Skip to main content

PDPL Disclosure Statement

Effective Date: 01.01.2026 · Last Updated: 01.10.2026

Pursuant to the Personal Data Protection Law No. 6698 (PDPL, known locally as KVKK) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform (the "Disclosure Communiqué"), we, Alpaco Yazılım Teknolojileri A.Ş. ("BraindPower" or the "Company"), as data controller, take the utmost care to protect the privacy and personal data of users who visit our website at https://braindpower.com/en (the "Website"), users of our mobile application (the "Mobile Application"), and those who request a demo or information.

This Website and Mobile Application Disclosure Statement (the "Disclosure Statement") has been prepared to inform data subjects about the methods by which personal data is collected during use of the Website and Mobile Application, the purposes and legal grounds for processing, the parties to whom data is transferred, and the rights data subjects hold under Article 11 of the PDPL.

1. Identity of the Data Controller

Under the Personal Data Protection Law No. 6698 (the "Law No. 6698"), your personal data will be collected and may be processed by BraindPower, as data controller, within the scope described below.

2. Categories and Types of Personal Data Processed

If you visit the Website, fill in the demo and contact forms, or use our platform's mobile applications (the "Mobile Application"), the following personal data is processed:

  • Identity Data: First name, last name.
  • Contact Data: E-mail address, telephone number; name of the organisation/company you work for, your role and title/position.
  • Transaction Security Data: IP address, Website entry-exit and traffic/log records, access dates and times, cookie records, device, operating system and internet browser information; for the Mobile Application, technical stack traces collected to diagnose problems when the application closes unexpectedly or fails, application crash status, device model, operating system version, application version and language, a randomly generated installation ID and information on the screen where the error occurred (these records contain no name, surname, e-mail, telephone or session information and are not used for advertising purposes).
  • Customer Transaction and Request Data: Message text, requests, suggestions and complaints submitted through the demo request form or by e-mail.
  • Marketing Data: Where you have given explicit consent; commercial electronic message approvals and preferences, newsletter responses, and the analytics and marketing cookie preferences regulated in the Cookie Policy.

3. Purposes of Processing Personal Data

Your personal data is processed, in a limited manner, for the purposes below, in accordance with the general principles set out in Article 4 of the PDPL (lawfulness and fairness; accuracy and, where necessary, being up to date; being processed for specified, explicit and legitimate purposes; being relevant, limited and proportionate to the purposes for which they are processed; and being retained for the period stipulated in the relevant legislation or required for the purpose of processing):

  • Retaining hosting provider traffic and log records as a legal obligation under the Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications (Law No. 5651) and related secondary legislation,
  • Ensuring information and processing security; ensuring the technical operation, stability, performance and continuity of the Website and Mobile Application; diagnosing and resolving technical errors and crashes in the Mobile Application; detecting suspicious transactions and cyber security breaches,
  • Evaluating and responding to communication, information and demo requests and contacting the requesters,
  • Promoting BraindPower products, modules and services within our AI-powered social media monitoring, analysis and digital insight platform, and planning and running demo presentation processes,
  • Managing request and complaint processes, measuring customer satisfaction and improving service quality,
  • Where you have given explicit consent; sending commercial electronic messages about the Company's products, modules and services under Law No. 6563 and the İYS legislation, and carrying out newsletter and marketing activities,
  • Serving as evidence in possible legal disputes, establishing and defending rights, and providing the information and documents requested by competent public institutions and judicial/administrative authorities within the legal framework.

4. Method and Legal Basis of Collecting Personal Data

Your personal data is collected wholly or partially by automated means: through technical communication files (cookies), server logs and the contact and demo request forms on the Website while it is visited, and, for the Mobile Application, through Google Firebase Crashlytics technical diagnostic mechanisms.

This personal data is processed on the following legal grounds set out in Article 5/2 of the PDPL:

  • Being expressly provided for by law: for retaining traffic records and access logs under Law No. 5651 and related legislation (PDPL Art. 5/2-a),
  • Processing of personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract: for meeting demo requests, preparing offers and conducting pre-contractual discussions under contracts to which the data subject is a party (for corporate customer representatives, under legitimate interest) (PDPL Art. 5/2-c),
  • Being mandatory for the data controller to fulfil its legal obligation: for making statutory notifications, taking information security measures and responding to requests from official authorities (PDPL Art. 5/2-ç),
  • Processing being mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject: for ensuring the security and technical stability of the Website and Mobile Application, carrying out Crashlytics error diagnostics, improving service quality and communicating with corporate customer representatives (PDPL Art. 5/2-f),
  • Processing being mandatory for the establishment, exercise or protection of a right: for serving as evidence in possible legal disputes and for establishing and defending rights (PDPL Art. 5/2-e),
  • Explicit consent of the data subject: where you have given explicit consent, for sending commercial electronic messages, newsletter and marketing processes, and for the non-essential analytics and marketing cookies described in the Cookie Policy (PDPL Art. 5/1). You can find detailed information about the types of cookies on our Website, their purposes and how to manage your cookie preferences on our Cookie Policy page.

5. Transfer of Personal Data

The personal data collected may be transferred to the following parties, for the purposes set out in this Disclosure Statement and in accordance with Article 8 of the PDPL:

  • To judicial authorities, law enforcement units, enforcement offices and other public institutions and organisations authorised by law, in order to fulfil our statutory notification and information obligations, conduct judicial or administrative processes and resolve legal disputes,
  • To authorised IT, infrastructure and software service providers, in order to provide hosting, cloud infrastructure, server services, CRM, e-mail delivery and technical IT support for the Website and Mobile Application,
  • To independent auditors, legal counsel and attorneys our Company works with, in order to establish, protect and exercise our legal rights.

Your personal data is transferred to Google and related cloud service providers located abroad, in connection with running mobile application technical crash/diagnostic services through Google Firebase Crashlytics and providing cloud computing infrastructure services. These continuous and regular transfers abroad are carried out in reliance on the Standard Contract (Standard Contractual Clauses / SCC) announced by the Personal Data Protection Board, under Article 9/4-(a) of the PDPL as amended by Law No. 7499.

6. Retention Period and Security of Personal Data

Your personal data is retained for the mandatory periods stipulated in the relevant legislation and for the periods required by the purpose of processing. Accordingly: hosting provider traffic records kept under Law No. 5651 are retained for two 2 years; Mobile Application technical crash and error diagnostic records for ninety 90 days on Google Firebase infrastructure; demo and information requests with a negative outcome for one 1 year; data relating to requests that turn into a commercial relationship for ten 10 years in line with general limitation periods; and commercial electronic message consent and opt-out records for three 3 years as required by legislation. When these periods end or the conditions for processing cease to exist, your data is deleted, destroyed or anonymised in accordance with our Company's Personal Data Retention and Destruction Policy. Under Article 12 of the PDPL, our Company takes all necessary technical and administrative measures to prevent the unlawful processing of and access to personal data and to ensure its safekeeping.

7. Rights of the Data Subject

As a data subject, you may exercise the following rights by applying to our Company under Article 11 of the PDPL:

  • Learning whether your personal data is processed,
  • Requesting information if your personal data has been processed,
  • Learning the purpose of processing and whether it is used in accordance with that purpose,
  • Knowing the third parties to whom your personal data is transferred, domestically or abroad,
  • Requesting correction if your personal data is incomplete or inaccurately processed,
  • Requesting deletion or destruction of your personal data under the conditions set out in Article 7 of the PDPL,
  • Requesting that correction, deletion and destruction operations be notified to third parties to whom your personal data has been transferred,
  • Objecting to an outcome against you arising from the analysis of your processed data exclusively by automated systems,
  • Requesting compensation for damages if you suffer harm due to unlawful processing of your personal data.

8. Application Procedure and Contact

You may submit your applications regarding the rights listed above to our Company by the following methods, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller:

  • In writing: By delivering your wet-signed petition together with documents verifying your identity, in person or through a notary, to 25929-34927-94050,
  • Registered Electronic Mail (KEP): By sending it, with your secure electronic signature, to our Company's KEP address alpacoyazilim@hs01.kep.tr,
  • E-mail: By using the e-mail address you previously notified to our Company and that is registered in our system, or by signing with a secure electronic/mobile signature, and sending it to support@braindpower.com or hello@braindpower.com.

Your application must include, as required by legislation, your first name, last name, signature (for written applications), Turkish ID number (for foreigners, nationality and passport number or foreign ID number if available), residence or workplace address for notification, e-mail address for notification if any, telephone number and the subject of your request.

Our Company will conclude the requests in an application, depending on their nature, as soon as possible and at the latest within thirty (30) days, free of charge. However, if the process requires a separate cost, the fee in the tariff determined by the Personal Data Protection Board may be charged. If your application is rejected, the response is found insufficient, or no response is given in time, you have the right to lodge a complaint with the Personal Data Protection Board under Article 14 of the PDPL within thirty (30) days from the date you learn of our Company's response and in any case within sixty (60) days from the date of application.

9. Changes to the Disclosure Statement

This Disclosure Statement may be reviewed in line with changes in legislation, decisions of the Personal Data Protection Board and updates to our Company's data processing activities. The updated text takes effect on the date it is published on the Website and Mobile Application.

10. Statement on Platform Activities and Social Media Data

This Disclosure Statement covers exclusively the data of Website visitors and Mobile Application users. Publicly available data relating to third parties processed within the social media monitoring, listening and AI analysis services that the BraindPower platform provides to its corporate customers, as well as corporate subscription/customer account and invoice data, are managed under corporate agreements that determine the data controller and data processor roles and under a separate Personal Data Policy.

Contact Us

Start making decisions with confidence

See how one platform can power every decision across social, PR, and marketing.