Scope and Model
Doruva One is business software organizations use for tasks, projects, chat, files, approvals and calendars. Each organization runs Doruva One in its own installation (its own server, or a separate installation operated for it). The mobile app (Android, package com.doruva.one) connects only to the address of your organization’s Doruva One installation that you enter.
There is no public sign-up. Accounts are created and managed by your organization’s administrator; you sign in with the credentials your organization gives you.
Who Is Responsible?
Business data such as tasks, messages, notes, files and user accounts is stored in your organization’s Doruva One installation, and your organization decides why and how long it is processed. Please contact your organization’s administrator first for requests about this data.
Doruva develops Doruva One and operates the central infrastructure that delivers transactional mobile notifications. Contact for data processed in that infrastructure:
- Data controller
- Mehmet Çalışır
- Brand
- Doruva
- [email protected]
- Address
- Caferağa Mahallesi, Moda Cad. No:2,
Çakıroğlu İş Hanı, Kadıköy / İstanbul, Türkiye
Information the App Processes
- Installation address: the address of the Doruva One installation you connect to is stored on your device.
- Sign-in: your email and password are sent only to your organization’s installation over an encrypted connection (HTTPS). Your password is not stored on the device; the session key issued by your installation is kept in the device’s secure storage (protected by Android Keystore).
- Content: tasks, notes, messages, mentions (@) and file references you view or create are exchanged directly with your organization’s installation. They are not sent to Doruva or any other server.
- Camera, photos and files: accessed only when you choose to attach something, through the system picker, for the item you select. The file is uploaded only to your organization’s installation. Files you open are downloaded to the app’s temporary cache for viewing.
- Device registration: when you enable notifications, the app registers the device’s notification key (FCM registration), app version, device name, language and a random per-installation device ID with your organization’s installation. Hardware identifiers (IMEI, MAC address, etc.) are not used.
Transactional Notifications
Notifications relate only to your work (e.g. a message to you, a mention, a task assignment, a new note, an approval or a calendar invitation). No advertising, campaign or bulk promotional notifications are sent.
A notification travels from your organization’s installation to Doruva’s central notification infrastructure (push.doruva.com) and from there to Google Firebase Cloud Messaging. What is transmitted:
- your device’s notification key,
- the notification title and a short preview text — you choose how much content is shown (see below),
- technical data needed to open the right screen when you tap it (notification ID, type, related record IDs, unread count).
Notification preview: the app setting Settings → Notifications → Notification preview (in Turkish: Ayarlar → Bildirimler → Bildirim önizlemesi) decides how much a notification shows and applies to all devices of your account:
- Full content (default): who did what and a short preview of what was written (e.g. “Ayşe: Can you join the meeting?”, “New task: Landing Page Revision”). The preview is shortened plain text.
- Title only: only who did what; no written content, task or event names (e.g. “New message from Ayşe”).
- Hide content: only the kind of notification; no names and no content (e.g. “New message”).
When you tap a notification, the content is loaded again from your organization’s installation with your session. The central infrastructure only relays notifications; it does not store or log notification titles or content. To verify which installation may send, it keeps the installation ID and public key, an irreversible salted hash of your device’s notification key (not the key itself) and security logs (installation ID, time, result code). Firebase Cloud Messaging is operated by Google to deliver the notification to your device; data may be processed outside Türkiye.
You can turn notifications off at any time in the app’s Settings or in Android’s notification settings. Signing out removes the device registration from your organization’s installation, and that device no longer receives notifications.
Not Used
The app contains no advertising, advertising ID, analytics or crash-reporting SDK, location, contacts access or user tracking. Doruva does not sell users’ or organizations’ conversation or business data and does not use it for advertising.
Retention and Deletion
- The session, installation address and cache on the device are deleted when you sign out or uninstall the app. App data is excluded from device backups.
- Data in your organization’s installation is kept for the periods your organization sets; your organization’s administrator can close or delete your account.
- The device-key hash in the central infrastructure is deleted when the device moves to another installation, when the key becomes invalid, or on request. Security logs are kept for at most 180 days.
Security
The app uses encrypted connections (HTTPS) only; cleartext traffic is disabled. The session key is kept in the device’s secure storage. Installations can reach the central notification infrastructure only with requests signed by their own key, and can only notify devices registered to them.
Access, Correction and Deletion Requests
For your account and business data in your organization’s installation, contact your organization’s administrator. If you do not know whom to ask, or for data in the central notification infrastructure, write to [email protected] with your organization’s name and Doruva One address; we forward requests about an organization’s data to that organization. See also Doruva One Support (Turkish).
Users
Doruva One is intended for business use and is not directed at people under 18.
Changes
This policy is updated when the app or the notification infrastructure changes; the current version is always published on this page. Turkish version: Doruva One Gizlilik Politikası.

