CEVIZ 3D VIEWER & CONVERTER PRIVACY POLICY AND PERSONAL DATA PROCESSING DISCLOSURE
🇹🇷 Türkçe1. IDENTITY OF THE DATA CONTROLLER
In the capacity of data controller under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR"):
| Trade Name | Ceviz Biyoteknoloji Anonim Şirketi |
| Short Name | "Ceviz" or "the Company" |
| Address | Çalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 Unit 3, Merkez/Kütahya, Türkiye |
| Tax Office | Çinili |
| Tax ID | 2071296229 |
| Business Activity | Research and experimental development in biotechnology (NACE 721002) |
| info@cevizbiotech.com |
2. PURPOSE AND SCOPE
This Privacy Policy ("Policy") has been prepared to fulfil our disclosure obligations regarding personal data processed through the Ceviz 3D Viewer & Converter application ("Application") developed by Ceviz.
Ceviz 3D Viewer & Converter is a platform that offers viewing, inspecting and converting 3D mesh files in STL, OBJ, PLY, GLB, GLTF, 3MF and DAE formats to STL. The Application is accessible via web browser, Apple App Store (iOS) and Google Play Store (Android).
This Policy applies in accordance with KVKK, GDPR, Turkish Electronic Commerce Regulation Law No. 6563, and related secondary legislation.
By using the Application, creating an account, or accessing the Application in guest mode, you acknowledge that you have read and understood the data processing activities described in this Policy.
3. DEFINITIONS
| Term | Description |
|---|---|
| User | A natural person who uses the Application by creating an account or in guest mode (e.g. engineers, designers, students, physicians) |
| Guest User | A person who uses the Application with limited features without creating an account |
| Registered User | A person who uses the Application by signing in with an e-mail address, Google, or Apple account |
| Mesh File | 3D model files in STL, OBJ, PLY, GLB, GLTF, 3MF and DAE formats |
| Conversion | The file translation process from supported source formats to STL format |
| Personal Data | Any information relating to an identified or identifiable natural person |
| Processing | Any operation performed on personal data, such as collection, recording, storage, alteration, disclosure, transfer, classification, or deletion |
4. CATEGORIES OF PERSONAL DATA PROCESSED
Ceviz processes the following categories of data to deliver the Application's functionality:
4.1. Account and Identity Data (Registered Users)
- First name, last name
- E-mail address
- Password (cryptographically hashed by Firebase Authentication; Ceviz cannot access the plain-text form of your password)
- Google or Apple account identifier (when social sign-in is used)
- Profile photo (optional)
4.2. Guest Session Data
- Anonymous session identifier generated by Firebase Anonymous Authentication
- File data stored temporarily for the duration of the session
Note: No name, surname, e-mail address, or any identifying information is requested from guest users. The anonymous session identifier cannot be linked to the user's real identity.
4.3. 3D File Data
- Mesh files uploaded by the user for viewing or conversion (STL, OBJ, PLY, GLB, GLTF, 3MF, DAE)
- STL output files produced as a result of conversion
- File name, size, format, and upload date
Important: Ceviz does not analyse, classify, or share uploaded 3D files with third parties. Files are processed solely for the technical purpose of viewing and conversion.
4.4. Sharing Data
- When a model is shared: recipient's username, sharing date, and link validity period (30 days)
4.5. Subscription and Payment Data
- Subscription plan (Free, Pro, Enterprise) and status
- Subscription start and end dates
Important: Payment transactions are managed entirely by Apple App Store and Google Play Store. Ceviz does not collect, store, or process any credit card numbers, bank account details, or other payment instrument data.
4.6. Technical and Device Data
- Device model, operating system version
- Browser type and version (for web users)
- Application version
- Crash reports and error logs
- IP address (solely for security and App Check verification purposes)
4.7. Notification Data
- Firebase Cloud Messaging (FCM) push notification token — stored to deliver conversion status and account update notifications
4.8. Usage Data
- Sign-in/sign-out timestamps
- Viewing and conversion counts (for quota tracking)
- In-app navigation statistics (aggregated)
5. PURPOSES AND LEGAL BASES FOR PROCESSING
| Data Category | Purpose | KVKK Legal Basis (Art. 5) | GDPR Legal Basis (Art. 6) |
|---|---|---|---|
| Account & Identity (4.1) | Account creation, authentication, service delivery | Performance of a contract (Art. 5/2-c) | Performance of a contract (Art. 6/1-b) |
| Guest Session (4.2) | Providing a trial experience without account registration | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
| 3D File Data (4.3) | File viewing and format conversion service delivery | Performance of a contract (Art. 5/2-c) | Performance of a contract (Art. 6/1-b) |
| Sharing Data (4.4) | User-to-user model sharing | Performance of a contract (Art. 5/2-c) | Performance of a contract (Art. 6/1-b) |
| Subscription Data (4.5) | Plan management, quota tracking | Performance of a contract (Art. 5/2-c) | Performance of a contract (Art. 6/1-b) |
| Technical Data (4.6) | Application stability, debugging, security | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
| FCM Token (4.7) | Conversion status notifications | Explicit consent (Art. 5/1) | Consent (Art. 6/1-a) |
| Usage Data (4.8) | Service quality improvement, quota management | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
6. FILE SECURITY AND CONFIDENTIALITY
Ceviz applies the following principles to protect the security and confidentiality of uploaded 3D files:
6.1. File Isolation: Each user's files are stored in user-specific directories on Firebase Storage (conversions/{userId}/...). No user can access another user's files under any circumstances. Access control is enforced through Firestore Security Rules and Storage Security Rules.
6.2. Encryption in Transit: All data traffic, including file uploads and downloads, is encrypted using TLS 1.2+ protocol.
6.3. Encryption at Rest: All files on Firebase Storage are encrypted at rest using AES-256.
6.4. Automatic Deletion: Files uploaded for conversion purposes are automatically deleted from the server within the retention period specified after the operation is completed (see Section 9).
6.5. No Content Analysis: Ceviz does not analyse, scan, classify, or use uploaded files for machine learning model training for any purpose other than viewing and conversion.
Important — Medical and Industrial Files: Ceviz 3D Viewer & Converter is not a medical device and should not be used for medical diagnosis, treatment, or surgical planning purposes. Ceviz provides no guarantee regarding the accuracy or clinical suitability of files viewed or converted through the Application. The confidentiality and intellectual property rights of industrial CAD files are entirely the User's responsibility.
7. DEVICE PERMISSIONS
The Application requests the following device permissions to deliver its functionality:
| Permission | Purpose | Required? |
|---|---|---|
| File/Media Access | 3D model file selection and upload | Required for file upload |
| Camera (iOS/Android) | Viewing models in the real environment via AR (Augmented Reality) mode | Optional; requested only when AR is used |
| Notifications | Delivering conversion status and account update notifications | Optional; you may decline |
| Internet Access | Data synchronisation with Firebase, file upload/download | Required |
| Network Status | Connectivity checks and offline alerts | Required |
About AR Mode: Camera permission is only requested when the AR feature is used. Camera footage is not recorded, sent to any server, or processed. All AR processing takes place on-device.
8. DATA SECURITY MEASURES
Ceviz implements the following administrative and technical measures to ensure the security of personal data:
Technical Measures:
- Encryption in transit: All data traffic is encrypted using TLS 1.2+ protocol
- Encryption at rest: All data on Firebase Storage and Firestore is encrypted at rest using AES-256
- Firebase App Check: All requests to the Application are verified via Play Integrity (Android) and App Attest (iOS); access from fraudulent clients is blocked
- Firestore Security Rules and Storage Security Rules: Layered access control ensures each user can only access their own data
- Password security: Passwords are hashed by Firebase Authentication using the scrypt algorithm; Ceviz cannot access passwords in plain text
- Error tracking: Crashlytics collects technical logs stripped of personally identifiable information
Administrative Measures:
- Written Confidentiality and Personal Data Protection Commitments have been signed with company employees
- Data access is regulated on a need-to-know basis
- A data breach response procedure has been established
9. DATA RETENTION PERIODS
Ceviz retains personal data only for the period necessary for the purpose of processing.
| Data Type | Retention Period |
|---|---|
| Account and identity data | As long as the account remains active |
| Guest session data | For the duration of the session; automatically deleted when the session ends |
| Files uploaded for viewing | Retained as long as the account is active unless deleted by the user |
| Files uploaded for conversion | Deleted from the server within 7 days after conversion is completed |
| Converted STL output files | Deleted from the server within 7 days after the user downloads them |
| Shared models | Sharing link is valid for 30 days; automatically deleted after expiry |
| Account deletion | Initiated immediately; all data is deleted |
| Firebase backups | Removed from Firebase infrastructure backups within 180 days after deletion |
| Crashlytics logs | Automatically deleted after 90 days |
| Data retained for legal obligations | Up to 10 years for tax legislation (invoice/contract data only) |
Important: Account deletion is irreversible. After deleting your account, you will no longer have access to your files, conversion history, or shared models.
10. TRANSFER OF PERSONAL DATA
10.1. Domestic Transfer
Your personal data is transferred only to authorised personnel within Ceviz for the purpose of service delivery. No data is transferred to any third-party person or organisation.
10.2. International Transfer
The Application uses Google Firebase services as its infrastructure. Firebase data is hosted within the European Union, in the europe-west3 region located in Frankfurt, Germany, in compliance with KVKK and GDPR. The reasons for selecting this region:
- Falls within the scope of an EU Commission adequacy decision
- Personal data of Republic of Türkiye citizens is processed under EU GDPR protection
- Qualifies as a country with adequate protection under KVKK Art. 9
The service provider, Google Ireland Limited, operates as a data processor in accordance with GDPR-compliant Standard Contractual Clauses (SCC).
11. THIRD-PARTY SERVICE PROVIDERS
The following Google/Firebase services are used in the capacity of "data processor":
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Firebase Authentication | Account management and authentication | E-mail, hashed password, social sign-in ID | europe-west3 |
| Cloud Firestore | Structured data (profiles, conversion records) | Data listed in Section 4 | europe-west3 |
| Firebase Storage | 3D file storage | Mesh files, conversion outputs | europe-west3 |
| Firebase Cloud Messaging (FCM) | Push notification delivery | FCM token, notification content | Global (Google infrastructure) |
| Firebase App Check | Fraudulent client prevention | Device integrity token | Global |
| Firebase Crashlytics | Error tracking | Anonymous technical logs | Global |
| Cloud Functions | File conversion and background jobs | Operation-dependent | europe-west3 |
Google's privacy policy: https://policies.google.com/privacy
Firebase data processing terms: https://firebase.google.com/terms/data-processing-terms
11.1. Advertising Services (Free Plan)
Advertisements may be displayed to users on the free plan. When an advertising network integration is implemented, the advertising provider used and the data processed will be disclosed by updating this policy. The advertising provider will process only the minimum data necessary for ad serving (such as device type and general location). No advertisements are shown to Pro and Enterprise plan users.
12. USER RESPONSIBILITIES
By using the Application, the User accepts the following obligations:
12.1. File Content Responsibility: The User represents and warrants that they own the intellectual property rights to the 3D files they upload or are authorised to upload such files. Liability arising from copyright infringement or unauthorised file upload rests exclusively with the User.
12.2. Industrial Confidentiality: If confidential or trade-secret CAD files are uploaded to the Application, maintaining the confidentiality of such files is the User's responsibility. Ceviz applies the security measures described in Section 6; however, Users should evaluate their own corporate confidentiality policies before uploading sensitive industrial data.
12.3. Medical File Disclaimer: Ceviz 3D Viewer & Converter is not a medical device. The User should not use the Application for medical diagnosis, treatment, or surgical planning purposes. For medical-purpose 3D model needs, the Ceviz App platform should be used.
12.4. Account Security: The User is obliged to keep their account password confidential, not share it with third parties, and immediately change their password in case of suspected unauthorised access.
12.5. Lawful Use: The User is exclusively responsible for the content and legality of files uploaded to the Application.
Legal liability arising from breach of these obligations rests exclusively with the User; Ceviz bears no responsibility.
13. CHILDREN'S PERSONAL DATA
Ceviz 3D Viewer & Converter is open to users of all ages. However, account creation by users under the age of 18 requires the consent of their legal representatives (parent/guardian). Guest mode can be used by everyone without age restriction; no personal data is collected in this mode.
Ceviz does not knowingly collect personal data from individuals under 18 without legal representative consent. If it is discovered that an account has been created without legal representative consent, the account and associated data will be deleted immediately.
14. DATA SUBJECT RIGHTS (KVKK ART. 11 AND GDPR)
Under KVKK Article 11 and GDPR, you have the following rights as a data subject:
- To learn whether your personal data is being processed
- To request information if your personal data has been processed
- To learn the purpose of processing and whether data is being used in accordance with its purpose
- To know the third parties to whom your personal data has been transferred, domestically or internationally
- To request correction of your personal data if it has been processed incompletely or inaccurately
- To request deletion or destruction of your personal data under the conditions set out in KVKK Article 7
- To request that operations carried out under points (5) and (6) be notified to third parties to whom your personal data has been transferred
- To object to the emergence of a result against you through the exclusive analysis of processed data by automated systems
- To claim compensation for damages arising from the unlawful processing of your personal data
Additionally under GDPR:
- Right to data portability — receiving your data in a structured format
- Right to object
- Right to restriction of processing
- Right to lodge a complaint with a supervisory authority — for Türkiye: Personal Data Protection Authority (KVKK); for EU: the relevant national supervisory authority
How to Apply
You may exercise these rights through any of the following channels:
- E-mail: info@cevizbiotech.com (subject: "KVKK Data Subject Request")
- Written application: Çalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 Unit 3, Merkez/Kütahya
- In-app: Profile > Delete My Account
Your request will be responded to free of charge within 30 days at the latest.
15. DATA BREACH NOTIFICATION
In the event that your personal data is subject to a data breach such as unauthorised access, disclosure, alteration, loss, or destruction, Ceviz will:
- Notify the Personal Data Protection Board within 72 hours in accordance with KVKK Article 12/5
- Notify the competent supervisory authority within 72 hours in accordance with GDPR Article 33
- Where the breach poses a high risk to your rights and freedoms, inform you without delay via in-app notification and e-mail
16. ACCOUNT AND DATA DELETION
You have full control over your data:
16.1. In-App Account Deletion: You can delete your account by following Profile > Delete My Account. When account deletion is initiated, the system performs the following steps immediately and irreversibly:
- All your 3D files and conversion outputs in Firebase Storage are deleted
- All your conversion records and sharing data in Firestore are deleted
- Your user profile document in Firestore is deleted
- Your Firebase Authentication record is deleted
- You are automatically signed out of the Application
16.2. Request via E-mail: If you cannot access the in-app deletion method, you can initiate the deletion process by sending a request to info@cevizbiotech.com. Your request will be processed within 7 days at the latest.
16.3. Deletion from Backups: Due to Firebase's infrastructure backup process, deleted data is completely removed from Google's backup layers within 180 days. During this period, backups can only be accessed by Google for disaster recovery purposes; no party, including Ceviz, can access these backups.
16.4. Irreversibility: Account deletion is irreversible. Deleted files and conversion history cannot be recovered under any circumstances. We recommend downloading any files you need to your own device before initiating the process.
17. COOKIES AND SIMILAR TECHNOLOGIES
Our mobile application does not use "cookies" in the traditional web sense. However, Firebase SDKs store temporary identifiers (tokens) in device memory for session management and App Check. These identifiers are not used for advertising or tracking purposes.
Our web version (viewer.cevizbiotech.com) uses mandatory technical cookies for Firebase Authentication session management. These cookies are used solely for session verification and are not shared with third parties.
18. APP STORES
Ceviz 3D Viewer & Converter is distributed through Apple App Store and Google Play Store, and is also accessible via web browser at viewer.cevizbiotech.com. When you download the Application, the relevant store's privacy policy and terms of service also apply:
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Google Play Privacy Policy: https://policies.google.com/privacy
Data related to your store account (download history, subscription payments, etc.) is processed directly by the relevant store; Ceviz has no access to this data.
19. CHANGES TO THIS POLICY
Ceviz may update this Policy from time to time. When material changes are made:
- The new version will be published in the Application and at cevizbiotech.com/privacy/viewer-en.html
- Registered users will be notified via push notification and/or e-mail
- A 30-day transition period will be provided before material changes take effect
It is the User's responsibility to follow the current version of the Policy.
20. GOVERNING LAW AND JURISDICTION
The interpretation and application of this Policy shall be governed by the laws of the Republic of Türkiye. The Courts and Enforcement Offices of Kütahya shall have jurisdiction over any disputes arising hereunder. Data subjects residing in the EU reserve their right to lodge a complaint with the supervisory authority of their member state.
21. CONTACT
For any questions, requests, and complaints regarding this Policy or your personal data:
Ceviz Biyoteknoloji A.Ş.
Çalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 Unit 3, Merkez/Kütahya, Türkiye
E-mail: info@cevizbiotech.com
This Policy entered into force on June 2, 2026.