Privacy Policy
Version 5 · published 17 September 2026
1. Why this document exists
This policy describes, in ordinary language, what YASAD Connect knows about you, where that information sits, who else can see it and how long it stays. If you are in the European Economic Area, the companion GDPR Information Notice sets out the same processing in the terms Regulation (EU) 2016/679 requires, including your rights and the lawful basis for each purpose.
We have written this from the system as it is built, not from a template. Where the product does not do something you might reasonably expect it to do, this text says so.
2. Who runs the service
Yazılım Sanayicileri Derneği (YASAD), of [YASAD postal address], Türkiye, decides what is collected and why. Its site is yasad.org.tr.
Internative (internative.net) builds, hosts and operates the application for YASAD, voluntarily and at no charge, and acts on the association's instructions. Internative also holds a seat on YASAD's audit board (denetim kurulu); we disclose that rather than obscure it. The iOS listing is published under an Apple Developer account belonging to Internative Yazılım A.Ş.
3. What we hold
From the group roster, supplied by YASAD before you ever open the application: your email address, and typically your name, your company, the matchmaking group you were invited into and the tag the organiser filed you under. This is how an invitation-only product works, and it means we hold your address before you have used the service.
From your account: every email address you attach and whether it has been verified, your account status, and the sign-in records the service needs to work.
From your profile, as you fill it in: name, title, biography, photo, LinkedIn address, interests, topics, your mobile number, your landline and its extension if you supply them, and your company details including its logo. Everything beyond the roster fields is optional.
From your use of the service: connection requests and connections, blocks you have placed, messages, meetings and their notes, your notification settings, and any support request you send YASAD from inside the application — its text, when you sent it, and the answer an administrator writes back. If your account has been suspended, the date and the reason the operator wrote are held on it too.
From a report somebody files about you, or that you file about somebody: the reason chosen, the reporter's own account of what happened, and a snapshot of how the reported profile read at that moment — the name, title, company or sector, image address and the groups the two parties shared — frozen so that a later edit cannot rewrite the record. Then the outcome: the decision, who made it, when, and the operator's note on it. No message thread is attached to a report, and the system has no field for one.
From the administration panel, about the people who run it: every write an administrator makes and every sign-in to the panel is recorded — who did it, what kind of action, which record, the fields that changed with their before and after values, the request and its result, and the administrator's IP address. Which fields may be recorded is fixed by a closed list in the code: message content, conversation content, a meeting's private note, an organiser's notes on a roster and your own profile fields are not on it and never enter the record. You appear in it only as the subject of what an administrator did.
A deletion request, if you make one: the day you asked, the day it is set to complete, what became of it — scheduled, cancelled or completed — the dates of those, and the reason you wrote if you chose to write one. That record is kept after the deletion completes; section 8 says why.
A calendar link, if you ask for one: when you add an accepted meeting to your own calendar without granting the calendar permission, a ten-minute token is held in the cache, knowing only which meeting it is for and which account asked.
A share link, if you mint one: a 24-hour token in the cache, knowing only which card — yours, or a company you belong to — it was made for.
A contact-export link, if you ask for one: a ten-minute token in the cache, knowing which member's card it is for and which account asked, because whether the file may carry a telephone number depends on who is reading it.
Nothing from your device's calendar or address book. If you grant the calendar permission, the application reads and writes calendar entries on the phone; none of that reaches our server and none of it is stored. Exporting a card to your contacts asks for no address-book permission at all.
Technical records: web-server access logs containing your IP address, the request and the time; rate-limiting counters; a short-lived count of failed sign-in attempts from your connection, and the temporary block that follows a sustained run of them — both of which hold your IP address (for IPv6, your address block) and nothing about which account was being tried; and the device token the push service needs to reach your phone.
Bot protection on the administration panel: the panel's sign-in screen runs Cloudflare Turnstile. Opening that screen connects your browser directly to Cloudflare, which discloses your IP address, your user agent and automatic signals about how the browser behaves; our server then asks Cloudflare to verify the one-time token the widget produced. This runs only on the administration panel's sign-in screen — the mobile application does not use it, so a member never meets it.
We do not ask for, and the product has no field for, financial details, identity-document numbers or any special category of data.
4. What we do with it
- Give you an account, sign you in and keep the session alive.
- Show you the people, companies and content of the matchmaking groups you belong to — and only those.
- Rank and suggest members you might usefully meet.
- Carry your messages, connection requests and meetings, and remind you about them.
- Send the operational emails the service depends on: your one-time sign-in code, invitations, and meeting notices.
- Let you export an accepted meeting to your own calendar when you ask for it.
- Let you show your own card, or your company's, to somebody outside the product through a short-lived link you create.
- Let you export another member's card into your own address book, with their telephone numbers and email address only where they have opted in and you are connected.
- Read and answer the support requests you send us from inside the application.
- Read reports members file about each other, decide them, and act on the decision — which may mean suspending an account and telling its holder why.
- Record what administrators do in the panel, so that the use of that authority can be shown afterwards.
- Keep the service secure and available: rate limiting, abuse investigation, and diagnosing faults.
- Meet YASAD's own legal and record-keeping obligations.
We do not sell your data, we do not rent it, and we run no advertising in this product.
5. Who can see what
Other members of your groups see your name, title, biography, LinkedIn address, photo, interests, topics, primary company, the groups you share, the tag the association gave you in each of those groups (investor, attendee, exhibitor, for instance) and your connection status. No screen shows them your email address or your telephone numbers, and the only route by which those can reach another member is the contact export in section 10 — which needs your own opt-in, off by default, *and* an accepted connection.
Members outside your groups see nothing about you at all.
Nobody sees you while a deletion is scheduled. From the moment you ask to delete your account until the thirty days are up, you are absent from every one of those screens — the same rule, in the same place, that hides a member of no shared group. It is a change of visibility and not of storage: nothing has been deleted yet, and cancelling puts you back exactly as you were. Section 8 covers what happens when the thirty days run out.
Anyone holding a share link you created sees a deliberately reduced card and nothing else: your name, your title, your company's name and your photo — or, for a company card, its name, logo, sector, city, country and website. Not your biography, not your interests or topics, not your LinkedIn address, not the groups you are in, and not your telephone numbers or email address. The link lasts 24 hours, is published nowhere and is served with instructions to search engines not to index it. Only you can create one about you, and it stops working if your account is suspended or deleted.
YASAD administrators see your identity, every email address linked to your account and whether it is verified, your group memberships, your companies, your connections, and your meetings — status, type, time, place, participants and group, but not the private note attached to a meeting. No screen in the administration panel shows the content of a message or a conversation.
The one thing administrators do read in full is a support request you send from inside the application, together with your name — you addressed it to the association, so it is shown in the panel and answered there. That is not a message to another member, and the rule above is unchanged for those.
The same reasoning covers a report: what a member writes to the association about you was written to the association, so an operator reads it. Filing one still opens no conversation — no thread travels with it. You are not told who reported you, and the reporter is not shown the operator's note.
Administrators are watched too. Every write in the panel and every sign-in to it is recorded against the operator who did it, in a row nobody can edit afterwards. That record exists to show how the authority was used; it gives an operator nothing they could not already see.
6. Who else processes your data for us
- Cloudflare R2 stores profile photos and company logos, in a private bucket. Nothing else is kept there.
- Cloudflare Turnstile protects the administration panel's sign-in screen from automated sign-in attempts. It is a separate service from R2 and a separate disclosure: the browser opening that screen talks to Cloudflare directly, handing over its IP address, user agent and behavioural signals, and our server asks Cloudflare whether the resulting one-time token is genuine. We rely on our legitimate interest in a sign-in screen that is not open to bots. It does not run in the mobile application.
- OneSignal delivers push notifications. It receives your account identifier, your device's push token and the notification itself — and the notification carries the sender's full name and up to 140 characters of the message text. OneSignal is a United States provider, and it hands the message on to Apple or to Google to reach your device. If you would rather that text did not travel that way, turn notifications off for the application in your device settings; the service still works, and the message still arrives in the app.
- Google Fonts serves the typefaces the mobile application uses. Your device fetches them from Google's servers while the app runs, which discloses your IP address and user agent to Google.
- Google Maps draws the map you pick a meeting venue or a company address on. Opening it discloses your device's IP address to Google along with the map requests. Google's own published disclosure for this SDK says it also collects crash records, performance measurements, in-app interaction data and a device identifier, for analytics — none of which reaches us or is available to us — and states that none of it is used for tracking. The same disclosure does not list location data: the permission the map asks for, so it can draw where you are, stays on your device. Turning the point you picked into a street address is done by your operating system's own geocoder, not by us.
- Email is not handled by any third-party provider. Our messages leave through YASAD's own mail server at mail.yasad.org.tr, under the association's own address.
7. Where your data lives
The service runs on a single rented server operated by Contabo, physically located in London, United Kingdom. The database and the cache run on that same machine, reachable only from the machine itself. The web server in front of them keeps access logs, including your real IP address, for 30 days, and then deletes them.
Because YASAD is established in Türkiye, association staff administering the service work with your data from Türkiye.
Two things leave that machine by design: the images in Cloudflare R2, and — for whoever opens the administration panel's sign-in screen — the IP address and browser signals Turnstile discloses to Cloudflare. Cloudflare runs a global network, so the country in which that request is answered depends on where the visitor is.
8. How long we keep it
We would rather tell you the truth here than a comfortable version of it.
There is no automatic expiry on the main data. Your account, your profile, your messages, your connections, your meetings, your support requests and the reports filed about or by you — decided ones included — are kept until somebody removes them by hand. Nothing about you in the database deletes itself with age.
What ends that is you deleting your account, and you can do it from inside the application. The request sets a date thirty days out; until that date nothing is destroyed, you are invisible to other members, and you can cancel. On that date the deletion completes and cannot be reversed: your profile, your privacy and notification preferences, the email addresses on your account and your group memberships are removed from the platform. What outlives it is short and deliberate — messages already delivered, which live in the other person's conversation and are that person's record too; your acceptances of these texts, which are the proof of what you agreed to; records needed for a legal claim or required by law; and the deletion request itself, which is how the association can show a deletion was asked for and honoured. The request record is therefore kept after the account is gone, carrying the dates and the reason you wrote if you wrote one.
Six things do expire on their own: your one-time sign-in code, after 10 minutes; a calendar link, after 10 minutes; a contact-export link, after 10 minutes; a share link, after 24 hours; a session's access token, after 15 minutes; and the token that renews a session, after 30 days. Web-server access logs are kept 30 days, as above.
Nothing at all is kept from your device's calendar, because nothing is ever collected from it — with the permission granted, that reading happens on your phone and never reaches us.
One record deletes itself purely with age, and it is not about you. The administrative audit log — every write in the panel and every sign-in to it — is kept for 730 days, that is 24 months, and the database removes each row when its own two years are up. A scheduled account deletion also runs off a clock, but that clock is one you started. The period is a constant in the code, not a setting somebody can quietly change on the server.
Those two periods, 30 days and 24 months, are not a contradiction, because they cover different records. The access log holds every request, and therefore every member's IP address, and it is gone after 30 days. The audit log holds only what administrators did, and the IP address in one of its rows is the administrator's. A member's IP address never enters the 24-month record. You appear in it only as the subject of an administrator's action, through the fields that action's closed list allows — your email address as the label, say, and the account status that changed.
The brute-force defence keeps two more, and both are short. A count of failed sign-in attempts from one connection lives at most 10 minutes, and is deleted the moment anyone at that connection signs in successfully. If the count crosses its threshold, the temporary block it opens clears itself after 15 minutes — further attempts do not extend it. Neither record names an account or an email address.
The bot-protection token is not stored at all. To stop the same token being presented twice we keep only an irreversible hash of it, in the cache, for 5 minutes — after which it removes itself. What Cloudflare retains on its own side is governed by Cloudflare's policies, not ours.
One consequence is worth stating plainly: when an outgoing email fails to send, the failed job is retained for inspection, and it still holds the message body it was going to send — which for a sign-in email includes the one-time code. Those codes are useless after 10 minutes, but the record is not automatically cleared.
9. How it is protected
Traffic between your device and the service is encrypted in transit. The database and the cache accept connections only from the server itself. Sign-in is by one-time code, so there is no password to steal, guess or reuse. Access to the group data you are entitled to is checked on the server for every request. The administration panel's sign-in screen additionally runs a bot check, and its result is verified on our server rather than taken on the browser's word — a token counts once and never again.
Some limits deserve to be named rather than buried. Messages are not end-to-end encrypted — they are readable on the server by someone with database access, even though no administrative screen displays them. And four kinds of web address in this product open without signing in, each unguessable, each published nowhere, and each protected by nothing except whose hands it ends up in:
- A profile photo or company logo, once uploaded, can be opened by anyone holding its long random address. It does not expire, and the image itself is not group-scoped.
- The calendar link you can mint for an accepted meeting works the same way for ten minutes. It carries the meeting's time, its place if one was given, and the other participant's name — never the private note and never an email address — and it stops working when the ten minutes are up.
- The contact-export link for another member's card lasts ten minutes and carries what section 10 describes, including their telephone numbers and email address where they have opted in and you are connected.
- The share link you mint for your own card lasts 24 hours and carries the reduced card described in section 5.
10. What you control
- Your profile. Everything past the roster fields is optional, and you can edit or empty it at any time.
- Your email addresses. You may add another address or ask for one to be removed.
- Notifications. The settings screen divides them into nine categories — announcements, connections, meetings, meeting reminders, messages, company requests, group membership, support, and moderation (reports you filed, and anything done to your own account). Each carries its own push switch and its own email switch: eighteen in all. Every one of them starts on, which is worth stating because it means a member who has never opened that screen is receiving everything. You can also turn push off for the application in your device settings, without losing the messages themselves.
- Your contact details. A single switch, in privacy settings, decides whether a member you are connected to may export your telephone numbers and your primary email address into their own address book. It is off by default — it is the one setting here that opens something rather than closing it, so leaving it alone means those details reach nobody. Turning it off again stops future exports; it cannot reach into an address book somebody already saved.
- Your calendar. The permission that lets the application write meetings into your device calendar is granted and withdrawn in your operating system's settings. Nothing it reads is ever sent to us. Withdraw it and the application falls back to the ten-minute calendar link.
- Share links. You create them, one at a time, and each dies after 24 hours. Nobody else can create one about you.
- Blocking. Block another member and each of you leaves the other's screens, any accepted meeting between you is cancelled and its reminders stop. They are not told, you are not told when somebody blocks you, and only the person who placed a block can lift it.
- Reporting. You can report a member or a company to YASAD. What you write is your own statement; no part of your conversation is attached, and the person you report is never told it was you.
- Your groups. Membership follows YASAD's rosters; ask the association if you believe you are in the wrong group.
- Your account itself. You can delete it from inside the application, without writing to anybody. It takes effect in thirty days, you are hidden from other members for all of them, nothing is destroyed until the last one, and you can cancel at any point in between — including by signing in, which stays possible for exactly that purpose. After that it is permanent. Section 8 lists what survives it.
11. Your rights, and how to use them
You may ask what we hold about you, ask us to correct it, ask us to delete it, and object to some of our processing. If you are in the EEA, the GDPR Information Notice explains those rights and their limits precisely.
Deleting your account is the one you do not have to ask for: it is in the application, and section 10 describes how it runs. There is still no self-service export, and that is not a way of refusing you — it means a person handles the request. Write to connect@yasad.org.tr for that, or for anything narrower than your whole account, and we will answer within one month.
12. Children
YASAD Connect is a professional service for adults. It is not designed for and must not be used by anyone under 18.
13. Changes
Every version of this policy is kept, numbered and dated. When a materially new version is published you will be asked to read it the next time you open the application, and we record which version you saw and when.
14. Contact
Write to connect@yasad.org.tr, or to Yazılım Sanayicileri Derneği, [YASAD postal address], Türkiye.