Privacy Policy
BeeUpTech privacy policy: personal data processed, legal grounds, transfers, retention periods and your rights.
This Privacy Policy explains how BeeUpTech Yazılım ve Teknoloji Hizmetleri (“BeeUpTech”, the “Company” or “we”) collects, uses, shares and retains personal data obtained through the www.beeuptech.com website and its related digital channels (contact and quotation forms, newsletter subscription, the AI-powered assistant, the free site analysis and campaign pages).
The Policy has been prepared in accordance with the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and its secondary legislation and — for visitors located in the European Union — the General Data Protection Regulation (“GDPR”). Our disclosure obligation under Article 10 of the KVKK is fulfilled separately through the Data Protection Notice; details on cookies and similar technologies are set out in the Cookie Policy.
1. Identity of the Data Controller
The legal entity acting as data controller within the meaning of Article 3/1(ı) of the KVKK is identified below.
| Legal name | BeeUpTech Yazılım ve Teknoloji Hizmetleri |
|---|---|
| Brand | BeeUpTech |
| Registered address | Levent, Buyukdere Avenue No: 185, 34394 Sisli / Istanbul, Türkiye |
| info@beeuptech.com | |
| Website | www.beeuptech.com |
2. Definitions
- Personal data: Any information relating to an identified or identifiable natural person.
- Data subject: The natural person whose personal data is processed — for the purposes of this Policy, website visitors, prospective clients, representatives of clients and suppliers, and job applicants.
- Processing: Any operation performed on personal data, including collection, recording, storage, alteration, transfer, classification and erasure.
- Data processor: A natural or legal person processing personal data on behalf of the data controller under its authorisation (such as our hosting, e-mail and analytics providers).
3. Categories and Sources of Personal Data
We collect only the data required to deliver the service. Special categories of personal data (health, biometric data, religion, union or association membership, etc.) are neither requested nor knowingly processed; please do not submit such data through our forms.
| Data category | Examples | Source |
|---|---|---|
| Identity | First name, last name | Contact / quotation form, chatbot, newsletter, campaign pages |
| Contact | E-mail address, telephone number, company name and job title, website address | Contact / quotation form, chatbot, newsletter |
| Customer transaction | Subject of the request, message content, project summary, stated budget and timeline, ticket number and correspondence history | Form and chatbot interactions |
| Transaction security | IP address, browser and device information (user agent), session key, server and application logs, reCAPTCHA risk score | Automatically, through your use of the site |
| Marketing | UTM parameters, referrer, page path visited, cookie identifiers, campaign click data | Cookies, link parameters, advertising networks |
| Consent records | KVKK consent flag and timestamp, cookie preference, commercial message consent | Form submissions and the cookie preference panel |
3.1 Data obtained indirectly
As part of our corporate sales and business development activities, corporate contact details of companies and their representatives may be obtained from publicly available sources (company websites, business directories, map and business listings). Such data is processed solely for corporate outreach on the legitimate interest ground under Article 5/2(f) of the KVKK; a reference to this Policy is provided at first contact, and your record is deleted without delay upon request.
4. Purposes of Processing
- Responding to quotation, demo, discovery-call and consultancy requests and tracking them as tickets
- Conducting pre-contractual negotiations and the formation and performance of contracts
- Customer relationship management, technical support and after-sales processes
- Operating the website, managing sessions, debugging and improving performance
- Ensuring information security and preventing fraud, automated bot traffic and misuse
- Where you have given explicit consent: analytics measurement, advertising performance evaluation and commercial electronic messages
- Complying with legal obligations, responding to requests from competent authorities, and establishing and defending legal claims
5. Legal Grounds
Every processing activity relies on at least one of the legal grounds below.
| Processing activity | Legal ground under KVKK | GDPR equivalent |
|---|---|---|
| Handling requests and quotations | KVKK Art. 5/2(c) — directly related to the formation or performance of a contract | GDPR Art. 6(1)(b) |
| Site security, logging, bot protection | KVKK Art. 5/2(f) — legitimate interest | GDPR Art. 6(1)(f) |
| Bookkeeping, invoicing and record-keeping duties | KVKK Art. 5/2(a) and (ç) — expressly provided by law and legal obligation | GDPR Art. 6(1)(c) |
| Analytics and advertising cookies | KVKK Art. 5/1 — explicit consent | GDPR Art. 6(1)(a) |
| Newsletter and commercial electronic messages | KVKK Art. 5/1 — explicit consent; approval under Law No. 6563 | GDPR Art. 6(1)(a) |
| Defence in legal disputes | KVKK Art. 5/2(e) — establishment, exercise or protection of a right | GDPR Art. 6(1)(f) |
6. Cookies and Similar Technologies
In addition to strictly necessary cookies, analytics and advertising cookies are used only if you give consent through the cookie preference panel. Until consent is given, Google Analytics and Google Ads tags operate in the “denied” consent state and no measurement identifier is created. For the full list, durations and preference management, see the Cookie Policy.
7. Transfer of Personal Data
We do not sell, rent or otherwise disclose your personal data to third parties for marketing purposes. Transfers are made only to the recipient groups below, limited to the stated purpose and subject to confidentiality undertakings and data processing agreements.
| Recipient group | Purpose of transfer | Location |
|---|---|---|
| Hosting and infrastructure providers | Operation of the website and database, backups | Türkiye |
| E-mail / SMTP service provider | Delivery of notifications, tickets and newsletters | Depends on provider configuration |
| Our own AI model server | Generation of chatbot responses | Private server restricted by access token |
| Google Ireland Ltd. / Google LLC (Analytics, Tag Manager, Ads, reCAPTCHA) | Consent-based measurement, advertising performance and bot protection | Outside Türkiye |
| Legal, accounting and independent audit advisers | Legal obligations and protection of rights | Türkiye |
| Competent public authorities | Statutory requests for information and documents | Türkiye |
7.1 International transfers
Limited data processed through Google services (cookie identifiers, IP address, user-agent information) may be processed on servers located abroad. Such transfers are carried out under Article 9 of the KVKK, based either on your explicit consent or on the appropriate safeguards recognised by the Turkish Data Protection Board (standard contracts, undertakings or an adequacy decision). If you do not consent to analytics and advertising cookies, no transfer occurs on that basis; security components such as reCAPTCHA continue to operate on the legitimate interest ground in order to protect the site against misuse.
8. Retention and Erasure
Your personal data is retained for as long as the purpose of processing requires and for the limitation periods prescribed by law; once these expire, the data is deleted, destroyed or irreversibly anonymised.
| Data type | Retention period | Basis |
|---|---|---|
| Contact / quotation requests (tickets) | 3 years from the last interaction | Request tracking and potential disputes |
| Client records under a contract | 10 years from termination of the contract | General limitation period (TCO Art. 146) and statutory bookkeeping duties |
| Newsletter subscription | Until unsubscription; 3 years thereafter for proof of consent | Burden of proof under Law No. 6563 |
| Server and application logs | 1 year | Information security and forensic traceability |
| Marketing and campaign interaction records | 2 years | Campaign performance analysis |
| Cookie data | As stated in the Cookie Policy | Varies by cookie type |
9. Data Security
Pursuant to Article 12 of the KVKK, we implement administrative and technical measures appropriate to the level of risk in order to prevent unlawful processing of and access to personal data:
- TLS/HTTPS encryption for all traffic; secure cookie configuration (Secure, HttpOnly, SameSite)
- Role-based access control, individual accounts and the principle of least privilege
- Restricted access to the administration panel, a strong password policy and session timeouts
- CSRF protection, server-side form validation and automated bot filtering via reCAPTCHA v3
- Regular backups, updates and security patch management
- Confidentiality undertakings with staff and data processing agreements with suppliers
- Notification to the Board and to affected data subjects as soon as possible in the event of a breach (KVKK Art. 12/5)
10. Automated Evaluation
The site uses an AI-powered assistant and automated bot protection. These systems serve response generation and security purposes only; no decision producing legal effects concerning you or similarly significantly affecting you is taken solely by automated means. Content generated by the assistant is informational and does not constitute a binding offer (see the Terms of Use).
11. Children’s Data
Our website is intended for business customers; we do not knowingly collect personal data from persons under the age of 18. Any such data identified is deleted without delay.
12. Your Rights and How to Exercise Them
Under Article 11 of the KVKK you have the right to: learn whether your personal data is processed; request information if it has been processed; learn the purpose of processing and whether the data is used in accordance with that purpose; know the third parties to whom the data is transferred in Türkiye or abroad; request rectification of incomplete or inaccurate data; request erasure or destruction where the statutory conditions are met; request that such actions be notified to third parties to whom the data was transferred; object to a result adverse to you arising from analysis carried out solely by automated means; and claim compensation for damage suffered due to unlawful processing.
You may submit your request, together with information verifying your identity, through the Data Subject Request Form. Requests are concluded free of charge as soon as possible and in any event within 30 days; where the operation entails an additional cost, the fee set out in the Board’s tariff may be charged.
12.1 Visitors covered by the GDPR
If you are located in the European Union or the European Economic Area, you have the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability and objection. Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out beforehand. You may send your requests to info@beeuptech.com and you also have the right to lodge a complaint with the supervisory authority in your country of residence.
13. Third-Party Links
Our site may contain links to third-party websites. BeeUpTech is not responsible for the content or privacy practices of those sites; we recommend reviewing their own policies.
14. Changes to this Policy
This Policy may be revised due to changes in legislation or in our processes. The current version is always published on this page, with the version number and effective date shown at the top. In the event of material changes, we will provide additional notice through appropriate channels.
15. Contact
For questions and requests regarding this Policy: info@beeuptech.com — adding “Privacy” to the subject line will speed up the review.