Platform Solutions Mobile Integrations Trust & Architecture Contact

CycleOps Mobile — Privacy Policy

The CycleOps Mobile application ("App") was developed by CycleOps AI and is designed for the Information Technology (IT) personnel of corporate customers to carry out management operations in the field. This Privacy Policy explains what data is processed when you use the App, for what purposes it is used, with whom it is shared, and your rights.

This policy has been prepared in compliance with the Personal Data Protection Law (KVKK — Law No: 6698), the Apple App Store Review Guidelines Privacy Disclosure requirements, and the Google Play User Data policy.

1. Data Controller

CycleOps Mobile operates in a multi-tenant architecture. Each corporate customer (tenant) runs an independent installation on its own server infrastructure. For this reason, the data controller is the organization the user works for (the entity it connects to via the "company code" entered in the App). CycleOps AI acts solely as the software provider and does not directly collect, store, or process user data.

Exception: The push token required to deliver notifications — the Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android — passes through CycleOps's Expo Push infrastructure (detailed below).

Contact:

2. Data Collected

2.1. Identity and Usage Data

DataDescriptionProcessing Purpose
UsernameActive Directory (AD) account nameLogging in to the corporate system
Display NameAD displayName fieldIdentifying the user in the interface
Profile PhotoAD thumbnailPhoto fieldAvatar display in the interface
Title / DepartmentAD title / departmentUser information in the interface

2.2. Device and Connection Data

DataDescriptionProcessing Purpose
Push TokenAPNs token (iOS) / FCM token (Android)Notification delivery
Device ModeliPhone / iPad or Android device model nameInventory in the admin panel
OS VersioniOS or Android operating system versionCompatibility check
App VersionCycleOps Mobile versionVersion-based support
Device NameName the user assigned to their deviceIdentification in the admin panel
Jailbreak / Root StatusWhether the device is jailbroken (iOS) or rooted (Android)Security policy enforcement
Last Seen TimeLast time the app was openedActive device tracking
Language PreferenceTR / ENSetting the notification language

2.3. Transaction and Approval Data

DataDescriptionProcessing Purpose
MFA Approval RequestsRDP / password reset / server access approvalsMulti-factor authentication
Request ApprovalsCorporate workflow approvalsAuthorization processes
Support TicketsTickets opened / commented onSupport management
IP Address (source)The IP from which the approved operation originatedAudit log + security tracking

2.4. Biometric Data

The App uses your device's biometric system — Touch ID / Face ID on iOS and BiometricPrompt (fingerprint / face unlock) on Android — to approve sensitive operations. Biometric data never leaves your device and is not sent to CycleOps servers. Only the local verification result (success/failure) is processed.

2.5. Camera

The App uses your camera for the "QR Scan" feature. Captured images are not stored and not sent to the server. Only the QR code content is processed locally.

3. Data Processing Purposes

4. Data Retention Period

5. Sharing with Third Parties

CycleOps Mobile does not share user data with third parties for commercial purposes. The following technical services are used:

ServicePurposeData
Apple Inc.Push Notification service (APNs) — iOS notification deliveryPush token, notification content
Google LLCFirebase Cloud Messaging (FCM) — Android notification deliveryPush token, notification content
Expo Inc.Push delivery infrastructurePush token, notification metadata
Cloudflare Inc.Tunnel + TLS certificateHTTPS connection encryption

Privacy policies of these services:

6. Data Security

7. User Rights (KVKK Article 11)

  1. Right to be informed — learning whether your personal data is being processed
  2. Right of access — requesting information about which of your data has been processed, if any
  3. Right to rectification — requesting correction of your incomplete or incorrectly processed data
  4. Right to erasure (Right to be Forgotten) — requesting deletion of your data
  5. Right to prevent transfer — objecting to the transfer of your data to third parties
  6. Objection to automated decision-making — objecting to decisions made through automated analysis

To exercise these rights:

8. Account Deletion

In line with Apple App Store Guidelines 5.1.1(v) and the Google Play account deletion requirements:

In-app account deletion: You can create a deletion request via Profile → "Delete My Account". This request:

  1. Automatically logs you out of the app
  2. Deletes your local device data (token + cache)
  3. Creates a support ticket with your organization's IT department

Direct corporate channel: By contacting the IT department of the organization you work for, you can request the deletion of all your data in the CycleOps system together with your Active Directory account.

CycleOps software provider channel: You can get support by writing to support@cycleops.ai.

The deletion process is completed within 30 days.

9. Children's Data

CycleOps Mobile is not an application aimed at children under 13. It is intended for corporate IT personnel. We do not knowingly collect data from users under 13.

10. International Data Transfer

Data is processed on customer servers in Turkey. The Apple Push Notification service, Firebase Cloud Messaging, and Expo Push infrastructure use international servers (EU and US). These transfers comply with KVKK Article 9 and GDPR Article 46 (Standard Contractual Clauses).

11. Policy Changes

12. Contact