Last updated: 20 May 2026
This notice explains how Gramavec processes your personal data as data controller under Türkiye's Personal Data Protection Law No. 6698 (KVKK). If you read Turkish, the Turkish version of this page is authoritative.
In transit
TLS 1.3
Cloud storage
Google-managed SSE
Fallback store
Fernet AES-128-CBC + HMAC
Auto-deletion
Free 24h · Pro 90d · Business 1y
Want to act on these rights now? Download a copy of your data or permanently delete your account from your settings.
Go to account settingsThe data controller is Gramavec. You may submit your applications and requests via the contact address published on our website.
Identity and contact data: your email address and authentication information.
Transaction security data: session tokens, rate-limiting records, and error logs.
Images you upload: the handwriting and signature images you submit for analysis, along with the analysis results generated from them.
Morphological features extracted from your images: the quantitative data produced by our calibrated measurement engine (pressure, slant, letter height, ratios, connection structure, etc.). In order to remain on the safe side against the possibility that these features could be broadly interpreted as biometric data within the meaning of KVKK Article 6, the relevant processing is based on your **explicit consent** (obtained at registration and before each upload).
Important scope distinction: Discovery services (personality style, learning style, handwriting awareness, partner compatibility) are offered for **entertainment and self-discovery** purposes — they are **not** an identification, diagnostic, hiring, or decision-making tool. Forensics services (signature comparison, document examination) are offered as **expert pre-screening**; the final opinion is always that of a certified expert. The Enterprise surface (membership, audit log, branding) contains only corporate management data.
We **do not intend to collect** clinical health data, religion/belief, biometric identifiers used for authentication purposes, or other special categories of data; we advise you not to upload such content.
Providing the analysis service you request, managing your account, enforcing usage limits, ensuring service security, and fulfilling the relevant legal obligations.
Your data is processed on the legal bases of being necessary for the establishment or performance of a contract, fulfilling a legal obligation, and the legitimate interest of the data controller (KVKK md. 5).
Processing that requires transfer abroad (see below) is based on your explicit consent.
Our analysis workflow relies on our own calibrated measurement engine; for certain language-understanding and image-interpretation steps, we use the Google Gemini API in the capacity of a **data processor**. In this context, the images you upload are transferred to the Gemini infrastructure located abroad for the duration of the relevant call; this transfer is based on your **explicit consent**. As committed under Gemini's policy, this call data is not retained for model training.
If you make a payment, the necessary data is shared with the payment service provider.
Uploaded raw images are retained for the duration of your subscription tier's retention window (Free: 24 hours, Professional: 90 days, Business: 1 year, Enterprise: per-organization policy) and are then automatically deleted by a scheduled cleanup task.
Structured analysis reports (numerical measurements + generated text) are retained in association with your account until you delete them or close your account. For Enterprise accounts, a shorter retention period chosen by the organization may apply.
Images are encrypted in transit with TLS 1.3; when stored on Google Cloud Storage, they are protected by Google-managed server-side encryption. When the MongoDB blob fallback path is used (development or single-tenant deployments), the raw image bytes are stored encrypted at the application level with Fernet (HMAC-authenticated AES-128-CBC) — at-rest protection is at the same level as the GCS path.
Retention periods required by legislation (e.g., statutory record-keeping obligations) are reserved.
You have the right to learn whether your personal data is being processed; to request information about it if it has been processed; to learn the purpose of processing and whether it is used in accordance with that purpose; to know the third parties to whom it is transferred domestically or abroad; to request its correction if it has been processed incompletely or incorrectly, and its erasure/destruction when the conditions are met; to request that these actions be notified to the third parties to whom the data has been transferred; to object to a result arising against you solely as a consequence of automated analysis and to request the remedy of any resulting damage.
You may submit requests concerning the rights set out above, together with information verifying your identity, to the contact address specified on our website. Your requests will be concluded as soon as possible and at the latest within the period prescribed by KVKK.