Legal
Privacy Policy
Last updated: 2 October 2026 · Also available in: Türkçe
This policy explains how Murat Efe Doğan (bradi.tech) ("bradi", "we", "us") handles personal data when you visit www.bradi.tech, contact us, or use bradi GO, our client panel at https://go.bradi.tech (together, the "Services"). It applies to the website, the panel, the bradi GO website tracker that our clients install on their own sites, and our integrations with Meta (Facebook, Instagram, WhatsApp) and Google.
Short version: we collect what we need to run a reporting panel for businesses that hire us, we read advertising and messaging data only with the account owner's permission, we never sell personal data or use it for our own advertising, and you can ask us to delete it at any time by writing to [email protected].
1. Who we are and how to reach us
The data controller for the website and for bradi GO user accounts is Murat Efe Doğan (bradi.tech), a sole proprietorship registered in Türkiye, located in Ankara, Türkiye.
Contact for all privacy matters, including requests to access or delete data: [email protected]. We answer within 30 days at the latest, and usually much sooner.
bradi is a digital marketing and software agency. bradi GO is an invite-only panel we provide to our business clients: it shows their website analytics, advertising results and, where they choose to connect it, WhatsApp Business conversation analytics. There is no public sign-up.
2. Our role: controller and processor
We act in two roles, and the difference matters for who you should contact first:
- Controller: for the website (www.bradi.tech), for the contact form, and for the accounts of people who sign in to bradi GO. We decide why and how this data is processed.
- Processor (on behalf of our client): for data about our clients' own website visitors, advertising accounts and WhatsApp Business conversations. The client business is the controller of that data; we process it only to provide the panel to that client, under their instructions and our agreement with them.
If you visited one of our clients' websites, or messaged one of our clients on WhatsApp, that business decides how your data is used. You can contact them directly, or write to [email protected] and we will forward your request and help them answer it.
3. What we collect
a) Visitors of www.bradi.tech
- Contact form: your name, email address, phone or WhatsApp number, business name, your message, the page you first arrived on and the page you sent the form from. The "leave your email" box collects only your email address.
- Website analytics: pages viewed, referrer, approximate location derived from your IP address, device and browser type, collected through Umami (cookieless), PostHog and the Google Ads tag (gtag.js). PostHog and Google may set cookies; see section 10.
b) bradi GO users (people at our client businesses and bradi staff)
- Account: email address, a display name, language preference (English or Turkish), role (client or admin) and the businesses you belong to. Passwords are stored only as a one-way hash; sign-in links are stored hashed and expire after 10 minutes.
- Sessions and security: session records with IP address and browser user agent, and a security log of sign-ins and administrative actions (for example inviting a user or adding a site), including the IP address.
- Usage: one record per user per day of which panel sections were used and for how many minutes. We do not record full URLs, search terms, IP addresses or browser details in this usage record.
- Content you create: funnels, saved settings, competitor analyses, and chat conversations with the panel's assistant.
c) Visitors of our clients' websites (bradi GO tracker)
When a client installs the bradi GO snippet on their website, it sends the following for each page view and interaction:
- The page path (without the query string), the referring URL, campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the name of any ad click identifier present (for example "fbclid" or "gclid" — the name only, never its value).
- Approximate location (country, and region and city where our network provider supplies them), the browser window width, time on page, scroll depth, number of clicks, and for clicks on links and buttons the element's visible label, link target and id. Text typed into form fields is never collected.
- A visitor identifier that is a one-way hash of the IP address and browser user agent combined with a random key that changes every day and is deleted after 36 hours. The IP address and user agent themselves are not stored, and the identifier cannot be linked across days.
- The tracker sets no cookies and uses no local storage on the visitor's device. It does not run when the browser sends a Do Not Track signal, and it ignores known bots.
- Session replay (only if the client turns it on for a share of visits, off by default): a recording of the page structure and changes (not a video), with every form field masked, query strings removed, and any element the client marks as private hidden or masked. Recordings are capped at one hour.
d) Data from Meta (Facebook and Instagram advertising)
Only when a client user connects their Meta ad account through "Login with Facebook for Business" and approves the requested permissions (ads_read and business_management), we receive:
- An access token for that user's grant, which we store encrypted (see section 8).
- The list of ad accounts the user can access (account id, name, currency, time zone, status), so the user can pick one.
- For the selected ad account only: daily advertising statistics at account and campaign level — spend, impressions, reach, clicks, click-through rate, cost per click, cost per thousand impressions, reported actions such as conversations started and purchases, purchase values, campaign ids and campaign names, currency and attribution setting.
We do not receive or store Facebook profile data, friends, posts, page content or any data about the people who saw or clicked the ads beyond these aggregate statistics. Our access is read-only: bradi GO cannot create, change or pause campaigns, budgets or bids.
e) Data from WhatsApp Business (Meta WhatsApp Business Platform)
Only when a client connects a WhatsApp Business number to bradi GO (through Meta's Embedded Signup, with the business account owner's approval), Meta sends us, for that number:
- Messages received and sent (including the text, the customer's phone number and WhatsApp profile name, timestamps, message type and, for messages that started from a Click-to-WhatsApp ad, the ad reference).
- Replies sent by the business from the WhatsApp Business app, message history the business chooses to share (up to six months), contact names synced from the app, and account status updates.
We use this only to show the client their own conversation analytics (for example response times, conversation volume and which ads produced conversations). bradi GO is read-only for WhatsApp: it does not send messages on anyone's behalf.
f) Data from Google (when connected)
If a client connects Google Ads or Google Search Console, we receive read-only reporting data: for Google Ads, daily cost, impressions, clicks, conversions and conversion value per account and campaign (with campaign names); for Search Console, clicks, impressions, click-through rate and position by date, search query and page. The scopes requested are adwords and webmasters.readonly.
g) Publicly available data for competitor analysis
When a client runs a competitor analysis, we collect publicly available information: the client's own website text, competitors' public websites and social profiles, and ads that competitors publish in the Meta Ad Library and LinkedIn Ad Library. Ads in these libraries are public by law; we store the ad text, images, dates and the advertiser's page name.
4. Why we use it and on what legal basis
| Purpose | Data | Legal basis (KVKK art. 5 / GDPR art. 6) |
|---|---|---|
| Answer your enquiry and prepare an offer | Contact form data | Steps before entering a contract; our legitimate interest in replying |
| Provide bradi GO to our clients (accounts, sign-in, reports) | Account, session, content, tracker, Meta, Google and WhatsApp data | Performance of our contract with the client; for data we process for clients, the client's instructions |
| Keep the panel secure and prevent misuse | Session records, IP addresses, security log | Legitimate interest; legal obligation to keep systems secure |
| Send service emails (sign-in links, password resets, reports, alerts, analysis ready) | Email address, language, report figures | Performance of contract |
| Improve the website and measure our own advertising | Website analytics and cookies | Consent where cookies require it; otherwise legitimate interest |
| Comply with law and handle legal claims | Any relevant data | Legal obligation; establishment, exercise or defence of legal claims |
We do not use personal data for automated decisions that have legal or similarly significant effects on you.
5. How we use data received from Meta
Data we receive through Meta's platforms (Facebook Login for Business, the Marketing API and the WhatsApp Business Platform) is used only to provide the client who connected it with their own reports inside bradi GO. In particular:
- We do not sell, rent or license Meta data, and we do not share it with data brokers or advertising networks.
- We do not use it to build profiles of people, to target or retarget advertising, or to train general-purpose AI models.
- We do not combine one client's Meta data with another client's data. Each client sees only the accounts they connected.
- Where we pass figures to an AI provider to generate a written summary for that same client (section 6), the provider is contractually barred from using it to train its models, and request storage is disabled.
- We keep it only as long as section 9 says, and delete it on request as described in our Data Deletion page: bradi.tech/data-deletion.
- We comply with the Meta Platform Terms and Developer Policies.
You can remove bradi GO's access to your Facebook account at any time in Facebook: Settings & privacy → Settings → Business integrations (or Apps and websites) → bradi GO → Remove. For a business portfolio: Business settings → Integrations → Connected apps.
7. International transfers
Some of the providers above are located outside Türkiye and outside the European Economic Area, mainly in the USA. Where we transfer personal data abroad, we rely on the safeguards the law provides: for transfers from Türkiye, the standard contractual clauses under KVKK article 9 notified to the Personal Data Protection Authority, or your explicit consent where required; for data subject to the GDPR, the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework where the provider is certified.
8. How we protect it
- All traffic is encrypted in transit (HTTPS/TLS).
- Access tokens from Meta and Google are encrypted at rest with AES-256-GCM, each bound to the business and connection it belongs to, and are never shown to anyone, including our staff.
- Webhooks from Meta are accepted only with a valid cryptographic signature.
- The panel is invite-only; every query is limited to the business the signed-in user belongs to. Staff access to a client account is logged, limited to one hour and visibly marked in the panel.
- The database is reachable only from our private hosting network.
No system is perfectly secure. If a breach affects your personal data, we will notify the authorities and you as the law requires. Report a suspected security issue to [email protected].
9. How long we keep it
| Data | Kept for |
|---|---|
| Contact form and email-box messages | As long as needed to answer and, if you become a client, for the duration of the relationship; otherwise up to 2 years |
| Sign-in links / password-reset links | 10 minutes / 1 hour |
| Panel accounts and the content users create | While the user has access to bradi GO; deleted within 30 days of a deletion request or the end of the client relationship |
| Panel usage records | 365 days |
| Security log (sign-ins and administrative actions) | Up to 2 years |
| Tracker events from clients' websites | 180 days; daily totals without personal data are kept for reporting |
| Daily visitor hashing key | 36 hours |
| Session replay recordings | 14 days, unless the client saves a specific recording |
| Meta, Google and WhatsApp access tokens | Until the connection is removed, access is revoked, or deletion is requested |
| Advertising statistics (Meta, Google) | While the client relationship lasts; deleted within 30 days of a deletion request or its end |
| Raw WhatsApp webhook deliveries | 30 days |
| Competitor analyses | Until the client deletes them or the client relationship ends |
Where the law requires us to keep records longer (for example invoices under Turkish tax law), we keep only what is required, for as long as required.
11. Your rights
Under KVKK article 11 and, where it applies, the GDPR, you have the right to:
- learn whether we process your personal data and request information about it;
- learn the purpose of processing and whether it is used accordingly;
- know the third parties in Türkiye or abroad to whom it is transferred;
- request correction of incomplete or inaccurate data;
- request deletion or destruction of your data, and that this is notified to third parties who received it;
- object to a result against you that arises exclusively from automated analysis;
- claim compensation for damage caused by unlawful processing;
- under the GDPR, also: data portability, restriction of processing, objection to processing based on legitimate interest, and withdrawal of consent at any time.
To exercise a right, email [email protected] from the address linked to your data, or send a signed written request to us in Ankara, Türkiye. We answer free of charge within 30 days. We may ask you to prove your identity. If you are not satisfied, you may complain to the Turkish Personal Data Protection Authority (KVKK, www.kvkk.gov.tr) or, in the EU, to your local data protection authority.
12. Deleting your data
You can ask us to delete your data at any time. Step-by-step instructions, including how to remove our access from Facebook and what we delete, are on our Data Deletion page: bradi.tech/data-deletion.
13. Children
Our Services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
14. Changes to this policy
We update this policy when our Services or the law change. The date at the top shows the latest version. If a change materially affects how we use data that clients have entrusted to us, we notify client administrators by email before it takes effect.