1. Who we are

This Policy is issued by [doldurulacak] ("we"), which provides the Advenro service, for the personal data it processes on its own behalf. Contact: privacy@advenro.com · KEP: [doldurulacak] · Address: [doldurulacak].

We have two different roles:

  • As controller: We process data about account holders, team members, visitors to our website and business partners for our own purposes. This Policy describes that data.
  • As processor: We process data that our Users upload to the Service or collect through it (CRM contacts, visitor events on their own sites, web form submissions, ad audiences) only on their instructions. The relevant User is the controller of that data; the relationship is governed by the Data Processing Agreement. These people should exercise their rights primarily against that User. We forward a request we receive to the User where we can identify the controller, and we do not decide it ourselves as if we were the controller.

2. Data we process

We do not request special categories of personal data; please do not enter such data in the Service.

4. Artificial intelligence

When you use AI features, inputs are sent to the selected provider (listed under Subprocessors) to produce an answer. We do not give your data for model training, and we work with providers under business API terms that exclude training. Answers are kept in a cache for at most 14 days so that repeating the same request costs nothing. Details: AI Terms.

Our team may also use AI when reviewing how the Service is doing overall. In that use only aggregate figures (for example totals of signups, usage and revenue) are sent to the provider; names, e-mail addresses, support messages and Customer Data are not.

5. Who we share data with

  • Our service providers (subprocessors): hosting, AI, e-mail delivery, payments. Current list: Subprocessors page.
  • Third parties you connect: Meta, Google, HubSpot, Stripe, RevenueCat and similar, only on your instruction and authorisation.
  • Competent public authorities: where required by law or requested by a competent authority.
  • Corporate transactions: in a merger, acquisition or asset transfer, subject to confidentiality.

We do not sell your personal data or rent it to third parties for advertising.

6. International transfers

Some of our service providers are located abroad (e.g. the US, the EU). Transfers are made by signing the standard contracts published by the Turkish Personal Data Protection Board under KVKK art. 9 and notifying the Authority within five business days of signing; transfers from the European Economic Area use the European Commission's Standard Contractual Clauses.

7. Retention

At the end of the period, data is deleted, destroyed or anonymised. An account-closure or deletion request does not delete, before the period above ends, data that must be kept to establish, exercise or defend a right, for tax and accounting, or for logs within Law No. 5651.

8. Security

We apply technical and organisational measures such as TLS encryption in transit, encrypted storage of access keys, role-based access, least privilege, protection against server-side request forgery (SSRF) for requests to user-supplied addresses, rate limiting and logging. No system is completely secure; if we learn of a data breach, we notify the Authority and affected persons within the periods required by law.

9. Your rights

Under KVKK art. 11 and the GDPR you may: learn whether your data is processed; request information; learn the purpose of processing and whether data is used accordingly; know the third parties it is transferred to; request correction if it is incomplete or inaccurate; request deletion or destruction where the conditions are met; request that these actions be notified to third parties it was transferred to; object to a result against you arising solely from automated analysis; and claim compensation for damage caused by unlawful processing. Under the GDPR you also have the rights to data portability and to object to processing.

Send requests from your registered e-mail to privacy@advenro.com, via KEP to [doldurulacak], or in writing to [doldurulacak]. We resolve requests free of charge within 30 days at the latest; if the action requires an additional cost, the fee set by the Board may be charged. If you are not satisfied with our answer, you may complain to the Turkish Personal Data Protection Board or, in the EU, to your local supervisory authority.

10. Cookies

Cookies and similar technologies are described in the Cookie Policy.

11. Children

The Service is not intended for people under 18; we do not knowingly collect children's data.

12. Changes

We may update this Policy. We announce material changes by e-mail or in-app notice. Version: 1.2.