Privacy Policy
Last updated: 5 October 2026
1. Introduction
This Privacy Policy explains how your personal data is collected, processed and protected when you use the Polpo Desk service (polpodesk.com). We process your data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Turkish data protection law (KVKK).
2. Data Controller
The data controller responsible for your personal data is:
COON TEKNOLOJİ LİMİTED ŞİRKETİ
ITOB OSB MAH. 10032 SOKAK NO:2-209, Menderes / İzmir, Türkiye
E-mail: [email protected]
3. Data We Collect
To provide the service, we process the following categories of data:
- Account data: e-mail address, name and password stored as a hash.
- Organization and plan data: the organization you belong to and your subscription/plan details.
- Session logs: start/end times and connection metadata for remote desktop sessions.
- Audit logs: activity records kept for security and accountability purposes.
The screen and control stream of remote sessions is end-to-end encrypted and is not stored on our servers; it is transmitted only between the connecting parties.
4. Purposes of Processing
- To create your account, verify your identity and provide access to the service.
- To establish and manage remote desktop and support sessions.
- To manage plans, limits and billing.
- To ensure the security of the service, prevent abuse and comply with legal obligations.
- To improve the service and provide technical support.
5. Legal Basis
Under applicable Turkish data protection law (KVKK Art. 5 and 6), we process your personal data where it is necessary for entering into or performing a contract, for compliance with our legal obligations, for our legitimate interests, and, where required, on the basis of your explicit consent.
Under the GDPR, our processing relies on Article 6: performance of a contract (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), legitimate interests (Art. 6(1)(f)) and, where applicable, consent (Art. 6(1)(a)).
6. Cookies and Local Storage
We use only cookies and browser local storage (localStorage) that are necessary for the service to work: the authentication token, your language preference and your theme (light/dark) preference. We do not use third-party advertising or tracking cookies.
7. Data Transfer (International)
We use Cloudflare for content delivery and connection infrastructure (CDN and TURN services). As a result, some technical data may be processed on servers outside Türkiye and an international data transfer may occur. We carry out these transfers with the appropriate safeguards required by the GDPR and KVKK.
8. Retention Periods
We retain your personal data only for as long as the purposes of processing require and for the statutory retention periods set out in applicable law. When you close your account, your data is deleted or anonymized unless legal obligations require otherwise.
9. Data Security
Remote sessions are end-to-end encrypted with WebRTC (DTLS-SRTP). Passwords are stored only as a hash. We apply technical and organizational measures to prevent unauthorized access to data and limit access to authorized personnel.
10. Your Rights
Under the GDPR and KVKK Art. 11 you have the following rights:
- To learn whether your personal data is being processed and to access it.
- To request rectification or erasure of your data.
- To object to processing and to request restriction of processing.
- To request the portability of your data (transfer to another controller).
- To withdraw any consent you have given and to lodge a complaint with the relevant supervisory authority.
To exercise these rights, you can contact us at [email protected].
11. Contact
For any questions or requests regarding this Privacy Policy or your personal data, you can reach us through our contact page or at [email protected].