Whose data, whose responsibility?
Bildirim.io appears in two different relationships in two different capacities. Which text concerns you depends on how you came into contact with us.
| Relationship | Data controller | Bildirim.io’s capacity |
|---|---|---|
| A customer with an account on Bildirim.io (publisher, site owner) | Bildirim.io service operator | Data controller — we process your account data on our own behalf |
| A reader who allows notifications on our customer’s site | Our customer (the news site / business concerned) | Data processor — we process only on the customer’s instruction |
Personal data processed
From our account-holding customers:
- Name and surname (as far as you choose to give them)
- Email address
- An irreversible hash of your password (Argon2id) — the password itself is never stored
- Billing and payment details (processed by the payment provider; card data never reaches us)
- Records of your use of the service: the projects, campaigns and automations you create
From our customers’ end users (notification subscribers):
- The push endpoint address generated by the browser and the encryption keys belonging to it
- Tags defined by the customer (e.g. interest category) and, if provided, the customer’s own user identifier
- Browser, operating system, language, country and time zone
- First subscription time, last seen time and subscription status
- Delivery and click events for the notifications sent
Purposes and legal bases
| Purpose | Legal basis (KVKK art. 5) |
|---|---|
| Creating your account and providing the service | Formation and performance of a contract |
| Delivering notifications | Performance of a contract / customer instruction |
| Invoicing and collection | Performance of a contract, legal obligation |
| Preventing abuse, spam and fraud | Legitimate interest |
| Monitoring service quality and errors | Legitimate interest |
| Retaining financial records | Legal obligation |
| Sending marketing messages (only if you separately opted in) | Explicit consent |
A notification subscription rests on permission given by the end user through their browser. Permission is collected by the browser’s own prompt; the user can withdraw it at any time from browser settings, and once withdrawn delivery also stops technically.
Who is it transferred to?
For a notification to reach the user’s device, passing it to the browser vendor’s push service is a technical necessity. Those services are established abroad. Notification content is delivered to them encrypted (RFC 8291); the push service in between cannot decrypt it.
The current list of sub-processors and what data goes where is published as a table on the Sub-Processors page. Beyond that we do not sell your personal data to third parties or share it for marketing. Data is shared only in response to lawful requests from public authorities, limited to the scope requested.
Retention periods
| Data | Retention period |
|---|---|
| Account record (name, email, password hash) | Until the account is deleted; within 30 days of a deletion request |
| Subscriber record (push endpoint, encryption keys, tags, country, browser, operating system, language, time zone) | Until the subscription ends or the project is deleted |
| Campaign content and send records | Until the project is deleted |
| Delivery and click events | 12 months (deleted automatically as monthly partitions) |
| Outgoing webhook delivery records | 90 days (deleted automatically) |
| Session refresh tokens | 30 days (invalid once expired) |
| Invoice and payment records | The period required by financial legislation (10 years) |
The periods are applied automatically by the system; for detail and the deletion method see the Retention and Deletion Policy.
Your rights (KVKK art. 11)
- To learn whether your personal data is processed
- To request information about it if it is
- To learn the purpose of processing and whether it is used accordingly
- To know the third parties to whom it is transferred, at home or abroad
- To request correction if it is incomplete or inaccurate
- To request erasure or destruction where the conditions are met
- To request that correction, erasure and destruction be notified to third parties it was transferred to
- To object to an adverse outcome produced solely by automated analysis
- To claim compensation if you suffer loss because of unlawful processing
How to apply
You can send your requests by email to [email protected]. Depending on its nature we conclude your request free of charge within thirty days at the latest. If the process incurs a cost, the fee set out in the Board’s tariff may be charged.
Where we cannot verify the applicant’s identity we may ask for further information; this is to prevent data being disclosed to an unauthorised person.
Identity of the data controller
| Field | Detail |
|---|---|
| Operator | Bildirim.io service operator |
| Service | https://bildirim.io |
| [email protected] |