Legal
Privacy Policy
What personal data we collect, why we process it, who else touches it, and what you can ask us to do about it.
Last updated: 24 August 2026
Eratt (Eratt) operates https://eratt.com and the connected customer portal (the "Service"). This policy explains what personal data we collect when you use the Service, why we process it, who we share it with, how long we keep it, and the rights you can exercise.
Eratt is the data controller for this processing. We are established in Istanbul, Türkiye, so processing is governed by Turkish Personal Data Protection Law no. 6698 ("KVKK"). Where we offer the Service to people in the European Economic Area or the United Kingdom, we also process personal data in accordance with the General Data Protection Regulation ("GDPR"). Where the two differ, we apply whichever gives you the stronger protection.
1. Data we collect
1.1 Data you give us
- Account data: name, email address, password hash, and — if you supply it — phone number, company name and store URL.
- Billing data: the plan you selected, invoice records and the billing details required to issue them. Card numbers never reach our servers: payments are processed by our payment provider, and we receive only a masked reference and the transaction result.
- Enquiry data: anything you write in a contact form, a support request or a WhatsApp conversation started from the Service.
1.2 Data about your brand and your content
- Brand data: public content from the website you ask us to analyse — product categories, page copy, tone-of-voice samples and terminology — used to build your content plan and to keep output consistent with your brand.
- Generated content: the articles, category copy, cover images, voiceover audio and short videos produced for you, together with your approvals, revision requests and rejections.
- Connection data: access tokens for the publishing channels you connect (WordPress, WooCommerce, Shopify, ikas, YouTube). Tokens are stored encrypted and are used only to publish content you have approved. You can revoke a connection at any time from the portal.
1.3 Data collected automatically
- Technical data: IP address, browser and device type, and timestamps, recorded in server and security logs.
- Usage data: which pages you visit and which actions you take in the product, used to operate and improve the Service.
- Cookies: strictly necessary cookies keep you signed in and secure the session. Analytics and marketing cookies are set only after you consent, and you can change that choice at any time through the cookie preferences link in the footer. See our cookie policy for the full list.
2. Why we process it, and on what basis
- To provide the Service — creating your account, running content generation, delivering approved content to your channels, and providing support. Lawful basis: performance of a contract.
- To take payment and meet accounting obligations — processing subscriptions, issuing invoices and retaining financial records. Lawful basis: performance of a contract and compliance with a legal obligation.
- To keep the Service secure — detecting abuse, rate limiting, fraud prevention and audit logging. Lawful basis: our legitimate interest in protecting the Service and its users.
- To improve the product — aggregate usage analysis and quality measurement. Lawful basis: legitimate interest, or your consent where the analysis relies on non-essential cookies.
- To send you service and marketing messages — operational emails are part of the contract; commercial messages are sent only with your consent, and every one carries an unsubscribe link.
3. Sub-processors
Producing a content bundle requires third-party processors. We share only what a processor needs, under a data processing agreement, and none of them is permitted to use your data for their own purposes.
- Anthropic PBC (United States) — large-scale text generation for articles and category copy.
- OpenAI, L.L.C. (United States) — text generation and structured extraction tasks.
- ElevenLabs Inc. (United States) — synthetic voiceover for the audio in your bundles.
- Firecrawl (United States) — retrieving the public pages of the website you ask us to analyse.
- DataForSEO (Lithuania, EU) — search demand and competitor visibility data.
- Payment provider — card processing, performed entirely on the provider's systems.
- Hosting and infrastructure providers — running the application, database and media storage.
Several of these processors are located outside Türkiye and the EEA. Transfers are made on the basis of the contractual safeguards permitted under Article 9 of the KVKK and Chapter V of the GDPR, including standard contractual clauses where applicable.
4. Retention
- Account and content data — kept while your account is active. After you close it, data is deleted or irreversibly anonymised within 90 days, except where a longer period is legally required.
- Invoices and financial records — retained for the statutory period under Turkish tax and commercial law.
- Security and audit logs — retained for up to 12 months.
- Publishing tokens — deleted as soon as you disconnect the channel.
5. Your rights
Subject to the conditions in the applicable law, you may ask us to:
- confirm whether we process personal data about you, and give you access to it;
- correct data that is inaccurate or incomplete;
- delete data, or restrict how we process it;
- provide the data you gave us in a portable, machine-readable format, or transmit it to another controller;
- object to processing carried out on the basis of legitimate interests, including profiling;
- withdraw consent at any time, without affecting processing already carried out;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Write to info@eratt.com and we will respond within 30 days. If you are unhappy with our response you may complain to the Turkish Personal Data Protection Authority (KVKK Kurumu) or, in the EEA or UK, to your local supervisory authority.
6. Security
Traffic is encrypted in transit with TLS. Passwords are stored as salted hashes and publishing tokens are encrypted at rest. Access to production data is restricted to personnel who need it and is logged. Should a breach create a high risk to your rights, we will notify you and the competent authority within the statutory deadline.
7. Children
The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect personal data from children; if you believe we have, contact us and we will delete it.
8. Changes to this policy
We may update this policy as the Service or the law changes. The date shown at the top of the page is the current version. Material changes are announced by email or in the product before they take effect.
9. Contact
- Controller: Eratt
- Address: [Registered address — to be updated], Istanbul / Türkiye
- Privacy enquiries: info@eratt.com
- Support: info@eratt.com
Turkish-language statutory notices — the KVKK disclosure text, the distance selling agreement and the delivery and refund terms — are published in Turkish only and are available from the Turkish version of this site.
See also our Terms of Service.