dmu ONE PRIVACY POLICY

Last Update: 18 August 2026 Effective Date: 18 August 2026

As dmu ONE, we attach importance to the privacy of our users and the protection of their data.

This Privacy Policy; It has been prepared to explain how the data created by the user during the use of the dmu ONE mobile application, entered into the application or processed within the scope of the operation of the application is handled.

dmu ONE is an application developed to help users manage finance, inventory, sales, human resources, projects, operations and similar business processes.

dmu ONE's basic privacy approach is as simple as possible:

The user's business data belongs to the user.

In the basic operating model of dmu ONE, the business data created within the application is kept on the user's device. dmu ONE does not store this data on a central dmu ONE server, use it for commercial purposes, sell it or transfer it to third parties for marketing purposes, unless expressly stated otherwise.


1. SCOPE

This Privacy Policy covers the dmu ONE mobile application and the data processing activities carried out during the use of the application.

In particular, the policy governs the following issues:


2. APPLICABLE LEGISLATION

Personal data processing activities carried out by dmu ONE are carried out by taking into account the following regulations, to the extent relevant:

In cases where dmu ONE is offered to users in the European Union or the European Economic Area and the relevant legislation falls within the scope of application, the provisions of the European Union General Data Protection Regulation ("GDPR - Regulation (EU) 2016/679") are also taken into account, to the extent relevant.

Since each country's data protection legislation may differ, if dmu ONE is used in different countries, the mandatory data protection provisions of the relevant country may also apply.


3. BASIC PRIVACY PRINCIPLE

dmu ONE, as much as possible local data storage It is designed to work on the principle of

The business records that the user enters into the application are basically stored on the user's device.

For example:

can be shown.

The processing of this data on the device does not mean that the data in question is automatically sent to dmu ONE or stored centrally by dmu ONE.


4. DATA ENTERED BY THE USER INTO THE APPLICATION

Since dmu ONE is a business management application, the user can create various information within the application.

This information may contain personal data depending on the user's usage style.

For example, the user;

can enter.

The user decides whether to enter this data into the application or not.

dmu ONE is not responsible for the lawful acquisition of information belonging to third parties that the user enters into the application within the scope of his/her own business activities.

User; It is obliged to act in accordance with the relevant data protection legislation when recording personal data of its employees, customers, suppliers or other third parties into the application.


5. DIFFERENCE OF DATA CONTROLLER ROLES

In terms of KVKK, "data controller" is the natural or legal person who determines the purposes and means of processing personal data.

In terms of the records kept by a business about its employees, customers or suppliers within dmu ONE, the relevant business or user may be the data controller for the personal data in question, depending on the characteristics of the concrete case.

For example, if a business records an employee's salary, leave or contact information in dmu ONE, it is the business that decides why this data will be recorded and how it will be used.

The fact that dmu ONE only provides the software infrastructure running on the device does not automatically make dmu ONE the data controller of all personal data entered into the application by the user.

In cases where dmu ONE collects or processes personal data directly for its own purposes, data liability is also evaluated in terms of the relevant activity.


6. DATA NOT ACCESSED BY dmu ONE

In the basic local operating model of dmu ONE, business records created by the user in the application are not displayed centrally by dmu ONE.

Therefore, dmu ONE is located on the user's device unless there is a central transfer;

can't see.

Having the data on the user's device and collecting it by dmu ONE are different.


7. PURPOSES OF PROCESSING DATA

In cases where personal data processing is required by dmu ONE, data may only be processed for the purposes necessary for the relevant processing activity.

These are in particular:

may include purposes.

Personal data will not be used in a way that is incompatible with the purpose for which they were collected.


8. BASIC PRINCIPLES IN THE PROCESSING OF PERSONAL DATA

dmu ONE aims to act in accordance with the basic principles stipulated in the KVKK in cases where personal data is processed.

In this context, personal data;

is taken as basis.


9. LEGAL REASONS FOR PROCESSING PERSONAL DATA

In cases where personal data must be directly processed by dmu ONE, the processing activity is based on one of the appropriate legal grounds regulated in the KVKK according to the concrete processing activity.

These are relevant:

There may be legal reasons such as.

If there is a processing activity that requires explicit consent, explicit consent is also obtained from the relevant user.


10. SPECIAL PERSONAL DATA

dmu ONE is not intended to require the user to enter sensitive personal data.

Users are advised not to enter unnecessary sensitive personal data into free text fields or other registration fields within the application.

If the user processes special personal data about its employees or other persons, it is the responsibility of the user or the relevant business to process this data in accordance with the law and to take the necessary technical/administrative measures.


11. FINANCIAL DATA

One of the core functions of dmu ONE is finance and business management.

Therefore, the user can apply;

You can enter financial information such as.

This information may be processed in order to perform the relevant functions of the application on the user's device.

This data is not considered centrally collected by dmu ONE as long as it is kept solely on the user's device.


12. PERSONNEL DATA

If the human resources module is used, the user can create various records regarding his employees.

The relevant user or business is responsible for creating these records in accordance with the law.

dmu ONE merely provides the technical means through which such information can be managed by the user.

Before recording personal data regarding its employees, the user must fulfill its disclosure, data security and other obligations, when necessary, arising from KVKK and other applicable legislation.


13. BACKUP

Using the backup functions offered by dmu ONE may be optional.

If the user uses the backup function, the data may be processed in accordance with the technical requirements of the selected backup method.

If the user stores the backup file via email, cloud storage, device storage or any other third-party service, the relevant third-party service provider's own privacy policies and terms of use may apply.

dmu ONE is not responsible for the security of independent third-party storage or communication services used by the user at his own discretion.

The user is responsible for keeping his backups securely.


14. STORAGE OF DATA

Local data created on the device may remain on the device until it is deleted by the user, the application data is cleared, or is removed by the operating system as a result of uninstalling the application.

If there is a limited category of data that dmu ONE collects centrally, this data is stored only for the period necessary for the relevant processing purpose or regulatory obligations.

If the storage period expires, deletion, destruction or anonymization methods may be applied in accordance with the applicable legislation.


15. DELETION OF DATA

The user can delete the records he has created by using the data deletion functions offered in the application.

If the bulk data reset feature offered by the application is used, application data on the device may be deleted.

Deletions may be irreversible.

Therefore, it is recommended that users create a suitable backup before deleting important records.


16. DATA SHARING WITH THIRD PARTIES

dmu ONE does not sell the business data the user enters into the application to advertisers.

dmu ONE does not provide users' business records to third parties for marketing purposes.

Personal data only;

It can be transferred in legal situations such as.

If any third-party service provider is used, the transfer is limited only to the extent necessary for the relevant service.


17. DATA USE FOR ADVERTISING PURPOSES

dmu ONE does not use the financial, commercial, employee, customer or supplier data that users enter into the application for the purpose of creating a behavioral advertising profile.

This data is not sold to advertising companies, and no ad targeting profiles are created from users' business records.


18. TRANSFER OF DATA ABROAD

In the basic on-device data processing model of dmu ONE, it is not possible for dmu ONE to centrally transfer abroad the business records entered into the application by the user.

However, if the user chooses to back up via an e-mail, cloud storage or similar third-party service with servers abroad, the data may be processed in the infrastructure of the relevant service provider.

If there is any international data transfer to be carried out directly by dmu ONE, the relevant transfer is carried out in accordance with the provisions of the KVKK regarding the transfer of personal data abroad and other applicable legislation.


19. DATA SECURITY

dmu ONE personal data;

It aims to implement reasonable technical and organizational measures to prevent

However, no software, device or electronic data storage system can provide absolute security.

The user;

recommended.


20. DEVICE LOSS OR MALFUNCTION

As a natural consequence of dmu ONE's local data storage model, the device;

In such cases, local data may be lost.

If a current backup is not available, it may not be possible to restore this data by dmu ONE.

Therefore, the responsibility for data backup belongs to the user.


21. APPLICATION PERMISSIONS

dmu ONE only aims to request device permissions necessary to perform the functions of the application.

When a device permission is required for a particular feature, the user is notified by the operating system and has the option to grant or deny permission where necessary.

Denying permissions may prevent the relevant function from working, but to the extent possible it will not prevent the use of other functions of the application.


22. ANALYTICS AND ERROR REPORTING

In order to monitor the technical performance of dmu ONE, identify errors or improve the application, technical information that is anonymous or that cannot be associated with the user as much as possible may be processed.

If third-party analysis or error reporting services are used, these services and the categories of data processed are separately disclosed within this Privacy Policy.

dmu ONE is not intended to use financial or commercial content entered into the application for analytical purposes.


23. COOKIES

It may not be necessary to use classic web cookies for the basic functions of the mobile application to work.

When the dmu ONE website is visited, the cookies and similar technologies used can also be explained within the scope of the website's Cookie Policy.


24. CHILDREN'S PRIVACY

dmu ONE has been developed mainly for business, entrepreneurial and professional users.

The application is not designed as a service for children.

dmu ONE does not aim to knowingly collect personal data from children in violation of applicable legislation.


25. RIGHTS OF THE RELATED PERSON UNDER KVKK

Within the scope of Article 11 of KVKK No. 6698, if the conditions are met, the relevant persons can apply to the data controller;

has the rights.

The applicability of these rights is assessed according to whether dmu ONE has the relevant personal data and its legal role in the relevant processing activity.

It may not be technically possible for dmu ONE to view, correct or delete data that dmu ONE does not access in any way and that is only on the user's device.


26. RIGHTS UNDER GDPR

Where the GDPR is applicable, data subjects may, to the extent their conditions apply;

may have rights.

In addition, data subjects may have the right to appeal to the competent data protection authority.


27. AUTOMATED DECISION MAKING

dmu ONE's core business management functions are not intended to make fully automated decisions that have legal consequences for the user or that affect the user in a similarly significant way.

Reports, calculations, statistics or recommendations generated by the application are intended to assist the user.

The final business, financial, legal, tax or managerial decision rests with the user.


28. FINANCIAL AND LEGAL RESPONSIBILITY

dmu ONE is a business management tool.

Calculations, reports or other outputs presented by the application are professional;

It is not a service.

The user is responsible for fulfilling his/her official accounting, tax, payroll or other legal obligations.


29. DATA BREACH

In the event of a security breach regarding the personal data processed by dmu ONE as the data controller, the necessary evaluations and notifications are made in line with the obligations stipulated in the applicable legislation.

Device security is the responsibility of the user with respect to data that resides only on the user's device and to which dmu ONE does not have access.


30. THIRD PARTY SERVICES

dmu ONE may interact with the operating system or third-party services to perform some features.

For example, by the user's own choice;

can use.

Once the user chooses to transfer data to a service other than dmu ONE, the privacy policy of the relevant service provider may apply.


31. GOOGLE PLAY AND DATA SECURITY

dmu ONE, when distributed through Google Play, aims to provide the necessary disclosures in accordance with Google Play's user data and data security policies.

"Data Safety" information provided on Google Play is kept up to date to reflect the data processing practices in the current version of the application.

If a new data collection method, SDK or third-party integration is added to the application, the relevant statements will be updated as necessary.


32. POLICY CHANGES

As dmu ONE evolves, new features may be added and existing features may be modified.

Therefore, this Privacy Policy;

It may be updated for reasons such as.

If significant changes are made, the "Last Updated" date on the policy is changed and users are informed by appropriate methods when necessary.


33. CURRENT VERSION OF THE POLICY

dmu ONE's current Privacy Policy is published on DMU's official website.

The privacy policy link on Google Play is also directed to this updated text.

Users are encouraged to review the policy periodically.


34. CONTACT AND KVKK APPLICATIONS

For requests regarding this Privacy Policy, dmu ONE's data processing practices, or the protection of personal data, DMU can be contacted through the following communication channels.

Data Controller / Service Provider: [Full trade/name information of DMU]

Address: [Official address]

Email: [KVKK/Privacy e-mail address]

Website: [DMU website]

Applications within the scope of KVKK can be made in accordance with the methods specified in the relevant legislation.

Depending on the nature of the application, additional information may be requested to verify the identity of the applicant.


35. FINAL PROVISIONS

Users are encouraged to review this Privacy Policy before starting to use dmu ONE.

The main purpose of this Policy is to explain to users the application's data processing approach in a clear and understandable manner.

The basic principle of dmu ONE's approach to privacy is this:

Your business's data is your data.

Business records you create within the scope of dmu ONE's on-device core features will remain on your device unless explicitly stated otherwise.

dmu ONE is not intended to sell this data, create advertising profiles or track users' commercial activities.

The Courts of İzmir, Republic of Türkiye, have jurisdiction.