Aşağıdaki belgeler bu web sitesini ve stüdyonun iş alma biçimini düzenler. Bilerek sade bir dille yazıldılar. Bir maddenin tescilli şirket bilgisine ya da imzaya ihtiyacı olduğu yerde tahmin yürütülmez, bu durum belirtilir ve imzalı sürüm işle birlikte verilir.

Son güncelleme 28 Eylül 2026

01

Information security policy

Wiener Labs builds systems that hold money, credentials and customer records. This policy describes how the studio handles that responsibility on client engagements.

Access is least privilege and time bound. We ask for the narrowest scope that lets the work happen, we use the client account rather than a shared one wherever the platform allows it, and access is revoked at handover rather than at some later tidy up.

Keys are rotated at handover. Deploy keys, signing keys, API tokens and service credentials created during an engagement are rotated when the work is delivered and the new values stay with the client. We do not keep a copy.

Client data stays in client infrastructure. Cloud accounts, databases and storage buckets are created in the client organisation and paid from the client account. Where we need production data to reproduce a fault we ask first and we prefer a redacted extract.

Onchain code is audited before mainnet. We do not deploy an unaudited smart contract to a production network, and we say so before the engagement starts rather than when the deadline arrives.

Findings are reported, not buried. If we discover a vulnerability in a client system, including one we wrote, it is reported to the client with a severity, a reproduction and a fix. If we discover one in a third party system we follow that vendor disclosure process.

Incidents get a written timeline. When something goes wrong we reconstruct what happened from logs and hand over the sequence, the cause and the remediation in writing.

02

Terms of use

This website is published by Wiener Labs as an informational description of the studio and the work it takes on. Using the site means accepting the terms below.

Nothing on this site is an offer or a contract. Service descriptions, timelines and capability lists are indicative. A binding scope and price exists only in a written proposal signed by both sides.

Nothing on this site is financial, investment, tax or legal advice. Descriptions of protocols, tokens and onchain mechanisms are technical descriptions of engineering work, not recommendations to buy, sell or hold anything.

The numbers we publish describe past work. Delivered project counts, revenue figures, competition results and grants are records of what has already happened and are not a promise of a future outcome.

Text, layout, code and original graphics on this site belong to Wiener Labs. Third party names, logos and marks belong to their owners and appear here to identify the network, product or organisation they name. Their appearance does not imply an endorsement of Wiener Labs by that owner.

The site links to third party destinations. We do not control them and we are not responsible for their content or their practices.

The site is provided as it is. We do not warrant that it is uninterrupted or error free, and we are not liable for loss arising from reliance on it.

03

Privacy notice

This notice explains what happens to personal data on this website. It is written against how the site actually behaves today, and it will be updated when that behaviour changes.

The pages are served as static files and carry no analytics, advertising or tracking script. Three forms on the site send what you type to the studio: the project brief, the waitlist and the feedback form. Nothing is sent until you press the send button.

The project brief sends the project type, the description you write, the timing and budget range you pick, any catalogue lines you keep, your name, your email and, if you add them, your company and a Telegram or X handle. The waitlist sends your email address. The feedback form sends your rating and, if you add them, a comment and an email address. Every submission also records the language of the page and the page you came from, cut down to its path on this site or to the domain of another site.

Submissions are stored in a database that Wiener Labs operates on Supabase, in the European Union (Ireland). They cannot be read back through the website and only the studio team can see them. We use them to answer you, to scope the work and, for the waitlist, to write when an engagement slot opens.

To keep the forms from being flooded by automated traffic, each submission also stores a one way fingerprint of the network address it came from. The fingerprint cannot be turned back into the address, is used only to limit how many submissions one network can send in an hour, and is deleted after one day.

A brief and the correspondence that follows it are kept for as long as it takes to answer you and, if work follows, for as long as the commercial relationship and the record keeping obligations that follow it require. Waitlist addresses are kept until you ask to be removed. Feedback is kept to improve how the studio works and can be deleted on request.

If you choose Sign in with Google on the account page, your request goes to Google under the Google privacy policy and you decide in the Google interface what is shared. Wiener Labs receives only what that flow returns and only for the purpose of creating the account you asked for.

The site is hosted on Vercel. Like any web host, Vercel processes the technical request data needed to serve a page, including the IP address and user agent, under its own terms as our processor.

When you write to the studio through the contact form on the main site, or by email, we process what you send in order to answer you and to scope the work. We keep that correspondence for as long as the commercial relationship and the record keeping obligations that follow it require.

You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, and object to its processing. Write to the studio and we will answer.

This notice serves as the clarification text required under Turkish data protection law and as the information notice required under the GDPR. The registered identity of the data controller is provided in the engagement documents.

06

Distance sales agreement

No sale is concluded through this website. There is no cart, no checkout and no payment page here, and nothing on this site can be bought by pressing a button.

Work is taken on under a written engagement agreement signed by both sides before anything starts. That agreement carries the scope, the deliverables, the schedule, the price, the payment plan, the revision limit, the intellectual property transfer and the termination terms for that specific engagement.

The commercial terms the studio works from are the ones published with our service catalogue: payment staged across signature, interim delivery and go live; two rounds of revision included on every line; scope changes priced in a written addendum rather than absorbed; thirty days of defect correction after delivery at no charge, where a new request is not a defect; and source code transferred in full on final payment.

Where the client is a consumer rather than a business, the mandatory protections of Turkish consumer legislation apply to the signed agreement regardless of what the agreement says, including the right of withdrawal for services not yet performed with the consumer consent.

A copy of the standard engagement agreement is available on request before you commit to anything.

07

Preliminary information form

This form pairs with the engagement agreement above and sets out what you are told before you sign, rather than after.

What is being supplied: software engineering, design and advisory services described in a proposal written for you. The catalogue on this site is the menu we quote from, not the order.

Price: fixed for the scope written in the proposal, in United States dollars unless the proposal says otherwise, exclusive of taxes and of third party costs. Third party costs stay with the client and are paid from client accounts: domains, hosting, cloud usage, model and API consumption, app store fees, audit firm fees, onchain transaction fees and licences.

Schedule: the duration in the proposal runs from the start date, and delays caused by the client waiting on a decision, an asset or an approval move the delivery date by the same amount.

Payment: staged as set out in the proposal. Work pauses while a payment is overdue and the delay is added to the schedule.

Delivery: source code, credentials and documentation are transferred on final payment. Third party accounts are opened in the client name and the keys are handed over.

Withdrawal and cancellation: the terms are in the signed agreement. Services already performed at the point of cancellation are invoiced.

Complaints: write to the studio first. Consumers in Türkiye may also apply to the consumer arbitration committee or the consumer court with jurisdiction at their residence.

The registered company identity, address, tax office and registration number are stated in the proposal and on every invoice.

Bunlarla ilgili sorular classic.wienerlabs.xyz üzerindeki iletişim formundan stüdyoya ulaşır.