Legal

Privacy Policy: How We Handle Personal Data.

How Deepinfo collects, uses and shares personal data across our website, platform, APIs and services, and how to exercise your rights under GDPR and KVKK.

  1. Collected

    name, email, company, job title · IP address, browser details

  2. Used

    to provide the Services, answer requests, meet legal obligations

  3. Shared (done)

    vetted sub-processors, under SCCs · We do not sell personal data.

  4. Kept

    subscription term plus 30 days · logs 90 days by default

  5. Your rights

    access, rectification, erasure, restriction, portability, objection, withdrawal of consent → [email protected]

On this page · 13 sections

1. Introduction

This Privacy Policy describes how Dofo Teknoloji Anonim Şirketi, doing business as Deepinfo, collects, uses, and protects personal data in connection with our website, platform, APIs, and services. We operate under dual Turkish (KVKK) and EU (GDPR) data protection frameworks.

2. Information We Collect

Information you provide: name, email, company, job title, and other details you submit through our forms or account setup. Information collected automatically: IP address, browser details, device identifiers, referrer, and usage patterns across our website and platform. When you submit a form on our website, it also carries the page you first opened in that visit, the site that referred you and any campaign tags in the link you followed, so we know which page brought the request. Customer Data: data submitted to the platform during normal use, governed by our Data Processing Agreement.

3. How We Use Information

We use personal data to provide and operate the Services, communicate with you about your account and support inquiries, respond to demo and sales requests, improve our products and security posture, and comply with legal obligations. We do not sell personal data.

Under GDPR, we rely on the following legal bases: performance of a contract (to deliver the Services you subscribed to), legitimate interests (to operate, secure, and improve our Services), consent (where required, for example marketing communications), and legal obligation (where mandated by applicable law).

5. Sharing and Disclosure

We share personal data only with: (a) vetted sub-processors acting on our behalf under contractual safeguards; (b) authorities where legally required; and (c) successors in the event of a merger, acquisition, or restructuring, with appropriate protections.

Sub-Processors

We engage sub-processors to support specific operational functions of the platform. Each sub-processor is contractually bound to the same data protection obligations we maintain.

The list below is current as of the date at the top of this document; we update it when sub-processors change, and we tell customers about material changes in advance, as described in Changes to This Policy.

Service / purposeProviderCountry / regionTransfer mechanism
Primary cloud infrastructure (compute, storage, networking)Google Cloud PlatformUS, EU, QatarSCCs
Secondary cloud infrastructureAmazon Web ServicesUS, TürkiyeSCCs
Customer support and lead captureIntercomUSSCCs
Transactional email deliverySendGridUSSCCs
Website hosting, CDN, DNS, and edge functions for form processingCloudflareUS (global edge)SCCs

6. International Data Transfers and Data Residency

Customer data is primarily stored in US-based infrastructure. EU-based infrastructure is available for EU customers on request, with additional regional infrastructure in Türkiye and Qatar for region-specific deployments. Cross-region data transfers operate under standard contractual clauses or equivalent mechanisms where the receiving region requires them.

7. Data Retention

We retain personal data for the duration required to provide the Services and to meet our legal obligations. Account data is typically retained for the term of your subscription plus 30 days.

Operational logs are retained for 90 days by default. Longer retention may apply for regulated customers or where required by law.

8. Your Rights

Depending on your jurisdiction, you have rights including: access to your personal data, rectification of inaccurate data, erasure, restriction of processing, portability, objection to processing, and withdrawal of consent. To exercise these rights, contact [email protected].

You also have the right to lodge a complaint with a data protection authority: in Türkiye, the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), after first applying to us as the KVKK requires; in the EU, the supervisory authority of the member state where you live or work, or where you believe the infringement took place.

9. Security

We implement appropriate technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, audit logging, and staff training. No system is perfectly secure, but we take our obligations seriously and continuously improve our posture.

10. Cookies and Similar Technologies

Our website does not use advertising cookies or analytics cookies. We measure website traffic with Cloudflare Web Analytics, which does not set cookies on your device.

Our website loads the Intercom Messenger, which we use for customer support and lead capture. Intercom sets functional cookies (such as intercom-id and intercom-session cookies) that keep a chat conversation continuous from one page to the next, and we rely on our legitimate interests to set them.

For the length of a visit, our website keeps the page you first opened, the referring site and any campaign tags in your browser's session storage, which the browser clears when you close the tab. They leave your browser only with a form you submit.

You can block or delete cookies through your browser settings. If you do, the Messenger may not keep your conversation between visits.

11. Children’s Privacy

Our Services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated with advance notice. The effective date at the top of this document indicates the current version.

13. Contact Us

Privacy inquiries: [email protected]. Legal inquiries: [email protected]. Data subject rights and DPO matters: [email protected].

The data controller is Dofo Teknoloji Anonim Şirketi, doing business as Deepinfo, headquartered at Necip Fazıl Mah. Günbatımı Sok. No:1, 34773 Ümraniye, İstanbul, Türkiye. Privacy questions: [email protected].

Ask About Your Data in Writing.

Email the privacy team for access, correction, deletion or any other data subject request, or with questions about sub-processors and data residency.