What this policy covers
This policy describes the personal data we process when you visit our site, sign up to the panel and use our service.
Personal data held in your own systems that a test touches is a separate matter: there we act as a processor and the Data Processing Agreement applies.
Controller
For your own customer and visitor data the controller is CM Apps Software LLC. Address: 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, US.
Write to [email protected] about anything concerning personal data. We answer written requests within 30 days at the latest.
Data you give us
At sign-up: name, work email, company name and your role.
Through the contact form: name, email, company, role, product type and platforms, your delivery expectation, whether a test environment exists, and the short description you write.
When ordering: billing details, tax number and what payment requires. We never see your card details; the payment provider processes them.
In support correspondence: the content of your messages and any attachments.
Data collected automatically
Server logs: IP address, date and time, page requested, referring address, browser and operating system. These are kept for security and fault diagnosis.
Measurement cookies run only if you allow them. If you do not, no analytics data is collected at all and the site works exactly the same.
Panel session and activity records: which action you took and when. This record exists so that, in a dispute, it is clear who approved what.
Data a test touches
We ask that your test environment holds no real personal data. Where it does, we touch it only as far as the test requires, do not copy it, and try to keep it out of the recordings.
Where personal data appears in evidence such as a screen recording or network log, we mask it, or ask you for instructions where masking is not possible.
For that processing you are the controller and we are the processor. The detail is in the Data Processing Agreement.
Why we process it
To deliver the service: manage your account, build the scope, run the test, deliver the report and carry out the re-test round.
To communicate: answer your request, keep you informed of test progress, send contractual notices.
For invoicing and accounting: to meet statutory bookkeeping requirements.
For security: detect unauthorised access, prevent abuse, protect our systems.
For improvement: with your permission, to understand which parts of the site get used.
Our legal bases
Performance of a contract: account, order, test execution and invoicing data.
Legal obligation: records we are required to keep under tax and commercial legislation.
Legitimate interests: security logging, prevention of abuse and claims handling. Wherever we rely on legitimate interests we have carried out a balancing test; we share the outcome on request.
Consent: measurement cookies and marketing messages. You can withdraw consent at any time; withdrawal does not make the processing before it unlawful.
Cookies
Strictly necessary cookies serve session and security and are not subject to consent. Measurement cookies run only with your explicit consent.
We store your choice in your browser and you can change it at any time. The full cookie list is on the Cookie Policy page.
Who we share it with
Sub-processors: hosting, recording storage, email, payment and support providers. The current list is on the Sub-processors page; we hold a written data processing agreement with each.
The tester network: testers assigned to a test, only as far as the test requires and under a confidentiality undertaking.
Legal and accounting advisers: only as far as necessary and under professional privilege.
Competent authorities: only to the extent legally required. If such a demand arrives, we tell you where legally permitted.
We do not sell your personal data, share it with advertising networks, or use it to train AI models.
International transfers
Some of our sub-processors are located outside our country. Those transfers are made under standard contractual clauses or the other safeguards the applicable law provides for.
The Sub-processors page shows where each provider is located. We share a copy of the transfer safeguards on request.
Retention periods
Account data: for as long as your account is open, and 12 months after it closes.
Test data, recordings and credentials: permanently deleted 90 days after a test ends. You can ask us to delete earlier.
Reports: kept in the panel for 24 months unless you ask otherwise; you can request earlier deletion.
Invoicing and accounting records: for the period the law requires (10 years in Türkiye).
Server security logs: 12 months.
Contact form records: 24 months, then deleted.
Security
We apply encryption in transit and at rest, least-privilege access control, multi-factor authentication, access logging and regular backups.
The full set of technical and organisational measures is on the Security Policy page.
No system is absolutely secure. In the event of a personal data breach we notify the competent authority within the statutory deadline and, where required, you directly.
Your rights
To learn whether your personal data is processed and, if so, to request information about it.
To learn the purpose of processing and whether the data is used in line with that purpose.
To know the third parties, domestic or foreign, it has been transferred to.
To have inaccurate or incomplete data corrected, and to have it erased where the conditions are met.
To have correction and erasure notified to the parties the data was transferred to.
To object to processing, and to withdraw consent where processing rests on it.
To receive your data in a structured, commonly used format and to port it.
To object to an outcome against you produced solely by automated analysis.
To claim compensation for damage caused by unlawful processing.
How to exercise them
Write to [email protected]. We may ask for further information to verify your identity; we do that only to answer the right person.
Requests are free. Where a request is manifestly unfounded or excessively repetitive we may charge a fee or refuse it to the extent the law allows; if we refuse, we say why in writing.
Our response time is 30 days at the latest.
Right to complain
If our answer does not satisfy you, you have the right to complain to the competent data protection authority. In Türkiye that is the Personal Data Protection Authority.
If you are in the European Economic Area you may also complain to the supervisory authority in your own country.
Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
The scope and price calculation you see in the panel is a direct result of the criteria you select; it contains no assessment of you.
Children
Our service is directed at businesses and is not intended for anyone under 18.
If we learn we have inadvertently collected a child’s data, we delete it immediately.
Changes
We may update this policy. We give at least 30 days’ notice of material changes by email and in the panel.
The date at the top of the page shows when it was last revised.
These documents are published in English and Turkish. In the event of conflict the Turkish text prevails.