Legal
Privacy Policy
How MONOM handles personal data on monom.technology, in the systems we build and operate for clients, and in the Google APIs those systems connect to.
Last updated: 4 August 2026
1. Who we are
MONOM Yazılım ve Bilişim Teknolojileri Sanayi Ticaret Limited Şirketi ("MONOM", "we") is the data controller for personal data collected through monom.technology. Registered address: Ahi Evran OSB Mah. Oğuz Cad. No: 31, Sincan / Ankara, Türkiye. MERSİS 0621131561000001 · Trade registry no. 548050 (Ankara).
For every data matter — access, correction, deletion, objection, or a question about this policy — write to hello@monom.technology.
2. Two different roles
On this website, MONOM is a data controller: we decide what is collected and why.
In the platforms we build and operate for clients, MONOM is a data processor. The client company is the controller of the data in its own system — its customers, contacts, quotations and messages. We process that data only on the client's documented instructions, under a written agreement, and never for our own purposes. Requests about data held in a client's system should be directed to that client; if you contact us instead, we will forward your request to them.
3. What we collect on this website, and why
We do not use advertising cookies, cross-site trackers, or profiling of any kind on this website. The two cookies we set are strictly necessary for the site to work as you asked it to, which is why there is no consent wall.
| Data | Why | Legal basis |
|---|---|---|
| Name, email, company, message from the contact form | To answer your enquiry and, if it goes further, to prepare a proposal | KVKK art. 5/2(f) legitimate interest · GDPR art. 6(1)(b) and (f) |
| Language and theme cookies | To serve the site in the language and theme you chose | Strictly necessary — no consent required, disclosed here |
| Aggregate, cookieless usage statistics | To understand how the site performs. No personal profiles, no advertising trackers | KVKK art. 5/2(f) legitimate interest · GDPR art. 6(1)(f) |
| Server logs (IP address, user agent, timestamp) | Security, abuse prevention and diagnosing faults | KVKK art. 5/2(f) legitimate interest · GDPR art. 6(1)(f) |
4. Google user data and the Google Ads API
Some client platforms we operate connect to the client's own Google Ads account so that advertising can be managed and real commercial outcomes reported back. This connection is always made by the client, through Google's OAuth 2.0 consent screen, using the AdWords scope, and only after they have been told what it does.
What we receive: an OAuth refresh token for the client's account, campaign and keyword performance metrics, and the identifiers needed to attribute enquiries to clicks. What we do with it: display performance inside the client's own platform, make campaign changes the client asks for, and upload offline conversion events (a qualified enquiry, an issued quotation, a closed sale) so the client's bidding can optimise toward real revenue.
How it is protected: refresh tokens are encrypted with AES-256-GCM before storage, the key lives only in the server environment, and tokens are never exposed to a browser or used outside server-side calls. Each client's records are isolated at the database level with row-level security, and the account identifier used in any API call is resolved from the signed-in user's own client context — never accepted from the request.
What we never do: we do not sell Google user data, transfer it to third parties for advertising or data-brokerage, use it to train generalised artificial-intelligence or machine-learning models, or allow humans to read it except with the client's explicit permission, for security investigations, or where the law requires it.
A client can disconnect at any time — from the Disconnect control in their platform or from their own Google account settings. Disconnection deletes the stored token immediately and stops all API access.
MONOM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Who else processes data for us
We keep the list of service providers deliberately short. Website hosting and delivery: Vercel. Databases for the client platforms we operate: Supabase (PostgreSQL). Advertising integration: Google, where a client has connected their account. Messaging delivery, where a client platform sends email, SMS or WhatsApp on the client's behalf: the provider named in that client's agreement.
Providers act on our instructions under contract. We do not sell personal data, and we do not share it for anyone else's marketing.
6. International transfers
Some of these providers process data outside Türkiye. Where that happens, transfers are made in line with the cross-border transfer regime in KVKK art. 9 and, where the GDPR applies, Chapter V of that regulation — using an appropriate safeguard or an explicit consent, as the case requires. Tell us at hello@monom.technology if you would like details of the safeguard relied on for a specific transfer.
7. How long we keep things
Enquiries sent through this website: up to 24 months after our last contact, then deleted or anonymised, unless a contract or a legal obligation requires longer.
Google OAuth tokens: until the client disconnects or revokes access, and in any case deleted within 30 days of an operations agreement ending.
Data inside client platforms: for as long as that client's agreement is in force, and thereafter according to the deletion terms of that agreement.
Aggregate analytics: retained in aggregate form only, with no ability to identify an individual visitor.
8. Security
Access control and row-level security are defaults in everything we build, not upgrades. Secrets and tokens are encrypted at rest, traffic is encrypted in transit, administrative access follows least privilege, and privileged actions are recorded in an audit trail. No system is perfectly secure, but these are the baselines we hold ourselves to and can evidence.
9. Your rights
Under KVKK art. 11 you may learn whether your personal data is processed, request information about it, learn its purpose and whether it is used accordingly, know the third parties it is transferred to, request correction or deletion, ask that those requests be passed on to recipients, object to a result produced solely by automated analysis, and claim compensation for damage caused by unlawful processing.
Where the GDPR applies, arts. 15–22 additionally give you access, rectification, erasure, restriction, portability, and the right to object.
Write to hello@monom.technology and we will respond within 30 days. You may also complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, in the EU/UK, to your local supervisory authority.
10. Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects an operated system, tell the affected clients directly. Previous versions are available on request.
This website and the platforms we operate are business tools. They are not directed at children, and we do not knowingly collect data from them.
The Turkish text is the legally operative version for KVKK purposes; the English text is a courtesy translation.