This Privacy Policy explains which personal data FİDKEEP TEKNOLOJİ TİCARET LİMİTED ŞİRKETİ ("Fidkeep") processes through the fidkeep.com website and the Fidkeep application; for which purposes and on which legal grounds the data is processed; to whom it is transferred; how long it is kept; and the rights of data subjects. The policy also contains the disclosures required by the Google API Services User Data Policy for user data received from Google APIs.
The formal notice under Article 10 of Law No. 6698 on the Protection of Personal Data ("KVKK") and the Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform is given in the KVKK Privacy Notice. For the purposes of Turkish law, that notice is authoritative; this policy describes the same processing in more detail and should be read together with it. This English version is provided for convenience; the Turkish version prevails in case of conflict.
1. Who we are and scope
Fidkeep is a web application that lets multi-location businesses collect their Google Business Profile reviews in one workspace, prepare AI-assisted reply drafts in each location's brand voice, publish replies to Google, follow reviews by topic and sentiment, have e-mail alerts sent to their team for new reviews that match rules they set, manage team access and follow location reports.
Identity and contact details of the data controller:
- Trade name: FİDKEEP TEKNOLOJİ TİCARET LİMİTED ŞİRKETİ
- Address: Sarıgüllük Mah. Ali Nadi Ünler Bul. Milenyum Apt. No: 3A, Şehitkamil / Gaziantep, Türkiye
- MERSİS No: 0387146003100001
- E-mail: [email protected]
- KEP (registered electronic mail): [email protected]
Further company details are available on the Company Information page.
This policy covers the following channels: the fidkeep.com website; the sign-in and sign-up screens at auth.fidkeep.com and the application running on fidkeep.com subdomains; and support and communications with Fidkeep by e-mail or KEP.
Fidkeep serves only businesses acting for commercial or professional purposes (merchants and tradespeople, legal entities, public institutions). The service is not offered to consumers.
Processing for which Fidkeep is the controller
Fidkeep is the data controller for data of website visitors, account users (name, e-mail, authentication data), billing and payment contacts, and persons involved in support and communications, as well as for security logs and marketing communications.
Processing for which Fidkeep is a processor
For the Google Business Profile content a customer syncs into its workspace (reviewer names, profile photos, review texts, ratings), for the topic and sentiment labels derived from that content and for data a customer places in its workspace about third parties, the customer is the data controller; Fidkeep processes this data on the customer's behalf and on its instructions as a data processor. This relationship is governed by the Data Processing Agreement.
If you wish to exercise your rights regarding a Google review you wrote about a business, you should first direct your request to that business. If your request reaches Fidkeep, we forward it to the relevant customer without delay and support the customer in responding. Removal of a review from Google is subject to Google's own processes.
2. Data we collect
Website visitors
- Network and device data: IP address, browser and device information (user agent), requested page, timestamp and referring address; this data is kept as access logs in the hosting and network security infrastructure.
- Analytics data (only with your explicit consent): through Google Analytics 4, pages visited, visit duration, traffic source, device and browser type, approximate location (country/city level) and a randomly generated client identifier. Google Analytics 4 does not log or store IP addresses.
- Cookie preference: the choice you make in the cookie banner is stored in your browser.
Account and identity data
- First and last name, e-mail address, e-mail verification status, account role, account creation and update times.
- If you register with e-mail and password, your password is not stored in plain text but only as a salted hash.
- If you use "Sign in with Google", the basic profile information Google provides for authentication (openid, email and profile scopes): name, e-mail address, e-mail verification status, profile photo and Google account identifier.
Authentication and security data
- Session identifiers and session expiry, IP address, browser and device information, linked sign-in methods.
- E-mail verification and password reset records, invitation records, security events and audit records with sensitive fields redacted.
- Google OAuth access and refresh tokens, token expiry and granted scopes. Tokens are stored so that the background synchronisation you authorised can continue, and they are encrypted at rest.
Google Business Profile data
The data received from Google when you grant the business.manage scope is listed in detail in section 5: business accounts, locations, reviews (reviewer display name, profile photo, rating, review text, media references, timestamps) and existing owner replies.
Workspace content
- Selected locations, team memberships and roles, e-mail addresses of invited persons, location-level access permissions.
- Location-level brand voice settings: reply language, tone, preferred and prohibited phrases, signatures, example replies and AI instructions.
- Automatic reply settings, report recipients, reply drafts, publishing actions, generated reports and product feedback.
- Smart rules: rule conditions (rating, whether the review has text, review topic), the locations a rule covers, the team members selected as recipients, whether the rule is active or paused, mute preferences and rule history (which reviews matched and who was e-mailed).
AI-related records
- Inputs sent to the AI provider and the outputs returned (reply drafts, topic and sentiment labels assigned to reviews, location setup suggestions, report narratives, structured feedback records).
- Operation records: model used, token counts, cost, status and provider request identifiers.
Billing and payment data
- Invoice name, tax office and tax identification number (for sole proprietorships, the Turkish national identity number where required by law), billing address and billing e-mail address.
- Plan, billing period, add-ons, payment status and invoice records.
- The card token, last four digits, card brand and expiry date returned by iyzico. Card details are entered on iyzico's secure payment form; Fidkeep never sees or stores full card numbers or CVV codes.
Support and communications data
- The content and attachments of e-mails and KEP messages you send us, your name and contact details, and the correspondence history of the request.
- Your commercial electronic message preferences and the related consent and opt-out records.
Operational and usage records
- Records of operations such as synchronisation, draft generation, publishing and the delivery of report and smart-rule e-mails, timestamps, quota usage, e-mail delivery status and related technical identifiers.
- Application error and performance records (which may include IP address, user identifier, browser information and request context).
- Access and traffic logs.
Special categories of personal data
Fidkeep does not knowingly process special categories of personal data within the meaning of Article 6 KVKK. Reviews, particularly those about hospitals and clinics, may incidentally contain health or other special-category details that the reviewer published. Fidkeep does not seek, extract or profile such data. Customers must not enter special-category data into instructions, example replies or replies.
3. Data sources and collection methods
Personal data is collected electronically, by fully or partly automated means, from the following sources:
- Directly from you: registration, account and workspace settings, order and invoice details, support correspondence.
- From workspace administrators: team member invitations, roles and location access.
- From Google: profile information provided during "Sign in with Google", and account, location, review and reply data received from the Google Business Profile API under the business.manage permission.
- From iyzico: payment result, card token, last four digits, card brand and expiry date.
- From AI providers: outputs generated at your request, under settings you enabled or in the normal operation of the Service (for example topic and sentiment labels for reviews).
- Automatically: cookies and similar technologies, access and security logs, error monitoring and operation records.
4. Purposes and legal bases
We process personal data for the following purposes, relying on the legal bases of Article 5 KVKK shown next to each:
- Creating accounts, sign-in and session management, providing the service: establishment or performance of a contract (Art. 5(2)(c)).
- Connecting Google Business Profile, synchronising reviews and replies, publishing replies on your instruction or under an automatic reply setting you enabled: performance of a contract (Art. 5(2)(c)). For reviewer data in this processing the customer is the controller; reviews are personal data made public by the reviewer (Art. 5(2)(d)).
- Generating AI-assisted reply drafts, location setup suggestions and report narratives: performance of a contract (Art. 5(2)(c)).
- Tagging synchronised reviews by topic and sentiment with AI and using the labels in the review list, review detail, dashboard, filtering and smart rules: performance of a contract (Art. 5(2)(c)). For reviewer data in this processing the customer is the controller; the labels classify the content of the review and are not used to profile, score or classify individuals.
- Sending alert e-mails about new reviews that match smart rules defined by the customer to recipients the customer selects from its own team members, and keeping rule history: performance of a contract (Art. 5(2)(c)); for team members who are not themselves party to the contract, additionally legitimate interest (Art. 5(2)(f)). For the review information contained in the e-mails the customer is the controller.
- Managing teams, roles, invitations and location access: performance of a contract (Art. 5(2)(c)).
- Sending service messages such as verification, password reset, invitation, security notice and report e-mails: performance of a contract (Art. 5(2)(c)).
- Billing, collection, accounting and issuing e-Invoices / e-Archive Invoices: express provision of law (Art. 5(2)(a); Tax Procedure Law No. 213, Turkish Commercial Code No. 6102), performance of a contract (Art. 5(2)(c)) and legal obligation (Art. 5(2)(ç)).
- Keeping access and traffic logs: express provision of law (Art. 5(2)(a); Law No. 5651) and legal obligation (Art. 5(2)(ç)).
- Information security, prevention of abuse and fraud, error monitoring and service continuity: legitimate interest (Art. 5(2)(f)).
- Responding to support requests: performance of a contract (Art. 5(2)(c)) and legitimate interest (Art. 5(2)(f)).
- Evaluating product feedback and improving the service: legitimate interest (Art. 5(2)(f)).
- Sending commercial electronic messages to merchants and tradespeople: express provision of law (Art. 5(2)(a); Law No. 6563) and legitimate interest (Art. 5(2)(f)); explicit consent where the legislation requires prior consent.
- Analytics measurement on the website (Google Analytics 4): explicit consent (Art. 5(1)).
- Responding to data subject requests and requests from public authorities: legal obligation (Art. 5(2)(ç)).
- Establishing, exercising or defending rights in disputes: Art. 5(2)(e).
Where processing relies on explicit consent, you may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out before it.
5. Google user data and Limited Use
Fidkeep's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google data we access
Through "Sign in with Google" (openid, email and profile scopes) we receive only: name, e-mail address, e-mail verification status, profile photo and Google account identifier.
To connect Google Business Profile we request the https://www.googleapis.com/auth/business.manage scope. Through this scope we receive and store:
- Business accounts: account identifiers, resource names, display names, account type, your role on the account and verification state.
- Locations: location identifier, location name, address, category, place ID, profile image and synchronisation times.
- Reviews: review identifier, reviewer display name and profile photo, star rating, review text, references to media attached to the review, creation and update times.
- Replies: the text of existing owner replies, publication state, update times and any Google policy status returned for a reply.
How we use it
Google user data is used only to provide features that you can see and use in the application:
- Signing you in with your Google account and securing your account.
- Listing the business accounts and locations you are authorised for, and showing the reviews and reply states of the locations you select in a single inbox.
- Preparing AI-assisted reply drafts for reviews and generating location reports.
- Tagging reviews by topic and sentiment, showing the labels in the review list, review detail and dashboard, and letting you filter reviews by topic and sentiment.
- Sending alert e-mails containing the review's information (location, rating, review text and reviewer's display name) about new reviews that match smart rules you define to the workspace team members you select as recipients of the rule.
- Publishing or updating on Google the replies you approve, or replies covered by a controlled automatic reply setting that an authorised user has explicitly enabled and configured.
Limited Use commitments
- Google user data is not sold.
- Google user data is not used for advertising; it is not used for targeted, personalised or retargeted advertising and is not transferred to advertising platforms, data brokers or information resellers.
- Google user data is transferred to third parties only to the extent necessary to provide or improve the user-facing features described above, for security purposes, or to comply with applicable law. For example, when a reply draft is generated, the review text, rating and reviewer display name are sent to our AI providers' models solely to generate that draft; for topic and sentiment tagging, only the review text and rating are sent, together with the topic list for the location's industry, solely to determine the labels. Smart-rule alert e-mails are delivered through Resend. The service providers involved are listed on the Subprocessors page.
- Google user data is not used to determine creditworthiness or for lending purposes.
- Google user data is not used to develop, improve or train generalised artificial intelligence or machine learning models. Fidkeep works with AI providers under terms under which API data is not used for model training.
- Fidkeep personnel do not read Google user data, except (i) where you have given explicit consent for specific data (for example, when you ask us in a support request to look at a particular review), (ii) where it is necessary for security purposes such as investigating abuse, a bug or a security incident, or (iii) where it is required to comply with applicable law.
Revoking access and deletion
- You can revoke Fidkeep's access to your Google account at any time on the Google Account permissions page, or remove the Google connection from within the application.
- When access is revoked, new synchronisation and publishing stop and the OAuth tokens are deleted.
- Revoking access does not by itself delete data already synchronised into your workspace. You can request deletion of this data by writing to [email protected] or through the Data Subject Request Form. Synchronised review and reply data and AI drafts are deleted within 90 days of the disconnection of the relevant location if you so request, and in any event within 90 days of account closure.
Before using Google user data for any new purpose other than those described in this section, we will inform you and obtain your consent.
6. AI processing
Fidkeep uses language models from third-party AI providers for reply drafts, review topic and sentiment tagging, location setup suggestions, report narratives and structuring product feedback; the identity of the providers and models used is kept confidential by Fidkeep. Depending on the feature, the following is sent to the provider: business and location name and category, review rating and text, reviewer display name, the location's language and tone settings, preferred and prohibited phrases, signatures, example replies, instructions from an authorised user, the topic list for the location's industry and feedback text. Only the data needed for the task is sent; for example, for topic and sentiment tagging only the review text and rating and the topic list for the location's industry are sent.
Fidkeep does not use customer content to train its own models or any AI model. AI output can be wrong; human review before publishing is recommended. Topic and sentiment labels only classify the content of a review; they are not used to profile, score or classify individuals and have no legal effect on anyone. Smart rules are evaluated on a rule basis according to the conditions the customer sets; only the rules' topic condition uses AI-generated labels. Automatic replies are off by default and run only when an authorised user explicitly enables them. Details are set out in the AI Use Principles.
8. International transfers
Our application servers, primary database and backups are hosted by our cloud infrastructure provider operating from a data centre in Finland. Cloudflare, Google, our AI providers, Resend, Linear and Sentry may process data in the United States or on their global infrastructure. iyzico processes data in Türkiye.
Finland (EU) and the United States are not countries covered by an adequacy decision under KVKK. Transfers abroad therefore rely on the standard contracts announced by the Personal Data Protection Board under Article 9 KVKK as amended by Law No. 7499; standard contracts are notified to the Personal Data Protection Authority within five business days of signature. Where concluding a standard contract is not possible, we rely, on an occasional basis, on the exceptions in Article 9(6) (for example, where the transfer is necessary for the performance of a contract with the data subject).
9. Commercial electronic messages
Under Law No. 6563 on the Regulation of Electronic Commerce and the Regulation on Commercial Communication and Commercial Electronic Messages, commercial electronic messages may be sent to merchants and tradespeople without prior consent. Where the legislation requires prior consent, messages are sent only with your consent.
Every commercial message includes a free and easy way to opt out. You can also send your opt-out request to [email protected]. Consent and opt-out records are kept for 3 years after the consent ends.
Service messages such as account verification, password reset, invitation, security notice, invoice, report and smart-rule alert e-mails are not commercial electronic messages; they are sent for as long as your account is open. You can mute smart-rule alert e-mails with one click, for the rule concerned or for all smart-rule e-mails, using the link in each e-mail.
11. Retention periods
Personal data is kept for as long as necessary for the purpose for which it is processed and for the period required by the applicable legislation:
- Account and workspace data: for the contract term; after account closure, an export can be requested for 30 days; the data is then deleted or anonymised within 90 days of account closure.
- Google OAuth tokens: while the Google connection is active; deleted when the connection is removed, Google access is revoked or the account is closed.
- Synchronised Google review and reply data and AI drafts: for the contract term; deleted within 90 days of account closure (or of disconnecting the location, if the customer requests).
- AI operation records (model, token counts, cost, status, request identifiers): 12 months.
- Access, traffic and security logs: 2 years (Law No. 5651 and security requirements).
- Sentry error records: 90 days.
- Invoices, payment and accounting records: 10 years (Turkish Commercial Code Art. 82, Tax Procedure Law Art. 253).
- Support correspondence: 2 years after the request is closed.
- Data subject request records: 3 years after the request is concluded.
- Commercial message consent and opt-out records: 3 years after the consent ends.
- Google Analytics 4 data: 14 months.
- Cookie preference: 12 months; you are asked again when it expires.
- Backups: kept on a rolling basis and overwritten within 30 days.
When the period expires or the conditions for processing no longer exist, the data is deleted, destroyed or anonymised in accordance with Article 7 KVKK. Deleted data disappears from backups at the latest at the end of the 30-day period within which backups are overwritten.
12. Security
We apply the following technical and organisational measures to protect personal data:
- TLS encryption in transit; encryption of OAuth tokens at rest.
- Passwords stored only as salted hashes; HttpOnly and Secure session cookies.
- Role- and location-based access control; least-privilege internal access; secret management.
- Request validation and rate limiting; audit logs with sensitive fields redacted.
- Encrypted, regularly tested backups; error monitoring.
- Confidentiality obligations for personnel; vendor due diligence; an incident response procedure.
If a breach affects data for which we are the controller, we notify the Personal Data Protection Board within 72 hours and the affected data subjects as soon as reasonably possible, in accordance with Article 12(5) KVKK. If a breach affects data for which we are a processor, we notify the customer without undue delay and at the latest within 48 hours of becoming aware of it.
You are responsible for keeping your account credentials secure and for assigning appropriate roles in your workspace. If you suspect unauthorised access, notify [email protected] immediately.
13. Your rights
Rights under Article 11 KVKK
Under Article 11 KVKK you may apply to the data controller to:
- Learn whether your personal data is processed.
- Request information about the processing if it is processed.
- Learn the purpose of processing and whether the data is used in line with that purpose.
- Know the third parties in Türkiye or abroad to whom the data is transferred.
- Request rectification if the data is incomplete or inaccurate.
- Request erasure or destruction under the conditions of Article 7 KVKK.
- Request that rectification, erasure or destruction be notified to third parties to whom the data was transferred.
- Object to a result against you arising from analysis of the data exclusively by automated systems.
- Claim compensation for damage suffered due to unlawful processing.
Users in the EU/EEA
Where the EU General Data Protection Regulation (GDPR) applies, you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing; where processing is based on consent you may withdraw it, and you may lodge a complaint with the supervisory authority in your country of residence.
How to make a request
In accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller, you can submit your request through the Data Subject Request Form or directly by:
- A written application with a wet signature sent to our address above.
- A message to our KEP address [email protected], sent from your KEP address or signed with your secure electronic signature or mobile signature.
- An e-mail to [email protected] from an e-mail address you have previously notified to us and that is registered in our systems.
We conclude your request free of charge as soon as possible depending on its nature and within 30 days at the latest; if the action requires an additional cost, the fee in the tariff set by the Personal Data Protection Board may be charged. We may ask for additional information to verify your identity and, for requests concerning a workspace, your authority. If your request is rejected, you find the response insufficient, or no response is given in time, you may file a complaint with the Personal Data Protection Board under Article 14 KVKK.
You can update some of your profile and workspace information yourself within the application.
14. Children
Fidkeep is a business service and is not directed at persons under 18. You must be at least 18 years old to create an account and use the service. If you believe someone under 18 has provided us with personal data, notify [email protected]; we will investigate and delete the data.
15. Changes
We may update this policy to reflect changes in the service, our service providers or the legislation. The current version is published on this page with its effective date. We announce material changes to registered users by e-mail or in-app notice at least 30 days before they take effect.
16. Contact
For privacy questions, requests and complaints, write to [email protected]; formal notices can be sent to our KEP address [email protected] or to Sarıgüllük Mah. Ali Nadi Ünler Bul. Milenyum Apt. No: 3A, Şehitkamil / Gaziantep, Türkiye. Related documents: KVKK Privacy Notice, Cookie Policy, Subprocessors, Data Processing Agreement and Terms of Service.
