Effective date: 15 August 2026
Company: Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş.
This Privacy Policy explains how Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş. ("Aspect", "we", "us" or "our") collects, uses, discloses, stores and protects personal data in connection with aspect.contact, our applications, digital profiles, lead capture and enrichment tools, integrations, AI-assisted features, enterprise services, professional services and related offerings (collectively, the "Services"). This Policy applies to account holders, customer administrators and personnel, website visitors, prospective customers, business contacts, and individuals whose information is processed through the Services, including contacts, leads, event attendees and other individuals whose information a customer submits, scans, synchronizes, enriches or researches using Aspect.
Aspect acts as a data controller when we determine why and how personal data is processed, including for account administration, our website, billing, security, support, business communications and our own legal obligations. When a customer uses the Services to upload, scan, synchronize, enrich, research, organize, analyze or otherwise process personal data about its contacts, leads, event attendees, employees or other individuals, the customer generally determines the purposes of that processing. In those circumstances, the customer acts as controller or business, and Aspect acts as processor, service provider or contractor, as those terms are used under applicable data protection laws. Our Data Protection Addendum governs that processing. Some processing may involve different roles depending on the feature and applicable law. Where required, we will describe the relevant role in the applicable contract, product notice or additional privacy notice.
| Category | Examples |
|---|---|
| Account and identity data | Name, username, account ID, authentication data, preferred language and similar account information. |
| Contact and professional data | Email address, phone number, company, job title, department, business address, professional profile links and similar business contact information. |
| Profile and content data | Profile photo, biography, links, digital business card fields, notes, tags, custom fields and other content submitted to the Services. |
| Lead and event data | Business card or badge information, event details, meeting context, notes, lead status, relationship information and other customer-provided interaction data. |
| Enrichment and research data | Business and professional information obtained from customer-connected sources, third-party data providers, public websites and other lawfully available sources, together with derived summaries, classifications and research outputs. |
| Integration data | Data synchronized with customer-selected CRM, calendar, directory, identity or workflow systems, and technical credentials or tokens required to maintain those integrations. |
| AI input and output data | Prompts, text, structured fields, extracted information, summaries and other content processed through AI-assisted features. |
| Billing and transaction data | Subscription, invoice, payment status, tax and transaction information. Payment card data may be handled directly by payment processors rather than stored by Aspect. |
| Support and communications data | Support requests, emails, feedback, call or meeting notes, and other communications with us. |
| Usage, device and security data | IP address, browser and device information, timestamps, authentication events, audit events, logs, diagnostic data, cookie or similar technology data and usage information. |
Directly from you, including when you create an account, complete a profile, contact us, request a demo, purchase Services or use product features. From your organization, including administrators and other authorized users who provision or manage your account. From customers and users of the Services, including when they scan a business card or event badge, import a contact, add notes, connect a CRM or request enrichment or research. From customer-connected third-party systems and integrations. From public or professionally available sources, such as company websites, public professional pages, business directories and other sources that may lawfully be used for the requested business research or enrichment. From service providers and data providers that support enrichment, hosting, security, analytics, communications, AI processing and other Services. Automatically from your device or browser when you use our website or Services.
| Purpose | What this includes | Typical legal basis |
|---|---|---|
| Provide and operate the Services | Create accounts, provide profiles, lead capture, enrichment, research, integrations, workflows and support. | Performance of a contract; legitimate interests; customer instructions where we act as processor. |
| Secure the Services | Authentication, fraud prevention, abuse detection, logging, incident response and service integrity. | Legitimate interests; legal obligations. |
| Improve and maintain the Services | Diagnostics, quality assurance, product analytics and development using data that is minimized or aggregated where practicable. | Legitimate interests; consent where required for cookies or similar technologies. |
| Billing and administration | Subscriptions, invoicing, accounting, tax, contract administration and collections. | Performance of a contract; legal obligations; establishment, exercise or defense of legal claims. |
| Communicate with you | Service notices, support, security communications, product information and relationship management. | Performance of a contract; legitimate interests; consent where required. |
| Marketing | Send marketing communications and manage preferences where legally permitted. | Consent or legitimate interests where permitted by applicable law. |
| AI-assisted processing | Extract, classify, summarize, research, enrich and generate responses or recommendations requested through the Services. | Performance of a contract; legitimate interests; customer instructions where we act as processor. |
| Legal and compliance | Respond to lawful requests, enforce agreements, protect rights and comply with legal obligations. | Legal obligations; legitimate interests; establishment, exercise or defense of legal claims. |
Aspect is designed to help business users organize and understand business relationships. Customers may provide contact information directly, scan business cards or event badges, connect CRM systems, or request research and enrichment about business contacts. Where Aspect processes this data on behalf of a customer, the customer is responsible for having an appropriate legal basis, providing required notices, honoring applicable marketing and communications rules, and ensuring its instructions to Aspect are lawful. Aspect processes the data only as permitted by the customer agreement, our Data Protection Addendum and applicable law. Where we obtain personal data indirectly while acting as controller, we provide transparency and other notices when required by applicable law, subject to any lawful exemptions.
Some Services use third-party AI model providers, including OpenAI, Anthropic Claude and Google Gemini or related Google Cloud AI services. Depending on the feature, we may send limited personal data, customer content or instructions to one or more of these providers to perform the requested processing. We seek to limit data sent to AI providers to what is reasonably necessary for the requested feature. We use business or API services and contractual protections appropriate to the relevant processing where available. Aspect does not intentionally enable optional settings that permit Customer Data to be used to train generalized or foundation models without the customer's prior authorization. AI-generated content can be incomplete or inaccurate. Users should review outputs before relying on them for material business decisions. Customers must not use the Services to make unlawful high-impact decisions about individuals or to process sensitive personal data unless the processing is lawful and expressly supported by the relevant Service.
We may disclose personal data to the following categories of recipients, only as reasonably necessary for the relevant purpose: Cloud infrastructure and hosting providers, including Amazon Web Services (AWS). AI processing providers, including OpenAI, Anthropic and Google. Security, monitoring, communications, support, payment, accounting and professional service providers. Customer-selected integrations, such as CRM, calendar, directory or workflow services, when a user or customer directs the transfer. Affiliates, successors or transaction counterparties in connection with a merger, financing, reorganization, acquisition or sale of assets, subject to appropriate confidentiality protections. Courts, regulators, law enforcement or other authorities when disclosure is required by law or reasonably necessary to protect rights, safety or security. Aspect does not sell Customer Data. Aspect does not use Customer Data for cross-context behavioral advertising or targeted advertising unrelated to providing the Services.
Aspect is established in Türkiye and uses service providers that may process personal data in other countries. This means personal data may be transferred internationally, including to countries outside Türkiye, the EEA, the United Kingdom or Switzerland. Where applicable law requires a transfer mechanism, we use legally recognized safeguards such as adequacy decisions, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or IDTA, contractual safeguards recognized under Swiss law, and the standard contracts or other safeguards available under Article 9 of the Turkish Personal Data Protection Law No. 6698 (KVKK).
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, comply with law, resolve disputes, maintain security and enforce agreements. Customer Data is generally retained for the duration of the customer relationship or until the customer deletes it. Following termination or a valid deletion request, data is removed from active systems within the periods described in our Data Retention & Deletion Policy, subject to legal holds, statutory obligations and backup rotation. Deletion from active systems does not always remove data immediately from encrypted or access-restricted backups. Backup copies are deleted or overwritten according to our backup lifecycle and are not restored to production except for legitimate disaster recovery or security purposes.
We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration or disclosure. Measures include access controls, encryption in transit and at rest where appropriate, logging and monitoring, backup and recovery measures, secure development practices, vulnerability management and restricted administrative access. No system can be guaranteed to be completely secure.
Depending on where you live and which law applies, you may have rights to access, obtain a copy of, correct, delete or restrict personal data; object to certain processing; withdraw consent; request portability; opt out of certain sales, sharing, targeted advertising or profiling; and lodge a complaint with a competent supervisory authority. Residents of Türkiye may exercise the rights set out in Article 11 of the KVKK. Individuals in the EEA and UK may exercise rights available under the GDPR or UK GDPR. Residents of California and other US states with comprehensive privacy laws may exercise the rights available under those laws, subject to applicable scope and exceptions. To submit a privacy request, contact info@aspect.contact or use another legally recognized method listed in the applicable local privacy notice. We may need to verify your identity or authority before completing a request. If Aspect processes your personal data solely on behalf of one of our customers, we may direct your request to that customer or assist the customer in responding.
Our website and Services may use cookies and similar technologies that are necessary for authentication, security, preferences, performance and analytics. Where required by law, non-essential cookies are used only after obtaining the required consent, and available controls can be used to change your preferences.
The Services are intended for business and professional use and are not directed to children. Individuals who are not legally able to enter into the applicable agreement should not create an account without authorization from a parent, guardian or other legally authorized person where permitted by law.
We may update this Policy from time to time. We will publish the updated version and revise the effective date. If a change materially affects how we process personal data, we will provide additional notice where required by law.
Privacy questions and requests may be sent to info@aspect.contact, aspectbilisim@hs01.kep.tr, or to Acarlar Mah. Derbent Sk. Acarkent A050 No: 23/1 Beykoz / Istanbul, Türkiye. You may also call 0 (850) 380 07 10.