This English text is a translation provided for convenience; in case of any discrepancy, the Turkish version (Gizlilik Politikası) prevails.
1. Who we are and scope of this policy
GOSpock is the brand and service operated by Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti. (the “Company”, “we”, “us”). GOSpock is business-to-business software provided as a service that enables companies with websites and mobile apps (“customers”) to send push notifications to web browsers, iOS apps and Android apps, and to manage campaigns, analyse events and attribute results to campaigns.
- Trade name: Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti.
- Address: İstiklal Mah. Piyalepaşa Bulv. No:22/1 B-C Blok, Beyoğlu / İstanbul, Türkiye
- Tax office and number: Kasımpaşa Vergi Dairesi – 6300431044
- E-mail: info@gospock.com
This policy covers the gospock.com website, the GOSpock admin panel (the “panel”) and the services provided through the GOSpock software development kit (the “SDK”). For our formal information notice under the Turkish Personal Data Protection Law No. 6698 (“KVKK”), see the Personal Data Protection Notice (KVKK).
2. Our two roles
We process personal data in two different roles. Which role applies determines to whom you should address your questions and requests.
a) As data controller
For the following people, we determine the purposes and means of processing and are therefore the data controller:
- visitors of the gospock.com website,
- business contacts and prospects who contact us by e-mail,
- panel users (employees and representatives of our customers who are invited to the panel).
b) As data processor
We process the data of people who use our customers’ websites and apps and receive their notifications (“end users”) on behalf of our customers and on their instructions. The data controller for this data is the respective customer; GOSpock acts as data processor. We do not use this data for our own purposes.
If you receive notifications from, or use, a company’s app or website, please address your questions and requests about your data directly to that company. We forward any such requests we receive to the customer concerned without delay and support the customer in answering them.
The processing terms for our customers are set out in the Data Processing Agreement.
3. Data we process as data controller
In the table below, legal bases are given by reference to the sub-paragraphs of Art. 5(2) KVKK. Where the EU General Data Protection Regulation (“GDPR”) applies, the corresponding basis is given in brackets.
| Whose data | Data | Purposes | Legal basis |
|---|---|---|---|
| Panel users | First and last name, e-mail address; password hash (the password itself is not stored); two-factor authentication and passkey data; panel language and theme preferences; session data | Opening and managing the account, secure sign-in to the panel, providing the service, support, sending invitation, password reset and limit warning e-mails | Art. 5(2)(c) performance of the contract with the customer; (f) legitimate interest (GDPR Art. 6(1)(b), (f)) |
| Panel users | Audit log (who did what, when); IP address and browser information in security logs | Information security, preventing unauthorised access and misuse, traceability of actions, evidence in disputes | Art. 5(2)(ç) legal obligation; (e) establishing, exercising or protecting a right; (f) legitimate interest (GDPR Art. 6(1)(f)) |
| Customer representatives | First and last name, title, company, contact details, contract and invoicing details | Concluding and performing the contract, invoicing, complying with commercial and financial obligations | Art. 5(2)(c) contract; (ç) legal obligation (GDPR Art. 6(1)(b), (f)) |
| Business contacts and prospects | First and last name, company, e-mail, phone, message content | Answering requests and questions, preparing offers, managing the business relationship | Art. 5(2)(c) steps taken at your request before entering into a contract; (f) legitimate interest (GDPR Art. 6(1)(b), (f)) |
| Website visitors | Server access logs: IP address, time, requested page, browser information (user agent) | Security and operation of the website, statutory traffic data obligations | Art. 5(2)(ç) legal obligation; (f) legitimate interest (GDPR Art. 6(1)(f)) |
gospock.com is a static website: it uses no analytics, no advertising or tracking cookies and no third-party trackers; all files, including fonts, are loaded from our own server and no data reaches third parties when a page loads. We obtain panel users’ data from the customer who invites them to the panel and from the users themselves; business contacts’ data from the e-mails they send us; and visitor and security logs from records generated automatically by our systems.
4. Data we process on behalf of our customers (SDK)
Our customers can add the GOSpock SDK to their websites and apps to send notifications and measure usage events. In this context, and limited to the customer’s instructions, we process the following data:
| Category | Data |
|---|---|
| Device and session | Random device id generated by the SDK (udid), session id, platform (web, iOS, Android), app version, SDK version |
| Notifications | Push token or web push subscription (endpoint and keys), notification permission state, notification channel preferences |
| Customer’s user id | Only if the customer uses the identify() function: a pseudonymous user id chosen by the customer. GOSpock does not ask for names, e-mail addresses or phone numbers. |
| Events | Events and their properties as defined by the customer, for example screens and content viewed, videos started, searches, notifications received and opened, campaign and variant id, UTM parameters |
| Time information | Event timestamps on the device and on the server |
| IP address | Used only transiently for security, rate limiting and abuse prevention; not stored with events. |
Data we do not collect: GOSpock does not collect precise location, contacts, advertising ids or special categories of personal data (e.g. health, religion, ethnic origin, biometric data). Our customers are obliged not to send such data in event properties.
Events that occur within 30 minutes after a notification is clicked or a link containing the gs_cid parameter is opened carry the id of the related campaign, so that the customer can measure the results of its campaigns. The data of each customer and of each app is kept separate.
The customer, as data controller, is responsible for informing its end users, obtaining any required permissions and consents, and naming GOSpock as a data processor in its own privacy notice.
5. How notifications work and how to stop them
Before a website or app can send notifications, your operating system or browser asks you for notification permission. Unless you grant this permission, no push notifications can be sent to you.
When you grant permission, a push token or web push subscription is created for your device. When the customer prepares a campaign in the panel, GOSpock passes the notification content and this token to the relevant push service (Google Firebase Cloud Messaging, Apple Push Notification service or your browser’s push service), which delivers the notification to your device.
You can stop notifications at any time:
- Mobile apps: Turn off notification permission for the app in your device settings (e.g. on iOS: Settings > Notifications; on Android: Settings > Apps > the app > Notifications).
- Websites: Remove the site’s notification permission in your browser’s site settings.
- Channel preferences: If the customer offers notification channel preferences in its app or site, you can turn off specific types of notifications there.
Tokens reported as invalid by the push service are deactivated. Where a notification is a commercial electronic message, the sending customer is responsible for complying with Law No. 6563 on the Regulation of Electronic Commerce and the rules of the Message Management System (İYS).
6. Hosting and transfers abroad
GOSpock’s servers and databases are hosted in data centers in Türkiye.
Data is transferred abroad only to deliver notifications, which is inherent to the service. Notifications are delivered through Google Firebase Cloud Messaging (Google LLC / Google Ireland), Apple Push Notification service (Apple Inc.) and the push services of browser vendors (Google, Mozilla, Apple, Microsoft). Only the data needed for delivery is sent to these services: the push token or web push subscription and the notification content (title, text, image link, link).
These transfers concern our customers’ end users; the customer, as data controller, decides to use these channels by enabling them. The transfers are made under Art. 9 KVKK, as amended by Law No. 7499 and in force since 1 June 2024, on the basis of appropriate safeguards (in particular standard contracts notified to the Personal Data Protection Authority within five business days of signature) or, where these are not available, the occasional-transfer exceptions provided by law. For customers to whom the GDPR applies, transfer safeguards are set out in the Data Processing Agreement.
E-mails such as invitations, password resets and limit warnings are sent through e-mail service providers; where these providers are located abroad, the transfer is made in accordance with the conditions of Art. 9 KVKK. Website visitors’ data is not transferred abroad; server access logs are kept only by the hosting provider in Türkiye.
7. Sharing of data
We do not sell or rent personal data and do not use it for advertising; we do not combine our customers’ end-user data with that of other customers or third parties. Data is shared only in the following cases and to the extent necessary:
- With the infrastructure providers we use to provide the service: hosting providers in Türkiye, e-mail service providers and the push services listed above for delivering notifications.
- For data processed on behalf of a customer, with the customer to whom the data belongs and in line with the instructions the customer gives through the panel.
- With public authorities and courts empowered by law, where there is a legal obligation.
8. Retention periods
- Raw event data: 90, 180 or 395 days depending on the customer’s package (for the Enterprise package, the period set in the contract); in any case no longer than 13 months unless otherwise agreed in the contract. Aggregated statistics that contain no personal data may be kept longer.
- Device records and push tokens: As long as the device is active. Tokens reported as invalid by the push service are deactivated.
- After the contract ends: Customer data is deleted or anonymised within 90 days, unless the law requires it to be kept. The customer may request an export of its data before then.
- Panel user accounts: For the term of the contract and thereafter for the statutory retention periods (e.g. 10 years for commercial records under the Turkish Commercial Code, where applicable).
- Security and access logs: Up to 2 years; at least 1 year where the traffic data obligations under Law No. 5651 apply.
- Correspondence with business contacts: Up to 3 years after the last contact, unless a contract follows.
Data whose retention period has expired is deleted, destroyed or anonymised.
9. Security
The main technical and organisational measures we take to protect personal data are:
- encryption in transit (HTTPS/TLS),
- storing passwords as hashes,
- two-factor authentication and passkeys for panel users,
- role-based access control and separation of each app’s data,
- separation of secret API keys from public SDK keys, and allowed web origins for SDK keys,
- rate limiting,
- audit logs of administrative actions,
- access to data by GOSpock staff only when needed (e.g. for a support request),
- backups.
10. Your rights
Under Art. 11 KVKK, you have the right to learn whether your personal data is processed; to request information if it has been processed; to learn the purpose of processing and whether data is used in line with that purpose; to know the third parties in Türkiye or abroad to whom data is transferred; to request correction if data is incomplete or inaccurate; to request erasure or destruction under Art. 7 KVKK; to request that these actions be notified to third parties to whom data has been transferred; to object to a result to your detriment arising from analysis exclusively by automated systems; and to claim compensation for damage arising from unlawful processing.
Where the GDPR applies (e.g. for people located in the European Union), you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests, and, where processing is based on consent, the right to withdraw consent at any time.
You can send your requests to info@gospock.com or to our postal address in section 1. The application procedure is described in the Personal Data Protection Notice (KVKK). We answer requests within 30 days at the latest and, as a rule, free of charge; we may ask for additional information to verify your identity.
If your application is rejected, you find our answer insufficient or we do not answer in time, you may lodge a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) under Art. 14 KVKK. Where the GDPR applies, you may also lodge a complaint with the supervisory authority of the EU member state of your habitual residence, place of work or place of the alleged infringement.
End users: If you use one of our customers’ apps or websites, you need to exercise your rights against that company as data controller. We forward requests we receive to the customer concerned and support the customer.
11. Children
GOSpock is a service for businesses; gospock.com and the panel are not directed at children and we do not knowingly collect children’s data. Where our customers’ apps are used by children, the customer as data controller is responsible for complying with applicable law and obtaining any required permissions.
12. Cookies and similar technologies
gospock.com does not use cookies; only the key gs_site_lang is kept in your browser’s local storage (localStorage) to remember the site language you chose. The panel uses first-party cookies only for strictly necessary purposes such as keeping you signed in and security. The GOSpock SDK on our customers’ websites stores values such as the device id and the notification registration on the customer’s own domain. For details, see the Cookie Policy.
13. Changes
We may update this policy to reflect changes in our services or in the law. The current text is published on this page and the “last updated” date at the top of the page is changed. We notify our customers and panel users separately of material changes.
14. Contact
For any questions about this policy or your personal data, you can reach us at info@gospock.com or at Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti., İstiklal Mah. Piyalepaşa Bulv. No:22/1 B-C Blok, Beyoğlu / İstanbul, Türkiye.