This policy explains, as a whole, what data the Dualyx Appointment platform (the "Platform") holds, how it is protected, who it is shared with and how long it is kept. The KVKK notice for panel users' personal data is a separate document, and the processor undertaking for businesses' customer data is set out in the Data Processing Agreement.
Version: v1 · Last updated: 4 September 2026
The Platform is multi-tenant: all businesses share a single database, but every record carries a tenant identifier (businessId) and queries are constrained by it. We treat the data in three layers.
Platform data. Accounts, business records, roles, subscription and package information, audit records, support records. In this layer the data controller is [LEGAL ENTITY NAME].
Business data. The business's own operational records: services, working hours, expense categories, notification templates, documents and settings.
Customer data. Records about the business's own customers. In this layer the data controller is the business; [LEGAL ENTITY NAME] acts as a data processor and accesses this data only to provide the service, troubleshoot problems and carry out the business's instructions.
The customer records a business enters in the Panel may include: first name, last name, phone number, email address, date of birth, national identification number and free-text notes.
The national identification number field is optional. Free-text note fields are stored as the business fills them in; if special categories of personal data are entered into those fields, the resulting obligations belong to that business.
The following records are also kept against a customer record: appointments (date, time, service, provider, status, recurrence and notes), attendance status, manual payment records (amount, method, discount, notes), expenses, SMS, WhatsApp and email messages sent along with their delivery states, and post-appointment feedback and ratings.
Payments are not collected through the Platform; the records are a record of payments the business took physically. No card number, CVC or similar payment instrument data is processed.
When a customer list is bulk imported from an Excel file, the uploaded file is not stored permanently; once the import completes only the created customer records remain, and the operation is written to the audit record.
Session records, sign-in and registration attempts, password reset requests, one-time sign-in codes and the IP addresses associated with them are kept to detect abuse and protect account security.
Every successful change made in the Panel is written to the in-business activity record. These records show which user performed which operation in which area, and a business admin can view them in the Panel. The records are not deleted.
The Platform uses no advertising or tracking cookies. The limited data held in the browser is described in the Cookies and Local Storage Notice.
Business documents and support attachments are stored privately and served only to authorised users. Logos and profile photos are served over a stable link so they can be displayed in the Panel; anyone who knows that link can reach the file. Confidential documents should therefore never be uploaded into the logo or profile photo fields.
Uploaded files are written to the Platform's own server rather than to a separate cloud storage service, so files sit with the same hosting provider as the database.
Each business has a storage quota and usage is visible in the Panel. Deleted files are first marked as deleted, then removed from storage.
We share data only with the providers needed to run the service. Each is bound by contract and processes data only on our instructions.
This policy is updated when the provider list changes. We do not sell data to third parties for advertising.
Because the servers and some providers are located outside Türkiye, transfers take place. These transfers are made in accordance with the conditions set out in KVKK Art. 9, relying on an adequacy decision, one of the appropriate safeguards (including standard contractual clauses) or one of the exceptions listed in the Law.
Data is kept for as long as the service relationship continues. A business can delete its customer records, appointments, payments, expenses and files from the Panel at any time. When a customer record is deleted, the appointments, payments and notification records attached to that customer are deleted in the same operation.
Closing the whole account and deleting its data is requested as described in the Account and Data Deletion document. Records subject to a statutory retention obligation continue to be kept for the prescribed period.
If unlawful access to personal data is identified, [LEGAL ENTITY NAME] takes the necessary technical measures and acts in accordance with legislation regarding notification to the Personal Data Protection Board and to data subjects. Where a breach affects the customer layer, the business acting as data controller is informed without delay.
The Platform is a service for businesses and panel users are not expected to be under 18. If a business's customer records include minors, meeting the necessary consent and guardianship requirements is that business's responsibility.
This policy may be updated; the current version is published at this address. Send questions to info@dualyxlabs.com or through the support screen in the Panel.