Last Updated: 24 July 2026 | Version: 2.0
This Disclosure Text has been prepared by Bimetrik Teknoloji Yazılım ve Danışmanlık Anonim Şirketi (“Bimetrik”, “Company”), in its capacity as data controller, pursuant to the Turkish Personal Data Protection Law No. 6698 (“KVKK”), for the purpose of informing website visitors, members, customers and business partners about the processing of their personal data.
1. Data Controller
- Legal Name: Bimetrik Teknoloji Yazılım ve Danışmanlık Anonim Şirketi
- Address: Yeniköy Merkez Mah. Vatan Cad. Teknopark Sitesi No: 83 İç Kapı No: B35 Başiskele/Kocaeli
- Tax Office / No: Tepecik Vergi Dairesi / 1751033095
- MERSIS No: 0175103309500001
- E-mail: [email protected]
- Registered E-mail (KEP): [email protected]
- Web: https://bimetrik.ai
2. Processed Personal Data
- Identity data: first name, last name, (where necessary) national ID number.
- Contact data: phone, e-mail, address.
- Financial data: invoice and payment information (card details are not stored).
- Transaction security data: IP address, log records.
- Usage and activity data: site/application usage data, cookie data.
- Corporate contact data: company name, tax number, authorized person information.
3. Purposes of Processing Personal Data
- Providing and improving online services, the mobile application and the browser extension,
- Membership, authentication and account management,
- Management of suggestions, complaints and requests, and communication,
- Detection/resolution of software errors and statistical evaluations,
- Ensuring information security and system management, and preventing misuse,
- Fulfilling legal obligations and complying with legislation,
- Marketing and promotional activities where you provide explicit consent.
4. Legal Bases
Your personal data is processed under Articles 5 and 6 of the KVKK on the legal bases of explicit consent (Art. 5/1), being expressly stipulated in laws/fulfillment of a legal obligation (Art. 5/2-ç), the establishment and performance of a contract (Art. 5/2-c) and legitimate interest (Art. 5/2-f).
5. Data Collection Methods
- Through the website, mobile application, browser extension and cookies,
- Through electronic forms, e-mail and communication/support channels,
- Through contracts and other commercial documents.
6. Transfer of Personal Data
Your personal data may be shared with infrastructure/technology providers, business partners, service providers and authorized public institutions/organizations within the framework of Article 8 of the KVKK and limited only to the relevant purpose. The categories of service providers used are published in our Sub-processor List for transparency. Your data is not sold or rented to third parties for marketing purposes.
7. International Transfer
The transfer of your personal data abroad is carried out pursuant to Article 9 of the KVKK No. 6698 (as amended by Law No. 7499), observing the following order:
- Where there is an adequacy decision announced by the Personal Data Protection Board, based on that decision;
- If there is no adequacy decision, provided that one of the appropriate safeguards listed in Article 9/3 of the KVKK is ensured (such as a standard contract between the parties, binding corporate rules, a written undertaking and Board authorization);
- In cases where these methods are not available, limited only to the incidental cases stipulated in Article 9/6 of the KVKK (e.g. obtaining your explicit consent, necessity for the performance of a contract).
The servers of our hosting, cloud and AI technology providers may be located abroad. In AI-powered features, no personal data is shared even in international transfers; data is processed in anonymized/masked form. Encryption, access control and contractual safeguards are applied in transfers.
8. Data Security
Pursuant to Article 12 of the KVKK, the necessary technical and administrative measures (encryption, firewall, SSL/TLS, access management, logging, physical security and regular backups) are taken for the confidentiality and security of your personal data. The measures applied are explained separately in our Data Security Policy.
9. Retention and Destruction
Your personal data is retained for the period required by the processing purpose and the retention periods stipulated in legislation; at the end of the period it is deleted, destroyed or anonymized. Details are set out in our Data Retention and Destruction Policy.
10. Data Subject Rights (Article 11 of the KVKK)
Under Article 11 of the KVKK, you have the rights to: learn whether your personal data is being processed; request information if it has been processed; learn the purpose of processing and whether it is used in accordance with its purpose; know the third parties to whom it has been transferred domestically or abroad; request correction if it has been processed incompletely or incorrectly; request its deletion/destruction under the conditions of Article 7 of the KVKK; request that correction/deletion operations be notified to the parties to whom the data has been transferred; object to results arising against you as a result of analysis exclusively by automated systems; and claim compensation for damage arising from unlawful processing.
11. Application Method and Response
To exercise your rights, you may apply in writing, via registered electronic mail (KEP), secure electronic signature/mobile signature, or through the e-mail address registered in our system to [email protected]. Your application is concluded within 30 days at the latest pursuant to Article 13 of the KVKK. If your application is rejected, the response is found insufficient, or no response is given in time, you may file a complaint with the Personal Data Protection Board within 30 days from the date you learn of the response and in any case within 60 days from the date of application.
12. Updates
This Disclosure Text may be updated when necessary. You can access the current version at https://app.bimetrik.com.