Privacy Policy
Explains what data ilgiERP processes when you use our services, why we process it, and what rights you have.
Last updated: 11 August 2026
1. Who this policy is for
İLGİSOFT BİLİŞİM VE DANIŞMANLIK HİZMETLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ ("İLGİSOFT", "we") operates the website at https://ilgierp.com and the cloud-based enterprise resource planning (ERP) service offered under the name ilgiERP. ilgiERP is a PRODUCT name; the rights and obligations in this policy belong to the legal entity İLGİSOFT. This policy applies both to visitors of our website and to authorised users of subscribing organisations.
General enquiries: info@ilgierp.com · Data protection requests: kvkk@ilgierp.com
2. Two distinct roles: controller and processor
The capacity in which we process data depends on whose data it is, and this distinction directly affects your rights.
- We act as controller when you visit our website, request a demo, contact us, or purchase a subscription. We determine the purposes of processing this data.
- We act as processor for the customer, supplier and personnel data that a subscribing organisation (tenant) uploads to the ERP. The tenant determines the purpose and scope; we host and process it solely on their instructions. Requests concerning such data should first be directed to that organisation.
3. Data we process
- Identity and contact data: name, job title, company name, email, phone.
- Account data: username, password hash (your password is stored irreversibly hashed, never in plain text), roles and permissions, session records.
- Usage data: IP address, browser and device information, pages accessed, error and performance logs.
- Billing and subscription data: billing entity, tax details, subscription plan and payment status. Card details never reach us; the payment page belongs to a licensed payment institution.
- Communication content: support requests and our replies.
4. Messaging channels and Meta platforms
The customer relationship management module lets a subscribing organisation connect its own WhatsApp Business, Instagram and Facebook accounts to our service. This connection is established only with the organisation's explicit consent and through Meta's own authorisation flow.
- Access tokens for a connected account are stored encrypted and are never shown on any screen or returned in any API response.
- Messages sent and received through these channels are stored as the organisation's own customer communication record; for that data the organisation is the controller and we are the processor.
- We use data obtained from Meta solely to provide the messaging service to the organisation. We do not use it for advertising, do not sell it, and do not process it for any purpose not permitted by Meta platform terms.
- An organisation may disconnect at any time; stored access tokens are deleted on disconnection.
5. Purposes of processing
- To provide the service and to create and manage your account.
- To operate subscription, invoicing and collection processes.
- To handle support requests and resolve faults.
- To keep the service secure and to detect abuse and unauthorised access.
- To comply with our legal obligations.
- To send commercial electronic messages where you have given explicit consent. You may withdraw consent at any time.
6. Who we share data with
We do not sell your data. We share only what is necessary, with parties necessary to deliver the service:
- Our cloud infrastructure provider (hosting, backup, logging).
- The payment institution — solely for subscription collection; card data goes to them directly.
- Email and messaging infrastructure providers.
- Competent public authorities — only where legally required and limited to the scope of the request.
7. International transfers
Our cloud infrastructure and some communication providers may be located outside Türkiye. In that case transfers are made on the basis of the conditions and appropriate safeguards required by the Turkish Personal Data Protection Law. You may request details of which providers are used and where data is hosted at kvkk@ilgierp.com.
8. Retention
We do not retain data once the purpose of processing has ceased. When a subscription ends, tenant data is deleted after a reasonable period allowed for data export. Records that legislation requires to be kept for a defined period — such as commercial books, invoices and accounting records — are retained for that period and for that purpose only.
9. Security
No technical measure provides absolute security. In the event of a data breach we will notify affected individuals and the Turkish Personal Data Protection Authority within the periods required by law.
- TLS encryption is used in transit.
- Passwords are stored irreversibly hashed.
- Each subscribing organisation's data is held in a separate database.
- Access rights are role-based and granted on a least-privilege basis.
- External system access tokens are stored encrypted.
10. Your rights
In relation to your personal data you have the right to learn whether it is processed, to request information about it, to learn whether it is used for its intended purpose, to know the parties to whom it is transferred domestically or abroad, to request correction if it is incomplete or inaccurate, to request erasure or destruction, to object to processing, and to claim compensation if you suffer damage.
You may submit requests to kvkk@ilgierp.com or in writing to SİLAHTAR MAHALLESİ ÇORLU YERLEŞKESİ OFİS NO:TGB12 BELDE/BUCAK SİNAN DEDE MEVKİİ ÇERKEZKÖY YOLU 3.KM. NAMIK KEMAL ÜNİVERSİTESİ ÇORLU MÜHENDİSLİK FAKÜLTESİ ÇORLU/TEKİRDAĞ/Türkiye. We respond within thirty days at the latest.
If you want your account and data deleted, follow the steps on our data deletion page.
11. Children's data
Our service is intended for business use and is not directed at anyone under eighteen. We do not knowingly collect children's data; if we become aware that such data has reached us, we delete it.
12. Changes
We may update this policy from time to time. Where a change is material we will notify you in-product or by email before it takes effect. The update date shown at the top of the page always reflects the version in force.