Privacy Policy

Effective date: 15 August 2026

Company: Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş.

This Privacy Policy explains how Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş. ("Aspect", "we", "us" or "our") collects, uses, discloses, stores and protects personal data in connection with aspect.contact, our applications, digital profiles, lead capture and enrichment tools, integrations, AI-assisted features, enterprise services, professional services and related offerings (collectively, the "Services"). This Policy applies to account holders, customer administrators and personnel, website visitors, prospective customers, business contacts, and individuals whose information is processed through the Services, including contacts, leads, event attendees and other individuals whose information a customer submits, scans, synchronizes, enriches or researches using Aspect.

1. Who we are and how to contact us

2. Our role under data protection law

Aspect acts as a data controller when we determine why and how personal data is processed, including for account administration, our website, billing, security, support, business communications and our own legal obligations. When a customer uses the Services to upload, scan, synchronize, enrich, research, organize, analyze or otherwise process personal data about its contacts, leads, event attendees, employees or other individuals, the customer generally determines the purposes of that processing. In those circumstances, the customer acts as controller or business, and Aspect acts as processor, service provider or contractor, as those terms are used under applicable data protection laws. Our Data Protection Addendum governs that processing. Some processing may involve different roles depending on the feature and applicable law. Where required, we will describe the relevant role in the applicable contract, product notice or additional privacy notice.

3. Personal data we process

CategoryExamples
Account and identity dataName, username, account ID, authentication data, preferred language and similar account information.
Contact and professional dataEmail address, phone number, company, job title, department, business address, professional profile links and similar business contact information.
Profile and content dataProfile photo, biography, links, digital business card fields, notes, tags, custom fields and other content submitted to the Services.
Lead and event dataBusiness card or badge information, event details, meeting context, notes, lead status, relationship information and other customer-provided interaction data.
Enrichment and research dataBusiness and professional information obtained from customer-connected sources, third-party data providers, public websites and other lawfully available sources, together with derived summaries, classifications and research outputs.
Integration dataData synchronized with customer-selected CRM, calendar, directory, identity or workflow systems, and technical credentials or tokens required to maintain those integrations.
AI input and output dataPrompts, text, structured fields, extracted information, summaries and other content processed through AI-assisted features.
Billing and transaction dataSubscription, invoice, payment status, tax and transaction information. Payment card data may be handled directly by payment processors rather than stored by Aspect.
Support and communications dataSupport requests, emails, feedback, call or meeting notes, and other communications with us.
Usage, device and security dataIP address, browser and device information, timestamps, authentication events, audit events, logs, diagnostic data, cookie or similar technology data and usage information.

4. Where personal data comes from

Directly from you, including when you create an account, complete a profile, contact us, request a demo, purchase Services or use product features. From your organization, including administrators and other authorized users who provision or manage your account. From customers and users of the Services, including when they scan a business card or event badge, import a contact, add notes, connect a CRM or request enrichment or research. From customer-connected third-party systems and integrations. From public or professionally available sources, such as company websites, public professional pages, business directories and other sources that may lawfully be used for the requested business research or enrichment. From service providers and data providers that support enrichment, hosting, security, analytics, communications, AI processing and other Services. Automatically from your device or browser when you use our website or Services.

5. Why we process personal data and our legal bases

PurposeWhat this includesTypical legal basis
Provide and operate the ServicesCreate accounts, provide profiles, lead capture, enrichment, research, integrations, workflows and support.Performance of a contract; legitimate interests; customer instructions where we act as processor.
Secure the ServicesAuthentication, fraud prevention, abuse detection, logging, incident response and service integrity.Legitimate interests; legal obligations.
Improve and maintain the ServicesDiagnostics, quality assurance, product analytics and development using data that is minimized or aggregated where practicable.Legitimate interests; consent where required for cookies or similar technologies.
Billing and administrationSubscriptions, invoicing, accounting, tax, contract administration and collections.Performance of a contract; legal obligations; establishment, exercise or defense of legal claims.
Communicate with youService notices, support, security communications, product information and relationship management.Performance of a contract; legitimate interests; consent where required.
MarketingSend marketing communications and manage preferences where legally permitted.Consent or legitimate interests where permitted by applicable law.
AI-assisted processingExtract, classify, summarize, research, enrich and generate responses or recommendations requested through the Services.Performance of a contract; legitimate interests; customer instructions where we act as processor.
Legal and complianceRespond to lawful requests, enforce agreements, protect rights and comply with legal obligations.Legal obligations; legitimate interests; establishment, exercise or defense of legal claims.

6. Lead enrichment, research and customer-provided contact data

Aspect is designed to help business users organize and understand business relationships. Customers may provide contact information directly, scan business cards or event badges, connect CRM systems, or request research and enrichment about business contacts. Where Aspect processes this data on behalf of a customer, the customer is responsible for having an appropriate legal basis, providing required notices, honoring applicable marketing and communications rules, and ensuring its instructions to Aspect are lawful. Aspect processes the data only as permitted by the customer agreement, our Data Protection Addendum and applicable law. Where we obtain personal data indirectly while acting as controller, we provide transparency and other notices when required by applicable law, subject to any lawful exemptions.

7. AI-assisted features

Some Services use third-party AI model providers, including OpenAI, Anthropic Claude and Google Gemini or related Google Cloud AI services. Depending on the feature, we may send limited personal data, customer content or instructions to one or more of these providers to perform the requested processing. We seek to limit data sent to AI providers to what is reasonably necessary for the requested feature. We use business or API services and contractual protections appropriate to the relevant processing where available. Aspect does not intentionally enable optional settings that permit Customer Data to be used to train generalized or foundation models without the customer's prior authorization. AI-generated content can be incomplete or inaccurate. Users should review outputs before relying on them for material business decisions. Customers must not use the Services to make unlawful high-impact decisions about individuals or to process sensitive personal data unless the processing is lawful and expressly supported by the relevant Service.

8. How we disclose personal data

We may disclose personal data to the following categories of recipients, only as reasonably necessary for the relevant purpose: Cloud infrastructure and hosting providers, including Amazon Web Services (AWS). AI processing providers, including OpenAI, Anthropic and Google. Security, monitoring, communications, support, payment, accounting and professional service providers. Customer-selected integrations, such as CRM, calendar, directory or workflow services, when a user or customer directs the transfer. Affiliates, successors or transaction counterparties in connection with a merger, financing, reorganization, acquisition or sale of assets, subject to appropriate confidentiality protections. Courts, regulators, law enforcement or other authorities when disclosure is required by law or reasonably necessary to protect rights, safety or security. Aspect does not sell Customer Data. Aspect does not use Customer Data for cross-context behavioral advertising or targeted advertising unrelated to providing the Services.

9. International transfers

Aspect is established in Türkiye and uses service providers that may process personal data in other countries. This means personal data may be transferred internationally, including to countries outside Türkiye, the EEA, the United Kingdom or Switzerland. Where applicable law requires a transfer mechanism, we use legally recognized safeguards such as adequacy decisions, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or IDTA, contractual safeguards recognized under Swiss law, and the standard contracts or other safeguards available under Article 9 of the Turkish Personal Data Protection Law No. 6698 (KVKK).

10. Data retention and deletion

We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, comply with law, resolve disputes, maintain security and enforce agreements. Customer Data is generally retained for the duration of the customer relationship or until the customer deletes it. Following termination or a valid deletion request, data is removed from active systems within the periods described in our Data Retention & Deletion Policy, subject to legal holds, statutory obligations and backup rotation. Deletion from active systems does not always remove data immediately from encrypted or access-restricted backups. Backup copies are deleted or overwritten according to our backup lifecycle and are not restored to production except for legitimate disaster recovery or security purposes.

11. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration or disclosure. Measures include access controls, encryption in transit and at rest where appropriate, logging and monitoring, backup and recovery measures, secure development practices, vulnerability management and restricted administrative access. No system can be guaranteed to be completely secure.

12. Your rights

Depending on where you live and which law applies, you may have rights to access, obtain a copy of, correct, delete or restrict personal data; object to certain processing; withdraw consent; request portability; opt out of certain sales, sharing, targeted advertising or profiling; and lodge a complaint with a competent supervisory authority. Residents of Türkiye may exercise the rights set out in Article 11 of the KVKK. Individuals in the EEA and UK may exercise rights available under the GDPR or UK GDPR. Residents of California and other US states with comprehensive privacy laws may exercise the rights available under those laws, subject to applicable scope and exceptions. To submit a privacy request, contact info@aspect.contact or use another legally recognized method listed in the applicable local privacy notice. We may need to verify your identity or authority before completing a request. If Aspect processes your personal data solely on behalf of one of our customers, we may direct your request to that customer or assist the customer in responding.

13. Cookies and similar technologies

Our website and Services may use cookies and similar technologies that are necessary for authentication, security, preferences, performance and analytics. Where required by law, non-essential cookies are used only after obtaining the required consent, and available controls can be used to change your preferences.

14. Children

The Services are intended for business and professional use and are not directed to children. Individuals who are not legally able to enter into the applicable agreement should not create an account without authorization from a parent, guardian or other legally authorized person where permitted by law.

15. Changes to this Policy

We may update this Policy from time to time. We will publish the updated version and revise the effective date. If a change materially affects how we process personal data, we will provide additional notice where required by law.

16. Contact

Privacy questions and requests may be sent to info@aspect.contact, aspectbilisim@hs01.kep.tr, or to Acarlar Mah. Derbent Sk. Acarkent A050 No: 23/1 Beykoz / Istanbul, Türkiye. You may also call 0 (850) 380 07 10.