Personal Data Protection and Privacy Notice
This notice explains how Astramio Bilişim Teknolojileri Sanayi ve Ticaret A.Ş. ("Astramio", "we") collects, uses, shares and protects personal data when you visit www.astramio.com, contact us, or use the Astramio platform and its assistant, Mio, at app.astramio.com (together, the "Services").
It is issued under the Turkish Personal Data Protection Law No. 6698 ("KVKK") as the data controller's disclosure notice (Article 10), and it is also written to meet the transparency requirements of the EU General Data Protection Regulation ("GDPR") and the UK GDPR for users in the European Economic Area and the United Kingdom.
This is an information notice only. Where we need your consent, for example for marketing emails or optional cookies, we ask for it in a separate, clearly labelled consent statement. Nothing in this notice is a request for consent.
1. Who is responsible for your data
| Data controller | Astramio Bilişim Teknolojileri Sanayi ve Ticaret A.Ş. |
|---|---|
| Address | Görükle Mah. Üniversite-1 Cad. ULUTEK Teknoloji Geliştirme Bölgesi No:933, 16285 Nilüfer / Bursa, Türkiye |
| Registration | Registered with the Bursa Trade Registry. Our MERSIS, trade registry and tax numbers appear on every invoice and order confirmation we issue. |
| Email for privacy matters | [email protected] |
| Postal requests | Marked "Personal Data Request" to the address above |
We have not appointed a statutory Data Protection Officer, and we have not appointed a representative in the EU or the UK under Article 27 of the GDPR or UK GDPR. If we appoint either, we will name them here. Privacy requests are handled by the team reachable at the address above.
Our two roles
- We act as data controller for data about website visitors, people who contact us, prospective customers, account holders and billing contacts.
- We act as data processor for content our customers bring into the platform: brand knowledge bases, drafts, media, connected social-media account data and the audience statistics we retrieve on their behalf. For that content the customer is the controller and our Data Processing Addendum applies. If you are a member of a customer's audience and have a question about how that customer uses Astramio, please contact the customer first.
2. What we collect and where it comes from
2.1 Website visitors (www.astramio.com)
- Server logs and security data: IP address, request time, requested page, user-agent. Our own server records these to run the site, to rate-limit form endpoints and to block abusive traffic.
- Local storage flag: a single browser key that remembers whether you have already seen an on-site announcement. It contains no identifier.
- Embedded media: pages that embed YouTube or Vimeo players load content from those providers when the player loads or is played; they may set their own cookies. See the Cookie Notice.
- Fonts: the site loads web fonts from Google Fonts, which means your browser sends your IP address to Google when a page loads.
We do not run advertising, behavioural analytics or session-recording tools on the marketing site. If that changes, this notice and the Cookie Notice will be updated first and any such tool will be switched off until you consent.
2.2 People who contact us or register interest
Through the contact form, pre-order form, internship application form, or email:
- name, email address, phone number, company name, and the message or CV you send;
- a one-time email verification code and the fact that it was verified;
- IP address and timestamp of the submission, for rate limiting and abuse prevention.
Pre-order entries are stored on our server and emailed to our support inbox.
2.3 Platform customers and users (app.astramio.com)
- Account data: name, work email, password (stored as a hash), organisation name, role, language, time zone, profile picture if you add one.
- Billing data: plan, invoices, billing address, tax identification number, payment status. Card numbers are entered directly into our payment processor's secure form and never reach our servers; we receive a payment token, the last four digits and the card brand.
- Usage and device data: log-in times, IP address, browser and device type, feature usage, error reports.
- Support data: tickets, emails and chat messages you exchange with us.
- Connected accounts: when you connect a social-media account, we store the access token, account identifier and profile name that platform gives us, and the posts, comments and performance metrics you ask us to retrieve. We use each platform strictly within its developer terms.
- Content you create: brand knowledge base entries, prompts, generated drafts, images, schedules, and comments.
2.4 Data we do not intentionally collect
We do not ask for and do not want special categories of personal data, such as health, religion, ethnic origin, biometric data or criminal records. Please do not put such data into prompts, knowledge bases or support messages. If we notice it, we may delete it.
2.5 Children
The Services are for businesses and professionals and are not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has given us personal data, contact us and we will delete it.
3. Why we use your data and on what legal basis
KVKK Article 5 and GDPR Article 6 both require a legal basis for each purpose. The table maps them.
| Purpose | Data used | KVKK basis (Art. 5/2) | GDPR basis (Art. 6/1) |
|---|---|---|---|
| Running and securing the website; rate limiting; preventing abuse | Server logs, IP, user-agent | (f) legitimate interest | (f) legitimate interest |
| Responding to contact, pre-order and internship requests | Form data, message | (c) necessary for a contract or pre-contract steps taken at your request | (b) contract / pre-contract |
| Creating and administering your account; providing the platform | Account, usage, content data | (c) contract | (b) contract |
| Generating content with AI on your instruction | Prompts, knowledge base, uploaded media | (c) contract | (b) contract |
| Publishing to and reading from connected social accounts | Tokens, account IDs, posts, metrics | (c) contract | (b) contract |
| Billing, invoicing, accounting, tax records | Billing data | (a) required by law; (c) contract | (c) legal obligation; (b) contract |
| Sending service messages such as security alerts, invoices and changes to terms | Email, account data | (c) contract; (f) legitimate interest | (b) contract; (f) legitimate interest |
| Sending marketing emails and product news | Email, name, plan | Explicit consent (Art. 5/1), given separately | (a) consent, given separately |
| Product analytics and improvement, aggregated where possible | Usage data | (f) legitimate interest | (f) legitimate interest |
| Preventing fraud, enforcing our terms, defending legal claims | Any relevant data | (e) exercise of a legal right; (f) legitimate interest | (f) legitimate interest |
| Complying with court orders and lawful requests from authorities | Any relevant data | (a) required by law | (c) legal obligation |
Where we rely on legitimate interest we have checked that our interest is not overridden by your rights. You can ask for a summary of that assessment.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Content suggestions inside the platform are recommendations you can accept or ignore.
4. How AI features use your data
Mio generates text and images by sending your prompt, relevant parts of your brand knowledge base and, where you choose, uploaded media to third-party AI model providers. We send only what is needed for the request, and we use business-tier APIs whose contracts prohibit the provider from using inputs or outputs for its own purposes, including model training.
- We do not use your prompts, knowledge base or outputs to train or fine-tune models that serve other customers.
- Generated output may be inaccurate or may resemble existing works. You review it before publishing. Where law requires AI-generated or AI-altered content to be labelled, for example under Article 50 of the EU AI Act applicable from 2 August 2026, the customer publishing the content is responsible for that labelling; the platform provides tools to help.
- We keep prompts and outputs as part of your workspace so you can reuse them. You can delete them at any time.
- The names of the model providers we currently use are included in the sub-processor list described in section 5.1.
5. Who we share data with
We do not sell personal data and we do not share it with third parties for their own advertising. We share data only as follows.
5.1 Service providers (sub-processors)
We use a small number of specialised providers, each bound by a written data processing agreement, acting only on our instructions:
| Category | Purpose |
|---|---|
| Cloud hosting and storage | Running the platform and website, backups |
| Email delivery (Google Workspace) | Verification codes, notifications, contact-form delivery to our support inbox |
| Payment processing | Card payments and subscription billing, by a processor licensed for payment services and PCI DSS certified |
| AI model providers | Text and image generation on your instruction |
| Error and performance monitoring | Reliability of the platform |
| E-invoice integrator (Türkiye) | Issuing the electronic invoices Turkish tax law requires |
The current list of named providers, their locations and the transfer mechanism covering each one is available by emailing [email protected], and is attached to the Data Processing Addendum for business customers. We give existing customers at least 30 days' notice by email before adding a sub-processor that will handle their content, and they may object.
5.2 Social-media platforms
When you connect an account we exchange data with that platform, for example Meta, X, LinkedIn, TikTok or YouTube, so we can publish and read on your behalf. Each platform processes that data under its own privacy policy.
5.3 Professional advisers, authorities and successors
Auditors, lawyers and accountants under confidentiality; courts, regulators and law enforcement where the law requires; a buyer or successor if Astramio is sold or merged, under this notice.
We do not share personal data with affiliates, resellers, investors or business partners for their own purposes. If we start working with a reseller or partner who needs your data to serve you, we will tell you before the sharing begins.
6. International transfers
6.1 Data leaving Türkiye
Some of the providers in section 5 are located outside Türkiye. Under Article 9 of the KVKK, as amended with effect from 1 September 2024, we transfer personal data abroad only where:
- the destination is covered by an adequacy decision of the Personal Data Protection Board; or
- we have signed the Board's standard contract with the recipient, without modification, and notified the Authority within five business days; or
- binding corporate rules or a written undertaking approved by the Board are in place; or
- one of the narrow exceptional grounds applies to a one-off transfer, for example where the transfer is necessary to perform a contract with you.
We do not rely on your explicit consent for routine or repeated transfers, because the amended law does not allow it. Remote access to data from outside Türkiye counts as a transfer and is covered by the same mechanisms.
6.2 Data coming from the EEA and the UK
Türkiye is not covered by an EU or UK adequacy decision. When we receive personal data from the EEA or UK we rely on the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, supported by a transfer risk assessment and technical measures such as encryption in transit and at rest. Business customers can obtain our Data Processing Addendum, which incorporates these clauses, by emailing [email protected].
7. How long we keep data
| Data | Retention |
|---|---|
| Website server logs | 30 days, then deleted or anonymised |
| Contact-form and internship messages | 12 months after the last correspondence, unless a contract follows |
| Pre-order registrations | Until the launch offer is fulfilled or 24 months, whichever is first |
| Email verification codes | Minutes; deleted after use or expiry |
| Account and content data | For the life of the account, then deleted within 30 days of closure; backups purge within 90 days |
| Connected-account tokens | Until you disconnect the account or close your workspace |
| Invoices, payment records, accounting entries | 10 years (Turkish Tax Procedure Law and Commercial Code) |
| Commercial electronic message consent records | 3 years after the consent ends (Law 6563) |
| Support tickets | 3 years after closure |
| Data subject request records | 3 years |
| Data needed for a pending dispute | Until the dispute is finally resolved |
When a period ends we delete, destroy or anonymise the data in line with the Turkish Regulation on Deletion, Destruction and Anonymisation of Personal Data and our internal retention policy.
8. How we protect data
We apply the technical and organisational measures required by KVKK Article 12 and GDPR Article 32, including TLS encryption in transit, encryption of stored credentials and tokens, role-based access, logging of administrative access, rate limiting and origin checks on public endpoints, regular backups, and staff confidentiality undertakings. No system is perfectly secure; if a breach is likely to harm you we will notify the Personal Data Protection Board within 72 hours and inform you as the law requires.
9. Your rights
9.1 Under the KVKK (Article 11)
You may ask us to:
- tell you whether we process your personal data;
- give you information about that processing;
- explain the purpose of processing and whether data is used for that purpose;
- name the third parties, in Türkiye or abroad, to whom data is transferred;
- correct incomplete or inaccurate data and notify recipients of the correction;
- delete or destroy data when the reasons for processing no longer exist, and notify recipients;
- refrain from producing a result against you through analysis by exclusively automated systems;
- compensate you for damage caused by unlawful processing.
9.2 Under the GDPR and UK GDPR (Articles 15 to 22)
If you are in the EEA or UK you additionally have the rights of access, rectification, erasure, restriction, data portability, objection including to direct marketing at any time, the right not to be subject to solely automated decisions with legal effect, and the right to withdraw any consent without affecting past processing.
9.3 How to exercise your rights
Send your request to [email protected] or by post to the address in section 1, with enough information for us to verify your identity. Under the Turkish Communiqué on Procedures and Principles for Applications to the Data Controller, a request should include your name, signature for written applications, Turkish ID number or passport number for foreign nationals, address or email for the reply, and the subject of the request. Account holders can also make requests from the email address registered to their account, which we treat as verified.
We answer free of charge within 30 days under KVKK Article 13, or one month under the GDPR, extendable by two months for complex requests. If a request causes disproportionate cost we may charge the fee set by the Board.
9.4 Complaints
- Türkiye: if we reject your request, answer inadequately or do not answer in time, you may complain to the Personal Data Protection Board within 30 days of our reply or 60 days of your application (kvkk.gov.tr).
- EEA: your local supervisory authority.
- UK: the Information Commissioner's Office (ico.org.uk).
We would appreciate the chance to resolve the issue first, but you are not required to contact us before complaining.
10. Marketing communications
We send commercial electronic messages by email, SMS or push notification only with your prior consent, obtained in a separate statement and recorded in the Turkish Message Management System (İYS) as required by Law No. 6563 and its Regulation on Commercial Communication and Commercial Electronic Messages. Every message contains a free and simple way to opt out, and opt-outs take effect within three business days. Service messages needed to run your account, such as invoices, security notices and changes to terms, are not marketing and cannot be opted out of while you hold an account.
11. Cookies
Our use of cookies and similar technologies is described in the Cookie Notice.
12. Regional supplements
12.1 California and other US states
Astramio does not meet the thresholds that make the California Consumer Privacy Act applicable, and we do not "sell" or "share" personal information as those terms are defined there. We nevertheless honour requests to know, delete and correct from US residents under the procedure in section 9.3, and we do not discriminate against anyone who exercises privacy rights.
12.2 EEA and UK
Sections 3, 6, 9.2 and 9.4 contain the information required by GDPR Articles 13 and 14. The legal bases listed in section 3 are the GDPR bases; where "legitimate interest" is named, the interest is described in the same row.
13. Changes to this notice
We may update this notice when the law, our providers or the Services change. Material changes will be announced by email to account holders or by a prominent notice on the site at least 14 days before they take effect. The date at the bottom of this page always shows the current version.
14. Contact
Astramio Bilişim Teknolojileri Sanayi ve Ticaret A.Ş.
Görükle Mah. Üniversite-1 Cad. ULUTEK Teknoloji Geliştirme Bölgesi No:933, 16285 Nilüfer / Bursa, Türkiye
[email protected]
Last Updated: 05/09/2026