Data Retention Policy
Last updated: March 10, 2025
This policy explains the principles governing the storage, processing and protection of personal data belonging to users of the Tengri Global Tracking System ("Tengri"), operated by Royal Steel Group Teknoloji Çelik ve Dış Ticaret Ltd Şti (the "Company"), within the framework of Turkish Personal Data Protection Law No. 6698 (KVKK) and the GDPR.
1. Data Controller
Royal Steel Group Teknoloji Çelik ve Dış Ticaret Ltd Şti
+90 850 225 84 85
info@royalsteelgroup.com.tr
www.royalsteelgroup.com.tr
2. Data Categories Retained and Retention Periods
| Data Category | Contents | Retention Period |
|---|
| Identity Data | First name, surname, email, profile photo | While the account is active + 30 days |
| Authentication | Password hash, Google/Facebook ID, JWT token | While the account is active |
| Subscription Data | Plan type, start/end date, Google Play token | While the account is active + 1 year (statutory) |
| API Usage Logs | Request count, endpoint, response time, IP address | 90 days |
| Session Data | IP address, browser, device, session duration | 30 days |
| Behaviour Analytics | Page views, features used, time spent in session, points where the premium wall was hit | Raw events 180 days, session summaries 400 days |
| Advertising Data | Ad impression/click counts (anonymous) | 1 year |
3. Legal Basis for Processing
- Performance of a contract: Account creation, session management, provision of the subscription service
- Legitimate interest: Service security, fraud prevention, system performance monitoring, usage analysis for product improvement
- Legal obligation: Tax and invoice records, statutory retention periods
- Explicit consent: Marketing communications (only where consent has been given)
4. Storage Location and Security
Your data is protected by the following security standards:
- Server Location: Data centres in Europe/North America
- Transport Encryption: TLS 1.2+ / 128-bit SSL encryption
- Database: Access control, encrypted connections
- Password Security: One-way hash using bcrypt (irreversible)
- API Keys: Cryptographically secure random generation
- Backups: Daily automatic backups, encrypted storage
5. Data Transfers
Your data may be transferred to the following third parties:
- Google LLC: OAuth authentication, Google Play payment processing
- PayTR Ödeme ve Elektronik Para Hizmetleri A.Ş.: Credit/debit card payment processing (PCI DSS compliant)
- Hostinger International: Server infrastructure services
All third parties to whom data is transferred are bound by data processing agreements compliant with the GDPR and KVKK.
6. Deletion and Destruction of Data
You have the right to have your data deleted. You may request the permanent deletion of all personal data associated with your account.
6.1 Automatic Deletion
- Following an account deletion request, all personal data is permanently destroyed within 30 days
- API usage logs are deleted automatically after 90 days
- Session data is cleared automatically after 30 days
- Raw behaviour events are deleted after 180 days and session summaries after 400 days
6.2 Manual Deletion Request
You may request deletion of your data in the following ways:
6.3 Scope of Deletion
The following data is permanently destroyed when an account is deleted:
- Identity and contact details (name, email, profile photo)
- Authentication data (password hash, OAuth links)
- Subscription history
- API keys and usage logs
- Session and device data
- Behaviour analytics records
Please note: Under statutory retention obligations, invoice and payment records must be kept for 5 years as required by tax legislation. This data is retained only for the duration of that legal requirement and is not used for any other purpose.
7. Data Breach Notification
If a security breach affecting your personal data is detected:
- The relevant regulatory authorities are notified within 72 hours
- Affected users are notified by email as soon as possible
- Transparent information is provided about the scope of the breach, the data types affected and the measures taken
8. User Rights
Your rights under the KVKK and the GDPR:
- Right of access: to request access to the personal data being processed
- Right to rectification: to request correction of inaccurate or incomplete data
- Right to erasure: to request deletion of your personal data (the "right to be forgotten")
- Restriction of processing: to request restriction of processing in certain circumstances
- Data portability: to receive your data in a structured format
- Right to object: to object to the processing of your data
9. Policy Updates
This policy may be updated when necessary. Significant changes will be notified by email and published on this page.
10. Contact and Applications
Royal Steel Group Teknoloji Çelik ve Dış Ticaret Ltd Şti
+90 850 225 84 85
info@royalsteelgroup.com.tr
www.royalsteelgroup.com.tr
Applications under the KVKK may be submitted to the contact details above from your registered email address or through a notary. Your application will be answered within 30 days at the latest.
This document is a translation provided for your convenience. The original and legally binding version of this document is the Turkish text. In the event of any discrepancy between this translation and the Turkish original, the Turkish version shall prevail.