This disclosure statement is prepared by Taz Technology ("Company", "we") in line with our obligations under the Turkish Law on the Protection of Personal Data No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR). It informs you, as data subjects, about the processing of your personal data within our website at https://taztech.tr and the services we provide.
TazMemory.AI is a multi-tenant enterprise AI operating system. We therefore take appropriate technical and organisational measures for both individual users' and our enterprise customers' (tenants') personal data. Enterprise customers act as data controllers (KVKK) / controllers (GDPR) for the data they process within their own tenant spaces; Taz Technology acts as a data processor for that data.
1. Data Controller and Contact
The controller responsible for the protection and processing of your personal data is:
Taz Technology Yeniköy Merkez Mah. Vatan Cad. Teknopark Sitesi No: 83/B46 Başiskele / Kocaeli, Türkiye Data Protection Contact Point: Ahmet Demirel Email: ademirel@taztechnology.com
For data subjects within the European Union, communication under the GDPR is handled through the same email address. If a Data Protection Officer (DPO) is appointed, their details will be updated in this statement.
2. Categories of Personal Data Processed
The following categories of personal data may be processed during your use of our services:
- chevron_rightIdentity and contact data (name, surname, email, phone, company, title, address).
- chevron_rightAccount data (username, password, session and login records).
- chevron_rightTransaction and usage data (API calls, chat/agent interactions, session logs, IP address, browser/device info).
- chevron_rightContent data (documents you upload, knowledge base content, agent outputs and feedback).
- chevron_rightFinancial data (minimal billing information passed to the payment processor; card numbers or bank accounts are not stored directly).
- chevron_rightSpecial categories of personal data (health, race, political opinion, etc.) are not processed unless your explicit consent is obtained or as required by law.
3. Purposes of Processing
Your personal data may be processed for the following purposes:
- chevron_rightAccount creation, authentication and access management.
- chevron_rightProviding, maintaining and improving the services (including agent training, RAG search, model routing).
- chevron_rightCustomer support and responding to your requests and notifications.
- chevron_rightEnsuring security, preventing abuse and fraud, and keeping audit logs.
- chevron_rightFulfilling legal obligations (KVKK, tax, accounting).
- chevron_rightMarketing and promotional communication where you provide explicit consent.
4. Legal Bases
Your personal data is processed on one of the lawful bases under Articles 5 and 6 of the KVKK and Article 6 of the GDPR:
- chevron_rightNecessity for the performance of a contract (KVKK 5/2-b, GDPR 6/1-b).
- chevron_rightCompliance with a legal obligation (KVKK 5/2-ç, GDPR 6/1-c).
- chevron_rightProcessing in line with our legitimate interests (KVKK 5/2-f, GDPR 6/1-f).
- chevron_rightExplicit consent (KVKK 5/1, GDPR 6/1-a).
- chevron_rightNecessity for the establishment, exercise or protection of a right (KVKK 5/2-e).
- chevron_rightProtection of vital interests (KVKK 5/2-d, GDPR 6/1-d).
Special categories of personal data are processed only with explicit consent or under statutory exceptions, in line with Article 6 of the KVKK and Article 9 of the GDPR.
5. Transfer of Personal Data and Cross-Border Transfer
Your personal data may be shared with third-party service providers necessary to deliver the service (hosting, cloud, payment processor, analytics, email and messaging channels) in accordance with Articles 8 and 9 of the KVKK and Articles 44 ff. of the GDPR. These parties process data only on our instructions and under confidentiality obligations.
For transfers outside Türkiye/the EEA, adequate protection or appropriate safeguards (Standard Contractual Clauses, binding corporate rules, etc.) are relied upon as required by KVKK Article 9 and GDPR Chapter V. Enterprise customers may keep their data geographically fixed via the on-premises / Türkiye data center option.
6. Retention and Erasure of Personal Data
Personal data is retained for the period necessary for the purpose of processing and as required by applicable law (KVKK 5/2-ğ, GDPR 5/1-e). At the end of this period, or when the processing purpose ceases, data is deleted, destroyed or anonymised in line with Article 7 of the KVKK and Article 17 of the GDPR.
Enterprise tenants' retention and erasure policies run through the platform's tenant-level retention settings; each tenant's data is logically isolated from others.
7. Data Subject Rights
Under Article 11 of the KVKK and Articles 15-22 of the GDPR, you have the following rights:
- chevron_rightTo be informed whether your personal data is being processed and to request information if it is (KVKK 11/1-a,b; GDPR 15).
- chevron_rightTo learn the purpose of processing and whether it is used in line with that purpose.
- chevron_rightTo request rectification of incomplete or inaccurate data (KVKK 11/1-e; GDPR 16).
- chevron_rightTo request erasure or destruction under certain conditions (KVKK 7; GDPR 17).
- chevron_rightTo request restriction of processing (GDPR 18).
- chevron_rightTo object to decisions based solely on automated processing (KVKK 11/1-g; GDPR 22).
- chevron_rightTo know the third parties to whom data is transferred and to request data portability (GDPR 20).
- chevron_rightTo withdraw your consent at any time (GDPR 7/3).
- chevron_rightTo demand compensation for damage suffered due to unlawful processing (KVKK 11/1-h).
To exercise these rights, you may submit a written application with identity-verifying documents to ademirel@taztechnology.com. Applications are concluded free of charge within 30 days at the latest under KVKK Article 13 (GDPR requests are answered within one month).
8. Security Measures and Breach Notification
Access controls (RBAC), encryption (in transit and at rest), JWT-based authentication, audit logs, rate limiting and regular security testing are applied to protect personal data.
In the event of a personal data breach, notifications are made to the competent supervisory authorities and, where required, to the affected data subjects, within the periods set by the KVKK and GDPR Articles 33/34.
10. Changes
This disclosure statement may be updated in line with legislative changes or the evolution of our services. Material changes are announced by posting on our website. We recommend reviewing it periodically.
Contact and application
For any requests regarding your personal data, you may submit a written application to ademirel@taztechnology.com.