This policy explains how we process personal data when you use the bipanel website, customer portal, and license and update services. It is written to meet the transparency requirements of the EU/UK General Data Protection Regulation (GDPR), Türkiye's Personal Data Protection Law No. 6698 (KVKK) and similar laws.
Who is responsible
The data controller is:
- [Company legal name]
- Address: [Address]
- Email: [email protected]
- Website: bipanel.io
What we collect
- Account and billing details: name, email, phone, company, billing address and tax details.
- Payment details: payments are processed by Stripe. We never see or store your card number; Stripe tells us the card brand, last four digits and payment result.
- License and installation data: when your bipanel installation validates its license or checks for updates, it sends the server name, IP address, bipanel version, install type and number of hosting accounts. The sites, databases and email on your server, and your customers' data, never reach us.
- Support and contact: support tickets, contact form messages and email correspondence.
- Technical logs: IP address, browser details, sign-in and activity logs, kept for security.
Data on your own servers
bipanel is software that runs on your server. You are the controller of the data you host there; we don't access or process it.
Why we use it, and our legal bases
- To run your account, sell and deliver licenses, take payments and issue invoices, validate licenses and provide updates and support: performance of a contract.
- To keep tax and accounting records: legal obligation.
- To secure the service and prevent abuse and fraud, and to improve the product: legitimate interests.
- To send release and offer announcements: your consent, which you can withdraw at any time from the portal or via the link in each email.
Sharing and international transfers
We don't sell your data. We share it only with providers we need to run the service: Stripe (payments), and our hosting and email delivery providers. Some are located in the United States; transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, for data from Türkiye, the safeguards required by Article 9 of KVKK. We may disclose data to authorities where the law requires it.
Cookies
We only use cookies that the site and portal need to work, with no advertising or tracking cookies. See the cookie policy.
Retention and security
We keep data while your account is open and for as long as tax and commercial law requires afterwards (typically up to 10 years for billing records). Passwords are stored as one-way hashes, connections are encrypted with TLS, and secret keys are stored encrypted.
Your rights
Depending on where you live, you can ask to access, correct, delete, restrict or port your data, object to processing, and withdraw consent. Email [email protected]; we respond within 30 days. You can also complain to your local data protection authority (for example, an EU supervisory authority or Türkiye's Personal Data Protection Authority).
Changes
We may update this policy and will announce material changes by email or in the customer portal.