LegalUpdated 2026-09-23

Privacy Policy

This Privacy Policy describes our processing of Account Data, Service Data, and personal data collected on visits to the marketing site. It does not govern Customer Content. Customer Content means the files, notebooks, prompts, synthetic output, and models trained for that data that you submit to the service, and the Data Processing Addendum governs that processing. If your personal data appears in another customer’s Customer Content, you must address that customer. Where we can identify the customer, we will refer your request to them.

The contracting party is DATAXID TEKNOLOJİ VE TİCARET ANONİM ŞİRKETİ, Reşitpaşa Mah. Katar Cad. İTÜ Tasarım ve Prototip Merkezi Binası No: 2/41, İç Kapı No: 5, 34469 Sarıyer, İstanbul, Türkiye. These terms are governed by the laws of the Republic of Türkiye, and the courts of Istanbul have jurisdiction, except where a mandatory consumer protection law of your residence says otherwise.

This policy forms part of the Terms of Service. By creating an account, you agree to this policy.

1. Categories of information

Account Data. When you create an account, Clerk processes your name, email address, and profile image on our behalf. We retain the plan associated with the account.

Billing. Polar, our payment processor, receives your name and email address for the purpose of billing the account. Resend sends service email concerning the account, including notices of credits and plan changes, to the email address on the account.

Service Data. We retain usage counts, security logs, and the non-secret portion of an API key. We display an API key once and do not retain it in a form from which we can recover the key.

Sites. The marketing site at dataxid.com does not place analytics cookies. The application places a Clerk session cookie, which is strictly necessary to maintain your signed-in session, and uses Vercel Analytics on the dashboard and the documentation. Vercel Analytics does not receive your datasets.

2. Purposes and recipients

We process Account Data and Service Data on the following grounds. We process them to perform our contract with you, which covers opening the account, authenticating you, billing you, sending service email, and enforcing the limits of your plan. We process billing records to comply with a legal obligation. We process security logs, usage counts, and dashboard and documentation analytics for our legitimate interest in securing and operating the service, where that interest is not overridden by your rights. We do not sell personal information. Agreeing to this policy is not, by itself, the legal ground for the processing.

We disclose each category to the processor named for it on the subprocessors page. Clerk holds the name, email address, and profile image. Microsoft Azure holds the plan, usage counts, security logs, and the non-secret portion of an API key, together with Customer Content as that page states. We may also disclose personal data where the law requires it, or in connection with a sale or reorganization of the business, provided the recipient is bound by this policy.

3. Retention

We retain Account Data and Service Data for so long as the account remains open and we require the information to provide the service. After the account closes, we will delete that information or restrict access to it within a reasonable time. We retain billing records for the period required by tax and commercial law. This Section 3 does not commit us to deletion within any fixed number of days.

4. Rights

Where the law of your residence provides the right, you may request access to Account Data, correction or deletion of it, restriction of its processing, or a copy of it, and you may object to processing. A person in Türkiye may exercise the rights provided by KVKK. A person in the European Economic Area or the United Kingdom may exercise the rights provided by the GDPR, to the extent that law applies. You must send the request to [email protected]. We may decline to act until we have confirmed that you are the holder of the account.

We do not knowingly collect Account Data from a person under 18. If you believe that we have done so, notify us at [email protected] and we will delete that Account Data.

5. Location of processing

We are established in Türkiye. The processors named in this policy process personal data in the European Union and in the United States, in the locations stated on the subprocessors page. Where a transfer of Account Data or Service Data from the European Economic Area, the United Kingdom, or Switzerland requires a safeguard, we make it under the Standard Contractual Clauses in the data-processing terms of the processor that receives the data. A transfer of Customer Content is made under the Standard Contractual Clauses incorporated by the Data Processing Addendum.

6. Changes

We may amend this policy by posting an updated version that states the date on which it takes effect. If an amendment is material, we will give notice to the email address on the account before that date. This policy forms part of the Terms of Service, and continued use of the service on or after the effective date constitutes acceptance of the amended policy.