Legal
Privacy Policy
What we collect when you request or purchase a diagnosis, review, audit, assessment or execution service; why it is used; how long it is kept; who may process it; and how to exercise your rights. Short version: we collect what the engagement requires, and nothing else.
1. Who is responsible
App Rescue Desk is a trading name of Alp Bozkurt, a sole proprietor established in Türkiye. For the personal data described here, that provider is the data controller.
For any privacy question, request or complaint, write to hello@apprescuedesk.com. A real person reads it.
2. What we collect
- Engagement intake
- Your name, work email, company or project name, country and time zone, your application and project URLs, the service route you choose, the application stage, ownership status, desired outcome, business impact, the workflows that matter most, your stack and connected services, access availability, and the route-specific information you choose to provide.
- Assessment evidence
- Repository, schema, policy, provider-setting, architecture, ownership, release, test, backup and operational evidence needed for the agreed scope of a review, audit or assessment.
- Engagement record
- Scope, correspondence, findings, diagnosis, risk register, dependency map, proposal, approval, change record, test evidence, acceptance result, invoice and closure record.
- Incidental customer data
- Limited production information that may be visible while we review logs, configuration or workflows — a user record, an email address, a transaction ID, a log line. We look at it only as far as the engagement requires. It is not treated as a dataset and is minimised wherever possible. We do not export or retain your database.
- Agency and portfolio data
- Where you enquire as an agency or portfolio: partner identity, communication mode, portfolio application inventory, client-ownership boundaries and non-solicitation terms.
- Specialist access records
- Where a disclosed specialist is used: the named specialist, assigned role, access granted, access revoked and QA records.
- Payment
- When a payment is taken it is handled by İyzico. We receive confirmation of payment, the amount, and limited billing details such as your name and country. We never receive or store your full card number.
- Website usage
- Page views, referring source and campaign parameters (utm_source, utm_medium, utm_campaign, utm_content), plus which steps of the intake flow were completed. Collected through PostHog in a cookie-free configuration — nothing survives the tab you close, and we do not recognise you across visits — and used in aggregate to understand which channels bring real customers.
- Server logs
- Standard web-server records: IP address, timestamp, requested URL, user agent. Kept briefly for security and abuse prevention.
3. What we ask you not to send
Do not send passwords, API keys, access tokens, database connection strings, recovery codes or private customer records through the intake form, by email, or over chat.
We do not need them, we do not want them in our inbox, and we will ask you to rotate anything you send us anyway. Access is granted through collaborator invitations, scoped roles or supervised screen sharing instead — see Access & Security.
If a credential does reach us despite this, we will tell you, delete it from our records, and ask you to rotate it.
4. Why we use it
- To route and qualify the service you request, before you are asked to pay.
- To confirm scope and price for a review, audit, assessment or execution.
- To deliver the diagnosis, review, audit or assessment you ordered.
- To plan and perform approved execution or migration, and to verify acceptance criteria.
- To take payment and issue receipts and refunds.
- To communicate with you about your engagement — requesting access, sending findings, agreeing scope.
- To coordinate disclosed specialists where an engagement requires one.
- To keep security, access and legal records required for accounting and tax, and to handle any later dispute.
- To improve product-level conversion and operations, in aggregate.
We do not sell your data, we do not share it with advertisers or data brokers, and we do not use your data, code or business information to train machine-learning models. We do not send marketing emails from engagement data, and there is no newsletter.
5. Legal bases
Where the EU or UK GDPR applies to you, we rely on the following legal bases:
- Contract
- Intake data, engagement records, correspondence and payment data — all necessary to provide the service you asked us to provide.
- Legal obligation
- Accounting and tax records relating to payments.
- Legitimate interests
- Aggregate website analytics, security logging and abuse prevention, and defending legal claims — balanced against your interests, and limited to what is necessary.
- Consent
- Anything optional, such as permission to reference your engagement publicly. You may withdraw consent at any time.
7. International transfers
We are based in Türkiye, and we process your engagement data there. Our service providers are located as follows: Railway and Google are established in the United States and operate infrastructure there and in the European Union; PostHog is used through its EU cloud, so that analytics data is hosted in the European Union; İyzico is established in Türkiye. If you are in the EU, the UK or elsewhere, your data may therefore be processed outside your country.
Türkiye has not been the subject of an adequacy decision by the European Commission. Where we process your data in Türkiye, we do so because it is necessary to perform the contract you have entered into with us — you asked us to work on your application, and we cannot do that without receiving your engagement data.
Our US-based providers apply their own transfer safeguards. Google relies on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
If this is not acceptable for your organisation, do not submit an intake, and contact us first.
8. How long we keep it
- Engagement records
- Up to 24 months after the engagement closes, so we can answer follow-up questions and handle any dispute. Deleted sooner on request.
- Declined or unqualified requests
- Deleted within 90 days where no engagement was opened and no payment was made.
- Payment and accounting records
- Kept as long as tax and accounting law requires. These cannot be deleted on request.
- Server logs
- Typically 30 days.
- Analytics
- Retained in aggregate, without identifying you.
9. Your customers' data
If, during an engagement, we encounter personal data belonging to your users, you remain the controller of that data and we act on your instructions in relation to it.
We access it only as far as diagnosing, reviewing or verifying the work requires, we do not copy or export it, and we do not use it for any other purpose. Please remove or mask customer data from anything you share with us. If your organisation requires a signed data processing agreement before we begin, contact us before submitting an intake.
10. Your rights
Subject to the law that applies to you — the EU or UK GDPR, Türkiye's KVKK, or your local equivalent — you can ask us to:
- Access the personal data we hold about you, and receive a copy.
- Correct anything inaccurate.
- Delete your data, where we are not legally required to keep it.
- Restrict or object to our processing.
- Port your data to another provider in a machine-readable format.
- Withdraw consent where processing is based on it.
Email hello@apprescuedesk.com. We respond within 30 days, and we do not charge for it. If you are unhappy with our response you may complain to your local data protection authority — in Türkiye, the Kişisel Verileri Koruma Kurumu (KVKK); in the UK, the Information Commissioner's Office (ICO); in the EU, your national supervisory authority.
12. Security
We use the minimum access necessary for each engagement, we do not use shared passwords, and access granted for an engagement is revoked when it closes. Engagement records are held in access-controlled systems, and payment card details never touch our systems.
The full process is on the Access & Security page. No system is perfectly secure; if a breach affects your personal data, we will tell you and the relevant authority without undue delay.
13. Children
This is a service for businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes
We may update this policy as the service evolves. The current version is always the one published here, and material changes are reflected in the "last updated" date at the top of the page.
Questions about this policy: hello@apprescuedesk.com.