Privacy Policy

Information on the processing of personal data under the GDPR

Privacy at a Glance

The following information provides an overview of which personal data we process when you use our website and our mobile app, and what rights you have.

Controller

PARPALİ YAZILIM VE BİLİŞİM HİZMETLERİ TİCARET LİMİTED ŞİRKETİ
Beştepe Mah.
Yenimahalle / Ankara, Türkiye

Email: info@fibreact.com
Data protection: datenschutz@fibreact.com
Phone: +90 552 251 06 53

FibreAct is used by companies for their own employees. The respective customer company is generally the controller for the processing of its employees' data; in that respect we act as a processor pursuant to Art. 28 GDPR. For our own website, registration and contract handling, we are the controller within the meaning of the GDPR.

Data We Process

When you use our services, we process in particular the following personal data:

  • First and last name and role within the company
  • Email address and telephone number
  • Company name and address
  • Job and installation data (e.g. site address, installation status, recorded measurements, documentation photos)
  • Device and connection data (device type, operating system and app version, push token)
  • Usage data (e.g. pages visited, access times)

Location Data

The mobile app records the device's location in order to document installation points and assign jobs to the correct site. In the foreground, location is recorded only while the app is open.

In addition, location may be recorded in the background. This is not active by default: it requires the customer company to enable the background tracking setting and the data subject to grant the corresponding permission on the device. The permission can be revoked at any time in the device's system settings.

The legal basis is the performance of the employment relationship (Art. 88 GDPR in conjunction with § 26 BDSG) or a legitimate interest of the customer company in coordinating field operations (Art. 6(1)(f) GDPR). Whether and to what extent location tracking of employees is permissible depends on the arrangements between the customer company and its employees; the customer company is responsible for this.

Camera and Photos

The app accesses the camera and photo library in order to capture, edit and store installation and documentation photos. Images are assigned to the relevant job and transmitted to our servers. Access takes place only with your explicit permission and can be revoked at any time.

Push Notifications

We use Firebase Cloud Messaging for job and appointment notifications. A device-specific push token is processed for this purpose. You can disable notifications at any time in your device's system settings.

Payment Processing

Payment processing is handled by Paddle.com as Merchant of Record. We do not store any credit card or bank details. Paddle processes your payment data in accordance with its own privacy policy.

Cookies

We use only technically necessary cookies for authentication and session management. We do not use tracking or advertising cookies.

Service Providers We Use

We use carefully selected service providers with whom data processing agreements pursuant to Art. 28 GDPR are in place:

  • Google Ireland Limited – Firebase Cloud Messaging for sending push notifications
  • Paddle.com Market Ltd. – payment processing as Merchant of Record
  • Contabo GmbH, Germany – operation of the application and database servers

Server Location

Our application and database servers are operated by Contabo GmbH in Germany. Personal data arising from the use of FibreAct is stored exclusively on servers within the European Union.

Transfers to Third Countries

As described under “Server Location”, data is stored in Germany. However, the controlling company is established in Türkiye, and there is no adequacy decision of the European Commission for Türkiye. Where our staff access this data from Türkiye for administration, maintenance and support purposes, this constitutes a transfer to a third country. It takes place on the basis of the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary technical and organisational safeguards.

Retention Period

We store personal data only for as long as is necessary for the respective purposes. After the contractual relationship ends, data is deleted unless statutory retention obligations apply. Job and documentation data is deleted on behalf of, and according to the instructions of, the respective customer company.

Your Rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Please contact datenschutz@fibreact.com. If your request concerns data we process on behalf of your employer, we will forward it to the responsible company.

Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority.

Changes to This Policy

We reserve the right to amend this privacy policy in order to reflect changes in the law or in the features of our services. The current version is always available on this page.