WardOps Privacy Policy
Version 1.1-DRAFT · 27 September 2026
This Policy explains how personal data is processed by the WardOps platform ("Platform") and by this website. It is prepared under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the related communiqué on the obligation to inform. [Additional notices for visitors and customers in the EU/UK (GDPR) and the United States will be added after legal review.]
1. Who We Are and Our Roles
1.1. Data controller: [COMPANY NAME], [ADDRESS], [COMPANY REGISTRATION NO.], email: [PRIVACY EMAIL] ("Company", "we"). [VERBİS registration details: …]
1.2. Two different kinds of personal data are processed on the Platform, and our role depends on which one:
- Account and usage data: account, sign-in, contact and log data of the employees of businesses that use the Platform (Authorised Users). For this data we are the data controller, and this Policy covers it directly.
- Operational data: names, titles, addresses, phone numbers, emails and correspondence of people such as shippers, consignees, notify parties, truckers and customs brokers, brought in by businesses through uploads or connected email accounts. For this data, the business using the Platform is the data controller, and we are the data processor acting on its instructions (Data Processing Agreement). Informing these people is that business's obligation; Section 10 of this Policy gives them general information.
- Website visitors and early-access requests: see Section 9.
2. Personal Data We Process (Authorised Users)
| Category | Data |
|---|---|
| Identity | Name, surname |
| Contact | Work email address, phone (if entered) |
| Customer transaction | Company, role (admin, operations, view-only), user settings |
| Transaction security | Non-reversible hash of the password, session data, sign-in and failed sign-in records, IP address, browser information, the permanent account ID from Google or Apple |
| Legal transaction | Records of acceptance of terms and policies (document, version, date, IP, browser) |
| Audit log | Records of actions in the Platform (for example adding users, sending replies, generating documents, changing settings) |
| Marketing | Only with separate permission: contact preference for newsletters and product news |
| Feedback | Support requests, survey answers, interview notes and in-Platform feedback |
We do not ask Authorised Users for special categories of personal data (health, biometrics, religion, political opinion, etc.). Such data should not be part of businesses' operational data; if it is, the business concerned is responsible.
3. How We Collect Personal Data
Personal data is collected, fully or partly by automated means, through sign-up and sign-in forms, information passed by Google or Apple at sign-in (name, email, permanent ID), details entered by an admin when adding a user, records created automatically while using the Platform, and support and contact channels.
4. Purposes and Legal Bases
| Purpose | Legal basis (KVKK Art. 5/2) |
|---|---|
| Opening the account, authentication and session management | (c) Formation and performance of a contract |
| Providing the Platform, user and permission management | (c) Performance of a contract |
| Information security, detecting and preventing unauthorised access, keeping logs | (ç) Legal obligation, (f) Legitimate interest |
| Proving acceptance of terms and policies, resolving disputes | (e) Establishing, exercising or protecting a right |
| Answering support requests, measuring and improving service quality | (c) Performance of a contract, (f) Legitimate interest |
| Legal obligations (tax, commercial and logging obligations, requests from authorities) | (a) Expressly provided by law, (ç) Legal obligation |
| Product news and newsletter | Explicit consent (only if given; can be withdrawn at any time) |
5. Transfers of Personal Data
5.1. Within Türkiye: to the extent needed to provide the Service, data may be transferred to hosting and infrastructure providers, accounting and legal advisers, auditors, legally authorised public institutions and courts.
5.2. Outside Türkiye: some parts of the Platform run through service providers located abroad, to the extent the related function is used:
- Authentication: Sign in with Google (Google LLC, USA), Sign in with Apple (Apple Inc., USA).
- Email integration: the Microsoft 365 / Outlook (Microsoft Corporation) or Gmail (Google LLC) account a business chooses to connect.
- AI document reading: depending on the business's preference, the necessary part of documents that text extraction and local OCR cannot read may be sent to an AI provider (Anthropic PBC, USA). The business can switch this off in the admin screen.
- AI classification (Jev): unless the business switches it off, an email's subject and body and the text of documents may be sent to TypeSafe to decide the email's type, whether it contains an out-of-routine question and where document values go on the shipment. The provider generates no text and commits not to train models on the data. The business can switch this off in the admin screen.
- Hosting: [HOSTING PROVIDER AND COUNTRY].
- Website hosting: this website is served by GitHub Pages (GitHub, Inc., USA); see Section 9.
International transfers are made in line with Article 9 of KVKK and related secondary legislation; for countries without an adequacy decision, within the framework of standard contracts announced by the Personal Data Protection Board or other appropriate safeguards provided by law. [The transfer mechanism will be finalised after legal review.]
5.3. We do not sell personal data, share it with third parties for advertising, or use it to train AI models.
6. Retention Periods
| Data | Retention period |
|---|---|
| Account data | While the account is active; deleted within [30] days after the contract ends |
| Sign-in and security records | [2] years |
| Audit logs | For the term of the contract and [2] years after it ends |
| Acceptance records for terms and policies | [10] years after the contract ends (limitation period) |
| Support and feedback records | [3] years |
| Early-access requests (website) | [12] months if no contract follows |
| Backups | Within the normal backup cycle, at most [90] days |
Expired data is deleted, destroyed or anonymised under the Regulation on the Deletion, Destruction or Anonymisation of Personal Data. [A retention and destruction policy will be prepared separately.]
7. Data Security
We apply technical and organisational measures such as separating data between companies, role-based permissions, storing passwords as non-reversible hashes, storing email integration credentials encrypted, ending sessions when permissions or passwords change, keeping audit and security logs, limiting access on a least-privilege basis and regular backups. Details are in the Schedule to the Data Processing Agreement.
8. Your Rights (KVKK Art. 11)
You have the right to learn whether your personal data is processed; to request information if it is; to learn the purpose of processing and whether data is used for that purpose; to know third parties to whom it is transferred in Türkiye or abroad; to request correction if it is incomplete or wrong; to request deletion or destruction under Article 7 of KVKK; to request that corrections and deletions be notified to third parties to whom data was transferred; to object to a result against you arising exclusively from automated analysis; and to claim compensation if you suffer damage from unlawful processing.
You can send requests in writing to [ADDRESS], by registered electronic mail (KEP) to [KEP ADDRESS], or from an email address previously registered with us to [PRIVACY EMAIL], together with information that identifies you. Requests are concluded free of charge within 30 days at the latest.
Requests about operational data (Section 1.2) should be made to the business that is the data controller; requests of this kind that reach us are forwarded to that business without delay.
9. Website Visitors and Early-Access Requests
9.1. Early-access form: if you ask for early access, we process the details you give us (name, work email, company, optional monthly volume and message) to reply to you and arrange a walkthrough. The legal basis is taking steps before a possible contract at your request and our legitimate interest in answering business enquiries. These details are delivered to us [by email / through FORM SERVICE PROVIDER] and kept for the period in Section 6.
9.2. Hosting logs: this website is hosted on GitHub Pages. When you visit it, GitHub logs your IP address for security purposes, whether or not you are signed in to GitHub. GitHub processes this data under its own privacy statement.
9.3. No cookies or tracking: this website does not set cookies and does not use analytics, advertising or tracking tools. Fonts are served from this website itself, not from a third-party font service.
10. General Information for People in Operational Data
Businesses using the Platform may process contact and correspondence details of shippers, consignees, notify parties, truckers, customs brokers and similar people to carry out transport and logistics operations. The purpose, legal basis and duration of this processing are determined by the business concerned. We process this data only on the business's instructions to provide the Service and do not use it for our own purposes.
11. Cookies and Browser Storage in the Platform
The Platform does not use advertising or tracking cookies. The browser's local storage is used to keep the session and remember user preferences (for example the last opened tab). If you choose to sign in with Google or Apple, that provider's sign-in component may use cookies under its own policies.
12. Changes
This Policy may be updated. The current version is published on the Platform and on this website; material changes are announced in the Platform.