Legal

Privacy Policy

Last updated: January 7, 2025

1. Provider and Data Controller

The provider and data controller responsible for this website and the Strajist AI platform is:

Strajist AI Yazılım A.Ş.

Barbaros Mah. Şebboy Sk. No:4/1, İç Kapı No:2

34746 Istanbul/Ataşehir, Türkiye

Email:

Phone: +90 216 987 34 53

As the data controller, we determine the purposes and means of processing personal data in connection with our AI visibility tracking platform and related services.

2. Data Processing to Enable Use of the Platform

When you access our platform, we automatically collect certain connection data necessary to provide and secure our services:

  • IP address
  • Date and time of access
  • Referrer URL (the page from which you accessed our platform)
  • Device information (device type, screen resolution)
  • Browser type and version
  • Operating system
  • Pages viewed and actions taken within the platform

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest). We have a legitimate interest in ensuring the security, stability, and functionality of our platform, as well as protecting against misuse and unauthorized access.

3. Data Processing upon Your Request

3.1 Registration and Account Creation

When you register for a Strajist AI account, we collect:

  • Email address
  • Organization/company name
  • Password (stored only in securely hashed form via Supabase Auth)
  • Name (optional)

Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract). This data is necessary to create your account and provide you with access to our services.

3.2 Brand Tracking Configuration

To provide our AI visibility tracking services, we process:

  • Brand names you wish to track
  • Keywords and search queries you configure
  • Competitor brands you specify for comparison
  • Industry and category information

Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract). This information is essential to deliver the core functionality of our platform.

3.3 Communication and Support

When you contact us for support or inquiries, we process the information you provide, including your email address and the content of your communication.

Legal basis: Art. 6 para. 1 lit. b GDPR (pre-contractual measures or contract performance) or Art. 6 para. 1 lit. f GDPR (legitimate interest in responding to inquiries).

3.4 Newsletter and Marketing Communications

If you subscribe to our newsletter or marketing communications, we collect your email address and any preferences you indicate.

Legal basis: Art. 6 para. 1 lit. a GDPR (consent). You may withdraw your consent at any time by clicking the unsubscribe link in any marketing email or by contacting us at .

4. Data Processing for Service Optimization

To improve our platform and user experience, we may collect and analyze:

  • Aggregated usage patterns and feature adoption
  • Performance metrics and error logs
  • User feedback and survey responses (when voluntarily provided)

Our platform is hosted on secure cloud infrastructure that provides:

  • Automatic SSL/TLS encryption for all connections
  • Content delivery network (CDN) for optimal performance
  • DDoS protection and security monitoring

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in improving our services and ensuring platform stability).

5. Cookies and Similar Technologies

We use cookies and similar technologies to operate our platform effectively. Below is a comprehensive overview of the cookies we use:

5.1 Strictly Necessary Cookies

These cookies are essential for the platform to function and cannot be disabled:

  • Authentication cookies: Managed by Supabase Auth to maintain your logged-in session
  • Security cookies: CSRF protection tokens to prevent cross-site request forgery attacks
  • Session cookies: To remember your authenticated state across page loads

5.2 Functional Cookies

These cookies remember your preferences and settings:

  • Theme preference: Light or dark mode setting
  • Language preference: Your chosen display language
  • Dashboard settings: Layout and display preferences

5.3 Analytics Cookies

We may use analytics tools to understand how users interact with our platform. These cookies collect aggregated, anonymized data about page views, feature usage, and navigation patterns. We use this information solely to improve our services.

5.4 Your Cookie Choices

You can manage your cookie preferences in the following ways:

  • Browser settings: Most browsers allow you to block or delete cookies. However, blocking essential cookies will prevent you from using our platform.
  • Opt-out of analytics: Where we use third-party analytics, we provide opt-out mechanisms.

Please note that disabling essential cookies will affect the functionality of our platform, including your ability to log in and use core features.

6. Data Transfer to Third Parties

We work with trusted third-party service providers to operate our platform. These providers process data on our behalf under strict contractual obligations:

6.1 Supabase (Backend Infrastructure)

We use Supabase for our database and authentication infrastructure. Supabase provides:

  • PostgreSQL database hosting with encryption at rest
  • Secure authentication services (Supabase Auth)
  • Automatic daily backups
  • Row Level Security for data isolation

Supabase maintains SOC 2 Type II certification and implements comprehensive security controls. For more information, see Supabase's privacy policy and security documentation.

6.2 Cloud Hosting Infrastructure

Our application is hosted on enterprise-grade cloud infrastructure that provides automatic SSL/TLS certificates, content delivery network (CDN), and robust security protections.

6.3 Payment Processing (Paddle)

All subscription payments are processed by Paddle.com Market Limited ("Paddle"), which acts as our Merchant of Record. When you purchase a subscription, Paddle collects and processes:

  • Payment method details (credit card, PayPal, etc.)
  • Billing name and address
  • Transaction history and invoice records
  • Tax identification information (where applicable)

We do not store your full payment card details on our systems. All payment data is processed directly by Paddle in accordance with PCI DSS requirements. For more information about how Paddle handles your data, please review Paddle's Privacy Policy.

6.4 International Data Transfers

Some of our service providers may process data outside the European Economic Area (EEA), including in the United States. Where such transfers occur, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): EU-approved contractual terms for international transfers
  • EU-US Data Privacy Framework: Where providers are certified under the framework
  • Adequacy decisions: Where applicable, transfers to countries with EU adequacy decisions

7. Storage Duration and Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Active account data: Retained while your subscription is active and for 30 days after account deletion request
  • Billing and transaction records: Retained for the period required by applicable tax and commercial law (typically 7–10 years)
  • Communication records: Support correspondence retained for 2 years after resolution
  • Log data: Server logs and security logs retained for up to 90 days
  • Encrypted backups: May persist for up to 90 days after data deletion from primary systems
  • Marketing consent records: Retained for the duration of consent plus 3 years for compliance purposes

8. Technical and Organizational Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using HTTPS with TLS 1.2 or higher
  • Encryption at rest: Data stored in our database is encrypted at rest using AES-256 encryption via Supabase
  • Secure authentication: Passwords are hashed using bcrypt via Supabase Auth; we never store plaintext passwords
  • Access controls: Row Level Security (RLS) ensures each customer can only access their own data
  • Automatic backups: Daily automated backups with point-in-time recovery capability
  • Internal access controls: Access to customer data is limited to authorized personnel on a need-to-know basis

9. Your Rights under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): You have the right to request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR): You have the right to request correction of inaccurate personal data or completion of incomplete data.
  • Right to erasure (Art. 17 GDPR): You have the right to request deletion of your personal data under certain circumstances ("right to be forgotten").
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request that we restrict the processing of your data in certain circumstances.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21 GDPR): You have the right to object to processing based on legitimate interests or for direct marketing purposes.

To exercise any of these rights, please contact us at . We will respond to your request within 30 days as required by GDPR.

10. Right to Object

Where we process your personal data based on legitimate interests (Art. 6 para. 1 lit. f GDPR), you have the right to object to such processing at any time. Upon receiving your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Objection to direct marketing: You may object to processing for direct marketing purposes at any time. Following such objection, we will no longer process your data for marketing.

Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

To exercise your right to object, contact us at .

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by email (sent to the email address associated with your account) or by posting a prominent notice on our platform prior to the changes becoming effective. We encourage you to review this Privacy Policy periodically. Your continued use of our services after any changes constitutes your acceptance of the updated Privacy Policy.

12. Contact Information

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us:

Strajist AI Yazılım A.Ş. – Data Protection

Barbaros Mah. Şebboy Sk. No:4/1, İç Kapı No:2

34746 Istanbul/Ataşehir, Türkiye

Email:

Phone: +90 216 987 34 53

We aim to respond to all inquiries within 30 days.