Privacy Policy
Last updated: September 19, 2026
Contents
Overview
This policy explains what personal data DOJILAB processes and why, who we share it with, how long we keep it, and your rights. It is written with the principles of Turkey's KVKK and the GDPR in mind; country-specific detail is in the KVKK Notice and GDPR Notice pages.
Data controller
The controller of your personal data is PAX GROUP DOO. Requests for access, rectification, erasure, restriction of processing, objection and data portability can be sent to contact@paxgroupglobal.com. The full contact details are in the block at the end of this page.
Categories of data and retention
Only the data below is processed to run the Service. Analytics and marketing cookies are covered by the Cookie Policy.
| Data | Scope | Retention |
|---|---|---|
| Account data | Name, email, password hash, language preference, consent timestamp | Until the account is deleted |
| Phone | Phone number and verification status (only while phone verification is enabled or when you add a number yourself; anti-bot / real-user check) | Until the account is deleted |
| Chart images | Screenshots you upload for analysis (private, access-restricted storage) | Until account deletion; rejected/inappropriate uploads deleted immediately. Images you attach in chat follow a shorter period |
| Analysis reports | AI-generated technical-outlook reports | Until the account is deleted |
| Doji AI conversations | The questions you ask, the answers you receive and your feedback (a like/dislike and any note you write). The question and the relevant context are sent to a third-party AI model provider so the answer can be produced | 90 days from the last message in the conversation; deleting a conversation yourself removes it immediately |
| Images you attach in chat | Chart images you attach in a conversation (private, access-restricted storage) and the short note produced by the image precheck. The image is sent to a third-party AI model provider so the answer can be produced | 30 days from sending; when image storage is off, no image is stored at all. The short note stays with the conversation |
| Audit and log data | Security events (register, login, analysis), IP address, device/browser info | Limited period for security |
| Quota counters | Monthly analysis usage counts | Per month; until account deletion |
| Credit records | Earned/granted credits and balance | Until the account is deleted |
| Country | Country code derived from the IP address at sign-up or from the phone country code (no city is stored) | Until the account is deleted |
| Subscription records | Store transaction identifiers, product identifier, period end and environment; card/payment details stay with the store | For the statutory financial record-keeping period |
| Ad delivery | Device identifier and ad-interaction data, passed to the ad provider; no personalised targeting | The ad provider's own retention periods |
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com
Purposes of processing
Your data is processed for, and limited to, the following purposes.
| Purpose | Detail |
|---|---|
| Providing the Service | Creating and managing your account and access |
| Producing analyses | Generating technical-outlook reports from your charts |
| Answering chat questions | Answering your questions in the Doji AI chat, assembling the context an answer rests on, and reviewing your feedback to improve the service |
| Security | Preventing abuse and running quota and fraud checks |
| Communication | Sending transactional email/SMS (verification, key notices) |
| Legal obligation | Meeting statutory retention and reporting duties |
Legal bases
Each processing activity relies on one of the legal bases below.
| Legal basis | Applied to |
|---|---|
| Performance of a contract | Account and analysis (KVKK 5/2-c; GDPR 6/1-b) |
| Explicit consent | Risk consent and international transfers (KVKK 5/1, 9; GDPR 6/1-a) |
| Legitimate interest | Security, logging and abuse prevention (KVKK 5/2-f; GDPR 6/1-f) |
| Legal obligation | Statutory retention duties (KVKK 5/2-ç; GDPR 6/1-c) |
Sub-processors
The following sub-processors are used to run the Service. Each accesses only the data needed for its function.
| Provider | Role | Region |
|---|---|---|
| Database & storage provider | Hosting account data and chart images | EU (Amsterdam) |
| Application hosting provider | Running the web app and API | Global / US |
| Cache / rate-limit provider | Quota and rate-limit counters | Global |
| AI model provider | Processing chart images for analysis and answering questions in the Doji AI chat | US |
| Email provider | Sending transactional email | Global / US |
| Phone verification provider | SMS phone verification | Global |
| Apple App Store | In-app subscription sales, payment collection and invoicing on iOS | Global |
| Google Play | In-app subscription sales, payment collection and invoicing on Android | Global |
| Subscription infrastructure provider (RevenueCat) | Verification and status tracking of store subscriptions | US |
| Ad provider (Google AdMob) | Delivery of rewarded video ads on the free tier (non-personalised) | US / Global |
International transfers
Because some sub-processors are located abroad, your data may be transferred internationally. Such transfers rely on your explicit consent and/or appropriate safeguards such as standard contractual clauses, under KVKK art. 9 and GDPR Chapter V.
Retention periods
Your data is kept while your account is active and for as long as legal obligations require. Security and audit logs are kept for a limited period. After a deletion request, data is deleted within a reasonable technical timeframe; see the Data Retention & Deletion section.
Data security
We apply technical and organizational measures such as access control, encrypted transport, and private, access-restricted storage. No system is 100% secure, but we work to reduce risk to a reasonable level.
Your rights
You have the rights of access, rectification, erasure, restriction of processing, objection, data portability, and withdrawal of consent. Requests can be made to the contact address below and are answered within the statutory period (at most 30 days).
Children's data
The Service is not directed to persons under 18, and we do not knowingly collect data from children. If we learn we have processed a child's data, we delete it.
Changes to this policy
We may update this policy. Material changes are announced in the Service or by email, and the current version is always published on this page.
Contact
For all privacy requests, use the data controller's contact details below.
Business and data-controller details
- Legal name
- Mert Gül
- Address
- Tekirdağ, Türkiye
- Data controller
- PAX GROUP DOO
- Controller address
- Zrtava Fasizma 46, Montenegro (PIB 03800709)
- Trade registry no.
- 51348461
- Phone
- +382 68 599708
- Support
- contact@paxgroupglobal.com
- Legal notices
- contact@paxgroupglobal.com
- Governing law
- Karadağ (Montenegro) hukuku