Privacy notice
This notice explains which personal data IESDesk keeps, why we keep it, how long we keep it, and who helps us.
Last changed:
Who is responsible
Ağustos Teknoloji Ltd. Şti. is the data controller for IESDesk.
- Address: Barbaros Mah. Denizmen Sok. 21/2, 34668 Üsküdar/İstanbul, Türkiye
- Email: agustos@agustos.com
- Istanbul Trade Registry no.: 358564-0
- MERSIS no.: 0059004540100019
- Tax office: Üsküdar, tax no.: 0590045401
This is the information notice of Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK). It also gives the information that Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) require.
Send each question about your data to the email address above. When you write to us, the privacy notice of agustos.com covers your message.
The data we keep, and why
Each item below says what we keep, why we keep it, the legal ground, and how long we keep it. The legal grounds come from Article 5 of the KVKK and Article 6(1) of the GDPR.
Your account
- What we keep
- Your email address, and your password as a one-way hash. Nobody can read your password from the hash. We also keep the dates of your sign-up and your email confirmation, your saved diagram themes, and your API tokens. We keep each API token only as a one-way hash, with the name that you gave it, its last four characters and the time of its last use.
- Why
- We use it to give you a private account and to sign you in. We also use your email address to send the emails that the service needs.
- Legal ground
- Our contract with you (KVKK Article 5(2)(c), GDPR Article 6(1)(b)).
- How long
- While your account is open. For a closed account, see How long we keep data.
Sign-in records
- What we keep
- For each sign-in: the time, the IP address, and the browser details that your browser sends (name, version and operating system).
- Why
- We use them to keep you signed in and to protect your account against misuse.
- Legal ground
- Our contract with you, and our legitimate interest in a secure service (KVKK Article 5(2)(c) and (f), GDPR Article 6(1)(b) and (f)).
- How long
- Until you sign out, reset your password or close your account.
Your files and your work
- What we keep
-
The IES and LDT files that you upload to a batch or a job, and their file names.
The metadata that IESDesk reads from the files, and your edits.
For each metadata sheet that you download, a copy of its cell values. For each sheet that you upload, the list of problems that IESDesk found. IESDesk does not keep the sheet file that you upload.
The files that IESDesk makes for you: export ZIP files, diagram ZIP files and CSV files.
Photometric files are technical data. They can still hold personal data, for example the name of a test engineer.
- Why
- We use them to do the work that you ask for, and to show you your earlier work.
- Legal ground
- Our contract with you (KVKK Article 5(2)(c), GDPR Article 6(1)(b)).
- How long
-
- Uploaded files: 30 days after the upload. You can delete them earlier on the batch page.
- Export ZIP files: 30 days after the export. You can delete one earlier on the batch page.
- Diagram ZIP files: 30 days after the diagram job ends.
- BUG Rating and ULOR jobs: IESDesk deletes each uploaded file as soon as it has the result. The results and the CSV file stay for 30 days after the upload.
- Metadata sheets: 30 days after the download. The problem lists of the uploads go with their sheet.
- The history of your batches and diagram jobs, with the file names, the metadata and your edits, stays after the files are gone. It stays while your account is open, so that you can see your earlier work.
Files on the free tools
IES View, LDT View, and the one-file pages of BUG Rating and ULOR read your file and show the result. They keep no copy of the file, and you need no account.
Feedback
- What we keep
- The message that you send with "Send feedback", the page where you sent it, and the time.
- Why
- We use it to fix problems and to make IESDesk better.
- Legal ground
- Our legitimate interest in a better service (KVKK Article 5(2)(f), GDPR Article 6(1)(f)).
- How long
- While your account is open. For a closed account, see How long we keep data.
Product news
- What we keep
- The email address that you give in the news form, the date when you confirmed it, and the date of our last confirmation email.
- Why
- We send one email to confirm the address. We send news only to a confirmed address, and only the news that the form promised.
- Legal ground
- Your explicit consent (KVKK Article 5(1), GDPR Article 6(1)(a)). You can take back your consent at any time. Each news email will have an unsubscribe link, or you can write to us.
- How long
- Until you unsubscribe or ask us to delete it. If you do not confirm the address, we delete it 30 days after our last confirmation email. An address that you gave before 28 September 2026 gets its confirmation email when IESDesk launches.
Attempt limits
- What we keep
- Counters of the attempts to sign in, sign up, reset a password, confirm an email address, join the news list, and use the free tools. Each counter is keyed by your IP address, or by your account when you are signed in. A second counter limits the account emails that one address gets. It is keyed by a one-way hash of the email address, not by the address.
- Why
- We use them to stop automated attacks, and to stop floods of email to one person.
- Legal ground
- Our legitimate interest in a safe service (KVKK Article 5(2)(f), GDPR Article 6(1)(f)).
- How long
- A counter of attempts counts for 1 or 3 minutes, and the email counter for 1 hour. Then they stop counting. The cache deletes old entries when it stores new ones, normally within 2 weeks.
Page visits
- What we keep
- When you open a page of iesdesk.com, Plausible counts the visit for us. It keeps the page address, the address of the page that sent you, the browser, the operating system, the device type, and a location (country, region and city) that it finds from your IP address. Plausible stores no IP address, no raw browser details and no cookie. It counts a visitor with a code that changes each day, so it cannot link your visits across days or across websites. The password reset page, the email confirmation page and the news confirmation page send nothing to Plausible, because their address holds a secret link.
- Why
- We use the counts to learn which pages people use and how they find IESDesk.
- Legal ground
- Our legitimate interest in knowing how the site is used (KVKK Article 5(2)(f), GDPR Article 6(1)(f)).
- How long
- Plausible keeps the counts until we delete the IESDesk site from our Plausible account.
Server logs
- What we keep
- For each request to IESDesk: the time, the IP address, the browser details, the page address and the result. The logs hold no passwords, email addresses, file names or file content.
- Why
- We use them to keep the service safe, and to find and fix faults.
- Legal ground
- Our legitimate interest in a safe service that works (KVKK Article 5(2)(f), GDPR Article 6(1)(f)).
- How long
- Each version of the application keeps at most 10 MB of log, and removes older lines. Each week, the server removes the old versions with their logs and keeps the five newest.
How long we keep data
Each item above gives its period. These rules also apply:
- When you close your account, IESDesk at once deletes your sign-in records and your diagram themes. It also deletes your BUG Rating and ULOR jobs and your diagram ZIP files. Your API tokens stop working.
- A closed account keeps your email address, your password hash, the history of your batches and diagram jobs, and your feedback. Your uploaded files and export ZIP files go when their 30 days end.
- To delete all of it, write to agustos@agustos.com from the email address of your account. We delete your account and all data that belongs to it within 30 days.
- Deleted data stays in the daily server backups of Hetzner for up to 7 more days. Then it is gone.
- Each night, IESDesk also keeps an encrypted copy of the database and the uploaded files. Each copy stays for up to 31 days. Then it is gone.
- After we delete an account on request, we keep a one-way hash of its email address and the date. Nobody can read the address from the hash. We use it only to delete the data again if we must restore a backup. We delete the hash 60 days after the erase.
Who else handles data
These companies run parts of IESDesk for us. They use personal data only to give their service to us.
- Hetzner (Germany) runs the server that holds the database and the uploaded files. The server is in Falkenstein, Germany. Hetzner keeps daily backups of the whole server for up to 7 days.
- Cloudflare (United States) carries all traffic between your browser and the server, and protects the site against attacks. Its R2 storage keeps the files that IESDesk makes for you (export ZIP files, diagram ZIP files, and BUG Rating and ULOR CSV files) in its Eastern Europe (EEUR) location. R2 storage also keeps the encrypted nightly copies of the database and the uploaded files, in its EU jurisdiction.
- Resend (United States) sends the emails of IESDesk from its EU region in Ireland. The emails come from hello@mail.agustos.com.
- Plausible Insights OÜ (Estonia) counts the page visits on iesdesk.com. It stores its data in the EU and sets no cookie.
- UptimeRobot s. r. o. (Slovakia) checks every 5 minutes that three status pages of iesdesk.com answer. It gets no data about users.
We give data to a court or a public authority only when the law requires it (KVKK Article 5(2)(ç), GDPR Article 6(1)(c)).
Transfers abroad
- The server is in Germany, and Plausible keeps its data in the EU. Under the KVKK, storage on a server outside Türkiye counts as a transfer abroad.
- Cloudflare and Resend are companies in the United States. Cloudflare handles your traffic in the data centre nearest to you, which can be outside the EU and Türkiye.
We use the safeguards of Article 9 of the KVKK and Chapter V of the GDPR for these transfers, such as standard contracts. Ask us which safeguard applies to each company.
Your rights
Article 11 of the KVKK and Articles 15 to 22 of the GDPR give you these rights:
- Learn whether we process your personal data, and get a copy of it.
- Learn why we process it, and whether we use it only for that purpose.
- Learn who receives it, in Türkiye or abroad.
- Have wrong or incomplete data corrected.
- Have your data deleted.
- Have the recipients told about a correction or a deletion.
- Limit how we use your data.
- Get your data in a common, machine-readable format.
- Object to a use that relies on our legitimate interest.
- Object to a result that only automated analysis produces and that harms you. IESDesk makes no such decision about you.
- Take back your consent for product news at any time.
- Claim compensation for a loss that unlawful processing caused.
To use a right, write to agustos@agustos.com from the email address that your request is about. You can also send a letter to the address above. We answer within 30 days, free of charge.
You can also complain to a data protection authority. In Türkiye, this is the Personal Data Protection Board (KVKK Board). In the EU, you can complain to the authority of the country where you live or work.
No sale of data
We do not sell personal data. We do not share it with advertisers or data brokers. If your browser sends a Global Privacy Control signal, nothing changes, because there is no sale or sharing to stop.
Changes to this notice
We publish each change on this page and change the date at the top. When a change affects how we use your data, we tell you before the change takes effect.