Skip to content

Last updated

Privacy Policy

What data Trilato processes while you use it, why, and what you can do about it.

What this policy covers

This policy covers the application at trilato.com.tr, the Trilato for LinkedIn browser extension, and the server behind them.

There are two separate groups of data: data about your account (your data) and data about the people you save into the CRM (third parties' data). Different rules apply to each, and the distinction is stated plainly below.

What we process

Account data: your name, e-mail address, the bcrypt hash of your password, your workspace and role, session records, and the SHA-256 digests of your extension keys. Neither your password nor your keys are stored anywhere in clear text.

CRM data: for the people you enter or save with the extension — name, title, company, e-mail addresses, phone, LinkedIn and Apollo address, profile photo URL, location, experience and education history, notes, meetings and outreach rounds.

Technical data: rate-limit counters and an audit record of administrative actions. We collect nothing for advertising, profiling or behavioural tracking.

Where the data comes from

Directly from you: sign-up, invitation and in-app forms.

From the extension: only when you press the button next to a person, and only from the LinkedIn or Apollo page open at that moment. The extension does not browse on its own and does not harvest in bulk.

From file imports: the spreadsheets you upload.

Why we process it

To run the service: keeping your contact list, preventing duplicates, deriving round and stage information, producing exports.

To protect your account: session handling, authorisation, rate limiting against abuse.

To meet our obligations: billing and records required by law.

Who we share it with

We do not sell your data and we do not pass it to anyone for advertising.

The application contains no third-party analytics, advertising or tracking tools. No external scripts are loaded into its pages.

Our infrastructure providers — server hosting and the CDN and security layer in front of the traffic — are technically able to access data and act solely to provide the service.

Where legally required, information is given to competent authorities, limited to the scope of the request.

How long we keep it

Account and CRM data are kept until you delete them or your workspace is closed.

Database backups are kept for 14 days by default and expire automatically. A record you delete in the app may remain in backups until that rotation completes.

The audit record of administrative actions is kept in a form that cannot be altered afterwards, and may be retained after an account closes.

Security

All traffic is encrypted with TLS. Passwords are hashed with bcrypt; session tokens, invitation tokens and extension keys are stored only as SHA-256 digests, so a database leak does not hand over a working credential.

Every query is scoped to a workspace id; one workspace's data is not visible to another.

The extension key never enters the page; all network requests leave from the extension's background service. The server accepts requests only from allow-listed extension origins.

Cookies

We use only the strictly necessary cookie that carries your session. There are no advertising or analytics cookies, which is why there is no consent banner.

Your rights

For data about you, you have rights of access, rectification, erasure and objection. If you are resident in Türkiye, your rights under KVKK and how to exercise them are set out on the KVKK notice page.

You can send a request to [email protected].

Changes

When we update this policy we change the date at the top of the page. For a substantial change we also notify the e-mail address on your account.

Contact

Data controller
Suleyman Gumus
VERBİS
Not subject to registration.