Solutions

Features

Pricing

Blog

FAQs

English

KVKK Customer Privacy Notice

Last update: Sep 14, 2026

Last update: Sep 14, 2026

At Hipposoft Yazılım Ltd. Şti. (“Hipposoft” or the “Company”), we attach great importance to the security of your personal data in connection with the services we provide through the HRplan human resources software and its related website www.hrplan.net, web application app.hrplan.net and mobile applications (collectively, the “Platform”).

This Privacy Notice has been prepared by our Company, in its capacity as data controller, pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (“KVKK”) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform, in order to inform you of the purposes for which and the legal grounds on which your personal data are processed, to whom they are transferred, and your rights under the KVKK. Your personal data are processed in accordance with the principles set out in Article 4 of the KVKK, namely: lawfulness and fairness; accuracy and being kept up to date; processing for specified, explicit and legitimate purposes; being relevant, limited and proportionate to the purposes of processing; and retention only for as long as necessary.

At Hipposoft Yazılım Ltd. Şti. (“Hipposoft” or the “Company”), we attach great importance to the security of your personal data in connection with the services we provide through the HRplan human resources software and its related website www.hrplan.net, web application app.hrplan.net and mobile applications (collectively, the “Platform”).

This Privacy Notice has been prepared by our Company, in its capacity as data controller, pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (“KVKK”) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform, in order to inform you of the purposes for which and the legal grounds on which your personal data are processed, to whom they are transferred, and your rights under the KVKK. Your personal data are processed in accordance with the principles set out in Article 4 of the KVKK, namely: lawfulness and fairness; accuracy and being kept up to date; processing for specified, explicit and legitimate purposes; being relevant, limited and proportionate to the purposes of processing; and retention only for as long as necessary.

  1. Scope

This notice covers the personal data of authorized representatives, account administrators and users of our corporate customers who register on the Platform or purchase a subscription; our customers who are individuals or sole proprietorships; prospective customers who request a free trial or demo; and persons who contact us through our sales, support and communication channels.

This notice covers the personal data of authorized representatives, account administrators and users of our corporate customers who register on the Platform or purchase a subscription; our customers who are individuals or sole proprietorships; prospective customers who request a free trial or demo; and persons who contact us through our sales, support and communication channels.

  1. Our Roles as Data Controller and Data Processor

Hipposoft is the data controller with respect to the personal data of the persons listed above that are processed in connection with establishing and maintaining the customer relationship.

Important note on Customer Data: With respect to the personal data that our customers enter or upload into HRplan concerning their own employees (e.g., employee identity and contact information; leave, advance payment, expense and asset assignment records, and documents attached to them), the data controller is our customer, as the employer of the relevant employee. With respect to such data, Hipposoft acts as a data processor within the meaning of Article 3 of the KVKK, solely in accordance with the customer’s instructions and the agreement between us. If you are an employee of a company that uses HRplan, we kindly ask that you first contact your employer to obtain information about the processing of your personal data and to exercise your rights.

Hipposoft is the data controller with respect to the personal data of the persons listed above that are processed in connection with establishing and maintaining the customer relationship.

Important note on Customer Data: With respect to the personal data that our customers enter or upload into HRplan concerning their own employees (e.g., employee identity and contact information; leave, advance payment, expense and asset assignment records, and documents attached to them), the data controller is our customer, as the employer of the relevant employee. With respect to such data, Hipposoft acts as a data processor within the meaning of Article 3 of the KVKK, solely in accordance with the customer’s instructions and the agreement between us. If you are an employee of a company that uses HRplan, we kindly ask that you first contact your employer to obtain information about the processing of your personal data and to exercise your rights.

  1. Categories of Personal Data Processed

Identity

First and last name; Turkish national ID number (T.C. Kimlik No.) for customers who are individuals or sole proprietorships and to whom an invoice must be issued.

Contact

Email address, phone and mobile phone number, business address, billing address.

Customer Transaction

Name of the company you work for and your position, subscription plan and number of users, order and invoice history, support tickets, request and complaint records, correspondence.

Finance

Tax office and tax number; invoice, e-invoice and e-archive information; payment amount, date and method; bank account/IBAN details for refund and collection transactions; transaction result information provided by the payment institution.

Transaction Security

Username, account login and logout records, IP address, device, operating system and browser information, transaction (log) records.

Marketing

Communication preferences and consent records for commercial electronic messages, campaign and email interaction data, and, if you give your consent, usage and preference information obtained through cookies and similar technologies.

Legal Transaction

Contracts, formal notices, official notifications and correspondence, information and documents relating to legal proceedings.

Data category

Personal data

Identity

First and last name; Turkish national ID number (T.C. Kimlik No.) for customers who are individuals or sole proprietorships and to whom an invoice must be issued.

Contact

Email address, phone and mobile phone number, business address, billing address.

Customer Transaction

Name of the company you work for and your position, subscription plan and number of users, order and invoice history, support tickets, request and complaint records, correspondence.

Finance

Tax office and tax number; invoice, e-invoice and e-archive information; payment amount, date and method; bank account/IBAN details for refund and collection transactions; transaction result information provided by the payment institution.

Transaction Security

Username, account login and logout records, IP address, device, operating system and browser information, transaction (log) records.

Marketing

Communication preferences and consent records for commercial electronic messages, campaign and email interaction data, and, if you give your consent, usage and preference information obtained through cookies and similar technologies.

Legal Transaction

Contracts, formal notices, official notifications and correspondence, information and documents relating to legal proceedings.

Data category

Personal data

Identity

First and last name; Turkish national ID number (T.C. Kimlik No.) for customers who are individuals or sole proprietorships and to whom an invoice must be issued.

Contact

Email address, phone and mobile phone number, business address, billing address.

Customer Transaction

Name of the company you work for and your position, subscription plan and number of users, order and invoice history, support tickets, request and complaint records, correspondence.

Finance

Tax office and tax number; invoice, e-invoice and e-archive information; payment amount, date and method; bank account/IBAN details for refund and collection transactions; transaction result information provided by the payment institution.

Transaction Security

Username, account login and logout records, IP address, device, operating system and browser information, transaction (log) records.

Marketing

Communication preferences and consent records for commercial electronic messages, campaign and email interaction data, and, if you give your consent, usage and preference information obtained through cookies and similar technologies.

Legal Transaction

Contracts, formal notices, official notifications and correspondence, information and documents relating to legal proceedings.

Our Company does not request any special categories of personal data from you in the context of the customer relationship. Your credit and debit card details are processed through authorized payment service providers for the purpose of carrying out payment transactions.

Our Company does not request any special categories of personal data from you in the context of the customer relationship. Your credit and debit card details are processed through authorized payment service providers for the purpose of carrying out payment transactions.

  1. Purposes and Legal Grounds for Processing Personal Data

Your personal data are processed for the purposes set out in the table below and on the basis of the legal grounds listed in Article 5 of the KVKK, as indicated next to each purpose. The same data category may be processed for more than one purpose and on more than one legal ground, depending on the activity in which it is used.

Your personal data are processed for the purposes set out in the table below and on the basis of the legal grounds listed in Article 5 of the KVKK, as indicated next to each purpose. The same data category may be processed for more than one purpose and on more than one legal ground, depending on the activity in which it is used.

Purpose of Processing:

Creating memberships and accounts, setting up subscriptions, providing HRplan services and authorizing users

Data Categories:

Identity, Contact, Customer Transaction, Transaction Security

Legal Ground:

Establishment or performance of a contract (Art. 5/2-c)

Purpose of Processing:

Invoicing, payment, collection and refund transactions, and keeping accounting records

Data Categories:

Identity, Contact, Finance

Legal Ground:

Performance of a contract (Art. 5/2-c); expressly provided for by law and compliance with a legal obligation (Art. 5/2-a and ç) – Tax Procedure Law, Turkish Commercial Code

Purpose of Processing:

Providing customer support services, managing requests and complaints

Data Categories:

Identity, Contact, Customer Transaction

Legal Ground:

Performance of a contract (Art. 5/2-c); legitimate interest (Art. 5/2-f)

Purpose of Processing:

Sending mandatory service-related notifications (maintenance, security, version and contract changes)

Data Categories:

Identity, Contact

Legal Ground:

Performance of a contract (Art. 5/2-c)

Purpose of Processing:

Ensuring information security, preventing unauthorized access and misuse, keeping log records

Data Categories:

Transaction Security

Legal Ground:

Compliance with a legal obligation (Art. 5/2-ç) – Law No. 5651 and related legislation; legitimate interest (Art. 5/2-f)

Purpose of Processing:

Measuring service quality, improving the Platform and generating usage statistics

Data Categories:

Customer Transaction, Transaction Security

Legal Ground:

Legitimate interest (Art. 5/2-f)

Purpose of Processing:

Responding to information requests from authorized public institutions and organizations, and ensuring compliance with legislation

Data Categories:

All relevant categories

Legal Ground:

Expressly provided for by law (Art. 5/2-a); compliance with a legal obligation (Art. 5/2-ç)

Purpose of Processing:

Managing legal disputes; establishing, exercising and protecting rights

Data Categories:

Identity, Contact, Finance, Legal Transaction, Transaction Security

Legal Ground:

Establishment, exercise or protection of a right (Art. 5/2-e)

Purpose of Processing:

Sending commercial electronic messages containing promotions, campaigns, newsletters, event announcements and satisfaction surveys

Data Categories:

Identity, Contact, Marketing

Legal Ground:

Explicit consent (Art. 5/1) and approval obtained under Law No. 6563

Purpose of Processing:

Website analytics, personalized advertising and retargeting (through non-essential cookies)

Data Categories:

Transaction Security, Marketing

Legal Ground:

Explicit consent (Art. 5/1) – details are provided in the Cookie Notice

Purpose of processing

Data categories

Legal ground

Creating memberships and accounts, setting up subscriptions, providing HRplan services and authorizing users

Identity, Contact, Customer Transaction, Transaction Security

Establishment or performance of a contract (Art. 5/2-c)

Invoicing, payment, collection and refund transactions, and keeping accounting records

Identity, Contact, Finance

Performance of a contract (Art. 5/2-c); expressly provided for by law and compliance with a legal obligation (Art. 5/2-a and ç) – Tax Procedure Law, Turkish Commercial Code

Providing customer support services, managing requests and complaints

Identity, Contact, Customer Transaction

Performance of a contract (Art. 5/2-c); legitimate interest (Art. 5/2-f)

Sending mandatory service-related notifications (maintenance, security, version and contract changes)

Identity, Contact

Performance of a contract (Art. 5/2-c)

Ensuring information security, preventing unauthorized access and misuse, keeping log records

Transaction Security

Compliance with a legal obligation (Art. 5/2-ç) – Law No. 5651 and related legislation; legitimate interest (Art. 5/2-f)

Measuring service quality, improving the Platform and generating usage statistics

Customer Transaction, Transaction Security

Legitimate interest (Art. 5/2-f)

Responding to information requests from authorized public institutions and organizations, and ensuring compliance with legislation

All relevant categories

Expressly provided for by law (Art. 5/2-a); compliance with a legal obligation (Art. 5/2-ç)

Managing legal disputes; establishing, exercising and protecting rights

Identity, Contact, Finance, Legal Transaction, Transaction Security

Establishment, exercise or protection of a right (Art. 5/2-e)

Sending commercial electronic messages containing promotions, campaigns, newsletters, event announcements and satisfaction surveys

Identity, Contact, Marketing

Explicit consent (Art. 5/1) and approval obtained under Law No. 6563

Website analytics, personalized advertising and retargeting (through non-essential cookies)

Transaction Security, Marketing

Explicit consent (Art. 5/1) – details are provided in the Cookie Notice

  1. Method of Collecting Personal Data

Your personal data are collected through registration, demo request and contact forms on the Platform, in-app transactions, email, phone and live support channels, payment and e-invoicing infrastructures, and cookies and similar technologies, by fully or partially automated means, or by non-automated means provided that they form part of a data filing system. Collection is carried out on the basis of the legal grounds specified for each purpose in Section 4.

Your personal data are collected through registration, demo request and contact forms on the Platform, in-app transactions, email, phone and live support channels, payment and e-invoicing infrastructures, and cookies and similar technologies, by fully or partially automated means, or by non-automated means provided that they form part of a data filing system. Collection is carried out on the basis of the legal grounds specified for each purpose in Section 4.

  1. Transfer of Personal Data

6.1. Domestic transfers

Your personal data may be transferred to the following groups of recipients in accordance with Article 8 of the KVKK, limited to the purposes and legal grounds specified in Section 4:

•      Suppliers and business partners: e-invoice/e-archive integrators, payment service providers, financial advisory and accounting service providers, legal advisors and independent auditors, for the purposes of providing the service, invoicing, processing payments and conducting legal proceedings.

•      Authorized public institutions and organizations, and judicial authorities: institutions such as the Revenue Administration, courts, enforcement offices and the Personal Data Protection Authority, within the scope of our legal obligations and upon request.

6.2. International transfers

The Platform’s infrastructure and certain supporting services are operated through service providers whose servers are located abroad. Your personal data may be transferred to the following service providers, limited to the stated purposes:

6.1. Domestic transfers

Your personal data may be transferred to the following groups of recipients in accordance with Article 8 of the KVKK, limited to the purposes and legal grounds specified in Section 4:

•      Suppliers and business partners: e-invoice/e-archive integrators, payment service providers, financial advisory and accounting service providers, legal advisors and independent auditors, for the purposes of providing the service, invoicing, processing payments and conducting legal proceedings.

•      Authorized public institutions and organizations, and judicial authorities: institutions such as the Revenue Administration, courts, enforcement offices and the Personal Data Protection Authority, within the scope of our legal obligations and upon request.

6.2. International transfers

The Platform’s infrastructure and certain supporting services are operated through service providers whose servers are located abroad. Your personal data may be transferred to the following service providers, limited to the stated purposes:

Service provider

Service and purpose of transfer

Data categories

Microsoft Azure

Hosting of the Platform, database, backup and infrastructure services

Identity, Contact, Customer Transaction, Finance, Transaction Security

Microsoft 365

Corporate email, correspondence and document management

Identity, Contact, Customer Transaction, Legal Transaction

Cloudflare

Content delivery, information security and prevention of cyberattacks

Transaction Security

Brevo

Sending transactional emails such as account and invoice notifications and, if you have given your consent, newsletter and campaign emails

Identity, Contact, Marketing

OneSignal

Sending mobile and web push notifications

Transaction Security (device identifiers), Customer Transaction

Craftgate

Processing payment transactions

Identity, Contact, Finance

Google Analytics

Website and app usage analytics (if you have given cookie consent)

Transaction Security, Marketing

Google Ads

Measuring advertising performance and retargeting (if you have given cookie consent)

Marketing

Hotjar

User experience analysis (if you have given cookie consent)

Transaction Security, Marketing

International transfers are carried out pursuant to Article 9 of the KVKK and the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad: where an adequacy decision exists regarding the country, international organization or sector to which the data will be transferred, on the basis of that decision; and where no such decision exists, on the basis of one of the appropriate safeguards listed in Article 9/4 of the KVKK, primarily the standard contracts announced by the Personal Data Protection Board. In incidental cases where there is no adequacy decision and none of the appropriate safeguards can be provided, the transfer is carried out on the basis of your separately obtained explicit consent (KVKK Art. 9/6-a), provided that you have been informed of the possible risks.

International transfers are carried out pursuant to Article 9 of the KVKK and the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad: where an adequacy decision exists regarding the country, international organization or sector to which the data will be transferred, on the basis of that decision; and where no such decision exists, on the basis of one of the appropriate safeguards listed in Article 9/4 of the KVKK, primarily the standard contracts announced by the Personal Data Protection Board. In incidental cases where there is no adequacy decision and none of the appropriate safeguards can be provided, the transfer is carried out on the basis of your separately obtained explicit consent (KVKK Art. 9/6-a), provided that you have been informed of the possible risks.

  1. Retention Period of Personal Data

Your personal data are retained for as long as necessary for the purpose for which they are processed and for the retention periods prescribed by the relevant legislation. In this context, for example, invoices and accounting records are retained for the periods prescribed by the Tax Procedure Law and the Turkish Commercial Code, while contract-related records are retained, from the termination of the contract, for the statutory limitation periods applicable to potential disputes. Processing based on your explicit consent is terminated if you withdraw your consent. Data whose retention period has expired are deleted, destroyed or anonymized in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data.

Your personal data are retained for as long as necessary for the purpose for which they are processed and for the retention periods prescribed by the relevant legislation. In this context, for example, invoices and accounting records are retained for the periods prescribed by the Tax Procedure Law and the Turkish Commercial Code, while contract-related records are retained, from the termination of the contract, for the statutory limitation periods applicable to potential disputes. Processing based on your explicit consent is terminated if you withdraw your consent. Data whose retention period has expired are deleted, destroyed or anonymized in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data.

  1. Your Rights under the KVKK

Pursuant to Article 11 of the KVKK, you have the right to apply to our Company in order to:

a)    learn whether your personal data are processed,

b)    request information about the processing, if your personal data have been processed,

c)    learn the purpose of processing your personal data and whether they are used in line with that purpose,

ç)    know the third parties in Türkiye or abroad to whom your personal data are transferred,

d)    request the rectification of your personal data if they are incomplete or inaccurately processed,

e)    request the deletion or destruction of your personal data within the framework of the conditions set out in Article 7 of the KVKK,

f)     request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom your personal data have been transferred,

g)    object to a result arising to your detriment through the analysis of the processed data exclusively by automated systems,

ğ)    claim compensation for damages if you suffer damage due to the unlawful processing of your personal data.

Pursuant to Article 11 of the KVKK, you have the right to apply to our Company in order to:

a)    learn whether your personal data are processed,

b)    request information about the processing, if your personal data have been processed,

c)    learn the purpose of processing your personal data and whether they are used in line with that purpose,

ç)    know the third parties in Türkiye or abroad to whom your personal data are transferred,

d)    request the rectification of your personal data if they are incomplete or inaccurately processed,

e)    request the deletion or destruction of your personal data within the framework of the conditions set out in Article 7 of the KVKK,

f)     request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom your personal data have been transferred,

g)    object to a result arising to your detriment through the analysis of the processed data exclusively by automated systems,

ğ)    claim compensation for damages if you suffer damage due to the unlawful processing of your personal data.

  1. Application Procedure

You may submit your requests concerning the rights listed above to our Company, in accordance with the Communiqué on the Procedures and Principles for Applications to the Data Controller, through one of the following methods:

•      In writing, in person or through a notary public, to our address set out in Section 10, together with documents verifying your identity;

•      From your Registered Electronic Mail (KEP) address to [email protected];

•      To [email protected], signed with a secure electronic signature or mobile signature;

•      To [email protected] from the email address you have previously provided to our Company and that is registered in our system.

Your application must include: your first and last name and, if the application is made in writing, your signature; your Turkish national ID number if you are a citizen of the Republic of Türkiye, or your nationality and passport number or, if any, your ID number if you are a foreign national; your residential or business address for service of notices; your email address and phone number for notifications, if any; and the subject of your request. Any information and documents relating to your request should be attached to the application.

Your applications will be concluded free of charge, following identity verification, as soon as possible depending on the nature of the request and within thirty (30) days at the latest. If the process requires an additional cost, a fee may be charged in accordance with the tariff set by the Personal Data Protection Board. If your application is rejected, you find the response insufficient, or no response is given in due time, you may file a complaint with the Personal Data Protection Board within thirty (30) days from the date you learn of the response and, in any case, within sixty (60) days from the date of your application.

You may submit your requests concerning the rights listed above to our Company, in accordance with the Communiqué on the Procedures and Principles for Applications to the Data Controller, through one of the following methods:

•      In writing, in person or through a notary public, to our address set out in Section 10, together with documents verifying your identity;

•      From your Registered Electronic Mail (KEP) address to [email protected];

•      To [email protected], signed with a secure electronic signature or mobile signature;

•      To [email protected] from the email address you have previously provided to our Company and that is registered in our system.

Your application must include: your first and last name and, if the application is made in writing, your signature; your Turkish national ID number if you are a citizen of the Republic of Türkiye, or your nationality and passport number or, if any, your ID number if you are a foreign national; your residential or business address for service of notices; your email address and phone number for notifications, if any; and the subject of your request. Any information and documents relating to your request should be attached to the application.

Your applications will be concluded free of charge, following identity verification, as soon as possible depending on the nature of the request and within thirty (30) days at the latest. If the process requires an additional cost, a fee may be charged in accordance with the tariff set by the Personal Data Protection Board. If your application is rejected, you find the response insufficient, or no response is given in due time, you may file a complaint with the Personal Data Protection Board within thirty (30) days from the date you learn of the response and, in any case, within sixty (60) days from the date of your application.

  1. Data Controller’s Contact Information

Trade name

HİPPOSOFT YAZILIM LİMİTED ŞİRKETİ

Address

AKAT MAH. HARE SK. 2.SÖLTAŞ K-10 BLOK NO: 12 BEŞİKTAŞ/ İSTANBUL

Website

www.hrplan.net

Trade name

HİPPOSOFT YAZILIM LİMİTED ŞİRKETİ

Address

AKAT MAH. HARE SK. 2.SÖLTAŞ K-10 BLOK NO: 12 BEŞİKTAŞ/ İSTANBUL

Phone

0850 288 3230

Website

www.hrplan.net

  1. Changes to This Notice

This notice may be updated in line with changes in legislation and in our personal data processing activities. The current version of the notice is always published at www.hrplan.net; the “Last Updated” date at the top of the notice indicates the most recent change.

This notice may be updated in line with changes in legislation and in our personal data processing activities. The current version of the notice is always published at www.hrplan.net; the “Last Updated” date at the top of the notice indicates the most recent change.

Purpose of processing

Data categories

Legal ground

Creating memberships and accounts, setting up subscriptions, providing HRplan services and authorizing users

Identity, Contact, Customer Transaction, Transaction Security

Establishment or performance of a contract (Art. 5/2-c)

Invoicing, payment, collection and refund transactions, and keeping accounting records

Identity, Contact, Finance

Performance of a contract (Art. 5/2-c); expressly provided for by law and compliance with a legal obligation (Art. 5/2-a and ç) – Tax Procedure Law, Turkish Commercial Code

Providing customer support services, managing requests and complaints

Identity, Contact, Customer Transaction

Performance of a contract (Art. 5/2-c); legitimate interest (Art. 5/2-f)

Sending mandatory service-related notifications (maintenance, security, version and contract changes)

Identity, Contact

Performance of a contract (Art. 5/2-c)

Ensuring information security, preventing unauthorized access and misuse, keeping log records

Transaction Security

Compliance with a legal obligation (Art. 5/2-ç) – Law No. 5651 and related legislation; legitimate interest (Art. 5/2-f)

Measuring service quality, improving the Platform and generating usage statistics

Customer Transaction, Transaction Security

Legitimate interest (Art. 5/2-f)

Responding to information requests from authorized public institutions and organizations, and ensuring compliance with legislation

All relevant categories

Expressly provided for by law (Art. 5/2-a); compliance with a legal obligation (Art. 5/2-ç)

Managing legal disputes; establishing, exercising and protecting rights

Identity, Contact, Finance, Legal Transaction, Transaction Security

Establishment, exercise or protection of a right (Art. 5/2-e)

Sending commercial electronic messages containing promotions, campaigns, newsletters, event announcements and satisfaction surveys

Identity, Contact, Marketing

Explicit consent (Art. 5/1) and approval obtained under Law No. 6563

Website analytics, personalized advertising and retargeting (through non-essential cookies)

Transaction Security, Marketing

Explicit consent (Art. 5/1) – details are provided in the Cookie Notice

Service provider

Service and purpose of transfer

Data categories

Microsoft Azure

Hosting of the Platform, database, backup and infrastructure services

Identity, Contact, Customer Transaction, Finance, Transaction Security

Microsoft 365

Corporate email, correspondence and document management

Identity, Contact, Customer Transaction, Legal Transaction

Cloudflare

Content delivery, information security and prevention of cyberattacks

Transaction Security

Brevo

Sending transactional emails such as account and invoice notifications and, if you have given your consent, newsletter and campaign emails

Identity, Contact, Marketing

OneSignal

Sending mobile and web push notifications

Transaction Security (device identifiers), Customer Transaction

Craftgate

Processing payment transactions

Identity, Contact, Finance

Google Analytics

Website and app usage analytics (if you have given cookie consent)

Transaction Security, Marketing

Google Ads

Measuring advertising performance and retargeting (if you have given cookie consent)

Marketing

Hotjar

User experience analysis (if you have given cookie consent)

Transaction Security, Marketing

Microsoft Azure

Service & Purpose of Transfer:

Hosting of the Platform, database, backup and infrastructure services

Transferred Categories:

Identity, Contact, Customer Transaction, Finance, Transaction Security

Microsoft 365

Service & Purpose of Transfer:

Corporate email, correspondence and document management

Transferred Categories:

Identity, Contact, Customer Transaction, Legal Transaction

Cloudflare

Service & Purpose of Transfer:

Content delivery, information security and prevention of cyberattacks

Transferred Categories:

Transaction Security

Brevo

Service & Purpose of Transfer:

Sending transactional emails such as account and invoice notifications and, if you have given your consent, newsletter and campaign emails

Transferred Categories:

Identity, Contact, Marketing

OneSignal

Service & Purpose of Transfer:

Sending mobile and web push notifications

Transferred Categories:

Transaction Security (device identifiers), Customer Transaction

Craftgate

Service & Purpose of Transfer:

Processing payment transactions

Transferred Categories:

Identity, Contact, Finance

Google Analytics

Service & Purpose of Transfer:

Website and app usage analytics (if you have given cookie consent)

Transferred Categories:

Transaction Security, Marketing

Google Ads

Service & Purpose of Transfer:

Measuring advertising performance and retargeting (if you have given cookie consent)

Transferred Categories:

Marketing

Hotjar

Service & Purpose of Transfer:

User experience analysis (if you have given cookie consent)

Transferred Categories:

Transaction Security, Marketing