← Tempoly
KVKK Notice

Privacy Policy and KVKK Notice

Last updated: 8 October 2026

As GokTwins Tech, we process, store and protect your personal data within the Tempoly service in accordance with Turkish Personal Data Protection Law No. 6698 (the “Law”) and related legislation. Pursuant to Article 10 of the Law, this text provides information on the data processing activities we carry out within our service. In case of any conflict, the Turkish version prevails.

Definitions and Scope

This text covers the procedures and principles for obtaining, recording, storing, updating, transferring and otherwise processing personal data under the Law, whether by automated or non-automated means.

It concerns users who create an account on Tempoly, visitors to tempoly.app and app.tempoly.app, and all natural persons who contact us.

Data Controller

Under the Law, the data controller is GokTwins Tech, which provides the Tempoly service (Address: [COMPANY ADDRESS], MERSİS No: [MERSİS NO], e-mail: info@tempoly.app).

If the user adds personal data of third parties (for example, the name of a customer or employee) to brand voice inputs or posts, the user is responsible for processing that data lawfully and informing the persons concerned; Tempoly performs only the technical processing needed to provide the service with respect to such data.

Categories of Personal Data Processed

Within our activities, we may process data in the following categories: identity (first name, last name; when you sign in with a social account, the name, profile picture and account ID shared by the provider), contact (e-mail), customer transaction (plan, subscription, credit movements and usage records), transaction security (password hash held by the authentication provider, login records, IP address, security and log records), finance (invoice and payment records; we do not store card numbers), content (brand voice inputs, example posts, the text, dates and engagement counts of past posts you import so we can learn your style, generated posts and the edits you make to them) and, once publishing becomes available, encrypted access tokens for connected social media accounts.

The categories processed vary by purpose and are determined in line with the data minimisation principle. The service is not designed to process special categories of personal data; we ask that you do not include such data in brand voice inputs.

Purposes of Processing

Your personal data is processed for the purposes of creating and managing your account; establishing and performing the subscription agreement; generating content based on your brand voice and moderating it automatically; recording credit spending and refunds; carrying out billing and collection; publishing approved posts to connected channels once available; sending transactional e-mails such as draft and account notifications; responding to support requests; ensuring information security and preventing abuse; improving the service; fulfilling our legal obligations; and responding to requests from competent authorities.

If commercial electronic messages are sent, your separate consent will be obtained.

Methods and Legal Bases of Processing

Your data is collected by automated means through channels such as sign-up, login and brand voice forms, records created while using the service, transaction notifications from the payment provider and e-mail correspondence, on the legal bases set out in Article 5 of the Law: the establishment and performance of a contract, compliance with a legal obligation, the establishment, exercise or protection of a right, legitimate interest and, where required, explicit consent.

Where processing is based on explicit consent, you may withdraw your consent at any time.

Cookies

The service uses strictly necessary (technical) cookies to maintain your session, remember your language preference and ensure security; technical data may be processed for security purposes as part of bot protection. These cookies are required for the service to work and do not share your identity with third parties for marketing purposes. If non-essential cookies are used, your prior consent will be obtained.

You can delete or block cookies in your browser settings; however, if strictly necessary cookies are blocked, you may not be able to sign in to the service.

Transfers of Data

Within the limits set by legislation and only to the extent needed for the relevant service, your personal data may be transferred to the following service providers: Supabase (database, authentication and file storage), Vercel (application hosting), Anthropic (AI text generation and automated moderation), Cloudflare (DNS and bot protection), Zoho Mail (transactional e-mail) and the payment provider acting as merchant of record (payment and billing). Your data may also be transferred to competent public authorities and courts.

Only the brand voice and post content needed for generation, style analysis and moderation is sent to the AI provider. Archive files you import are opened in your browser; only post texts and engagement counts reach our servers, photos and videos are not uploaded. Your personal data and content are not sold.

These providers' servers may be located abroad. Transfers abroad are carried out on the basis of the appropriate safeguards set out in Article 9 of the Law or the other conditions provided for in the legislation.

Data Security and Retention Periods

Your data is protected by technical and administrative measures, including encrypted communication (TLS), workspace-based access authorisation and data isolation, storing passwords only as hashes, encrypted storage of connected account access tokens and signature-verified payment notifications.

Your personal data is kept for as long as your account remains open and for the period required by the relevant legislation or the purpose of processing; at the end of these periods it is deleted, destroyed or anonymised.

Account Deletion and Destruction of Data

You can request the deletion of your account by writing to info@tempoly.app from your registered e-mail address. After identity verification, your account is deleted within 7 business days at the latest.

Deletion destroys account and login information, profile information, brand voice inputs, imported past posts, generated posts and their edits, and connected account access tokens. Invoice and payment records subject to a legal retention obligation are kept for the period required by legislation.

Rights of the Data Subject

Under Article 11 of the Law, you have the right to learn whether your personal data is processed, to request information if it has been processed, to learn the purpose of processing and whether it is used in line with that purpose, to know the third parties to whom it is transferred in Türkiye or abroad, and to request correction if it is incomplete or inaccurate.

You also have the right to request the deletion or destruction of your data under the conditions set out in the Law, to request that these actions be notified to the third parties to whom it was transferred, to object to an outcome against you arising from analysis exclusively by automated systems, and to claim compensation if you suffer damage due to unlawful processing.

How to Apply

You can submit requests regarding your rights in writing to info@tempoly.app from your registered e-mail address, or by other methods that verify your identity.

In accordance with the Law, your applications are concluded free of charge within thirty days at the latest. If your application is rejected or you find the response insufficient, you may lodge a complaint with the Personal Data Protection Board.

Policy Updates

This text may be updated when necessary; the current version takes effect as soon as it is published on our website.

You can always access the latest version of this text on this page.