Personal Data Protection Disclosure
Last updated: 20 August 2026 · Law No. 6698 (KVKK)
1. Data controller and scope
This disclosure explains how personal data may be processed in connection with EVRE under Law No. 6698 on the Protection of Personal Data (KVKK). EVRE's role depends on the activity and deployment concerned.
For the EVRE website, demo and sales communications, direct EVRE accounts, our own security and operations, and our own business activities, EVRE may act as data controller.
When an organisation uses EVRE for its employees, teams, or other users and determines the purposes and scope of the relevant processing, that organisation may be the data controller and EVRE may act as processor on its behalf. The applicable customer agreement, data-processing terms, security schedule, or order form may define the roles and instructions for that deployment in more detail.
2. Personal data and collection methods
Depending on how EVRE is used, the active deployment, and the organisation's configuration, we may process the following categories:
Account and access data
Name, surname, business email, organisation, role or title, membership, authentication, and access information.
Organisation-provided content
Scenarios, competency models, evaluation criteria, training material, procedures, and other organisational context supplied by a customer.
Simulation and evaluation data
Written or spoken responses, transcripts, conversation history, scenario events, decisions, scores, evaluation reasoning, evidence excerpts, feedback, and reporting or coaching information.
Voice data
Spoken input and the resulting transcript when voice functionality is used. The processing path and retention depend on the active deployment and speech provider.
Technical and contact data
IP address, device and browser information, session and security events, feature usage, errors, performance metadata, and information sent through demo, sales, support, or privacy communications.
Data may be collected through the website and forms, account registration or SSO, customer invitations and provisioning, use of simulations, optional voice input, technical interactions with the service, and communications with EVRE.
3. Processing purposes and legal grounds
The purpose of processing and the legal ground for processing are separate elements. The applicable KVKK condition depends on the activity, the parties' role, and the deployment instructions.
Where spoken or written content happens to include special-category data, that content is not made special-category data merely because it is voice. Any such processing must be assessed under the applicable Art. 6 condition and the relevant controller's instructions.
4. Voice, AI, and simulation processing
Voice mode is optional. Spoken input may be processed and transcribed by the speech-processing infrastructure configured for the active deployment. Standard Cloud deployments may use managed speech services; customer or enterprise deployments with stricter boundaries may use private or local speech-to-text infrastructure.
- EVRE does not use voiceprint or biometric identity profiles, or employee voice cloning, as a standard product function.
- A transcript created from spoken input may become part of the simulation record and may be used for evaluation, feedback, and authorised reporting.
- Raw-audio transmission and retention are deployment- and provider-dependent. This disclosure therefore does not promise that raw audio is never stored or that every provider has zero retention.
- AI services may receive simulation context, transcripts or conversation history, evaluation criteria, technical metadata, and outputs when required by the configured flow. The exact payload and provider depend on the deployment.
5. Recipients and international transfers
Personal data may be disclosed to the following recipient groups for the stated purposes, subject to the active deployment and applicable customer instructions:
Customer and authorised organisation users
Assignments, training administration, evaluation, feedback, and reports within the customer's authorised scope.
Cloud, database, authentication, and application providers
Hosting, authentication, storage, delivery, and operation of the configured service.
AI and speech providers
Simulation generation, evaluation, speech-to-text, or text-to-speech only where the configured flow requires it.
Security, observability, edge, support, and communications providers
Security, reliability, incident handling, support, transactional email, and limited technical operations as applicable.
EVRE maintains relevant contractual and data-processing terms and provider-specific security documentation for the providers used in the applicable flow. This is not a blanket statement that every current or future vendor has the same agreement, location, retention, or configuration.
Where personal data is transferred outside Türkiye, the transfer is assessed under the current KVKK Article 9 regime. Depending on the flow, this may require an adequacy decision, an appropriate safeguard such as a notified standard contract or approved binding corporate rules, or a limited incidental-transfer exception where its statutory conditions are met. Regular provider transfers are not justified simply by treating use of the service as blanket explicit consent.
The detailed privacy policy describes deployment-dependent processing in more detail: Privacy Policy
6. Retention, deletion, and provider lifecycle
Retention depends on the data category, purpose, customer instructions, deployment model, applicable legal obligations, and the technical lifecycle of the systems involved. EVRE does not state one universal retention period for every deployment.
Application, account, simulation, and evaluation records
Kept only for the relevant service, customer, security, legal, or reporting purpose and according to the applicable lifecycle decision.
Raw audio
May be memory-only, provider-processed, or subject to a deployment-specific retention path. No blanket no-storage statement applies to every deployment.
Backups, security records, and provider operational records
May follow separate technical, contractual, backup, or legal lifecycles and may not disappear at the same moment as an application record.
Deletion or anonymisation
When data is no longer required, EVRE or the relevant customer controller may direct deletion, destruction, anonymisation, or removal from use. Provider and backup exceptions are handled through their applicable lifecycle.
7. Your rights under KVKK Article 11
Subject to the applicable role and statutory conditions, you may have the right to:
- Learn whether personal data is processed and request information about the processing.
- Learn the purpose of processing and whether the data is used consistently with that purpose.
- Learn the domestic or international third parties to whom data is transferred.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction where the statutory conditions are met.
- Request notification of correction, deletion, or destruction to the relevant third parties where required.
- Object to a result against you arising solely from analysis by automated systems.
- Request compensation for damage arising from unlawful processing.
If EVRE acts as the direct controller for the relevant activity, send your request to EVRE. If EVRE processes the data on behalf of an enterprise customer, the customer may be the primary controller and may need to handle the request with EVRE.
For the current application channel and identity-verification information, contact [email protected]
A complaint to the Personal Data Protection Board is not a substitute for the application to the data controller. You should first apply to the relevant data controller under Article 13. If the application is rejected, the response is inadequate, or no response is given within the statutory period, you may retain the right to complain to the Board under the applicable time limits.
8. Security measures
EVRE applies technical and organisational measures intended to protect personal data against unauthorised access, use, alteration, loss, or disclosure. Controls vary by deployment and are not presented as a guarantee that every system or provider has identical settings.
- Server-side authorisation, tenant boundaries, and role-based access controls.
- Database Row Level Security (RLS) and application-level access checks.
- In the reviewed 18 August 2026 production snapshot, RLS was enabled on all 75 reviewed public-schema tables. This is a dated snapshot, not a promise about every future table or deployment.
- Privileged credentials kept server-side and multi-factor authentication for administrator access.
- Encrypted network and storage controls provided by the relevant infrastructure providers, together with security-event and operational controls appropriate to the flow.
Provider certifications, whitepapers, and technical measures belong to the provider and are not presented as EVRE certification. For example, the reviewed ElevenLabs security materials describe provider-level AES-256 at rest and TLS 1.2 or higher in transit; they do not establish EVRE's own certification or workspace settings.
9. Contact and effective date
For questions about this disclosure or a request concerning processing for which EVRE acts as controller, contact:
KVKK applications: [email protected]
General privacy: [email protected]
This disclosure is effective as of 20 August 2026 and may be updated when EVRE's products, deployment models, providers, or legal obligations change. The current version and its last-updated date are published on this page.
For the Authority's general guidance on the disclosure duty, see kvkk.gov.tr
This disclosure is prepared under Article 10 of Law No. 6698. It should be read together with any applicable customer-specific data-processing terms.

