Data Privacy & Security

Protected data.
Controlled access.

Your data is stored securely, and access is limited to authorised people only.

Role-based access

Agency team
  • NOVA KOZMETİKAccess granted
  • PERA AYAKKABINo access
  • KUZEY OUTDOORNo access

Enforced at the database level

Our commitments

Not with badges, but with how we work

Security isn't a label we attach — it's a set of rules enforced in every layer of the product.

KVKK compliance

Personal data is processed under Turkey's Personal Data Protection Law No. 6698 (KVKK). Our privacy notice, data controller details and your rights of application are set out clearly in our legal documents.

Privacy policy

Encryption in transit and at rest

Dashboard and API traffic is encrypted with TLS. Access keys for your ad and store connections are stored encrypted in the database and are never shown in plain text in the dashboard.

Brand isolation

Every user sees only the brands they are assigned to. This rule is enforced not in the interface but in the database, through row-level access rules — an unauthorised request never reaches the data.

How we protect your data

We built security as the foundation of the product, not as a layer added later. Every new feature goes through the same access rules.

Role-based access

Agency, brand and admin roles are kept separate. Only authorised roles can perform management and integration actions.

Official connections

We connect to ad and store platforms through official authorisation (OAuth) or the API keys the platform issues. We never ask for your account password.

Keys stay on the server

Access keys are reachable only by the server components that sync your data. They never reach the browser or client-side code.

FlyPilot follows the same rules

Our AI assistant sees only the data of brands you are authorised for, and it always asks for your approval before taking any action in your ad account.

Infrastructure & backups

Data is held with trusted cloud providers and backed up regularly. System access is logged.

Vulnerability disclosure

If you believe you've found a security vulnerability, write to info@cirofly.com. We review every report and get back to you.

Have a question on your mind?

Ask us anything about security, KVKK or how we process data.