1. Data controller and contact
Under Turkish Personal Data Protection Law No. 6698 (KVKK), the data controller is:
| Legal entity | Prefux Teknoloji Yazılım Elektronik Limited Şirketi |
|---|---|
| Address | Hacımehmetli Mah. Akışlar Sk. Selman Demir-Recai Ceylan Sitesi No: 22 İç Kapı No: 3, Alanya / Antalya, Türkiye |
| MERSIS No | 0733140170000001 |
| Trade Registry No | 32159 — Alanya Trade Registry (registered 22.06.2026) |
| Tax Office / No | Alanya · 7331401700 |
| Phone | +90 535 951 07 30 |
| info@prefux.com |
Scope: the Prefux mobile app (com.prefux.app, Android and iOS), the Prefux web panel (app.prefux.com), the Prefux Business Suite service delivered through api.prefux.com, and this corporate website.
2. Two different roles — this distinction matters
Prefux is multi-tenant business software: each business keeps its data in its own database. This creates two separate relationships, and which one applies determines who you address your requests to.
| Our direct relationship with you | Your account, your sessions, your security records. Here Prefux is the controller. Example data: email, name, password hash, session record, IP address. |
|---|---|
| Data we process for your employer | The products you sell, the tabs you open, the orders you deliver, and the customer details inside them. Here your employer is the controller; Prefux is the processor acting on the business's instructions. |
If you are a business customer and receive a request about your own customers' data, you are the controller for that data. Prefux gives you the access and export tools you need to answer such requests.
3. What data we process
3.1 Account and identity data
- Email address — your identifier and contact address. Your employer creates the account; you use it to sign in.
- Name / display name — visible on screens and in records.
- Password — never stored in clear text; hashed irreversibly with Argon2id.
- Phone number (optional) — used only if SMS or WhatsApp notifications are enabled. Entered from the web panel, never from the mobile app.
- Two-factor authentication (MFA) secret — stored encrypted if you enable MFA. The secret is generated and displayed only in the web panel.
- Verification code (6 digits, single use) — transmitted only at the moment of verification; never stored on the device or the server.
- Role and permissions — assigned by your administrator; they determine which screens you see.
3.2 Business data (on behalf of your employer)
Products, stock movements, sales and payment-method records; restaurant tables, tabs and menu items; deliveries and the end-customer details attached to them (name, phone, address, order note, amount to collect at the door); customer records — name, phone, email, address, trade name, tax number, notes and contact history.
The tax number field may, at the business's discretion, contain a national identity number. That is identity data under the KVKK; we recommend businesses fill this field only when genuinely required.
3.3 Location data
This is the most sensitive data the mobile app collects, so we describe it in detail.
| Who is it collected from? | Only users in the courier role. Cashier, waiter and manager roles are never asked for location. |
|---|---|
| When is it collected? | Only when you update a delivery's status (“Picked up” / “Delivered”). |
| How much is collected? | A single location point (latitude/longitude) at that moment. There is no continuous trail. |
| Is it collected in the background? | No. The app never requests background location permission; it works only with “while using the app” permission. |
| Is it mandatory? | No. If you decline, the delivery status still updates; the app only shows an informational note. |
| Am I told beforehand? | Yes. Before the operating system's permission dialog appears, the app explains in-app what location is used for. If you choose “Not now”, permission is never requested. |
| Who can see it? | Only authorised users of the business you work for. No other business can see it. |
| How long is it kept? | 30 days. After that the latitude/longitude fields are cleared automatically; the delivery record remains, the location does not. This cleanup runs regardless of the business's subscription status. |
| Is it used for advertising? | No. It is never used for advertising, profiling or sale to third parties. |
3.4 Technical and security records
- IP address and browser/app identifier — in the audit record of sign-in, sign-out, password change, two-factor authentication and administrator actions. Purpose: detecting unauthorised access and protecting your account.
- Session record — in server-side fast storage (Redis). The session key itself is not stored, only its cryptographic hash.
- Transaction audit record — who changed which record, when, and its before/after state. Held in the business's own database and protected by a hash chain.
- Server error and access logs — for fault diagnosis, in the hosting infrastructure.
3.5 What is stored on your device
- Session refresh key — in the device's secure store (iOS Keychain / Android Keystore).
- Access key — in memory only; never written to disk, lost when the app closes.
- Your courier location-consent choice (courier role only; whether you allowed it or chose “not now”) — kept in the same secure store. It is not location data, only a record of your choice.
- Both session keys are deleted when you sign out; your location-consent choice stays on the device so we do not ask you the same question again on your next sign-in. It is removed entirely when you uninstall the app.
3.6 Subscription and payment data (web only)
Subscription payments are taken on iyzico's own payment page; the card number and CVV never reach and are never stored on Prefux servers. After payment, iyzico returns the following to us:
- Stored-card key — sent to iyzico only when the subscription renews automatically. It does not contain the card number. It is not created at all if you do not choose to save your card.
- IP address and name for renewals — the IP address of the request that started the last payment and the user's name; iyzico requires them for the automatic renewal charge as well. Sent to iyzico only for renewals and deleted together with the stored card.
- Last 4 digits of the card and the card brand — solely to show “which card am I paying with” in the panel.
- Payment transaction records — amount, date, period, transaction number, error code.
There is no payment flow in the mobile app.
3.7 Data we do not collect
We never collect: advertising identifiers (IDFA / Android Advertising ID), contacts, calendar, photos and files, microphone, camera, health data, browsing history, or device fingerprints.
The app contains no advertising network, analytics or tracking SDK. We do not match your usage with other companies' data for advertising — in App Store terms, we do not perform tracking.
Card details are never entered into the mobile app. The “Card” option at the point of sale only records which method a payment was taken by; the card itself goes through a separate payment terminal.
3.8 How we collect this data
Your personal data is collected by wholly or partly automated means, through these channels: information you or your employer enter into the mobile app and the web panel; sign-in, transaction and security records created automatically on our servers; the single location point read with your consent in the courier role; the payment result iyzico returns to us for subscription payments; and the technical records kept in your browser on this corporate site (Cookie Policy). We do not buy, rent or compile this data from any source other than you or your employer.
4. Purposes and legal bases
The left column states why we process, the right column states the legal basis we rely on.
| Creating your account, signing you in, delivering the service | KVKK Art. 5/2-c — necessary for the conclusion and performance of a contract (GDPR Art. 6/1-b) |
|---|---|
| Keeping the business's sales, stock and service records | KVKK Art. 5/2-c; for financial records also Art. 5/2-ç, legal obligation (GDPR Art. 6/1-b and 6/1-c) |
| Showing the delivery location to the business | KVKK Art. 5/2-f — legitimate interest. The data is minimal (a single point) and time-limited (30 days). (GDPR Art. 6/1-f) |
| Account security and detection of unauthorised access | KVKK Art. 5/2-f — legitimate interest (GDPR Art. 6/1-f) |
| Keeping a tamper-evident audit trail | KVKK Art. 5/2-ç and 5/2-f (GDPR Art. 6/1-c and 6/1-f) |
| Statutory retention (invoicing, accounting) | KVKK Art. 5/2-ç — legal obligation (GDPR Art. 6/1-c) |
| Sending notifications (email / SMS / WhatsApp) | KVKK Art. 5/1 — explicit consent; the channel is enabled deliberately by the business (GDPR Art. 6/1-a) |
5. Who we share it with
We do not sell your data. We do not transfer it to third parties for advertising or marketing. Transfers happen only to deliver the service, and only in the limited cases below:
| Hetzner Online GmbH (servers and databases) | All service data, within the scope of hosting. Location: Helsinki, Finland — European Union. |
|---|---|
| iyzico Payment Services | For subscription payments: the business representative's name and email, the business name, and the amount. The card number and CVV never reach us. Only when a subscription is purchased via the web. Location: Türkiye. |
| Netgsm (SMS) | The recipient's phone number and message text. Only if the SMS channel is enabled. Location: Türkiye. |
| Google Firebase Cloud Messaging | Device notification key and notification text. Only if you granted notification permission and the push channel is enabled. |
| Google (“Sign in with Google”) | Your name, email address and Google account identifier. Only if you use the “Sign in with Google” button: Google verifies your account and reports the result to the app. If the feature is not enabled in the published build, the button never appears and no data reaches Google. Signing in with Google does not create a new account; it only verifies your existing one. Password sign-in is always available. |
| Meta WhatsApp Cloud API | The recipient's phone number and template message variables. Only if the WhatsApp channel is enabled. |
| Email server (SMTP) | The recipient's email address, subject and body. Only if the email channel is enabled. |
| Crash reporting (Sentry) | Error stack trace, app version, device and operating system information. Only if configured; when not configured the component never starts. |
| Object storage | Product images only. No personal data is uploaded. |
| Have I Been Pwned | Only the first 5 characters of the SHA-1 hash of your password (k-anonymity). The password itself or its full hash is never sent. |
| Competent public authorities | Only upon a legally valid written request, limited to the scope requested. |
Third-party components in the mobile app. Business data (sales, tabs, customers) goes only to api.prefux.com. Beyond that the app contains four components: Firebase Cloud Messaging, which obtains a device key if you grant notification permission; Sentry, which sends crash reports if configured; “Sign in with Google”, which runs only if it is enabled in the published build and only when you tap the button; and a location component that, in the courier role only and with your consent, reads your location — those points go to the Prefux server, never to a third party. Data reaches every other recipient in the table from the server, and only if the relevant channel is enabled.
5.1 International transfers
Our servers are located in Finland (European Union); the infrastructure of notification, crash-reporting and “Sign in with Google” providers may sit outside Türkiye. Such transfers are made only with the data necessary to deliver the service and only to the extent necessary; data-processing terms are contractually agreed with our providers. We maintain the transfer mechanisms required under KVKK Art. 9 in line with applicable law.
6. Retention periods
| Courier location points | 30 days — unconditionally. Latitude/longitude are cleared at the end of the period. This cleanup runs independently of the business's subscription status; a retention promise cannot be tied to an employer's payment status. |
|---|---|
| Incoming call records (Telephony module) | 6 months. Created only if the business enables the optional Telephony (caller-ID) module and connects its phone system: the caller's number, call time and, if any, the matched customer record are processed. At the end of the period the record is permanently deleted. |
| Session refresh key | 30 days — or the moment you sign out or revoke the session. |
| Access key | 15 minutes. |
| Incomplete sign-up requests | 7 days, then permanently deleted. |
| IP address and browser information in system and session audit records | 12 months. At the end of the period these two fields are cleared automatically; the audit record itself (who, what, when) remains in place. |
| Transaction audit record (business database) | Not deleted. Records are linked to one another by a hash chain; deleting or altering a row breaks that chain in a provable way. The IP address in these records is an input to the chain and therefore cannot be separated from the record. |
| Notification device record | Deactivated immediately when the account is deleted, and the value of the device notification key is erased; no notification is sent to that device afterwards. |
| Stored-card key, last 4 digits, card brand, renewal IP address and name | Deleted when the subscription closes. When you cancel, the subscription runs to the end of the period; the card reference is deleted the moment that period ends and the subscription actually closes. The card record held on iyzico's side is subject to iyzico's own retention policy. |
| Account and business data | For the duration of the subscription and at most 90 days after it ends. This is our retention ceiling; business data is deleted by the end of that period. If you want it deleted sooner, request it through the channel in section 8 — we conclude such requests within 30 days. |
| Financial and accounting records | For the period required by law — 10 years under Art. 82 of the Turkish Commercial Code. A deletion request does not shorten this period. |
| Transaction and event queue records | 14–30 days (technical records). |
| Print job records | 7 days. |
An honest note about how deletion works. When business records (customers, staff, products) are deleted in Prefux, they are marked as deleted and disappear from every screen in normal use; but they remain in the database for accounting integrity and the audit trail. Requests for permanent, irreversible deletion are handled through the channel in section 8.
7. Security measures
- All traffic runs over HTTPS/TLS; the app rejects cleartext connections, and a release build cannot be compiled against a non-HTTPS address.
- Passwords are hashed with Argon2id; the plain value is stored nowhere.
- Each business's data lives in a separate database; a user sees only their own business's data.
- Authorisation is enforced on the server; hiding a button in the interface does not count as a security measure.
- Session keys are rotated; if reuse is detected, the entire session family is revoked.
- Accounts are temporarily locked after failed sign-in attempts; optional two-factor authentication (TOTP) is supported.
- On the device, the session key is held in the operating system's secure store.
- Transaction audit records in the business database are protected by a hash chain, so retroactive alteration is detectable. System and session audit records are append-only — the application never writes updates or deletes to them.
8. Your rights and how to exercise them
Under KVKK Art. 11 you have the right to: learn whether your personal data is processed; request information if it is; learn the purpose of processing and whether it is used accordingly; know the third parties to whom it is transferred, in Türkiye or abroad; request correction if it is incomplete or inaccurate; request erasure or destruction where the conditions are met; request notification of correction and erasure to third parties it was transferred to; object to an adverse outcome produced solely by automated analysis; and claim compensation for damage arising from unlawful processing.
If you are covered by the GDPR you additionally have the rights to data portability (Art. 20), object to processing (Art. 21) and lodge a complaint with a supervisory authority.
How to apply: write to info@prefux.com, or send a written request to the address in section 1. We conclude requests within 30 days at the latest (KVKK Art. 13/2). Under the GDPR the period is one month (Art. 12/3).
Ask your employer first. For requests about your data inside your employer's records (for example a customer record or a delivery), your employer is the controller. Prefux cannot change their records without the business's instruction. Requests about your account itself — email, password, sessions — can be sent to us directly.
8.1 Withdrawing your consent
You can stop consent-based processing at any time and without giving a reason; this does not affect the lawfulness of processing carried out before withdrawal:
- Location — remove Prefux's location permission in your device settings. You can continue updating delivery status without the permission.
- Notifications — turn off notification permission in device settings; or your business administrator can disable the relevant channel (email / SMS / WhatsApp / push) from the panel.
- In every case you can also request it by writing to info@prefux.com.
9. Account deletion
You can delete your account yourself. From the app or the panel the request is processed immediately; if you cannot sign in and apply by email, it is concluded within 30 days at the latest, after identity verification. There are three routes: in the mobile app, the account icon at the top right of your role's home screen → My Account → “Delete my account”; in the web panel, the account deletion card at the bottom of the Settings page; and if you cannot sign in, a request to info@prefux.com.
Full public explanation: prefux.com/en/delete-account.
Deletion is performed by anonymisation, in three layers:
- Your identity data — name, email, phone, password, two-factor settings and sessions — is deleted immediately and irreversibly, regardless of your business's subscription status.
- Your notification device records are deactivated at the same moment and the value of the device key is erased.
- Your courier name in delivery records is replaced with “Deleted User” in your business's database. If the business's subscription has ended, this step is queued and completed on a periodic maintenance run independently of subscription status; the first two layers still finish immediately.
Sales, tab, delivery and audit records remain as required by commercial and tax law; those records do not contain your name, email or phone number.
Deletion is refused in two cases, with reasons given: an account that is the sole owner of a business (ownership must be transferred first, otherwise nobody could reach the business data) and platform administrator accounts.
10. Not directed at children
Prefux is business software and is not directed at children under 13; more generally it offers no content or service aimed at anyone under 18. Accounts are created only by business administrators, for their staff. We do not knowingly collect data from anyone under 18. If we learn that we have processed such data by mistake, we delete it to the extent the law permits. If you are a parent or guardian and become aware of such a case, please contact us.
11. Cookies
The mobile app uses no cookies. The web panel uses only one strictly necessary cookie: the refresh key that keeps your session alive. This corporate site sets no tracking cookies by default. For details see the Cookie Policy.
12. Changes to this policy
We may update this policy. For material changes we will inform you in the app and/or by email before the change takes effect. The “last updated” date at the top of this page always reflects the version in force.