This is an English translation provided for convenience. If there is any inconsistency, the Turkish version prevails.
This Privacy Policy explains what data is collected when you use Sosyal Karne, the digital analysis, reporting, social media visibility and business performance assessment service provided by Vebusoft Yazılım Sistemleri Ltd. Şti.; for what purposes that data is processed, how it is stored, with whom it may be shared, and what rights users have.
Sosyal Karne analyzes data from Instagram, Meta, Facebook Page, Google Business Profile and similar digital assets that businesses connect with their own permission, and produces reports on social media performance, digital visibility, business profile quality and conversion readiness.
This Privacy Policy covers visitors to our website, users who register for the user panel, paying customers, users who connect an Instagram/Meta or Google account, users who submit support requests, and all individuals or representatives of legal entities who use our services.
1. Data Controller
Your personal data is processed by the following company in its capacity as data controller under the Turkish Personal Data Protection Law No. 6698 (KVKK):
Vebusoft Yazılım Sistemleri Ltd. Şti.
Address: Sultaniye Mahallesi Doğan Araslı Bulvarı Han Plus No:146-50/346 Esenyurt / İstanbul
Tax Office: Esenyurt Vergi Dairesi
Tax No: 7450767985
MERSİS No: 0745076798500001
Email: gizlilik@vebusoft.com
Support: info@vebusoft.com
Phone: +90 538 954 79 10
Website: https://sosyalkarne.com
2. Definitions
In this policy:
Company: means Vebusoft Yazılım Sistemleri Ltd. Şti.
Service / Platform: means the Sosyal Karne website, user panel, reporting infrastructure, digital analysis system, payment flow and all related software services.
User: means any individual, or representative of a legal entity, who registers on the Platform, purchases a service, creates a report, connects an Instagram/Meta or Google account, submits a support request or visits the site.
Customer: means the person or business that receives paid or free services through the Platform.
Personal Data: means any information relating to an identified or identifiable natural person.
Business Data: means the profile, visibility, review, performance, social media, website and marketing data of the business the User represents.
OAuth Connection: means the authorization process through which the User connects their Instagram, Meta, Facebook, Google or similar third-party accounts to the Platform with their own explicit approval.
API Token: means the technical access credential used to access the User's account on the relevant third-party platform within the scope of the permissions granted by the User.
3. What Data Do We Collect?
Depending on the nature of our services, the following categories of data may be processed.
3.1. Account and identity data
- First and last name
- Company name
- User role or title
- Registered email address
- Phone number
- User ID
- Account creation date
- Account status
- User preferences
- Panel login and session information
3.2. Contact data
- Email address
- Phone number
- Billing and notification address
- Information shared in support requests
- Message content submitted through contact forms
- Records of requests, complaints and feedback
3.3. Company and billing data
- Trade name
- Tax office
- Tax number
- MERSİS number
- Company address
- Billing information
- Purchased package
- Order number
- Payment date
- Payment status
- Subscription information
3.4. Payment data
Payments may be processed through payment service providers and virtual POS infrastructure. The data that may be processed in this context includes:
- Payment amount
- Order number
- Payment date
- Payment status
- Last four digits of the card
- Card type
- Bank response codes
- Payment provider transaction ID
- Refund or cancellation transaction information
Credit card numbers, CVV codes or full card details are not stored in plain form by the Company. This information is processed on the payment service provider's secure infrastructure.
3.5. Business and digital asset data
Business information entered by the user or obtained through a connection may include:
- Business name
- Business category
- Industry
- Website address
- Instagram username
- Facebook Page information
- Google Business Profile information
- Business address
- Phone number
- Opening hours
- Map and location information
- Brand description
- Custom notes entered by the user
3.6. Instagram, Meta and Facebook data
From Instagram, Meta or Facebook accounts the user connects with their explicit permission, the following data may be obtained to the extent the respective platforms allow:
- Instagram professional account ID
- Instagram username
- Profile name
- Profile photo or profile picture link
- Bio
- Website link
- Follower count and total post count
- Post information: posting date, content type, caption and image link
- Like and comment counts per post
- Reach / view metrics per post
- Connected Facebook Page information
- Page ID
- Page name
- The user's access rights on the page or business
- OAuth permission status
- API access token information
- Token creation, refresh and validity information
Sosyal Karne does not post, send messages, write comments, create ad campaigns, change account settings or contact third parties on the user's behalf on Instagram, Facebook or Meta platforms.
Data we do not access. Sosyal Karne does not access or process Stories data, direct messages (DMs), follower lists, follower identity or demographic information, or the accounts your account follows. The analysis is based only on the profile and post data listed above.
3.7. Google and Google Business Profile data
From a Google account or Google Business Profile the user connects with their explicit permission, the following data may be obtained within the scope of the relevant API permissions:
- Basic Google user account information
- Business profiles the user has access to
- Google Business Profile business name
- Business category
- Business address
- Phone number
- Website information
- Opening hours
- Business description
- Google reviews
- Review rating
- Number of reviews
- Profile visibility and performance metrics
- User actions
- Metrics related to search and discovery visibility
- OAuth permission information
- API access token information
- Token creation, refresh and validity information
Google user data is used only to provide the service the user has explicitly approved, to analyze business performance and to create reports. Google user data is not used for ad targeting, data sales, third-party marketing or any purpose outside the service.
3.8. Website and analysis data
The following information may be analyzed from the website address or digital assets the user enters into the system:
- Website URL
- Page titles
- Meta descriptions
- Content structure
- Image and text layout
- Technical accessibility indicators
- Mobile-friendliness indicators
- Conversion elements
- Forms, buttons and contact areas
- Basic site performance data
3.9. Technical and security data
The following data may be processed for platform security and technical continuity:
- IP address
- Browser information
- Device information
- Operating system
- Login and logout times
- In-panel activity records
- Error logs
- API request and response records
- System event records
- Security alert records
- Authorization and access records
- User agent information
- Data collected through cookies and similar technologies
3.10. Support and communication records
When a user contacts us through support or contact channels, the following data may be processed:
- Subject of the request
- Message content
- Email correspondence
- Support records
- Screenshots
- Error descriptions
- Additional information the user chooses to share
4. For What Purposes Do We Process Data?
Personal data and business data are processed for the following purposes:
- Creating and managing user accounts
- Verifying user identity and account security
- Providing the purchased service
- Producing digital analyses and performance reports
- Establishing Instagram, Meta, Facebook and Google connections
- Retrieving the permitted data from connected accounts
- Analyzing business visibility and digital performance
- Displaying reports in the panel or delivering them to the user
- Managing the package or subscription the user selected
- Carrying out payment and billing processes
- Evaluating cancellation, refund and subscription requests
- Providing technical support
- Responding to user requests and complaints
- Improving service quality
- Ensuring system security
- Preventing unauthorized access, misuse and fraud
- Analyzing errors, outages and performance issues
- Fulfilling legal obligations
- Responding to requests from authorized public institutions and organizations
- Protecting our rights in the event of a dispute
- Fulfilling users' requests to remove connections, delete data or close accounts
5. Legal Grounds for Processing Personal Data
Your personal data may be processed under the KVKK on the following legal grounds:
5.1. Conclusion or performance of a contract
Data needed to create the user account, provide the service, prepare the report, and carry out payment and subscription transactions is processed on this basis.
5.2. Legal obligation
Data may be processed as required for invoicing, accounting, tax, statutory record-keeping, requests from official authorities and regulatory obligations.
5.3. Establishment, exercise or protection of a right
Data may be processed to resolve disputes, evaluate requests and complaints, handle payment disputes, address breaches of contract or in connection with legal proceedings.
5.4. Legitimate interest
Data may be processed to ensure system security, prevent misuse, improve service quality, analyze errors and run operational processes.
5.5. Explicit consent
The user's explicit consent may be obtained for connecting Instagram, Meta, Facebook, Google or similar third-party accounts; sending marketing communications; using non-essential cookies; or other processing that requires explicit consent.
6. Use of Third-Party Platform Data
Sosyal Karne may integrate with third-party platforms such as Instagram, Meta, Facebook and Google. Data obtained from these platforms:
- Is obtained only with the user's explicit permission.
- Is used only to provide the service.
- Is used to create the user's own reports.
- Is not used to post content or take actions on the user's behalf.
- Is not used for ad targeting.
- Is not sold to third parties.
- Is not used for any other purpose beyond the user's explicit permission.
On the respective platforms' permission screens, users can see which data they are granting access to and review the scope of the permissions before approving the connection.
7. Use of Google User Data
Data obtained through your Google account or Google Business Profile connection is used only for the following purposes:
- Listing the business profiles you have access to
- Analyzing the business profile you select
- Assessing Google Business Profile visibility
- Including Google reviews and ratings in the report
- Reporting profile performance metrics
- Producing an assessment of digital visibility and business performance
Google user data:
- Is not viewed by humans unnecessarily.
- Is not used for ad targeting.
- Is not sold to third parties.
- Is not used for marketing outside the Platform.
- Is not used outside the stated purpose of the service.
- Is deleted, or access is removed, when the user requests it.
7.1. Limited Use disclosure. Sosyal Karne's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7.2. Requested permission scope. For the Google Business Profile connection, only the https://www.googleapis.com/auth/business.manage scope is requested. This scope is used to list the business profiles the user is authorized for and to analyze profile, review, photo, post and performance data on a read-only basis. Using this scope, Sosyal Karne does not edit the business profile on the user's behalf, does not write or reply to reviews, does not publish posts, does not upload photos, does not change business information and does not perform any write operations. For Sign in with Google, only the openid, email and profile scopes are used; these scopes are not used for any purpose other than account creation and authentication.
8. Use of Meta, Instagram and Facebook Data
Data obtained through an Instagram, Meta or Facebook connection is used only for the following purposes:
- Identifying the Instagram professional account the user is authorized for
- Verifying the relationship between the connected Facebook Page and the Instagram account
- Reporting profile information
- Analyzing content and account performance metrics
- Producing a social media visibility and engagement report
- Showing the connected account status in the user's panel
- Removing the connection when the user requests it
Sosyal Karne does not create posts, stories, comments, messages or ads on your behalf through your Instagram or Facebook account.
9. Storage of API Tokens and Connection Information
API tokens obtained from Instagram, Meta, Facebook and Google connections are technical access credentials. This information:
- Is not shared with unauthorized persons.
- Is not displayed in plain form in the panel.
- Is not written in plain form to logs.
- Is stored encrypted or in a secure manner where possible.
- Is used only by authorized system services.
- Is deleted or disabled when the user removes the connection.
- Is subject to access controls for security purposes.
10. With Whom Data May Be Shared
Your personal data and business data may be shared with the following parties to the extent necessary to provide the service:
- Server and cloud infrastructure providers
- Database service providers
- Payment service providers
- Virtual POS providers
- Email delivery services
- Notification services
- Accounting and financial service providers
- Technical support and software service providers
- Security and log management service providers
- Legal advisors
- Authorized public authorities
- Courts, enforcement offices and administrative authorities
Your personal data is not sold to third parties.
11. International Data Transfers
Some technical service providers, cloud servers, email infrastructure, payment infrastructure, analytics tools or third-party platforms may be located outside Turkey.
For this reason, your personal data may be transferred abroad in order to provide the service and operate the technical infrastructure.
Where data is transferred abroad, technical, administrative and legal measures in line with the applicable legislation are taken.
12. Data Retention Period
Data is retained for as long as necessary for the purpose of processing. General retention principles:
- User account data is retained while the account is active.
- Business and report data may be retained while the user account or subscription is active.
- API token information is retained while the relevant connection is active.
- When a connection is removed, new data retrieval stops and the token is deleted or disabled.
- Payment and invoice records are retained for the period required by the relevant legislation.
- Support requests and transaction records are retained for a reasonable period.
- Security logs may be retained for as long as necessary for system security and dispute management.
- Data whose processing purpose has ended, or whose reason for retention no longer exists, is deleted, destroyed or anonymized.
13. Data Security
Reasonable technical and administrative measures are taken to protect data. These measures may include:
- Use of HTTPS
- Access control
- Authorization layers
- Encryption
- Secure token storage
- Log masking
- Firewall
- Backup policies
- Restricted administrator access
- Role-based authorization
- Monitoring of unauthorized access
- Keeping system event records
- Fixing security vulnerabilities
- Restricting staff and service provider access
Even so, data transmission over the internet and electronic storage methods are never completely risk-free. Users therefore also need to protect the security of their own accounts.
14. User Account Security
The user must:
- Keep their account information confidential.
- Use a strong password.
- Not share their password with third parties.
- Notify us immediately if they notice unauthorized use.
- Connect only businesses and accounts they are authorized for.
The Company cannot be held liable for damages resulting from the user's own fault or from information the user gives to unauthorized third parties.
15. Cookies and Similar Technologies
Cookies may be used on our website and panel. Cookies may be used for:
- Session management
- Security
- Remembering user preferences
- Making the panel work properly
- Completing the payment flow
- Measuring site performance
- Error analysis
- Analytics measurement
- Marketing and retargeting
Strictly necessary cookies are required for the service to work. For non-essential cookies, user consent is obtained where required. For details, please see the Cookie Policy page.
16. Marketing Communications
If the user has given explicit consent, campaign, announcement, product update or informational messages may be sent by email, SMS or similar channels.
The user can withdraw consent to marketing communications at any time.
Mandatory service notifications, security alerts, billing information and operational messages about the account are not considered marketing communications.
17. Data Deletion and Removing Connections
The user can remove connected Instagram, Meta, Facebook or Google accounts from the panel. When a connection is removed:
- New data retrieval from the relevant platform stops.
- The API token is deleted or disabled.
- Automatic data updates end.
- The user may separately request deletion of previously generated report data as well.
The user can send account deletion or data deletion requests to gizlilik@vebusoft.com. For data deletion requests, identity and account ownership may be verified.
18. Resolution of Data Deletion Requests
Verified data deletion requests are evaluated within a reasonable period. As a result of the request:
- The user account may be closed.
- The related business data may be deleted.
- API token information may be deleted.
- Report data may be deleted or anonymized.
- Records that must be retained due to legal requirements may be retained for the applicable period.
Data subject to a statutory retention obligation is retained only for the purposes required by the relevant legislation.
19. Children's Privacy
Sosyal Karne is not a service directed at children.
The Platform is not intended to be used, or to have accounts created or payments made, by persons under the age of 18.
If you believe that data belonging to a person under 18 has been processed, you can contact us.
20. Third-Party Links
Our website or panel may contain links to third-party websites, payment systems, social media platforms or external services.
The Company is not responsible for the privacy practices of third-party sites. Users are advised to review the privacy policies of those third parties.
21. Automated Analysis and Scoring
Sosyal Karne may produce automated analyses or scores in areas such as digital visibility, social media performance, business profile quality, review presence, website readiness and similar areas. These scores and analyses:
- Are for informational purposes.
- Do not guarantee any specific business outcome.
- Do not on their own replace a legal, financial or business decision.
- Are limited to the information provided by the user and the data that can be accessed.
- May be affected by the API data the platforms provide and by technical limitations.
22. User Rights
Under the KVKK, users have the following rights:
- To learn whether their personal data is being processed
- To request information about it if it has been processed
- To learn the purpose of processing and whether the data is used in line with that purpose
- To know the third parties to whom the data is transferred in Turkey or abroad
- To request correction of incomplete or inaccurately processed data
- To request deletion or destruction of the data
- To request that corrections or deletions be notified to the third parties to whom the data was transferred
- To object to an outcome against them that results from analysis by automated systems
- To claim compensation for damages suffered due to unlawful processing
23. Exercising Your Rights
Users can send their privacy and KVKK-related requests to the following address:
Email: gizlilik@vebusoft.com
Including the following information in the application will speed up the process:
- Full name
- Registered email address
- Business name
- Subject of the request
- Scope of the request
- Information that helps verify identity or account ownership
Applications are evaluated in accordance with the applicable legislation.
24. Changes to This Policy
This Privacy Policy may be updated from time to time.
The current policy is always published at https://sosyalkarne.com/gizlilik-politikasi.
In the case of significant changes, users may be informed by email, panel notification or through the website.
A user who continues to use the Platform is deemed to have accepted the current Privacy Policy.
25. Contact
You can contact us about privacy, data security, data deletion, removing connections or KVKK applications.
Vebusoft Yazılım Sistemleri Ltd. Şti.
Address: Sultaniye Mahallesi Doğan Araslı Bulvarı Han Plus No:146-50/346 Esenyurt / İstanbul
Email: gizlilik@vebusoft.com
Support: info@vebusoft.com
Website: https://sosyalkarne.com
