Apilex

PRIVACY POLICY

Privacy Policy

Last updated: 16.07.2026 · Version: 3.0

1. Introduction, Purpose and Scope

Apilex (the "Company", "we") is a technology company that provides artificial intelligence-assisted legal research, case-law analysis and document generation services for legal professionals. By this Privacy Policy (the "Policy"), we explain, pursuant to the Personal Data Protection Law No. 6698 (the "KVKK"), how and on what grounds we collect, store, use, share and otherwise process your personal data through our website at www.apilex.ai and our Apilex platform (collectively, our "Services").

If you are established in the European Economic Area (the "EEA") and your personal data are processed under the General Data Protection Regulation (the "GDPR"), please review the GDPR Privacy Notice instead of this Policy.

If you have questions about the processing of your personal data as described in this Policy, please contact us using the contact details set out in the section "Identity of the Data Controller and Contact Details" below.

2. Identity of the Data Controller and Contact Details

Your personal data are processed, in the capacity of data controller under the KVKK, by the company whose trade name is set out below ("Apilex", the "Company", "we"):

  • Title: FİTTY TEKNOLOJİ ANONİM ŞİRKETİ
  • Address: Çifte Havuzlar Mah. Eski Londra Asfaltı Cad. Kuluçka Mrk. A1 Blok No: 151/1C İç Kapı No: B34 Esenler/İstanbul
  • Email: privacy@apilex.ai
  • KEP: fittyteknoloji@hs03.kep.tr

3. Relationship of this Policy to Other Privacy Notices

This Policy is an overarching document that sets out the general framework and fundamental principles governing Apilex's personal data processing activities. Separate privacy notices are published pursuant to Article 10 of the KVKK for each process in which we process personal data, including website visitors, contact form / demo request / support request processes, career applications, and processes relating to our employees, employee candidates, interns and supplier employees; such privacy notices shall be interpreted together with this Policy and in a manner consistent with the fundamental principles set out herein. In the event of any conflict between a privacy notice and this Policy, the privacy notice specific to the relevant process shall prevail.

Personal data processing activities relating to the Company's employees, employee candidates, interns and supplier employees do not fall within the data categories, processing purposes and retention periods set out in Article 4 and the subsequent articles of this Policy; the rules set out in the separate privacy notices referred to above shall apply to such persons.

For detailed information on the use of cookies, the separately published Cookie Policy shall apply.

4. Categories of Personal Data Collected

Your personal data are collected through our website, our platform interface, cookies and similar technologies, support and contact forms and email channels, by wholly or partly automated means, or by non-automated means provided that they form part of a data recording system.

  • Identity Information: First name, last name; where billing is required, Turkish ID number or tax identification number.
  • Contact Information: Email address, mobile phone number.
  • Customer Commercial Transaction Information: Subscription and package information, invoice information, request information, free-use code, call-centre records.
  • Request/Complaint Information: The content of a demo request, contact-form message or support request, together with the date and time of the request.
  • User Account Information: Your language preference and account settings.
  • Content and Legal Data: Documents you upload to the Platform and personal data contained in those documents; summaries, tables and drafts you create; prompts you enter into the Assistant; your search history; your projects.
  • Usage and Technical Data: Device identifier, IP address, browser and operating-system information, browsing history, approximate location information that may be associated with the IP address. Collected through cookies and similar technologies during your use of our Services.

The personal data categories listed above, other than the Content and Legal Data category, are collected only to the extent limited to and necessary for the fulfilment of the stated purposes; data that are unrelated to, or excessive in relation to, the purpose are not collected. Content and Legal Data, by contrast, are handled under a zero data retention principle in order to support you, as the data controller in respect of such data, in fulfilling your own obligations.

Roles of the Parties: Data Controller and Data Processor

Apilex is the data controller in respect of the Identity, Contact, Customer Transaction, Request/Complaint, User Account and Usage/Technical Data categories.

Content and Legal Data are different. These are case files, contracts and other documents that you upload to the Platform, and personal data of third parties contained in those documents (your client, the opposing party, a witness, etc.). In respect of such data, you are the data controller; Apilex is merely the data processor acting on your instructions. Accordingly, you are responsible for ensuring that data relating to third parties in the documents you upload have been obtained lawfully, that such persons are informed where required, and that the processing is based on an appropriate legal ground.

The Platform operates under a zero data retention policy. In accordance with this principle, and pursuant to binding service agreements with technology partners involved in its technical processes, user data, commands and queries sent to the artificial intelligence model, and the responses generated by the model are not stored on the server in any way. In compliance with KVKK and GDPR obligations, data are completely deleted as soon as the processing call on the Platform ends. They are not used to train or develop any model currently available, or to be made available in the future, on the Platform. Your content is stored in encrypted form and may be accessed only by our authorized personnel, for limited purposes such as your support request or technical troubleshooting.

Artificial intelligence-assisted outputs generated within the scope of our Services (petition drafts, contract drafts, summaries, analyses, etc.) are merely drafts and reference materials; they do not constitute legal advice and do not amount to a decision producing legal effects concerning you or third parties that is based solely on automated processing. It is your responsibility to verify the accuracy and suitability of such outputs for the specific matter and to consult a legal professional before using them.

No profiling is carried out in relation to your user behaviour within the scope of our Services.

Processing of Special Categories of Personal Data

Legal documents you upload to the Platform (case files, contracts, etc.) may, exceptionally, contain special categories of personal data such as health data, data relating to criminal convictions and security measures, or trade-union membership. In respect of such data as well, you are the data controller; Apilex processes such data solely on your instructions, in the capacity of data processor. It is your responsibility to ensure that such data are processed lawfully.

5. Purposes of Processing Personal Data and Legal Bases

  • Creation of your account, establishment and performance of our contractual relationship, and communication with you: based on the legal ground that processing is directly related to the establishment or performance of a contract.
  • Conduct of sales, after-sales support, production and operations, and customer relationship management processes: based on the legal ground that processing is directly related to the establishment or performance of a contract.
  • Provision, development and personalization of our Services: based on the legal ground that processing is directly related to the establishment or performance of a contract.
  • Contacting you in order to evaluate your demo request: based on the legal ground of taking measures necessary prior to the establishment of a contract.
  • Evaluating the message you submit via the contact form and responding to you: based on the legal ground of our legitimate interests, provided that this does not harm your fundamental rights and freedoms.
  • Handling your support request: based on the legal ground that processing is directly related to the performance of a contract if you are a member, and on our legitimate interests if you are not a member.
  • Your contact information may be processed, based on the legal ground of our legitimate interests provided that this does not harm your fundamental rights and freedoms, for the purpose of remaining in communication with you in relation to our products and services and conducting marketing analysis. However, in order to send you commercial electronic messages (promotions, campaigns, advertisements, etc. by email/SMS), we obtain your explicit consent separately pursuant to Law No. 6563 on the Regulation of Electronic Commerce and the Message Management System (İYS); you may withdraw such consent at any time.
  • Ensuring the security of our Services, detecting misuse and developing our Services: based on the legal ground of our legitimate interests.
  • Fulfilment of our legal obligations and provision of information to competent authorities: based on the legal ground that processing is expressly provided for by law.

Where we rely on our legitimate interests, we apply a two-stage balancing test that first assesses whether such interest genuinely exists and then whether that interest does not prejudice your fundamental rights and freedoms.

6. Transfer of Personal Data

Your personal data may be transferred to the following categories of recipients:

Domestically:

  • Our payment institution: for the purpose of carrying out payment and collection transactions.
  • Our web analytics and advertising service provider: for the purpose of analysing the use of our website and our Services and conducting marketing activities.
  • Competent public institutions and organizations: for the purpose of fulfilling our legal obligations and providing information to competent authorities.

Abroad:

  • Our hosting service provider: for the purpose of hosting our Services and storing your data securely.
  • Our artificial intelligence-assisted analysis and content generation service providers: for the purpose of providing the artificial intelligence-assisted research, analysis and document generation functions you request through the Platform.
  • Our payment institution: for the purpose of carrying out payment and collection transactions.
  • Our web analytics and advertising service provider: for the purpose of analysing the use of our website and our Services and conducting marketing activities.
  • Competent public institutions and organizations: for the purpose of fulfilling our legal obligations.

Transfers we make to countries for which no adequacy decision has been issued are carried out within the framework of the appropriate safeguards provided for under Article 9 of the KVKK.

7. Retention Period and Destruction of Personal Data

Your personal data are retained for the period prescribed by the applicable legislation or for as long as necessary for the purposes for which they are processed. Accordingly:

  • Your records relating to membership, sales and order processes: retained for 10 years following the termination of the contractual relationship.
  • Your data processed in the context of marketing activities: retained for 5 years from the end of the relevant activity.
  • Your transaction records within the scope of demo requests, contact forms and support requests: retained for 1 year from the conclusion of your request.
  • Your Content and Legal Data (documents you upload, your prompts, your search history, your projects): deleted immediately and permanently when you delete your account; if you do not delete your account, logs relating to such data are retained for 1 year.
  • Your Usage and Technical Data: retained for 1 year.
  • Your log records kept for information-security purposes: retained for 5 years.

At the end of the retention period, your personal data are deleted ex officio or upon your request, in accordance with the procedures set out in our Personal Data Retention and Destruction Policy; they are destroyed by secure deletion methods in electronic environments and in an irreversible manner in physical environments. In certain cases, data may continue to be retained for statistical purposes after being rendered anonymous by techniques such as masking or aggregation.

8. Cookies

Within the scope of our Services, cookies and similar technologies are used to ensure the operation of the Site, analyse usage and improve your experience. For cookies other than strictly necessary cookies (such as analytics, functionality and advertising/targeting cookies), your explicit consent is obtained; you may withdraw or change such consent at any time via the cookie preference panel. Detailed information on cookie types, purposes of use, retention periods and how you can manage your preferences is available in the Cookie Policy.

9. Measures Taken for the Security of Your Personal Data

In order to prevent the unlawful processing of your personal data and unauthorized access to such data, we take the necessary technical measures, including an access-authorization matrix and controls, regular maintenance and review of log records, encryption, firewalls, regular penetration tests and vulnerability scans, data-loss prevention and data-masking applications, backup, and intrusion detection and prevention systems; and the necessary administrative measures, including keeping the personal data processing inventory up to date, employee confidentiality undertakings, regular awareness training, and audits of suppliers/data processors. Our information-security processes are conducted in a manner consistent with international standards (ISO 27001).

In the event of a data breach, we notify the Personal Data Protection Board and the affected data subjects without delay and in any event within 72 hours.

10. Your Control Over Your Personal Data

You may view and manage your account information and privacy preferences via the Settings page. If you wish to delete your account, you may submit a request directly by following the steps Settings > Profile > Delete Account.

11. Data Subject Rights and Application Procedure

Pursuant to Article 11 of the KVKK, as a Data Subject you have the following rights:

  • To learn whether your personal data are being processed,
  • To request information if your personal data have been processed,
  • To learn the purpose of processing of personal data and whether they are used in accordance with their purpose,
  • To know the third parties to whom personal data are transferred domestically or abroad,
  • To request the rectification of personal data if they have been processed incompletely or inaccurately,
  • To request the erasure or destruction of personal data within the framework of the conditions provided for by the applicable legislation,
  • To request that the operations carried out pursuant to the two preceding items be notified to third parties to whom the data have been transferred,
  • To object to the occurrence of a result against you by means of the analysis of processed data exclusively through automated systems,
  • To request compensation for damage if you suffer damage due to the unlawful processing of personal data.

To exercise these rights, you may submit your request to us together with documents verifying your identity. For this purpose, you may apply in writing to the address set out in Article 2, to our KEP address, by secure electronic signature or mobile signature, or from the email address registered in our system to privacy@apilex.ai. Your application will be concluded free of charge as soon as possible and in any event within thirty days, depending on its nature; if the operation requires an additional cost, the fee set out in the tariff determined by the Board may be charged. If your request is rejected, found insufficient, or not answered within the prescribed period, you may lodge a complaint with the Personal Data Protection Board within thirty days from the date you learn of the response and in any event within sixty days from the date of the application.

12. Updates and Entry into Force

We may update this Policy from time to time. The current version is published on this page. In the event of material changes, we will inform you through appropriate communication channels. This Policy enters into force as of the date of its publication.