Identity of the data controller
Your personal data is processed by the company identified below, acting as data controller.
Last updated
Prepared under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data.
Your personal data is processed by the company identified below, acting as data controller.
Identity: name. Contact: e-mail address, telephone number, address. Professional experience: title, employer, experience and education history. Transaction security: password digest, session records, key digests, IP-based rate-limit counters. Visual record: profile photo URL. Customer transactions: saved notes, outreach and meeting rounds.
Providing the service and performing the contract, creating and authorising user accounts, ensuring information security and preventing abuse, billing and meeting financial obligations, handling requests and complaints.
Under Article 5 of the Law: processing directly related to the conclusion or performance of a contract (5/2-c), compliance with a legal obligation of the controller (5/2-ç), processing necessary for the establishment, exercise or protection of a right (5/2-e), and the legitimate interests of the controller provided that the fundamental rights of the data subject are not harmed (5/2-f).
Personal data is collected electronically and by automated means, through forms within the application, records created by the user's explicit action via the browser extension, and files uploaded by the user.
Under Article 8 of the Law, your personal data may be transferred to the suppliers providing server hosting and network security so that the service can be delivered, and to competent public authorities upon request, limited to the scope of that request.
Because of the content delivery and security layer in front of the traffic, data may be processed on servers outside Türkiye. Where that happens, the conditions in Article 9 of the Law are observed.
Your data is not sold or transferred to third parties for marketing purposes.
Personal data is retained for as long as necessary for the purpose of processing and for the limitation periods set out in the relevant legislation. On expiry, or upon your request, it is erased, destroyed or anonymised.
Because database backups are kept for 14 days by default, a deleted record may remain in backups for that period.
Under Article 11 of the Law you have the right to: learn whether your personal data is processed; request information if it has been; learn the purpose of processing and whether it is used accordingly; know the third parties to whom it is transferred, at home or abroad; request rectification if it is incomplete or inaccurate; request erasure or destruction within the conditions of Article 7; request that rectification, erasure and destruction be notified to the third parties to whom the data was transferred; object to a result against you arising from analysis solely by automated systems; and claim compensation if you suffer loss due to unlawful processing.
You may submit your requests in writing in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller, or through registered electronic mail, secure electronic signature, or the e-mail address registered in our system. Your application is concluded within thirty days at the latest. Where the process incurs a cost, the fee in the tariff set by the Board may be charged.
For applications: [email protected]
When you use Trilato to save personal data belonging to third parties, you are the data controller for that data and Trilato acts as a data processor.
Accordingly, meeting the duty to inform, having an appropriate legal ground, and responding to those individuals' requests are your responsibility. A separate data processing agreement is signed with corporate customers on request.