Türkçe · Medyapin

Privacy Policy

Draft dated: 2026-09-02

1. Who this covers

Medyapin OS is a digital signage / experience platform. This draft describes personal data about organization staff accounts (dashboard users): email, role, locale preference, and authentication-related records (sessions, optional MFA).

The product does not collect end-consumer / passerby facial identity, visitor IDs, or biometric identifiers in the default product. Signage viewers are not the data subjects described here.

2. What we process

Account data: email address, password hash (never plaintext), role / permission assignments, UI locale, and session tokens.

Operational data tied to the organization (not primarily to a named person): device and fleet metadata, schedules, content assets, proof/uptime aggregates, and audit logs of administrative actions.

Optional features may store encrypted third-party remote-access credentials or dashboard-login secrets that an organization chooses to configure — those secrets belong to the organization tenant.

3. Retention (organization-wide)

Organizations can configure time-based retention for audit logs, proof records, raw telemetry, aggregates, and screenshots via the retention-policy API. Raw camera/audio retention is forced to zero days in the product.

Org-wide retention is separate from a per-user erasure request (right to erasure).

4. Right to erasure

An organization owner or admin with organization.manage may call POST /api/v1/organizations/:orgId/users/:userId/erase to erase a staff account.

Erasure hard-deletes user-owned auth rows (MFA, recovery codes, login challenges, sessions, role assignments), anonymizes the users row (email replaced with a non-reversible placeholder, password cleared), and keeps the user id so operational attribution foreign keys (device claims, commands, emergency events, AI drafts, etc.) do not orphan.

Self-service erasure by the data subject and a public terms-of-service page are not yet provided; both are known gaps pending follow-up work and legal review.

5. Sub-processors / hosting

Default local and on-prem deployments use self-hosted PostgreSQL, Redis, MinIO (object storage), and NATS — no third-party SaaS sub-processor is required by the core stack.

Cloud deployments may introduce additional processors; list TBD pending legal review (do not invent vendors here).

6. Contact

For privacy requests, contact the organization that operates your Medyapin tenant, or MEDYAPIN OS ownership after this draft is finalized.