Privacy Policy
Version: 1.0 — Last updated: August 15, 2026
Governing language: This English translation is provided for convenience only. The legally binding version is the Turkish original; in case of any discrepancy, the Turkish version prevails.
1. General Information and Data Controller
This Privacy Policy explains how personal data is collected, used, shared, transferred, stored, and protected in connection with the services offered under the ReportEngine brand via the reportengine.ai domain and its subdomains (the “Service”).
Data controller: AK Kurumsal İletişim Turizm Eğitim Danışmanlık A.Ş.
Address: Çeliktepe Mah. Kubilay Cad. No:1 İç Kapı No:13, 34413 Kağıthane/Istanbul, Türkiye
Phone: +90 212 225 61 31 · E-mail: info@reportengine.ai
For the detailed disclosure required under Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and the information provided under the EU General Data Protection Regulation (“GDPR”), see the Data Protection Notice. This Policy and that notice should be read together.
2. Data We Collect
2.1 Data you provide directly
- Account data: full name, work e-mail address, password (stored in irreversibly hashed form by our identity provider), organization/company information, role.
- Contact form data: full name, work e-mail, company name, message content.
- Customer content: report contents, documents, images, and related metadata you upload to the Service. Where such content contains third parties’ personal data, the user is responsible for having obtained that data lawfully (see the Terms of Service).
- Payment and billing data: invoice title, tax office/number, bank (EFT) transfer receipt details. No credit card data is collected or processed.
2.2 Data collected automatically
- Usage and log data: IP address, browser type and version, operating system, access dates/times, pages viewed, error records, session identifiers.
- Cookies and similar technologies: (i) strictly necessary cookies for session management and security (including authentication session cookies) — required for the Service to function and do not require separate consent; (ii) cookie-free, aggregate site statistics that process no personal data (Cloudflare Web Analytics); (iii) analytics cookies loaded only with your explicit consent — Microsoft Clarity (
_clck,_clsk): page usage, click and navigation analysis with heatmaps/session recordings (form inputs and report contents are masked in recordings); data in this scope is transferred to Microsoft Corporation (abroad). You can withdraw your analytics consent at any time via the “Cookie Preferences” link in the site footer. No marketing/advertising cookies are used. - Error and performance monitoring: error tracking tools (e.g. Sentry) may collect technical event records to detect application errors.
3. Purposes of Use
- Providing the Service, creating and managing accounts, authentication (including multi-factor authentication);
- Operating report creation, AI-assisted content generation, compliance checking, and export functions;
- Handling requests and complaints, providing support, responding to contact form submissions;
- Invoicing, payment tracking, and fulfilling statutory bookkeeping obligations;
- Ensuring Service security, preventing misuse, detecting errors, and improving performance;
- Fulfilling legal obligations and responding to requests from competent authorities;
- Sending promotional and informational messages where you have given explicit consent.
AI and your data: customer content is transmitted to the configured model provider solely to perform the requested AI operation; your content is not used by us to train third-party foundation models.
4. Recipients of Data
Personal data is not sold. Data is shared only with the following categories of recipients, strictly limited to the stated purposes:
| Recipient / Category | Purpose | Location |
|---|---|---|
| Supabase (authentication, database, storage) | Account management, data hosting | EU region (configured region) |
| Amazon Web Services (EC2) | Application hosting, PDF generation, real-time collaboration | EU (Frankfurt, eu-central-1) |
| Netlify | Website hosting and delivery | EU/US |
| AI model provider | AI content generation (per-operation only) | Depends on configuration |
| E-mail delivery provider | Transactional e-mails, notifications | EU/US |
| Error monitoring (Sentry) | Error and performance tracking | EU/US |
| Competent public authorities | Legal obligations and official requests | Türkiye |
| Legal, accounting, and audit service providers | Fulfilling legal obligations, protecting rights | Türkiye |
5. International Transfers
Some of the above service providers operate servers abroad. Transfers abroad are carried out in accordance with Article 9 of the KVKK (as amended on March 12, 2024) and the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (July 10, 2024) — where no adequacy decision exists, by executing standard contracts and providing appropriate safeguards. Transfers within the scope of the GDPR are conducted under appropriate safeguard mechanisms such as Standard Contractual Clauses (SCCs). See the Data Protection Notice for details.
6. Retention Periods
- Account and profile data: for the duration of membership; after account closure, in limited form for the limitation periods under applicable law (generally not exceeding 10 years).
- Customer content: for the duration of membership; deleted after the 30-day export window following the end of the agreement (statutory retention obligations reserved).
- Invoices and commercial records: 10 years under the Turkish Commercial Code (Law No. 6102) and Tax Procedure Law (Law No. 213).
- Traffic/log records: the periods prescribed by Law No. 5651 and secondary legislation (minimum 1 year, maximum 2 years).
- Contact form messages: up to 3 years after the request is resolved.
At the end of these periods, data is deleted, destroyed, or anonymized.
7. Data Security
- Encryption in transit (TLS/HTTPS) and access-controlled infrastructure at rest;
- Role-based authorization, multi-factor authentication (TOTP) support;
- Irreversible (hashed) password storage;
- Access and operation logging, error/incident monitoring;
- Data processing agreements and confidentiality commitments with service providers.
No system can guarantee absolute security; however, technical and organizational measures reasonably accepted in the industry are applied and regularly reviewed. If a breach affecting personal data is detected, the notifications required by law are made (to the Turkish Data Protection Board and, where required, to the affected individuals; under the GDPR, within the 72-hour rule).
8. Your Rights
Your rights under Article 11 of the KVKK (information, rectification, erasure, notification of third-party recipients, objection to automated outcomes, compensation, etc.) and under Articles 15-22 of the GDPR (access, rectification, erasure/right to be forgotten, restriction, data portability, objection), together with how to exercise them, are explained in detail in the Data Protection Notice. You may submit requests to info@reportengine.ai.
9. Children’s Data
The Service is not directed at individuals under 18, and no data is knowingly collected from them. If such a situation is detected, the relevant data is deleted immediately.
10. Third-Party Links
The Service may contain links to third-party sites (e.g. map services, social media). The privacy practices of those sites are the responsibility of the respective third parties; we recommend reviewing their privacy policies before visiting.
11. Changes to this Policy
This Policy may be updated from time to time. Material changes are announced via the Platform or by e-mail; the current version is always published on this page. The “Last updated” date indicates when the changes took effect.
12. Contact
For privacy questions and requests: info@reportengine.ai · +90 212 225 61 31 · AK Kurumsal İletişim Turizm Eğitim Danışmanlık A.Ş., Çeliktepe Mah. Kubilay Cad. No:1 İç Kapı No:13, 34413 Kağıthane/Istanbul, Türkiye.