EVRE

Personal Data Protection Disclosure

Last updated: 20 August 2026 · Law No. 6698 (KVKK)

1. Data controller and scope

This disclosure explains how personal data may be processed in connection with EVRE under Law No. 6698 on the Protection of Personal Data (KVKK). EVRE's role depends on the activity and deployment concerned.

For the EVRE website, demo and sales communications, direct EVRE accounts, our own security and operations, and our own business activities, EVRE may act as data controller.

When an organisation uses EVRE for its employees, teams, or other users and determines the purposes and scope of the relevant processing, that organisation may be the data controller and EVRE may act as processor on its behalf. The applicable customer agreement, data-processing terms, security schedule, or order form may define the roles and instructions for that deployment in more detail.

This page is a KVKK disclosure, not a general consent statement. Where a separate consent is legally required for an optional purpose, it is requested separately and specifically.

2. Personal data and collection methods

Depending on how EVRE is used, the active deployment, and the organisation's configuration, we may process the following categories:

Account and access data

Name, surname, business email, organisation, role or title, membership, authentication, and access information.

Organisation-provided content

Scenarios, competency models, evaluation criteria, training material, procedures, and other organisational context supplied by a customer.

Simulation and evaluation data

Written or spoken responses, transcripts, conversation history, scenario events, decisions, scores, evaluation reasoning, evidence excerpts, feedback, and reporting or coaching information.

Voice data

Spoken input and the resulting transcript when voice functionality is used. The processing path and retention depend on the active deployment and speech provider.

Technical and contact data

IP address, device and browser information, session and security events, feature usage, errors, performance metadata, and information sent through demo, sales, support, or privacy communications.

Data may be collected through the website and forms, account registration or SSO, customer invitations and provisioning, use of simulations, optional voice input, technical interactions with the service, and communications with EVRE.

Users and organisations should not submit unnecessary special-category personal data, trade secrets, or highly sensitive information unless the relevant deployment has been specifically configured and authorised for that purpose. A simulation may be fictional, customer-configured, or contain information entered by a participant; it is not safe to assume that every conversation is fictional or free of company information.

3. Processing purposes and legal grounds

The purpose of processing and the legal ground for processing are separate elements. The applicable KVKK condition depends on the activity, the parties' role, and the deployment instructions.

Account, authentication, and service deliveryPerformance of a contract where applicable (Art. 5/2-c), or the condition selected by the relevant customer controller.
Security, abuse prevention, and legal protectionApplicable legal obligation, establishment/exercise/protection of a right, or legitimate interest where the statutory conditions are met (Art. 5/2-ç, e, f).
Enterprise training, evaluation, and reportingThe customer controller's documented purpose and applicable Art. 5 or Art. 6 condition; EVRE follows the customer's lawful instructions when acting as processor.
Optional voice or communicationsA separate and specific consent is used only where it is the approved and legally required ground. Microphone permission is not, by itself, a KVKK legal ground.

Where spoken or written content happens to include special-category data, that content is not made special-category data merely because it is voice. Any such processing must be assessed under the applicable Art. 6 condition and the relevant controller's instructions.

4. Voice, AI, and simulation processing

Voice mode is optional. Spoken input may be processed and transcribed by the speech-processing infrastructure configured for the active deployment. Standard Cloud deployments may use managed speech services; customer or enterprise deployments with stricter boundaries may use private or local speech-to-text infrastructure.

  • EVRE does not use voiceprint or biometric identity profiles, or employee voice cloning, as a standard product function.
  • A transcript created from spoken input may become part of the simulation record and may be used for evaluation, feedback, and authorised reporting.
  • Raw-audio transmission and retention are deployment- and provider-dependent. This disclosure therefore does not promise that raw audio is never stored or that every provider has zero retention.
  • AI services may receive simulation context, transcripts or conversation history, evaluation criteria, technical metadata, and outputs when required by the configured flow. The exact payload and provider depend on the deployment.
The downloaded ElevenLabs document set supports provider-level security and contractual capability statements, including encryption and enterprise security features. It does not prove EVRE's current plan, workspace setting, Zero Retention Mode activation, data-residency entitlement, request-history behaviour, or production deletion. Provider capability evidence is not EVRE configuration evidence.

5. Recipients and international transfers

Personal data may be disclosed to the following recipient groups for the stated purposes, subject to the active deployment and applicable customer instructions:

Customer and authorised organisation users

Assignments, training administration, evaluation, feedback, and reports within the customer's authorised scope.

Cloud, database, authentication, and application providers

Hosting, authentication, storage, delivery, and operation of the configured service.

AI and speech providers

Simulation generation, evaluation, speech-to-text, or text-to-speech only where the configured flow requires it.

Security, observability, edge, support, and communications providers

Security, reliability, incident handling, support, transactional email, and limited technical operations as applicable.

EVRE maintains relevant contractual and data-processing terms and provider-specific security documentation for the providers used in the applicable flow. This is not a blanket statement that every current or future vendor has the same agreement, location, retention, or configuration.

Where personal data is transferred outside Türkiye, the transfer is assessed under the current KVKK Article 9 regime. Depending on the flow, this may require an adequacy decision, an appropriate safeguard such as a notified standard contract or approved binding corporate rules, or a limited incidental-transfer exception where its statutory conditions are met. Regular provider transfers are not justified simply by treating use of the service as blanket explicit consent.

The detailed privacy policy describes deployment-dependent processing in more detail: Privacy Policy

6. Retention, deletion, and provider lifecycle

Retention depends on the data category, purpose, customer instructions, deployment model, applicable legal obligations, and the technical lifecycle of the systems involved. EVRE does not state one universal retention period for every deployment.

Application, account, simulation, and evaluation records

Kept only for the relevant service, customer, security, legal, or reporting purpose and according to the applicable lifecycle decision.

Raw audio

May be memory-only, provider-processed, or subject to a deployment-specific retention path. No blanket no-storage statement applies to every deployment.

Backups, security records, and provider operational records

May follow separate technical, contractual, backup, or legal lifecycles and may not disappear at the same moment as an application record.

Deletion or anonymisation

When data is no longer required, EVRE or the relevant customer controller may direct deletion, destruction, anonymisation, or removal from use. Provider and backup exceptions are handled through their applicable lifecycle.

An account-deletion request does not support a promise that every database, log, backup, provider, or legal record is physically erased immediately. The applicable controller, customer instruction, provider terms, backup lifecycle, and legal retention obligations determine the complete deletion path.

7. Your rights under KVKK Article 11

Subject to the applicable role and statutory conditions, you may have the right to:

  • Learn whether personal data is processed and request information about the processing.
  • Learn the purpose of processing and whether the data is used consistently with that purpose.
  • Learn the domestic or international third parties to whom data is transferred.
  • Request correction of incomplete or inaccurate data.
  • Request deletion or destruction where the statutory conditions are met.
  • Request notification of correction, deletion, or destruction to the relevant third parties where required.
  • Object to a result against you arising solely from analysis by automated systems.
  • Request compensation for damage arising from unlawful processing.

If EVRE acts as the direct controller for the relevant activity, send your request to EVRE. If EVRE processes the data on behalf of an enterprise customer, the customer may be the primary controller and may need to handle the request with EVRE.

For the current application channel and identity-verification information, contact [email protected]

A complaint to the Personal Data Protection Board is not a substitute for the application to the data controller. You should first apply to the relevant data controller under Article 13. If the application is rejected, the response is inadequate, or no response is given within the statutory period, you may retain the right to complain to the Board under the applicable time limits.

8. Security measures

EVRE applies technical and organisational measures intended to protect personal data against unauthorised access, use, alteration, loss, or disclosure. Controls vary by deployment and are not presented as a guarantee that every system or provider has identical settings.

  • Server-side authorisation, tenant boundaries, and role-based access controls.
  • Database Row Level Security (RLS) and application-level access checks.
  • In the reviewed 18 August 2026 production snapshot, RLS was enabled on all 75 reviewed public-schema tables. This is a dated snapshot, not a promise about every future table or deployment.
  • Privileged credentials kept server-side and multi-factor authentication for administrator access.
  • Encrypted network and storage controls provided by the relevant infrastructure providers, together with security-event and operational controls appropriate to the flow.

Provider certifications, whitepapers, and technical measures belong to the provider and are not presented as EVRE certification. For example, the reviewed ElevenLabs security materials describe provider-level AES-256 at rest and TLS 1.2 or higher in transit; they do not establish EVRE's own certification or workspace settings.

9. Contact and effective date

For questions about this disclosure or a request concerning processing for which EVRE acts as controller, contact:

KVKK applications: [email protected]

General privacy: [email protected]

This disclosure is effective as of 20 August 2026 and may be updated when EVRE's products, deployment models, providers, or legal obligations change. The current version and its last-updated date are published on this page.

For the Authority's general guidance on the disclosure duty, see kvkk.gov.tr

This disclosure is prepared under Article 10 of Law No. 6698. It should be read together with any applicable customer-specific data-processing terms.