Privacy Policy
This is a courtesy translation provided for convenience. The legally binding version is the Gizlilik PolitikasΔ± (Turkish).
Data controller: digitalforce360 OΓ (Estonian registry code 16940165), Narva mnt 5, Kesklinna linnaosa, 10117 Tallinn, Estonia. Contact: legal@ohana360.com
1. Scope
This policy explains the personal data processed when you use the Ohana360 cloud CRM service (web and mobile). Ohana360 is a multi-tenant business application: each organization owns its own data.
2. Data we process
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, password (stored irreversibly with bcrypt) | Account creation, authentication, session management | Performance of contract |
| Your organization's CRM records (customers, contacts, deals, cases and similar) | Providing the service; the content of these records is controlled by your organization | Performance of contract |
| Usage and audit logs (logins, administrative actions, IP-based rate limiting) | Security, abuse prevention, troubleshooting | Legitimate interest |
| Session cookie (ohana_sess) and mobile session token | Maintaining your session (essential; no ad or tracking cookies) | Legitimate interest |
| Push notification subscription (only if you enable it) | Delivering notifications | Consent |
3. Sharing
Your personal data is never sold and never shared with third parties for advertising. Data is hosted only with the infrastructure providers required to run the service (hosting: Hostinger; transactional email is sent from the server). Disclosure to competent authorities may occur where legally required.
4. Retention and deletion
You can permanently delete your account in the app via User Menu > Delete My Account. If you are the last user, the organization and all its data are deleted. Deleted data rolls off backups within at most 7 days (backups are kept on a 7-day cycle). You may also request deletion by email.
5. Your rights (KVKK art. 11 and GDPR art. 15-22)
You have the rights of access, rectification, erasure, restriction of processing, portability and objection. Write to the contact address above; requests are answered within 30 days at the latest. Under the GDPR you may also lodge a complaint with your local supervisory authority.
6. Security
All traffic is encrypted with HTTPS. Passwords are stored with bcrypt, sessions are protected by HttpOnly cookies or device-specific tokens, and optional two-factor authentication (2FA) is offered. Database access uses parameterized queries and administrative actions are recorded in the audit log.
7. Children's privacy
Ohana360 is a business application and is not directed at persons under 16.
8. Changes
Updates to this policy are published on this page; significant changes are announced in the app.
Ready to see it with your own data?
Create your organization in minutes. Free to start, no credit card required.