Privacy Policy
Last updated: April 27, 2026 · Effective date: April 27, 2026
At Vidyon, we are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Vidyon platform. It complies with the General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK — Law No. 6698).
1. Data Controller
Vidyon is the data controller responsible for your personal data. If you have questions about how your data is handled, you can contact us at: privacy@vidyon.tv
2. Data We Collect
We collect the following categories of personal data:
2.1 Account and Identity Data
- Full name and email address (provided at registration)
- Hashed password (never stored in plain text)
- Profile information you choose to provide
2.2 Usage and Technical Data
- IP address, browser type, and operating system
- Pages visited, features used, and session duration
- Error logs and diagnostic information
2.3 Device Data
- Device identifiers and pairing codes for registered TV devices
- Device status, online/offline events, and command history
2.4 Content Data
- Media files, slide content, playlists, and schedules you create or upload
- Organization and team membership information
3. How We Use Your Data
We use your personal data for the following purposes:
- Service provision: To create and manage your account, authenticate sessions, and deliver the features of the platform
- Communication: To send transactional emails (e.g., password reset, invitations, billing notifications)
- Security: To detect and prevent fraud, abuse, and unauthorized access
- Service improvement: To analyze usage patterns and improve the platform's performance and features
- Legal compliance: To comply with applicable laws and legal obligations
4. Legal Basis for Processing
Under GDPR, we process your personal data on the following legal bases:
- Contractual necessity: Processing required to perform the contract (Terms of Service) with you
- Legitimate interests: Security monitoring, fraud prevention, and service improvement
- Legal obligation: Compliance with applicable laws
- Consent: For optional marketing communications (you can withdraw consent at any time)
5. Data Sharing and Third Parties
We do not sell your personal data. We may share data with the following categories of third parties solely to operate the Service:
- Cloud infrastructure providers (e.g., hosting, storage, database) — subject to data processing agreements
- Email delivery services — to send transactional emails on our behalf
- Analytics providers — for aggregated, anonymized usage analytics
- Legal authorities — only when required by law or to protect our legal rights
All third-party processors are bound by data processing agreements and are required to protect your data in accordance with applicable law.
6. International Data Transfers
Your data may be processed in countries outside your own. When transferring data outside the European Economic Area (EEA) or Turkey, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Data Retention
We retain your data for the following periods:
- Account data: For the duration of your account, plus up to 90 days after deletion to allow recovery
- Usage logs: Up to 12 months
- Financial records: As required by applicable tax and accounting laws (typically 5–10 years)
- Deleted content: Purged within 30 days of deletion
8. Your Rights
Under GDPR and KVKK, you have the following rights regarding your personal data:
- Right of access: Request a copy of your personal data
- Right to rectification: Correct inaccurate or incomplete data
- Right to erasure: Request deletion of your data ("right to be forgotten")
- Right to restriction: Restrict how we process your data
- Right to data portability: Receive your data in a machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent at any time where processing is consent-based
To exercise any of these rights, contact us at privacy@vidyon.tv. We will respond within 30 days.
9. Cookies
We use the following types of cookies:
- Essential cookies: Required for authentication and core platform functionality (cannot be disabled)
- Preference cookies: Store your language and display preferences
- Analytics cookies: Help us understand how the Service is used (you may opt out)
You can control cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.
10. Data Security
We implement appropriate technical and organizational security measures, including:
- TLS encryption for all data in transit
- Encryption of sensitive data at rest
- Access controls and principle of least privilege
- Regular security reviews and vulnerability assessments
Despite our efforts, no transmission over the internet is 100% secure. You use the Service at your own risk.
11. Children's Privacy
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes.
13. Contact and Complaints
For questions or concerns about this Privacy Policy or how we handle your data, contact us at: privacy@vidyon.tv
If you are located in the EU/EEA, you have the right to lodge a complaint with your local supervisory authority. If you are located in Turkey, you may apply to the Personal Data Protection Authority (KVKK — www.kvkk.gov.tr).