DIDOSHE OS — Privacy Policy

Este documento aún no está disponible en tu idioma. El texto en inglés que aparece a continuación es la versión aplicable.

Last updated: 26 August 2026

This policy explains how your personal data is processed when you use DIDOSHE OS. It also serves as the privacy notice required by KVKK (Turkish Law No. 6698 on the Protection of Personal Data) art. 10.


1. In short

  • We do not sell your data.
  • We do not use third-party cookies for advertising or tracking.
  • Our AI providers do not use your data to train models.
  • The party that decides about the data belonging to the Studio's own clients is the Studio, not us.
  • You can export your data and delete your account whenever you want (see Terms of Service section 12.2 and the Account Deletion page).

The details are below.

2. Two different roles — this distinction matters

DIDOSHE acts in different roles for different types of data. This decides who you should turn to, and about what.

(a) Data for which DIDOSHE is the data controller

The subscribing Studio's and its users' own data: account details, e-mail, business details, invoice and payment records, support correspondence, application usage records, visits to the marketing website.

For this data, we decide the purpose and the method. This policy applies to that data directly.

(b) Data for which DIDOSHE is the data processor

End Client data that the Studio enters into the system: name, phone, e-mail, appointment history, services and packages purchased, notes, and photographs and health-related records where these exist.

For this data, the data controller is the Studio. We only store and process it on the Studio's instructions. The Studio decides what is collected, how long it is kept and who it is shown to.

(c) Where the same data appears in both roles

Some data falls into both groups, and this is not a contradiction:

  • Staff data: the name, role, working hours and sales record of a Studio's employee are the Studio's data as far as the Studio's own human resources purposes go (we are the processor). The login and authentication record of that same employee is data that we process as data controller, for our purpose of keeping the account secure.
  • Technical records (IP, device, error logs): ours, for security and debugging purposes; the Studio's, to the extent the Studio accesses them for its own audit and reporting purposes.

In every case, whoever decides the purpose also decides the role.

If you are an End Client: for requests about your data, you must first contact the salon where you booked. We forward requests that reach us to the relevant Studio within 72 hours, and we tell you which Studio we sent them to. Answering the request on the merits is the Studio's obligation as data controller.

The contractual counterpart of this split of roles is the Data Processing Agreement (DPA).

3. What data we collect

3.1 About the Studio and its users (role: data controller)

Data Where it comes from Why
Name and surname, e-mail, phone Sign-up form Creating the account, contact
Business name, address, tax details Sign-up / invoicing Forming the contract, invoicing
Password (as an encrypted hash) Sign-up Authentication
Subscription plan, payment status, invoice history Stripe Invoicing, statutory retention
Support requests and correspondence From you Providing support
Login records, IP address, device and browser details Automatic Security, fraud prevention, debugging
In-app usage records Automatic Fixing errors, improving the product
Contact form content From you Responding to your request

Your card details are not stored by us. Payment details are processed and stored by Stripe.

3.2 About End Clients (role: data processor)

Data entered by the Studio: name and surname, phone, e-mail, date of birth (if the Studio enters it), appointment history, services received, packages purchased, payment records, free-text notes, and photographs where these exist.

The Studio decides the scope of this data. A Studio may choose to enter records that amount to health data, such as allergies, skin problems or medication use; in that case it is the Studio's obligation to obtain the necessary explicit consent.

3.3 About End Clients using the public booking page

The name, phone number and chosen service you enter to make a booking are written directly into the relevant Studio's records. DIDOSHE is again a data processor in this operation.

No session cookie is set on this page. The cookies that are set are: functional cookies that remember your language preference, and analytics and marketing cookies subject to your consent. Details are in the Cookie Policy.

Purpose KVKK basis GDPR basis
Creating the account and providing the Service art. 5/2-c (performance of the contract) Art. 6(1)(b)
Invoicing and collection art. 5/2-c and 5/2-ç (legal obligation) Art. 6(1)(b) and (c)
Responding to support requests art. 5/2-c Art. 6(1)(b)
Security, prevention of misuse and fraud art. 5/2-f (legitimate interest) Art. 6(1)(f)
Fixing errors and improving the product art. 5/2-f Art. 6(1)(f)
Meeting legal obligations art. 5/2-ç Art. 6(1)(c)
Product announcements and marketing e-mails explicit consent Art. 6(1)(a)
Storing special-category (health) data entered by the Studio art. 6 — the basis is established by the Studio (see section 2(b)) Art. 9(2)(a) — the basis is established by the Studio

You can stop marketing e-mails at any time, using the link at the bottom of the message or by writing to info@didoshe.co. This does not stop the mandatory notices about your account (invoices, security, changes to the service).

5. Data flow in the AI features

This section sets out plainly which data goes to which provider. All of these features are optional; you can use the whole of the Service without them.

5.1 Reading expenses from a photo of a receipt

The photo of the receipt you take is sent to the API of Anthropic PBC (USA) to be converted into text. Anthropic processes this image only in order to answer the request; it does not use it to train models. Once the operation is finished, the image is not kept on our servers either; only the information extracted from the receipt (amount, date, merchant, category) is written into your record.

Alternative: you can enter the expense record by hand.

5.2 Creating an appointment by voice

The sentence you speak is sent to the AI provider to be converted into text, and the appointment details are extracted from it. Speech is converted to text by ElevenLabs Inc. (USA); the appointment details are then extracted from that text by Anthropic PBC (USA).

In this flow the End Client's name and appointment details may also be passed to the provider, because they are part of the sentence you speak. Your studio's End Client name list is sent to Anthropic so that it can work out which client you mean. If you say a client's name while speaking, that audio also reaches ElevenLabs. No other client details — phone number, e-mail address or address — are sent.

Your voice recording is Your voice recording is not stored on our servers; it is discarded once the operation completes. For the providers' own retention periods, see their privacy policies..

Alternative: you can create the appointment by hand from the calendar.

5.3 Morning voice briefing

The day's appointment list and summary information are turned into text, sent to the ElevenLabs (voice generation) service and read out loud.

In this flow End Client names may be converted into speech. No personal names appear in the briefing text. Only figures are converted to speech: appointment count, occupancy rate, cancellations, amounts collected and similar summaries. Client, staff and product names are shown on screen only and never enter the spoken text.

This preference has been switched off in our account.

Our providers do not use this data to train their own models.

Alternative: you can turn the briefing off and read the same information on screen.

5.4 Accuracy warning

Information produced by AI should not be relied on without being checked independently; the output may be wrong, incomplete or misleading. The details are in section 9 of the Terms of Service.

5.5 Automated decision-making

The AI features produce suggestions; they do not make decisions. No fully automated decision is taken about you or your End Clients that produces legal effects or similarly significantly affects them (KVKK art. 11/1-g; GDPR art. 22). Appointments are always created by a person; even voice booking asks for spoken confirmation before saving. Prices are never set automatically by the system.

6. Who we share data with

We do not sell or rent your data to any third party for marketing purposes. We use the following providers to run the Service:

Provider What for Which data Location
Supabase Database and authentication All Studio Data, account details USA — North Virginia (AWS us-east-1)
Vercel Hosting the application Request records, IP, technical logs USA — Washington D.C.
Stripe Payment processing, sales tax calculation Name, e-mail, billing address, card details (held only at Stripe) Stripe, Inc. — USA
Resend Sending transactional e-mails Recipient e-mail address, message content USA
Twilio + Meta (WhatsApp) Appointment reminder messages End Client phone number, message content USA and Meta's global infrastructure
Anthropic PBC Receipt reading, voice booking interpretation, morning briefing text The image/text sent; End Client name list in voice booking USA
ElevenLabs Voice briefing, speech-to-text, voice generation Text to be converted into speech; speech recording in voice booking USA
Google (Analytics) Website usage statistics IP address (truncated), page views, device and browser information USA

In addition:

  • Where legally required: on a court order or the request of a competent authority, to the minimum extent legally necessary.
  • In the event of a company transfer: to the buyer, in a merger, acquisition or sale of the business. In that case you will be notified in advance.

Changes to the sub-processor list and your right to object are dealt with in the Data Processing Agreement (DPA).

7. International transfer

Some of the providers above are based in the USA, and your data is transferred outside Turkey and the European Union.

Under KVKK. Article 9 of Law No. 6698 changed in June 2024. Transfers abroad are made using the standard contract published by the Board or one of the other appropriate safeguards listed in the law. For Studios established in Turkey, the legal basis for the transfer is set out in Annex 4 of the Data Processing Agreement (DPA).

Under GDPR. For Studios established in the EU, transfers are made using the European Commission's Standard Contractual Clauses (2021/914, Module 2) and, where needed, additional technical/organisational measures. For transfers from the United Kingdom, the UK Addendum (the IDTA addendum) also applies.

8. Security

  • All data transmission is encrypted with TLS.
  • Data at rest is encrypted at disk level by our infrastructure provider.
  • Database access is limited by row level security (RLS) policies; each Studio sees only its own data. This is a rule enforced by the database itself, not a filter in the application layer.
  • Passwords are stored hashed in a way that cannot be reversed.
  • Role separation: studio owner and staff permissions are distinct. Staff cannot reach settings or sales screens.
  • Staff access limits: staff see only the expense records they entered themselves. End Client phone numbers and e-mail addresses are never sent to a staff member's device unless permission is granted separately.
  • System keys carrying full privileges are held only on the server side and are never sent to a browser.
  • Scheduled jobs are protected by a secret key; calls without it are rejected.
  • Notifications from the payment provider are verified by signature.
  • Limited logging: message delivery history, cancelled sales, account deletion requests and system events are recorded. No general-purpose access audit log is kept.

The following measures are not implemented and are not undertaken in this policy: multi-factor authentication, regular penetration testing, continuous access auditing, data loss prevention software and regular staff security training.

No system is absolutely secure. There is always a residual risk in transmission over the internet.

In the event of a personal data breach: if we detect a breach in the data we hold in our own capacity as data controller (account, billing, support, security records), we make the notification to the competent authority within the period set by law and, where required, to the data subjects concerned. In a breach affecting Studio Data, notification to the authority and to the data subjects is the Studio's obligation as data controller; we provide the information and support needed (see DPA arts. 7.4 and 7.5). In a breach affecting Studio Data, we inform the relevant Studio without delay and within 48 hours at the latest (see DPA art. 7.1).

9. How long we keep data

Data Period
Account and Studio Data For the term of the subscription + 30 days after termination (must be the same as Terms of Service section 12.4 and DPA clause 11.1)
Invoice and payment records 10 years (required by tax and commercial legislation)
Support correspondence 3 years
Security and login records 12 months
Image sent to the AI Not kept after the operation
Voice recording sent to the AI Not kept after the operation
Marketing permissions Until the permission is withdrawn; the record of withdrawal is kept for a further 3 years as proof

The 30-day waiting period after you ask for your account to be deleted, and the process itself, are explained on a separate Account Deletion page.

10. Your rights

10.1 Under KVKK art. 11 (Turkey)

To learn whether your personal data is being processed; if it has been processed, to request information about it; to learn the purpose of the processing and whether the data is used in line with that purpose; to know the third parties in Turkey or abroad to whom it has been transferred; to ask for it to be corrected if it has been processed incompletely or wrongly; to ask for it to be erased or destroyed; to ask that correction, erasure and destruction be notified to the third parties to whom the data was transferred; to object to a result that goes against you arising from analysis carried out solely by automated systems; and to claim compensation if you suffer loss because of unlawful processing.

You can make your application in line with the Communiqué on the Procedures and Principles for Application to the Data Controller. We respond within 30 days at the latest.

10.2 Under GDPR (European Union / United Kingdom)

The rights of access, correction, erasure, restriction of processing, data portability, objection to processing and withdrawal of consent. You also have the right to complain to your local data protection authority.

10.3 How to apply

Write to info@didoshe.co. We may ask for further information in order to verify your identity.

Note: if your request concerns a Studio's client record, the data controller for that data is the Studio, so we forward the request to the relevant Studio and inform them within 72 hours.

11. Children

Opening an account on the Service and being a Studio user is not open to people under 18.

The public booking page, on the other hand, can also be used by people under 18; no age verification is carried out on that page. It is also possible for a Studio to keep a record for an End Client under 18 (a child's haircut, for example). In both cases it is the Studio's obligation to obtain the necessary parental permission. No age declaration is requested on the public booking page. Because it is the Studio that deals directly with the person making the booking and provides the service, obtaining parental consent for a minor's appointment and complying with any age restrictions is the Studio's responsibility.

12. Representatives and contact

Data controller for the data listed in section 2(a) of this policy: SCARPAX LLC — 311 60th St Suite #206, West New York, NJ 07093, USA

(For End Client data, the data controller is the Studio you booked with — see section 2(b).) info@didoshe.co

Data protection contact point: kvkk@didoshe.co

You may send any data protection request to this address.

Representatives. DIDOSHE OS does not currently have an appointed representative in Türkiye or the European Union. The Service is provided directly by SCARPAX LLC, established in the United States. When our user numbers in those territories reach the level at which appointing a representative becomes required, this section will be updated and the representative's details published here.

13. Changes

We may update this policy. We announce material changes at least 30 days in advance, by e-mail and by in-app notice. The effective date appears at the top of the document.