Legal

Security

Information security, access control, infrastructure security, integration security, incident handling and responsible disclosure principles for My Marketing Mix.

Last updated: 28 June 2026Türkçe oku

1. Security approach

We treat platform security as an ongoing process combining technical, administrative and organizational controls. Our goal is to protect customer data, accounts, integration permissions and the confidentiality of generated outputs.

Security controls apply across product development, infrastructure operations, vendor management, user authorization, support workflows and incident response.

2. Data classification and access model

Customer content, integration tokens, API keys, reports, campaign performance data, brand assets and user account information are treated as sensitive operational data.

Access is limited by need and role. Company/workspace-level user roles, team memberships, invitations and authorization decisions are managed through product UI and backend controls.

3. Authentication and session security

  • User sessions use an access-token and refresh-token architecture.
  • The refresh token is stored in an httpOnly cookie; security decoy cookies may be used to make token-targeted attacks harder.
  • Unauthorized access, token renewal failures, session validity and logout flows are part of security controls.
  • Users and company administrators are responsible for protecting passwords, API keys and integration tokens.

4. Application and API security

  • TLS in transit and encryption at rest where supported by the relevant system.
  • Authentication, company/workspace context and permission checks for API requests.
  • Restricted access to sensitive keys, tokens and secrets.
  • Security logs, error monitoring, event records and suspicious activity detection.
  • Authorization and scope checks for file uploads, report exports, OCR, image generation and integration operations.
  • Security review, permission checks and bug tracking in product development processes.

5. Infrastructure, backup and continuity

Cloud infrastructure, databases, storage, queues, email, notification, AI model and integration services may be used to operate the service. Reasonable security, access and monitoring controls are applied to these services.

Backup, recovery and operational continuity procedures are designed to reduce data loss risk. User error, third-party outages, incorrect integration permissions or device security risks cannot be fully eliminated.

6. AI and integration security

In AI-assisted features, customer content, prompts, images, reports and modeling data are technically processed to generate requested outputs. Processing is limited to service scope, customer instructions and security requirements.

For integrations such as Google, Meta, LinkedIn, TikTok, Canva, HubSpot, Salesforce and similar providers, access scope depends on permissions granted by the user. Avoiding unnecessary permissions, removing unused connections and protecting third-party account security are customer responsibilities.

7. Vendor and third-party security

Security suitability of cloud, payment, email, support, analytics, AI and integration providers used to deliver the service is reviewed on a reasonable basis.

Third-party services have their own security policies, data processing terms, outage risks and API limits.

8. Incident handling

When a security incident is suspected, we assess the nature of the event, affected scope, relevant accounts, data categories, remediation steps and notification obligations.

Where applicable law requires it, notifications are made to relevant customers, affected persons or competent authorities. Root-cause analysis and corrective/preventive actions may be planned after the incident.

9. Customer responsibilities

  • Use strong passwords and enable multi-factor authentication where available.
  • Keep team memberships and user roles current; remove access for departed users.
  • Protect API keys, integration permissions, downloaded reports and exported files.
  • Apply least-privilege access within the company/workspace.
  • Remove unnecessary permissions from Google, Meta, LinkedIn, TikTok, CRM, analytics and other connected accounts.
  • Ensure a legal basis and permissions before uploading sensitive or special-category personal data.
  • Report suspicious activity, unauthorized access or suspected vulnerabilities promptly.

10. Responsible disclosure

You can report suspected vulnerabilities to [email protected] with "Security" in the subject line. Please include reproduction steps, affected URL/account, technical detail and contact information.

Do not download data, access accounts that are not yours, cause service disruption, conduct social engineering, physical attacks or destructive testing without prior written authorization. No bug bounty is promised unless stated in writing.