Privacy Agreement
Last updated: June 16, 2026
This Agreement sets out how personal data collected through the deeplexs.com and app.deeplexs.com websites, the Deeplexs web application, the browser extension and all related services (together the "Platform"), operated by Rackle Bilişim ve Teknoloji A.Ş., is processed. It is prepared under Personal Data Protection Law no. 6698 (KVKK), its secondary legislation and the decisions of the Personal Data Protection Board. The Turkish text is the operative version.
1. Data controller
Rackle Bilişim ve Teknoloji A.Ş. · Ehlibeyt Mah. Ceyhun Atuf Kansu Cd. No:124 İç Kapı No:27 Çankaya/Ankara, Türkiye · MERSİS No: 0857058969400001 · KEP: racklebilisim@hs01.kep.tr · Email: kurumsal@deeplexs.com. Anyone who visits, registers on or uses the Platform is deemed to accept the practices described in this Agreement.
2. Separation of roles
Deeplexs takes on two different roles for two categories of data. For data relating to account creation, billing, support and the operation of the Platform, it is the data controller. For personal data belonging to clients or third parties contained in the petitions, files, documents and queries uploaded by the User (Client Data), the User is the data controller; Deeplexs acts solely as a data processor on the User's instructions. The User acknowledges that the obligations of disclosure, legal basis and, where required, explicit consent for such content rest with the User, who acts within the scope of attorney–client privilege.
3. Personal data processed
Account and identity data: name, surname, email address, phone number, firm/organisation name and title, and a password stored as an irreversible hash. Billing and payment data: billing title, tax office/number, billing address. Usage and transaction security data: IP address, browser and device information, session records, audit logs, and traffic records required under Law no. 5651. Communication and support data: support requests and correspondence. Content data: documents and files uploaded to the Platform, queries and their outputs — processed in the capacity of data processor as described in section 2.
4. Purposes and legal grounds
Creating membership and providing the service: performance of a contract (art. 5/2-c). Billing, financial obligations and traffic records under Law no. 5651: legal obligation (art. 5/2-ç). Ensuring Platform security, preventing misuse and improving service quality: legitimate interest (art. 5/2-f). Establishment, exercise or protection of rights: art. 5/2-e. Commercial electronic messages: explicit consent together with İYS approval under Law no. 6563. Consent required for such processing is obtained separately and freely; withholding it does not prevent use of the Platform's core services.
5. Payment data
Payment transactions are carried out through iyzico, a payment institution authorised under Law no. 6493. Credit and debit card details are not stored on Deeplexs systems; card data is processed directly by the payment institution.
6. Commitments regarding AI processing
No model training on user data: uploaded files, queries and Client Data are not used to train or improve AI models. Source-bound answers: AI responses are grounded in the case-law and legislation corpus on the Platform, and User content never becomes a source for other users' queries. Firm-level isolation: each firm/organisation account's data is held in logically isolated workspaces. Masking mode: on request, personal and sensitive data is masked before being processed by AI components.
7. Hosting and cross-border transfers
Platform data is held on servers in the Microsoft Azure Sweden Central region. In order to provide the Service, personal data is transferred abroad to AI model providers and infrastructure service providers; such transfers are carried out within the conditions set out in art. 9 of KVKK. Detailed information about the legal basis and recipient groups can be requested from kurumsal@deeplexs.com. Under the Enterprise plan, the model can run entirely on your own infrastructure so that data does not leave your environment.
8. Domestic transfers
Personal data may be transferred, only to the extent necessary to provide the Service and in accordance with art. 8 of KVKK, to hosting and cloud infrastructure providers, payment institutions, and email and notification infrastructure providers acting as data processors. Transfers to authorised public authorities are made only where legally required and after verifying the lawfulness of the request. For content covered by attorney–client privilege, the narrowest interpretation permitted by legislation is applied.
9. Retention periods
Account data: for the duration of membership and, after it ends, for the general statute of limitations. Billing and financial records: ten years as required by legislation. Traffic records: for the period prescribed by Law no. 5651. Content data and Client Data: deleted or anonymised within ninety days at the latest once the User deletes them or membership ends. Support correspondence: three years. Data whose retention period has expired is removed through deletion, destruction or anonymisation within a periodic disposal cycle.
10. Data security
Principal measures taken under art. 12 of KVKK: encryption of data in transit and at rest, firm-level logical data isolation, role-based access control and the principle of least privilege, audit logs and regular access reviews, and regular application of security updates with vulnerability monitoring. Should personal data be obtained by others through unlawful means, the situation is reported to the data subject and the Personal Data Protection Board as soon as possible under art. 12/5 of KVKK.
11. Cookies
Only cookies strictly necessary for session management and security are used on the Platform; no analytics or marketing cookies are used.
12. Your rights under KVKK
Under art. 11 of KVKK you have the right to learn whether your personal data is processed; to request information if it has been; to learn the purpose of processing and whether it is used accordingly; to know the third parties to whom it is transferred domestically or abroad; to request correction if it is incomplete or incorrect; to request erasure or destruction within the framework of art. 7; to request that correction and erasure be notified to third parties to whom the data was transferred; to object to a result against you arising from analysis solely by automated systems; and to claim compensation for damage suffered due to unlawful processing.
13. How to apply
Requests may be sent, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller, to kurumsal@deeplexs.com or to the postal or KEP address stated above. Applications are concluded free of charge within thirty days at the latest; where the process entails an additional cost, the fee in the tariff set by the Board may be charged. If an application is rejected, a complaint may be filed with the Personal Data Protection Board within thirty days of learning the response and in any case within sixty days of the application.
14. Third-party links and changes
The Platform may contain links to official systems such as UYAP and UETS or to third-party sites; the operators concerned are responsible for their privacy practices. Data accessed through UYAP and UETS connections is processed only through the User's own authorised session and at the User's request; Deeplexs does not establish independent access to these systems on the User's behalf. This Agreement may be revised in line with legislative changes or service updates; material changes are announced through the Platform and/or by email before they take effect.