Privacy Policy - Deep Search

Privacy Policy

Last updated: 4/9/2026

GDPR Compliant | EU Representative Available

1. Overview

Deep Search, operated by APPIOS BILISIM TEKNOLOJILERI SANAYI TICARET LIMITED SIRKETI ("we," "our," or "us"), is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you use our AI-powered research platform.

This policy complies with the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws. If you are located in the European Union, we act as the data controller for your personal information.

Key Principle: We collect only the minimum data necessary to provide our services and never sell your personal information to third parties.

2. Information We Collect

Account Information

  • Email address (via Google/Apple authentication)
  • Name and profile picture (from your authentication provider)
  • Unique user identifier
  • Account creation and last login dates

Search Data

  • Search queries and terms you enter
  • Search history and timestamps
  • Search results and interactions
  • Search mode preferences (fast, super, username)

Biometric Data (Face Search)

  • Facial images you upload for search purposes
  • Biometric templates derived from uploaded images
  • Face search results and match scores

Important: Biometric data is processed with explicit consent and deleted within 30 days unless you request longer retention.

Payment Information

  • Stripe customer ID and subscription details
  • Payment transaction history
  • Billing address (processed by Stripe)

Note: We do not store credit card numbers or payment details. All payment processing is handled securely by Stripe.

Technical Information

  • IP address and location data
  • Device type, browser, and operating system
  • Usage analytics and performance metrics
  • Error logs and crash reports
  • Cookies and session data

4. How We Use Your Information

We use your personal data for the following purposes:

Service Delivery

  • Process search requests
  • Provide search results
  • Manage user accounts
  • Handle customer support

Payment Processing

  • Process subscriptions
  • Manage billing
  • Handle refunds
  • Prevent fraud

Communication

  • Send service notifications
  • Provide customer support
  • Send security alerts
  • Marketing (with consent)

Improvement

  • Analyze usage patterns
  • Improve AI algorithms
  • Enhance user experience
  • Develop new features

5. Data Sharing & Third Parties

We share your data only as described below. We never sell personal information to third parties.

Firebase (Google)

Authentication services and user management

Data Processing Agreement in place

Stripe

Payment processing and subscription management

PCI DSS compliant processor

Backend Search Services

AI-powered search processing and result aggregation

Encrypted data transmission

Analytics Services

Usage analytics and performance monitoring (anonymized data only)

GDPR-compliant processing

Legal Disclosures

We may disclose personal information if required by law, court order, or to protect our rights and safety.

6. Biometric Data Policy

Special Protection for Biometric Data

Facial recognition data receives the highest level of protection under our privacy framework.

Collection & Consent

  • Explicit consent required before processing facial images
  • Clear explanation of how biometric data will be used
  • Option to withdraw consent at any time

Processing & Security

  • Encryption of all biometric templates
  • Processing occurs in secure, isolated environments
  • No permanent storage of original facial images
  • Access limited to authorized personnel only

Retention & Deletion

  • Biometric templates deleted within 30 days by default
  • Immediate deletion upon request
  • Secure deletion from all systems and backups
  • Deletion confirmation provided upon request

7. Data Retention Policies

We retain personal data only as long as necessary for the purposes outlined in this policy:

Account Data

Retained while your account is active plus 90 days after deletion

Search History

Retained for 2 years or until account deletion

Biometric Data

Deleted within 30 days (or immediately upon request)

Payment Records

Retained for 7 years for tax and audit purposes

Analytics Data

Anonymized data retained for 3 years

Security Logs

Retained for 1 year for security purposes

Data is automatically deleted according to these schedules unless longer retention is required by law.

8. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right to Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

"Right to be forgotten" - request deletion of your data

Right to Data Portability

Receive your data in a machine-readable format

Right to Object

Object to processing based on legitimate interests

Right to Restrict Processing

Limit how we process your personal data

Right to Withdraw Consent

Withdraw consent for biometric data processing

Right to Complain

File a complaint with your data protection authority

How to Exercise Your Rights

Contact us at info@appios.com.tr or use the contact form below. We will respond within 30 days.

9. International Data Transfers

Your personal data may be transferred to and processed in countries outside your jurisdiction, including the United States.

EU-US Data Privacy Framework

We rely on adequacy decisions and appropriate safeguards for EU data transfers.

Standard Contractual Clauses

Data Processing Agreements include EU-approved standard contractual clauses.

All data transfers are protected by appropriate technical and organizational measures to ensure the security of your personal data.

10. Data Security Measures

We implement comprehensive security measures to protect your personal data:

Technical Safeguards

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Regular security audits
  • Automated vulnerability scanning

Access Controls

  • Multi-factor authentication
  • Role-based access control
  • Regular access reviews
  • Principle of least privilege

Monitoring

  • 24/7 security monitoring
  • Intrusion detection systems
  • Audit logging
  • Incident response procedures

Organizational

  • Security training for staff
  • Background checks
  • Confidentiality agreements
  • Regular policy updates

11. Cookies & Tracking Technologies

We use cookies and similar technologies to provide and improve our services:

Essential Cookies

Required for authentication and basic functionality

Cannot be disabled

Analytics Cookies

Help us understand how you use our service

Can be disabled in settings

Preference Cookies

Remember your settings and preferences

Optional

Security Cookies

Protect against fraud and unauthorized access

Required for security

You can manage cookie preferences through your browser settings or our cookie preference center.

12. Children's Privacy

Age Restriction: 18+

Our service is not intended for users under 18 years of age.

We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

13. Data Breach Notification

In the unlikely event of a data breach affecting your personal information:

We will notify relevant authorities within 72 hours (GDPR requirement)

You will be notified without undue delay if the breach poses a high risk

We will provide clear information about the nature and impact of the breach

We will recommend steps you can take to protect yourself

We maintain an incident response plan and conduct regular security assessments to minimize the risk of data breaches.

14. Privacy Policy Updates

We may update this Privacy Policy to reflect changes in our practices or applicable laws. When we make changes:

We will update the "Last updated" date at the top of this policy

For material changes, we will provide prominent notice on our website

We may also notify you by email if you have an account with us

Your continued use after changes constitutes acceptance of the updated policy

15. Contact Information & Data Protection Officer

For any privacy-related questions, concerns, or to exercise your rights, please contact us:

General Privacy Inquiries

Company: APPIOS BILISIM TEKNOLOJILERI SANAYI TICARET LIMITED SIRKETI

Email: info@appios.com.tr

Response Time: Within 30 days

Languages: English, Turkish

Data Protection Officer

Email: info@appios.com.tr

Role: GDPR Compliance & Data Protection

Availability: Monday-Friday, 9 AM - 5 PM CET

Mailing Address

APPIOS BILISIM TEKNOLOJILERI SANAYI TICARET LIMITED SIRKETI

Kocaeli, Turkey

EU Representative

If you are located in the EU and have concerns about our data processing, you can also contact our EU representative at info@appios.com.tr

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns adequately.

This Privacy Policy is compliant with GDPR, CCPA, and other applicable privacy laws.