1. Scope
This policy applies to business users of the Ustat Tamircim app, people who contact us for support, and customer, vehicle, service and invoice records that may be processed through the application.
Since active modules may vary by business preference, the categories of data processed may differ depending on enabled modules and integrations.
2. Categories of data that may be processed
- Account and contact data: name, surname, phone number, email and business information.
- Vehicle and service data: plate number, make, model, technical details, service records, complaint notes, service history and photos.
- Customer data: customer name, phone details, vehicle relations, transaction history and invoice address details.
- Financial and document data: collections, payment movements, receivable / payable records and e-invoice / e-archive document data.
- Support and communication data: in-app messages, support records and support content shared via WhatsApp.
- Technical data: device type, operating system, app version, IP address, session logs, error and security logs.
3. Processing purposes
- To operate service intake, vehicle card, customer management and work order processes.
- To manage collections, financial movements, stock and product workflows.
- To run e-invoice, e-archive and document center processes.
- To manage in-app notifications, message center and support flows.
- To maintain security, authorization, troubleshooting, performance monitoring and system improvements.
- To comply with legal obligations, maintain records and respond to official requests.
4. Legal bases
Data may be processed on the basis of contract performance, legal obligations, legitimate interests, protection of legal rights and, where required, explicit consent.
5. Data sharing
Data may be shared to the extent necessary with cloud infrastructure providers, messaging and notification services, e-invoice / e-archive integrators, technical support providers and legally authorized public authorities.
Personal data is not sold, rented or transferred to third parties for unrelated marketing purposes.
6. Retention and deletion
Data may be retained while the account remains active and for the periods required by applicable law. At the end of the retention period, data is deleted, destroyed or anonymized.
Financial and document records subject to legal retention obligations may be kept for the minimum period required by law even if a deletion request is submitted.
7. Security
We use access control, role-based authorization, logging, session security and reasonable technical and administrative measures. However, no system can be guaranteed to be completely error-free or absolutely secure.
8. Your rights
- To learn whether your data is being processed.
- To request information about processed data.
- To request correction of incomplete or inaccurate data.
- To request deletion, destruction or anonymization where legally available.
- To object to or request restriction of processing where applicable.
- To request access or data portability to the extent available.
9. Policy changes
This policy may be updated when necessary. The current version will always be published on this page together with the effective date shown above.
