Privacy policy
How Cupdesk Meet handles your data
1. Who is responsible
Cupdesk Meet is operated by Cupdesk (“we”). We are the data controller for the personal data described below. Contact: destek@cupdesk.com.
2. What we process and why
| Data | Who | Why | Kept for |
|---|---|---|---|
| Name, e-mail address and profile picture from your Google account | Members | Sign-in with a verified Google account; blocklist check for banned accounts; showing your name in meetings | While your account is active; deleted on request |
| Private address book: display names, optional e-mail and phone, notes, and links to other members you saved | Members (host only) | Your personal contacts list, groups and scheduled invites — visible only to you, not to other members | Until you remove the entry or delete your account |
Session cookie (cupdesk_sid) with IP address and browser type | Members | Keeping you signed in; detecting stolen sessions | Up to 7 days, or until you sign out |
| Display name you type before joining | Guests | Showing who is in the meeting; lobby admission by the host | With the meeting record (see 4) |
| IP address of lobby requests and of failed or abusive link attempts | Guests and visitors | Rate limiting, blocking link-guessing attacks | Security log, see 4 |
| Meeting records: room title, who joined and left, when | All participants | Meeting history for the host; troubleshooting | See 4 |
| Host actions (start/stop recording, mute, remove, admit) with IP address and browser type | Hosts and moderators | Tamper-evident audit trail (hash-chained) | For the life of the service, for accountability |
| Recordings (audio and video of the meeting) | All participants, only when the host starts a recording | Providing the recording to the host | Deleted automatically 30 minutes after the meeting ends, or earlier when the host confirms deletion |
Live audio, video, screen-sharing and chat are relayed by our media server in real time and are not stored unless the host starts a recording. Everyone in the room sees a recording indicator while a recording is running; it cannot be hidden.
3. Cookies and local storage
We use one essential cookie (the session cookie above). Your browser also stores preferences locally — language, theme, camera and microphone choices — which never leave your device. We use no analytics, no advertising and no third-party trackers; the site's security policy blocks third-party scripts.
4. Retention
Sessions expire after 7 days. Recordings are deleted 30 minutes after the meeting ends. Meeting, lobby and security records are kept as long as needed for security, troubleshooting and legal obligations, and are deleted or anonymised when no longer needed. You can ask us to delete your account data at any time.
5. Who else receives data
- Google LLC — only for signing in. Authentication happens on Google's pages under Google's privacy policy; we never receive your password.
- Resend, Inc. — only when a host sends a transactional meeting invite or reminder e-mail from Contacts or scheduled meetings. We pass recipient address, subject and message body; Resend delivers the mail and does not use it for marketing. See Resend's privacy policy.
- Our hosting provider — the service runs on a single server we rent in the European Union (Netherlands). The provider stores our data on our behalf and does not access it.
We do not sell or share personal data for marketing. We disclose data only when legally required.
6. Security
All connections use TLS; media streams are encrypted in transit (DTLS-SRTP). Sign-in requires a verified Google account; specific accounts can be blocked. Meeting links use long random keys, attempts to guess them are rate-limited, and sensitive host actions are written to a tamper-evident audit log. Please report vulnerabilities to destek@cupdesk.com (see security.txt).
7. Your rights
Under the GDPR and the Turkish Personal Data Protection Law (KVKK) you may ask for access to, correction or deletion of your data, object to processing, and lodge a complaint with your supervisory authority. Write to destek@cupdesk.com; we answer within 30 days.
8. Changes
We will post any changes on this page with a new “last updated” date.
Gizlilik politikası
Cupdesk Meet verilerinizi nasıl işler?
1. Veri sorumlusu
Cupdesk Meet, Cupdesk (“biz”) tarafından işletilir. Aşağıda açıklanan kişisel verilerin veri sorumlusuyuz. İletişim: destek@cupdesk.com.
2. Hangi verileri neden işliyoruz?
| Veri | Kim | Neden | Saklama süresi |
|---|---|---|---|
| Google hesabınızdaki ad, e-posta adresi ve profil fotoğrafı | Üyeler | Doğrulanmış Google hesabıyla giriş; yasaklı hesaplar için engel listesi kontrolü; toplantıda adınızın gösterilmesi | Hesabınız aktif kaldığı sürece; talep üzerine silinir |
| Özel rehber: görünen adlar, isteğe bağlı e-posta ve telefon, notlar ve kaydettiğiniz diğer üyelere bağlantılar | Üyeler (yalnız toplantı sahibi) | Kişisel rehberiniz, gruplar ve planlanan davetler — yalnız size görünür, diğer üyelere açılmaz | Siz silene veya hesabınızı kapatana kadar |
Oturum çerezi (cupdesk_sid) ile IP adresi ve tarayıcı türü | Üyeler | Oturumunuzu açık tutma; çalınan oturumları tespit etme | En fazla 7 gün ya da çıkış yapana kadar |
| Katılmadan önce yazdığınız görünen ad | Misafirler | Toplantıda kimin olduğunu göstermek; toplantı sahibinin lobiden kabul etmesi | Toplantı kaydıyla birlikte (bkz. 4) |
| Lobi isteklerinin ve başarısız/kötü niyetli bağlantı denemelerinin IP adresi | Misafirler ve ziyaretçiler | Hız sınırlama, bağlantı tahmin saldırılarını engelleme | Güvenlik kaydı, bkz. 4 |
| Toplantı kayıtları: oda başlığı, kimin ne zaman katılıp ayrıldığı | Tüm katılımcılar | Toplantı sahibi için toplantı geçmişi; sorun giderme | Bkz. 4 |
| Toplantı sahibi işlemleri (kayıt başlat/durdur, sustur, çıkar, kabul et) ile IP adresi ve tarayıcı türü | Toplantı sahipleri ve moderatörler | Değiştirilmesi fark edilebilir denetim izi (zincirli özet) | Hesap verebilirlik için hizmet süresince |
| Toplantı kayıtları (ses ve görüntü) | Tüm katılımcılar, yalnız toplantı sahibi kayıt başlatırsa | Kaydın toplantı sahibine sunulması | Toplantı bittikten 30 dakika sonra otomatik silinir; toplantı sahibi onaylarsa daha erken |
Canlı ses, görüntü, ekran paylaşımı ve sohbet medya sunucumuz üzerinden anlık aktarılır; toplantı sahibi kayıt başlatmadıkça saklanmaz. Kayıt sürerken odadaki herkes kayıt göstergesini görür; bu gösterge gizlenemez.
3. Çerezler ve yerel depolama
Yalnız bir zorunlu çerez kullanırız (yukarıdaki oturum çerezi). Tarayıcınız dil, tema, kamera ve mikrofon tercihlerinizi cihazınızda saklar; bunlar cihazınızdan çıkmaz. Analitik, reklam ya da üçüncü taraf izleyici kullanmıyoruz; sitenin güvenlik politikası üçüncü taraf betikleri engeller.
4. Saklama
Oturumlar 7 gün sonra sona erer. Kayıtlar toplantı bittikten 30 dakika sonra silinir. Toplantı, lobi ve güvenlik kayıtları güvenlik, sorun giderme ve yasal yükümlülükler için gerektiği sürece tutulur; gereksiz hale geldiğinde silinir ya da anonimleştirilir. Hesap verilerinizin silinmesini her zaman isteyebilirsiniz.
5. Verileri başka kim alır?
- Google LLC — yalnız giriş için. Kimlik doğrulaması Google'ın sayfalarında, Google'ın gizlilik politikası kapsamında yapılır; şifrenizi hiçbir zaman almayız.
- Resend, Inc. — yalnız bir toplantı sahibi Kişiler veya planlanan toplantılardan işlem e-postası (davet veya hatırlatma) gönderdiğinde. Alıcı adresi, konu ve mesaj gövdesini iletiriz; Resend yalnız teslimat yapar, pazarlama için kullanmaz. Bkz. Resend gizlilik politikası.
- Barındırma sağlayıcımız — hizmet, Avrupa Birliği'nde (Hollanda) kiraladığımız tek bir sunucuda çalışır. Sağlayıcı verileri bizim adımıza saklar, erişmez.
Kişisel verileri pazarlama amacıyla satmaz ya da paylaşmayız. Yalnız yasal zorunluluk halinde açıklarız.
6. Güvenlik
Tüm bağlantılar TLS kullanır; medya akışları aktarımda şifrelidir (DTLS-SRTP). Giriş doğrulanmış Google hesabı gerektirir; belirli hesaplar engellenebilir. Toplantı bağlantıları uzun rastgele anahtarlar kullanır, tahmin denemeleri hız sınırına tabidir ve hassas toplantı sahibi işlemleri değiştirilmesi fark edilebilir bir denetim kaydına yazılır. Güvenlik açıklarını destek@cupdesk.com adresine bildirin (bkz. security.txt).
7. Haklarınız
KVKK ve GDPR kapsamında verilerinize erişme, düzeltme, silme, işlemeye itiraz etme ve denetim makamına (Türkiye'de Kişisel Verileri Koruma Kurulu) şikâyette bulunma hakkınız vardır. destek@cupdesk.com adresine yazın; 30 gün içinde yanıtlarız.
8. Değişiklikler
Değişiklikleri bu sayfada yeni bir “son güncelleme” tarihiyle yayımlarız.