Privacy Policy
Last updated: 2 August 2026 · Effective date: 2 August 2026
This policy explains how the Madvise service, provided by Ege Mert Özcan ("Madvise", "we"), processes personal data. By using the service, or by contacting a business through an ad run on Madvise, you accept the practices described here.
1. Data Controller
Under Turkish Personal Data Protection Law no. 6698 ("KVKK"), the data controller is Ege Mert Özcan (sole proprietorship).
Address: Mustafa Kemal Mahallesi, Bilişim İnovasyon Merkezi, ODTÜ Teknokent No:280 D:G, 06510 Çankaya / Ankara
E-mail: info@pursula.com
Division of responsibility (important): Businesses that advertise through Madvise are the primary data controllers for the data of their own prospects ("leads"). When Madvise processes that lead data on a business's behalf and on its instructions, Madvise acts largely as a data processor. For data relating to Madvise's own customer (business) accounts, Madvise is the controller. The data processing agreement between us and the business governs the consequences of this split.
Madvise's commercial structure will shortly be transferred to a joint-stock company. When that transfer happens, the controller details on this page will be updated and separately announced as a material change.
2. What Madvise Does
Madvise lets small and medium-sized businesses publish ads in one click, see their ad data translated into plain language, and receive AI-assisted recommendations. The product's distinguishing feature is connecting a prospect (lead) who arrives from an ad back to the specific creative they came from, and on to the final sales outcome.
The service covers Meta (Facebook/Instagram/WhatsApp) ads today. The Google Ads integration is an optional additional channel that becomes active only when you connect your own Google Ads account.
These functions require processing the personal data described below.
3. Personal Data We Process
3.1. Business (Customer) Data
Data relating to businesses that use Madvise and their authorised users:
- Identity and contact details (name, e-mail, phone, business name).
- Account and authentication data (hashed password, session data; if you sign in with Google, the name, e-mail and profile picture Google passes to us).
- Connected account data (Meta Page/ad account ID, WhatsApp Business account details, and — if you connect one — your Google Ads customer ID).
- Brand and product information (brand brain content, product/service catalogue, website addresses you submit for analysis).
- Usage and system logs (activity records, IP address, device/browser information).
- Billing and subscription information (if any).
3.2. Lead (End User) Data
Data processed on behalf of a business about people who click its ad and get in touch through a messaging channel (WhatsApp, Messenger, Instagram DM):
- Messaging identifier and profile name (e.g. WhatsApp phone number or platform user ID).
- The content of the messages sent.
- Ad attribution (referral) data — which ad or creative the message originated from.
- The outcome marked by the sales side (e.g. contacted → interested → appointment → sale) and, where entered, the sale amount.
- The relevant consent record, where one exists.
3.3. Ad Performance Data
Campaign data received from Meta and — if you connect it — Google Ads, which is largely aggregate/statistical: impressions, clicks, conversations started, conversions and spend.
3.4. Conversion Measurement Data
For businesses that choose the Google Ads channel, we may process click identifiers (e.g. GCLID) and — only where the individual has consented — hashed matching keys such as e-mail or phone, in order to connect an ad click to a real sale. This data is held in a separate, access-restricted store, is encrypted, and is used only for conversion measurement.
4. Purposes and Legal Bases
| Purpose | Legal basis (KVKK art. 5) |
|---|---|
| Providing the service and managing the account | Formation/performance of a contract |
| Publishing ads and synchronising their data | Performance of a contract / legitimate interest |
| Connecting leads to the ad creative and the sales outcome | Legitimate interest of the business / explicit consent where required |
| AI-assisted recommendations and content generation (aggregate metrics and brand data only) | Legitimate interest |
| Conversion measurement and performance reporting | Legitimate interest / explicit consent |
| Security, abuse prevention and logging | Legitimate interest / legal obligation |
| Meeting legal obligations | Legal obligation |
Where explicit consent is required for lead data, that consent is obtained and recorded by the relevant business — usually at the start of the conversation or within the ad flow.
5. How We Collect Data
- Directly from you: when you create an account, use the service and contact us.
- Through messaging channels: when you click an ad and send a message, via the Meta WhatsApp Business Platform (Cloud API) and the relevant platform interfaces.
- From ad platforms: by synchronising performance data over the API for the Meta and (where connected) Google Ads account you have linked.
- From your website: when you run the "Improve Your Site" analysis, by reading the publicly available pages of the address you provide, server-side. This analysis collects no visitor data.
- Automatically: through system and security logs, cookies and similar technologies.
6. Sharing With Third Parties
Madvise does not sell personal data. We share data only to the extent needed to provide the service, and only with the suppliers (data processors) below:
| Supplier | Purpose | Data shared |
|---|---|---|
| Meta Platforms | Ad delivery, WhatsApp/Messenger messaging and performance data | Messaging lead data, ad metrics |
| Google (Ads API, Data Manager, Sign in with Google) | Optional Google Ads management, conversion measurement and account sign-in | Campaign configuration, conversion/click identifiers, basic profile data for sign-in |
| Anthropic (Claude API) | AI-assisted recommendations and copy generation | Aggregate metrics and brand information only — no lead PII (phone, name, message content) is sent |
| Google (Gemini API) | Fallback provider for brand brain generation | Brand information only — no lead PII is sent |
| fal.ai | Ad image and video generation | Generation requests and product photos you upload (contains no lead PII) |
| Supabase | Database, authentication and storage (EU region) | All application data (encrypted / access-controlled) |
| Vercel | Frontend hosting | Application traffic |
| Railway | Backend / worker hosting | Application data (during processing) |
Privacy by design: No lead personal data is ever sent to the AI recommendation layer — only aggregated ad metrics are.
6.1. Use of Google User Data (Limited Use)
When you sign in with your Google account or connect your Google Ads account to Madvise, information obtained from Google APIs is used only on your instructions, to manage your own ad account and report back to you.
- Data received from Google APIs is never sold, and is never used for ad targeting or ad personalisation.
- It is not transferred to third parties other than the suppliers strictly required to provide the service, and is never used for credit scoring or similar purposes.
- No humans read this data. The only exceptions are your explicit permission, a review necessary for security purposes, where the law requires it, and where the data has been aggregated or anonymised.
- Access is limited to the narrowest scope the operation you requested requires.
- You can revoke the connection at any time from Madvise settings or from your Google Account security settings; on revocation, the stored authorisation tokens are deleted.
Madvise's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
On the Google Ads channel, ad spend is owed directly to Google and is charged to your own Google Ads account; Madvise does not collect that spend. See the Terms of Service for detail.
6.2. International Transfers
Some of the suppliers above may process data outside Türkiye (e.g. in the EU or the USA). Such transfers are made under KVKK art. 9 with appropriate safeguards in place (standard contractual clauses, an adequacy decision, or explicit consent where required). Primary data storage is configured in the EU region.
7. Data Security
The technical and organisational measures we take to protect personal data include:
- Hashing of lead phone numbers and sensitive identifiers.
- Row-Level Security at the database level.
- Authorisation tokens and click identifiers stored encrypted under managed keys.
- Encryption in transit and at rest.
- Role-based access and least privilege.
- EU-region hosting and regular security reviews.
No system is 100% secure, but we make every reasonable effort to protect your data with industry-standard measures.
8. Retention Periods
We keep personal data only for as long as the processing purposes require and for the periods the applicable legislation prescribes:
| Data type | Retention period |
|---|---|
| Business account data | For as long as the account is active, plus 6 months after closure |
| Lead data | The period set in the agreement with the relevant business; where none is set, 12 months from the end of the campaign |
| Conversion measurement identifiers (e.g. click IDs) | At most 90 days |
| Authorisation tokens (Meta/Google connections) | Until the connection is removed; deleted immediately on removal |
| System and security logs | 90 days |
| Legal/financial records | As required by law (as a rule, 10 years) |
Once these periods expire, data is deleted, destroyed or anonymised.
9. Your Rights (KVKK art. 11)
Under the KVKK you have the right to:
- Learn whether your personal data is being processed,
- Request information if it has been processed,
- Learn the purpose of processing and whether the data is used in line with that purpose,
- Know the third parties, in Türkiye or abroad, to whom it has been transferred,
- Request correction if it has been processed incompletely or inaccurately,
- Request its erasure or destruction,
- Request that corrections and erasures be notified to the third parties it was transferred to,
- Object to a result against you arising from analysis carried out solely by automated systems,
- Claim compensation for damage suffered because of unlawful processing.
To exercise these rights, contact info@pursula.com. We will respond to your request within 30 days at the latest.
For requests about lead data you may need to approach the advertising business first; in that case we will direct your request to them.
10. Account and Data Deletion
To have your account and data deleted, send an e-mail from your account address to info@pursula.com with the subject "Data deletion request". We will complete the request within 30 days at the latest and confirm the outcome to you in writing.
Independently of a deletion request, you can revoke the authorisation of your connected Meta or Google accounts from settings at any time; doing so deletes the relevant tokens immediately. Financial records subject to a statutory retention obligation continue to be kept until that period expires.
11. Cookies and Similar Technologies
The Madvise web application uses cookies necessary for session management, language preference (Turkish/English) and basic security. Where analytics or marketing cookies are used, separate consent is obtained. You can manage cookies in your browser settings, though disabling essential cookies may affect some functionality.
12. Children's Privacy
Madvise is not directed at people under 18 and does not knowingly collect personal data from children. If we become aware that we hold a child's data, we delete it.
13. Changes to This Policy
We may update this policy from time to time. For material changes we update the "Last updated" date and, where appropriate, notify you separately. The current version is always available on this page.
14. Contact
For any privacy question, request or application:
Ege Mert Özcan
E-mail: info@pursula.com
Address: Mustafa Kemal Mahallesi, Bilişim İnovasyon Merkezi, ODTÜ Teknokent No:280 D:G, 06510 Çankaya / Ankara