Who is responsible
Narlinx is the data controller (veri sorumlusu) for personal data about accounts, billing identity, support, and the marketing site. Contact the controller at info@narlinx.com. We have not listed a registered company title or street address on this page; that email is the contact for KVKK and GDPR requests until we publish one.
For personal data inside an organization’s devices, assets, telemetry, location, logs, and similar operational records (“Customer Data”), the customer organization is the controller and Narlinx is the processor (veri işleyen). Operators of that organization decide what to ingest and who may see it.
This Privacy Policy explains how we handle personal data under Law No. 6698 on the Protection of Personal Data (KVKK) and, where it applies, the EU General Data Protection Regulation (GDPR). It covers narlinx.com, app.narlinx.com, our APIs, ingest, and companion apps.
Personal data we process
Depending on how you use the Service, we process:
- Account data: name, email, password hash, language and date/time format preferences, session identifiers, and organization membership
- Organization administration: roles, abilities, site-access assignments, invitations, and API keys (hashed)
- Customer Data you choose to send: device and asset attributes, telemetry, discrete events, outdoor and indoor location, geofences, rules, flows, files, and operational logs
- AI conversations: text, voice audio, tool results, and persisted transcripts when you use the assistant
- Notifications: in-app inbox rows, email content, and SMS content and destination numbers you configure (Netgsm)
- Marketing-site contact form: name, email, optional company, and message
- Technical data: IP address, user agent, and security logs needed to run ingest and the product
Why we process it (legal bases)
Under KVKK Art. 5 and GDPR Art. 6, we rely on:
- Contract: creating and securing your account, running the organization, ingest, commands, and support you ask for
- Legitimate interests (and KVKK’s comparable grounds): securing the Service, preventing abuse, product reliability, and limited service improvement that does not override your rights
- Consent: where we ask for it (for example optional marketing email, if we ever send it) — you may withdraw it
- Legal obligation: tax, accounting, and requests we must answer from competent authorities
Who we share data with
We do not sell personal data. We share it with:
- Infrastructure we operate: PostgreSQL/TimescaleDB, Redis, and NATS for the product
- OpenAI, when you use the AI assistant (session audio/text and tool context)
- Email transport (SMTP) when we send transactional mail such as password reset, invitations, and rule notifications
- Netgsm, when an organization sends SMS notifications
- Your own organization members, according to roles and site scope you configure
International transfers
AI features send conversation content to OpenAI, which processes data in the United States. Using those features is an instruction to transfer that content outside Turkey (and, where GDPR applies, outside the EEA).
We do not claim a specific signed set of standard contractual clauses on this page. If you cannot accept that transfer, do not use the AI assistant and do not put personal data in prompts. For other subprocessors, we choose providers and settings consistent with KVKK transfer rules and GDPR Chapter V where they apply, and we will update this section when we publish more detail.
Your rights
Under KVKK Art. 11 you may apply to us to learn whether we process your data, to request access, correction, deletion or anonymization, to learn recipients, to object to a result against you, and to claim compensation for damage caused by unlawful processing. Send applications to info@narlinx.com. You may also complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurulu).
Where GDPR applies, you also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority in your EU/EEA member state. If we rely on consent, you may withdraw it without affecting prior lawful processing.
For Customer Data we process as processor, we will route your request to the customer organization when they are the controller, unless we must answer you directly by law.
Children
The Service is for adult operators of organizations. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to info@narlinx.com and we will delete it.
How long we keep data
Account data lasts for the life of the account plus a short wind-down for security and dispute handling. Sessions expire or are revoked as described in the product (refresh tokens currently last on the order of days).
Customer Data is kept for as long as the organization uses the Service. After an organization is closed we delete it within a reasonable period, then from backups on their cycle, unless law requires a longer hold (for example invoice records if paid billing exists).
Contact-form messages are kept long enough to answer you and then deleted or archived in ordinary email retention. Security logs are kept for a limited diagnostic window.
Security
We use HTTPS, hashed passwords, hashed API keys, organization isolation in queries, site-scoped access where configured, HTTP-only refresh cookies on the web app, and session revocation. No method is perfect. You must protect credentials and decide which location and telemetry you ingest.
Report suspected incidents to info@narlinx.com.
Changes to this policy
We may update this Privacy Policy. The effective date at the top of the page will change. Material changes will be announced by email or in the product when reasonably possible. Continued use after the effective date is acceptance of the updated policy.
Contact
Privacy and KVKK applications: info@narlinx.com. Cookie questions about the marketing site are also answered on the cookie policy page. This policy should be read with the Terms of Service, which include processor terms for Customer Data.