Privacy Policy
Last updated: 5 October 2026
This policy explains how Codesseum Yapay Zeka Hizmetleri San. ve Tic. Ltd. Şti. ("Codesseum", "we") processes personal data on the codesseum.com website and in the mobile and web apps we build. Our Turkish data protection notice under Law No. 6698 (KVKK) is at codesseum.com/kvkk.
Data controller
Codesseum Yapay Zeka Hizmetleri San. ve Tic. Ltd. Şti.
Email: [email protected] WhatsApp: +90 850 302 50 18
The codesseum.com website
Our website is a static site that introduces our company. It has no accounts or sign-in and keeps no database of visitors.
We do not use cookies. The site does not store cookies or use local storage (localStorage, sessionStorage) in your browser, and it contains no analytics or advertising tools, tracking pixels or social media plugins. Fonts and the 3D graphics on the page load from our own server; opening the page sends no requests to third-party content servers.
The only data processed when you visit is the technical information that every web request necessarily carries: IP address, time of the request, page requested, browser and operating system (user agent) and referring page. We process it to deliver the page to you and to protect the site against attacks and abuse. The site is served through the Cloudflare network, so Cloudflare also processes this technical information. The server hosting the site is in Turkey (Sunucun Bilgi İletişim Teknolojileri ve Ticaret Ltd. Şti., Istanbul).
The contact form does not send your data to us. When you fill it in and press send, your name, email and message open as a ready email in the email app on your device; whether to send it is up to you. When you write to us by email or WhatsApp, we process your name, contact details and the content of your message to answer your request and, where relevant, to arrange a meeting or run a business relationship. Our email runs on Google Workspace. WhatsApp messages pass through WhatsApp (Meta) and are also subject to WhatsApp's own terms.
Links to other sites (for example edudiamond.codesseum.com or wa.me) open that service's page; that service's privacy notice applies there.
Our mobile and web apps
The data our apps process depends on the app. Our general principles:
We process only the data an app needs to work. In apps that require an account, this may include your account details (name, email), content you create in the app, technical data (device model, operating system, app version, IP address, error logs) and, for in-app purchases, your subscription status. Your card details never reach us; payments are made through the App Store or Google Play.
In apps with AI features, the content you type or upload is sent to our AI model provider to generate a response. In the Neptune AI app, this provider is Anthropic, PBC (USA); content is sent only to generate responses. By default, Anthropic does not use content processed through its API to train models and deletes it within 30 days; it may retain content longer if a Usage Policy violation is suspected or where required by law (flagged content for up to 2 years). We ask for your explicit permission in the app before sending. The app clearly shows when you are interacting with AI.
Permissions such as location, camera, microphone or notifications are used only for the related feature and only with the consent you give when your device asks; you can withdraw a permission at any time in your device settings.
In apps we provide to schools, institutions or companies (for example EduDiamond), user data is processed on behalf of that institution; the institution is then the data controller and we act as a processor under our contract with it. For requests about that data, please contact your institution first; if you write to us, we will forward your request to it.
Our consumer apps are not directed at children under 13, and we do not knowingly collect data from them; if we find out we have, we delete it.
We do not sell your personal data or share it with third parties for advertising.
Who we share data with
We share data only with service providers we use to deliver our services (hosting, network and security, email and, depending on the app, cloud infrastructure, AI and payment providers) and with competent public authorities where the law requires. For the website these providers are: Cloudflare (network and security), Sunucun Bilgi İletişim Teknolojileri ve Ticaret Ltd. Şti. (hosting, Turkey), Google (Google Workspace email) and WhatsApp (Meta), the latter only if you write to us on WhatsApp.
International transfers
Because we use Cloudflare, Google and WhatsApp (Meta), data processed on the website and in our contact channels may be transferred to servers outside Turkey. We carry out these transfers in line with the conditions and safeguards set out in Article 9 of KVKK. Providers outside Turkey used by an app are named in that app.
Retention
We keep the website's technical logs for no longer than 90 days; Cloudflare's own logs follow Cloudflare's retention periods. We keep email and WhatsApp correspondence for 2 years from the last message; if it turns into a business relationship, we keep commercial correspondence for 10 years as required by Article 82 of the Turkish Commercial Code. App data is kept while your account is open; after you delete your account or data, it is deleted or anonymised, except data we are legally required to keep. Data whose retention period has ended is deleted, destroyed or anonymised.
Security
The site is served only over an encrypted connection (HTTPS). We limit access to data to people who need it for their work and choose our service providers with their security measures in mind.
Your rights
Under Article 11 of KVKK you have the right to learn whether your data is processed, to request information about it, to learn the purpose of processing and whether it is used accordingly, to know the third parties it is transferred to, to request correction of incomplete or inaccurate data, to request deletion or destruction where the legal conditions are met, to request that these actions be notified to the recipients, to object to a result against you arising solely from automated analysis, and to claim compensation for damage caused by unlawful processing. How to apply and the response times are set out in our KVKK notice (codesseum.com/kvkk).
If you are in the European Union, under the General Data Protection Regulation (GDPR) you also have the right to access, rectify and erase your data, to restrict processing, to object, to data portability, and to lodge a complaint with the data protection authority of your country. The legal basis for processing on the website is our legitimate interest in delivering and protecting the site (GDPR Art. 6(1)(f)); when you write to us, it is answering your request or taking steps before a contract (Art. 6(1)(b) and (f)).
Changes
When we update this policy, we publish the new version on this page with its last updated date.
Contact
For privacy questions and requests: [email protected]