Skip to content
SessiONN
tr en de
Download
Legal

Privacy Policy

What SessiONN processes, where it is stored, and what is never collected at all.

Last updated:

01 Scope

This policy covers the SessiONN remote support application and the sessionn.app website. The data controller is LAICOS Bilişim Yazılım ve Bilgi Sistemleri İthalat İhracat Limited Şirketi; contact details are at the bottom of this page.

02 How the product works

SessiONN shows one person's computer screen to a support technician, with that person granting permission every single time. When the application starts, it generates a nine digit access code and a single use PIN. A connection is established only after the code has been read out to the other party and the on screen consent has been given.

Without consent the screen is not even captured. Capture starts after consent, not before.

03 What is never collected

The following is not a setting that can be switched on; the product is simply not written to do it:

  • No screenshots and no video recording. There is no recording feature.
  • Clipboard content is not stored. Only the event itself is logged: direction, type, size, time.
  • The content of transferred files is not stored. Again, only the event is logged.
  • There is no keylogger.
  • No third party advertising or profiling trackers are used.

04 What is processed

DataWhy
Account email addressRegistered user sign in, address book and account correspondence
Terminal number (9 digits)To identify the target of a connection
Session metadata: who connected, when, for how longSecurity, abuse investigation and support history
Connection events: direction, type, size and time of clipboard and file transfersA trace of what happened in the session, without the content
Access attempts and audit trailSo that unauthorised access attempts are visible
Device network address (encrypted)So that a connection can be established

05 Passwords and secrets

Account passwords, the terminal secret and the unattended access password are stored only as irreversible hashes. The plain values are not present in the database; a forgotten password cannot be read back to you, only reset.

06 Why the network address is encrypted and the audit trail is hashed

Two different needs call for two different methods:

  • The address in the audit trail (for who did what investigations) is kept as an irreversible hash. The address cannot be recovered from it.
  • The address used to connect has to be reversible, because it must be decrypted in order to connect. It is stored encrypted with AES-256-GCM and the key is not in the database. If a database backup were to leave the building on its own, the addresses would be unreadable.

The connection address is live data, not history: it is cleared when the terminal goes offline. SessiONN keeps no record of where a user was on any given date.

07 Transport security

All traffic is encrypted in transit with TLS. Both sides connect outbound to the relay server, which passes bytes between them; it does not inspect content and does not record frames. The server log contains only a masked connection code, the channel and the time.

To be straight about it: today the stream is decrypted at the server. An end to end encryption layer, where the server can never see the content, is planned but not yet live. We do not present an unbuilt safeguard as if it existed.

08 Where data is stored

Data is processed on servers hosted in Türkiye (Istanbul). There is no onward transfer abroad. For users located in the European Union this means personal data is processed in a country outside the EU; the processing is based on the performance of a contract under Article 6(1)(b) GDPR.

09 Unattended access

Connecting to a computer without asking for consent each time is possible only if the owner of that computer sets it up explicitly and with their own hands. Such access is tied to a person, requires a separate password and can be revoked at any moment. There is no hidden mode of access concealed from the user.

10 Retention

Session metadata and the audit trail are kept for as long as they are needed for security review. When you close your account your account data is deleted; only records that do not directly identify you remain in the audit trail, for a limited period, for abuse investigation. The connection address is cleared when the terminal goes offline.

11 Your rights

Under the Turkish Personal Data Protection Law (KVKK) Article 11 and, if you are in the European Union, Articles 15 to 22 GDPR, you have the right to access your data, to have it corrected, erased or its processing restricted, to receive it in a portable format and to object to processing. Send your request to the address at the bottom of this page; it will be answered within 30 days at the latest.

12 Cookies

This site uses no advertising or profiling cookies. The only cookie is a strictly necessary session cookie on the partner application page. Fonts are hosted on our own server; no request is made to an external font service. Details are in the Cookie Policy.

13 Security incidents

If we determine that personal data has been unlawfully obtained by others, we notify the affected individuals and the Turkish Personal Data Protection Authority as soon as possible.

14 Changes

This policy may be updated. The current version is always published on this page and carries its last updated date at the top.

Contact and requests

Questions about this text and data subject requests can be sent to [email protected] or in writing to Caferağa Mah. General Asım Gündüz Cad. Bahariye Plaza No: 62/5, Kadıköy / İstanbul, Türkiye.

Legal nameLAICOS Bilişim Yazılım ve Bilgi Sistemleri İthalat İhracat Limited Şirketi
AddressCaferağa Mah. General Asım Gündüz Cad. Bahariye Plaza No: 62/5, Kadıköy / İstanbul, Türkiye
Tax office / Tax IDKadıköy Vergi Dairesi (034272) / 6081463620
MERSIS no0608-1463-6200-0001
Trade registry no367228-5
Company email[email protected]
Email[email protected]
Phone0216 606 54 84