Privacy Policy
Last updated: September 22, 2026
This Privacy Policy explains how Yolosoft Technology processes personal data through Vexo (the "Service") as data controller under Turkey's Law on the Protection of Personal Data No. 6698 ("KVKK"). It applies to your account, workspace, and any personal data your agents report as part of using the Service. Vexo serves customers worldwide, so Sections 10 and 11 below add rights specific to residents of the EU/EEA/UK and California, on top of - not instead of - the rights in Section 9.
1. Data Controller
The data controller of the personal data described in this policy is:
- Yolosoft Technology
- Registered address: [Yolosoft Technology's registered address, Turkey]
- Contact: yolosoft.tech@gmail.com
2. Personal Data We Process, and Why
- Account data (email address, name, password): used to create and secure your account, authenticate you, and send you the email notifications you keep turned on (machine offline alerts and the weekly summary). Passwords are never stored in plain text - only a salted Argon2id hash is kept.
- Workspace data (workspace names, member roles, invitations you send or receive): used to operate role-based access control within your workspace.
- Infrastructure metrics (utilization, thermal, availability, and resource data your agents report, plus the electricity-rate and hardware-cost inputs you configure): used to generate the dashboards and reports the Service exists to provide.
- Machine identity (a one-way hash of each enrolled machine's operating-system machine ID, and its host name when it enrolls with a fleet enrollment key): used to recognise a machine that enrolls again, so it doesn't appear twice. The machine ID itself is never sent.
- Usage and log data (IP address, request timestamps): used for security, fraud prevention, and diagnosing service issues.
3. Legal Basis for Processing (KVKK Art. 5)
We process account, workspace, and infrastructure-metrics data because it is necessary to establish and perform the contract formed by these Terms (KVKK Art. 5/2-c), and usage/log data on the basis of our legitimate interest in keeping the Service secure and reliable (KVKK Art. 5/2-f). Where a one-time verification code is sent to confirm a sign-in or a sensitive action, that processing is likewise necessary for contract performance. We do not process any special category of personal data (KVKK Art. 6) through the Service.
4. How We Collect Your Data
Directly from you (account and workspace data you enter), and automatically from the Vexo agent you install and enroll on your own infrastructure (infrastructure metrics), and from your browser or client when it makes a request to the Service (usage and log data).
5. Data Retention
- One-time verification codes are deleted automatically after 24 hours, regardless of whether they were used.
- A copy of each notification email we send (its recipient and content) is kept for 30 days, to deliver it and retry a failed delivery, and then deleted automatically.
- Infrastructure metrics history is retained according to your workspace's configured retention period and purged automatically once it expires.
- Account and workspace data is retained for as long as your account exists, and deleted when you delete your account or your membership in a workspace ends.
6. Transfer of Personal Data
We share personal data only with service providers who process it on our behalf and under our instructions (for example, email delivery for verification codes and notifications), or when required by a competent Turkish authority. We do not sell personal data. Any transfer of personal data outside Turkey is carried out in accordance with KVKK Art. 9, using one of its permitted bases (such as an adequacy decision, an appropriate safeguard recognized under KVKK, or your explicit consent). [List of sub-processors and their country of location to be confirmed].
7. Security Measures
Passwords are hashed, not stored in plain text. Sign-in and other sensitive actions (such as revoking an agent) require a one-time code sent to your verified email in addition to your password. Session cookies are set as HTTP-only, and marked Secure outside local development, so they cannot be read by page scripts or sent over an insecure connection. Every workspace's data is isolated from every other workspace.
8. Cookies
We use a small number of first-party, HTTP-only cookies required to keep you signed in and remember your active workspace (access and refresh session tokens, and your currently selected workspace). We do not use third-party advertising or tracking cookies.
9. Your Rights Under KVKK Article 11
As a data subject ("ilgili kişi"), you have the right to:
- Learn whether your personal data is being processed;
- Request information about it if it has been processed;
- Learn the purpose of processing and whether it is used in accordance with that purpose;
- Know the third parties, domestic or abroad, to whom your data is transferred;
- Request correction of incomplete or inaccurate data;
- Request deletion or destruction of your data, subject to the retention periods above and any legal obligation to retain it;
- Request that any correction, deletion, or destruction be notified to third parties your data was transferred to;
- Object to a result that arises against you through analysis of your data exclusively through automated means; and
- Claim compensation for damages arising from unlawful processing.
10. Additional Disclosures for EU/EEA/UK Residents (GDPR)
If you are located in the European Union, the European Economic Area, or the United Kingdom, the EU/UK General Data Protection Regulation ("GDPR") applies to our processing of your personal data in addition to KVKK, regardless of where Yolosoft is established. Under the GDPR:
- Our legal bases for processing mirror Section 3: performance of a contract with you (GDPR Art. 6(1)(b)) for account, workspace, and infrastructure-metrics data, and our legitimate interest in keeping the Service secure (GDPR Art. 6(1)(f)) for usage and log data.
- You have the right to access, rectify, erase, or restrict processing of your personal data, to receive a copy of it in a portable format, to object to processing based on legitimate interest, and to not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you.
- You have the right to lodge a complaint with your local data protection supervisory authority, or with the supervisory authority of the EU/EEA member state where you live, work, or where the alleged infringement occurred.
- Where we transfer your personal data outside the EU/EEA/UK (including to Turkey), we rely on an adequacy decision or an appropriate safeguard recognized under GDPR Chapter V (such as Standard Contractual Clauses).
- EU representative: if Yolosoft has no establishment in the EU, GDPR Art. 27 requires us to appoint an EU representative for you to contact instead of, or in addition to, us directly. [Name and contact details of Yolosoft Technology's appointed EU representative under GDPR Art. 27, or confirmation that Yolosoft has an EU establishment and this requirement does not apply].
11. Additional Disclosures for California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you the following rights in addition to those in Section 9:
- The right to know what personal information we have collected about you and why;
- The right to request deletion of your personal information, subject to the retention periods in Section 5;
- The right to correct inaccurate personal information;
- The right to opt out of the sale or sharing of your personal information - Yolosoft does not, and will not, sell or share personal information as those terms are defined by the CCPA/CPRA, so there is nothing to opt out of; and
- The right to not be discriminated against for exercising any of these rights.
We do not process sensitive personal information about California residents beyond what is necessary to provide the Service (your account credentials), so the CCPA/CPRA right to limit use of sensitive personal information does not apply beyond that use. You, or an authorized agent acting on your behalf, can submit a CCPA/CPRA request using the contact details in Section 12.
12. How to Exercise Your Rights
You can submit a request under any of the sections above by writing to yolosoft.tech@gmail.com or to the registered address above. We will respond within the timeframe required by the applicable law (for a KVKK request, as a rule, without delay and within thirty days at the latest), free of charge unless the request is manifestly unfounded, excessive, or repetitive, in which case the applicable law's fee provisions apply. We may need to verify your identity before acting on a request.
13. Data Controllers' Registry (VERBİS)
[Yolosoft Technology's VERBİS registration status to be confirmed - registered under registration number ..., or exempt under the relevant Personal Data Protection Board exemption decision].
14. Children's Privacy
The Service is not directed to children, and we do not knowingly collect personal data from children.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by email or an in-product notice) before the changes take effect.
16. Contact
Questions about this policy, or requests regarding your personal data, can be sent to yolosoft.tech@gmail.com.