Privacy

Privacy Policy

This policy explains how personal information is handled when you visit Midvex, contact us, or use a Midvex application — including applications distributed through Google Play and the Google Workspace Marketplace.

Last updated: 16 August 2026

Controller

VARS SU ÜRÜNLERİ İTHALAT İHRACAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ (“VARS”, the “Company”, “we” or “us”) is the controller for processing carried out under the Midvex brand. Contact us at [email protected] or İsmet Kaptan Mah., Şair Eşref Blv. No:6 D:304/B, Konak, İzmir, 35210, Türkiye.

Information we collect

  • Contact details such as name, email, telephone, company and role
  • Messages, requirements, budgets, files and project details submitted through forms and the project planner
  • Authentication, account and session information if you create an account
  • Technical information such as IP address, device/browser, access time, error and security logs
  • Language, interface and cookie preferences
  • Google account and mailbox data accessed with your permission when you connect a Midvex application — described in detail under “Midvex applications and Google user data” below

How we use it

  • Respond to enquiries, assess requirements and prepare proposals
  • Provide accounts, saved project drafts and requested services
  • Operate and secure the site, prevent abuse and diagnose errors
  • Meet contractual, accounting and legal duties and establish or defend legal rights
  • Send marketing only where we have a separate valid permission

Sharing and international processing

We may share information, only as necessary, with providers of hosting, databases, authentication, email, file storage, security and professional advice; competent authorities; and parties needed to establish or perform a contract.

Depending on a supplier's infrastructure, data may be processed outside Türkiye. Any such transfer is made under an applicable condition and safeguard in Article 9 of Turkish Law No. 6698.

Retention and security

We keep data for as long as needed for its purpose and applicable statutory limitation or retention periods, then delete, destroy or anonymise it. The exact period depends on the enquiry, account, contract and legal obligation involved.

We apply appropriate access controls, transfer security, backups and incident procedures. No internet transmission can be guaranteed completely secure.

Midvex applications and Google user data

Midvex Mail Insights (the “App”) is a Midvex business application used by authorised Midvex personnel to review, analyse and extract commercial information — enquiries, quotations, orders, invoices, shipping notices and supplier correspondence — from Midvex-managed Google Workspace mailboxes. Access is granted by the mailbox holder through Google's OAuth consent screen and can be withdrawn at any time.

The App requests the narrowest scopes that let it perform that function:

  • https://www.googleapis.com/auth/gmail.readonly — read-only access to messages, attachments, labels and headers, so the App can identify business documents and extract the fields listed below. The App cannot send, alter, label or delete mail.
  • openid, .../auth/userinfo.email and .../auth/userinfo.profile — identify which Google account authorised the App and show the signed-in user inside it.

How Google user data is used, stored and shared

Message bodies and attachments are read to produce those results and are not stored in full beyond the processing run. What we retain is the extracted fields, the Gmail message identifier and basic metadata, held in the Midvex workspace of the account that authorised the connection, for as long as that connection exists or our accounting and legal retention duties require.

OAuth tokens are stored encrypted and used only to call the scopes listed above. Google user data is not sold, not used for advertising or profiling, and not disclosed to anyone beyond the authorised Midvex personnel and the vetted hosting, database and security providers that operate the App under contract.

  • Detect business documents in mail and extract structured fields such as counterparty, document type, reference number, date, currency and amount.
  • Write those extracted fields into Midvex's own records so they can be reconciled against our commercial data.
  • Show the connected user each result together with a link back to the message it came from.
  • Keep operational and error logs needed to run the App securely and diagnose faults.

Google API Services Limited Use disclosure

Midvex Mail Insights's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We use Google user data only to provide and improve the user-facing features described above, and for no other purpose.
  • We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets after notice to affected users.
  • We do not use Google user data to serve advertisements of any kind.
  • We do not allow humans to read Google user data unless the account holder has given specific consent for the messages concerned, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymised for internal operations.
  • We do not use Google Workspace APIs data to develop, improve or train generalised artificial-intelligence or machine-learning models. Automated extraction inside the App runs only on the authorising account's own data to produce that account's own results.

Withdrawing access and deleting Google data

Revoking access stops new processing but does not by itself erase records already extracted — send the deletion request to remove those. We complete deletion requests within 30 days, except for records we are legally obliged to keep, and confirm in writing once done.

  • Disconnect inside the App, or remove Midvex at https://myaccount.google.com/permissions. This revokes our tokens at once and stops all further access to the mailbox.
  • Email [email protected] from the connected address with the subject “Delete Google data” to have the extracted fields, metadata and logs held for that account erased.
  • A Google Workspace administrator can revoke the App for an entire domain from the Google Admin console.

Your choices and rights

You can manage browser storage, use the opt-out offered in marketing messages, and send privacy requests to [email protected]. The KVKK Notice explains rights and application methods under Turkish data-protection law.

Changes

We may update this policy when our services or law change. The current version and effective date will be posted here.

Midvex — VARS

VARS SU ÜRÜNLERİ İTHALAT İHRACAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ

İsmet Kaptan Mah., Şair Eşref Blv. No:6 D:304/B, Konak, İzmir, 35210, Türkiye

[email protected]+90 232 290 57 56

VKN 9240533729 · MERSİS 0924053372900001