1. Scope
This policy applies to the vectonn.com.tr website and the application, support and account operations carried out through it. For the commercial data of customers using the VectONN application, the service agreement and its data-processor annexes apply.
2. Customer data vs. site data
There are two distinct data sets that do not mix:
- Site data: the information you submit through forms on this site. We are the data controller.
- Customer data: the commercial records you operate in the VectONN application. You are the data controller; we act as data processor.
3. Where data is kept
In the VectONN application, each customer's data is kept in its own separate database. One business's records never sit in the same table as another's. This is not a setting added later, but the foundation of the architecture.
Access is limited by independent layers and these rules are re-verified with automated tests on every release.
4. Authorization
In the application, authorization is off by default: a user can only enter screens within the scope of permissions explicitly granted. Authorization is checked on the server side. Sensitive operations are distributed with separate permissions and who did what is written to the audit log.
5. Traceability of records
Financial and stock records are never changed silently. When an error is corrected, who changed what and when is written to an audit log, and that log cannot be deleted. In line with Turkish accounting practice, a correction is made by deleting the wrong record and entering the right one; the related customer, stock and accounting movements are reversed together, so balances stay consistent.
One exception: records belonging to a period for which the e-Ledger certificate has been obtained. In that period nothing can be deleted or edited; a correction is possible only as a reverse entry (storno) and both records remain in the ledger. This follows Tax Procedure Law art. 217 and Turkish Commercial Code art. 65.
6. Backups
Databases are backed up regularly. Having taken a backup is not enough on its own; the backup's restorability is also verified. A verified backup is a precondition for every production release.
7. Technical measures on the site side
- All traffic is carried encrypted over HTTPS.
- Forms are protected against session forgery with a token (CSRF).
- Passwords are stored irreversibly.
- Forms use an invisible field against automated submission.
- All data from users is escaped before being written to the screen.
8. Third-party services
A limited number of external services are used to run the site: hosting, e-mail delivery, font distribution and analytics. Analytics cookies run only with your consent; for details see the Cookie Policy page.
9. Mobile apps
VectONN has three mobile apps: PatrONN (summaries and approvals for the business owner), VectONN Team (internal communication and field work) and EdgePOS Adisyon (restaurant order terminal). All three are free, contain no advertising, and none of the data collected is shared with third parties; no ad network, data broker or external analytics provider is used.
In these apps an account is not created by the user: the business you work for defines a user for you on VectONN. The apps therefore work within the permissions your employer grants you, not as personal tools.
What each app processes:
- PatrONN: your name and user identifier (sign-in), device identifier (security and notifications), your in-app activity (troubleshooting and improvement), and the business's commercial and financial records (the app's core function).
- EdgePOS Adisyon: your user identifier, device identifier and order/sales records. Location, contacts, photos, audio and messages are not processed.
- VectONN Team: in addition to the above, location, photos and video, audio recordings, in-app messages, e-mail address and stored contact details. See below.
Specific notes for VectONN Team:
- Location is read only while the app is open on screen and only with your permission; there is no background location tracking. You can withdraw the permission at any time.
- Photos, video and audio are processed only when you attach them to a message or a work record, record a voice message, or join a voice or video call. The app never opens the camera or microphone on its own. A voice message you record is end-to-end encrypted like any other message.
- Messages are end-to-end encrypted. Content is decrypted only on the sending and receiving devices and is never held in readable form on the server. This means not even your employer can read the content of your conversations. Because the encrypted message still passes through the server, we declare it as 'collected' in the Google Play data safety form; hiding it would be misleading.
- Notification fault log. So that we can find out why a notification did not reach you, the server keeps the result of each send for a short time. This log contains your user identifier, the device identifier, the platform, the sending channel (standard notification or the iPhone incoming-call channel), the notification permission status at the time of sending, whether a notification address exists on the device, the send result, an error code if there was one, the time, and the type of notification together with the number of the related notification record. The notification address itself, the title and content of the notification and the identity of the sender are not written to this log. For HR notifications the type and record number are not stored either, and the time is kept only to the hour. Entries are deleted automatically after 30 days. For encrypted messages and calls, successful sends are not logged at all; only a failed send is kept, to the hour and for 72 hours. These entries do not record message or call as a separate type; however, because incoming calls on iPhone are sent through a separate channel, the channel of a failed call is visible in the log. The log is held in your business's own database, is visible there only to people with device management permission, and is used only to diagnose notification faults; it must not be used to assess employees' behavior or performance.
- If you connect a mailbox, its access details are kept in the device's secure storage and used only to reach your own mailbox.
All app traffic is encrypted with HTTPS; unencrypted connections are entirely disabled in published builds. The apps contain no database address, connection string or infrastructure secret; the phone talks only to authorised service endpoints and every permission check is performed on the server.
You can request deletion of your account and data on the Account and Data Deletion Request page.
10. Data deletion requests
You can request the deletion of your personal data. Your request is fulfilled except for records that legislation requires to be retained. When financial records cannot be deleted, fields containing personal data are made inaccessible and you are informed.
How to submit your request, what is deleted and what has to be retained is explained step by step on a separate page: Account and Data Deletion Request.
11. Security incidents
If we detect that personal data has been unlawfully obtained by others, we notify the relevant persons and the Personal Data Protection Board as soon as possible.
12. Changes
This policy may be updated. The current version is always published on this page with the last update date at the top.
Requests and contact
For questions about this document or requests regarding your personal data, write to kvkk@laicos.com.tr or to Caferağa Mah. General Asım Gündüz Cad. Bahariye Plaza No: 62/5, Kadıköy / İstanbul.
| Legal name | LAICOS Bilişim Yazılım ve Bilgi Sistemleri İthalat İhracat Limited Şirketi |
|---|---|
| Address | Caferağa Mah. General Asım Gündüz Cad. Bahariye Plaza No: 62/5, Kadıköy / İstanbul |
| Tax office / Tax ID | Kadıköy Vergi Dairesi (034272) / 6081463620 |
| MERSIS no | 0608-1463-6200-0001 |
| Trade registry no | 367228-5 |
| Corporate e-mail | info@laicos.com.tr |
| info@vectonn.com.tr | |
| Phone | 0216 606 54 84 |