Privacy Policy
Data Protection and Privacy Statement for Website and Google Applications
Last Updated: September 4, 2026 | Effective Date: September 4, 2026
Google API Services User Data Policy Disclosure
mhrgl.com's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Introduction and Data Controller
At Mahir Gül (mhrgl.com), we respect your privacy and are committed to safeguarding your personal data. This Privacy Policy describes how we collect, process, retain, and protect information when you visit our website mhrgl.com, or use any web, mobile, desktop applications, cloud tools, Google Workspace add-ons, or Google OAuth API integrations developed and operated by Mahir Gül (collectively referred to as "Applications" or "Services").
Data Controller: Mahir Gül | Email: [email protected] | Website: https://www.mhrgl.com
2. Google User Data and Requested OAuth Scopes
When our Applications connect with Google Sign-In or Google APIs, we strictly adhere to the principle of data minimization and request only the absolute minimum scopes necessary to operate the application’s core features. Depending on the specific application or feature authorized by you, data accessed may include:
- Profile & Authentication Information: Full name, email address, profile picture URL, and unique Google User ID (openid, email, profile). This data is strictly used to authenticate your identity and create or maintain your user session.
- Application-Specific API Data: Data accessed via specific Google API scopes explicitly requested by the application and approved by you (e.g., calendar event syncing, spreadsheet data automation, file transfers, or notification services).
- OAuth Authentication Tokens: Short-lived access tokens and refresh tokens generated by Google are stored securely and encrypted solely to perform authorized API calls on your behalf.
3. Purposes of Processing Google User Data
All Google user data collected or accessed is processed exclusively for the following operational purposes:
- Authenticating the user's identity and securing access to the application.
- Executing and delivering the specific user-facing features and integrations requested by the user.
- Providing customer service, diagnosing software bugs, and troubleshooting system issues.
- Ensuring the security and stability of our systems and preventing fraud, abuse, or unauthorized access.
4. Data Sharing, No-Sale Policy & Human Access Restrictions
We maintain strict safeguards regarding how Google user data is handled:
- We Never Sell Google User Data: Personal information and Google user data are NEVER sold, rented, leased, or traded to any third party, data broker, or commercial entity under any circumstances.
- No Advertising or Marketing Use: We NEVER use or transfer Google user data for serving advertisements, including personalized, retargeted, or interest-based ads.
- No Generalized AI/ML Model Training: Google user data is NEVER used to train or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models without explicit consent.
- Strict Limits on Human Access: No human employees or developers are permitted to read or view Google user data, except under the following limited conditions:
- We have obtained your explicit, affirmative agreement for specific data or records (e.g., for technical support or debugging requested by you);
- It is strictly necessary for security purposes (such as investigating an exploit, system vulnerability, or abuse);
- It is necessary to comply with applicable laws, court orders, or enforceable governmental requests;
- The data has been completely aggregated and anonymized for internal technical performance diagnostics.
5. Data Storage, Security & Retention Periods
We employ robust technical and organizational security measures to protect user data against unauthorized access, alteration, or disclosure:
- Encryption in Transit: All communications between your client, our servers, and Google APIs are encrypted using industry-standard TLS / HTTPS protocols.
- Encryption at Rest: Sensitive authentication credentials, API keys, and access tokens are protected using strong cryptographic algorithms (e.g., AES-256) on secured servers.
- Retention Policy: We retain Google user data only for the duration necessary to provide the active service to you or until you request account deletion. OAuth tokens are automatically expired or invalidated upon logout or access revocation.
6. Revoking Google Permissions & Complete Data Deletion
Users maintain full autonomy over their personal and Google account data:
Revoke Access via Google Account
You can disconnect our application's access to your Google Account at any time directly through Google Security Settings:
Google Account PermissionsRequest Complete Data Deletion
To request the complete, permanent deletion of your account and any stored data, simply email us:
[email protected] (Deletion Request)Deletion SLA: Once a deletion request is received and verified, all associated personal and Google user data will be permanently purged from our active databases within 30 days, and a written confirmation will be sent to your email.
7. Your Legal Rights (GDPR & KVKK)
Under the European Union General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK No. 6698), you have the right to:
- Request access to and a copy of the personal data we hold about you;
- Request correction or rectification of any inaccurate or incomplete data;
- Request erasure (the "right to be forgotten") of your personal data;
- Request restriction of processing or object to certain types of processing;
- Request data portability in a structured, commonly used machine-readable format;
- Lodge a complaint with a competent supervisory authority if you believe your rights have been violated.
8. Website Cookies & Analytics
The website mhrgl.com utilizes essential cookies for session management and user experience. We may also use third-party tools such as Google AdSense or Google Analytics. You can adjust your cookie preferences or block cookies at any time using your web browser's privacy settings.
9. Children's Privacy (COPPA & GDPR-K)
Our website and applications are not intended for or directed to individuals under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal information without parental consent, we will take immediate steps to delete such data from our servers.
10. Updates & Contact Details
We may update this Privacy Policy from time to time to reflect modifications in our software, legal requirements, or Google policies. Any revisions will be published on this page with an updated "Last Updated" timestamp.
Developer & Contact Information:
Developer / Controller: Mahir Gül
Email: [email protected]
Website: https://www.mhrgl.com
Phone: +90 537 990 23 52 | +43 690 104 84 622