Legal
Privacy Policy: How We Handle Personal Data.
How Deepinfo collects, uses and shares personal data across our website, platform, APIs and services, and how to exercise your rights under GDPR and KVKK.
-
name, email, company, job title · IP address, browser details
-
to provide the Services, answer requests, meet legal obligations
-
Shared (done)
vetted sub-processors, under SCCs · We do not sell personal data.
-
subscription term plus 30 days · logs 90 days by default
-
access, rectification, erasure, restriction, portability, objection, withdrawal of consent → [email protected]
On this page · 13 sections
1. Introduction
This Privacy Policy describes how Dofo Teknoloji Anonim Şirketi, doing business as Deepinfo, collects, uses, and protects personal data in connection with our website, platform, APIs, and services. We operate under dual Turkish (KVKK) and EU (GDPR) data protection frameworks.
2. Information We Collect
Information you provide: name, email, company, job title, and other details you submit through our forms or account setup. Information collected automatically: IP address, browser details, device identifiers, referrer, and usage patterns across our website and platform. When you submit a form on our website, it also carries the page you first opened in that visit, the site that referred you and any campaign tags in the link you followed, so we know which page brought the request. Customer Data: data submitted to the platform during normal use, governed by our Data Processing Agreement.
3. How We Use Information
We use personal data to provide and operate the Services, communicate with you about your account and support inquiries, respond to demo and sales requests, improve our products and security posture, and comply with legal obligations. We do not sell personal data.
4. Legal Basis for Processing
Under GDPR, we rely on the following legal bases: performance of a contract (to deliver the Services you subscribed to), legitimate interests (to operate, secure, and improve our Services), consent (where required, for example marketing communications), and legal obligation (where mandated by applicable law).
5. Sharing and Disclosure
We share personal data only with: (a) vetted sub-processors acting on our behalf under contractual safeguards; (b) authorities where legally required; and (c) successors in the event of a merger, acquisition, or restructuring, with appropriate protections.
Sub-Processors
We engage sub-processors to support specific operational functions of the platform. Each sub-processor is contractually bound to the same data protection obligations we maintain.
The list below is current as of the date at the top of this document; we update it when sub-processors change, and we tell customers about material changes in advance, as described in Changes to This Policy.
| Service / purpose | Provider | Country / region | Transfer mechanism |
|---|---|---|---|
| Primary cloud infrastructure (compute, storage, networking) | Google Cloud Platform | US, EU, Qatar | SCCs |
| Secondary cloud infrastructure | Amazon Web Services | US, Türkiye | SCCs |
| Customer support and lead capture | Intercom | US | SCCs |
| Transactional email delivery | SendGrid | US | SCCs |
| Website hosting, CDN, DNS, and edge functions for form processing | Cloudflare | US (global edge) | SCCs |
6. International Data Transfers and Data Residency
Customer data is primarily stored in US-based infrastructure. EU-based infrastructure is available for EU customers on request, with additional regional infrastructure in Türkiye and Qatar for region-specific deployments. Cross-region data transfers operate under standard contractual clauses or equivalent mechanisms where the receiving region requires them.
7. Data Retention
We retain personal data for the duration required to provide the Services and to meet our legal obligations. Account data is typically retained for the term of your subscription plus 30 days.
Operational logs are retained for 90 days by default. Longer retention may apply for regulated customers or where required by law.
8. Your Rights
Depending on your jurisdiction, you have rights including: access to your personal data, rectification of inaccurate data, erasure, restriction of processing, portability, objection to processing, and withdrawal of consent. To exercise these rights, contact [email protected].
You also have the right to lodge a complaint with a data protection authority: in Türkiye, the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), after first applying to us as the KVKK requires; in the EU, the supervisory authority of the member state where you live or work, or where you believe the infringement took place.
9. Security
We implement appropriate technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, audit logging, and staff training. No system is perfectly secure, but we take our obligations seriously and continuously improve our posture.
10. Cookies and Similar Technologies
Our website does not use advertising cookies or analytics cookies. We measure website traffic with Cloudflare Web Analytics, which does not set cookies on your device.
Our website loads the Intercom Messenger, which we use for customer support and lead capture. Intercom sets functional cookies (such as intercom-id and intercom-session cookies) that keep a chat conversation continuous from one page to the next, and we rely on our legitimate interests to set them.
For the length of a visit, our website keeps the page you first opened, the referring site and any campaign tags in your browser's session storage, which the browser clears when you close the tab. They leave your browser only with a form you submit.
You can block or delete cookies through your browser settings. If you do, the Messenger may not keep your conversation between visits.
11. Children’s Privacy
Our Services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated with advance notice. The effective date at the top of this document indicates the current version.
13. Contact Us
Privacy inquiries: [email protected]. Legal inquiries: [email protected]. Data subject rights and DPO matters: [email protected].
The data controller is Dofo Teknoloji Anonim Şirketi, doing business as Deepinfo, headquartered at Necip Fazıl Mah. Günbatımı Sok. No:1, 34773 Ümraniye, İstanbul, Türkiye. Privacy questions: [email protected].
Ask About Your Data in Writing.
Email the privacy team for access, correction, deletion or any other data subject request, or with questions about sub-processors and data residency.