1. Who we are
Muhammet Tarık Kılıç ("MotoFull", "we") is established at Kanuni Mah. İstiklal Cad. No: 12/1C İç Kapı No: 4, Ortahisar/Trabzon, Türkiye. You can reach our privacy contact at info@motofull.com.tr.
⚠️ An EU representative under Art. 27 GDPR has not been appointed yet. One must be appointed before offering the service to customers in the EU. Set euRepresentative in lib/company.ts.
2. Controller or processor?
MotoFull is software sold to motorcycle repair shops. This creates two distinct roles, and it determines who you should contact about your data:
| Data | Controller | Our role |
|---|---|---|
| Data a repair shop holds about its own customers (name, phone, plate, service history) | The repair shop | Processor — we act only on the shop’s instructions |
| A shop’s own account and billing data | MotoFull | Controller |
| Motorcycle owner portal accounts and ride data | MotoFull | Controller |
| Website visit statistics | MotoFull | Controller |
If a repair shop holds a service record about your motorcycle, please contact that shop first. We will support them in fulfilling your request.
3. What we collect and why
| Data | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Name, email, phone, company details | Creating and running your account | Contract (6(1)(b)) |
| Billing and invoice data | Payment and statutory bookkeeping | Legal obligation (6(1)(c)) |
| Vehicle and service records | Delivering the core service | Contract (6(1)(b)) |
| Fault codes, complaint text, document photos | AI diagnosis and document reading | Contract (6(1)(b)) |
| Ride telemetry (speed, distance, lean angle summary) | Showing you your own riding statistics | Consent (6(1)(a)) — you start each ride yourself |
| Login records, session data | Security and abuse prevention | Legitimate interests (6(1)(f)) |
| Aggregated visit statistics | Understanding and improving the product | Legitimate interests (6(1)(f)) |
We do not process special categories of data (Art. 9 GDPR). Identity-document scanning was deliberately removed from the product because the risk it carried was disproportionate to its benefit.
4. Who we share data with
We do not sell personal data and we do not share it for advertising. We use the processors listed on our subprocessors page: Google (Gemini AI), MongoDB Atlas, Render, Vercel, and — for payments — iyzico.
5. International transfers
Some processors are located outside the EEA, primarily in the United States. Such transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with supplementary technical measures such as encryption in transit.
About AI features: content you submit to the AI diagnosis, document reading or assistant features is sent to Google's Gemini API. Uploaded photos are not stored on our servers. Using AI features is entirely optional — every field can be entered manually.
6. How long we keep data
| Data | Retention |
|---|---|
| Service records and invoices | 10 years (statutory bookkeeping obligation) |
| Account data | While the account is active, plus 6 months |
| AI chat history | 1 year, deleted automatically |
| Ride records | Until you delete them or close your account |
| Website visit records | 180 days, deleted automatically |
| Uploaded document photos | Not stored |
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Have your data erased (Art. 17)
- Restrict processing (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, without affecting prior processing (Art. 7(3))
You can delete your account and data yourself from Profile → Delete account in the customer portal. For anything else, write to info@motofull.com.tr. We respond within one month.
You also have the right to lodge a complaint with your local data protection supervisory authority.
8. Security
Data is encrypted in transit using TLS. Passwords are stored only as irreversible bcrypt hashes — we cannot read them. Each repair shop's data is isolated at the system level. Rate limiting and session controls guard against unauthorised access.
In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay.
9. Children
The service is intended for businesses and adult motorcycle owners. We do not knowingly collect data from children under 16.
10. Changes
We may update this policy. Material changes will be announced in the application before they take effect.