Inside the platform

Product

Back to home

Legal

Privacy Policy

Effective 15 September 2026

On this page

Who is responsible

Narlinx is the data controller (veri sorumlusu) for personal data about accounts, billing identity, support, and the marketing site. Contact the controller at info@narlinx.com. We have not listed a registered company title or street address on this page; that email is the contact for KVKK and GDPR requests until we publish one.

For personal data inside an organization’s devices, assets, telemetry, location, logs, and similar operational records (“Customer Data”), the customer organization is the controller and Narlinx is the processor (veri işleyen). Operators of that organization decide what to ingest and who may see it.

This Privacy Policy explains how we handle personal data under Law No. 6698 on the Protection of Personal Data (KVKK) and, where it applies, the EU General Data Protection Regulation (GDPR). It covers narlinx.com, app.narlinx.com, our APIs, ingest, and companion apps.

Personal data we process

Depending on how you use the Service, we process:

  • Account data: name, email, password hash, language and date/time format preferences, session identifiers, and organization membership
  • Organization administration: roles, abilities, site-access assignments, invitations, and API keys (hashed)
  • Customer Data you choose to send: device and asset attributes, telemetry, discrete events, outdoor and indoor location, geofences, rules, flows, files, and operational logs
  • AI conversations: text, voice audio, tool results, and persisted transcripts when you use the assistant
  • Notifications: in-app inbox rows, email content, and SMS content and destination numbers you configure (Netgsm)
  • Marketing-site contact form: name, email, optional company, and message
  • Technical data: IP address, user agent, and security logs needed to run ingest and the product

Who we share data with

We do not sell personal data. We share it with:

  • Infrastructure we operate: PostgreSQL/TimescaleDB, Redis, and NATS for the product
  • OpenAI, when you use the AI assistant (session audio/text and tool context)
  • Email transport (SMTP) when we send transactional mail such as password reset, invitations, and rule notifications
  • Netgsm, when an organization sends SMS notifications
  • Your own organization members, according to roles and site scope you configure

International transfers

AI features send conversation content to OpenAI, which processes data in the United States. Using those features is an instruction to transfer that content outside Turkey (and, where GDPR applies, outside the EEA).

We do not claim a specific signed set of standard contractual clauses on this page. If you cannot accept that transfer, do not use the AI assistant and do not put personal data in prompts. For other subprocessors, we choose providers and settings consistent with KVKK transfer rules and GDPR Chapter V where they apply, and we will update this section when we publish more detail.

Cookies and similar storage

We use cookies and similar storage that are needed to run the sites. The marketing site’s cookie list is also published at /cookies. Product cookies live on app.narlinx.com. We do not use advertising or analytics pixels.

  • narlinx.consent (narlinx.com): first-party, about one year, stores whether you accepted or rejected marketing-site cookies
  • narlinx-landing-color-mode (narlinx.com): first-party, about one year, stores the light appearance only, and only after you accept cookies
  • narlinx.lang (narlinx.com): first-party, about one year, stores English or Turkish from your choice or from Turkish in the browser language list, and only after you accept cookies
  • i18n_redirected (app.narlinx.com): stores the UI language you picked
  • __refresh_token (app.narlinx.com): HTTP-only refresh token for your session; not readable by page JavaScript

Your rights

Under KVKK Art. 11 you may apply to us to learn whether we process your data, to request access, correction, deletion or anonymization, to learn recipients, to object to a result against you, and to claim compensation for damage caused by unlawful processing. Send applications to info@narlinx.com. You may also complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurulu).

Where GDPR applies, you also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority in your EU/EEA member state. If we rely on consent, you may withdraw it without affecting prior lawful processing.

For Customer Data we process as processor, we will route your request to the customer organization when they are the controller, unless we must answer you directly by law.

Children

The Service is for adult operators of organizations. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to info@narlinx.com and we will delete it.

How long we keep data

Account data lasts for the life of the account plus a short wind-down for security and dispute handling. Sessions expire or are revoked as described in the product (refresh tokens currently last on the order of days).

Customer Data is kept for as long as the organization uses the Service. After an organization is closed we delete it within a reasonable period, then from backups on their cycle, unless law requires a longer hold (for example invoice records if paid billing exists).

Contact-form messages are kept long enough to answer you and then deleted or archived in ordinary email retention. Security logs are kept for a limited diagnostic window.

Security

We use HTTPS, hashed passwords, hashed API keys, organization isolation in queries, site-scoped access where configured, HTTP-only refresh cookies on the web app, and session revocation. No method is perfect. You must protect credentials and decide which location and telemetry you ingest.

Report suspected incidents to info@narlinx.com.

Changes to this policy

We may update this Privacy Policy. The effective date at the top of the page will change. Material changes will be announced by email or in the product when reasonably possible. Continued use after the effective date is acceptance of the updated policy.

Contact

Privacy and KVKK applications: info@narlinx.com. Cookie questions about the marketing site are also answered on the cookie policy page. This policy should be read with the Terms of Service, which include processor terms for Customer Data.