PRIVACY NOTICE (KVKK)
1. Introduction
At Addyol ("Company", "we", "our", or "us"), we respect your privacy and are committed to protecting personal data entrusted to us.
This Privacy Notice explains how we collect, use, process, disclose, and protect personal data obtained through our website, digital platforms, software solutions, technology services, communication channels, and business relationships.
This Privacy Notice applies to:
- Website visitors;
- Customers and prospective customers;
- Business partners;
- Technology partners;
- Investors and investment applicants;
- Startup founders and representatives;
- Suppliers and service providers;
- Individuals who communicate with us through digital or physical channels.
The Company processes personal data in accordance with applicable data protection laws, including where applicable the European Union General Data Protection Regulation ("GDPR"), the Turkish Personal Data Protection Law No. 6698 ("KVKK"), and other applicable privacy regulations.
2. Data Controller Identity
The entity responsible for processing your personal data is:
Company Name: Addyol Bilişim ve Dış Tic. Hiz. Ltd. Şti.
Registered Address: Cumhuriyet İş Merkezi, No. 34-36, D. 309, Bayrampaşa 34030 İstanbul
Company Registration Number: 0007132189600001
Tax Identification Number: 0071321896
Email: info@addyol.com
Phone: (Whatsapp) +90 (532) 069-8480
For purposes of applicable data protection laws, the Company acts as the data controller where it determines the purposes and means of processing personal data.
3. Categories of Personal Data We Process
Depending on your relationship with the Company, we may process the following categories of personal data.
3.1 Identity Information
This may include:
- Full name;
- Identification details where legally required.
3.2 Contact Information
This may include:
- Email address;
- Telephone number;
- Business address;
- Communication records.
3.3 Professional and Corporate Information
This may include:
- Company name;
- Job title;
- Position;
- Department;
- Industry;
- Professional background;
- Organization information.
3.4 Commercial and Business Information
In connection with our technology products, services, investments, and partnerships, we may process information including:
- Requested products or services;
- Software licensing requirements;
- Number of users or endpoints;
- SaaS subscription details;
- Cloud deployment requirements;
- Project specifications;
- Commercial proposals;
- Investment applications;
- Partnership opportunities.
3.5 Technical and Digital Information
When you access our website or digital services, we may automatically collect technical information, including:
- IP address;
- Browser information;
- Device information;
- Operating system;
- Language preferences;
- Access dates and times;
- Website interaction data;
- Server logs;
- Cookie identifiers;
- Security and performance information.
3.6 Communication Information
We may process information contained in communications with us, including:
- Emails;
- Contact form submissions;
- Support requests;
- Demo requests;
- Proof of Concept (PoC) applications;
- Investment proposals;
- Partnership discussions;
- Meeting notes.
4. Purposes of Processing Personal Data
We may process personal data for the following purposes:
4.1 Providing Products and Technology Services
Including:
- Delivering software solutions;
- Managing SaaS services;
- Providing cloud-based solutions;
- Operating digital platforms;
- Managing API services;
- Providing technical support;
- Performing implementation and consulting services.
4.2 Managing Business Relationships
Including:
- Responding to inquiries;
- Preparing proposals;
- Managing customer relationships;
- Conducting business communications;
- Evaluating partnership opportunities;
- Managing supplier relationships.
4.3 Technology Investment Activities
Where applicable, personal data may be processed for:
- Reviewing investment applications;
- Evaluating startup opportunities;
- Managing innovation programs;
- Communicating with founders and representatives;
- Conducting business assessments.
Submission of information does not create any obligation for the Company to invest or enter into a business relationship.
4.4 Security and Operational Purposes
Including:
- Protecting systems and infrastructure;
- Preventing unauthorized access;
- Detecting security incidents;
- Monitoring platform performance;
- Maintaining operational continuity;
- Improving service reliability.
4.5 Legal and Regulatory Compliance
Personal data may be processed to:
- Comply with legal obligations;
- Respond to lawful requests from authorities;
- Establish, exercise, or defend legal claims;
- Maintain required business records.
5. Legal Bases for Processing
The Company processes personal data based on one or more of the following legal grounds, depending on the nature of the processing activity:
Performance of a Contract
Processing may be necessary for:
- Providing requested products or services;
- Managing subscriptions;
- Performing contractual obligations.
Compliance with Legal Obligations
Processing may be required to:
- Meet accounting obligations;
- Fulfill regulatory requirements;
- Respond to lawful requests.
Legitimate Interests
The Company may process personal data where necessary for legitimate business interests, including:
- Improving products and services;
- Ensuring information security;
- Managing customer relationships;
- Protecting business operations.
Such processing is conducted after considering individuals' rights and interests.
Consent
Where required by applicable law, the Company may request your consent before processing certain categories of personal data.
You may withdraw your consent at any time where processing is based on consent.
6. Methods of Collection
Personal data may be collected through:
- Company websites;
- Online forms;
- Demo request forms;
- Contact forms;
- Investment application forms;
- Partnership applications;
- Emails;
- Telephone communications;
- Online meetings;
- Customer support systems;
- Cookies and similar technologies;
- Technical monitoring systems.
The Company may use trusted third-party business platforms, such as CRM, communication, analytics, and form management providers, to support its operations.
7. Disclosure of Personal Data
The Company may share personal data where necessary with:
- Cloud service providers;
- Hosting providers;
- CRM providers;
- Communication service providers;
- Technical support providers;
- Analytics providers;
- Professional advisors;
- Auditors;
- Legal consultants;
- Competent governmental authorities where legally required.
The Company requires appropriate confidentiality, security, and data protection standards from service providers processing personal data on its behalf.
8. International Data Transfers
Due to the global nature of technology infrastructure, certain service providers, cloud platforms, or business partners may be located outside your country of residence.
Where personal data is transferred internationally, the Company applies appropriate safeguards required under applicable data protection laws, which may include:
- Adequacy decisions;
- Standard contractual clauses;
- Contractual safeguards;
- Technical and organizational security measures.
The Company transfers personal data only where necessary for legitimate business purposes and appropriate protection measures are in place.
9. Data Retention
The Company retains personal data only for as long as necessary to fulfill the purposes described in this Privacy Notice, comply with legal obligations, resolve disputes, enforce agreements, and protect legitimate business interests.
Retention periods are determined based on factors including:
- The nature and purpose of the processing activity;
- The duration of the business relationship;
- Applicable legal and regulatory requirements;
- Accounting and contractual obligations;
- Potential legal claims or dispute resolution requirements;
- Information security requirements.
When personal data is no longer required, the Company will securely:
- Delete the data;
- Anonymize the data; or
- Otherwise dispose of the data in accordance with applicable laws and internal procedures.
10. Customer Data and Technology Solutions
The Company provides technology solutions including, where applicable:
- Software platforms;
- SaaS applications;
- Cloud-based solutions;
- Artificial intelligence solutions;
- API services;
- Digital products;
- Technology consulting services.
Customer data processed through these solutions is generally stored within infrastructure selected and controlled by the customer, including:
- Customer-managed servers;
- Private cloud environments;
- Public cloud platforms;
- Customer-designated data centers.
The Company does not routinely access, monitor, or control customer data stored within customer-controlled environments.
Where technical support, troubleshooting, maintenance, or implementation services require access to customer systems, access may only be provided:
- Upon the customer's explicit authorization;
- For a specific technical purpose;
- For the minimum period necessary;
- With appropriate security controls.
Such access is limited strictly to the relevant support activity.
Customers remain responsible for ensuring that their own processing activities involving employees, users, customers, or third parties comply with applicable data protection laws.
11. Data Security
The Company applies appropriate technical and organizational measures designed to protect personal data against:
- Unauthorized access;
- Accidental loss;
- Destruction;
- Alteration;
- Disclosure;
- Unauthorized processing.
Security measures may include:
- Access control procedures;
- Authentication mechanisms;
- Encryption technologies;
- Network security controls;
- Firewall protection;
- System monitoring;
- Logging and audit mechanisms;
- Backup procedures;
- Vulnerability management;
- Security reviews;
- Employee awareness and confidentiality obligations.
The Company regularly reviews its security practices to improve the protection of personal data.
While the Company applies reasonable security measures, no electronic transmission or storage system can be guaranteed to be completely secure.
12. Your Privacy Rights
Depending on applicable laws and your jurisdiction, you may have rights regarding your personal data.
These rights may include:
Right of Access
You may request confirmation as to whether your personal data is being processed and request access to such information.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
Where legally applicable, you may request deletion of your personal data.
Right to Restriction of Processing
You may request limitation of certain processing activities under applicable circumstances.
Right to Object
You may object to certain processing activities, including processing based on legitimate interests or direct marketing where applicable.
Right to Data Portability
Where legally applicable, you may request your personal data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
Right to Lodge a Complaint
You have the right to submit a complaint to the relevant data protection authority if you believe your personal data has been processed unlawfully.
13. Exercising Your Rights
Requests relating to your personal data may be submitted using the contact information provided below.
To help us process your request efficiently, your submission should include:
- Full name;
- Contact details;
- Description of your request;
- Relevant supporting information where applicable.
The Company will review and respond to requests within the legally required timeframe.
Where permitted by applicable law, the Company may request additional information to verify the identity of the requester.
14. Cookies and Similar Technologies
The Company may use cookies and similar technologies to support:
- Website functionality;
- Security;
- Performance measurement;
- Analytics;
- User experience improvements.
Detailed information regarding cookies, their purposes, and management options is available in our Cookie Policy.
15. Third-Party Websites and Services
Our website or digital services may contain links to third-party websites, platforms, or services.
The Company is not responsible for the privacy practices, security measures, or content of third-party services.
Users are encouraged to review the privacy notices and terms of use of third-party providers before using such services.
16. Changes to This Privacy Notice
The Company may update this Privacy Notice periodically to reflect:
- Changes in applicable laws;
- Regulatory requirements;
- New products and services;
- Changes in technology;
- Improvements to privacy practices.
The updated version becomes effective when published on the Company's website unless otherwise stated.
Where required by applicable law, significant changes may be communicated through appropriate channels.
17. Contact Information
If you have questions, requests, or concerns regarding this Privacy Notice or the processing of your personal data, you may contact us:
Company Name: Addyol Bilişim ve Dış Tic. Hiz. Ltd. Şti.
Address: Cumhuriyet İş Merkezi, No. 34-36, D. 309, Bayrampaşa 34030 İstanbul
Company Registration Number: 0007132189600001
Tax Identification Number: 0071321896
Email: info@addyol.com
Phone: (Whatsapp) +90 (532) 069-8480