URLy
الرئيسية كيف يعمل؟ الأسئلة الشائعة اتصل بنا Security Legal Policies
EnglishEnglishTürkçeTürkçeGermanDeutschFrenchFrançaisSpanishEspañolRussianРусскийArabicالعربية✓

📜 Legal Policies 26 Docs

Service & Usage
  • 📜 01. Terms of Service
  • 🚫 02. Acceptable Use Policy
  • ⚖️ 16. Content Moderation & Expression
Privacy & Data Protection
  • 🛡️ 03. Global Privacy Policy
  • 🍪 04. Cookie Policy
  • ⏱️ 06. Data Retention & Deletion Policy
  • 🇹🇷 10. KVKK Privacy Notice (Turkey)
  • 🇪🇺 11. GDPR (EEA & UK) Privacy Notice
  • 👤 13. Data Subject Request Procedure
  • 🌐 14. Subprocessors Disclosure
  • ✍️ 23. Explicit Consent Statement (TR)
  • ✍️ 24. Explicit Consent Statement (EN)
Security & Disclosure
  • 🔒 07. Security Policy
  • 🚸 12. Child Safety & CSAM Policy
  • 🎯 15. Vulnerability Disclosure Policy
  • 💻 18. Security Page Specification
  • 📑 19. RFC 9116 security.txt Standard
Legal Requests & Compliance
  • 🚨 05. Abuse Reporting Procedure
  • ©️ 08. Copyright & DMCA Takedown Policy
  • 🏛️ 09. Law Enforcement Guidelines
  • 📊 17. Transparency Report Framework
Official Submission Forms
  • 📝 20. Privacy & DSR Request Form Spec
  • ⚠️ 21. Abuse Report Form Spec
  • 🏷️ 22. Copyright & Trademark Form Spec
Master Archive & Directives
  • 📌 25. Policy Package Overview (README)
  • 📚 26. Consolidated Master Policy & Alignment
⏱️ Privacy & Data Protection ✍️ Related Submission Channel →

06. Data Retention & Deletion Policy

🏢 Firma Life 📍 Selçuklu / Konya, Türkiye ⚖️ Konya Mahkemeleri 📑 06_Retention_Deletion.txt

Data Retention & Deletion Policy

URly / urly.tr

Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]

This Policy establishes general retention targets for categories of information. These are not guarantees of exact automatic deletion dates.

1. Account information

While active and generally up to 12 months after deletion/closure.

2. Deleted account records

Generally up to 12 months after deletion, subject to legal, security and dispute exceptions.

3. Short Links and destination records

While active and generally up to 12 months after deactivation/deletion where applicable.

4. Click/access logs

Generally up to 12 months.

5. IP/device/browser/OS/language

Generally up to 12 months.

6. Security and abuse logs

Generally up to 24 months.

7. Fraud/phishing/malware enforcement records

Generally up to 24 months.

8. Abuse reports

Generally up to 24 months.

9. Legal requests and records

For the duration of the relevant legal matter and as long as reasonably necessary afterward.

10. Aggregated/de-identified data

May be retained longer where it no longer constitutes personal data under applicable law.

11. Anonymous Short Links

Current anonymous Short Links may expire after 30 days of inactivity under product rules.

12. Legal hold

Data may be preserved beyond ordinary retention when necessary for litigation, legal process, investigations, disputes or regulatory requirements.

13. Security incidents

Relevant records may be retained longer where necessary to investigate, remediate and document a security incident.

14. Backups

Backups may retain information beyond primary-system deletion schedules for a limited operational period and may not be individually erasable immediately.

15. Deletion requests

Requests may be submitted to legal@urly.tr. Deletion does not override information that must lawfully be retained.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Creator IP

The IP address associated with creation of a Short Link (urls.creator_ip) is retained strictly for security, abuse prevention, and legal compliance. In accordance with automated retention sweeps:
- For active Short Links, creator IP is retained for up to 12 months (365 days) from creation, after which it is automatically and irreversibly anonymized (set to NULL).
- For deleted or expired Short Links, creator IP is retained for an abuse dispute window of up to 90 days, after which it is automatically set to NULL.

IP geolocation cache

IP geolocation cache records (ip_geo_cache) are retained for a maximum of 12 months (365 days) or automatically cleared when orphaned, ensuring no indefinite retention of cached location mappings.

Support tickets

Support and communication records (support_tickets) are retained strictly according to operational necessity and applicable legal dispute periods:
- Unverified pending requests (status = pending_verification): Automatically purged after 14 days if email confirmation is not completed.
- IP addresses: IP addresses associated with support submissions are retained for up to 90 days for abuse prevention and fraud screening, then automatically anonymized (set to NULL).
- Resolved/closed records and inquiries: Retained for up to 3 years from creation to facilitate quality assurance, dispute resolution, consumer inquiries, and statutory limitation periods under applicable law, after which all ticket messages, user details, and responses are permanently deleted.

API applications

Developer API records (api_applications) are retained strictly in accordance with security lifecycle and operational needs:
- Active API credentials: Retained while the application is active and valid to enable programmatic link shortening and analytics services.
- Application IP addresses: IP addresses recorded at application submission are retained for 90 days for abuse prevention and developer verification, then automatically anonymized (set to NULL).
- Rejected applications: Retained for 90 days following review to allow for applicant inquiries and appeals, after which all project details and reasons are permanently deleted.
- Disabled/inactive credentials: Keys revoked, marked inactive, or unused for more than 12 months (365 days) are automatically purged.
- Orphaned applications: Applications linked to deleted user accounts are immediately deleted during automated account purge cycles.

Rate-limit records

Rate-limit records (rate_limits) are retained strictly for operational security and automated abuse mitigation (rate limiting and brute-force prevention). Expired rate-limit windows are automatically purged 1 day (24 hours) after expiration.

Referrer minimization

Where referrer information is stored (clicks_log.referer), URLy automatically sanitizes and minimizes incoming referrers at the point of ingestion. Query strings (?token=..., ?email=...) and fragments (#...) are strictly stripped to prevent accidental retention of sensitive parameters or personally identifiable information (PII). In addition, automated retention sweeps retroactively sanitize historical referrer records, and the outbound Referrer-Policy header is configured to protect visitors upon redirection.

Deletion versus anonymization

Information that is irreversibly aggregated or de-identified may no longer be treated as personal data, subject to applicable law and the quality of the de-identification.

Legal hold

A legal hold may suspend ordinary deletion for specific records. The hold should be limited to relevant information and removed when no longer necessary.

Backups

Backup retention should be documented separately so that deletion requests and incident-response obligations can be reconciled with backup architecture.

Review cadence

Retention schedules should be reviewed periodically against actual database cleanup jobs and application behavior.

Legal Notice & Contacts:
This document is issued by Firma Life under Turkish law. For official inquiries or data subject rights, please contact the designated department above.

Destek: support@urly.tr • Kötüye Kullanım: abuse@urly.tr • Hukuk & KVKK: legal@urly.tr • Güvenlik (RFC 9116): security@urly.tr
URLy

منصة اختصار روابط سريعة وآمنة وذكية مع تحليلات في الوقت الفعلي.

Firma Life
Horozluhan Mah. Öksüz Cad. No: 168
Selçuklu / Konya, Türkiye

Quick Links

  • الرئيسية
  • كيف يعمل؟
  • الأسئلة الشائعة
  • اتصل بنا
  • Security & VDP

Key Policies

  • Terms of Service
  • Acceptable Use
  • Privacy Policy
  • KVKK Notice
  • Security Policy

التواصل والدعم

  • 📩 support@urly.tr
  • 🛡️ abuse@urly.tr
  • ⚖️ legal@urly.tr
  • 🔒 security@urly.tr
© 2026 URLy.tr (Firma Life). All rights reserved.
26 Legal Documents • RFC 9116 • security.txt