Privacy Policy
Last updated: 16.07.2026
1. Scope and Applicability
This Privacy Policy sets out how Apilex Teknoloji Anonim Şirketi, operating as Apilex (“Apilex”, “we”, “us”), processes personal data of individuals located in the European Economic Area (“EEA”) in connection with our website (www.apilex.ai), our AI-powered legal platform (app.apilex.ai), our mobile application, and our plug-ins and integrations (together, the “Services”), in accordance with Regulation (EU) 2016/679 (“GDPR”).
This Policy applies where Apilex acts as a data controller, namely with respect to:
- individuals who visit our website or use our platform, including representatives of our corporate customers, and matters arising from that use such as account administration and billing;
- prospective customers and their representatives, including individuals who request a product demonstration or otherwise engage with us in the course of sales and business development activities;
- individuals who contact us through our website's contact form or raise a support request;
- attendees of events, webinars, and surveys we organize or participate in;
- subscribers to our newsletters and other marketing communications; and
- representatives of our suppliers, service providers, and other business partners.
This Privacy Policy does not apply to any input submitted to, or output generated by, our platform, nor to documents uploaded to our platform (collectively, “Content”). We process Content on behalf of our customers, who are the data controllers of that Content, and our processing of it is governed by the relevant customer agreement, under which Apilex acts as a data processor. We do not use the substance of your documents, prompts, or outputs for analytics, marketing, or model training, and we access them only to the extent necessary to provide the Services; we may separately process metadata about platform usage, such as query volume or feature activity, as described in Section 2. Any queries relating to personal data contained in Content should be directed to the Apilex customer responsible for that data; if we receive a rights request concerning Content, we will forward it to the relevant customer.
If you are located outside the EEA and your personal data is subject to a different data protection framework, for example the UK GDPR or Türkiye's KVKK, a separate notice applies to you.
Apilex is not directed at children, and we do not knowingly collect personal data from them through our website or platform. Content you upload as a customer may incidentally contain personal data relating to a minor, for example where a case file or contract concerns one; in that case, the data is handled as Content under this Section, and you remain its controller.
2. Personal Data We Collect
We collect personal data in three ways: directly from you, automatically as you use our website and platform, and occasionally from others.
Information you provide to us
- Account Data: To give you or your employer access to the platform, we need your name, email address, language preference, and a password.
- Contact and Request Data: When you reach out to us, whether through our contact form, a demo request, or a support ticket, we collect your name, email address, phone number, and the details of what you are asking.
- Marketing Data: We collect this to reach you with relevant updates and offers, and to understand how our marketing activities are performing. This can include your name and email address when you subscribe to our newsletter, information from your interactions with our social media pages, and data gathered through advertising and marketing tools we use to run campaigns and measure their effectiveness.
- Event Data: Registering for a webinar or survey means sharing your name, email address, and any other details the registration asks for.
- Billing Data: Where invoicing requires it, we ask for a billing address or a tax or company identification number.
Information we collect automatically
- Log Data: Whenever you visit our website or use our platform, your browser shares its type and the time of your request. We also collect your IP address this way, which helps us keep the Services secure.
- Device Data: So that our Services display correctly, we see the type of device you are using, its operating system, and a device identifier.
- Usage Data: We look at which features you access and how much time you spend on the platform, to help us understand how the Services are used and where to improve them. This does not extend to the substance of your queries or any documents you upload, which fall outside this Policy under Section 1.
- Cookie Data: Our website uses cookies and similar technologies to function properly and to help us understand how it is used. Further detail is available in our Cookie Policy.
Information we receive from other sources
- Third-Party Data: Occasionally we learn about you from others, for instance when a colleague registers you for an event or your company is identified to us as a prospective customer.
3. How We Use Your Personal Data and Our Legal Bases
The table below sets out what we use your personal data for, why we are allowed to under the GDPR, and how long we keep it.
| Purpose | Legal Basis | Retention |
|---|---|---|
| Setting up and administering your account. If you register directly, we need this to run our side of the contract with you. If your employer holds the contract with us instead, we process your Account Data as a processor acting on your employer's instructions, and your employer is responsible for the lawfulness of that instruction. | Contractual necessity (Art. 6(1)(b) GDPR), or processing on your employer's instructions (Art. 28 GDPR) | 10 years from the end of the contractual relationship |
| Identifying and engaging prospective customers. We use contact and professional details, whether you shared them with us directly or we received them from a business partner or public source, to reach out about our Services. | Legitimate interest in business development (Art. 6(1)(f) GDPR) | 1 year from your last interaction, or until you object |
| Responding to your inquiries. Whether you have reached out through our contact form, a demo request, or a support ticket, we want to be able to help. | Legitimate interest in addressing inquiries (Art. 6(1)(f) GDPR), or contractual necessity if you are already a customer and the request relates to your subscription (Art. 6(1)(b) GDPR) | 1 year from resolution of your request |
| Running events, webinars, and surveys. We use your registration details to organize your participation and follow up with you afterward. | Contractual necessity toward you as a participant (Art. 6(1)(b) GDPR), and legitimate interest in following up with attendees (Art. 6(1)(f) GDPR) | 1 year from the event |
| Sending you marketing communications. If you are an existing customer, we may keep you informed about our Services unless you object. Otherwise, we only do this with your consent. | Legitimate interest (Art. 6(1)(f) GDPR) for existing customers; consent (Art. 6(1)(a) GDPR) otherwise, withdrawable at any time | 5 years from your last interaction, or until you object or withdraw consent |
| Keeping our Services secure. We use this data to protect the Services from misuse and to investigate security incidents. | Legitimate interest in security (Art. 6(1)(f) GDPR) | 5 years |
| Maintaining and improving our Services. We look at your device information and usage patterns to fix issues and build better features. | Legitimate interest in product improvement (Art. 6(1)(f) GDPR) | 1 year |
| Managing relationships with suppliers and business partners. We use contact details to perform our agreements and handle day-to-day dealings with these parties. | Legitimate interest in supplier and partner management (Art. 6(1)(f) GDPR) | 10 years from the end of the relationship |
| Meeting our legal obligations. For example, responding to a valid request from a competent authority. | Legal obligation (Art. 6(1)(c) GDPR) | As required by applicable law |
| Recording customer support calls. We record calls with our support and customer success teams for quality assurance and to resolve your request. | Legitimate interest in service quality and dispute resolution (Art. 6(1)(f) GDPR) | 3 years |
Where we rely on legitimate interest, we have weighed it against your rights and freedoms and concluded it does not override them. You can ask us for more detail on this assessment at privacy@apilex.ai.
Some of this data is necessary for us to provide the Services at all. Without your Account Data, for example, we cannot create or maintain your access to the platform, and without Billing Data, we cannot issue invoices where these are required. Where a category is not essential in this way, such as Marketing Data, providing it is entirely your choice.
We do not make any decision about you based solely on automated processing that would have a legal or similarly significant effect on you. The outputs our platform generates, such as draft analyses, summaries, or document reviews, are reference material for you to review and act on; they are not decisions made by us about you.
4. Who We Share Your Personal Data With
We share personal data only where it is necessary to run our business and deliver the Services, and never sell it.
- Payment providers: To process payments, we share your billing details with the payment provider you have chosen.
- Hosting providers: To keep the Services running and your data securely stored, our hosting provider processes personal data on our behalf.
- AI-powered analysis and content-generation providers: To deliver the research, analysis, and drafting features you use on the platform, these providers process the prompts and documents involved in your request. As explained in Section 1, this processing happens under a zero-data-retention architecture and only for the duration needed to generate your result.
- Plug-ins and integrations: If you choose to connect a third-party service to the platform, such as Google Drive, we access and share data with that service to the extent needed to provide the connected functionality, for example importing or exporting your documents. This exchange is governed both by this Policy and by the third-party service's own privacy terms, and you can disconnect it at any time from your account settings.
- Marketing and advertising providers: To run our marketing campaigns and measure how they perform, we share data with the social media platforms, advertising networks, and marketing tools described in Section 2.
- Professional advisors: Where reasonably necessary, we may share personal data with our lawyers, auditors, or consultants.
- Competent public authorities: Where the law requires it, for example in response to a valid legal request, we share personal data with the relevant authority.
A current list of our sub-processors, together with the safeguards applicable to each, is available in our Sub-Processor List.
5. International Data Transfers
We always aim to keep your personal data as close to home as possible. Our infrastructure, including our hosting and the AI-powered analysis and content-generation providers referenced in Section 4, is located within the EEA, and by using our Services, you understand that your personal data will primarily be processed there.
In certain circumstances, your personal data may still be transferred outside the EEA. Apilex itself is established in Türkiye, and our Türkiye-based personnel access this data in the ordinary course of business, for example to manage accounts, provide support, and operate the Services. Because Türkiye is a country for which the European Commission has not issued an adequacy decision, this access constitutes an international transfer under the GDPR. The same applies if any of our sub-processors are located outside the EEA. Your rights over your personal data, described in Section 7, are not affected when it is transferred internationally, and you can find more detail on who we share your data with in Section 4.
Safeguards we rely on
Countries outside the EEA, including your own country of residence, may have laws that let public authorities request access to personal data stored there for law enforcement or national security purposes. Regardless of whether we or one of our providers processes your personal data, we make sure an appropriate safeguard is in place before any transfer takes place, in line with the requirements of the GDPR. These safeguards include:
- Adequacy decisions: Where the European Commission has decided that a country offers a level of protection equivalent to the GDPR, we may rely on that decision.
- Standard Contractual Clauses: Where no adequacy decision applies, as is the case for the transfer of data to Apilex in Türkiye, we rely on the Standard Contractual Clauses adopted by the European Commission. These require the recipient to protect your data to the same standard as under the GDPR and to preserve your rights over it. We also assess whether local laws in the recipient's country could undermine that protection, and put additional technical or organizational measures in place where needed.
- Data Privacy Framework: Where a sub-processor is certified under the EU-U.S. Data Privacy Framework or an equivalent framework recognized by the European Commission, we may rely on that certification as a valid safeguard for transfers to that party.
- Derogations under Article 49 GDPR: In limited, one-off situations where none of the above applies, for example where you have given your explicit consent to a specific transfer or where the transfer is necessary to establish or defend a legal claim, we may rely on the applicable exception under Article 49 GDPR.
- Pseudonymization: Before Content reaches an AI model, including those located outside the EEA, our platform automatically masks the personal data it contains, so that the model itself never processes the underlying personal data in identifiable form.
The safeguards applicable to each of our sub-processors are set out in our Sub-Processor List. You can request more detail about any of these safeguards, or a copy of the relevant clauses, by contacting us at privacy@apilex.ai.
6. How We Keep Your Personal Data Secure
We maintain technical and organizational measures designed to protect your personal data against unauthorized access, loss, or misuse, including encryption, firewalls, and intrusion detection systems; access controls that limit who within Apilex can see your data and why; regular logging and review of access to our systems; regular penetration testing and vulnerability scanning; and confidentiality obligations and security training for our staff. Our practices are aligned with ISO 27001, and we hold our sub-processors to comparable standards through the contracts we have in place with them.
Further detail on our technical and organizational measures is available in our Security Addendum.
If a personal data breach occurs, we will notify the competent supervisory authority without undue delay, and, where the breach is likely to result in a high risk to you, we will notify you directly, in each case in line with Articles 33 and 34 GDPR.
Before any document or query reaches an AI model, our platform automatically detects and masks personal data it contains (such as names, ID numbers, and contact details), replacing it with placeholder tokens; the AI model never has access to the underlying personal data, and the original values are restored only after the model's output is returned to you.
7. Your Data Protection Rights
Subject to the conditions set out in the GDPR, you have the following rights.
- Information and access: This Policy, together with our responses to your questions, is intended to keep you informed about how we process your personal data. Beyond that, you are entitled to confirmation of whether we are processing your personal data and to a copy of it.
- Rectification: If any of your personal data is inaccurate or incomplete, you may request that we correct it.
- Erasure, also known as the right to be forgotten: In certain cases, for example where we no longer need your data for the purpose it was collected for, or where you withdraw consent we relied on, you may request that it be deleted. This right is not absolute: we may retain data we still need, where our interest in keeping it outweighs yours, or where the law requires us to. If we have made your data public or shared it with others, we will take reasonable steps to pass on your erasure request to them as well.
- Restriction: While we are assessing a rectification request or an objection under the following right, you may request that we pause processing your data rather than continue it.
- Object: Processing based on our legitimate interest may be challenged on grounds relating to your particular situation; unless we can demonstrate compelling and legitimate grounds that override your interests, we will stop that processing. Direct marketing may be objected to at any time and without justification, whether by using the unsubscribe link in a marketing email or by contacting us directly, and doing so will turn off marketing communications addressed to you specifically, though not the non-promotional emails related to your account or our business relationship.
- Data portability: Where your data is processed under a contract or your consent, you are entitled to a copy in a structured, machine-readable format, and, where technically feasible, to have it transmitted directly to another controller.
- Withdrawing consent: Consent may be withdrawn at any time, without affecting the lawfulness of any processing carried out before the withdrawal. For consent relating to cookies specifically, this can be managed through our cookie preference settings; further detail is available in our Cookie Policy.
- Complaints: A complaint about our processing may be lodged with the supervisory authority of your habitual residence, your place of work, or the place where the alleged infringement occurred.
To exercise any of these rights, please contact us at privacy@apilex.ai. We may ask you to verify your identity before acting on your request, and we will respond within the timeframes the GDPR requires.
8. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, regulatory, or operational changes. The current version is published on our website and takes effect as of its publication date. Where a change is material, we will notify you through appropriate channels before it takes effect.
9. Who We Are and How to Contact Us
The data controller responsible for your personal data under this Privacy Policy is:
- Apilex Teknoloji Anonim Şirketi (operating as Apilex)
- Osmangazi Mah. 3117. Sokak Altınbaş Teknopark No:3/15 Esenyurt/İstanbul
If you have any questions or concerns about our use of your personal data, please contact our Data Protection Officer at privacy@apilex.ai.
Data Protection Officer: Gonca Alanbay