Privacy and Personal Data Protection Policy

Effective date: 18 August 2026

1.1. Scope and data controller

Performance Intelligence is a software service developed under the Dreavion Technology brand that helps businesses view and report their performance data from different advertising, analytics, search and other supported platforms in a single environment.

This policy explains the framework within which personal data is processed for authorized users of the Performance Intelligence platform, people who contact Dreavion Technology, and visitors to the dreaviontechnology.com corporate website.

Job candidates who apply through the careers pages are outside the scope of this policy. A separate Candidate Privacy Notice is published for them.

Official company and data controller information: Dreavion Teknoloji Sanayi ve Ticaret Limited Şirketi. Istanbul Trade Registry Office, registry no 1154612. MERSİS no 0313155054000001. Zincirlikuyu Tax Office, tax identification no 3131550540. Address: Emniyet Evleri Mah. Eski Büyükdere Cad. Sapphire No: 1/1, İç Kapı No: 1B04, Kağıthane / İstanbul. Privacy and data protection contact: info@dreaviontechnology.com

1.2. How does Performance Intelligence work?

Performance Intelligence retrieves performance data from third party platforms the user has authorized, processes it on the server side, and presents it to the user through the platform interface and reports.

The product's core integration approach is read only. Performance Intelligence is not designed to create ads, change ad or campaign settings, update budgets and bids, or write operational data to connected platforms on the user's behalf in supported integrations.

The supported platforms and the types of data retrieved from them may change as the product develops. When a new integration is added, the principle is to use only the data and permissions required to deliver that specific feature.

1.3. Categories of data we process

A. Account and authorization data. Name and surname, email address, in-account role, the customer or workspace the user belongs to, membership and authorization information, and the technical information required to run the session may be processed.

B. Integration and connection data. When a user connects a third party platform, the connection status, source information such as the selected account, property or ad account, the required permission information, and the access credentials needed for the connection to work may be processed. OAuth or similar access credentials are processed on the server side in line with the product's technical architecture and are protected against access. These credentials are not displayed in plain text in the ordinary user interface.

C. Performance and reporting data. Impressions, clicks, cost and spend, traffic, sessions, channels, campaigns, pages, search queries, location, device and similar performance data may be retrieved from connected platforms. A significant part of this data consists of aggregated performance measurements. That said, search queries, URLs, page names or free text fields coming from third party platforms may contain information that qualifies as personal data, depending on the content at the source.

D. Form and lead data transferred into the system by the customer. When the customer uses the form or lead features of Performance Intelligence, name and surname, email, phone and other information contained in the form may be transferred into the system. As a rule, the relevant customer determines the purpose for which this data is collected and the legal basis on which it is processed. The customer is responsible for meeting the required disclosure and other data protection obligations for its own collection activity.

E. Notification and report delivery data. When Telegram or other notification channels that may be supported in future are used, the channel and chat identifier, notification preferences, delivery status, and error and transaction records may be processed.

F. Technical, security and usage data. Session information, request and error logs, synchronization records, security events, report download records, and technical connection data including IP address for the purpose of preventing abuse may be processed.

1.4. For what purposes do we process data?

Depending on the specific processing activity, personal data may be processed for the following purposes: setting up and delivering the service and managing user accounts, verifying user and customer permissions, establishing and maintaining third party platform connections, and retrieving, storing, displaying and reporting performance data.

It may also be processed to create, store and deliver reports through the channels the user selects, to ensure information security, to prevent abuse and unauthorized access, for error analysis, technical support and service continuity, to improve the functions offered to the user, and to fulfil legal obligations and to establish, exercise or protect rights.

1.5. What we do not do

We do not use user or integration data obtained through Performance Intelligence for data brokerage, we do not sell it to third parties, and we do not use it for targeting on third party advertising networks.

We do not use customer data to train artificial intelligence or machine learning models, whether Dreavion Technology's own or those of third parties.

1.6. Use of Google API data

Data accessed through Google APIs is used solely to provide or improve the Performance Intelligence features the user explicitly uses.

Performance Intelligence's use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.

User data accessed through Google APIs is not read by humans. The exceptions are the user's explicit consent, reviews carried out for security purposes, the fulfilment of legal obligations, and data that has been aggregated and anonymized.

Google API data is not used for advertising targeting, is not sold, and is not used to train artificial intelligence or machine learning models.

Data accessed through Google APIs and stored persistently within Performance Intelligence is held in database and storage services hosted in the Frankfurt location in the European Union region on the current production infrastructure. Access and refresh tokens for Google accounts are stored in encrypted form. Customer data is logically separated on a tenant basis and is used only in that customer's dashboard, analyzes and generated reports. Infrastructure providers and data processing roles are described separately in the Sub-processors and External Platforms List.

1.7. Meta and other connected platforms

On Meta, Google and other supported platforms, only the permissions required for the reporting and monitoring functions the product offers to the user are requested.

When the Meta Ads integration is used, the purpose of Performance Intelligence is to retrieve performance data from the ad account on a read only basis and report it to the user. The connected platforms' own terms, permission models and privacy practices apply in addition.

1.8. Parties with whom data is shared

In order to deliver the service, data sharing or data access may occur with the following groups of recipients, only to the extent necessary: application hosting, database, authentication and file storage providers, corporate website infrastructure providers, the advertising, analytics, search, e-commerce, marketplace and other external platforms the customer connects at its own request, the notification and messaging services the customer selects, legal, financial or technical advisors, and public institutions and organizations authorized by law.

The current list of infrastructure and external platforms is published on the Sub-processors and External Platforms List page.

1.9. Transfer of data abroad

Some of the infrastructure providers we use, or the external platforms the customer connects, may result in personal data being processed outside Türkiye or transferred abroad.

Where personal data is transferred abroad, the transfer must rely on an applicable transfer mechanism under Article 9 of Law no. 6698 on the Protection of Personal Data and the related secondary legislation.

Transfer mechanism and appropriate safeguard: the applicable mechanism under Article 9 will be announced in this section once infrastructure agreements and data flows are settled.

1.10. Retention periods

We keep personal data limited to the period necessary for the purpose of processing and the periods required by applicable legislation. The same retention period does not apply to every category of data.

Account and authorization data: kept for as long as the account relationship continues and throughout the statutory limitation periods following closure of the account.

Connection access tokens: when the user disconnects the relevant platform, the access credential held by Dreavion is removed.

Performance and reporting data: kept for as long as the account relationship continues, and assessed under a data deletion request when the account is closed.

Report files: kept accessible for the period stated in the customer's plan and removed from active report storage at the end of that period. Current periods are stated within the product and in the plan terms.

Technical and security records: kept for the period required by the purposes of security, auditing and preventing abuse.

Support and contact correspondence: kept for as long as necessary after the relationship ends, taking applicable limitation periods into account.

Disconnecting a platform does not mean that performance data previously retrieved from that platform is automatically deleted. The user or the authorized customer may submit a separate data deletion request.

Limited records that must be kept for security, auditing, dispute resolution and legal obligations may be retained for as long as necessary for that purpose. Some data deleted from active systems may remain for a limited period in the infrastructure providers' technical backups until ordinary backup and rotation processes complete. This does not mean that deleted data is accessible again for ordinary use of the product.

1.11. Security

We apply technical and administrative measures to protect personal data against unauthorized access, unlawful processing, loss or disclosure. These measures may include controls such as access control, authorization, encryption, tenant and customer separation, dedicated storage areas, and logging and monitoring mechanisms.

No information system can guarantee absolute security. Security measures are reviewed taking risks, product architecture and applicable obligations into account.

1.12. Data breach notification

Where it is established that personal data has been unlawfully obtained by others, the situation is reported to the Personal Data Protection Board as soon as possible and in any case within seventy-two hours of that determination.

The data subjects affected by the breach are informed as soon as reasonably possible and by an appropriate method.

Where Dreavion Technology acts as a data processor, the breach is reported to the relevant customer without delay and reasonable support is provided so that the customer can meet its own notification obligations.

If you have identified a security vulnerability or a possible breach, you can report it to info@dreaviontechnology.com

1.13. Disconnecting and data deletion

Removing a third party platform connection stops future data synchronization for that platform and causes the connection credentials held by Dreavion to be removed. This action does not automatically delete all historical performance data or reports created earlier.

For the scope of data deletion and account closure requests, see the Data Deletion and Account Closure Instructions page.

1.14. Data subject rights

The rights under Law no. 6698 and the procedures for exercising them are explained in the Data Protection Disclosure Notice.

1.15. Automated decision making

Performance Intelligence does not produce decisions taken solely by automated systems that produce legal effects concerning data subjects or similarly significantly affect them.

1.16. Cookies and similar technologies

The Cookies and Similar Technologies Policy applies to the mandatory session cookies and browser storage technologies used in the Performance Intelligence dashboard and to the technologies used on the corporate website.

1.17. Changes

This policy may be updated if the product, the legislation or our data processing activities change. The current version and its effective date are published on this page. Separate notice is given where the law or an agreement in force requires it.

1.18. Contact

Dreavion Teknoloji Sanayi ve Ticaret Limited Şirketi. Registered address: Emniyet Evleri Mah. Eski Büyükdere Cad. Sapphire No: 1/1, İç Kapı No: 1B04, Kağıthane / İstanbul. Privacy and data protection: info@dreaviontechnology.com

Dreavion Technology

Dreavion Technology

We make emerging technology understandable and usable.

© 2026 Dreavion Technology

Dreavion Technology

Dreavion Technology

We make emerging technology understandable and usable.

© 2026 Dreavion Technology

Dreavion Technology

Dreavion Technology

We make emerging technology understandable and usable.

© 2026 Dreavion Technology