KVKK compliance
Personal data is processed under Turkey's Personal Data Protection Law No. 6698 (KVKK). Our privacy notice, data controller details and your rights of application are set out clearly in our legal documents.
Privacy policy
Your data is stored securely, and access is limited to authorised people only.
Role-based access
Agency teamEnforced at the database level
Security isn't a label we attach — it's a set of rules enforced in every layer of the product.
Personal data is processed under Turkey's Personal Data Protection Law No. 6698 (KVKK). Our privacy notice, data controller details and your rights of application are set out clearly in our legal documents.
Privacy policyDashboard and API traffic is encrypted with TLS. Access keys for your ad and store connections are stored encrypted in the database and are never shown in plain text in the dashboard.
Every user sees only the brands they are assigned to. This rule is enforced not in the interface but in the database, through row-level access rules — an unauthorised request never reaches the data.
We built security as the foundation of the product, not as a layer added later. Every new feature goes through the same access rules.
Agency, brand and admin roles are kept separate. Only authorised roles can perform management and integration actions.
We connect to ad and store platforms through official authorisation (OAuth) or the API keys the platform issues. We never ask for your account password.
Access keys are reachable only by the server components that sync your data. They never reach the browser or client-side code.
Our AI assistant sees only the data of brands you are authorised for, and it always asks for your approval before taking any action in your ad account.
Data is held with trusted cloud providers and backed up regularly. System access is logged.
If you believe you've found a security vulnerability, write to info@cirofly.com. We review every report and get back to you.
Ask us anything about security, KVKK or how we process data.