Privacy Notice
What personal data Mediaory processes, why and on what basis, who receives it, how long we keep it, and the rights you have under Turkey's data protection law (KVKK). Written in plain language.
Last updated: 9 October 2026
Data controller
This notice is given under Article 10 of Law No. 6698 on the Protection of Personal Data (KVKK). For the account, billing-contact, usage and form data described below, the data controller is:
- Mediaory
- Contact: [email protected]
When a customer puts personal data into its workspace (for example colleagues' names in comments), the customer decides why and how it is used and Mediaory processes it on the customer's behalf; a data processing addendum is available on request. For public sources, see section 5.
What personal data we process
The data depends on how you use Mediaory:
- Account data: your name, e-mail address, job title, language and time-zone preferences, and a hashed password.
- Organization and billing contact data: the organization you belong to and your role. If you add a billing profile, the company name, tax office, tax number, address and invoice e-mail you enter.
- Workspace content you create: monitoring keywords and queries, alert rules, tags, comments, assignments, reports and exports, and your organization's settings.
- Security and usage data: sign-in sessions, IP address and browser type, security and audit events, usage counters (for example how many keywords or reports you use) and error logs.
- Connected accounts: if you connect a YouTube or X account we keep its access tokens (stored encrypted) and the account's public identifier, and read only what the connection allows.
- Forms: what you type into the contact, takedown and data-request forms, including your name and e-mail address.
- People named in public sources: see section 5.
Why we process it, and on what legal basis
We do not sell personal data, we do not use it for advertising, and we do not use your workspace data to train AI models.
Under Article 5 of the KVKK we rely on these bases:
- Creating and running your account and providing the service: performance of a contract (Art. 5/2-c).
- Service e-mails such as verification, invitations, alerts, digests and weekly archive links: performance of a contract (Art. 5/2-c). We do not send marketing e-mail.
- Keeping the service secure, preventing abuse and fixing errors: our legitimate interest, which does not override your rights (Art. 5/2-f).
- Indexing public sources so customers can monitor media coverage: our and our customers' legitimate interest, with the data kept to the minimum described in section 5 (Art. 5/2-f).
- Invoicing and accounting records: legal obligation (Art. 5/2-ç).
- Answering your requests and complaints, and establishing, exercising or defending legal claims: Art. 5/2-e and 5/2-f.
- Connecting a social account: your consent, which you can withdraw at any time by disconnecting it (Art. 5/1).
How we collect it
- Directly from you: when you register, use the service or write to us.
- Automatically: cookies and similar technologies (section 12) and server and security logs when you use Mediaory.
- From the platforms you connect, with your authorization.
- From public sources — RSS and Atom feeds, sitemaps and public web pages — for the content described in section 5.
Content from public sources
We index publicly available sources. For each story we keep the headline, the link, the publication time, a public author name where the source gives one, and an excerpt of at most 200 characters; we do not keep the full text or images. For matching we also keep a word fingerprint: hashes of the words of the headline and summary, which cannot be turned back into text.
Press reports can contain sensitive information about the people they name. We do not build profiles of those people. Stories that no customer's monitoring matched are deleted after 14 days. Stories that were matched stay as mentions in the customer's workspace until the customer's own retention setting removes them or the organization is deleted, and are listed in the customer's weekly archive.
People named in public news are not our customers. If you want a story about you removed from our index, or have a question about it, send us its link (section 10); publishers can use the takedown form.
Who receives it
We share personal data only with these groups:
- Our service providers, who process it on our instructions: cloud hosting and database, object storage for archives, e-mail delivery, bot protection on public forms and — only if AI features are switched on — an AI provider. Each one, with its purpose and data, is listed on the service providers page.
- The platforms you connect (Google/YouTube, X): data is exchanged only for that connection.
- Other members of your organization, who see your name, e-mail address, role and the content you create in the workspace.
- Authorities, courts and professional advisers, when the law requires or to establish, exercise or defend legal claims.
Transfers abroad
The service providers that help us run Mediaory are located outside Türkiye, mainly in the United States and the European Union, so personal data is transferred abroad when you use the service. Since the 2024 amendment of Article 9 of the KVKK, routine transfers abroad rest on the safeguards the law lists — an adequacy decision, the Board's standard contract, binding corporate rules or an approved undertaking — and no longer on explicit consent alone. Our transfers are made in line with Article 9.
You can ask us which safeguard applies to a given provider (section 10).
How long we keep it
- Account data: while your account exists. When you delete your account, your name, e-mail address and other personal details are irreversibly anonymized and your sessions are closed.
- Organization data: when an organization is deleted its members lose access at once, and everything linked to it — mentions, reports, comments, archive files — is permanently erased after 30 days.
- Stories that no monitoring matched: deleted after 14 days. Matched stories stay as mentions until the organization's retention setting removes them or the organization is deleted.
- Sign-in sessions and one-time tokens (verification, password reset, invitations): removed 30 days after they expire or are used.
- Billing and accounting records: for the period the law requires.
- Contact, takedown and data-request forms: as long as needed to handle the request and to show how we answered it.
Your rights
Under Article 11 of the KVKK you have the right to:
- learn whether your personal data is processed;
- request information if it has been processed;
- learn the purpose of processing and whether it is used accordingly;
- know the third parties it is transferred to, in Türkiye or abroad;
- ask for correction if it is incomplete or inaccurate, and for the correction to be notified to those it was transferred to;
- ask for deletion, destruction or anonymization when the reasons for processing no longer exist (Art. 7), and for that to be notified to those it was transferred to;
- object to a result against you that arises solely from automated analysis; and
- claim compensation for loss caused by unlawful processing.
How to use your rights
Write to [email protected], or to the address or KEP address in section 1. Tell us who you are and what you ask; we may ask for information to confirm your identity so that your data is not given to someone else.
We answer as soon as possible and within 30 days at the latest, free of charge. If answering needs extra cost, the fee set by the Personal Data Protection Board may be charged.
If you are a customer, you can export your account data and delete your account or organization yourself in Settings.
If you are not satisfied with our answer, or do not receive one in time, you can complain to the Personal Data Protection Board (kvkk.gov.tr).
Security
We take technical and organizational measures proportionate to the risk, including:
- encrypted connections (HTTPS) between your browser and Mediaory;
- passwords stored only as salted hashes;
- sign-in sessions that are signed, checked on the server and revocable;
- access tokens of connected accounts stored encrypted;
- role-based access, and a check on every request that the data belongs to your organization; and
- an audit trail of sensitive actions, and rate limiting against abuse.
No system is perfectly secure. If a breach affects your personal data, we will notify the Personal Data Protection Board and the people affected as the law requires.
Cookies
Mediaory uses only the cookies it needs to sign you in and to remember your language and theme. We use no analytics, advertising or tracking cookies. Details are on the cookie policy page.
Changes to this notice
We update this notice when our processing changes. The date at the top shows the latest version, and we will tell account holders about material changes by e-mail or in the app.
Contact
Privacy questions and requests: [email protected]. Publishers: use the takedown request form.