KVKK / GDPR transparency
Privacy and data protection notice
How ASI: Azalt Sustainability Index processes account, claim, workspace, API, alert and operational data.
v1.0 · effective 1 September 2026
1. Controller and contact
Erguvan Karbon Denkleştirme Çözümleri Tic. A.Ş. (Erguvan) operates ASI and acts as controller for account administration, service security, customer support and product operations. Contact privacy@azalt.ai for privacy requests.
2. Data we process
- — Verified work email, organization membership, role and sign-in records.
- — API-key metadata, endpoint usage, timestamps, response status and truncated network address.
- — Workspace content such as watchlists, saved views, portfolio holdings, claims, corrections and audit events.
- — Claim records: the claimant's name, job title, telephone number and corporate email, and the letter of authorization PDF where one is required.
- — Correction submissions: the proposed change, the supporting evidence attached to it, the submitting organization and the reviewer's decision.
- — Consent records: the version of the legal documents accepted, the moment of acceptance and the network address it came from.
- — Alert destination, consent record and delivery status. A WhatsApp number is stored only when you enter it for alerts or contact the service.
- — Strictly necessary session and preference data. ASI does not use advertising trackers.
3. Purposes and legal bases
We process data to provide and secure the contracted or requested service, authenticate users, enforce entitlements, deliver consented alerts, answer requests, keep audit records and comply with law. Depending on context, the basis is performance of a contract, legitimate interests in operating a secure business service, compliance with legal obligations, or consent for optional electronic communications.
4. Profile claiming, KYC and the letter of authorization
When someone claims a company profile we collect the claimant's corporate email address, name, job title and telephone number, and — where the email domain does not match the company's — a signed letter of authorization uploaded as a PDF.
The purpose is narrow: verifying that the person is authorized to represent the company whose record they are about to control. The legal bases are performance of a contract, in establishing and operating the account relationship at the claimant's own request, and our legitimate interest in the integrity of the registry, which includes protecting a company from someone claiming a record they have no authority over.
Claim records and letters of authorization are kept for the life of the claim and for 10 years after it ends, matching the evidentiary and record-keeping periods customary under Turkish commercial law.
Access to claimant identity data and letters of authorization is limited to platform administrators, who open them only to decide a claim; each access is written to the audit log.
5. Correction requests
When a claimed company submits a data change request, we store the submission, the evidence attached to it and the reviewer's decision as an audit record. Corrections are part of the provenance of the record: an accepted correction, and the fact that the company submitted it, may be reflected on public pages after review. Please do not attach personal data that is not needed to prove the point.
6. Consent record
When you create an account we record which version of these documents you were shown, the moment you accepted them and the network address the acceptance came from. This record exists only to prove what was agreed and when. It is kept for 10 years and is used for no other purpose.
7. Providers and international transfers
Limited data may be processed by hosting, database, object-storage, transactional-email, error-monitoring, product-analytics and messaging providers used to operate ASI. Current categories include Vercel, including its cookieless Vercel Analytics measurement, Neon, Amazon Web Services, Resend, Sentry, and Meta for the WhatsApp channel where that feature is enabled. Transfers outside Türkiye or the EEA are made only using an applicable statutory mechanism and contractual safeguards. A current sub-processor list is available from the privacy contact.
8. Retention and security
Sign-in codes expire within minutes and their records are deleted after 7 days. Full network addresses in usage and audit records are erased after 30 days; operational usage, audit and alert-delivery records are deleted after 13 months; inactive WhatsApp conversation sessions are deleted after 24 hours. Alert destinations remain until you delete the preference. Claim records, letters of authorization and consent records follow the longer periods stated in sections 4 and 6. Contract, security or legal-hold requirements may require a longer period. ASI uses access controls, tenant isolation, encryption in transit, security headers, audit logging and dependency scanning.
9. Your rights
Subject to applicable law, you may request information, access, correction, deletion, restriction, portability or objection, and may withdraw alert consent at any time from the watchlist workspace. Send requests to privacy@azalt.ai. You may also complain to the Turkish Personal Data Protection Authority or the competent EEA supervisory authority.