Tekno Portal

Microsoft Store Edition Privacy Policy

Applies only to the Windows version of Tekno Portal installed from the Microsoft Store. That version has no card payment and no IBAN entry. The general privacy policy applies to the iOS and Android versions and to the Windows version distributed directly by the company.

Effective date: 27 August 2026

This policy applies only to the Windows version of Tekno Portal installed from the Microsoft Store. The general privacy policy applies to the iOS and Android versions and to the Windows version distributed directly by the company.

Tekno Portal is a business-to-business (B2B) self-service application for customers of Tekno İklimlendirme. It is not intended for general consumers. Accounts cannot be created in the app; they are issued by Tekno İklimlendirme and the credentials are delivered through your sales representative.

1. Not present in this version

The following are not present in this version, and the app never asks for them:

  • There is no card payment. The app does not ask for a cardholder name, card number, expiry date or security code (CVV); it does not process, transmit or store card data.
  • There is no IBAN entry and no IBAN display. The app never asks you for a bank account number.
  • No financial transaction is initiated or processed.
  • No advertising, advertising identifier, third-party tracking or analytics software.
  • No crash-reporting service is used.
  • No access to location, camera, microphone, contacts, calendar, health or sensor data is requested.

2. Data processed

Account and session data

Username and password (transmitted to the company's server only with the sign-in request), user id, name and role, the account code and access rights bound to the account, session token and its validity period.

So that your session can continue on the next launch, your username and password are stored on your device: they are encrypted with the Windows data protection mechanism (DPAPI), can be decrypted only by the same Windows user, are kept in a record separate from the session token, are never sent to the server or to any third party, and are deleted when you sign out.

Business data (display only)

Account code, legal title and display name; balance, debit and credit position; account statement history; invoice details, invoice lines and invoice PDF documents; receipt documents; orders, pending orders and quotes; past product (stock) movements; product catalogues.

This data already belongs to your own accountand is retrieved from the company's own server (ERP). The app displays it; no payment or collection operation is performed on it.

Invoice details

Legal title, address, district, province, tax office, tax number, phone and e-mail are displayed. Of these, only the address, district and phonefields can be updated in the app, and when updated they are sent to the company's server. Legal title, tax office, tax number and province cannot be changed in the app.

Order and quote data

Product information and product-specific price queries from your own catalogue, the orders and order lines you create, pending orders and quote records. Price and account code are not sent from the client in an order request; both are derived on the server. A single-use transaction id generated for each basket prevents the same order being recorded twice.

Data kept on the device only

The location (address) recordsyou enter yourself in the Profile section are never sent to the server; they are kept only in the app's area on your device. These records contain no coordinates; the map is searched using the address text you typed. Downloaded product catalogues (PDF), viewed statement/invoice/receipt documents, incomplete order drafts, temporary inputs in the calculators, and simple app preferences such as whether the release-notes window has been shown, also remain on the device.

Technical data

The application version and application id (sent so the server can check the minimum supported version) and the state of the network connection (read on the device only, to tell “no internet” apart from “server unreachable”).

Crash records stay on the device

If the app closes unexpectedly, technical error information is written to %LocalAppData%\TeknoPortal\cokme.log on your device only. This file is never transmitted anywhere automatically; it is reviewed only if you send it with a support request.

3. Purposes of processing

  • Authenticating the user and managing the session
  • Showing the user only the data belonging to their own accounts
  • Providing account statement, balance and invoice information
  • Running order and quote processes
  • Updating the address, district and phone fields of the invoice details
  • Downloading and displaying product catalogues and documents
  • Running the value-date and discount calculators
  • Checking the minimum application version and showing an update prompt when needed
  • Applying permission-based access controls

Data is not used for advertising, ad targeting, profiling or third-party marketing.

4. Data transfer and sharing

  • The company's own server. Account, business and order data is transmitted only to api.teknoiklimlendirme.com over HTTPS.
  • Microsoft Store. Distribution and updates of the app are handled through the Microsoft Store; this covers only the download of application files.
  • Map application. Tapping a link on the locations screen opens a map search in the default browser using the address text you typed. The app does not read or transmit the device's location.
  • No data is transmitted to any other third party. Data is not sold or transferred to third parties for marketing purposes.

5. Data security

  • All server communication uses HTTPS (TLS); unencrypted connections are not allowed.
  • Requests are authorised with a server-validated API key and, for the signed-in user, a time-limited session token.
  • Session information is stored encrypted with the Windows data protection mechanism (DPAPI).
  • The username and password stored for silent sign-in are kept in a record separate from the session token and are likewise encrypted with DPAPI; they are deleted when you sign out.
  • On the server, every request is validated against the set of accounts the user may access; a request for an account outside that scope is rejected.

6. Retention

Session information stored on the device becomes invalid when you sign out or when the session token expires; the silent sign-in record is deleted when you sign out. All local data is removed when the app is uninstalled. Because the location records you enter are kept on the device only, they are lost when the app is uninstalled or the device is changed; they are not synchronised across devices. Business and financial data on the server is retained according to the company's data retention policies and applicable legal obligations.

7. Account creation and closure

New accounts cannot be created in the app; accounts are issued by Tekno İklimlendirme. To request closure of your account or suspension of your access, contact your sales representative or the addresses below.

8. Your rights

You have the right to learn whether your personal data is processed, to request information about it, and to request its correction or deletion. Because this account is created by the business you work with, that business is the primary data controller.

9. Children's privacy

The app is intended only for authorised users of corporate customers; data is not knowingly collected from individuals under 18.

10. Changes to this policy

This policy may be updated; the current version is always published at this address and the effective date is changed.

11. Contact

Company / Data Controller: Tekno İklimlendirme
E-mail: info@teknoiklimlendirme.com
Web: teknoiklimlendirme.com

Technical Developer: Mehmet Gümrah
E-mail: support@mgumrah.com
Web: mgumrah.com