Privacy Policy
Version 2026-09-12
1. Who is responsible
BPMN Central is operated by Numan Karaaslan, a sole proprietor established in Türkiye. For the data described in section 2 we are the data controller under the GDPR and the veri sorumlusu under Turkish law (KVKK No. 6698).
You can reach us about anything on this page through the contact page.
2. The two kinds of data, and why the distinction matters
Account and operational data — we are the controller. This is the data we hold to run the service: your account, your subscription, and what our systems record while operating your instance. It is described below.
The content inside your instance — you are the controller, we are the processor. Paid instances run against your own database and your own object storage. The processes, documents, user accounts and any personal data your organisation puts into the application are written to infrastructure you own and control. We do not copy it, do not store it elsewhere, and do not have an operational need to read it. Our access is limited to what administering the instance requires; we do not hold your database credentials or storage keys anywhere except in the running configuration of your own instance.
3. What we collect, why, and on what legal basis
| Data | Why | Legal basis | | --- | --- | --- | | Email address, password hash, company name, interface language | To create and secure your account, sign you in, and send you service email in your language | Performance of a contract | | One-time login, verification and password-reset codes | To confirm it is you | Performance of a contract | | Subscription records: plan, subdomain, status, billing period, provider identifiers | To provide, bill and support your subscription | Performance of a contract | | Operational records about your instance: provisioning events, restarts, memory and health alerts, error reports, quota counters | To keep the instance running, to warn you before it fails, and to enforce fair-use limits | Legitimate interest in operating a reliable service | | Contact and support messages you send us | To answer you and keep a record of the conversation | Legitimate interest / performance of a contract | | Server logs, including IP addresses, and anti-abuse counters | Security, fraud and abuse prevention, diagnosing faults | Legitimate interest in protecting the service |
Payment data. We never see or store your card details. Payments are processed by Polar as Merchant of Record; Polar is the seller for the transaction and an independent controller of the payment data it collects under its own privacy policy. We receive only what we need to operate your subscription: identifiers, plan, status and period.
No advertising, no profiling, no selling. We do not sell or rent personal data, we do not use it for advertising, and we do not carry out automated decision-making that produces legal effects for you.
4. Cookies
We use only cookies that are necessary for the site to work: the session cookie that keeps you logged in, the language cookie that remembers whether you want English or Turkish, and the CSRF token that protects forms. We do not use advertising or third-party analytics cookies, so there is no tracking consent banner to click through.
5. Who else processes it
We use a small number of providers, and only for the purposes above:
- Microsoft Azure (Sweden) — the infrastructure customer instances run on.
- Hetzner (Germany) — the server the website and control plane run on.
- RunPod — temporary infrastructure for free trial instances only.
- Polar — payments and merchant-of-record services.
- Resend — delivery of transactional email (verification codes, alerts, subscription notices).
Some of these providers operate outside Türkiye and the EEA. Where personal data is transferred, it is done under the provider's standard contractual clauses or equivalent safeguards. Under KVKK, your explicit consent or another lawful transfer ground under Article 9 applies to transfers abroad; by creating an account and using a service that runs on this infrastructure you are informed of and accept these transfers.
We disclose data to no one else, except where we are required to by law or a binding order, or where it is necessary to establish or defend a legal claim.
6. How long we keep it
- Account data — while your account exists, and for a reasonable period after deletion where we must keep records for accounting or legal-defence purposes.
- Subscription and billing records — for as long as Turkish tax and commercial legislation requires.
- Operational records and logs — typically months, not years; they are kept only as long as they are useful for diagnosing faults and preventing abuse.
- Content inside your instance — governed by your own retention rules, on your own infrastructure. When a subscription ends we delete the instance; your database and storage are untouched, and deleting what is in them is your decision.
7. Your rights
Under the GDPR and KVKK you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, a copy in a portable format, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time, which does not affect processing already carried out.
Ask through the contact page. We will answer within thirty days, and may need to verify your identity first — we will only act on a request from the account's own address, or on evidence of equivalent strength.
For data inside your own instance, direct the request to the organisation that operates that instance: they are the controller, and it is their infrastructure. If they ask us for help acting on it, we will assist.
If you believe we have handled your data unlawfully you may complain to your local supervisory authority, or to the Turkish Personal Data Protection Authority (KVKK Kurumu).
8. Security
The measures that matter most here are described in plain language on our security page: every database connection is TLS-verified against the hostname it was issued for, credentials go into the configuration of your own instance and nowhere else, each customer instance is isolated at the network level, and passwords are stored only as salted hashes. No system is perfect; if a breach affects your personal data we will notify you and the relevant authority without undue delay, as GDPR Article 33 and KVKK require.
9. Changes
We may update this policy. The version identifier at the top of this page changes when we do, and we will notify account owners by email before a material change takes effect.