Dosyon
Back to home

Privacy and data protection notice

This page explains the main data categories used by Dosyon's beta, self-service subscription, and external information flows. Live payments open only when the controller identity and support address below are fully configured.

Identity and scope

The party operating the beta service: Opsida. Live use and payment with real customer or employee data must not begin before the full legal name and contact details are disclosed.

What data do we process?

  • Email address and secure session records when an account is created.
  • Selected plan, billing period, terms version, and subscription status.
  • Company, tax, address, and contact details in an invoice request.
  • The workbook you choose to upload and the app data created from it.
  • Full name, email, optional organization or phone, submitted information, consent time, and notice version in an external information form.
  • Limited technical logs for security, debugging, and service quality.
  • The path of the first page you landed on, any UTM values in that address, the referring site's domain, and a random number stored in your browser.

Purpose, sharing, and retention

Data is processed to verify accounts, create drafts from files, operate apps, manage subscriptions and invoices, provide security, and support users. Identity and app data are processed on Supabase (database, Frankfurt — eu-central-1) and Vercel (hosting, Frankfurt — fra1). Account verification, invitation, reminder and notice emails are sent through Brevo, which receives the recipient's email address together with the subject and body of the message. Payment and subscription data are processed through Paddle, and card numbers never reach Dosyon servers. Domain and DNS are managed by Squarespace. Vercel's visit and page-speed measurement runs on the site's pages and is processed through Tinybird (Spain), Vercel's analytics subprocessor. Error tracking is bundled but not configured in production; when configured, error reports are sent to Sentry. All of these providers are established outside Türkiye; the standard contracts required under KVKK art. 9 have not yet been signed and notified to the Authority.

The company sharing an external information form determines the processing purpose; Dosyon provides the form and retention infrastructure. Externally submitted information receives a deletion date 180 days after creation, and a company manager may permanently delete it earlier.

Chart readings are off by default and run only when a workspace admin turns them on. When on, only a chart's summary — how many categories there are and the corresponding figures — is sent to a language model (today openai/gpt-4o-mini) through OpenRouter. Category names are replaced by codes such as K1 and K2 before sending and restored on the way back to you; records, rows and fields whose visibility is restricted are never sent. While the feature is off, no chart-reading request reaches this provider at all. As a separate second flow, a column-mapping assistant may be enabled when you upload a file; when it is on, only sheet names, column headers and inferred data types are sent to the same provider. Cell values, rows and personal data are not sent in that flow either.

To see which page actually works, a first-party cookie (dsy_attr) is written in your browser holding the path of the first page you saw, any UTM values in that address, the referring site's domain, and a random number; it expires after 90 days. This information only reaches Dosyon's own server: no third-party analytics service or ad network is used and no external tracking script is added to any page. The events kept alongside the cookie contain no email, name, file name or cell value, and no IP address is stored. If you block cookies the product works exactly the same; your visit is simply counted as unknown.

To improve the product we may keep aggregate, de-identified schema statistics: how many columns a file had, the distribution of data types, the shape of the table relationships we detected, and the kinds of corrections made during conversion. These statistics contain no cell values, person names, company names, file names or file contents, and are not used in a way that can be traced back to a single workspace.

Choice, deletion, and requests

A plan preference alone does not grant paid access; entitlements open only after a signed payment-provider notification. You can request access, correction, export, or deletion through support. Requests are handled manually until self-service deletion is available; payment and invoice records subject to legal retention may be excluded.