Legal

Privacy Policy

Last updated: August 26, 2026

Hirelli (“we”, “us”, “the Service”) is committed to protecting your personal data. This policy explains what data we collect, how we use it, and your rights as a data subject. It applies to all users of hirelli.com, regardless of location.

We operate in compliance with:

  • Turkey's Law No. 6698 on the Protection of Personal Data (KVKK) — our operating entity is Turkish, so this is our primary data-protection law. See our dedicated KVKK notice.
  • EU General Data Protection Regulation (GDPR) — for users in the European Economic Area
  • UK Data Protection Act 2018 / UK GDPR — for users in the United Kingdom
  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) — for users in the UAE

1. Who We Are

Hirelli is operated by TR Software Research & Education A.Ş. (Turkish commercial title: TR Yazılım Araştırma ve Eğitim A.Ş.), a company established in Türkiye. D-U-N-S® Number: 751125497.

Our role: we are the data controller for your account and platform data (name, email, company, usage and billing records). For the business content you put into an agent's memory and the contacts your agents act on (brand documents, leads, customer messages), you are the controller and Hirelli acts as your data processor, handling that data only on your instructions and under a Data Processing Agreement.

For data protection queries: [email protected]

2. Data We Collect

  • Account information: Full name, email address, company name — provided during registration.
  • Usage data: Which agents you hired, which tasks were run, approval/rejection decisions, timestamps.
  • Company content: Brand voice documents, product briefs, campaign examples — content you upload into agent memory.
  • Payment information: Processed via iyzico. We do not store card numbers; iyzico acts as a separate data processor.
  • Technical data: IP address, browser type, device identifiers, session logs — collected automatically for security and performance monitoring.

3. Legal Basis for Processing

  • Contractual necessity — to deliver the services you signed up for.
  • Legitimate interests — platform security, fraud prevention, product improvement (anonymised analytics only).
  • Legal obligation — financial record-keeping required by the Turkish Commercial Code (TTK) and applicable tax law.
  • Consent — for optional marketing communications (withdrawable at any time).

4. How We Use Your Data

  • To operate agent workflows and maintain company-specific memory (tone of voice, SOPs, product knowledge).
  • To process payments and manage your subscription.
  • To send transactional notifications (task results, approval requests, billing receipts).
  • To improve the platform using anonymised, aggregated usage statistics.
  • To comply with legal obligations and respond to lawful authority requests.

5. Who Has Access to Your Data

  • Authorised members of your organisation — based on the roles you assign (Owner / Admin / Member / Viewer).
  • Hirelli staff — only when a support request requires it, with full audit logging.
  • Sub-processors (the third parties that process data to deliver the service):
    • iyzico — payment processing (Türkiye)
    • OpenAI — AI voice, speech-to-text, embeddings and image generation (US)
    • Anthropic (Claude) — AI text generation (US)
    • ElevenLabs — AI voice synthesis (US)
    • Twilio — voice-call telephony (US)
    • Google — Maps/Places lookup, Ads, and OAuth sign-in (US)
    • Meta — advertising and social publishing, only for accounts you connect (US)
    • Brevo — transactional and campaign email (EU)
    • Resend — transactional email delivery (US)
    • Cloudflare — content delivery and network security (US & global)
    We use each sub-processor only for the purpose listed, under a Data Processing Agreement. We update this list when it changes.

Your data is never sold or shared with third parties for commercial purposes. Your agent memory is tenant-isolated and never visible to other organisations.

6. International Data Transfers

Your data may be transferred to and processed in countries outside the UAE — including the United States and EU member states — for cloud infrastructure and payment processing. These transfers are governed by Standard Contractual Clauses (SCCs), UAE PDPL cross-border transfer provisions, and binding contractual obligations on all recipients.

7. Data Retention

  • Active account: Data is retained for the duration of your subscription.
  • Account closure: Personal data is permanently deleted within 30 days, except where legally required.
  • Financial records: Retained for the period required by Turkish commercial and tax law (generally up to 10 years).
  • Security logs: Minimum 1 year; Enterprise plans: configurable retention.

8. Your Rights

Under Turkey's KVKK (Law No. 6698)

  • Learn whether your data is processed, and request access to it
  • Request correction of inaccurate data, or erasure where processing is no longer justified
  • Object to outcomes produced solely by automated analysis
  • Request that we notify the third parties your data was shared with
  • Lodge a complaint with the Turkish Personal Data Protection Authority (KVKK Kurumu)

Full detail is in our KVKK notice.

Under UAE PDPL (Federal Decree-Law No. 45/2021) — UAE users

  • Right to access — obtain a copy of your personal data
  • Right to correction — request inaccurate data be corrected
  • Right to erasure — request deletion where processing is no longer justified
  • Right to restrict processing
  • Right to withdraw consent at any time
  • Right to lodge a complaint with the UAE Data Office

Under GDPR / UK GDPR (EU & UK users)

  • All rights above, plus:
  • Right to data portability — export your data in a machine-readable format
  • Right to object to processing based on legitimate interests
  • Right not to be subject to solely automated decision-making with legal effects
  • Right to lodge a complaint with your national supervisory authority (e.g. ICO in the UK)

To exercise any right, email [email protected] or use our contact form. We respond within 30 days (PDPL) / 1 month (GDPR).

9. Cookies & Analytics

We use two kinds of cookies and similar technologies:

  • Strictly necessary — session authentication, security tokens, and language preference. These are required for the site to work.
  • Analytics & advertising — Google Analytics and Google Ads (gtag.js) help us understand how the site is used and measure the performance of our advertising. These set third-party cookies.

When you first visit, a banner lets you accept or reject non-essential (analytics and advertising) cookies. We use Google Consent Mode, so these cookies are not set until you accept. You can also opt out through your browser settings or Google's own opt-out tools. Disabling them does not affect the core functionality of the service. To revisit your choice, clear this site's storage in your browser or contact [email protected].

10. Children's Privacy

Hirelli is a B2B platform intended for businesses and professionals aged 18 and above. We do not knowingly collect data from minors. If you believe a minor has registered, contact [email protected] immediately.

11. Changes to This Policy

If we make material changes, we will notify you by email at least 15 days before the change takes effect. Continued use of the service after that date constitutes acceptance of the updated policy.

12. Contact & Data Protection Officer

TR Software Research & Education A.Ş. trading as Hirelli
General support & privacy queries: [email protected] (24/7 email support)
Data Protection Officer: [email protected]

Privacy Policy — Hirelli - Hirelli