mybusyness logomybusyness

Privacy Policy

D-09 · v1.0 · published

FieldValue
Document codeD-09
Document namePrivacy Policy
Versionv1.0
Publication date2026-09-25
Legal basisGDPR; UAVG
Where shownPrivacy policy page (no login) · footer · registration form
Statusv1.0 published (2026-09-25)

1. In brief — six sentences

  1. Customer data of the Netherlands region stays on servers in the Netherlands; only masked text goes to external language models.
  2. A large part of the product's work uses no language model at all; for that work, not a single row of your data leaves the system.
  3. Identification data is masked before anything leaves the system; secrets go to no model.
  4. We do not sell your data and do not pass it on to third parties for marketing purposes.
  5. Money transfers and the submission of tax filings are locked in code for virtual collars.
  6. What we do is written to an unchangeable audit trail that you can also view.

2. Who, what, why

The controller is Topluyıldız Danışmanlık A.Ş. (mybusyness), with its registered office in Türkiye. Topluyıldız Danışmanlık A.Ş. has no establishment and no subsidiary in the Netherlands or anywhere else in the European Union. Because the website and the service are offered to people and businesses in the Netherlands, the GDPR (Regulation (EU) 2016/679; in the Netherlands also known as the «AVG») applies (Article 3(2) GDPR), supplemented by the Dutch GDPR Implementation Act (Uitvoeringswet AVG, «UAVG»).

ItemValue
E-mailsales@mybusyness.com

Customer data of the Netherlands region is stored and backed up on servers in the Netherlands (European Union) and does not leave the European Union; the only exceptions are listed exhaustively in D-08.

This policy shows on one page what happens to your data when you visit the website, open an account and use the product with your business. Details:

TopicDocument
Data when you visit the websiteD-01 · Privacy Notice for Website Visitors
Data after you open an accountD-02 · Privacy Notice for Users and Customers
CookiesD-03 · Cookie Policy · D-04 · Cookie Consent Text and Banner
Our role for your business's dataD-07 · Data Processing Agreement
Transfers outside the European UnionD-08 · International Data Transfers
How to exercise your rightsD-13 · Data Subject Request Form

3. Terms (defined once)

  1. Virtual collar: The software layer that prepares the work of a department. In legal terms: automated or software-assisted processing.
  2. COPAI: The layer that masks content and assigns it to a confidentiality class before every external model call.
  3. Masking: Replacing identification data with placeholders such as [BSN-001].
  4. Audit trail: The record of every action, protected by a hash chain; it cannot be changed.

4. The path of your data — four commitments

4.1 Masking first

Before every external model call, Turkish identity number, AHV number, BSN, IBAN (each with check-digit validation), telephone, e-mail, tax number, card number and key-like strings are masked. A sentence that goes out looks like this: «[KISI-001] has requested a payment to [IBAN-001].»

The content is also assigned to a confidentiality class from D0 to D5:

  • D0–D2 — general content: may go masked to a cloud language model.
  • D3–D4 — sensitive content: goes only to a local model. If there is no local model, a visible error appears; there is no silent switch to the cloud.
  • D5 — secrets: go to no model.

The link between placeholder and original value is stored encrypted and destroyed after 24 hours.

4.2 Encrypted access keys

If you connect an external service with your own key: only you enter the key; our server stores it encrypted, does not show it again, does not log it and never hands it to a virtual collar.

What we do not claim: «We never see your key» — that would not be true. The key reaches the server over a secure connection and is decrypted in memory for each call. We say so openly.

4.3 Audit trail

Every job, every model call, every masking and every finalization is recorded with a hash chain. It can be shown mathematically that a record has not been changed afterwards. There is no way to delete or change it. Even if you remove an external connection, the related entry remains.

The audit trail is not an option but a legal duty; the privacy switches in the product do not turn it off.

4.4 Money lock

Money transfers and the submission of tax filings are locked in code for virtual collars. No instruction, no setting and no preference of a business can lift this lock. Finalizing is always done by the owning department, not by the General Manager in place of the department.

5. What we do not do

  • We do not sell your data.
  • We do not pass your data on to third parties for marketing purposes.
  • We do not send identification data unmasked to external models; content of classes D3–D4 goes only to a local model, content of class D5 to no model.
  • We do not ask for card data on the website or in the application; payment is made against invoice by bank transfer.
  • We do not pre-tick consent boxes.
  • We do not use the approach «by continuing to browse, you consent».
  • We do not conceal errors; we state the cause and the next step.

6. Tenant isolation

Each business's data is kept separate. On every read and write, the server checks the business identifier and the membership; permissions cannot be raised from the browser. Each person sees only the data within their role and department.

7. Whose data, whose responsibility

DataController
Your account and subscription dataTopluyıldız
Customer, employee and supplier data that your business entersYour business — Topluyıldız is the processor here

The second row matters: informing your business's customers and employees is your business's responsibility. The rules for this are set out in D-07.

8. Retention — in brief

DataPeriod
Mask vault24 hours
Raw text of a jobReduced to a masked summary when the job closes, at the latest after 30 days
Audit trailNot destroyed
Account and business data10 years after the account is closed
Business documents createdThe customer's statutory retention periods
Server access log30 days
Raw measurement data12 months, then monthly totals; monthly totals 36 months
Consent record10 years after withdrawal

9. Your rights

Under Articles 15–22 GDPR you have, in particular, the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right not to be subject to a decision based solely on automated processing (Article 22 GDPR). You can withdraw consent at any time (Article 7 GDPR).

D-13 · Data Subject Request Form is available for your request. We respond within one month (Article 12(3) GDPR). You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Article 77 GDPR).

10. In the event of a security incident

If a personal data breach occurs, we investigate it immediately, inform the parties concerned and notify the Autoriteit Persoonsgegevens without undue delay and, where feasible, within 72 hours (Article 33 GDPR), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the breach is likely to result in a high risk, the data subjects are also informed (Article 34 GDPR). The incident is also recorded in the audit trail.

11. Contact

E-mail: sales@mybusyness.com — the other contact details are in section 2.

12. Changes

If this policy changes, the version number is increased and the date is updated. If processing based on your consent is extended, we ask for your consent again.


This document describes the behaviour of mybusyness as measured in the code. This is not legal advice.

FieldValue
Document codeD-01
Document namePrivacy Notice for Website Visitors
Versionv1.0
Publication date2026-09-25
Legal basisArticle 13 GDPR; Article 11.7a of the Telecommunicatiewet (cookies)
Where shownPrivacy policy page (no login) · link in the cookie banner
Statusv1.0 published (2026-09-25)

1. Controller

This notice provides the information required by Article 13 of Regulation (EU) 2016/679 (the General Data Protection Regulation, «GDPR»; in the Netherlands also known as the «AVG»).

ItemValue
CompanyTopluyıldız Danışmanlık A.Ş.
Brandmybusyness
E-mailsales@mybusyness.com
Websitemybusyness.com

The controller has its registered office in Türkiye. Topluyıldız Danışmanlık A.Ş. has no establishment and no subsidiary in the Netherlands or anywhere else in the European Union. Because the website is offered to people in the Netherlands, the GDPR applies to it (Article 3(2) GDPR). Please send any questions about data protection to the e-mail address above.

2. Scope

This notice applies only to people who visit the website and have not yet opened an account. If you have an account, or if your business uses mybusyness, D-02 · Privacy Notice for Users and Customers applies to you.

3. Terms (defined once)

  1. Personal data: Any information relating to an identified or identifiable natural person (Article 4 GDPR).
  2. Processing: Any operation performed on personal data, such as collecting, storing, using, disclosing or erasing it.
  3. Cookie: A small text file stored in your browser when you visit the website. This notice also covers comparable storage in the browser (local storage).
  4. Virtual collar: Our name for the software layer that prepares the work of a department. In legal terms, this is automated or software-assisted processing.

4. Data processed

When you only visit the website, the following data is processed:

Data categoryContentSource
Security dataIP address (masked: for IPv4 without the last block, for IPv6 without the last blocks), time of the request, page requested, response code, browser summary (browser family and platform)Server access log
Storage in the browserNecessary entries (language, region, cookie choice, consent identifier); only with your consent measurement cookies from Google AnalyticsYour browser
Measurement dataPage views, scroll depth, clicks on buttons, use of the live demoThe website's own measurement
Contact dataIf you write to us: name, e-mail address, content of the messageYour message
Consent recordConsent identifier, time, document code + version + region, salted IP hash (never the raw IP address), browser summary (browser family and platform), your choiceCookie banner

The server access log never stores the query string (the part of the address after ?). The raw IP address is not stored.

The text you type into the live demo is processed with sample data and is not sent to any language model. Please do not enter personal data there.

5. Purposes

We process your data for the following purposes:

  1. Operation, security and availability of the website.
  2. Detecting attacks, misuse and errors; investigating incidents.
  3. Understanding which parts of the website are read and improving the content (Google Analytics only with your consent).
  4. Answering your enquiries.
  5. Keeping verifiable proof of your consent and of your choice.

Before any call to an external language model, identification data is masked; content of classes D3–D4 goes only to a local model; content of class D5 goes to no model.

PurposeLegal basis
Operation and security of the website, necessary storageLegitimate interest in secure operation (Article 6(1)(f) GDPR); for necessary storage, Article 11.7a of the Telecommunicatiewet (no consent needed for strictly necessary storage)
Server access logLegitimate interest in security and troubleshooting (Article 6(1)(f) GDPR)
Google AnalyticsYour consent (Article 6(1)(a) GDPR; Article 11.7a of the Telecommunicatiewet)
Answering enquiriesSteps prior to a contract (Article 6(1)(b) GDPR) or legitimate interest (Article 6(1)(f) GDPR)
Consent recordLegitimate interest in proving consent (Article 6(1)(f) GDPR); duty to demonstrate consent (Article 7 GDPR)
Responding to requests from authoritiesLegal obligation (Article 6(1)(c) GDPR)

If you do not consent, the website keeps working in full; only Google Analytics is not loaded.

7. Recipients

RecipientWhatPurposeOutside the EU
Website server in TürkiyePage requests, server access log, consent record, e-mails to usOperation of the websiteYes — Türkiye
Google Ireland Limited and Google LLC (Google Analytics) — only with your consentIP address, device and browser information, browsing dataVisitor statisticsYes
Competent authoritiesRecords requestedLegal obligationsDepends on the authority

The website (including the pages under /nl) is served from a server in Türkiye. Details of every transfer outside the European Union and of the safeguards are set out in D-08 · International Data Transfers.

The website loads fonts, images and videos only from its own server.

8. How the data is collected

The data is collected automatically and partly automatically from the requests your browser sends to our server, from storage in your browser and from your e-mails to us.

9. Retention

DataPeriodAfterwards
Server access log (with masked IP)30 daysErased
Raw measurement row12 monthsReduced to monthly totals (no longer linked to any person)
Monthly measurement totals36 monthsErased
Consent record10 years after withdrawalErased
Correspondence10 yearsErased
Cookies and browser storageDepends on the entry — see D-03 · Cookie PolicyErased in the browser

10. Your rights

Under Articles 15–22 GDPR you have, in particular, the right to:

  1. obtain access to the personal data we process about you (Article 15);
  2. have inaccurate personal data rectified (Article 16);
  3. have personal data erased (Article 17);
  4. have processing restricted (Article 18);
  5. receive your personal data in a structured, commonly used and machine-readable format (Article 20);
  6. object to processing based on legitimate interest (Article 21);
  7. withdraw your consent at any time, with effect for the future (Article 7 GDPR).

Note: No decision based solely on automated processing that produces legal effects for you is made from website visit data (Article 22 GDPR).

11. Your request

You can send your request using D-13 · Data Subject Request Form or informally by e-mail to sales@mybusyness.com. We respond within one month (Article 12(3) GDPR).

You can withdraw your consent to Google Analytics at any time. The «Cookie preferences» link in the footer is available on every page; that is where you change your choice. Withdrawal does not make the processing carried out before it unlawful.

13. Complaint

You have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). In the Netherlands, this is the Autoriteit Persoonsgegevens.

14. Changes

If this notice changes, we publish the new version at this address with a new version number and date. If processing based on your consent is extended, we ask for your consent again.


This document describes the behaviour of mybusyness as measured in the code. This is not legal advice.

FieldValue
Document codeD-02
Document namePrivacy Notice for Users and Customers
Versionv1.0
Publication date2026-09-25
Legal basisArticles 13, 14 and 28 GDPR
Where shownPrivacy policy page · registration form · account settings
Statusv1.0 published (2026-09-25)

1. Controller

ItemValue
CompanyTopluyıldız Danışmanlık A.Ş.
Brandmybusyness
E-mailsales@mybusyness.com

The controller has its registered office in Türkiye. Topluyıldız Danışmanlık A.Ş. has no establishment and no subsidiary in the Netherlands or anywhere else in the European Union. Because the service is offered to businesses in the Netherlands, the GDPR applies to it (Article 3(2) GDPR). Please send any questions about data protection to sales@mybusyness.com.

2. The most important distinction first: two roles

mybusyness holds two separate sets of data, and the role of Topluyıldız is different for each.

Data setContentRole of Topluyıldız
A · Account and subscription dataYour name, your e-mail address, an irreversible hash of your password, your role, login records, your business's company name and tax or company number, invoice and payment correspondenceController (Topluyıldız)
B · Your business's business dataEverything your business enters into or uploads to the system: customer records, invoices, employee data, contract texts, e-mails and documentsProcessor (Topluyıldız) — your business is the controller

Your business is the controller for data set B. If you enter personal data of your customers, employees or suppliers into the system, informing those people and establishing a legal basis for the processing is your business's responsibility. Topluyıldız processes this data only on your instructions and within the contract (Article 28 GDPR). The rules for this are set out in D-07 · Data Processing Agreement.

Sections 3–11 describe data set A. Section 12 summarises how data set B is processed.

3. Terms (defined once)

  1. User: The natural person who opens an account.
  2. Business: The legal entity or sole proprietorship that the user creates in mybusyness or joins by invitation.
  3. Virtual collar: The software layer that prepares the work of a department. In legal terms: automated or software-assisted processing.
  4. COPAI: The layer that masks identification data and assigns content to a confidentiality class BEFORE an external language model is called.
  5. Approval engine: The set of rules that decides whether a task can be done directly, goes under department review, or may only be done by a human.
  6. Audit trail: The record of every action, protected by a hash chain; it cannot be changed or deleted.

4. Personal data processed (data set A)

CategoryContent
IdentityName
ContactE-mail address; telephone where provided
LoginIrreversible hash of the password (the password itself is not stored), session data
Business and permissionsCompany name, tax or company number, sector, location, number of employees, your role (General Manager / department user), your membership
SecurityLogin and logout times, masked IP address, browser summary (browser family and platform), security events
UsageScreens opened, number of jobs started, quota use, records finalized
Audit trailType and time of the action, user and business identifier, chain hash
FinancePlan, invoice details, payment correspondence
Consents and declarationsDocument code + version + region, time, channel, salted IP hash

No card data is requested, asked for or stored on the website or in the application. Payment is made against invoice by bank transfer.

5. Purposes

  1. Opening, operating and securing your account and your business's area.
  2. Permissions: which person may see which department's data.
  3. Calculating quota, trial period and subscription status.
  4. Providing the service: approval engine, job processing, creating documents.
  5. Keeping the audit trail — proof of who finalized what.
  6. Invoicing, receipt of payments and bookkeeping.
  7. Support and error analysis.
  8. Complying with legal obligations and establishing, exercising or defending legal claims.
  9. Measuring where the product falls short, and improving the product.
  10. Only with your consent: sending electronic marketing messages (D-11).
PurposeLegal basis
Account, service, quota and subscription (1–4)Performance of the contract (Article 6(1)(b) GDPR)
Audit trail (5)Legitimate interest in proof (Article 6(1)(f) GDPR); legal obligation (Article 6(1)(c) GDPR)
Invoicing and bookkeeping (6)Legal obligation (Article 6(1)(c) GDPR)
Support and error analysis (7)Performance of the contract (Article 6(1)(b) GDPR); legitimate interest (Article 6(1)(f) GDPR)
Legal obligations and legal claims (8)Legal obligation (Article 6(1)(c) GDPR); legitimate interest (Article 6(1)(f) GDPR)
Product measurement (9)Legitimate interest (Article 6(1)(f) GDPR)
Electronic marketing messages (10)Your consent (Article 6(1)(a) GDPR; Article 11.7 of the Telecommunicatiewet)

The audit trail does not depend on consent and cannot be switched off. The switches on the application's privacy screen change masking and measurement, not the audit trail.

7. Recipients

RecipientWhatPurposeOutside the EU
Server hosting providerAll system dataOperation of the serversNo — servers in the Netherlands
Cloud language model providersMasked text only — see section 9Preparing certain types of jobYes
Google Ireland Limited / Google LLCVisit and browsing data (only with your cookie consent)MeasurementYes
Operation and maintenanceAccess to system data as far as needed for operation and maintenanceOperation, maintenance, supportYes — remote access from Türkiye
Services connected by your businessOnly to the service you connect, with your key, only the records concernedIntegrationYour business's decision
Accountants, auditors, legal representativesInvoice and contract documentsLegal obligations and protection of rightsDepends on the adviser
Competent authoritiesRecords requestedLegal obligationsDepends on the authority

Customer data of the Netherlands region is stored and backed up on servers in the Netherlands (European Union) and does not leave the European Union; the only exceptions are listed exhaustively in D-08.

E-mails are currently not sent through a third-party provider; if a provider is selected, D-08 · International Data Transfers is updated before it is put into use.

8. How the data is collected

The data is collected automatically and partly automatically from the registration and set-up forms, from the records the system creates while you use it, from uploaded files and from your correspondence with us.

9. What goes to cloud language models — explained openly

A large part of the product's work uses no language model at all; these tasks are calculated entirely in code. When a task needs an external model, the following steps run before the call:

  1. Masking. Turkish identity number, AHV number, BSN, IBAN (each with check-digit validation), card number, telephone number, e-mail address, tax number and key-like strings are replaced before every network call with placeholders such as [BSN-001] or [IBAN-001].
  2. Classification. The content is assigned a confidentiality class from D0 to D5.
  3. Routing.
    • D0–D2 (general content): may go masked to a cloud language model.
    • D3–D4 (sensitive content): go only to a local model. If no local model is set up, a visible error appears; there is no silent switch to the cloud.
    • D5 (secrets): go to no model.
  4. Vault. The link between placeholder and original value is stored encrypted and destroyed after 24 hours. The answer is resolved again within the boundaries of your business.

An honest limit: Masking removes identification data; free business text (for example a contract clause or a paragraph from correspondence) may still contain personal data afterwards. We therefore treat sending text to cloud language models as a transfer of personal data outside the European Union and follow Chapter V GDPR (see D-08).

Difference between the upload routes: When data is imported via Excel or CSV, not a single row leaves the system; this route is pure code. On the PDF route, only masked text goes out.

10. Retention

DataPeriod
Account and business data10 years after the account is closed
Password hash and session dataErased when the account is closed
Mask vault24 hours
Raw text of a jobReduced to a masked summary when the job closes, at the latest after 30 days
Audit trailNot destroyed — record of evidence and integrity
Business documents created (for example invoices)The customer's statutory retention periods
Server access log30 days
Raw product measurement data12 months, then monthly totals; monthly totals 36 months
Consents and declarations10 years after withdrawal

Destruction usually means reduction rather than erasure: the row remains, but the raw personal data in it is replaced by a masked summary and cannot be recovered.

11. Your rights and your request

The rights listed in D-01 section 10 also apply to you (Articles 15–22 GDPR). You can send your request using D-13 · Data Subject Request Form or by e-mail to sales@mybusyness.com; we respond within one month (Article 12(3) GDPR). You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Article 77 GDPR).

Automated individual decisions (Article 22 GDPR): The product makes no decision about you based solely on automated processing that produces legal effects for you or similarly significantly affects you. The approval engine assigns a task to one of three levels — direct, under department review, or human only; finalizing is always done by a human. Money transfers and the submission of tax filings are locked in code for virtual collars; no setting and no instruction can lift this lock.

Erasure requests and the audit trail: The audit trail is kept as proof and because of legal obligations, and it is not erased. When you request erasure, the entry in the audit trail remains; job texts and document contents, however, are reduced to a masked summary and then no longer contain personal data.

12. Your business's business data (data set B) — in brief

  • Your business's data is separated by tenant isolation: on every read and write, the server checks the business identifier and the membership. Permissions cannot be raised from the browser.
  • Each person sees only the data within their role and department.
  • Access keys for external services are stored encrypted, not shown again, not logged, and never handed to the virtual collars.
  • Your business's obligations and ours for this data are governed by D-07 · Data Processing Agreement.

13. Changes

If this notice changes, we publish the new version with a new date and inform you in the application. If processing based on your consent is extended, we ask for your consent again.


This document describes the behaviour of mybusyness as measured in the code. This is not legal advice.