Relevant · relevant.com.tr
Legal
KVKK notice
This notice informs people who use Relevant or visit relevant.com.tr how their personal data is processed under Personal Data Protection Law No. 6698 (KVKK), as required by Article 10 of the Law. It states who the data controller is, why and on what legal basis data is processed, who may receive it, and how to exercise your rights.
Last updated:
Identity of the data controller#
Under Article 3 of Personal Data Protection Law No. 6698 (the “Law” or “KVKK”), the data controller is Relevant (“Relevant”, “we” or “us”), the company behind relevant.com.tr and the Relevant evaluation platform. Relevant has not appointed a separate representative.
- Legal entity
- Relevant
- Privacy and data protection
- privacy@relevant.com.tr
- Legal notices
- legal@relevant.com.tr
This notice covers the processing that Relevant carries out as a data controller: data about visitors to the website, people who create or administer an account, and people who contact us. For the datasets, traces and evaluation results that customers bring into a workspace, Relevant acts as a data processor. Requests about that data are passed to the customer concerned, and the terms of the processing are set out in the data processing agreement.
Purposes of processing#
In line with the general principles in Article 4 of the Law, we process your personal data only for the following purposes:
- creating and managing your account, and carrying out authentication and authorization;
- providing the service: running the evaluations you configure and storing and displaying their results;
- carrying out information security processes, preventing abuse and keeping audit trails;
- billing, collection, accounting and meeting tax obligations;
- answering support requests and contact form messages, and sending notices about the service;
- improving the service by analyzing aggregate usage data, with optional analytics only when you give explicit consent;
- sending product announcements and electronic commercial messages if you have given permission; and
- meeting legal obligations, answering requests from competent authorities, and establishing, exercising or defending legal claims.
Categories of personal data processed#
- Identity
- What it includes
- First and last name.
- Contact
- What it includes
- Work email address, company name, job title and the information you share in the contact form.
- Customer transaction
- What it includes
- Plan and workspace details, member list and roles, usage records, API key metadata (name, prefix, creation date) and audit logs.
- Transaction security
- What it includes
- IP address, session and access logs, browser and device information, and security event logs.
- Financial
- What it includes
- Billing details, tax identification number and payment status. Card details are collected and held by our payment processor, not by us.
- Request and complaint management
- What it includes
- Support requests, contact form messages and any applications you make under the Law.
- Marketing
- What it includes
- Your communication preferences and, where given, your permission to receive electronic commercial messages.
Relevant is not designed to process special categories of personal data (Article 6 of the Law). We recommend masking or removing personal and special-category data from datasets and traces before you upload them to a workspace wherever you can.
Recipients of personal data and purposes of transfer#
We do not sell personal data. In line with Articles 8 and 9 of the Law, it may be transferred only to the groups of recipients below, and only for the purposes stated:
- Cloud hosting and infrastructure providers
- Purpose of transfer
- Hosting and delivering the service
- Legal ground (Article 5)
- Performance of a contract; legitimate interests
- Email delivery providers
- Purpose of transfer
- Sending account, security and support messages
- Legal ground (Article 5)
- Performance of a contract; legitimate interests
- Error and performance monitoring providers
- Purpose of transfer
- Keeping the service reliable and diagnosing faults
- Legal ground (Article 5)
- Legitimate interests
- Payment processors
- Purpose of transfer
- Collecting payment and invoicing
- Legal ground (Article 5)
- Performance of a contract; legal obligation
- Analytics providers
- Purpose of transfer
- Measuring aggregate usage, only with your explicit consent
- Legal ground (Article 5)
- Explicit consent
- Financial advisers, legal counsel and independent auditors
- Purpose of transfer
- Advice, audit and meeting legal obligations
- Legal ground (Article 5)
- Legal obligation; establishment, exercise or protection of a right; legitimate interests
- Competent public authorities and judicial bodies
- Purpose of transfer
- Meeting obligations that arise from legislation
- Legal ground (Article 5)
- Provided for by law; legal obligation
Transfers abroad
Customer content is processed in the region you choose for your workspace. Where a service provider is located abroad, the transfer relies on a mechanism provided by Article 9 of the Law and its implementing legislation: an adequacy decision, appropriate safeguards such as a standard contract notified to the Personal Data Protection Authority, or an occasional transfer that meets the statutory conditions. The current list of service providers by category and region is on the subprocessors page.
Legal bases for processing (Articles 5 and 6)#
- Account management and providing the service
- Legal basis
- Article 5(2): processing the personal data of the parties to a contract is necessary, provided it is directly related to the establishment or performance of that contract.
- Billing, accounting and tax
- Legal basis
- Article 5(2): processing is expressly provided for by law, and is necessary for the controller to meet a legal obligation.
- Information security, preventing abuse and improving the service (aggregate analysis)
- Legal basis
- Article 5(2): processing is necessary for the legitimate interests of the controller, provided it does not harm the fundamental rights and freedoms of the data subject.
- Establishing, exercising or defending legal claims
- Legal basis
- Article 5(2): processing is necessary for the establishment, exercise or protection of a right.
- Electronic commercial messages and optional analytics
- Legal basis
- Article 5(1): explicit consent, which is freely given, specific and based on being informed. Electronic commercial messages are sent only with the permission the applicable rules require.
Where processing relies on explicit consent, you can withdraw it at any time. Withdrawing does not affect the lawfulness of processing that took place before. Special categories of personal data (Article 6) are not intended to be processed. If they are, they are processed only where one of the conditions listed in Article 6 applies.
How personal data is collected#
Your personal data is collected by electronic means, wholly or partly automatically, through these channels:
- the sign-up and sign-in pages, the contact form, and account and workspace settings;
- invitations sent by a workspace administrator;
- email and support correspondence; and
- automatic means such as server logs and browser local storage. The cookie policy describes them in detail.
Your rights (Article 11)#
Under Article 11 of the Law, you can apply to us to exercise the following rights:
- 1.to learn whether your personal data is processed;
- 2.to request information if your personal data has been processed;
- 3.to learn the purpose of the processing and whether the data is used in line with that purpose;
- 4.to know the third parties, in the country or abroad, to whom your personal data is transferred;
- 5.to request correction of personal data that is incomplete or inaccurately processed;
- 6.to request erasure or destruction of your personal data under the conditions set out in Article 7 of the Law;
- 7.to request that the operations carried out under items 5 and 6 are notified to the third parties to whom your data has been transferred;
- 8.to object to an outcome against you that results from analysis of your data exclusively by automated systems; and
- 9.to claim compensation for damage you suffer because your personal data was processed unlawfully.
How to apply and how we respond is described in the next section. The privacy policy describes the equivalent rights under GDPR and other applicable data protection laws.
How to submit a request#
You can submit an application about your rights in writing by either of these routes:
- by email to privacy@relevant.com.tr, sent from the email address registered with your account; or
- through the contact form, choosing the Privacy topic.
So that we can handle your application, please include:
- your first and last name;
- the information we need to confirm your identity, such as the email address registered with your account;
- an email or postal address where we can send our answer;
- a clear description of what you are asking for; and
- any supporting information or documents.
Our response
We conclude applications as soon as possible and within 30 days at the latest, depending on the nature of the request, free of charge. If the process requires a separate cost, a fee may be charged at the rate set by the Personal Data Protection Board (the “Board”) under Article 13 of the Law. We may ask for additional information to confirm your identity.
Right to complain
If your application is rejected, you find our answer insufficient, or we do not answer in time, you can complain to the Board within 30 days of learning our response and in any case within 60 days of the date of your application (Article 14 of the Law).
Retention periods#
- Account data
- Retention period
- While the account is active. After the account is closed it is deleted or anonymized within 30 days, subject to any legal retention obligation.
- Evaluation runs, traces and review history
- Retention period
- Set by your plan: 7 days on Free, 30 days on Pro and 90 days on Team, or as agreed on Enterprise. Data is deleted when the retention window ends.
- Billing and accounting records
- Retention period
- For the period required by the applicable tax and commercial legislation, generally up to ten years.
- Support and contact records
- Retention period
- Up to 24 months after the last message.
- Security and access logs
- Retention period
- 12 months.
- Data processed on the basis of explicit consent
- Retention period
- Until you withdraw your consent.
At the end of the retention period your personal data is deleted, destroyed or anonymized in accordance with the regulation on the deletion, destruction or anonymization of personal data. Deleted data is removed from backups on their normal rotation cycle, which does not exceed 35 days.
Security measures (Article 12)#
Relevant takes the technical and administrative measures needed to provide an appropriate level of security: to prevent unlawful processing of personal data, to prevent unlawful access to it, and to keep it safe. The main measures are:
- encryption in transit and at rest;
- logical separation between customers (tenant isolation);
- role-based authorization and the principle of least privilege;
- audit logs for access and administrative actions; and
- confidentiality obligations for personnel and periodic review of access rights.
If personal data is obtained by others through unlawful means, we notify the data subject and the Board as soon as possible. The security page has more detail.
Changes to this notice#
We update this notice when our processing activities or the law change. The date at the top shows the latest revision. We notify workspace owners by email before a material change takes effect, and we keep earlier versions available on request.