Legal

Privacy Policy

Last updated: 2 October 2026 · Also available in: Türkçe

This policy explains how Murat Efe Doğan (bradi.tech) ("bradi", "we", "us") handles personal data when you visit www.bradi.tech, contact us, or use bradi GO, our client panel at https://go.bradi.tech (together, the "Services"). It applies to the website, the panel, the bradi GO website tracker that our clients install on their own sites, and our integrations with Meta (Facebook, Instagram, WhatsApp) and Google.

Short version: we collect what we need to run a reporting panel for businesses that hire us, we read advertising and messaging data only with the account owner's permission, we never sell personal data or use it for our own advertising, and you can ask us to delete it at any time by writing to [email protected].

1. Who we are and how to reach us

The data controller for the website and for bradi GO user accounts is Murat Efe Doğan (bradi.tech), a sole proprietorship registered in Türkiye, located in Ankara, Türkiye.

Contact for all privacy matters, including requests to access or delete data: [email protected]. We answer within 30 days at the latest, and usually much sooner.

bradi is a digital marketing and software agency. bradi GO is an invite-only panel we provide to our business clients: it shows their website analytics, advertising results and, where they choose to connect it, WhatsApp Business conversation analytics. There is no public sign-up.

2. Our role: controller and processor

We act in two roles, and the difference matters for who you should contact first:

  • Controller: for the website (www.bradi.tech), for the contact form, and for the accounts of people who sign in to bradi GO. We decide why and how this data is processed.
  • Processor (on behalf of our client): for data about our clients' own website visitors, advertising accounts and WhatsApp Business conversations. The client business is the controller of that data; we process it only to provide the panel to that client, under their instructions and our agreement with them.

If you visited one of our clients' websites, or messaged one of our clients on WhatsApp, that business decides how your data is used. You can contact them directly, or write to [email protected] and we will forward your request and help them answer it.

3. What we collect

a) Visitors of www.bradi.tech

  • Contact form: your name, email address, phone or WhatsApp number, business name, your message, the page you first arrived on and the page you sent the form from. The "leave your email" box collects only your email address.
  • Website analytics: pages viewed, referrer, approximate location derived from your IP address, device and browser type, collected through Umami (cookieless), PostHog and the Google Ads tag (gtag.js). PostHog and Google may set cookies; see section 10.

b) bradi GO users (people at our client businesses and bradi staff)

  • Account: email address, a display name, language preference (English or Turkish), role (client or admin) and the businesses you belong to. Passwords are stored only as a one-way hash; sign-in links are stored hashed and expire after 10 minutes.
  • Sessions and security: session records with IP address and browser user agent, and a security log of sign-ins and administrative actions (for example inviting a user or adding a site), including the IP address.
  • Usage: one record per user per day of which panel sections were used and for how many minutes. We do not record full URLs, search terms, IP addresses or browser details in this usage record.
  • Content you create: funnels, saved settings, competitor analyses, and chat conversations with the panel's assistant.

c) Visitors of our clients' websites (bradi GO tracker)

When a client installs the bradi GO snippet on their website, it sends the following for each page view and interaction:

  • The page path (without the query string), the referring URL, campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the name of any ad click identifier present (for example "fbclid" or "gclid" — the name only, never its value).
  • Approximate location (country, and region and city where our network provider supplies them), the browser window width, time on page, scroll depth, number of clicks, and for clicks on links and buttons the element's visible label, link target and id. Text typed into form fields is never collected.
  • A visitor identifier that is a one-way hash of the IP address and browser user agent combined with a random key that changes every day and is deleted after 36 hours. The IP address and user agent themselves are not stored, and the identifier cannot be linked across days.
  • The tracker sets no cookies and uses no local storage on the visitor's device. It does not run when the browser sends a Do Not Track signal, and it ignores known bots.
  • Session replay (only if the client turns it on for a share of visits, off by default): a recording of the page structure and changes (not a video), with every form field masked, query strings removed, and any element the client marks as private hidden or masked. Recordings are capped at one hour.

d) Data from Meta (Facebook and Instagram advertising)

Only when a client user connects their Meta ad account through "Login with Facebook for Business" and approves the requested permissions (ads_read and business_management), we receive:

  • An access token for that user's grant, which we store encrypted (see section 8).
  • The list of ad accounts the user can access (account id, name, currency, time zone, status), so the user can pick one.
  • For the selected ad account only: daily advertising statistics at account and campaign level — spend, impressions, reach, clicks, click-through rate, cost per click, cost per thousand impressions, reported actions such as conversations started and purchases, purchase values, campaign ids and campaign names, currency and attribution setting.

We do not receive or store Facebook profile data, friends, posts, page content or any data about the people who saw or clicked the ads beyond these aggregate statistics. Our access is read-only: bradi GO cannot create, change or pause campaigns, budgets or bids.

e) Data from WhatsApp Business (Meta WhatsApp Business Platform)

Only when a client connects a WhatsApp Business number to bradi GO (through Meta's Embedded Signup, with the business account owner's approval), Meta sends us, for that number:

  • Messages received and sent (including the text, the customer's phone number and WhatsApp profile name, timestamps, message type and, for messages that started from a Click-to-WhatsApp ad, the ad reference).
  • Replies sent by the business from the WhatsApp Business app, message history the business chooses to share (up to six months), contact names synced from the app, and account status updates.

We use this only to show the client their own conversation analytics (for example response times, conversation volume and which ads produced conversations). bradi GO is read-only for WhatsApp: it does not send messages on anyone's behalf.

f) Data from Google (when connected)

If a client connects Google Ads or Google Search Console, we receive read-only reporting data: for Google Ads, daily cost, impressions, clicks, conversions and conversion value per account and campaign (with campaign names); for Search Console, clicks, impressions, click-through rate and position by date, search query and page. The scopes requested are adwords and webmasters.readonly.

g) Publicly available data for competitor analysis

When a client runs a competitor analysis, we collect publicly available information: the client's own website text, competitors' public websites and social profiles, and ads that competitors publish in the Meta Ad Library and LinkedIn Ad Library. Ads in these libraries are public by law; we store the ad text, images, dates and the advertiser's page name.

4. Why we use it and on what legal basis

PurposeDataLegal basis (KVKK art. 5 / GDPR art. 6)
Answer your enquiry and prepare an offerContact form dataSteps before entering a contract; our legitimate interest in replying
Provide bradi GO to our clients (accounts, sign-in, reports)Account, session, content, tracker, Meta, Google and WhatsApp dataPerformance of our contract with the client; for data we process for clients, the client's instructions
Keep the panel secure and prevent misuseSession records, IP addresses, security logLegitimate interest; legal obligation to keep systems secure
Send service emails (sign-in links, password resets, reports, alerts, analysis ready)Email address, language, report figuresPerformance of contract
Improve the website and measure our own advertisingWebsite analytics and cookiesConsent where cookies require it; otherwise legitimate interest
Comply with law and handle legal claimsAny relevant dataLegal obligation; establishment, exercise or defence of legal claims

We do not use personal data for automated decisions that have legal or similarly significant effects on you.

5. How we use data received from Meta

Data we receive through Meta's platforms (Facebook Login for Business, the Marketing API and the WhatsApp Business Platform) is used only to provide the client who connected it with their own reports inside bradi GO. In particular:

  • We do not sell, rent or license Meta data, and we do not share it with data brokers or advertising networks.
  • We do not use it to build profiles of people, to target or retarget advertising, or to train general-purpose AI models.
  • We do not combine one client's Meta data with another client's data. Each client sees only the accounts they connected.
  • Where we pass figures to an AI provider to generate a written summary for that same client (section 6), the provider is contractually barred from using it to train its models, and request storage is disabled.
  • We keep it only as long as section 9 says, and delete it on request as described in our Data Deletion page: bradi.tech/data-deletion.
  • We comply with the Meta Platform Terms and Developer Policies.

You can remove bradi GO's access to your Facebook account at any time in Facebook: Settings & privacy → Settings → Business integrations (or Apps and websites) → bradi GO → Remove. For a business portfolio: Business settings → Integrations → Connected apps.

6. Who we share it with

We never sell personal data. We share it only with the service providers below, which process it on our behalf under contract, and only as far as each needs:

ProviderWhat forLocation
Railway CorporationHosting of the website, the panel and its databaseServers in the EU (Netherlands); company in the USA
Cloudflare, Inc.Network, security and approximate visitor locationGlobal network; USA
Resend, Inc.Sending emails (sign-in links, reports, contact form)USA
OpenAI, L.L.C.Competitor research and the panel's chat assistantUSA
Anthropic, PBCWritten summaries in weekly reportsUSA
Apify Technologies s.r.o.Collecting public ads and search results for competitor analysisCzech Republic (EU)
Meta Platforms Ireland Ltd. / Meta Platforms, Inc.Facebook Login, Marketing API, WhatsApp Business PlatformIreland / USA
Google LLC / Google Ireland Ltd.Google Ads and Search Console APIs, Google sign-in for those, Google Ads tag on the website, Translate on shared reportsIreland / USA
PostHog, Inc. and Umami Software, Inc.Analytics on www.bradi.tech onlyUSA / EU

We may also disclose data where the law requires it, to a court or public authority, or to protect our rights, and to a successor if the business is transferred, in which case this policy continues to apply.

7. International transfers

Some of the providers above are located outside Türkiye and outside the European Economic Area, mainly in the USA. Where we transfer personal data abroad, we rely on the safeguards the law provides: for transfers from Türkiye, the standard contractual clauses under KVKK article 9 notified to the Personal Data Protection Authority, or your explicit consent where required; for data subject to the GDPR, the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework where the provider is certified.

8. How we protect it

  • All traffic is encrypted in transit (HTTPS/TLS).
  • Access tokens from Meta and Google are encrypted at rest with AES-256-GCM, each bound to the business and connection it belongs to, and are never shown to anyone, including our staff.
  • Webhooks from Meta are accepted only with a valid cryptographic signature.
  • The panel is invite-only; every query is limited to the business the signed-in user belongs to. Staff access to a client account is logged, limited to one hour and visibly marked in the panel.
  • The database is reachable only from our private hosting network.

No system is perfectly secure. If a breach affects your personal data, we will notify the authorities and you as the law requires. Report a suspected security issue to [email protected].

9. How long we keep it

DataKept for
Contact form and email-box messagesAs long as needed to answer and, if you become a client, for the duration of the relationship; otherwise up to 2 years
Sign-in links / password-reset links10 minutes / 1 hour
Panel accounts and the content users createWhile the user has access to bradi GO; deleted within 30 days of a deletion request or the end of the client relationship
Panel usage records365 days
Security log (sign-ins and administrative actions)Up to 2 years
Tracker events from clients' websites180 days; daily totals without personal data are kept for reporting
Daily visitor hashing key36 hours
Session replay recordings14 days, unless the client saves a specific recording
Meta, Google and WhatsApp access tokensUntil the connection is removed, access is revoked, or deletion is requested
Advertising statistics (Meta, Google)While the client relationship lasts; deleted within 30 days of a deletion request or its end
Raw WhatsApp webhook deliveries30 days
Competitor analysesUntil the client deletes them or the client relationship ends

Where the law requires us to keep records longer (for example invoices under Turkish tax law), we keep only what is required, for as long as required.

10. Cookies

  • bradi GO (go.bradi.tech) uses only strictly necessary cookies: the sign-in session (7 days, renewed while you use the panel) and two preference cookies that remember the business and site you selected (1 year). They are not used for tracking or advertising.
  • The bradi GO tracker on our clients' websites uses no cookies or local storage.
  • www.bradi.tech uses analytics and advertising cookies from PostHog and Google (the Google Ads tag), and cookieless analytics from Umami. You can block or delete cookies in your browser settings; the website works without them.
  • Shared competitor-analysis reports offer Google Translate, which may set Google cookies if you use it.

11. Your rights

Under KVKK article 11 and, where it applies, the GDPR, you have the right to:

  • learn whether we process your personal data and request information about it;
  • learn the purpose of processing and whether it is used accordingly;
  • know the third parties in Türkiye or abroad to whom it is transferred;
  • request correction of incomplete or inaccurate data;
  • request deletion or destruction of your data, and that this is notified to third parties who received it;
  • object to a result against you that arises exclusively from automated analysis;
  • claim compensation for damage caused by unlawful processing;
  • under the GDPR, also: data portability, restriction of processing, objection to processing based on legitimate interest, and withdrawal of consent at any time.

To exercise a right, email [email protected] from the address linked to your data, or send a signed written request to us in Ankara, Türkiye. We answer free of charge within 30 days. We may ask you to prove your identity. If you are not satisfied, you may complain to the Turkish Personal Data Protection Authority (KVKK, www.kvkk.gov.tr) or, in the EU, to your local data protection authority.

12. Deleting your data

You can ask us to delete your data at any time. Step-by-step instructions, including how to remove our access from Facebook and what we delete, are on our Data Deletion page: bradi.tech/data-deletion.

13. Children

Our Services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

14. Changes to this policy

We update this policy when our Services or the law change. The date at the top shows the latest version. If a change materially affects how we use data that clients have entrusted to us, we notify client administrators by email before it takes effect.