1. Data controller
The data controller under Turkish Law No. 6698 is MAD CAT LABS YAPAY ZEKA VERİ BİLİMLERİ VE YAZILIM ANONİM ŞİRKETİ.
Trade Registry No: 1140106; MERSİS: 0610168252400001; address: Seyrantepe Mah. Gökdeniz Sk. No: 15 İç Kapı No: 6 Kağıthane / İstanbul, Türkiye; email: [email protected]; phone: +90 (212) 274 67 33.
2. Data subject groups
- Website visitors.
- Platform users, company administrators and team members.
- Customer and prospective customer representatives.
- People submitting demo, quote, support and contact forms.
- Individuals whose data appears in integrations or customer content.
- Supplier, business partner and public authority representatives.
3. Categories of personal data
- Identity, contact, company and role information.
- Account, user, team, permission and authentication records.
- Customer transaction, contract, quote, invoice, payment and support records.
- Campaign, brief, file, chat, comment, brand kit, report, image, generated output and integration data uploaded to the platform.
- Ad account, CRM, analytics, audience/segment, budget, conversion, performance and marketing mix modeling data.
- IP address, device, browser, operating system, language/locale, cookie, localStorage, log, security and usage data.
- Marketing consents, communication preferences and event/demo requests.
4. Processing purposes
- Operating membership, account management, authentication, authorization and workspace management processes.
- Providing SaaS services, AI-assisted creative generation, reporting, marketing mix modeling, integrations and support.
- Operating Strategy Lab, Asset Creation, Marketing Mix, reporting, support widget, file generation, OCR, image generation and campaign automation processes.
- Meeting contract, quote, invoice, accounting, collection, retention and official request obligations.
- Maintaining information security, system operations, debugging, abuse prevention and service quality.
- Conducting product announcements, marketing communications, cookie preferences, analytics and campaign measurement where consent or another legal basis applies.
- Analyzing product performance, capacity needs and feature usage with aggregated or anonymized data.
5. Legal bases
- Processing directly related to establishment or performance of a contract.
- Compliance with legal obligations of the controller.
- Establishment, exercise or protection of a right.
- Legitimate interests, provided fundamental rights and freedoms are not harmed.
- Processing expressly provided by law.
- Explicit consent where required.
6. Notice and explicit consent distinction
The obligation to provide notice is fulfilled independently from explicit consent. Data subjects are informed about processing even where processing is based on contract performance, legal obligation, legitimate interest or another legal basis.
Where explicit consent is required, the notice text and consent text are structured separately. Consent must relate to a specific subject, be based on information and be given freely; non-essential marketing or cookie activities may use separate preference/consent mechanisms.
7. Special categories of personal data
The services are not designed to collect special categories of personal data. You should not upload health data, biometric data, criminal conviction data, religious belief, political opinion, union membership or similar special-category data to the platform.
If customer content, files, images, CRM records or integration data contain special-category personal data, the relevant customer/company account is responsible for ensuring the required legal basis, explicit consent, notice, authorization and security measures.
8. Collection methods
Data is collected electronically or physically through the website, application, forms, support channels, cookies, localStorage/sessionStorage records, logs, APIs, integrations, contracts, email communications, demo requests, content uploaded by users and information provided by company/workspace administrators.
Google, Meta, LinkedIn, TikTok, Canva, HubSpot, Salesforce, Google Search Console, Google Business Profile, Google Ads, Google Analytics, Yandex Metrica, Hotjar and similar tools may be data sources within the scope connected by the user or enabled by the company.
9. Recipients
Personal data may be shared with cloud infrastructure, storage, email, analytics, AI, payment, support, security, integration, CRM, advertising/analytics platforms, business partners, suppliers and competent public authorities only as required to provide the service.
For corporate accounts, company administrators may access user memberships, roles, projects, activities, reports, support requests, billing information and integration status to manage the account.
10. International transfers
International transfers may be required due to cloud services, AI model providers, analytics tools, email/support systems or third-party platforms connected by the user.
International transfers are carried out under KVKK and secondary legislation primarily through adequacy decisions, and where no adequacy decision exists, through appropriate safeguards, standard contracts, binding corporate rules or Board authorization. Where appropriate safeguards are not available, incidental transfer conditions provided by legislation are assessed separately.
11. Retention and deletion
Personal data is retained while the processing purpose and legal basis continue. When the retention period ends, data is deleted, destroyed or anonymized. Backup cycles, disputes, statutory retention periods and security logs may require reasonable additional periods.
Account data may be retained while the account is active; billing and accounting records for statutory periods; security logs for reasonable security periods; project, brief, file and report records while necessary to provide the contracted service.
12. Rights under KVKK Article 11
You may learn whether your data is processed; request information; learn the processing purpose and whether it is used accordingly; know third parties to whom data is transferred domestically or abroad; request correction of incomplete or inaccurate data; request deletion or destruction where conditions apply; request notification of these actions to third parties; object to automated analysis producing adverse results; and claim compensation for damages caused by unlawful processing.
13. Application procedure
You may submit requests to [email protected] or to Seyrantepe Mah. Gökdeniz Sk. No: 15 İç Kapı No: 6 Kağıthane / İstanbul, Türkiye. Requests are concluded as soon as possible and generally no later than 30 days depending on their nature.
Applications may be submitted in writing, by secure electronic signature, mobile signature, registered electronic mail address or by using the electronic mail address previously registered in our systems. Applications should include name-surname, signature or electronic verification information, Turkish ID number or passport/identity information for foreigners, notification address, email/phone information, request subject and explanations regarding the request.
Identity, account or representation authority may be verified before concluding the request. Certain requests for corporate accounts may be assessed under company-admin instructions, contract terms and legal retention obligations.
Applications are generally free of charge. If the response requires additional cost, the fee set by the Turkish Personal Data Protection Board may be charged.
14. Children's data
The services are not directed to persons under 18. If you believe a child's personal data has been submitted to the platform, you may contact us. After appropriate verification, access restriction or deletion requests will be assessed.
15. Notice changes
This notice may be updated due to changes in the product, integrations, data processing processes or legislation. The current notice is effective from the date it is published on the website.