Proje vitrini hazırlanıyorPreparing project showcaseПодготавливаем витрину проекта
Skip to main content
Effective Date: 21 April 2026

Data Protection Notice

Notice under the Turkish Personal Data Protection Law (KVKK) No. 6698 and the EU General Data Protection Regulation (GDPR)

1. Data Controller

Pursuant to the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR"), your personal data is processed by Rocketly (the "Company", "Rocketly", "we") as data controller, in the scope described below. For EU residents, Rocketly acts both as data controller (for account data) and as data processor (for your CRM content).

Contact details

Legal name: Rocketly
Address: Istanbul, Türkiye
Email: [email protected]
Web: https://gorocketly.com
VERBİS registration: [registration in progress]

2. Personal Data We Process

The following categories of personal data are processed in the scope of our services:

Data categoryData processed
IdentityFirst name, last name, username
ContactEmail address, phone number, address details
Account & accessPassword (hashed — bcrypt), role information, session records, two-factor authentication data
Customer transactionRecords created on the platform (customers, opportunities, quotes, appointments, tasks), analysis results, usage statistics
Transaction securityIP address, browser and device information, log records, approximate location data, cookie data
FinancialInvoicing details (name, address, tax number). Card details are not stored — they are processed by the payment provider Polar.sh in a PCI-DSS compliant manner.
Voice & mediaAudio recordings uploaded for call analysis (optional, uploaded by the user), uploaded files
Communication contentMessages delivered via integrated channels (WhatsApp Business, Instagram DM, Email IMAP, Telegram, SMS) — stored per your explicit configuration
MarketingMarketing preferences obtained with explicit consent, newsletter subscription details

3. Purposes and Legal Bases of Processing

Your personal data is processed for the purposes below, relying on the legal bases set out in Articles 5 and 6 of the KVKK:

PurposeLegal basis
Account creation, user authenticationEstablishment and performance of a contract
Provision of the CRM service, data storage and processingPerformance of a contract, legitimate interest
Invoicing and accounting operationsRequired by law (Turkish Tax Procedure Law, Turkish Commercial Code)
Security, prevention of misuse, fraud detectionLegitimate interest, legal obligation
Customer support and technical support requestsPerformance of a contract, legitimate interest
Service improvement and product development (anonymous analytics)Legitimate interest
Marketing communication, newsletter deliveryExplicit consent
AI-assisted analysis (call analysis, lead scoring, AI agent)Explicit consent (can be withdrawn from settings)
Legal compliance, court and public authority requestsLegal obligation

4. Methods of Collection

Your personal data is collected through the following channels:

Website and mobile application: Registration form, data created during use, automatically collected technical data
API and integrations: Third-party services you have authorised (Google Calendar, Gmail, WhatsApp Business and similar)
Communication channels: Email, live support, contact form
Cookies and similar technologies: For usage analysis and session management
Webhook and form integrations: Lead data arriving from our customers' own websites

The legal bases for this collection are the conclusion and performance of a contract (subscription), compliance with a legal obligation, and legitimate interest. We do not use analytics or marketing cookies (Google Analytics/Tag Manager has been removed), so no cookie consent notice is shown.

5. Transfer of Personal Data

Your personal data may be transferred to our service providers, business partners, authorized public institutions, and private entities within the framework of conditions and purposes set forth in Articles 8 and 9 of the KVKK and Articles 44-49 of the GDPR. All transfers to third countries occur only under Standard Contractual Clauses (SCC) or equivalent safeguards and, where required, your explicit consent.

5.1 Domestic Transfers

Pursuant to Article 8 of the KVKK, your personal data may be transferred to the following parties in order to achieve the purposes set out in this notice:

• Authorized public institutions and organizations (court order, prosecutor's request and similar)
• Financial advisers and independent auditors (for tax and accounting obligations)
• Legal advisers (in the event of a legal dispute)

5.2 International Transfers

In order to deliver our services, data is transferred to the international service providers below within the framework of Article 9 of the KVKK and your explicit consent. Your production data (system of record) is hosted in EU data centres in Germany (Frankfurt), under EU data protection and Schrems II safeguards.

Service providerCountryPurpose
DigitalOceanGermany (Frankfurt)Data hosting (under EU data protection)
AI service providersVaries by provider and selected configurationRunning the AI features you enable
SentryUSA / EUError tracking and performance monitoring
Polar.shUSAPayment and invoicing
Google (OAuth, FCM)EU / USAAuthentication, push notifications

Transfers outside the EU are carried out under Standard Contractual Clauses (SCC) approved by the Turkish Data Protection Board or on the basis of explicit consent. The large majority of your data is hosted within the borders of the EU (Germany / Frankfurt).

6. Retention Periods

Your personal data is retained for the periods below, in line with the purpose of processing and with our legal obligations:

Data categoryRetention period
Account dataFor as long as the account is active + 1 year (anonymised within 30 days of a deletion request)
Invoicing and accounting10 years (required by Article 253 of the Turkish Tax Procedure Law)
Transaction security logs90 days (cleared automatically)
Cookie dataSession, 90 days or 2 years depending on the cookie type (see the Cookie Policy)
Marketing communication recordsUntil explicit consent is withdrawn
Support and communication records3 years (Turkish Code of Obligations limitation period)
Deleted CRM records90 days (soft delete) + anonymisation

7. Your Rights under KVKK and GDPR

Pursuant to Article 11 of the KVKK and Articles 15-22 of the GDPR, you have the following rights:

Right of Access: Request a copy of your personal data we hold.
Right to Rectification: Correct inaccurate or incomplete data.
Right to Erasure ("right to be forgotten"): Request deletion under conditions set forth in Article 7 KVKK and Article 17 GDPR.
Right to Restriction: Restrict processing under specific conditions.
Right to Data Portability: Export your data in a machine-readable format.
Right to Object: Object to processing, including profiling and automated decision-making.
Right to be Informed: Learn whether your data is being processed and for what purposes.
Right to know third parties: Learn to whom your data is transferred domestically or internationally.
Right to Withdraw Consent: Withdraw consent at any time where consent is the legal basis.
Right to lodge a complaint: With the Turkish Data Protection Authority (KVKK) or your local EU supervisory authority.

8. How to Exercise Your Rights

To exercise the rights listed above, you may reach us through one of the following channels, in line with the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller:

Email: [email protected] (subject: "KVKK / GDPR Data Request") — for EU requests you may also write to [email protected]
From inside the application: Settings → Privacy → KVKK Request
By notary or registered mail with return receipt: the address given above
Data Protection Officer: [email protected]

Your application must state your request clearly and comprehensibly, together with documents establishing your identity. We will respond to your request free of charge within 30 days at the latest. If the operation additionally requires a cost, the fee in the tariff set by the Board may be charged. There is no fee unless your request is manifestly unfounded or excessive.

9. Data Security Measures

Rocketly implements the technical and organisational measures below to prevent unlawful processing of personal data, prevent unauthorised access, and ensure the safe retention of data:

Technical Measures

• Encrypted transmission with TLS 1.3 (HTTPS), HSTS enabled; AES-256 encryption at rest
• Password hashing with bcrypt
• Two-Factor Authentication (2FA) support
• Firewall, DDoS protection, rate limiting
• Regular security patches and software updates
• Daily encrypted database backups (30-day rolling retention, offline cold-storage copies) and a disaster recovery plan
• Role-based access control (RBAC)
• Security logging and anomaly detection — every data access is logged with user identity, timestamp and action; 90-day retention
• Data residency: all personal data at rest is stored in EU data centres (Germany / Frankfurt); certain sub-processors may process specific data abroad (see Section 5)

Organisational Measures

• Keeping a personal data inventory
• KVKK training and confidentiality agreements for employees
• Regular review of the data processing inventory
• Data processing agreements with sub-processors
• A data breach detection and notification procedure

10. Data Breach Notification Process

If your personal data is obtained by others through unlawful means, we will notify the Turkish Personal Data Protection Authority and the affected data subjects as soon as possible (within 72 hours), in line with Article 33 of the GDPR. The notification will state the nature of the breach, the categories of data and the number of people affected, its likely consequences, the measures taken, and our recommendations.

11. Cookie Policy

Our website and application use cookies. Cookie types: strictly necessary (session management) and functional (preferences). We do not use analytics or marketing cookies (Google Analytics/Tag Manager has been removed; no consent notice is shown). You can manage cookie settings from your browser. For details: Cookie Policy.

12. Children's Data

Rocketly services are not directed at persons under the age of 18. If you become aware that you have unknowingly transferred the data of a person under 18 to us, notify us immediately at [email protected]; the data concerned will be deleted.

13. Changes to this Notice

This Notice may be updated from time to time in line with changes in legislation or updates to our services. Material changes will be announced on our website and through your registered email address. We recommend that you review this Notice regularly.

14. Right to Complain

If you are not satisfied with our response to your application, or if your application is not answered within 30 days, you have the right to lodge a complaint with the Turkish Personal Data Protection Board. Residents of the EU may also lodge a complaint with their local supervisory authority.

Turkish Personal Data Protection Authority:
Address: Nasuh Akar Mahallesi, 1407. Sokak No: 4, 06520 Balgat, Çankaya / Ankara, Türkiye
Web: www.kvkk.gov.tr

Start using Rocketly today.


Discover the CRM built for your industry.