How SmartIO Bilişim Sistemleri San. ve Tic. Ltd. Şti. collects, uses, shares and protects personal information in connection with the Browsonic service.
This Privacy Policy explains howSMARTIO BİLİŞİM SİSTEMLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ("SmartIO", "we", "us"), the operator of the Browsonic service, collects, uses, shares and protects personal information in connection with our website at browsonic.com, our dashboard, our software development kits and related services (collectively, the "Service").
We act as a data controller for personal information about our customers, account members and website visitors, and as a data processor for personal information contained in telemetry that you, our customer, send into the Service through our SDKs.
For data subjects in Türkiye the operative text is the Turkish KVKK Aydınlatma Metni, which is the disclosure Article 10 of Law No. 6698 requires; a fuller Turkish version of this policy is atGizlilik Politikası. Where this English text and the Turkish ones differ, the Turkish ones prevail for those readers.
1. Information We Collect
Account information
When you create an account we collect your name, email address, password (hashed), organisation name and, optionally, your role and timezone.
Billing information
When you subscribe to a paid plan we collect billing contact details and tax information. Payment card numbers are collected and held by our third-party payment processor; we receive only a tokenised reference, the card brand, the last four digits and the expiry date.
Telemetry from our SDK
When you install our SDK in your application, the SDK transmits the events your application generates — errors, unhandled rejections, network failures and the context attached to them. The exact contents are determined by how you configure the SDK and by the libraries you use. Telemetry may include user identifiers, IP addresses, browser and device metadata, URLs, breadcrumbs, console messages and stack traces.
Session Replay and screen capture
If our customer enables the optional Session Replay feature, the SDK records a reconstruction of the end user's browser session — DOM structure and mutations, mouse movement, clicks, scrolls and input interactions — so the customer can replay what happened before an error. The related App Atlas feature renders screenshots of application screens from these recordings. By default the SDK masks all text and all input values and blocks media before capture, so the recording stores the shape of the page rather than its content; the customer configures what is masked or unmasked and is responsible, as data controller, for obtaining any consent this processing requires. Session replays are not kept for the telemetry window listed below: recordings carry their own expiry — 90 days on Professional, 30 days on Enterprise and 14 days on every other plan — after which they are deleted automatically, regardless of how long the account's other event data is retained.
Usage data
We collect data about how you interact with the dashboard — pages visited, features used, search queries, approximate location derived from IP address, browser and operating-system version.
Communications
When you contact us by email or chat we keep a copy of the message and our response.
Cookies and similar technologies
We use a small number of strictly necessary cookies (for authentication and CSRF defence) and, with your consent where required, analytics cookies. See Section 9 for details.
2. How We Use Information
We use personal information to:
- provide, operate, maintain and secure the Service;
- authenticate users and protect against fraud and abuse;
- bill you for paid plans, collect taxes and prevent payment fraud (working with our payment processor);
- communicate with you about your account, security advisories, product updates and changes to terms;
- respond to support requests;
- understand how the Service is used so we can improve it;
- comply with legal obligations and enforce our Terms.
We do not sell your personal information.
3. Legal Bases (EU / UK)
If you are in the EU, UK or another jurisdiction that requires a legal basis for processing, we rely on the following bases:
- Contract — to deliver the Service you have subscribed to;
- Legitimate interests — to secure the Service, prevent abuse, improve the product and communicate operationally;
- Consent — for analytics cookies and for marketing email where required by law;
- Legal obligation — to retain records required by tax or other laws.
You may withdraw consent at any time without affecting prior processing.
4. Sharing with Third Parties
We share personal information only with:
- Service providers (sub-processors) that help us run the Service. We require them to protect personal information consistent with this Policy and only to use it on our instructions. Our current sub-processors are:
- DigitalOcean, LLC — Cloud hosting and storage for the Service (Amsterdam, Netherlands (EU region)).
- iyzico Ödeme Hizmetleri A.Ş. — Payment processing and subscription billing (Türkiye; outside the EEA).
- Google Ireland Ltd. — Google Analytics 4 — aggregate usage analytics, consent-gated (Ireland (EU)).
- OpenAI, L.L.C. — AI error-insight generation — an error message and its stack are sent to the model when a customer requests an insight. Optional: the feature is inert unless an API key is configured. (United States; outside the EEA).
- Transactional e-mail (SMTP) provider — Delivery of account e-mail — verification, password reset, invitations and alert notifications (As configured for the deployment; disclosed on request; outside the EEA).
- Authorities and other third parties when we are legally required to do so, when necessary to investigate fraud or security incidents, or to protect the rights, property or safety of Browsonic, our customers or the public.
- Acquirers in connection with a merger, acquisition, financing or sale of assets, subject to notice to you where required.
5. International Transfers
SmartIO is established in the Republic of Türkiye and hosts the Service on infrastructure located in the European Union (DigitalOcean, Amsterdam / Netherlands). Where personal information is transferred from the EU / UK to a country that does not provide an adequate level of protection, we rely on the Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum as appropriate. For data subjects in Türkiye, processing is carried out in compliance with Law No. 6698 on the Protection of Personal Data (KVKK); see ourKVKK Aydınlatma Metni for the Turkish-law disclosure, which is the controlling text for data subjects in Türkiye.
One transfer is worth naming rather than leaving inside the sub-processor list. The optional AI error insightfeature sends an error message and its stack trace toOpenAI, L.L.C. in the United Stateswhen a user asks for an explanation of an error. The feature is inert unless it has been configured, no telemetry is sent to OpenAI in the ordinary course of processing, and the transfer is covered by the Standard Contractual Clauses. If you would rather no data left the EEA at all, do not use the feature — and tell us, so we can confirm it is disabled for your account.
6. Data Retention
We retain personal information only for as long as necessary to provide the Service and fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law:
- Account information — for the life of your account, plus up to 30 days after deletion for backup recovery.
- Billing records — for at least seven (7) years to comply with tax and accounting obligations.
- Telemetry — according to the retention window of the plan the account is on. Those windows are7 days on Free, 14 on Starter, 90 on Professional and 365 on Enterprise; the plan's window is shown on the pricing page and in the dashboard. Aggregated, anonymised metrics may be kept longer.
- Support tickets — for up to two (2) years after resolution.
- Server logs — for up to 30 days.
- Security and audit records — for up to400 days. These are the tamper-evident records of security-relevant actions taken in the Service: who signed in, who changed a setting, who exported or deleted data. Each entry holds the acting user's email address and IP address.
Two things about this category are worth stating plainly rather than leaving to be discovered. First, the retention period is longer than any other category here, because the value of an audit trail is precisely that it still exists when a question is asked late. Second, these records survive account deletion: they are deliberately excluded from erasure, because a log that can be erased by the account it incriminates is not a security control. We rely on ourlegitimate interest in the security and integrity of the Service (and, where applicable, on our legal obligation to keep such records) rather than on your consent, and the records are used for security and dispute-resolution purposes only. You may object to this processing at the address in Section 12; where an objection cannot be honoured we will say so and explain why.
7. Security
We implement administrative, technical and physical safeguards designed to protect personal information against unauthorised access, alteration, disclosure or destruction. These include encryption in transit and at rest, least-privilege access controls, audit logging, regular dependency scanning and security review of changes.
No system can be guaranteed to be 100% secure. If we become aware of a security incident affecting your personal information, we will notify you in line with applicable law.
8. Your Rights
Depending on where you live, you may have rights to:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- delete your personal information;
- restrict or object to certain processing;
- receive a copy of your information in a structured, machine-readable format (portability);
- lodge a complaint with your local data protection authority.
Most of these rights can be exercised from your account settings; for everything else, write tobrowsonic-privacy@smartiobilisim.comand we will respond within the timeframes required by law (typically 30 days).
California residents have additional rights under the CCPA, including the right to know what categories of personal information we collect, the right to delete and the right to non-discrimination. We do not sell personal information as defined by the CCPA.
9. Cookies
We use the following cookies on our website and dashboard:
- Strictly necessary — authentication, CSRF tokens, load balancing. These are set without consent because the Service cannot function without them.
- Functional — to remember preferences such as timezone, theme and language.
- Analytics — we use Google Analytics 4(provided by Google Ireland Ltd.) to understand aggregate usage of our marketing site and console. These cookies are set only with your consent where required. We do not send account credentials or end-user personal identifiers to Google.
On browsonic.com the analytics cookie is set only after you chooseAccept analytics in the consent banner shown on your first visit; until then no Google Analytics script is loaded at all. You can change that choice at any time throughCookie settings in the footer, or through your browser settings. Blocking strictly necessary cookies will prevent the Service from working correctly.
10. Children
The Service is not directed to children under 16 and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contactbrowsonic-privacy@smartiobilisim.comand we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by email to your account owner or by notice in the dashboard at least fifteen (15) days before they take effect. The "Last updated" date at the top of this Policy reflects the most recent revision.
12. Contact
Questions about this Policy or about how we handle personal information:
SMARTIO BİLİŞİM SİSTEMLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ
Balcalı Mah. Güney Kampüs/5 Sk., Teknokent No:4, İç Kapı No:108, Sarıçam / Adana, Türkiye
Office: +90 322 911 0941 · Call Center: 0850 308 8824
Email: browsonic-privacy@smartiobilisim.com
Mersis No: 0772138018200001
If you are in the EU or UK and have a complaint that we are unable to resolve, you can contact your local data protection authority.