Privacy Policy
D-09 · v1.0 · published
| Field | Value |
|---|---|
| Document code | D-09 |
| Document name | Privacy Policy |
| Version | v1.0 |
| Publication date | 2026-09-25 |
| Legal basis | GDPR; UAVG |
| Where shown | Privacy policy page (no login) · footer · registration form |
| Status | v1.0 published (2026-09-25) |
1. In brief — six sentences
- Customer data of the Netherlands region stays on servers in the Netherlands; only masked text goes to external language models.
- A large part of the product's work uses no language model at all; for that work, not a single row of your data leaves the system.
- Identification data is masked before anything leaves the system; secrets go to no model.
- We do not sell your data and do not pass it on to third parties for marketing purposes.
- Money transfers and the submission of tax filings are locked in code for virtual collars.
- What we do is written to an unchangeable audit trail that you can also view.
2. Who, what, why
The controller is Topluyıldız Danışmanlık A.Ş. (mybusyness), with its registered office in Türkiye. Topluyıldız Danışmanlık A.Ş. has no establishment and no subsidiary in the Netherlands or anywhere else in the European Union. Because the website and the service are offered to people and businesses in the Netherlands, the GDPR (Regulation (EU) 2016/679; in the Netherlands also known as the «AVG») applies (Article 3(2) GDPR), supplemented by the Dutch GDPR Implementation Act (Uitvoeringswet AVG, «UAVG»).
| Item | Value |
|---|---|
| sales@mybusyness.com |
Customer data of the Netherlands region is stored and backed up on servers in the Netherlands (European Union) and does not leave the European Union; the only exceptions are listed exhaustively in D-08.
This policy shows on one page what happens to your data when you visit the website, open an account and use the product with your business. Details:
| Topic | Document |
|---|---|
| Data when you visit the website | D-01 · Privacy Notice for Website Visitors |
| Data after you open an account | D-02 · Privacy Notice for Users and Customers |
| Cookies | D-03 · Cookie Policy · D-04 · Cookie Consent Text and Banner |
| Our role for your business's data | D-07 · Data Processing Agreement |
| Transfers outside the European Union | D-08 · International Data Transfers |
| How to exercise your rights | D-13 · Data Subject Request Form |
3. Terms (defined once)
- Virtual collar: The software layer that prepares the work of a department. In legal terms: automated or software-assisted processing.
- COPAI: The layer that masks content and assigns it to a confidentiality class before every external model call.
- Masking: Replacing identification data with placeholders such as
[BSN-001]. - Audit trail: The record of every action, protected by a hash chain; it cannot be changed.
4. The path of your data — four commitments
4.1 Masking first
Before every external model call, Turkish identity number, AHV number, BSN, IBAN (each with check-digit validation), telephone, e-mail, tax number, card number and key-like strings are masked. A sentence that goes out looks like this: «[KISI-001] has requested a payment to [IBAN-001].»
The content is also assigned to a confidentiality class from D0 to D5:
- D0–D2 — general content: may go masked to a cloud language model.
- D3–D4 — sensitive content: goes only to a local model. If there is no local model, a visible error appears; there is no silent switch to the cloud.
- D5 — secrets: go to no model.
The link between placeholder and original value is stored encrypted and destroyed after 24 hours.
4.2 Encrypted access keys
If you connect an external service with your own key: only you enter the key; our server stores it encrypted, does not show it again, does not log it and never hands it to a virtual collar.
What we do not claim: «We never see your key» — that would not be true. The key reaches the server over a secure connection and is decrypted in memory for each call. We say so openly.
4.3 Audit trail
Every job, every model call, every masking and every finalization is recorded with a hash chain. It can be shown mathematically that a record has not been changed afterwards. There is no way to delete or change it. Even if you remove an external connection, the related entry remains.
The audit trail is not an option but a legal duty; the privacy switches in the product do not turn it off.
4.4 Money lock
Money transfers and the submission of tax filings are locked in code for virtual collars. No instruction, no setting and no preference of a business can lift this lock. Finalizing is always done by the owning department, not by the General Manager in place of the department.
5. What we do not do
- We do not sell your data.
- We do not pass your data on to third parties for marketing purposes.
- We do not send identification data unmasked to external models; content of classes D3–D4 goes only to a local model, content of class D5 to no model.
- We do not ask for card data on the website or in the application; payment is made against invoice by bank transfer.
- We do not pre-tick consent boxes.
- We do not use the approach «by continuing to browse, you consent».
- We do not conceal errors; we state the cause and the next step.
6. Tenant isolation
Each business's data is kept separate. On every read and write, the server checks the business identifier and the membership; permissions cannot be raised from the browser. Each person sees only the data within their role and department.
7. Whose data, whose responsibility
| Data | Controller |
|---|---|
| Your account and subscription data | Topluyıldız |
| Customer, employee and supplier data that your business enters | Your business — Topluyıldız is the processor here |
The second row matters: informing your business's customers and employees is your business's responsibility. The rules for this are set out in D-07.
8. Retention — in brief
| Data | Period |
|---|---|
| Mask vault | 24 hours |
| Raw text of a job | Reduced to a masked summary when the job closes, at the latest after 30 days |
| Audit trail | Not destroyed |
| Account and business data | 10 years after the account is closed |
| Business documents created | The customer's statutory retention periods |
| Server access log | 30 days |
| Raw measurement data | 12 months, then monthly totals; monthly totals 36 months |
| Consent record | 10 years after withdrawal |
9. Your rights
Under Articles 15–22 GDPR you have, in particular, the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right not to be subject to a decision based solely on automated processing (Article 22 GDPR). You can withdraw consent at any time (Article 7 GDPR).
D-13 · Data Subject Request Form is available for your request. We respond within one month (Article 12(3) GDPR). You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Article 77 GDPR).
10. In the event of a security incident
If a personal data breach occurs, we investigate it immediately, inform the parties concerned and notify the Autoriteit Persoonsgegevens without undue delay and, where feasible, within 72 hours (Article 33 GDPR), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the breach is likely to result in a high risk, the data subjects are also informed (Article 34 GDPR). The incident is also recorded in the audit trail.
11. Contact
E-mail: sales@mybusyness.com — the other contact details are in section 2.
12. Changes
If this policy changes, the version number is increased and the date is updated. If processing based on your consent is extended, we ask for your consent again.
This document describes the behaviour of mybusyness as measured in the code. This is not legal advice.
| Field | Value |
|---|---|
| Document code | D-01 |
| Document name | Privacy Notice for Website Visitors |
| Version | v1.0 |
| Publication date | 2026-09-25 |
| Legal basis | Article 13 GDPR; Article 11.7a of the Telecommunicatiewet (cookies) |
| Where shown | Privacy policy page (no login) · link in the cookie banner |
| Status | v1.0 published (2026-09-25) |
1. Controller
This notice provides the information required by Article 13 of Regulation (EU) 2016/679 (the General Data Protection Regulation, «GDPR»; in the Netherlands also known as the «AVG»).
| Item | Value |
|---|---|
| Company | Topluyıldız Danışmanlık A.Ş. |
| Brand | mybusyness |
| sales@mybusyness.com | |
| Website | mybusyness.com |
The controller has its registered office in Türkiye. Topluyıldız Danışmanlık A.Ş. has no establishment and no subsidiary in the Netherlands or anywhere else in the European Union. Because the website is offered to people in the Netherlands, the GDPR applies to it (Article 3(2) GDPR). Please send any questions about data protection to the e-mail address above.
2. Scope
This notice applies only to people who visit the website and have not yet opened an account. If you have an account, or if your business uses mybusyness, D-02 · Privacy Notice for Users and Customers applies to you.
3. Terms (defined once)
- Personal data: Any information relating to an identified or identifiable natural person (Article 4 GDPR).
- Processing: Any operation performed on personal data, such as collecting, storing, using, disclosing or erasing it.
- Cookie: A small text file stored in your browser when you visit the website. This notice also covers comparable storage in the browser (local storage).
- Virtual collar: Our name for the software layer that prepares the work of a department. In legal terms, this is automated or software-assisted processing.
4. Data processed
When you only visit the website, the following data is processed:
| Data category | Content | Source |
|---|---|---|
| Security data | IP address (masked: for IPv4 without the last block, for IPv6 without the last blocks), time of the request, page requested, response code, browser summary (browser family and platform) | Server access log |
| Storage in the browser | Necessary entries (language, region, cookie choice, consent identifier); only with your consent measurement cookies from Google Analytics | Your browser |
| Measurement data | Page views, scroll depth, clicks on buttons, use of the live demo | The website's own measurement |
| Contact data | If you write to us: name, e-mail address, content of the message | Your message |
| Consent record | Consent identifier, time, document code + version + region, salted IP hash (never the raw IP address), browser summary (browser family and platform), your choice | Cookie banner |
The server access log never stores the query string (the part of the address after ?). The raw IP address is not stored.
The text you type into the live demo is processed with sample data and is not sent to any language model. Please do not enter personal data there.
5. Purposes
We process your data for the following purposes:
- Operation, security and availability of the website.
- Detecting attacks, misuse and errors; investigating incidents.
- Understanding which parts of the website are read and improving the content (Google Analytics only with your consent).
- Answering your enquiries.
- Keeping verifiable proof of your consent and of your choice.
Before any call to an external language model, identification data is masked; content of classes D3–D4 goes only to a local model; content of class D5 goes to no model.
6. Legal bases
| Purpose | Legal basis |
|---|---|
| Operation and security of the website, necessary storage | Legitimate interest in secure operation (Article 6(1)(f) GDPR); for necessary storage, Article 11.7a of the Telecommunicatiewet (no consent needed for strictly necessary storage) |
| Server access log | Legitimate interest in security and troubleshooting (Article 6(1)(f) GDPR) |
| Google Analytics | Your consent (Article 6(1)(a) GDPR; Article 11.7a of the Telecommunicatiewet) |
| Answering enquiries | Steps prior to a contract (Article 6(1)(b) GDPR) or legitimate interest (Article 6(1)(f) GDPR) |
| Consent record | Legitimate interest in proving consent (Article 6(1)(f) GDPR); duty to demonstrate consent (Article 7 GDPR) |
| Responding to requests from authorities | Legal obligation (Article 6(1)(c) GDPR) |
If you do not consent, the website keeps working in full; only Google Analytics is not loaded.
7. Recipients
| Recipient | What | Purpose | Outside the EU |
|---|---|---|---|
| Website server in Türkiye | Page requests, server access log, consent record, e-mails to us | Operation of the website | Yes — Türkiye |
| Google Ireland Limited and Google LLC (Google Analytics) — only with your consent | IP address, device and browser information, browsing data | Visitor statistics | Yes |
| Competent authorities | Records requested | Legal obligations | Depends on the authority |
The website (including the pages under /nl) is served from a server in Türkiye. Details of every transfer outside the European Union and of the safeguards are set out in D-08 · International Data Transfers.
The website loads fonts, images and videos only from its own server.
8. How the data is collected
The data is collected automatically and partly automatically from the requests your browser sends to our server, from storage in your browser and from your e-mails to us.
9. Retention
| Data | Period | Afterwards |
|---|---|---|
| Server access log (with masked IP) | 30 days | Erased |
| Raw measurement row | 12 months | Reduced to monthly totals (no longer linked to any person) |
| Monthly measurement totals | 36 months | Erased |
| Consent record | 10 years after withdrawal | Erased |
| Correspondence | 10 years | Erased |
| Cookies and browser storage | Depends on the entry — see D-03 · Cookie Policy | Erased in the browser |
10. Your rights
Under Articles 15–22 GDPR you have, in particular, the right to:
- obtain access to the personal data we process about you (Article 15);
- have inaccurate personal data rectified (Article 16);
- have personal data erased (Article 17);
- have processing restricted (Article 18);
- receive your personal data in a structured, commonly used and machine-readable format (Article 20);
- object to processing based on legitimate interest (Article 21);
- withdraw your consent at any time, with effect for the future (Article 7 GDPR).
Note: No decision based solely on automated processing that produces legal effects for you is made from website visit data (Article 22 GDPR).
11. Your request
You can send your request using D-13 · Data Subject Request Form or informally by e-mail to sales@mybusyness.com. We respond within one month (Article 12(3) GDPR).
12. Withdrawing consent
You can withdraw your consent to Google Analytics at any time. The «Cookie preferences» link in the footer is available on every page; that is where you change your choice. Withdrawal does not make the processing carried out before it unlawful.
13. Complaint
You have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). In the Netherlands, this is the Autoriteit Persoonsgegevens.
14. Changes
If this notice changes, we publish the new version at this address with a new version number and date. If processing based on your consent is extended, we ask for your consent again.
This document describes the behaviour of mybusyness as measured in the code. This is not legal advice.
| Field | Value |
|---|---|
| Document code | D-02 |
| Document name | Privacy Notice for Users and Customers |
| Version | v1.0 |
| Publication date | 2026-09-25 |
| Legal basis | Articles 13, 14 and 28 GDPR |
| Where shown | Privacy policy page · registration form · account settings |
| Status | v1.0 published (2026-09-25) |
1. Controller
| Item | Value |
|---|---|
| Company | Topluyıldız Danışmanlık A.Ş. |
| Brand | mybusyness |
| sales@mybusyness.com |
The controller has its registered office in Türkiye. Topluyıldız Danışmanlık A.Ş. has no establishment and no subsidiary in the Netherlands or anywhere else in the European Union. Because the service is offered to businesses in the Netherlands, the GDPR applies to it (Article 3(2) GDPR). Please send any questions about data protection to sales@mybusyness.com.
2. The most important distinction first: two roles
mybusyness holds two separate sets of data, and the role of Topluyıldız is different for each.
| Data set | Content | Role of Topluyıldız |
|---|---|---|
| A · Account and subscription data | Your name, your e-mail address, an irreversible hash of your password, your role, login records, your business's company name and tax or company number, invoice and payment correspondence | Controller (Topluyıldız) |
| B · Your business's business data | Everything your business enters into or uploads to the system: customer records, invoices, employee data, contract texts, e-mails and documents | Processor (Topluyıldız) — your business is the controller |
Your business is the controller for data set B. If you enter personal data of your customers, employees or suppliers into the system, informing those people and establishing a legal basis for the processing is your business's responsibility. Topluyıldız processes this data only on your instructions and within the contract (Article 28 GDPR). The rules for this are set out in D-07 · Data Processing Agreement.
Sections 3–11 describe data set A. Section 12 summarises how data set B is processed.
3. Terms (defined once)
- User: The natural person who opens an account.
- Business: The legal entity or sole proprietorship that the user creates in mybusyness or joins by invitation.
- Virtual collar: The software layer that prepares the work of a department. In legal terms: automated or software-assisted processing.
- COPAI: The layer that masks identification data and assigns content to a confidentiality class BEFORE an external language model is called.
- Approval engine: The set of rules that decides whether a task can be done directly, goes under department review, or may only be done by a human.
- Audit trail: The record of every action, protected by a hash chain; it cannot be changed or deleted.
4. Personal data processed (data set A)
| Category | Content |
|---|---|
| Identity | Name |
| Contact | E-mail address; telephone where provided |
| Login | Irreversible hash of the password (the password itself is not stored), session data |
| Business and permissions | Company name, tax or company number, sector, location, number of employees, your role (General Manager / department user), your membership |
| Security | Login and logout times, masked IP address, browser summary (browser family and platform), security events |
| Usage | Screens opened, number of jobs started, quota use, records finalized |
| Audit trail | Type and time of the action, user and business identifier, chain hash |
| Finance | Plan, invoice details, payment correspondence |
| Consents and declarations | Document code + version + region, time, channel, salted IP hash |
No card data is requested, asked for or stored on the website or in the application. Payment is made against invoice by bank transfer.
5. Purposes
- Opening, operating and securing your account and your business's area.
- Permissions: which person may see which department's data.
- Calculating quota, trial period and subscription status.
- Providing the service: approval engine, job processing, creating documents.
- Keeping the audit trail — proof of who finalized what.
- Invoicing, receipt of payments and bookkeeping.
- Support and error analysis.
- Complying with legal obligations and establishing, exercising or defending legal claims.
- Measuring where the product falls short, and improving the product.
- Only with your consent: sending electronic marketing messages (D-11).
6. Legal bases
| Purpose | Legal basis |
|---|---|
| Account, service, quota and subscription (1–4) | Performance of the contract (Article 6(1)(b) GDPR) |
| Audit trail (5) | Legitimate interest in proof (Article 6(1)(f) GDPR); legal obligation (Article 6(1)(c) GDPR) |
| Invoicing and bookkeeping (6) | Legal obligation (Article 6(1)(c) GDPR) |
| Support and error analysis (7) | Performance of the contract (Article 6(1)(b) GDPR); legitimate interest (Article 6(1)(f) GDPR) |
| Legal obligations and legal claims (8) | Legal obligation (Article 6(1)(c) GDPR); legitimate interest (Article 6(1)(f) GDPR) |
| Product measurement (9) | Legitimate interest (Article 6(1)(f) GDPR) |
| Electronic marketing messages (10) | Your consent (Article 6(1)(a) GDPR; Article 11.7 of the Telecommunicatiewet) |
The audit trail does not depend on consent and cannot be switched off. The switches on the application's privacy screen change masking and measurement, not the audit trail.
7. Recipients
| Recipient | What | Purpose | Outside the EU |
|---|---|---|---|
| Server hosting provider | All system data | Operation of the servers | No — servers in the Netherlands |
| Cloud language model providers | Masked text only — see section 9 | Preparing certain types of job | Yes |
| Google Ireland Limited / Google LLC | Visit and browsing data (only with your cookie consent) | Measurement | Yes |
| Operation and maintenance | Access to system data as far as needed for operation and maintenance | Operation, maintenance, support | Yes — remote access from Türkiye |
| Services connected by your business | Only to the service you connect, with your key, only the records concerned | Integration | Your business's decision |
| Accountants, auditors, legal representatives | Invoice and contract documents | Legal obligations and protection of rights | Depends on the adviser |
| Competent authorities | Records requested | Legal obligations | Depends on the authority |
Customer data of the Netherlands region is stored and backed up on servers in the Netherlands (European Union) and does not leave the European Union; the only exceptions are listed exhaustively in D-08.
E-mails are currently not sent through a third-party provider; if a provider is selected, D-08 · International Data Transfers is updated before it is put into use.
8. How the data is collected
The data is collected automatically and partly automatically from the registration and set-up forms, from the records the system creates while you use it, from uploaded files and from your correspondence with us.
9. What goes to cloud language models — explained openly
A large part of the product's work uses no language model at all; these tasks are calculated entirely in code. When a task needs an external model, the following steps run before the call:
- Masking. Turkish identity number, AHV number, BSN, IBAN (each with check-digit validation), card number, telephone number, e-mail address, tax number and key-like strings are replaced before every network call with placeholders such as
[BSN-001]or[IBAN-001]. - Classification. The content is assigned a confidentiality class from D0 to D5.
- Routing.
- D0–D2 (general content): may go masked to a cloud language model.
- D3–D4 (sensitive content): go only to a local model. If no local model is set up, a visible error appears; there is no silent switch to the cloud.
- D5 (secrets): go to no model.
- Vault. The link between placeholder and original value is stored encrypted and destroyed after 24 hours. The answer is resolved again within the boundaries of your business.
An honest limit: Masking removes identification data; free business text (for example a contract clause or a paragraph from correspondence) may still contain personal data afterwards. We therefore treat sending text to cloud language models as a transfer of personal data outside the European Union and follow Chapter V GDPR (see D-08).
Difference between the upload routes: When data is imported via Excel or CSV, not a single row leaves the system; this route is pure code. On the PDF route, only masked text goes out.
10. Retention
| Data | Period |
|---|---|
| Account and business data | 10 years after the account is closed |
| Password hash and session data | Erased when the account is closed |
| Mask vault | 24 hours |
| Raw text of a job | Reduced to a masked summary when the job closes, at the latest after 30 days |
| Audit trail | Not destroyed — record of evidence and integrity |
| Business documents created (for example invoices) | The customer's statutory retention periods |
| Server access log | 30 days |
| Raw product measurement data | 12 months, then monthly totals; monthly totals 36 months |
| Consents and declarations | 10 years after withdrawal |
Destruction usually means reduction rather than erasure: the row remains, but the raw personal data in it is replaced by a masked summary and cannot be recovered.
11. Your rights and your request
The rights listed in D-01 section 10 also apply to you (Articles 15–22 GDPR). You can send your request using D-13 · Data Subject Request Form or by e-mail to sales@mybusyness.com; we respond within one month (Article 12(3) GDPR). You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Article 77 GDPR).
Automated individual decisions (Article 22 GDPR): The product makes no decision about you based solely on automated processing that produces legal effects for you or similarly significantly affects you. The approval engine assigns a task to one of three levels — direct, under department review, or human only; finalizing is always done by a human. Money transfers and the submission of tax filings are locked in code for virtual collars; no setting and no instruction can lift this lock.
Erasure requests and the audit trail: The audit trail is kept as proof and because of legal obligations, and it is not erased. When you request erasure, the entry in the audit trail remains; job texts and document contents, however, are reduced to a masked summary and then no longer contain personal data.
12. Your business's business data (data set B) — in brief
- Your business's data is separated by tenant isolation: on every read and write, the server checks the business identifier and the membership. Permissions cannot be raised from the browser.
- Each person sees only the data within their role and department.
- Access keys for external services are stored encrypted, not shown again, not logged, and never handed to the virtual collars.
- Your business's obligations and ours for this data are governed by D-07 · Data Processing Agreement.
13. Changes
If this notice changes, we publish the new version with a new date and inform you in the application. If processing based on your consent is extended, we ask for your consent again.
This document describes the behaviour of mybusyness as measured in the code. This is not legal advice.