Privacy Policy

Last updated: 30 September 2026

Draft — subject to legal review.

This policy explains how Baktam collects, uses and protects personal data when you visit baktam.com, use the Baktam web panel, mobile apps or API, or interact with a garage that uses Baktam (for example through a quote approval link or an online booking page). We aim to collect only what is needed to provide the service, and we never sell personal data.

1. Who we are

Baktam is a cloud software service for vehicle workshops, operated by Fatih Bilgiç (“Baktam”, “we”, “us”). You can reach us about privacy matters at [email protected].

2. Our role: controller and processor

Where Baktam is the controller

We decide how and why personal data is processed for our own purposes: user accounts, subscription and billing records, support requests, messages sent through our contact form, website visits and the security of the service.

Where Baktam is the processor

Each garage (our customer, the “business”) decides which data it records about its own customers, vehicles and staff. For that data the business is the controller and Baktam processes it on the business's behalf and only to provide the service. If you are a customer of a garage and want to exercise your rights, please contact that garage first; we will help the garage respond. A data processing agreement for business customers: [to be confirmed].

3. Data we process

  • Account data: name, phone number, email address, preferred language, and a password stored only as a one-way hash.
  • Business and billing data: business name, address, country, currency, tax or VAT registration number (for example a TRN), plan and payment records.
  • Data the business records in Baktam: customers' names, phone numbers, email addresses and tax numbers; vehicles (plate, chassis number/VIN, make, model, odometer); job cards, sales, payments, reminders, notes, photos and signatures.
  • Public pages: when a customer uses a booking page we receive the name, phone number, plate and note they enter; when they respond to a quote approval link we record their decision, name and signature.
  • Technical data: IP address, browser or device information and sign-in records, used to keep accounts secure, limit abuse and troubleshoot errors. The mobile apps store a push notification token if you allow notifications.

4. Why we use it and on what legal basis

Where the GDPR or UK GDPR applies, we rely on the following legal bases for the data we control:

  • Performance of a contract: creating and running your account, providing the service and support, and billing.
  • Legal obligation: keeping invoices and accounting records for the periods required by law.
  • Legitimate interests: securing the service, preventing fraud and abuse, and fixing errors, balanced against your rights.
  • Consent: marketing emails and any optional analytics. You can withdraw consent at any time.

We do not use personal data for automated decisions that have legal or similarly significant effects.

5. Where data is stored

The Baktam cloud service is hosted in the European Union, in data centres in Germany. Daily backups are kept for a limited period to allow recovery. Enterprise customers can instead run Baktam on their own server; in that case the data stays on that server and the business is responsible for its hosting, backups and security.

Some service providers that a business chooses to connect (for example SMS or WhatsApp providers) may process data outside the EU. Where data is transferred outside the EU or UK, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses [to be confirmed].

6. Service providers (sub-processors)

We share personal data only as far as each provider needs it to perform its task:

  • Hosting: infrastructure provider with data centres in Germany.
  • Email delivery: an email sending service for account emails such as password resets and daily summaries.
  • Messaging chosen by the business: SMS through Twilio, or WhatsApp Business (Cloud API) by Meta, using the business's own account and contract with that provider. (Netgsm is available for businesses in Turkey only.)
  • E-invoicing in Saudi Arabia: when a Saudi business has onboarded ZATCA e-invoicing, the invoices it issues, including the customer details shown on them, are sent to ZATCA's Fatoora platform, as Saudi e-invoicing rules require. ZATCA receives them as a tax authority, not as our processor.
  • Push notifications for the mobile apps: the Expo push service, which delivers notifications through Apple and Google.
  • Website analytics: Microsoft Clarity, only on the public website and only with your consent (see section 7).
  • Error monitoring: Sentry, only if enabled. It is configured not to send default personal data; phone numbers and email addresses are masked and cookies, authorization headers and request bodies are removed.

A list of the specific providers is available on request. We may disclose data where required by law or by a valid order of a court or authority.

7. Cookies and similar technologies

Essential cookies

These are needed for the service to work and do not require consent: a session cookie that keeps you signed in, a cookie that remembers your language, and baktam_consent, which stores your cookie choice for 6 months. The web panel also stores a few interface preferences (such as favourites) in your browser's local storage.

Analytics cookies (only with your consent)

On our public website (baktam.com, including the /en and /ar pages) we use Microsoft Clarity to understand how visitors use the site and to improve it. Clarity is loaded only after you choose “Accept analytics” in the cookie banner; until you choose, or if you reject, no data is sent to Clarity. Our legal basis is your consent (GDPR / UK GDPR Art. 6(1)(a) and the applicable cookie rules; explicit consent under Turkey's KVKK; consent under the UAE and Saudi PDPL).

  • What it collects: clicks, scrolling, mouse movements, pages visited, session duration, device and browser information and approximate location. Text you type into form fields is masked and never recorded.
  • Cookies: _clck (1 year) and _clsk (1 day), set by Clarity. We deny advertising storage; the data is not used for advertising by us.
  • Who processes it: Microsoft Corporation, as our service provider; data may be stored outside your country, including in the United States.
  • Where it never runs: the Baktam web panel, sign-in pages, the approval, receipt and booking links that garages send to their customers, and print pages.

You can withdraw your consent at any time: open “Cookie settings” in the website footer and choose “Reject”. Clarity is then stopped, its cookies are deleted and it is not loaded on later visits. Withdrawing consent does not affect processing that took place before.

We do not use advertising or cross-site tracking cookies.

8. How long we keep data

  • Account and business data: for as long as the subscription is active.
  • After cancellation: data remains available for export for 60 days and is then deleted, unless the business asks for earlier deletion [to be confirmed].
  • Backups: overwritten on a rolling basis after a limited period [retention period to be confirmed].
  • Invoices and billing records: for the period required by tax and accounting law.

Data that a business records about its own customers is kept according to that business's instructions and deleted when the business deletes it or closes its account.

9. How we protect data

  • All connections use encrypted HTTPS (TLS).
  • Passwords and API keys are stored only as one-way hashes.
  • Quote approval and receipt links use random tokens that are stored only as hashes. Public pages (approvals, receipts, booking and shared vehicle history) are rate-limited and show personal details in masked form.
  • Credentials for SMS, WhatsApp and e-invoicing providers are encrypted (AES-256-GCM) in the database and are never shown again in the interface or returned by the API.
  • Each business's data is isolated from other businesses, and role-based permissions limit what each user can see: for example, technicians do not see prices or costs.
  • Important actions are recorded in an audit log, and data is backed up daily.

If a personal data breach affects your data, we will notify the affected business and, where required, the competent authority without undue delay.

10. Your rights

Depending on where you live, you may have the right to access your data, correct it, have it deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent. These rights apply under the EU GDPR and UK GDPR, and similar rights exist under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), Saudi Arabia's Personal Data Protection Law (PDPL), Qatar's personal data privacy law and applicable US state privacy laws.

To exercise your rights, email [email protected]. We will respond within one month, or within the period required by the law that applies to you. You also have the right to complain to your data protection authority, for example your EU supervisory authority or, in the UK, the Information Commissioner's Office (ICO).

11. Children

Baktam is a business service and is not directed at children.

12. Changes to this policy

We may update this policy from time to time. We will announce significant changes by email to account owners before they take effect.

13. Contact

Questions about this policy or your data: [email protected].