This document is provided for information only and is not legal advice; it should be reviewed by counsel before it goes live.
Privacy Policy
Last updated: 14 June 2026
This Privacy Policy explains how İnisiyatif Yazılım Bilgisayar Danışmanlik Hiz. Ltd. Şti. (“Zervanor”, “we”, “us”) collects, uses, discloses, and protects personal data when you visit our website, create an account, or use the Zervanor automation platform (the “Service”).
We act as a data controller for the account and usage data described below. For the data your organization sends through the Service to run its own workflows and agents, we act as a data processor on your organization’s behalf — those activities are governed by our Data Processing Agreement.
If you are in Türkiye, please also read our KVKK Disclosure Notice, which sets out your rights under Law No. 6698. If you are in the EEA or UK, this policy is designed to meet our obligations under the GDPR.
Who we are
The data controller is İnisiyatif Yazılım Bilgisayar Danışmanlik Hiz. Ltd. Şti., registered in İstanbul, Türkiye (Tax No. 4780545883 · MERSİS 0478054588300013). For any privacy matter you can reach us at privacy@zervanor.com, or for Türkiye/KVKK requests at kvkk@zervanor.com.
What personal data we collect
We collect only what we need to operate the Service:
- Account data — your email address, name, username, and a securely hashed password (we never store passwords in plain text). If you sign in with Google, we receive your Google account identifier, email, and name.
- Authentication & security data — login timestamps, failed-login counters, IP address, and browser/device information (User-Agent) for each session, used to keep accounts secure.
- Billing data — your plan, subscription status, and a payment-provider customer identifier. Card numbers are handled directly by our payment providers and are never stored on our systems.
- Usage & diagnostic data — actions you take in the platform (audit logs), error reports, and aggregate analytics about how the website and dashboard are used.
- Communications — messages you send us (e.g. support or contact-form submissions) and the email address you provide.
- Workflow content — data that flows through the automations and agents you build. We process this on your instructions as a processor; see the DPA.
We do not intentionally collect special-category data, and we ask that you do not place such data into free-text fields unless strictly necessary.
How and why we use your data
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Create and authenticate your account, run your workflows | Performance of a contract |
| Keep accounts secure | Detect abuse, rate-limit, lock out brute-force attempts | Legitimate interests / legal obligation |
| Billing & payments | Manage subscriptions, process payments, issue invoices | Performance of a contract / legal obligation |
| Support & communication | Respond to your requests, send service notices | Performance of a contract / legitimate interests |
| Improve the Service | Aggregate analytics, fix errors, plan features | Legitimate interests / consent (cookies) |
| Marketing (optional) | Product updates and news, only if you opt in | Consent |
| Comply with the law | Tax, accounting, and lawful requests | Legal obligation |
Under the KVKK, the corresponding legal grounds are explicit consent and the exceptions in Articles 5(2) and 6(3) (e.g. necessity for a contract, legal obligation, and legitimate interests).
Cookies and analytics
Our website and dashboard use cookies and similar technologies. Strictly necessary cookies are always on; analytics and similar non-essential cookies load only after you consent via our cookie banner. For the full list and how to change your choice, see the Cookie Policy.
Who we share data with (sub-processors)
We do not sell personal data. We share it only with vendors who help us run the Service, under contracts that require them to protect it. Current categories and providers include:
| Category | Provider(s) | Purpose |
|---|---|---|
| Payments | PayTR, Stripe | Subscription billing and payment processing |
| Email & notifications | Novu, our SMTP provider | Transactional email and in-app notifications |
| Authentication | Google (Sign-in) | Optional single sign-on |
| AI / LLM features | OpenAI, Google (Gemini) | Optional AI-assisted features you invoke |
| Hosting & infrastructure | Akamai (Linode), Cloudflare | Cloud hosting, storage, CDN, and network security |
| Error & performance monitoring | Sentry, Grafana stack | Diagnostics and reliability |
The current list is maintained as part of our DPA. We update it as our vendors change.
International transfers
We are based in Türkiye and use service providers that may process data in the EEA, the UK, the US, and other countries. Where data leaves the EEA/UK or Türkiye, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and equivalent KVKK mechanisms — and assess each transfer for an adequate level of protection.
How long we keep data
We keep personal data only as long as necessary:
- Account data — for the life of your account, then deleted or anonymized after closure (see below).
- Billing records — for the period required by Turkish tax and accounting law.
- Security and audit logs — for a limited retention window appropriate to their security purpose.
- Workflow content — under your organization’s control and configurable retention settings.
When you delete your account, we deactivate it and anonymize the personal identifiers in our records, retaining only what we are legally required to keep.
Your rights
Depending on where you live, you have rights to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data (“right to be forgotten”);
- Restrict or object to certain processing;
- Port your data to another provider;
- Withdraw consent at any time (without affecting prior processing); and
- Lodge a complaint with a supervisory authority — in Türkiye the Personal Data Protection Authority (KVKK Kurumu), or in the EEA your local data protection authority.
You can exercise the most common rights directly from the dashboard: download a copy of your data from Settings → Privacy → Download your data, and delete your account from Settings → Danger Zone. For anything else, email privacy@zervanor.com and we will respond within the timeframes required by law (generally 30 days).
How we protect your data
We use industry-standard measures including encryption in transit, hashed passwords, tenant isolation, least-privilege access, audit logging, and continuous monitoring. No system is perfectly secure, but we work to protect your data and to notify you and the relevant authorities of any breach as required by law.
Children
The Service is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. We will post the new version here with a revised “Last updated” date and, for material changes, notify you in the product or by email.
Contact
İnisiyatif Yazılım Bilgisayar Danışmanlik Hiz. Ltd. Şti. — privacy@zervanor.com (general) · kvkk@zervanor.com (Türkiye/KVKK).
Data controller
İNİSİYATİF YAZILIM BİLGİSAYAR DANIŞMANLIK HİZ. LTD. ŞTİ.
Acıbadem Mah. Çeçen Sk. Akasya Evleri A (Kule) Blok
No: 25 A İç Kapı No: 150 Üsküdar / İstanbul
VKN: 4780545883 · MERSİS: 0478054588300013