GURU IQ · CORPORATE INFORMATION
Privacy & Personal Data
Personal data use, device permissions, equipment access and your rights in the GURU IQ mobile and web applications. This page also covers the GURU IQ product website.
Last updated
Scope and service provider
GURU IQ is an enterprise equipment management service provided by GURU ENERJİ HİZMETLERİ VE PROJE DANIŞMANLIĞI LİMİTED ŞİRKETİ. This policy covers the mobile application, browser-based web application, membership and account processes, equipment links and GURU IQ product pages together. Contact us about privacy at info@guru-pmr.com.
Employee and equipment records entered by your organization also relate to its own business operations. Its privacy notices should therefore be considered alongside this policy. The responsibilities of the service provider and your organization depend on the purpose of the processing and their respective roles; using the application does not constitute blanket consent to every processing activity.
Information in the application
Account and membership processes use names, email addresses, phone numbers, organization, role, language and contact preferences, together with invitation and access-request details. Operational records may identify an equipment custodian, handovers and transfers, maintenance assignments, calibration information, the person performing an action and its time.
When the relevant feature is used, notes, inspection photos, operation-linked location, device notification registration and technical security information are also processed. Information is collected electronically from entries by you or your organization, application actions and permitted device features. Do not add personal or sensitive information that is unnecessary for the operation to free-text fields or photos.
How information is used
Account and membership details support authentication, invitations, access-request review and authorization. Person-linked equipment records support inventory, handover, maintenance and calibration operations; transaction history traces changes and responsibility.
Email addresses support invitations, account recovery and assistance. Device notification registrations route operational notifications according to your preferences. Technical records and security checks support service operation and abuse prevention. Offline records allow pending actions to synchronize when a connection becomes available.
Legal framework for processing
Under Türkiye’s Law No. 6698, each processing purpose must have a valid legal basis. Establishing or performing a contract can provide a basis only for necessary processing concerning its parties. An organization’s service contract does not mean that all employee data can be processed on that same basis.
Depending on the specific activity, the conditions concerning a legal obligation, establishing, exercising or protecting a right, or legitimate interests that do not prejudice fundamental rights and freedoms must be assessed. Where explicit consent is required, it must be separate, specific and informed. Granting camera, location or notification permission on a device does not itself constitute consent to all processing or international transfers.
Camera, location and notification permissions
The camera supports features such as QR scanning and attaching operation photos. NFC scanning identifies an equipment tag. When you choose to use your current location, coordinates obtained with device permission may be attached to the relevant record. Notification permission and application preferences control operational notifications sent to your device.
You can manage permissions in your device settings. Disabling a permission may limit the relevant feature; it does not automatically erase previously recorded photos, locations or transaction history. Email, organizational contact preferences and device notification permission are separate settings.
Access and equipment links
Access within the application is restricted by organization membership and user permissions. An equipment page opened through NFC or QR without signing in presents limited equipment information; it does not open private maintenance notes, contact details or the organization’s full inventory. Contact information within the application is available to authorized users in the context of the relevant equipment and contact preferences.
Service infrastructure
The service linked from this page uses Supabase for database, authentication and file infrastructure; Resend for transactional email; Google Firebase Cloud Messaging and Apple APNs for device notifications; and Cloudflare Turnstile to prevent abuse of access-request forms. GURU-PMR web hosting is provided by GüzelHosting.
Data sent to each provider depends on its function: email services may process recipient addresses and message content; notification services may process device routing details and notification data; security and hosting services may process connection and technical records. Organizational users can access only authorized information, and information may also need to be provided to competent authorities where legally required.
Cloud, email, notification and security infrastructure may involve processing outside Türkiye. International transfers are subject to Article 9 of the Law separately from the processing basis; a provider’s general privacy policy alone does not establish that these conditions have been met. You can use the request channels below to ask about recipients and transfer arrangements affecting your data.
Retention and on-device records
Account, operational, photo and technical records have different retention requirements. The processing purpose, organizational record obligations and lawful retention grounds must be considered together. Erasure, destruction or anonymization requirements apply when the reasons for processing cease; there is no single retention period for every record.
Offline use stores some records and unsynchronized actions on your device. Uninstalling the application or clearing device data does not erase organizational records on the server and may lose unsynchronized work. Closing an account is not itself immediate erasure of operational history, backups or offline copies. Correction and erasure requests must be assessed against the relevant records and retention grounds.
Product website and cookies
The GURU IQ product pages do not use advertising or analytics cookies, tracking pixels, registration forms or account sign-in. Fonts and images load from the same server. Hosting infrastructure may process IP addresses and technical access logs for connectivity and security. The product website does not access your application session or inventory.
This does not mean that the application uses no cookies or on-device records: the web application uses browser storage to maintain sessions and support offline work. Other GURU-PMR corporate pages, contact forms and external links have their own data-processing scope.
Your rights and requests
Under Türkiye’s Personal Data Protection Law No. 6698, you may ask whether your personal data is processed, request information about its purposes and recipients, and seek correction of incomplete or inaccurate data or erasure or destruction where the legal conditions are met. You may also request that recipients be informed of corrections or erasure, object to an adverse result arising solely from automated analysis and seek compensation for harm caused by unlawful processing. Identity and authority checks may be needed to handle your request securely.
Requests and contact
Send privacy questions and personal data requests to info@guru-pmr.com. The company’s head-office address for written requests is Atıfbey Mah. 67 Sk. No:33 AMASS Residence D:32, 35410 Gaziemir / İzmir / Türkiye. For formal requests by email, use the address previously supplied to us and recorded in our systems; other statutory request methods remain available.
State your name, surname, request and an address for our response. Formal requests may require statutory identity information, a signature for written submissions and relevant supporting documents. Do not send passwords or one-time codes, or proactively attach a full copy of an identity document. Further information needed for secure verification may be requested separately.
The Law requires requests to be resolved as soon as appropriate to their nature and within 30 days. Requests are generally free; the Board’s tariff may apply where additional costs arise. Requests concerning organizational records may require identification of the relevant controller and coordination with your organization.
Policy updates
This policy may be updated as service features or explanations of data use change. The current text is available on this page, with the most recent update date shown at the top.