Privacy and Personal Data Protection Policy
Effective date: 27 September 2026
1.1. Scope and data controller
Performance Intelligence is a software service developed under the Dreavion Technology brand that helps businesses view and report their performance data from different advertising, analytics, search and other supported platforms in a single environment.
This policy explains the framework within which personal data is processed for authorized users of the Performance Intelligence platform, people who contact Dreavion Technology, and visitors to the dreaviontechnology.com corporate website.
Job candidates who apply through the careers pages are outside the scope of this policy. A separate Candidate Privacy Notice is published for them.
Official company and data controller information: Dreavion Teknoloji Sanayi ve Ticaret Limited Şirketi. Istanbul Trade Registry Office, registry no 1154612. MERSİS no 0313155054000001. Zincirlikuyu Tax Office, tax identification no 3131550540. Address: Emniyet Evleri Mah. Eski Büyükdere Cad. Sapphire No: 1/1, İç Kapı No: 1B04, Kağıthane / İstanbul. Privacy and data protection contact: info@dreaviontechnology.com
1.2. How does Performance Intelligence work?
Performance Intelligence retrieves performance data from third party platforms the user has authorized, processes it on the server side, and presents it to the user through the platform interface and reports.
The product’s core integration approach is read only. Performance Intelligence is not designed to create ads, change ad or campaign settings, update budgets and bids, or write operational data to connected platforms on the user’s behalf in supported integrations.
The supported platforms and the types of data retrieved from them may change as the product develops. When a new integration is added, the principle is to use only the data and permissions required to deliver that specific feature.
1.3. Categories of data we process
A. Account and authorization data. Name and surname, email address, in-account role, the customer or workspace the user belongs to, membership and authorization information, and the technical information required to run the session may be processed.
B. Integration and connection data. When a user connects a third party platform, the connection status, source information such as the selected account, property or ad account, the required permission information, and the access credentials needed for the connection to work may be processed. OAuth or similar access credentials are processed on the server side in line with the product’s technical architecture and are protected against access. These credentials are not displayed in plain text in the ordinary user interface.
C. Performance and reporting data. Impressions, clicks, cost and spend, traffic, sessions, channels, campaigns, pages, search queries, location, device and similar performance data may be retrieved from connected platforms. A significant part of this data consists of aggregated performance measurements. That said, search queries, URLs, page names or free text fields coming from third party platforms may contain information that qualifies as personal data, depending on the content at the source.
D. Form and lead data transferred into the system by the customer. When the customer uses the form or lead features of Performance Intelligence, name and surname, email, phone and other information contained in the form may be transferred into the system. As a rule, the relevant customer determines the purpose for which this data is collected and the legal basis on which it is processed. The customer is responsible for meeting the required disclosure and other data protection obligations for its own collection activity.
E. Notification and report delivery data. When Telegram or other notification channels that may be supported in future are used, the channel and chat identifier, notification preferences, delivery status, and error and transaction records may be processed.
F. Technical, security and usage data. Session information, request and error logs, synchronization records, security events, report download records, and technical connection data including IP address for the purpose of preventing abuse may be processed.
G. Billing and subscription data. When a paid plan is purchased, the Paddle customer and subscription identifiers, the plan, subscription status, billing period and billing country may be processed. Card and other payment details are collected and held by Paddle, which acts as merchant of record, and are not stored by Dreavion.
1.4. For what purposes do we process data?
Depending on the specific processing activity, personal data may be processed for the following purposes: setting up and delivering the service and managing user accounts, verifying user and customer permissions, establishing and maintaining third party platform connections, and retrieving, storing, displaying and reporting performance data.
It may also be processed to create, store and deliver reports through the channels the user selects, to ensure information security, to prevent abuse and unauthorized access, for error analysis, technical support and service continuity, to improve the functions offered to the user, and to fulfil legal obligations and to establish, exercise or protect rights.
We process relevant account and performance data to provide AI-assisted analyses and responses through Scout.
1.5. What we do not do
We do not use user or integration data obtained through Performance Intelligence for data brokerage, we do not sell it to third parties, and we do not use it for targeting on third party advertising networks.
We do not use customer data to train artificial intelligence or machine learning models, whether Dreavion Technology’s own or those of third parties.
1.6. Use of Google API data
Data accessed through Google APIs is used solely to provide or improve the Performance Intelligence features the user explicitly uses.
Performance Intelligence’s use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.
User data accessed through Google APIs is not read by humans. The exceptions are the user’s explicit consent, reviews carried out for security purposes, the fulfilment of legal obligations, and data that has been aggregated and anonymized.
Google API data is not used for advertising targeting, is not sold, and is not used to train artificial intelligence or machine learning models.
Data accessed through Google APIs and stored persistently within Performance Intelligence is held in database and storage services hosted in the Frankfurt location in the European Union region on the current production infrastructure. Access and refresh tokens for Google accounts are stored in encrypted form. Customer data is logically separated on a tenant basis and is used only in that customer’s dashboard, analyzes and generated reports. Infrastructure providers and data processing roles are described separately in the Sub-processors and External Platforms List.
1.7. Meta and other connected platforms
On Meta, Google and other supported platforms, only the permissions required for the reporting and monitoring functions the product offers to the user are requested.
When the Meta Ads integration is used, the purpose of Performance Intelligence is to retrieve performance data from the ad account on a read only basis and report it to the user. The connected platforms’ own terms, permission models and privacy practices apply in addition.
1.8. Parties with whom data is shared
In order to deliver the service, data sharing or data access may occur with the following groups of recipients, only to the extent necessary: application hosting, database, authentication and file storage providers, corporate website infrastructure providers, the advertising, analytics, search, e-commerce, marketplace and other external platforms the customer connects at its own request, the notification and messaging services the customer selects, legal, financial or technical advisors, and public institutions and organizations authorized by law.
The current list of infrastructure and external platforms is published on the Sub-processors and External Platforms List page.
1.9. Transfer of data abroad
Some of the infrastructure providers we use, or the external platforms the customer connects, may result in personal data being processed outside Türkiye or transferred abroad.
Where personal data is transferred abroad, the transfer must rely on an applicable transfer mechanism under Article 9 of Law no. 6698 on the Protection of Personal Data and the related secondary legislation.
Transfer mechanism and appropriate safeguard: the condition relied on is determined for each transfer under Article 9 of Law no. 6698, for example an adequacy decision, appropriate safeguards such as standard contracts, or, for incidental transfers, the exceptions set out in that Article. For users in the European Economic Area, transfers under the GDPR are described in section 1.15.
1.10. Retention periods
We keep personal data limited to the period necessary for the purpose of processing and the periods required by applicable legislation. The same retention period does not apply to every category of data.
Account and authorization data: kept for as long as the account relationship continues and throughout the statutory limitation periods following closure of the account.
Connection access tokens: when the user disconnects the relevant platform, the access credential held by Dreavion is removed.
Performance and reporting data: kept for as long as the account relationship continues, and assessed under a data deletion request when the account is closed.
Report files: kept accessible for the period stated in the customer’s plan and removed from active report storage at the end of that period. Current periods are stated within the product and in the plan terms.
Technical and security records: kept for the period required by the purposes of security, auditing and preventing abuse.
Support and contact correspondence: kept for as long as necessary after the relationship ends, taking applicable limitation periods into account.
Disconnecting a platform does not mean that performance data previously retrieved from that platform is automatically deleted. The user or the authorized customer may submit a separate data deletion request.
Limited records that must be kept for security, auditing, dispute resolution and legal obligations may be retained for as long as necessary for that purpose. Where applicable and where backup functionality is enabled, some data deleted from active systems may remain for a limited period in the infrastructure providers’ technical backups until ordinary backup and rotation processes complete. This does not mean that deleted data is accessible again for ordinary use of the product.
1.11. Security
We apply technical and administrative measures to protect personal data against unauthorized access, unlawful processing, loss or disclosure. These measures may include controls such as access control, authorization, encryption, tenant and customer separation, dedicated storage areas, and logging and monitoring mechanisms.
No information system can guarantee absolute security. Security measures are reviewed taking risks, product architecture and applicable obligations into account.
1.12. Data breach notification
Where it is established that personal data has been unlawfully obtained by others, the situation is reported to the Personal Data Protection Board as soon as possible and in any case within seventy-two hours of that determination.
The data subjects affected by the breach are informed as soon as reasonably possible and by an appropriate method.
Where Dreavion Technology acts as a data processor, the breach is reported to the relevant customer without delay and reasonable support is provided so that the customer can meet its own notification obligations.
If you have identified a security vulnerability or a possible breach, you can report it to info@dreaviontechnology.com
1.13. Disconnecting and data deletion
Removing a third party platform connection stops future data synchronization for that platform and causes the connection credentials held by Dreavion to be removed. This action does not automatically delete all historical performance data or reports created earlier.
For the scope of data deletion and account closure requests, see the Data Deletion and Account Closure Instructions page.
1.14. Data subject rights under Law no. 6698
The rights under Law no. 6698 and the procedures for exercising them are explained in the Data Protection Disclosure Notice.
1.15. GDPR and European Economic Area users
Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), applies alongside this policy where it is legally applicable, in particular to processing concerning users in the European Economic Area. This section adds what the GDPR requires. The provisions of this policy on Law no. 6698 continue to apply where that Law applies.
A. Our role as controller and processor
Dreavion Teknoloji Sanayi ve Ticaret Limited Şirketi, identified in section 1.1, is the controller for the processing it carries out for its own purposes. These are creating and administering accounts, billing and subscription records, support and contact correspondence, the security of the service, and the corporate website.
For data a customer processes through Performance Intelligence, such as performance data from connected platforms and form and lead data, the customer is the controller and Dreavion Technology acts as its processor under the Data Processing Agreement. If you are a customer’s own customer or lead, please direct your request to that customer. If your request reaches us, we forward it to them.
B. Legal bases for our own processing
Account creation and administration, providing the features you use, and service communications: performance of a contract with you (Article 6(1)(b) GDPR). Where you use an account on behalf of an organisation that is our customer, our legitimate interest in providing the service to that organisation (Article 6(1)(f)).
Billing and subscription records: performance of a contract (Article 6(1)(b)). Keeping records the law requires: compliance with a legal obligation (Article 6(1)(c)) where the obligation arises under European Union or Member State law, and otherwise our legitimate interest in meeting the legal obligations that apply to us (Article 6(1)(f)).
Security, preventing abuse and unauthorised access, error analysis and service continuity: our legitimate interest in operating a secure and reliable service (Article 6(1)(f)).
Support requests and enquiries: steps taken at your request before entering into a contract, or performance of a contract (Article 6(1)(b)), or our legitimate interest in responding to enquiries (Article 6(1)(f)).
Establishing, exercising or defending legal claims: our legitimate interest (Article 6(1)(f)).
Website analytics through Google Analytics 4 and any other non-essential cookies on the corporate website: your consent (Article 6(1)(a)), given and managed through the cookie preferences. See the Cookie and Similar Technologies Policy.
Providing account data is necessary to create and use an account. Without it we cannot provide the service. Where we rely on legitimate interests, you can object as described below.
C. Your rights under the GDPR
Where the GDPR applies, you have the right to access your personal data, to have inaccurate data rectified, to have data erased, to restrict processing, to data portability, and to object to processing based on legitimate interests. Each right applies under the conditions and exceptions in Articles 15 to 21 of the GDPR.
Where processing is based on your consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement.
Requests can be sent to info@dreaviontechnology.com. We may ask for information needed to confirm your identity. We respond without undue delay and within one month of receiving the request. Where necessary, that period may be extended by two further months given the complexity and number of requests, and we will tell you within the first month.
These rights exist alongside the rights under Article 11 of Law no. 6698 described in the KVKK Privacy Notice. The two sets of rights are not identical, and each applies where its own law applies.
D. International transfers
The main application, database, authentication and file storage infrastructure of Performance Intelligence is hosted in the European Union (Frankfurt). Dreavion Technology is established in Türkiye, and some providers, as well as platforms a customer chooses to connect, may process data outside the European Economic Area. The providers and their verified processing locations are listed on the Sub-processors and External Platforms List.
Where Chapter V of the GDPR requires a transfer mechanism, the transfer relies on the mechanism that fits the relationship concerned, such as an adequacy decision of the European Commission, standard contractual clauses adopted by the European Commission, or another mechanism permitted by Chapter V. You can ask for information about the safeguard used for a transfer, and how to obtain a copy of it, at info@dreaviontechnology.com.
For data processed on a customer’s behalf, the transfer rules are set out in section 1.9 of the Data Processing Agreement.
1.16. Automated decision making
Performance Intelligence does not produce decisions taken solely by automated systems that produce legal effects concerning data subjects or similarly significantly affect them.
1.17. Cookies and similar technologies
The Cookies and Similar Technologies Policy applies to the mandatory session cookies and browser storage technologies used in the Performance Intelligence dashboard and to the technologies used on the corporate website.
1.18. Changes
This policy may be updated if the product, the legislation or our data processing activities change. The current version and its effective date are published on this page. Separate notice is given where the law or an agreement in force requires it.
1.19. Contact
Dreavion Teknoloji Sanayi ve Ticaret Limited Şirketi. Registered address: Emniyet Evleri Mah. Eski Büyükdere Cad. Sapphire No: 1/1, İç Kapı No: 1B04, Kağıthane / İstanbul. Privacy and data protection: info@dreaviontechnology.com