Privacy Policy
Last updated · 13 sections
This Privacy Policy explains what we collect when you use spatly.io, Spatly Studio, published surfaces, embeds, the REST API and the MCP server, what we do with it, and how to exercise your rights under the GDPR and the Turkish KVKK.
Sections
Data Controller
This Privacy Policy governs the processing of personal data by:
- Controller
- Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi
- Tax ID (Vergi No)
- 8800579984, Tax Office: Şarköy
- Address
- İSTİKLAL MAH. GANOS SK. NO: 5 B, 59800 Şarköy / Tekirdağ, Turkey
- support@spatly.io
Spatly is a product of Türkol Yazılım. The policy covers the website at spatly.io, Spatly Studio (the editor at /app), published surfaces at spatly.io/s/<id> and on custom domains, embeds served through embed.js, the REST API and the MCP server.
Data We Collect
- Account Information: Name, email address, password (stored as a hash) and, if you sign in with Google, the identifier Google gives us. Workspace name, the workspaces you belong to and your role in each, plan and billing status.
- Authentication Data: Hashed passwords, Google OAuth tokens and identifiers (only if you sign in with Google), and the session cookie that keeps you signed in.
- Workspace Content: Projects, datasets and files you upload, live data connections, layers, beats, the four surfaces (stories, slides, dashboards and insight containers), themes, marks and assets. Credentials inside a connection, for example an API header for a REST source, are encrypted at rest and are never sent to viewers or agents.
- API and MCP tokens: Tokens (
spk_…) you create for the REST API and the MCP server are stored as a hash; only the token prefix is kept in clear text so you can recognise it in Settings. We log which token made a request, when, and against which route. - Viewer analytics for published surfaces: When someone reads a published surface or an embed we record view events (
view,scene,expand,select) with the public id of the surface, a random per-tab session id, a timestamp and a small amount of event metadata (for example which chapter was reached). We do not record the reader’s name, email or IP address in these events, and we set no cookies on the reader’s browser for this purpose. Authors see aggregate counts, daily totals and top referrers. - Technical Data: IP address, browser type, operating system, device information and timestamps in our request logs, used for security, rate limiting and abuse prevention.
- Payment Data: Subscription billing is processed by Paddle (our Merchant of Record). We retain your Paddle customer and subscription identifiers and the plan you are on; we never store credit card details directly.
- Support correspondence: Emails you send to support@spatly.io and the details you include in them.
Purpose of Data Processing
- Providing and maintaining the Spatly platform and its mapping and storytelling tools: the studio, the four surfaces, live data and publishing.
- User account, workspace and membership management, and authentication.
- Rendering your published surfaces at
spatly.io/s/<id>, on custom domains and inside embeds, and delivering REST API and MCP tool requests made with your tokens. - Refreshing the live data connections you configure (URL, REST, webhook, scheduled pulls and MCP sources) and sending the metric alert emails you set up.
- Providing AI features (“Start from a prompt”, story and caption generation). For these requests we send the field names, types and summary statistics of the dataset you are working with, its bounding box and up to twenty sample rows to Anthropic’s API for the duration of the request. We do not use your content to train models, and Anthropic does not use API inputs to train its models.
- Communicating service updates, security alerts, billing receipts and support responses.
- Improving platform performance and reliability, and understanding how published surfaces are read in aggregate.
- Complying with legal obligations and preventing fraud and abuse.
Legal Basis for Processing
- Contract Performance: To provide you with the services you signed up for (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Legitimate Interest: For platform security, fraud prevention, aggregate analytics and service improvement (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Legal Obligation: To comply with applicable laws and regulations, including tax and accounting rules (GDPR Art. 6(1)(c); KVKK Art. 5(2)(a) and (ç)).
- Consent: For optional communications and non-essential cookies (GDPR Art. 6(1)(a); KVKK Art. 5(1)).
International Transfers
Your account data and workspace content are stored and processed in the European Union (the Netherlands). The data controller is established in Türkiye and accesses that data for support and operations; this transfer relies on your explicit consent and the safeguards of KVKK Art. 9 and, for data subjects in the EU/EEA and the UK, on the European Commission’s Standard Contractual Clauses and the UK Addendum.
Paddle (United Kingdom / United States), Anthropic (United States) and Zoho (EU data centres) process data under their own data processing agreements, which incorporate Standard Contractual Clauses where a transfer outside the EEA takes place.
Data Retention
We retain your personal data for the duration of your account. Upon account deletion, all personal data is permanently removed within 30 days, except where retention is required by law (for example invoices held by Paddle and our accounting records).
- Request logs with IP addresses: 30 days.
- Encrypted daily backups: 30 days, after which deleted content ages out of backups as well.
- Viewer analytics events: kept as raw events for 90 days and as aggregate counts for as long as the surface is published.
- Unpublishing a surface (setting it to draft) removes it from public links and embeds immediately; cached snapshots may persist for up to 24 hours.
Your Rights
Under GDPR and KVKK (Law No. 6698, Art. 11), you have the following rights:
- Right of Access: Request a copy of your personal data and learn whether and how it is processed.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data.
- Right to Data Portability: Request your data in a machine-readable format.
- Right to Object: Object to data processing based on legitimate interests, including automated processing that produces a result against you.
- Right to Withdraw Consent: Withdraw consent at any time, without affecting processing that took place before withdrawal.
- Right to Lodge a Complaint: Complain to the Turkish Personal Data Protection Authority (KVKK Kurumu) or to your local EU/EEA or UK supervisory authority.
You can export any project (data, layers, beats and surfaces) as JSON from Studio, and change your email or password from Settings. To delete a workspace or your account, or to exercise any other right, contact support@spatly.io from the email address on your account. We will respond within 30 days.
Security
We implement industry-standard security measures including SSL/TLS encryption in transit, secure password hashing, hashed API and MCP tokens, encryption at rest for connection credentials, HSTS headers, CSRF protection, rate limiting, per-workspace access control and regular security audits.
Children
Spatly is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has created an account, write to us and we will delete it.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or platform notification at least 30 days before they take effect. The date at the top of this page is the date of the current version.
Contact
Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi
İSTİKLAL MAH. GANOS SK. NO: 5 B, 59800 Şarköy / Tekirdağ, Turkey
Email: support@spatly.io
- Tax ID (Vergi No)
- 8800579984 Tax Office: Şarköy
- Address
- İSTİKLAL MAH. GANOS SK. NO: 5 B, 59800 Şarköy / Tekirdağ, Turkey
- support@spatly.io
Spatly is a product of Türkol Yazılım. Paddle.com Market Ltd. is the Merchant of Record for all paid plans.
Questions about any of these documents: support@spatly.io. We answer within 30 days, usually much sooner.