CycleOps Mobile — Privacy Policy
The CycleOps Mobile application ("App") was developed by CycleOps AI and is designed for the Information Technology (IT) personnel of corporate customers to carry out management operations in the field. This Privacy Policy explains what data is processed when you use the App, for what purposes it is used, with whom it is shared, and your rights.
This policy has been prepared in compliance with the Personal Data Protection Law (KVKK — Law No: 6698), the Apple App Store Review Guidelines Privacy Disclosure requirements, and the Google Play User Data policy.
1. Data Controller
CycleOps Mobile operates in a multi-tenant architecture. Each corporate customer (tenant) runs an independent installation on its own server infrastructure. For this reason, the data controller is the organization the user works for (the entity it connects to via the "company code" entered in the App). CycleOps AI acts solely as the software provider and does not directly collect, store, or process user data.
Exception: The push token required to deliver notifications — the Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android — passes through CycleOps's Expo Push infrastructure (detailed below).
Contact:
- Email: support@cycleops.ai
- Web: https://cycleops.ai
2. Data Collected
2.1. Identity and Usage Data
| Data | Description | Processing Purpose |
|---|---|---|
| Username | Active Directory (AD) account name | Logging in to the corporate system |
| Display Name | AD displayName field | Identifying the user in the interface |
| Profile Photo | AD thumbnailPhoto field | Avatar display in the interface |
| Title / Department | AD title / department | User information in the interface |
2.2. Device and Connection Data
| Data | Description | Processing Purpose |
|---|---|---|
| Push Token | APNs token (iOS) / FCM token (Android) | Notification delivery |
| Device Model | iPhone / iPad or Android device model name | Inventory in the admin panel |
| OS Version | iOS or Android operating system version | Compatibility check |
| App Version | CycleOps Mobile version | Version-based support |
| Device Name | Name the user assigned to their device | Identification in the admin panel |
| Jailbreak / Root Status | Whether the device is jailbroken (iOS) or rooted (Android) | Security policy enforcement |
| Last Seen Time | Last time the app was opened | Active device tracking |
| Language Preference | TR / EN | Setting the notification language |
2.3. Transaction and Approval Data
| Data | Description | Processing Purpose |
|---|---|---|
| MFA Approval Requests | RDP / password reset / server access approvals | Multi-factor authentication |
| Request Approvals | Corporate workflow approvals | Authorization processes |
| Support Tickets | Tickets opened / commented on | Support management |
| IP Address (source) | The IP from which the approved operation originated | Audit log + security tracking |
2.4. Biometric Data
The App uses your device's biometric system — Touch ID / Face ID on iOS and BiometricPrompt (fingerprint / face unlock) on Android — to approve sensitive operations. Biometric data never leaves your device and is not sent to CycleOps servers. Only the local verification result (success/failure) is processed.
2.5. Camera
The App uses your camera for the "QR Scan" feature. Captured images are not stored and not sent to the server. Only the QR code content is processed locally.
3. Data Processing Purposes
- Secure login to corporate systems (authentication)
- Multi-factor authentication (MFA) — approving sensitive operations such as RDP and password resets
- Delivering approval requests via push notifications
- Corporate workflow approvals (request management)
- Opening and tracking support tickets
- Device inventory management
- Keeping an audit log (audit trail) — KVKK Article 12 compliance
4. Data Retention Period
- Push token, device metadata: Retained until the user deletes the app or the account is closed.
- MFA approval records: Retained for 2 years in the audit log.
- Support tickets: Retained for 5 years after closure (legal obligation).
- Session (JWT) token: Stored in device memory; deleted on logout.
- AD profile photo / display_name: Kept encrypted in the device's local cache (AsyncStorage); deleted when the user logs out.
5. Sharing with Third Parties
CycleOps Mobile does not share user data with third parties for commercial purposes. The following technical services are used:
| Service | Purpose | Data |
|---|---|---|
| Apple Inc. | Push Notification service (APNs) — iOS notification delivery | Push token, notification content |
| Google LLC | Firebase Cloud Messaging (FCM) — Android notification delivery | Push token, notification content |
| Expo Inc. | Push delivery infrastructure | Push token, notification metadata |
| Cloudflare Inc. | Tunnel + TLS certificate | HTTPS connection encryption |
Privacy policies of these services:
- Apple: https://www.apple.com/legal/privacy/
- Google: https://policies.google.com/privacy
- Expo: https://expo.dev/privacy
- Cloudflare: https://www.cloudflare.com/privacypolicy/
6. Data Security
- All server communication is encrypted with TLS 1.2+
- Passwords are hashed with bcrypt and are never stored in plain text
- JWT tokens are signed with HS256/RS256
- Biometric approval is mandatory for sensitive operations
- Hash-based opaque URLs are used for AD profile photo access (enumeration protection)
- When a jailbroken (iOS) or rooted (Android) device is detected, access may be restricted in line with corporate policy
- DMZ topology: Mobile app internet → DMZ Portal → Internal network (one-way trust)
7. User Rights (KVKK Article 11)
- Right to be informed — learning whether your personal data is being processed
- Right of access — requesting information about which of your data has been processed, if any
- Right to rectification — requesting correction of your incomplete or incorrectly processed data
- Right to erasure (Right to be Forgotten) — requesting deletion of your data
- Right to prevent transfer — objecting to the transfer of your data to third parties
- Objection to automated decision-making — objecting to decisions made through automated analysis
To exercise these rights:
- The organization you work for: Contact your corporate IT department
- CycleOps software-related: support@cycleops.ai
8. Account Deletion
In line with Apple App Store Guidelines 5.1.1(v) and the Google Play account deletion requirements:
In-app account deletion: You can create a deletion request via Profile → "Delete My Account". This request:
- Automatically logs you out of the app
- Deletes your local device data (token + cache)
- Creates a support ticket with your organization's IT department
Direct corporate channel: By contacting the IT department of the organization you work for, you can request the deletion of all your data in the CycleOps system together with your Active Directory account.
CycleOps software provider channel: You can get support by writing to support@cycleops.ai.
The deletion process is completed within 30 days.
9. Children's Data
CycleOps Mobile is not an application aimed at children under 13. It is intended for corporate IT personnel. We do not knowingly collect data from users under 13.
10. International Data Transfer
Data is processed on customer servers in Turkey. The Apple Push Notification service, Firebase Cloud Messaging, and Expo Push infrastructure use international servers (EU and US). These transfers comply with KVKK Article 9 and GDPR Article 46 (Standard Contractual Clauses).
11. Policy Changes
- Announced via in-app notification
- The current version is kept at https://cycleops.ai/privacy
- The effective date changes with each update
12. Contact
- Email: support@cycleops.ai
- Web: https://cycleops.ai