Sign inFree AI Analysis

Legal

Privacy Policy and Data Protection Notice

Last updated: · Data controller: Ali Enes Keskin (YUEN Digital Agency)

This is an informational translation; the Turkish version is legally binding.

Frequently asked questions

What data does YUEN collect and how long is it kept?

Contact details, the portal account and performance data of the connected ad accounts. Personal data categories are kept for at most 24 months, invoices for 10 years (anonymised) as required by law; access tokens are deleted the moment a connection is removed.

Does YUEN sell client data or use it to train AI?

No. Data is never sold, never shared with third parties and never used to train general AI models. Google data is subject to the Limited Use requirements; only de-identified, aggregated statistics may be used to improve the service.

Ali Enes Keskin (YUEN Digital Agency) (“YUEN”, “we”) respects the privacy of our clients, platform users and website visitors. This text explains which data we collect, what we use the data obtained from your Google and Meta accounts for, how long we keep it, with whom we do not share it, and your rights. Section 10 is the disclosure notice under Turkish Law No. 6698 on the Protection of Personal Data (KVKK). In case of any discrepancy, the Turkish version prevails.

1. Data controller

  • Name: Ali Enes Keskin (YUEN Digital Agency)
  • Address: Sırakapılar Mah. Hastane Cad. Hulusi Kayaoğlu İşhanı No:17 İç Kapı No:3, Merkezefendi / Denizli, Türkiye
  • Tax office / no: Pamukkale Tax Office / 5460637343
  • Email: agencyyuen@gmail.com · Phone: +90 552 999 02 58 · Web: https://yuen.agency

2. Data we collect

a) Data you share with us directly

  • Contact details: full name, email address, phone number, company name, city.
  • Request content: information and attachments you provide in the quote / call form and in portal messages.
  • Billing details: legal name, tax office and number, billing address.
  • Portal records: orders, content approvals and comments, appointments, notification preferences, questions you type into the AI Help assistant.

b) Data we access as part of the service (Google and Meta)

As part of ads management and content services, with your explicit authorisation, we access data belonging to your Google and Meta accounts. Details in section 3.

c) Data collected automatically

  • Session and security logs: sign-in time, IP address, browser and device information.
  • Activity logs: who did what and when for every change made in the portal and panels (activity_log).

3. Google and Meta data

How we obtain it

  • Google Ads: through Google’s official OAuth 2.0 consent screen, with the adwords scope only. Your password never reaches us; the access token you grant is stored on the server encrypted with AES-256-GCM. Via the Google Ads API we read campaign, ad group, keyword, search-term and daily performance data; we write budget, status, negative-keyword and bid changes only on an active plan and with your assigned expert’s approval.
  • Google Drive: no client OAuth is used. A YUEN-owned service account (yuen-drive@yuen-platform.iam.gserviceaccount.com) sees only the folder you share, read-only (drive.readonly); it caches the file list for 10 minutes and transfers files only to show them to you in the portal and to publish content you approved. Access ends the moment you remove the share.
  • Meta (Facebook & Instagram): via Facebook Login for Business; ad account (ads_read, ads_management), Page (pages_show_list, pages_read_engagement, pages_manage_posts) and Instagram business account (instagram_basic, instagram_manage_insights, instagram_content_publish) permissions. Until Meta’s app review is complete, only reading and the publishing queue (no publishing) operate.

What we use it for

  • Reporting ad performance and generating recommendations with rules + AI (recommendations go through expert approval).
  • Publishing the content you approved to your Instagram / Facebook account at the scheduled time.
  • Showing the files in your Drive folder in the portal and linking them to the content calendar.
  • Measuring service quality (aggregated, non-personalised statistics).

Aggregated statistics: YUEN may use de-identified, aggregated statistics to improve the service and its recommendation rules; identifiable client data is never used for model training.

What we do not use it for

  • Transferring, selling or renting to third parties for advertising / marketing purposes.
  • Combining with other clients’ data or showing it to other clients beyond anonymous benchmarking.
  • Training AI models: data is sent to the model provider (Anthropic) only for the current answer; it is not used for training; the provider keeps it only briefly for security purposes and does not store it permanently.
  • Building credit, insurance or ad-targeting profiles.

Compliance with the Google API Services User Data Policy

YUEN Platform’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve user-facing features; we do not use it to serve advertising; we allow humans to read it only with your explicit consent, for security purposes or where required by law; we do not transfer it to third parties.

Compliance with the Meta Platform Terms

We process Meta data in accordance with the Meta Platform Terms and Developer Policies: only for the defined purpose, within the scope you permitted, stored encrypted; data deletion requests received from Meta are fulfilled through the process on the data deletion page.

4. Purposes and legal basis

  • Responding to your request and preparing a quote (formation of the contract).
  • Performing the contracted services: setting up, managing and reporting ad campaigns; producing content and submitting it for your approval; file sharing (performance of the contract).
  • Invoicing, accounting and tax obligations (legal obligation).
  • Information security, debugging and abuse prevention (legitimate interest).
  • Service information to free-plan users: based only on your own data, polite and infrequent; every email has an opt-out link (legitimate interest / explicit consent).

5. Retention periods

Client data and free-analysis visitor data are subject to different periods. Once you are a client, personal data categories are kept for at most 24 months. If you only requested a free analysis and did not become a client, the site address and email you gave us, together with the report produced from them, are kept for at most 6 months; once the report has been sent to you we have no reason to keep that data.

DataPeriodNote
Google / Meta access tokensImmediately when the connection is removedDeleted from the server and revoked on the platform side.
Ad metrics (campaign, keyword, search term)24 monthsOlder rows are deleted by the monthly clean-up job (1st of the month); all removed if the account is deleted.
Drive file-list cache10 minutesFiles themselves are not copied; the temporary copy for publishing is deleted within 1 hour.
Messages, attachments, content calendar, appointments24 monthsDeleted by the monthly clean-up job; all removed with account deletion.
AI analysis and chat records (clients)24 monthsNot stored permanently by the model provider.
Free analysis requests (site address, email, report)6 monthsNot client data; once the report has been sent there is no reason to keep it. Deleted by the monthly clean-up job.
Invoices and financial records10 yearsTurkish Tax Procedure Law; kept anonymised (separated from identity) after account deletion.
Session and activity logs24 monthsSecurity purposes; deleted by the monthly clean-up job.
Aggregated, de-identified statisticsIndefiniteAverage CTR/CPA/ROAS at sector × channel × month level; contains no client identity.

6. Who we share with, who we do not

We do not sell, rent or give your data to ad networks or data brokers; we do not share it with our other clients. We share it only with sub-processors strictly necessary to deliver the service, to the extent needed:

  • Supabase (database, authentication, file storage; EU / Frankfurt) — processor.
  • Vercel (application hosting) — processor.
  • Google (Ads API, Drive API) and Meta (Graph API) — the source of the data; changes we write are sent to these platforms.
  • Anthropic (Claude models) — only the data needed for the current request is sent for AI analyses and assistant answers; it is not used for training; the provider keeps it only briefly for security purposes and does not store it permanently.
  • Resend / SMTP provider — notification emails.
  • Accountant and competent public authorities — within legal obligations.

Where infrastructure providers’ servers are located abroad, transfers are made in accordance with Article 9 of the KVKK (standard contract / explicit consent).

7. Security

Access tokens encrypted with AES-256-GCM; data separated per client with row-level security (RLS); all business logic server-side; HTTPS; least-privilege principle; service-account method for Drive; weekly backups (daily as we grow; kept 8 weeks); access and change logs. Details: Security & access.

8. Cookies

Strictly necessary cookies are always used. Analytics and marketing cookies load only if you consent in the cookie banner; your choice is stored for 12 months and can be changed any time via the “Cookie settings” link in the footer. No analytics or marketing script runs before consent (Google Consent Mode v2 default: “denied”).

CookiePurposeCategoryDuration
sb-*-auth-token (Supabase)Keeps your session signed inNecessary
yuen-dil, yuen-dil-oneriLanguage preference and dismissed language suggestionNecessary
yuen-paraDisplay currency preference (₺/$/€)Necessary
yuen-cerezYour cookie consent (analytics / marketing choice)Necessary
_ga, _ga_* (Google Analytics 4)Anonymous visit statisticsAnalytics
_gcl_au, _gcl_aw (Google Ads)Ad conversion measurement and remarketingMarketing
_fbp, _fbc (Meta Pixel)Ad conversion measurement and remarketingMarketing

Analytics and marketing cookies are used only on the public site and the client portal; personal data such as e-mail addresses are hashed (SHA-256) server-side before transmission. There is no tracking in the expert and admin panels.

9. Deletion and access revocation

  • Remove access (instant): Portal → Connections. The token is deleted and revoked on the Google / Meta side.
  • Delete my account (30 days): Portal → My account. Can be undone within 30 days; when the period ends all data is deleted and invoices are kept anonymised.
  • By email: agencyyuen@gmail.com — completed within 30 days at most.
  • Step-by-step instructions: /en/veri-silme.

10. Data Protection Notice (KVKK)

Pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data, Ali Enes Keskin (YUEN Digital Agency), as data controller, informs you about how your personal data is processed.

Categories of personal data processed

  • Identity: first and last name.
  • Contact: email, phone, address.
  • Customer transactions: request and complaint records, order and service history, messages, content approvals.
  • Finance: billing information, payment records.
  • Marketing / service data: performance data of the ad accounts you connected.
  • Transaction security: IP address, sign-in and activity logs.

Collection method and legal basis

Data is collected electronically through website forms, the portal, email, phone, WhatsApp and in-person meetings, and through the Google and Meta APIs with your explicit authorisation. Legal bases: Art. 5/2-c formation or performance of a contract, Art. 5/2-ç legal obligation, Art. 5/2-f legitimate interest; where none applies, your explicit consent (Art. 5/1).

Transfers

Transferred, limited to the processing purpose, to the sub-processors in section 6 and, upon request, to competent public authorities. International transfers comply with Article 9 of the Law.

Your rights (Art. 11)

  • To learn whether your personal data is processed and to request information about it.
  • To learn the purpose of processing and whether it is used in line with that purpose.
  • To know the third parties to whom it is transferred, domestically or abroad.
  • To request correction if incomplete or incorrect; to request erasure or destruction under the conditions of the Law, and notification of these actions to third parties.
  • To object to a result against you arising from analysis exclusively by automated systems (AI recommendations go through expert approval; there is no automated decision).
  • To claim compensation for damage caused by unlawful processing.

Applications

You may submit your requests, together with information verifying your identity, by email to agencyyuen@gmail.com or in writing to Sırakapılar Mah. Hastane Cad. Hulusi Kayaoğlu İşhanı No:17 İç Kapı No:3, Merkezefendi / Denizli, Türkiye. Requests are concluded free of charge within thirty days at the latest.

11. Changes and contact

We may update this text; the current version is always published on this page with the last-updated date in the header. For material changes we notify portal users by email. Questions: agencyyuen@gmail.com.