Relevant · relevant.com.tr
Legal
Privacy policy
This policy explains what personal data Relevant collects when you visit relevant.com.tr or use the product, why we collect it, who receives it and what rights you have. It is written to meet the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
Last updated:
Who we are and our roles#
Relevant operates relevant.com.tr and the Relevant evaluation platform. In this policy “Relevant”, “we” and “us” mean that company. The contact details for privacy questions are in the contact section.
We handle personal data in two different roles, and the rules that apply to each differ:
- Controller. For personal data about visitors to relevant.com.tr, people who sign up for or administer an account, and people who contact us, we decide why and how the data is processed. This policy describes that processing.
- Processor. For the datasets, traces, evaluation results and reviews that customers bring into a workspace, the customer is the controller and we process the data on its documented instructions under our data processing agreement. If you are an end customer of an organization that uses Relevant, that organization is the right place to send privacy requests about your data.
Personal data we collect#
The categories below cover the website, the sign-up flow and the product. We collect the data directly from you unless stated otherwise.
- Account data
- What it includes
- Name, work email address, role, workspace name and the sign-in details needed to authenticate you.
- Source
- You, or the workspace administrator who invited you
- Workspace and usage data
- What it includes
- Plan, workspace settings, member list, API key metadata (name, prefix, creation date), evaluation run configuration, feature usage and audit log entries.
- Source
- Generated as you use the product
- Customer content
- What it includes
- Datasets, questions, reference answers, traces, retrieved passages, model outputs, review decisions and comments. Support conversations used as evaluation data may incidentally contain personal data about the customer’s own end users.
- Source
- You and the systems you connect
- Billing data
- What it includes
- Billing contact, company name, tax identification number, invoices and payment status. Card details are collected and held by our payment processor, not by us.
- Source
- You
- Communications
- What it includes
- Messages sent through the contact form or by email, support requests and your communication preferences.
- Source
- You
- Technical data
- What it includes
- IP address, browser and device type, referring page, timestamps and security logs. Browser storage is described in the cookie policy.
- Source
- Your browser, collected automatically
Special categories of data
Relevant is not designed to process special categories of personal data (Article 9 GDPR and the equivalent provisions of other data protection laws), such as health, biometric or political-opinion data. Please remove or mask personal and special-category data from datasets and traces before you upload them wherever you can.
How we use personal data and our legal bases#
We process personal data only for the purposes below and only where a legal basis in Article 6 GDPR, or an equivalent basis under another applicable data protection law, applies.
- Provide the service
- What this involves
- Create and manage accounts, authenticate you, run the evaluations you configure and store their results.
- Legal basis
- Contract: GDPR Art. 6(1)(b)
- Secure the service
- What this involves
- Monitor for abuse, apply rate limits, keep audit logs and investigate incidents.
- Legal basis
- Legitimate interests: GDPR Art. 6(1)(f)
- Billing and accounting
- What this involves
- Issue invoices, keep tax and accounting records, handle payment status.
- Legal basis
- Contract and legal obligation: GDPR Art. 6(1)(b), (c)
- Support and service messages
- What this involves
- Answer questions, resolve issues and send notices about your account, security and changes to the terms.
- Legal basis
- Contract and legitimate interests: GDPR Art. 6(1)(b), (f)
- Improve the product
- What this involves
- Analyze aggregate usage and performance to decide what to build and fix. Optional analytics run only with your consent.
- Legal basis
- Legitimate interests; consent for optional analytics: GDPR Art. 6(1)(a), (f)
- Product updates
- What this involves
- Send newsletters or product announcements you have opted in to. You can unsubscribe in every message.
- Legal basis
- Consent: GDPR Art. 6(1)(a), and the consent rules for electronic marketing that apply where you live
- Legal compliance and claims
- What this involves
- Respond to lawful requests from authorities, and establish, exercise or defend legal claims.
- Legal basis
- Legal obligation and legitimate interests: GDPR Art. 6(1)(c), (f)
Other data protection laws recognize comparable grounds, and we apply the equivalent ground wherever one of those laws governs the processing. Where we rely on legitimate interests we weigh them against your rights and expectations, and you can object at any time (see your rights). We do not make decisions about individuals that produce legal or similarly significant effects by solely automated means.
Customer content and model training#
Customer content stays yours. We process it only to provide the service you asked for, such as storing a dataset, running an evaluation, applying a judge and showing you the results.
- No training on your content. We do not use customer datasets, traces, reviews or evaluation results to train or fine-tune machine-learning models, ours or anyone else’s.
- Model providers you choose. When you run an evaluation that calls a model, for instance an LLM judge, only the content needed for that call is sent to the provider you configured, under that provider’s terms and the safeguards listed on the subprocessors page.
- Data processed in the region you choose. You select a region for the workspace when you create it, and customer content is stored and processed there.
- Staff access. Access to customer content is limited to what is needed to operate and support the service, is restricted by role and is logged.
International transfers#
Customer content is processed in the workspace region you choose. Some account, support or provider-side processing can involve access from, or storage in, another country. Where personal data leaves the European Economic Area, the United Kingdom or any other jurisdiction whose law restricts transfers, we rely on one of these mechanisms:
- an adequacy decision for the destination country;
- the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies;
- for transfers from other jurisdictions that restrict transfers abroad, the mechanism that law provides, such as an adequacy decision, a standard contract or other appropriate safeguards, or an occasional transfer that meets the statutory conditions.
You can ask for a copy of the safeguards that apply to your data through the contact details below.
How long we keep personal data#
We keep personal data only as long as the purpose requires or the law obliges us to.
- Account data
- Retention
- While the account is active, then deleted or anonymized within 30 days after closure unless the law requires us to keep it longer.
- Evaluation runs, traces and review history
- Retention
- Set by your plan: 7 days on Free, 30 days on Pro and 90 days on Team, or as agreed on Enterprise. The extended retention add-on keeps them for 12 months on Team. Data is deleted when the retention window ends.
- Datasets and reference answers
- Retention
- Until you delete them or close the workspace.
- Billing records
- Retention
- For the period tax and commercial law require, generally up to ten years.
- Support and contact messages
- Retention
- Up to 24 months after the last message.
- Security and access logs
- Retention
- 12 months.
Deleted data is removed from backups on their normal rotation cycle, which does not exceed 35 days, and it is not restored into the live service. Workspace owners can also delete the workspace itself from the settings page, and remove imported datasets from the Datasets page.
How we protect personal data#
We apply technical and organizational measures that match the risk, including encryption in transit and at rest, tenant isolation, role-based access control, audit logging and least-privilege access for staff. The security page describes them in more detail.
If a personal data breach affects you, we will notify the competent authorities and the affected customers within the time limits that apply, and we will describe what happened, what data was involved and what we are doing about it.
Your rights#
Depending on where you live, you have the following rights over your personal data:
- to know whether we process your data and to receive a copy (access);
- to have inaccurate or incomplete data corrected (rectification);
- to have your data deleted or destroyed when the conditions in the law are met (erasure);
- to restrict processing, and to object to processing based on legitimate interests;
- to receive the data you provided in a structured, commonly used format and to move it elsewhere (portability);
- to withdraw consent at any time, without affecting processing that took place before;
- not to be subject to a decision based solely on automated processing that has legal or similarly significant effects; and
- to lodge a complaint with a supervisory authority.
Some laws add further rights. Article 11 of Law No. 6698 (KVKK), for instance, includes the right to claim compensation for damage caused by unlawful processing. How to apply, and how we answer, is set out in the KVKK notice.
How to exercise your rights
Send your request to the privacy contact below, or use the contact form and choose the Privacy topic. We may ask you to confirm your identity before we act on a request. We reply within one month, or sooner where the law that applies to you sets a shorter deadline, and we do not charge a fee unless the request is manifestly unfounded or excessive.
Complaints
You can complain to the data protection authority where you live or work: in the European Union, the supervisory authority of your member state; in the United Kingdom, the Information Commissioner’s Office.
Children#
Relevant is a business product for engineering and quality teams and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy#
We update this policy when our practices or the law change. The date at the top shows the latest revision. We notify workspace owners by email before a material change takes effect, and we keep earlier versions available on request.
Contact#
Questions about this policy and requests to exercise your rights go to privacy@relevant.com.tr.
- Legal entity
- Relevant
- Privacy and data protection
- privacy@relevant.com.tr
- Legal notices
- legal@relevant.com.tr
You can also write to us through the contact form.