Help & Documentation
Company
Last updated: August 2026
The General Data Protection Regulation (GDPR) (EU) 2016/679 establishes rules for the protection of natural persons with regard to the processing of personal data. Persono is committed to full compliance with GDPR and equivalent data protection frameworks including Turkey’s Personal Data Protection Law (KVKK).
Persono operates in the following capacities:
On behalf of our Clients, Persono may process the following categories of personal data:
Persono processes personal data under the following legal bases:
Under GDPR, individuals whose data is processed have the following rights:
Requests related to personal data held within a Client’s Persono account should be directed to the Client (Data Controller). Requests related to data held directly by Persono can be submitted to: [email protected]
Persono implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure:
Persono retains Client data for the duration of the service agreement. Upon termination, data is retained for a maximum of 90 days before permanent deletion, unless a longer retention period is required by law or agreed in writing with the Client.
Persono’s primary infrastructure is hosted within Turkey. Where data is transferred outside Turkey or the EEA, Persono ensures appropriate safeguards are in place in accordance with GDPR Article 46, including standard contractual clauses where applicable.
Persono uses a limited number of trusted third-party sub-processors to deliver its services (such as cloud hosting and email delivery providers). All sub-processors are contractually bound to process data only on Persono’s instructions and in compliance with GDPR.
A current list of sub-processors is available upon request.
Clients who require a Data Processing Agreement (DPA) in accordance with GDPR Article 28 may request one by contacting [email protected]. The DPA defines the responsibilities of Persono as Data Processor and the Client as Data Controller.
In the event of a personal data breach, Persono will notify affected Clients without undue delay and, where required, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.
For any questions regarding this policy or data protection practices:
Cumhuriyet Mah. FSM Bulvarı Cadde 224 Sitesi No:41A/A
Nilüfer — Bursa / Türkiye
📧 [email protected]
📞 +90 (224) 909 8170