SOSPITA YAZILIM LIMITED ŞİRKETİ (“Sospita”, “Sospita Software”, “we”, “us”, or “our”) develops and provides enterprise platforms, business applications, professional mobile applications, and consumer software.
We are committed to protecting personal data and designing our services with privacy, security, responsible use of artificial intelligence, and confidentiality in mind.
This Privacy Policy explains how personal data may be collected, used, stored, disclosed, and protected when you use Sospita websites, applications, platforms, and related services.
Depending on the service and the circumstances, Sospita may act as a data controller, a data processor/service provider acting on behalf of an organization, or may provide applications in which certain information remains stored locally on the user’s device.
This Policy is intended to support compliance with applicable privacy legislation, including the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where applicable, the EU General Data Protection Regulation (“GDPR”).
1. Services Covered by This Policy
This Privacy Policy applies to Sospita-operated websites and current or future Sospita software products, including, where applicable:
Sospita SafeGuard
Sospita HSE Platform and its modules
Sospita Risk Assessment
My Checklists
Sospita Athletic Performance
Huner
other applications and services released by Sospita Software that reference this Privacy Policy
Individual products may provide additional privacy notices where a particular feature, integration, or category of information requires more specific explanation.
Separate Terms of Use may apply to each product.
2. Our Role in Processing Personal Data
2.1 When Sospita Acts as a Data Controller
Sospita generally acts as a data controller when we determine why and how personal data is processed, including for:
visitors to our corporate website;
people who contact us;
demo and information requests;
customer and prospective-customer administration;
billing and subscription administration;
direct users of Sospita applications where Sospita determines the processing purposes;
account security and fraud prevention;
product administration and support;
service improvement where permitted by law;
legal and regulatory compliance.
For some direct-to-consumer products, including individual use of sports or professional applications, Sospita may therefore act as the controller of account and cloud-service information.
2.2 When Sospita Acts as a Processor
Where an organization such as an employer, club, academy, contractor organization, or other customer uses a Sospita service to manage its users or operational records, the organization will generally determine:
whose personal data is entered;
which information is collected;
why it is processed;
who may access it;
how long it should be retained.
In those circumstances, the customer organization generally acts as the data controller and Sospita acts as a data processor, processing the information according to the customer’s instructions and the applicable agreement.
Examples may include:
Permit to Work records;
observations and safety records;
risk assessments;
incident investigations;
contractor and personnel records;
audit records;
club membership records;
athlete records managed by a club;
attendance and training records;
club-administered performance measurements.
Where Sospita acts only as a processor, the customer organization is responsible for establishing the applicable legal basis for processing and for providing required notices to individuals.
2.3 Local-First Applications
Some Sospita applications are designed so that some or all user-created information is stored locally on the user’s phone or tablet.
Depending on the application and features enabled, this may include:
risk assessments;
checklists;
audit records;
photographs;
signatures;
evidence;
locally stored templates;
assessment history.
Where information remains only on the device and is not transmitted to Sospita, Sospita does not receive or control that content.
Information may nevertheless leave the device when the user deliberately:
exports or shares a report;
creates a backup;
uses a cloud feature;
submits information to support;
enables an online or AI-supported feature.
The application will determine which of these capabilities are available.
3. Categories of Personal Data
The information processed depends on the Sospita product used.
3.1 Account and Identification Information
We may process information such as:
name and surname;
email address;
account identifier;
organization or club affiliation;
role and permissions;
preferred language;
profile information;
authentication and account-security information.
3.2 Organizational and Operational Records
Enterprise and professional applications may process information contained in business records such as:
Permit to Work records;
approvals and workflow actions;
observations;
risk assessments;
incident and investigation records;
findings and corrective actions;
contractor information;
competency information;
audit records;
checklists;
comments and notes;
photographs and attachments;
signatures where enabled;
activity and audit logs.
The contents of such records are generally determined by the organization or user creating them.
3.3 Sports, Training and Performance Information
Sports and performance services may process:
training programmes;
scheduled activities;
attendance;
completed workouts;
exercise results;
progress information;
performance measurements;
club or team membership;
coach-athlete relationships;
match or game statistics;
athlete statistics;
training history;
performance goals.
Performance parameters may vary depending on the sport, club, coach, or individual user.
3.4 Health, Wellness and Injury Information
Where specifically enabled by the user or customer, certain sports features may process health or wellness-related information, including:
height and weight;
injury information;
injury status and history;
activity data;
sleep information;
energy or calorie information;
wellness indicators;
recovery-related information;
other health or fitness information entered by the user or authorized organization.
Such data may qualify as special-category personal data under GDPR or special categories of personal data under KVKK and will be processed only where an appropriate legal condition applies.
Health data receives enhanced legal protection under applicable privacy laws.
We do not assume that all information entered into a sports application is non-medical. Injury or health-related information may be legally treated as health data depending on its content and context.
3.5 Apple Health and Health Connect Information
Where supported and enabled, Sospita Athletic Performance may request permission to read limited health and fitness information through Apple HealthKit or Android Health Connect.
The currently supported information includes:
sleep information; and
total calories or energy used.
Access is optional, permission-based, and controlled through the user’s device settings.
The underlying numerical sleep and calorie/energy values are processed on the user’s device. They are not transmitted to Sospita’s backend, stored in the Sospita database, or sent to Sospita’s AI service provider.
The application may derive limited categorical indicators from these values, such as sleep trend, sleep consistency, recovery state, burn trend, source and coverage information. These derived indicators do not contain the underlying numerical health values.
Derived indicators may be transmitted to Sospita’s backend and stored as part of daily coaching records and monthly athlete evaluation records. They are used by Sospita’s application logic to support features such as Recovery & Readiness information.
These health-derived indicators are not sent to OpenAI as part of Athletic Performance AI prompts.
Users can enable or revoke access to health information through their device settings.
Sospita does not use health or fitness information obtained through HealthKit or Health Connect for advertising or marketing.
3.6 Uploaded Content
Depending on the product, users may provide:
photographs;
videos;
documents;
evidence;
signatures;
training materials;
programme content;
profile images;
other user-generated content.
Users and customer organizations are responsible for ensuring that they have the authority to upload personal data relating to other individuals.
3.7 Technical and Security Information
When online services are used, we may process technical information such as:
IP address;
browser and device type;
operating system;
application version;
login and authentication events;
timestamps;
security events;
diagnostic information;
crash and error information;
performance logs;
request metadata.
This information is used primarily to operate, protect, troubleshoot, and improve our services.
3.8 Subscription and Transaction Information
We may process information relating to:
subscription status;
purchased products or modules;
subscription tier;
transaction references;
entitlement status;
billing contact information;
renewal or expiration status.
Purchases made through Apple App Store or Google Play are processed by the relevant platform.
Sospita generally does not receive the user’s full payment-card details from those platforms.
Other payment or entitlement service providers may be used where specified for the relevant service.
3.9 Website and Communication Information
When you use our website or contact us, we may process:
contact details;
company information;
demo requests;
support correspondence;
information included in messages;
website security and anti-abuse information;
limited analytics information.
4. Purposes of Processing
Depending on our role and the relevant service, personal data may be processed to:
provide and operate Sospita services;
create and administer accounts;
authenticate users;
manage access and permissions;
deliver customer-requested workflows;
maintain records and audit trails;
provide training and performance functionality;
generate reports;
support subscription and entitlement management;
respond to support requests;
prevent misuse, fraud, and security incidents;
diagnose technical problems;
maintain service reliability;
improve functionality;
comply with legal obligations;
establish, exercise, or defend legal claims;
provide AI-assisted functionality where enabled.
We do not sell personal data.
5. Artificial Intelligence
Certain Sospita products may include AI-assisted functionality.
Examples may include:
review of safety-related content;
identification of possible omissions or inconsistencies;
coaching suggestions;
performance insights;
athlete evaluation reports;
incident-analysis support;
summarization or structured recommendations.
Depending on the product and feature, AI processing may use information supplied by the user or organization, such as:
workflow content;
observations;
incident information;
workout information;
performance measurements;
attendance;
statistics;
injury or wellness information where specifically enabled and legally permitted.
For Sospita Athletic Performance, AI coaching and athlete evaluation requests may include app information such as schedules, attendance, training adherence, fitness goals, performance measurements, game statistics, sport, position, age or age group and sex, and, where recorded in the app, nutrition logs and active injury information. These requests do not include sleep or calorie/energy information obtained through Apple HealthKit or Android Health Connect, or the health indicators derived from that information.
Where an AI feature requires information to be processed by an external AI service provider, Sospita may transmit the information necessary to provide that feature.
Relevant service providers and applicable transfer arrangements are identified where appropriate in our Subprocessor and Service Provider information.
Sospita’s design principle is:
“AI assists; people decide.”
AI output is intended to support users and professionals. It is not intended to replace professional judgment.
In particular:
AI does not make final Permit to Work approvals;
AI does not independently make final safety decisions;
AI coaching output is not medical diagnosis or medical treatment;
AI-generated athlete evaluation is intended as decision support for the athlete or coach;
AI-generated output should be reviewed before being relied upon for important decisions.
We do not use AI output as the sole basis for decisions producing legal or similarly significant effects on an individual.
Sospita AI integrations are designed not to create a persistent AI profile of the user.
AI requests are intended to contain only information required for the requested feature and, where applicable, limited prior AI-generated context. Sospita does not use AI provider-side conversation history or previous-response chaining for these requests.
6. Legal Bases for Processing
Where GDPR applies and Sospita acts as a controller, processing may rely on one or more of the following:
performance of a contract;
compliance with a legal obligation;
legitimate interests, where those interests are not overridden by the individual’s rights;
consent, where required;
another lawful basis permitted by applicable law.
Where special-category data such as health information is processed, an additional lawful condition applicable to special-category processing must also apply.
Where KVKK applies, personal data and special-category personal data are processed in accordance with the applicable conditions under Law No. 6698.
Where Sospita acts as a processor, the customer organization is responsible for determining the lawful basis for the underlying processing.
7. Clubs, Employers and Other Organizations
If you use a Sospita service through an employer, club, academy, school, contractor organization, or other customer:
that organization may create or manage your account;
it may determine which information is collected;
authorized administrators may access information associated with your account;
the organization may determine retention periods and access rights;
requests concerning organization-controlled data should ordinarily be directed to that organization.
Sospita supports customer organizations in responding to applicable data-subject requests where required by law and contract.
8. Children and Young Athletes
Some sports or club-management services may be used by clubs or academies that include younger athletes.
Where a club, academy or other organization manages a young athlete’s account, that organization is responsible for ensuring that it has an appropriate legal basis, authority, and any required parental or guardian authorization for the information it submits.
Sospita Athletic Performance includes functionality that allows organizations to record parent or guardian information and, where appropriate, parental/guardian consent.
Sospita provides this functionality on behalf of the relevant organization and does not independently verify every organization-managed parental consent.
Where Sospita directly determines the processing purposes for a child’s account, applicable legal requirements concerning parental or guardian authorization will apply.
9. Sharing of Personal Data
We may share personal data only where necessary and lawful, including with:
customer organizations administering the relevant service;
authorized users within those organizations;
hosting and infrastructure providers;
database and storage providers;
authentication providers;
email and notification providers;
payment and subscription platforms;
customer-support providers;
analytics and security providers;
AI service providers where an AI feature is used;
professional advisers;
authorities where required by law.
We require service providers acting on our behalf to process personal data only for authorized purposes and subject to appropriate contractual safeguards.
We do not sell personal data or health data to advertising platforms or data brokers.
10. Data Hosting and International Transfers
Application and service data hosted by Sospita is stored in EU regions.
Sospita operates from Türkiye and may use service providers with operations, support functions, affiliates or subprocessors in other jurisdictions.
Where personal data is transferred internationally, we use a lawful transfer mechanism applicable to the circumstances.
For transfers subject to GDPR, this may include:
an adequacy decision;
Standard Contractual Clauses;
another lawful safeguard or applicable derogation.
For transfers subject to KVKK, transfers are handled under Article 9 of Law No. 6698 and applicable regulations, including adequacy mechanisms, appropriate safeguards such as standard contracts, or applicable statutory exceptions.
Current service providers and relevant processing information are maintained separately in our Subprocessor and Service Provider List.
11. Data Storage and Retention
We retain personal data only for as long as reasonably necessary for the relevant purpose, taking into account:
contractual obligations;
customer instructions;
account status;
legal and regulatory requirements;
safety or audit requirements;
dispute-resolution needs;
backup and disaster-recovery periods.
Retention varies by product and category of information.
Examples include:
organization-controlled data retained according to the applicable customer agreement or customer instruction;
direct-user account information retained while the account remains active and for a limited period afterward where necessary;
financial and transaction records retained as required by applicable tax and accounting law;
support correspondence retained for a reasonable support and audit period;
security logs retained for a period proportionate to their security purpose.
For local-first applications, information stored solely on the device remains subject to the user’s own deletion, backup, and device-management choices unless a cloud feature is enabled.
More specific retention schedules may be provided in product notices or customer agreements.
12. Data Security
Sospita uses technical and organizational safeguards designed to protect personal data against:
unauthorized access;
disclosure;
alteration;
destruction;
loss;
misuse.
Measures may include, depending on the system:
encrypted network communications;
access controls;
role- and permission-based authorization;
authentication safeguards;
tenant separation;
logging and monitoring;
secure development practices;
backups and recovery mechanisms;
restricted administrative access.
No system can guarantee absolute security, and security controls evolve as technology and risks change.
13. Data Breaches
Where Sospita acts as a processor and becomes aware of a personal-data breach affecting customer-controlled information, we will notify the relevant controller without undue delay, in accordance with applicable law and contractual obligations.
Where Sospita acts as a controller, we will make required notifications to competent authorities and affected individuals in accordance with applicable law.
14. Cookies and Website Analytics
Our corporate website uses:
strictly necessary technologies to deliver and secure the website, protect forms against spam and automated abuse, and remember your privacy choice in your browser’s local storage;
optional first-party analytics, used only if you allow it, to measure campaign page views, store and download clicks and form submissions;
campaign attribution, used only if you allow analytics, which keeps the campaign source of your visit (UTM parameters, landing page and referring domain) in session storage for the current browser tab and attaches it to analytics events and form submissions.
Optional analytics is stored by Sospita in its own database without IP addresses, browser user agents or persistent visitor identifiers, and is not used for advertising or cross-site profiling. Your form submissions are delivered whatever your analytics choice.
If your browser sends a Global Privacy Control or Do Not Track signal, optional analytics and campaign attribution remain off.
You can change your choice at any time on our Privacy Settings page. Details of the cookies and browser storage we use, and how long they are kept, are set out in our Cookie & Local Storage Notice.
15. Your Privacy Rights
Depending on applicable law, individuals may have rights to:
know whether personal data is being processed;
access personal data;
obtain information about processing purposes;
correct inaccurate or incomplete information;
request deletion or destruction;
restrict processing;
object to certain processing;
receive portable data where applicable;
withdraw consent where processing depends on consent;
object to certain solely automated decisions;
complain to an applicable supervisory authority.
Where the relevant data is controlled by your employer, club, academy, or another organization, please contact that organization first.
We will assist the organization where required.
Instructions for submitting an account or personal-data deletion request are available on our Account & Data Deletion Requests page.
16. Managing Health and Device Permissions
Permissions for Apple HealthKit and Android Health Connect can be managed through the relevant device settings.
Sospita Athletic Performance accesses supported health information only where the user grants the required device permission.
Currently, supported device-health information is limited to sleep information and total calories or energy used.
The underlying numerical values remain on the user’s device and are not stored in the Sospita database or transmitted to OpenAI.
The application may calculate limited non-numeric indicators, such as sleep trend, sleep consistency, recovery state and burn trend. These derived indicators may be sent to Sospita’s backend and retained as part of daily coaching records and monthly athlete evaluation records.
Revoking device permission prevents future access to the affected health information. Previously created derived coaching or evaluation records may remain subject to the applicable retention policy.
17. Third-Party Platforms and Links
Sospita products may interact with third-party services such as:
Apple App Store;
Google Play;
Apple HealthKit;
Android Health Connect;
payment or entitlement services;
authentication services;
external links chosen by users.
Those providers may process information independently under their own privacy policies.
Maps and site location services. Certain Sospita SafeGuard features use Google Maps Platform to allow authorised users to select, save and display the location of operational sites and related records, and to support address or place search where enabled. Sospita does not use Google Maps for continuous tracking of users’ location. When Google Maps features are used, the user’s device connects to Google and Google may receive technical information such as IP address, device/browser information and map or search requests. Google processes this information under its own terms and privacy policy.
Sospita is not responsible for independent processing conducted by third parties outside our control.
18. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
new products or features;
changes to our processing activities;
changes to service providers;
changes in applicable law;
security or operational developments.
The current version will always display its effective date.
Where required by law, we will provide additional notice of material changes.
19. Contact
For privacy questions, requests, or concerns:
SOSPITA YAZILIM LIMITED ŞİRKETİ
Türkiye
Email: info@sospita.io
Where required for formal KVKK requests, additional application methods or company identification details may be published separately.