dmu ONE PRIVACY POLICY
Last Update: 18 August 2026 Effective Date: 18 August 2026
As dmu ONE, we attach importance to the privacy of our users and the protection of their data.
This Privacy Policy; It has been prepared to explain how the data created by the user during the use of the dmu ONE mobile application, entered into the application or processed within the scope of the operation of the application is handled.
dmu ONE is an application developed to help users manage finance, inventory, sales, human resources, projects, operations and similar business processes.
dmu ONE's basic privacy approach is as simple as possible:
The user's business data belongs to the user.
In the basic operating model of dmu ONE, the business data created within the application is kept on the user's device. dmu ONE does not store this data on a central dmu ONE server, use it for commercial purposes, sell it or transfer it to third parties for marketing purposes, unless expressly stated otherwise.
1. SCOPE
This Privacy Policy covers the dmu ONE mobile application and the data processing activities carried out during the use of the application.
In particular, the policy governs the following issues:
- information entered into the application by the user,
- business and financial records,
- personnel and human resources records,
- stock and product records,
- customer and supplier records,
- project and operation records,
- application settings,
- backup and restore operations,
- data storage operations performed on the device,
- limited data processing activities that may be technically necessary,
- users' rights regarding their personal data.
2. APPLICABLE LEGISLATION
Personal data processing activities carried out by dmu ONE are carried out by taking into account the following regulations, to the extent relevant:
- Personal Data Protection Law No. 6698 ("KVKK"),
- Regulations and communiqués issued within the scope of KVKK,
- Personal Data Protection Board decisions,
- relevant electronic communications and electronic commerce legislation,
- Applicable legislation on consumer protection,
- Other applicable Republic of Türkiye legislation regarding information security and protection of personal data.
In cases where dmu ONE is offered to users in the European Union or the European Economic Area and the relevant legislation falls within the scope of application, the provisions of the European Union General Data Protection Regulation ("GDPR - Regulation (EU) 2016/679") are also taken into account, to the extent relevant.
Since each country's data protection legislation may differ, if dmu ONE is used in different countries, the mandatory data protection provisions of the relevant country may also apply.
3. BASIC PRIVACY PRINCIPLE
dmu ONE, as much as possible local data storage It is designed to work on the principle of
The business records that the user enters into the application are basically stored on the user's device.
For example:
- they come,
- expenses,
- debts,
- they will receive,
- cash registers,
- bank records,
- sales,
- acquisitions,
- products,
- stock records,
- suppliers,
- customers,
- personnel records,
- salaries,
- advances,
- permissions,
- overtime,
- projects,
- operations,
- tasks,
- reports
can be shown.
The processing of this data on the device does not mean that the data in question is automatically sent to dmu ONE or stored centrally by dmu ONE.
4. DATA ENTERED BY THE USER INTO THE APPLICATION
Since dmu ONE is a business management application, the user can create various information within the application.
This information may contain personal data depending on the user's usage style.
For example, the user;
- customer name,
- supplier name,
- employee name and surname,
- phone number,
- email address,
- task or position information,
- salary information,
- working information,
- financial records,
- business transaction information
can enter.
The user decides whether to enter this data into the application or not.
dmu ONE is not responsible for the lawful acquisition of information belonging to third parties that the user enters into the application within the scope of his/her own business activities.
User; It is obliged to act in accordance with the relevant data protection legislation when recording personal data of its employees, customers, suppliers or other third parties into the application.
5. DIFFERENCE OF DATA CONTROLLER ROLES
In terms of KVKK, "data controller" is the natural or legal person who determines the purposes and means of processing personal data.
In terms of the records kept by a business about its employees, customers or suppliers within dmu ONE, the relevant business or user may be the data controller for the personal data in question, depending on the characteristics of the concrete case.
For example, if a business records an employee's salary, leave or contact information in dmu ONE, it is the business that decides why this data will be recorded and how it will be used.
The fact that dmu ONE only provides the software infrastructure running on the device does not automatically make dmu ONE the data controller of all personal data entered into the application by the user.
In cases where dmu ONE collects or processes personal data directly for its own purposes, data liability is also evaluated in terms of the relevant activity.
6. DATA NOT ACCESSED BY dmu ONE
In the basic local operating model of dmu ONE, business records created by the user in the application are not displayed centrally by dmu ONE.
Therefore, dmu ONE is located on the user's device unless there is a central transfer;
- how much money you earn,
- how much you spend,
- your debts,
- what they will receive,
- employee salaries,
- stock amounts,
- its customers,
- its suppliers,
- sales,
- projects,
- operations
can't see.
Having the data on the user's device and collecting it by dmu ONE are different.
7. PURPOSES OF PROCESSING DATA
In cases where personal data processing is required by dmu ONE, data may only be processed for the purposes necessary for the relevant processing activity.
These are in particular:
- ensuring the application works,
- Fulfillment of functions requested by the user,
- performing data backup or restoration operations,
- troubleshooting technical problems,
- ensuring security,
- meeting user demands,
- fulfillment of legal obligations,
- Meeting the lawful requests of competent authorities
may include purposes.
Personal data will not be used in a way that is incompatible with the purpose for which they were collected.
8. BASIC PRINCIPLES IN THE PROCESSING OF PERSONAL DATA
dmu ONE aims to act in accordance with the basic principles stipulated in the KVKK in cases where personal data is processed.
In this context, personal data;
- processing in accordance with the law and the rules of honesty,
- be accurate and up to date when necessary,
- processing for specific, clear and legitimate purposes,
- be relevant, limited and proportionate to the purpose for which they are processed,
- be kept for the period required by the relevant legislation or for the purpose for which they are processed.
is taken as basis.
9. LEGAL REASONS FOR PROCESSING PERSONAL DATA
In cases where personal data must be directly processed by dmu ONE, the processing activity is based on one of the appropriate legal grounds regulated in the KVKK according to the concrete processing activity.
These are relevant:
- clearly stipulated in the law,
- is directly related to the establishment or performance of a contract,
- It is mandatory for the data controller to fulfill its legal obligation,
- Data processing is mandatory for the establishment, exercise or protection of a right,
- Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject,
- explicit consent of the person concerned
There may be legal reasons such as.
If there is a processing activity that requires explicit consent, explicit consent is also obtained from the relevant user.
10. SPECIAL PERSONAL DATA
dmu ONE is not intended to require the user to enter sensitive personal data.
Users are advised not to enter unnecessary sensitive personal data into free text fields or other registration fields within the application.
If the user processes special personal data about its employees or other persons, it is the responsibility of the user or the relevant business to process this data in accordance with the law and to take the necessary technical/administrative measures.
11. FINANCIAL DATA
One of the core functions of dmu ONE is finance and business management.
Therefore, the user can apply;
- income,
- expense,
- debt,
- will receive,
- wage,
- advance,
- sales,
- purchasing,
- till,
- bank
You can enter financial information such as.
This information may be processed in order to perform the relevant functions of the application on the user's device.
This data is not considered centrally collected by dmu ONE as long as it is kept solely on the user's device.
12. PERSONNEL DATA
If the human resources module is used, the user can create various records regarding his employees.
The relevant user or business is responsible for creating these records in accordance with the law.
dmu ONE merely provides the technical means through which such information can be managed by the user.
Before recording personal data regarding its employees, the user must fulfill its disclosure, data security and other obligations, when necessary, arising from KVKK and other applicable legislation.
13. BACKUP
Using the backup functions offered by dmu ONE may be optional.
If the user uses the backup function, the data may be processed in accordance with the technical requirements of the selected backup method.
If the user stores the backup file via email, cloud storage, device storage or any other third-party service, the relevant third-party service provider's own privacy policies and terms of use may apply.
dmu ONE is not responsible for the security of independent third-party storage or communication services used by the user at his own discretion.
The user is responsible for keeping his backups securely.
14. STORAGE OF DATA
Local data created on the device may remain on the device until it is deleted by the user, the application data is cleared, or is removed by the operating system as a result of uninstalling the application.
If there is a limited category of data that dmu ONE collects centrally, this data is stored only for the period necessary for the relevant processing purpose or regulatory obligations.
If the storage period expires, deletion, destruction or anonymization methods may be applied in accordance with the applicable legislation.
15. DELETION OF DATA
The user can delete the records he has created by using the data deletion functions offered in the application.
If the bulk data reset feature offered by the application is used, application data on the device may be deleted.
Deletions may be irreversible.
Therefore, it is recommended that users create a suitable backup before deleting important records.
16. DATA SHARING WITH THIRD PARTIES
dmu ONE does not sell the business data the user enters into the application to advertisers.
dmu ONE does not provide users' business records to third parties for marketing purposes.
Personal data only;
- the user's explicit request,
- user-selected integration,
- Compulsory technical service for the provision of the service,
- legal obligation,
- Valid requests of legally authorized public institutions
It can be transferred in legal situations such as.
If any third-party service provider is used, the transfer is limited only to the extent necessary for the relevant service.
17. DATA USE FOR ADVERTISING PURPOSES
dmu ONE does not use the financial, commercial, employee, customer or supplier data that users enter into the application for the purpose of creating a behavioral advertising profile.
This data is not sold to advertising companies, and no ad targeting profiles are created from users' business records.
18. TRANSFER OF DATA ABROAD
In the basic on-device data processing model of dmu ONE, it is not possible for dmu ONE to centrally transfer abroad the business records entered into the application by the user.
However, if the user chooses to back up via an e-mail, cloud storage or similar third-party service with servers abroad, the data may be processed in the infrastructure of the relevant service provider.
If there is any international data transfer to be carried out directly by dmu ONE, the relevant transfer is carried out in accordance with the provisions of the KVKK regarding the transfer of personal data abroad and other applicable legislation.
19. DATA SECURITY
dmu ONE personal data;
- being processed unlawfully,
- unlawful access,
- to disappear,
- to be changed,
- to be viewed by unauthorized persons
It aims to implement reasonable technical and organizational measures to prevent
However, no software, device or electronic data storage system can provide absolute security.
The user;
- using device screen lock,
- Using strong password/PIN,
- keeping your device up to date,
- Do not install applications from unknown sources,
- Keeping your backups in a safe place,
- not share device access with unauthorized persons
recommended.
20. DEVICE LOSS OR MALFUNCTION
As a natural consequence of dmu ONE's local data storage model, the device;
- disappearing,
- being stolen,
- physical harm,
- restoring to factory settings,
- degradation of storage space,
- deletion of data by the operating system
In such cases, local data may be lost.
If a current backup is not available, it may not be possible to restore this data by dmu ONE.
Therefore, the responsibility for data backup belongs to the user.
21. APPLICATION PERMISSIONS
dmu ONE only aims to request device permissions necessary to perform the functions of the application.
When a device permission is required for a particular feature, the user is notified by the operating system and has the option to grant or deny permission where necessary.
Denying permissions may prevent the relevant function from working, but to the extent possible it will not prevent the use of other functions of the application.
22. ANALYTICS AND ERROR REPORTING
In order to monitor the technical performance of dmu ONE, identify errors or improve the application, technical information that is anonymous or that cannot be associated with the user as much as possible may be processed.
If third-party analysis or error reporting services are used, these services and the categories of data processed are separately disclosed within this Privacy Policy.
dmu ONE is not intended to use financial or commercial content entered into the application for analytical purposes.
23. COOKIES
It may not be necessary to use classic web cookies for the basic functions of the mobile application to work.
When the dmu ONE website is visited, the cookies and similar technologies used can also be explained within the scope of the website's Cookie Policy.
24. CHILDREN'S PRIVACY
dmu ONE has been developed mainly for business, entrepreneurial and professional users.
The application is not designed as a service for children.
dmu ONE does not aim to knowingly collect personal data from children in violation of applicable legislation.
25. RIGHTS OF THE RELATED PERSON UNDER KVKK
Within the scope of Article 11 of KVKK No. 6698, if the conditions are met, the relevant persons can apply to the data controller;
- Learning whether personal data is being processed or not,
- Requesting information if personal data has been processed,
- To learn the purpose of processing personal data and whether they are used for their intended purpose,
- Knowing the third parties to whom personal data is transferred at home or abroad,
- Request correction of personal data if it is incomplete or incorrectly processed,
- Requesting the deletion or destruction of personal data within the framework of the conditions stipulated in the law,
- To request correction, deletion or destruction to be notified to third parties to whom the data has been transferred,
- Objecting to the emergence of a result against the person by analyzing the processed data exclusively through automatic systems,
- Requesting compensation for damages in case of damage due to unlawful processing of personal data
has the rights.
The applicability of these rights is assessed according to whether dmu ONE has the relevant personal data and its legal role in the relevant processing activity.
It may not be technically possible for dmu ONE to view, correct or delete data that dmu ONE does not access in any way and that is only on the user's device.
26. RIGHTS UNDER GDPR
Where the GDPR is applicable, data subjects may, to the extent their conditions apply;
- access to personal data,
- correction of data,
- deletion of data,
- limitation of processing,
- objection to processing,
- data portability,
- Withdrawal of consent in consent-based transactions
may have rights.
In addition, data subjects may have the right to appeal to the competent data protection authority.
27. AUTOMATED DECISION MAKING
dmu ONE's core business management functions are not intended to make fully automated decisions that have legal consequences for the user or that affect the user in a similarly significant way.
Reports, calculations, statistics or recommendations generated by the application are intended to assist the user.
The final business, financial, legal, tax or managerial decision rests with the user.
28. FINANCIAL AND LEGAL RESPONSIBILITY
dmu ONE is a business management tool.
Calculations, reports or other outputs presented by the application are professional;
- accounting,
- financial consultancy,
- tax consultancy,
- legal consultancy,
- investment consultancy
It is not a service.
The user is responsible for fulfilling his/her official accounting, tax, payroll or other legal obligations.
29. DATA BREACH
In the event of a security breach regarding the personal data processed by dmu ONE as the data controller, the necessary evaluations and notifications are made in line with the obligations stipulated in the applicable legislation.
Device security is the responsibility of the user with respect to data that resides only on the user's device and to which dmu ONE does not have access.
30. THIRD PARTY SERVICES
dmu ONE may interact with the operating system or third-party services to perform some features.
For example, by the user's own choice;
- email application,
- file manager,
- cloud storage service,
- sharing app
can use.
Once the user chooses to transfer data to a service other than dmu ONE, the privacy policy of the relevant service provider may apply.
31. GOOGLE PLAY AND DATA SECURITY
dmu ONE, when distributed through Google Play, aims to provide the necessary disclosures in accordance with Google Play's user data and data security policies.
"Data Safety" information provided on Google Play is kept up to date to reflect the data processing practices in the current version of the application.
If a new data collection method, SDK or third-party integration is added to the application, the relevant statements will be updated as necessary.
32. POLICY CHANGES
As dmu ONE evolves, new features may be added and existing features may be modified.
Therefore, this Privacy Policy;
- changing application features,
- change of legislation,
- adding new integrations,
- changing data processing methods,
- changing security requirements
It may be updated for reasons such as.
If significant changes are made, the "Last Updated" date on the policy is changed and users are informed by appropriate methods when necessary.
33. CURRENT VERSION OF THE POLICY
dmu ONE's current Privacy Policy is published on DMU's official website.
The privacy policy link on Google Play is also directed to this updated text.
Users are encouraged to review the policy periodically.
34. CONTACT AND KVKK APPLICATIONS
For requests regarding this Privacy Policy, dmu ONE's data processing practices, or the protection of personal data, DMU can be contacted through the following communication channels.
Data Controller / Service Provider: [Full trade/name information of DMU]
Address: [Official address]
Email: [KVKK/Privacy e-mail address]
Website: [DMU website]
Applications within the scope of KVKK can be made in accordance with the methods specified in the relevant legislation.
Depending on the nature of the application, additional information may be requested to verify the identity of the applicant.
35. FINAL PROVISIONS
Users are encouraged to review this Privacy Policy before starting to use dmu ONE.
The main purpose of this Policy is to explain to users the application's data processing approach in a clear and understandable manner.
The basic principle of dmu ONE's approach to privacy is this:
Your business's data is your data.
Business records you create within the scope of dmu ONE's on-device core features will remain on your device unless explicitly stated otherwise.
dmu ONE is not intended to sell this data, create advertising profiles or track users' commercial activities.
The Courts of İzmir, Republic of Türkiye, have jurisdiction.