Privacy Policy
Last updated: 10 August 2026
PallasMark Privacy Policy
1. Data Controller
PallasMark is a software service operated by RecRam Inc. ("Company"), a company incorporated in the State of Delaware, United States. RecRam Inc. is wholly owned by RecRam Yazılım Anonim Şirketi, headquartered in Kocaeli, Turkey, which serves as the group's head office and operational base.
- RecRam Inc. (USA) — 112 Capitol Trail Suite A1127, Newark, Delaware 19711, United States · EIN: 38-4300256 · Registered Agent: Social Enterprise LLC
- RecRam Yazılım Anonim Şirketi (Turkey, headquarters and parent) — Muallimköy Mah. Deniz Cad. Muallimköy T.G.B. 1.Etap 1.1.C1 Blok No:143/8 İç Kapı No:1, Gebze/Kocaeli · Tax office: Uluçınar Vergi Dairesi · Tax no: 7342530245 · Trade registry no: 40113 · MERSİS no: 0734253024500001
- Contact (single address for all legal, privacy, and KVKK requests): hello@pallasmark.com
RecRam Yazılım Anonim Şirketi acts as RecRam Inc.'s Turkey-based data controller representative under KVKK Art. 6698 and Art. 11 of the Regulation on the Data Controllers' Registry.
This policy is issued to fulfil disclosure obligations under KVKK Art. 10 and GDPR Art. 13-14. Data subjects in Turkey are additionally covered by our KVKK Notice.
2. Personal Data Processed
Merchant Data:
- Identity: name, surname, email, company name, password (stored as a hash)
- Team members: role (staff/admin/owner), login session records (device fingerprint, IP/location, timestamped signed session chain)
- Legal: tax number, trade registration number, address (if provided by the Merchant)
- Payment: billing address (card details stored by Paddle/Stripe, not by PallasMark)
- Usage: login times, transaction history, API requests
Buyer Data (processed on behalf of, and on the instructions of, the Merchant — see DPA; no account is created for buyers):
- Contact: email or phone (for sending the approval link)
- Delivery proof: video/photo files uploaded by the Merchant
- Approval record: IP address, browser/device fingerprint (user agent, screen resolution, timezone, language, canvas hash, Do-Not-Track preference), timestamp, hash of the accepted contract text
- Location: optional GPS coordinates (only with the buyer's explicit consent)
- Session recording: a replay of on-page scrolling/click interactions on the approval page (form inputs are masked); automatically deleted after 180 days
- Viewing data: video watch duration
- Dispute evidence: additional video/photo uploaded by the buyer when disputing (if any)
3. Purposes and Legal Bases
Merchant data:
- Performance of contract (KVKK Art. 5/2-c / GDPR Art. 6(1)(b)): account management, billing
- Legitimate interest (KVKK Art. 5/2-f / GDPR Art. 6(1)(f)): platform security, abuse detection, team access logging
- Legal obligation (KVKK Art. 5/2-c / GDPR Art. 6(1)(c)): tax and accounting records
Buyer data (on Merchant's instructions):
- Legitimate interest (GDPR Art. 6(1)(f)): creation and retention of delivery evidence, integrity of legal evidence
- Electronic consent record under ETK Art. 6
- Explicit consent (KVKK Art. 5/1 / GDPR Art. 6(1)(a)): only when optional location data is collected
4. Retention Periods
Retention is governed by the following concrete mechanisms rather than a single fixed number of years:
- Delivery evidence (video/photo): retained for the duration set by the Merchant's subscription plan; plan details are shown in account settings
- Session recording (on-page interaction replay): 180 days from capture, then automatically deleted
- After account closure: a 30-day window is provided for the Merchant to export data, after which it is permanently deleted
- Data subject erasure requests: logged to an audit record and manually completed by an operator within 30 days
- Billing/payment records: 10 years under Turkish Tax Procedure Code Art. 253
5. Data Transfers
Personal data may be shared with:
- Cloudflare, Inc. — storage of video/photo evidence files (object storage, global content delivery network)
- Resend and EmailIt — sending email notifications
- Twilio Inc. — sending SMS notifications
- Meta Platforms, Inc. (WhatsApp Business Platform) — sending WhatsApp notifications
- Paddle.com Market Ltd. and/or Stripe, Inc. — payment processing (Merchant's chosen provider; card data is held by these providers and never reaches us)
- netcup GmbH (Germany) — infrastructure provider hosting the application server and database
Because our application server and database are hosted in Germany (EU), personal data collected from Turkey is transferred abroad; this transfer is governed by KVKK Art. 9. Transfers to US-based providers such as Cloudflare, Twilio, and Meta are safeguarded under the Standard Contractual Clauses (SCCs) required by GDPR Art. 46.
6. Data Security
- TLS 1.2+ encryption in transit, AES-256 at rest
- SHA-256 hash-based file integrity verification
- Role-based access control; the Company's own staff access is logged via a signed (Ed25519) session chain
- Regular security audits
7. Data Subject Rights
Your rights under KVKK Art. 11 and GDPR Art. 15-22: access, rectification, erasure, restriction of processing, data portability, objection.
Submit requests to hello@pallasmark.com. We respond within 30 days. Complaints: Turkey's Personal Data Protection Board (kvkk.gov.tr) or your EU supervisory authority.
8. Cookies and Updates
The platform uses only technically necessary cookies — no third-party advertising or tracking cookies. See our Cookie Policy for details. This policy may be updated with prior notice.
9. Account and Data Deletion
To request deletion of your account and associated data, email hello@pallasmark.com. Once verified, your account and personal data will be deleted within a reasonable time, except where required to retain certain records by law.
Revision History
- 10 Aug 2026v2.3Removed legacy legal-review placeholders and confirmed current company, data-processing, provider, and account-deletion disclosures.
- 03 Aug 2026v2.2Clarified the PallasMark–RecRam Inc. brand relationship and removed draft placeholders and contact email inconsistencies.
- 18 Jul 2026v2.1Added an account and data deletion section (Google Play Data Safety requirement)
- 03 Jul 2026v2.0Initial version — prepared with real company details (tokenized).