GDPR Art. 6(1)(b)).
- Keeping the service secure, preventing abuse and fixing errors: our legitimate interests (KVKK Art. 5(2)(f); GDPR Art. 6(1)(f)).
- Handling orders, subscriptions and refunds; meeting tax and accounting obligations: performance of the contract and legal obligation (KVKK Art. 5(2)(c) and (ç); GDPR Art. 6(1)(b) and (c)).
- Answering your support requests: performance of the contract and legitimate interests (KVKK Art. 5(2)(c) and (f); GDPR Art. 6(1)(b) and (f)).
- Keeping the records needed for legal claims (for example order and correspondence records) and dealing with such claims: legal obligation and the establishment, exercise or defence of legal claims (KVKK Art. 5(2)(ç) and (e); GDPR Art. 6(1)(c) and (f)).
- Product news and offers: only if you give separate explicit consent (KVKK Art. 5(1); GDPR Art. 6(1)(a); for commercial electronic messages, Turkish Law No. 6563). You can withdraw your consent at any time. Mandatory service messages (subscription, security, changes to the terms) are sent regardless of this consent.
We do not carry out automated decision-making or profiling. You can use the free version without an account; account data is required for the full version.
5. Recipients and services the program connects to directly
- Netlify, Inc. (United States): hosts the websites and the account, sync and YouTube check services; acts as a processor.
- Paddle (Paddle.com Market Limited and the group companies named in the Paddle Buyer Terms, United Kingdom): as Merchant of Record, processes payment and order data as an independent controller under its own privacy notice: https://www.paddle.com/legal/privacy
- Cloudflare, Inc. (United States): provides the name server service for the mapfirms.com domain and forwards e-mails sent to destek@mapfirms.com.
- Google LLC (United States): provides the mailbox service in which support e-mails are received and, for the optional YouTube check, answers queries through the YouTube Data API under the Google Privacy Policy: https://policies.google.com/privacy
- Competent public authorities: only where required by law.
We do not sell your personal data and do not share it with anyone for advertising purposes.
When you use its features, the program connects directly from your computer, without going through us, to: the sources you select (map services, official company registers, business directories, open datasets, websites); OpenStreetMap services (map tiles and Nominatim address lookup); Esri (satellite and dark map layers); for the optional social profile checks, the public interfaces of Bluesky, the Mastodon server concerned and GitHub; the encrypted DNS (DNS-over-HTTPS) services of Cloudflare and Google for the e-mail domain check; Google's Chrome for Testing download service (served from Google and GitHub), to download the driver for Google Chrome that map searches need; www.google.com and Cloudflare's address 1.1.1.1, to check the internet connection (the network proxy test in the settings also uses www.google.com); and the WhatsApp, e-mail and phone apps you open. These services process your IP address and the content of the request under their own privacy policies; this data does not reach us. The only exception is the optional YouTube check, which runs through our server as described in section 3. If you set a network proxy in the settings, the connections of map and business directory searches pass through that proxy server, and whoever operates it (for example your company or your proxy provider) can see them.
6. International transfers
The controller is located in Türkiye. The following service providers process personal data on servers outside Türkiye, including in the United States:
- Netlify, Inc. (United States): account, device, session, security and phone sync data, the requests of the optional YouTube check (channel identifier or handle, license document and IP address) and technical access data, in order to host the websites and the account, sync and check services.
- Cloudflare, Inc. (United States): the e-mails sent to destek@mapfirms.com, in order to forward them to the support mailbox.
- Google LLC (United States): support correspondence, for the mailbox service; for the optional YouTube check, the channel identifiers or handles sent to the YouTube Data API.
For more information about these transfers, write to destek@mapfirms.com.
When you make a purchase, you give your data directly to Paddle; Paddle processes it under its own privacy notice.
7. Retention periods
- Account, device and session data: as long as your account exists; for an account that is closed but not deleted, up to 3 years after closure for possible disputes. For deleted accounts, the next item applies.
- Account activity log: each entry for 12 months, and at most the latest 200 entries per account; expired entries are no longer shown and are deleted during our server's maintenance runs. If your account is deleted, it is first archived: sign-in and full-version access stop at once and the account can be restored within 30 days. After these 30 days, during maintenance runs, or earlier on request, the account, its devices, sessions, activity log and phone sync data are permanently deleted. So that license documents already issued cannot be used, a revocation record containing only the account ID is kept until those documents expire (8 days) and is then deleted during maintenance runs. What remains is a one-way hash of the account ID and the time of deletion, so that the ID is not given to anyone else, and the pairing markers described under phone sync data below; order data is kept as stated below.
- Security counters: daily counters keyed by a one-way hash of the IP address are kept until the end of the day concerned and are then deleted during our server's maintenance runs; failed sign-in counters are reset by a successful sign-in or a password change and are otherwise deleted during maintenance runs 30 days after the last failed attempt.
- Phone sync data: until you remove the pairing or ask for its deletion; if your account is permanently deleted, it is deleted together with the account or during the maintenance runs that follow. After deletion, only a marker with the random pairing code and the time of deletion remains, so that the paired phone can show that the pairing was removed.
- Order data: for the period required by tax and commercial law, up to 10 years.
- Support correspondence: 3 years from the last message.
- Optional YouTube check: apart from the hosting provider's server logs (next item), our service does not write the requests, license documents or IP addresses to permanent storage; the one-way hashes and counts used to limit requests exist only in the server's memory, and answers are reused from it for at most 6 hours.
- Server logs: for the hosting provider's short standard retention periods.
When the period expires, the data is deleted, destroyed or anonymised.
8. Your rights and how to exercise them
Under KVKK Art. 11 you have the right to: learn whether your personal data is processed; request information if it has been processed; learn the purpose of processing and whether the data is used in line with that purpose; know the third parties in Türkiye or abroad to whom it has been transferred; request correction if it is incomplete or inaccurate; request deletion or destruction under the conditions of KVKK Art. 7; request that correction, deletion and destruction be notified to the third parties to whom the data was transferred; object to a result against you arising exclusively from analysis by automated systems; and claim compensation if you suffer damage from unlawful processing.
If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection (in particular to processing based on legitimate interests) (GDPR Arts. 15-22), and the right to withdraw consent at any time.
How to apply: send your request to destek@mapfirms.com from the e-mail address registered on your account or with information that allows us to verify your identity. We will resolve your request free of charge within 30 days at the latest (KVKK Art. 13; GDPR Art. 12). We may ask for additional information to verify your identity.
Complaints: in Türkiye, if your request is rejected, you find the answer insufficient or you do not receive an answer in time, you may lodge a complaint with the Personal Data Protection Board (https://www.kvkk.gov.tr). You may also complain to the data protection authority of the country in the European Economic Area where you live or work or where the infringement took place (https://www.edpb.europa.eu), in the United Kingdom to the Information Commissioner's Office (https://ico.org.uk), and in other countries to the competent data protection authority.
9. Company data you collect with MapFirms: you are the controller
MapFirms is a tool that runs on your computer. The company information you find on the sources you select (which may include personal data such as the names, phone numbers and e-mail addresses of sole traders or employees) is stored only on your computer. Apart from the two cases described below, this data does not reach us; we do not sell it and do not combine data collected by different users.
You are the controller of this data within the meaning of the KVKK, the GDPR and similar laws. It is therefore your obligation to: determine the legal basis on which you process the data; inform the individuals, including where you obtained their data, no later than at the first contact (KVKK Art. 10, GDPR Art. 14); respond to their requests; not keep the data longer than necessary; and keep it secure. The program records which source each piece of information came from, which makes it easier for you to tell people the source.
If you use phone sync, this data is stored on our servers end-to-end encrypted, and only in our capacity as a processor acting on your behalf (End User License Agreement, section 7). If you turn on the optional YouTube check, the channel identifiers or handles found on company websites pass through our server only to be forwarded to Google, as described in section 3; apart from the hosting provider's server logs, our service does not write them to permanent storage and reuses the answers from the server's memory for at most 6 hours.
If a person who believes their details are in a MapFirms user's database contacts us, we will tell them that we have no access to that data and that they should direct their request to the user concerned.
10. Changes to this notice
We may update this notice when our services or the law change. We will announce material changes in the program or on our website. The version of this text is PRIVACY-1.