Data Protection

Comprehensive data protection measures and your rights (Effective: August 2, 2025)

πŸ›‘οΈData Protection Overview

We are committed to protecting your personal data and complying with applicable data protection laws. This page explains our security measures, our processors, retention and deletion practices, international transfers, and how you can exercise your rights.

Scope: Applies to the website (flinxai.com) and our mobile apps on Apple App Store and Google Play. See also our Privacy Policy for full details.

Data Controller: [Flinx-AI legal name], Address: [Full address], Email: [[email protected] or [email protected]].

πŸ”Security Measures

πŸ”’Encryption

Encryption in transit (TLS). Encryption at rest is applied where supported by our cloud/service providers (e.g., AES-256 or equivalent).

πŸ”‘Access Control

Role-based access, least-privilege, and MFA for administrative access. Secrets are stored using secure secret management.

πŸ”Logging & Monitoring

Centralized logging, alerting, and anomaly detection to help identify suspicious activity and performance issues.

πŸ’ΎBackup & Recovery

Regular automated backups; recovery runbooks and drills to support continuity.

πŸ› οΈSecure Development

SDLC practices: code review, dependency scanning, environment segregation, and change management.

πŸ‘₯Staff & Training

Need-to-know access, confidentiality undertakings, and periodic security & privacy awareness training.

🧩Processors & Sub-Processors

We do not sell personal data. We use trusted service providers to operate our services:

πŸ’³ Payments

Stripe (or similar). Card data is processed by the provider; we do not store card numbers.

πŸ“ˆ Analytics

Analytics provider(s) for usage metrics and product improvement (with consent where required).

☁️ Hosting/CDN

[Cloud provider / CDN] for infrastructure, storage, and content delivery.

βœ‰οΈ Email & Support

Email delivery and support ticketing systems to handle account and help requests.

See the Privacy Policy for legal bases and the full description of processing.

🌐International Data Transfers

Where data is transferred outside your country/region, we implement appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and technical/organizational measures with our processors.

πŸ—„οΈData Retention & Deletion

  • Account & contact data: kept while your account is active; deleted or anonymized upon request/closure, subject to legal holds.
  • Security logs & diagnostics: typically up to 12 months unless needed for security/legal reasons.
  • Analytics: up to 24 months in aggregate/pseudonymized form.
  • Billing & tax records: retained for the statutory period required by law.

Backups are cycled periodically; deletions may reflect in backups after the backup lifecycle (typically 30–90 days).

πŸ“‹Your Data Rights

πŸ‘οΈ

Access

Request confirmation and a copy of your personal data.

✏️

Rectification

Ask us to correct inaccurate or incomplete data.

πŸ—‘οΈ

Erasure

Request deletion where legally applicable.

πŸ“¦

Portability

Receive data in a structured, machine-readable format, where applicable.

πŸ›‘

Restriction & Objection

Restrict processing or object to processing on legitimate-interest grounds.

πŸ””

Consent Management

Withdraw consent (e.g., analytics cookies) at any time via Cookie Preferences.

You may also lodge a complaint with your local supervisory authority (e.g., KVKK Kurumu in TΓΌrkiye or an EU DPA).

βœ‰οΈHow to Exercise Your Rights

Send your request to [email protected]. We may need to verify your identity. We aim to respond within 30 days (extendable where permitted). For KVKK requests, you may also submit via a signed application or registered email as required by law.

🚨Incident Response

If we become aware of a personal data breach, we will investigate promptly and take appropriate action:

1.

Contain, assess scope/impact, and mitigate.

2.

Notify supervisory authorities within 72 hours where legally required.

3.

Inform affected users without undue delay when required.

4.

Implement corrective actions and improve controls.

βš–οΈCompliance Note

πŸ‡ͺπŸ‡Ί

GDPR

We align with GDPR requirements for EU/EEA users.

πŸ‡ΉπŸ‡·

KVKK

We address obligations under TΓΌrkiye's KVKK.

πŸ‡ΊπŸ‡Έ

CCPA/CPRA (where applicable)

We honor applicable rights for Turkey residents.

This page is informational and not legal advice. In case of discrepancy, the Privacy Policy prevails.

πŸ“žData Protection Contact (DPO if appointed)

For privacy or security questions, or to exercise your rights, please contact us:

πŸ“§
πŸ•’

Response Time

We aim to respond within 30 days.

Related: Privacy Policy Β· Terms & Conditions Β· Cookie Policy