KionelLAB WORKFLOWS

Privacy Notice

Effective date: 2026-09-15 Version: 1.0

This notice explains what personal data Kionel collects when you use its website and buy a licence, and what we do with it. The Turkish-language notice on the policies page covers the same processing under Turkish data protection law (KVKK).

1. Who is responsible

Taha Bayar, a sole proprietorship registered in Türkiye, trading as Kionel ("we"), is the controller for the processing described here.

Postal address: Bademli 259. Cad., Kırkkonaklar, Çankaya / Ankara, Türkiye Privacy contact: privacy@kionel.com Security reports: security@kionel.com

2. What the software does not send us

The transfer application and the sample comparison tool run entirely in your browser. File contents, sample lists, camera frames and encryption keys are never uploaded to us and never leave your device. Keys and preferences are stored in your own browser storage. Clearing your browser data removes them.

We use no analytics, no advertising and no tracking cookies.

3. What we do collect

When you send the contact form: your name, email address, organisation (if you fill it in) and your message. We also store a salted hash of your IP address to detect flooding; the address itself is not stored. Purpose: replying to you and preventing abuse. Legal basis: our legitimate interest in answering enquiries and keeping the form usable. Retention: deleted automatically after 12 months.

When you buy a licence: the organisation name you enter, the order identifier returned by the payment provider, the licence file we issue and, for subscriptions, the licence key used to download renewals. A strictly necessary cookie identifies your purchase session in your browser for 30 days. Purpose: delivering and renewing your licence. Legal basis: performance of our contract with you. Retention: order records are deleted 13 months after their last update; subscription records are kept while the subscription exists.

Payment data: we never see your card. Polar (polar.sh) acts as merchant of record: it takes the payment, issues the invoice and handles tax as an independent controller for that processing. See Polar's own privacy policy.

Technical logs: our hosting provider processes standard request metadata (such as IP address and user agent) to deliver and protect the site. Our own error logs deliberately record no payloads, tokens, names or file contents.

4. Who else processes the data

order records.

We do not sell personal data and do not share it for advertising.

5. International transfers

We are established in Türkiye and our providers operate globally, so your data may be processed outside your country, including in the United States. Where GDPR applies, such transfers rely on the European Commission's Standard Contractual Clauses concluded with those providers.

6. Your rights

Where GDPR or UK GDPR applies you may ask for access to your data, correction, erasure, restriction, objection and portability, and you may complain to your supervisory authority. Under KVKK you have equivalent rights and may apply to the Turkish Data Protection Authority.

Write to privacy@kionel.com. We answer within 30 days. We may ask for information to confirm who you are, but only what is needed for that.

7. Security

The site is served over HTTPS with a strict content security policy. Signing keys live in server-side secret storage and are never sent to browsers. No customer file content is processed on our servers, because it never reaches them.

We publish a vulnerability disclosure policy; please report security issues to security@kionel.com rather than through the contact form.

8. Children

Kionel is sold to organisations. The site is not directed at children and we do not knowingly collect their data.

9. Changes

We may update this notice. Material changes are announced on this page at least thirty days before they take effect.