Privacy notice
Last updated 22 September 2026
1. Who we are
BRİFTEK REKLAM YAZILIM TİCARET LİMİTED ŞİRKETİ, Caferağa Mah. Moda Cad. No:5 Kadıköy/İSTANBUL, is the controller of the personal data described here. For any privacy question or request, write to support@briftek.com.tr.
2. What this notice covers
Everything DAX does with personal data: the public pages of the Open Web Ad Experience Index, the free media plan snapshot, audit requests, and customer accounts with the analyses, orders, lists and sites in them. How the service itself works is set out in the terms of service.
3. What we process, why, and on what basis
Free snapshot
You give us a benchmark market and up to 5 website domains. We use them only to produce your snapshot. To do so we look the domains up in Google’s Chrome UX Report API, which returns public, aggregated measurements; nothing about you is sent to Google, only the domain names. Domain names of websites are normally not personal data. We keep only what your result page shows, so that your result link keeps working.
Your IP address
To limit free snapshots, sign-ups, sign-in attempts and site checks, we count requests per IP address or account in the server’s memory. These counters are not written to disk and are cleared within a day. Our hosting provider may keep technical access logs, which include IP addresses, for up to 30 days for security. The legal basis is our legitimate interest in protecting the service (GDPR Art. 6(1)(f)).
Audit requests
If you ask for the full audit from a snapshot, we process your work email, your company and message if you add them, the snapshot concerned, and the time of your request and consent, only to contact you about the audit. The legal basis is your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time by writing to support@briftek.com.tr.
Your account and team
Your name, work email, company name and the kind of company you say it is, the language you use, when you confirmed your email and last signed in, and your role in the team. We never store your password, only an irreversible hash of it. When an owner invites a colleague, we process the colleague’s email to send the invitation. We use this to create and run the account, sign you in, manage the team and send the emails the service needs. The legal basis is the contract with your company (GDPR Art. 6(1)(b)) and, for colleagues, our legitimate interest in providing the service your company ordered (Art. 6(1)(f)).
Invoicing, orders and payments
The company name, the contact person, billing email and phone, tax number and office, and invoice address; each order, its amount and when it was paid. Payment is by bank transfer: we see the sender and reference on our bank statement to match the payment, and we do not store card or bank account details. We use this to take orders, open access and invoice. The legal bases are the contract (Art. 6(1)(b)) and our legal obligation to keep commercial and tax records (Art. 6(1)(c)).
Analyses and saved lists
When you analyse a media plan, an Excel file is read in your own browser and only the columns DAX needs are sent to us: website domains, and where present the category, format, device, CPM and budget of each line. The file itself does not leave your computer. Plans are not expected to contain personal data; please do not put any in them. Analyses, saved site lists and their rules are visible only to your company, are never added to the benchmark other customers are scored against, and are kept in the market they belong to. The legal basis is the contract (Art. 6(1)(b)).
Site verification and correction requests
If you add a site to prove it is yours, we process its domain, the verification code, how and when it was verified, and who added it. To check, we look up the site’s DNS records and may request one small file from the site. If you ask for a correction, we process what you write. We use this to handle corrections to our lists. The legal basis is the contract (Art. 6(1)(b)).
Emails
We send the emails the service needs: confirming your email, password resets, invitations, orders and payments, reminders before access ends, changes to saved lists, and Site Monitor updates. Our administrators are told of new sign-ups, orders and correction requests, with the name, email and company concerned, so that they can act on them. The legal bases are the contract (Art. 6(1)(b)) and our legitimate interest in running the service (Art. 6(1)(f)). We do not send newsletters or advertising.
4. Cookies and browser storage
When you sign in, we set one cookie that keeps you signed in: it holds a random code (we store only a hash of it), cannot be read by scripts and expires after 30 days or when you sign out. It is strictly necessary for the signed-in service. We use no advertising or analytics cookies. On analysis pages the browser remembers only whether you opened or closed the report guide; this stays on your device.
5. Who receives your data
Our hosting provider, Amazon Web Services (AWS), Frankfurt, Germany, which stores the data and its backups on our behalf; and Amazon Web Services (Amazon SES), United States, through which emails are sent, which therefore receives your email address and the email. Google receives only website domain names. We share data with authorities only where the law requires it. We do not sell personal data.
Where a provider processes data outside the European Economic Area or Turkey, the transfer is protected by the safeguards the law requires, such as the European Commission’s standard contractual clauses or the standard contracts under Turkish law.
6. How long we keep it
- Snapshot summaries: 12 months.
- Audit requests: 24 months after our last contact with you, or until you withdraw consent, whichever is earlier.
- Accounts, team members, analyses, saved lists, sites and correction requests: while the account exists. The owner can delete the account on the account page, which deletes them at once; if you ask us instead, we delete them within 30 days.
- Orders and invoicing records: 10 years, as commercial and tax law requires, also after the account is deleted.
- Sign-in sessions: up to 30 days. Email confirmation, password and invitation links: 2 hours to 7 days.
- Backups: 30 days, after which each backup is overwritten.
- Request counters in memory: one day. Access logs: up to 30 days.
7. Your rights
You can ask us for access to your data, to correct or delete it, to restrict or object to its use, and to receive it in a portable format. Write to support@briftek.com.tr; we will answer within one month. If you think we have not handled your data properly, you can complain to the data protection authority where you live or work — in Turkey, the Personal Data Protection Authority (KVKK).
8. Changes
If we change how we process personal data, we will update this notice and its date, and tell account owners of material changes by email.