Privacy Policy

Effective September 18, 2026

This Privacy Policy explains how ZincirX uses personal data about the people it deals with: account holders, contacts at businesses, visitors to our website and apps, and people who write to us.

ZincirX is a service for businesses. Manufacturers use it to record how their products are made and to publish a digital product passport for each production batch, which anyone can open by scanning the batch's QR code.

In this policy, “you” means the person the data is about. A “customer” is a business that has a ZincirX account, and an “account holder” is a person with their own sign-in who acts for one or more customers. “We”, “us” and “our” mean our two companies, ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. and ZincirX Inc.; section 1 explains which of them is responsible for which data.

This policy gives the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and by Article 10 of Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK). For the KVKK, it is our information notice (aydınlatma metni): section 1 names the controller, section 5 says how the data is collected, section 6 gives the purposes and legal grounds, sections 9 and 10 say to whom and why data is transferred, and section 14 sets out your rights.

How customers may use ZincirX is set out in our Terms of Service at https://zincirx.com/terms and our Data Processing Terms at https://zincirx.com/data-processing.

1. Who is responsible for your data

ZincirX is provided by two companies. ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. is a joint-stock company established in Türkiye, with its address at Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye. ZincirX Inc. is a corporation incorporated in Delaware, United States (Delaware file number 10758618), with its registered office at c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States and its principal office at Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye. The registration details of both are in the company details on our Legal Notice at https://zincirx.com/legal-notice.

The company responsible for your data, the controller (in Turkish law, the veri sorumlusu), depends on how you deal with us:

  • If you are an account holder for a customer established in Türkiye, ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. is the controller of your account data, because it is the company that contracts with and invoices that customer.
  • If you are an account holder for any other customer, ZincirX Inc. is the controller of your account data, for the same reason. ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. operates the platform for both companies and processes that data on ZincirX Inc.'s behalf under an intra-group data processing agreement.
  • If you are an account holder for customers of both kinds, each company is the controller of your account data for the customers it contracts with.
  • If you have signed up but do not yet belong to a customer, if you visit our website or apps, write to us or report content without an account, or if you are a contact at a business that is not a customer, the controller is ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., which runs the website and the apps.

The two companies are separate controllers, not joint controllers. Each is responsible for the data it controls, and ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. uses the data it processes for ZincirX Inc. only on ZincirX Inc.'s instructions.

For the content customers put into ZincirX, such as their passports, we act for the customer instead. Section 2 explains how.

For any question about this policy or your data, write to info@zincirx.com. You can also call +90 536 587 41 81, or write to either company at the address above. Our contact page at https://zincirx.com/contact lists the same email address and phone number.

We have not appointed a data protection officer. Privacy questions sent to info@zincirx.com go to the people who handle them.

Our representatives in the European Union, including for the purposes of Article 27 of the GDPR, are listed with their contact details in the company details on our Legal Notice at https://zincirx.com/legal-notice. You may contact a representative, in addition to or instead of us, about anything in this policy, and info@zincirx.com is always open to you.

2. When we act for our customers

Customers use ZincirX to keep and publish their own production records: product and process templates, production batches and their steps, photos, documents and other files, GPS positions recorded at the start and end of each step, passport information, the names and contact details of the people they give access to restricted passport information, and statistics on scans of their QR codes.

The customer decides what goes into these records and what is published, so the customer is the controller of any personal data in them. The company the customer contracts with processes that data on the customer's behalf, as its processor, under our Data Processing Terms at https://zincirx.com/data-processing. Where that company is ZincirX Inc., ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. acts as its sub-processor.

We process personal data in customer content only to provide the service to the customer and on its instructions. We do not sell it or use it for purposes of our own, such as training AI models. The exceptions are a set of totals across all customers, namely the number of templates, the number of batches and how many batches are in each status, which we publish and which identify no business, product or person, and what an account holder chooses to type into the AI assistant, described next.

The AI assistant is our own feature, not part of the service we provide on a customer's behalf. If an account holder types a customer's content, such as passport data, into it, we handle that message as controller, as section 8 explains: we send it to Google to produce the reply and do not store it.

Our apps use your device's camera and location only with your permission, and open your photo library only when you choose a photo. They use the camera to scan QR codes and take photos, and your location to record where a production step starts and ends. The photos and positions you record become part of the customer's content.

To show a recorded position as an address, our apps use the address lookup built into your phone's operating system, which sends the position to Apple on an iPhone and, on most Android phones, to Google.

If your personal data appears in a customer's content, for example because you appear in a photo, your name is in a document or you recorded a production step, the customer decides how it is used and its own privacy notice applies. Please contact that business. If you contact us instead, we will pass your request to it and help it respond.

3. Public passport pages

A passport is issued when a customer assigns it to a production batch. From then on, anyone who scans the batch's QR code, opens its link or looks it up by the product's GS1 identifiers can see the public part of the passport. The public part of each passport is also published in machine-readable form, as JSON-LD and as GS1 EPCIS 2.0 events, which anyone can read.

The public part is the manufacturer's own record of the product, such as its production steps, photos, documents and the places where steps were recorded. The customer decides what is public, and information it restricts is shown only to the people it gives access to.

Customers must not put the personal data of consumers, meaning the people who buy or use their products, on their passports without those people's explicit consent. They should also keep other personal data, such as the names of individual workers or positions that reveal where someone lives, off the public part.

A passport stays online for its availability term: 10 years, counted from the day it is issued, unless the order it came from states a different term; if that order recorded a later end date, the later date applies. It stays online even after the customer's contract ends, unless erasure was chosen for its order at checkout or the customer asks for its passports to be erased when it leaves.

When a passport's attributes, certifications or product group change, we add a new revision and keep the earlier ones instead of overwriting them. This is a design choice, not a technical limitation. Production steps, such as their notes and recorded locations, can be edited by the business, and it can remove uploaded files; those edits are not kept as revisions. Where personal data in a passport has to be corrected or removed, including from its earlier revisions, the customer can ask us by email at info@zincirx.com and we will correct or remove it.

When someone opens a passport page, we record the visit for the customer's scan statistics: the time, the browser and device description that the browser sends, and a keyed hash of the IP address instead of the address itself. These records are deleted after 12 months.

When someone opens restricted passport information, we log which passport and which access grant were used, including the name recorded for the person or organisation given access, the access level, the time and a keyed hash of the IP address, so that it can be shown who read it. This log is kept for 36 months.

If you believe a passport page contains illegal content, report it with the form at https://zincirx.com/report-content, which every passport page links to, or by email to info@zincirx.com. Your name and email address are optional; if you give an email address, we confirm that we received the report and tell you what we decided. A person reviews every report.

If we act on a report, we send the business concerned a statement of reasons, saying what we did, why, and how it can contest the decision. We reveal who made the report only where that is strictly necessary.

4. The personal data we collect

As controller, we collect the following categories of personal data.

  • Account data: your name and email address; your phone number and profile photo if you add them; your password, stored only as a hash; your two-factor sign-in settings; your language; and your role in each business you belong to.
  • Sign-in data: if you sign in with Google, Facebook or Apple, the account identifier that provider gives us and the name and email address it shares; and the session and token records that keep you signed in on the web and in our apps.
  • Business data: the details a customer gives at onboarding and afterwards, such as its name, tax number, address, phone, email, website and logo, its GS1 and customs identifiers (GLN and EORI), details of any qualified certificate it registers, documents it uploads to confirm the business, and the name and position of its contact person. Most of this is about a business, but some of it, such as a sole trader's tax number, is personal data.
  • Team data: the name, email address and position of each person a business adds as a member or who applies to join it, and their role and permissions in that business.
  • Purchase data: what was bought, when and at what price, the payment channel used, any invoice issued for the purchase, and the references returned by the payment service provider, Apple or Google. Card details go to the payment service provider and never reach us.
  • Acceptance records: which version of our terms and policies each account holder accepted and when, and the confirmation given before each purchase that the sale is final.
  • Correspondence and requests: what you tell us by email or by phone; account deletion applications and our decisions on them; reports of illegal content, with a name and email address if you choose to give them; and applications from people who want to introduce ZincirX to businesses, with what they tell us about their motivation and experience and their phone number.
  • Assistant messages: what you type into the AI assistant, which is sent to Google to produce a reply and is not stored by us.
  • Business contact data: for people at businesses we deal with or would like to deal with, their name, position, business email address and phone number, the business's public details, notes of our contacts with them and any quotes we send. For our sales emails, we also record whether an email was opened and whether its links were clicked.
  • Technical data: the IP address and the browser or device details sent with each request to our website, apps and interfaces, and records of actions taken in the service, such as adding a member to a business, which we use to deliver the service, keep it secure and fix faults.
  • Analytics data: if you accept Google Analytics, data about how you use our website, collected through Google's cookies, as described in section 15.

5. Where the data comes from

Most personal data comes from you, through the forms in our website and apps: when you sign up, complete onboarding, add colleagues, buy passports, use the assistant or write to us.

Some is collected automatically: technical data with each request, session records while you are signed in and, only if you accept, Google Analytics data through cookies.

Some comes from others:

  • A colleague who adds you to a business gives us your name, email address and position. When you sign in with that email address, you can use that business's account.
  • If you apply to join a business, we pass your name and email address to that business so that its owner can decide.
  • Google, Facebook or Apple, if you choose to sign in with them, give us an account identifier and, depending on the provider and your settings, your name and email address.
  • Payment service providers, Apple and Google tell us whether a payment went through and give us its reference.
  • For business contacts, we use public sources, such as business listings on Google Maps and in business directories, web searches, including searches made with Google's Gemini service, and the business's own website, together with what the business or the person tells us.

6. Why we use it and on what legal basis

For each purpose below we give the legal basis under the GDPR and, separately, the processing condition under Article 5 of the KVKK. Where we rely on legitimate interests, we say what the interest is.

The two laws differ on one point. The GDPR treats only duties under EU or Member State law as legal obligations, so where we keep records because Turkish or US law requires it, our GDPR basis is our legitimate interest in complying with the laws our companies are subject to, while under the KVKK it is a legal obligation.

  • Creating and running accounts, signing account holders in and providing the service: under the GDPR, Article 6(1)(b) (contract) where you are yourself the customer, for example as a sole trader, and otherwise Article 6(1)(f), our legitimate interest in providing the service your business has ordered. Under the KVKK, Article 5(2)(c) (contract), or Article 5(2)(f) (legitimate interest) where you are not a party to the contract.
  • Onboarding customers and checking that they are businesses: under the GDPR, Article 6(1)(b), or Article 6(1)(f), our legitimate interest in selling only to businesses. Under the KVKK, Article 5(2)(c), or Article 5(2)(f).
  • Selling passports and plans, taking payment and issuing invoices: under the GDPR, Article 6(1)(b), or Article 6(1)(f), our legitimate interest in completing a sale to the business you act for. Under the KVKK, Article 5(2)(c), and Article 5(2)(ç) (legal obligation) for the invoices Turkish law requires.
  • Keeping accounting, tax and payment records for the periods the law requires: under the GDPR, Article 6(1)(f), our legitimate interest in complying with the tax and commercial laws of Türkiye and the United States that apply to our companies. Where these records are kept after an account is deleted, the GDPR exception for data needed to establish, exercise or defend legal claims (Article 17(3)(e)) also applies. Under the KVKK, Article 5(2)(ç), legal obligation.
  • Recording which version of our terms was accepted, and each purchase's confirmation that the sale is final: under the GDPR, Article 6(1)(f), our legitimate interest in being able to show what was agreed. Under the KVKK, Article 5(2)(e), establishing, exercising or protecting a right.
  • Sending service emails, such as sign-in and verification messages, answers to your applications and requests, and notice of changes to our terms: under the GDPR, Article 6(1)(b), or Article 6(1)(f), our legitimate interest in keeping account holders informed about the service they use. Under the KVKK, Article 5(2)(c), or Article 5(2)(f).
  • Answering questions and support requests: under the GDPR, Article 6(1)(b) where the request concerns a contract, and otherwise Article 6(1)(f), our legitimate interest in answering the people who contact us. Under the KVKK, Article 5(2)(c), or Article 5(2)(f).
  • Handling privacy requests, including account deletion, and keeping a record of our decisions: under the GDPR, Article 6(1)(c), because the GDPR requires us to answer, and Article 6(1)(f) for the record, our legitimate interest in being able to show how we answered. Under the KVKK, Article 5(2)(ç), and Article 5(2)(e) for the record.
  • Running the AI assistant: under the GDPR, Article 6(1)(f), our legitimate interest in answering questions about ZincirX quickly for the people who choose to ask. Under the KVKK, Article 5(2)(f).
  • Keeping the service and accounts secure, preventing fraud and misuse, and fixing faults: under the GDPR, Article 6(1)(f), our legitimate interest in protecting the service, our customers and the people who use it. Under the KVKK, Article 5(2)(f).
  • Handling reports of illegal content: under the GDPR, Article 6(1)(c), because the EU Digital Services Act requires hosting services to act on such reports, and otherwise Article 6(1)(f), our legitimate interest in keeping unlawful content off the service. Under the KVKK, Article 5(2)(f).
  • Contacting businesses about ZincirX, sending them quotes and keeping a record of our contacts, including whether our sales emails are opened and their links clicked: under the GDPR, Article 6(1)(f), our legitimate interest in offering our service to businesses. Under the KVKK, Article 5(2)(f).
  • Considering applications from people who want to introduce ZincirX to businesses, and working with those we accept: under the GDPR, Article 6(1)(b), because you ask us to consider your application, and otherwise Article 6(1)(f), our legitimate interest in choosing who introduces ZincirX on our behalf. Under the KVKK, Article 5(2)(c), or Article 5(2)(f).
  • Measuring how our website is used with Google Analytics: under the GDPR, Article 6(1)(a), your consent, which the cookie rules of your country, such as § 25 TDDDG in Germany, also require. Under the KVKK, Article 5(1), your explicit consent.
  • Complying with orders from courts and authorities, and establishing, exercising or defending legal claims: under the GDPR, Article 6(1)(c) where EU or Member State law requires it, and otherwise Article 6(1)(f), our legitimate interest in meeting the laws that apply to us and protecting our rights. Under the KVKK, Article 5(2)(ç), and Article 5(2)(e).

Where we rely on legitimate interests, you can object, as explained in section 13.

Where we rely on consent, you can withdraw it at any time without affecting what we did before, and refusing consent never limits your use of the service.

We do not make decisions about anyone based solely on automated processing that produce legal effects concerning them or similarly significantly affect them.

7. What you have to give us

To open an account you must give your name, an email address and a password, or sign in with Google, Facebook or Apple.

To complete onboarding, a business must give its name, tax number, email address, phone number, address, city, country and business category. ZincirX is sold only to businesses, and onboarding cannot be completed without a tax number.

To buy passports you must give the details that the payment service provider, Apple or Google asks for.

These are contractual requirements: without them we cannot provide the service. Some of them, such as the details shown on an invoice, are also required by tax law.

Everything else, such as a phone number or photo on your own profile or a message to the assistant, is optional, and so is consent to Google Analytics.

Business contacts do not have to give us anything.

8. The AI assistant

Our website, dashboard and apps offer an assistant that answers questions about ZincirX. It is an AI system, not a person. It is our own feature, not part of the service we provide on a customer's behalf: in the dashboard and apps it is provided by the company responsible for your account data under section 1, and on our public website by ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., and the company that provides it is the controller of your messages. Its replies are produced by Google's Gemini models.

When you send a message, the messages in that conversation are sent to Google, which processes them for us to produce the reply. ZincirX does not store them. How long Google keeps them, and what it may use them for, is governed by Google's terms for the Gemini service.

Please do not include personal data, yours or anyone else's, in your messages. The assistant does not need it to answer you.

The assistant only writes answers. It makes no decisions about you, your account or your business.

The assistant is not a way to reach our team. To contact a person, write to info@zincirx.com.

We rely on our legitimate interest in answering questions about ZincirX quickly for the people who choose to ask (GDPR Article 6(1)(f); KVKK Article 5(2)(f)). Sending messages to Google in the United States is covered in section 10.

9. Who we share it with

We share personal data only for the purposes described above, with these recipients:

  • Our two companies, ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. and ZincirX Inc., as far as each needs it to run the platform and serve its customers, with ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. acting for ZincirX Inc. as described in section 1.
  • Hostinger, which provides the servers our data is stored on and our email service, and MailChannels, through which that email service delivers our emails. Where the servers are is stated on our Data Formats and Infrastructure page at https://zincirx.com/data-formats.
  • Stripe, in the United States, which processes every card payment made to ZincirX Inc. for purchases on our website.
  • Apple and Google, which take payment for purchases in our iOS and Android apps and tell us about them.
  • Google, which processes the messages sent to the AI assistant for us, to produce its replies. We also use Google's Gemini service to read our own bank statements and receipts when we keep our accounts, and a bank statement can show the name of someone who paid us.
  • Google, Facebook or Apple, if you choose to sign in with them. They confirm your identity to us and learn that you are signing in to ZincirX.
  • Google, for Google Analytics, only if you accept analytics cookies.
  • Other members of a business you belong to, who see your name, email address, position and activity in that business as their role allows.
  • The public, who see what customers publish on their passport pages.
  • People who introduce ZincirX to businesses on our behalf, for the business contacts they work with.
  • Professional advisers, such as lawyers, accountants and auditors, when they need it to advise us.
  • Courts, tax authorities, law enforcement, data protection authorities and other public bodies, when they order us to act against content or to provide information, where the law otherwise requires it, or where we need it to establish or defend a legal claim. Under the EU Digital Services Act, we must tell the authorities if we learn of information giving rise to a suspicion of a criminal offence that threatens someone's life or safety.

Recipients in Türkiye include ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., our professional advisers and Turkish authorities. Recipients abroad include ZincirX Inc., a company incorporated in the United States, for the data of the customers it contracts with; Stripe in the United States, for card payments to ZincirX Inc.; Google in the United States, to produce the assistant's replies and, if you accept, for Google Analytics; and MailChannels, to deliver our emails. They may also include Google, Apple and Facebook, when you sign in with them or buy in our apps, and hosting providers established outside Türkiye, for the services described above.

If you ask, we will tell you the names of the specific recipients of your personal data.

10. International transfers

ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. operates ZincirX from Türkiye, and ZincirX Inc. is incorporated in the United States. Neither country is in the European Economic Area. The European Commission has not adopted an adequacy decision for Türkiye, and its adequacy decision for the United States covers only organisations certified under the EU–US Data Privacy Framework.

Personal data you give us is therefore processed by ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., which runs the platform from Türkiye, on servers provided by Hostinger; where those servers are is stated on our Data Formats and Infrastructure page at https://zincirx.com/data-formats. It is also made available to ZincirX Inc. for the data it controls, and sent to the recipients listed in section 9, including Google in the United States. These transfers are protected as follows:

  • Where the GDPR applies, we transfer personal data to a country without an adequacy decision only under the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914. This covers the transfers between our two companies and to our service providers.
  • For Google, the standard contractual clauses in Google's data processing terms apply. Google LLC is also certified under the EU–US Data Privacy Framework, for which the Commission adopted an adequacy decision in Implementing Decision (EU) 2023/1795.
  • We transfer personal data out of Türkiye only on a basis that Article 9 of the KVKK allows. For regular transfers, including those to ZincirX Inc. and to our service providers abroad, that basis is the standard contract announced by Türkiye's Personal Data Protection Board, notified to the Personal Data Protection Authority within five business days of its signature. We do not rely on consent for regular transfers abroad.

You can ask for a copy of these safeguards by writing to info@zincirx.com.

11. How long we keep it

We keep personal data only for as long as its purpose requires, and then delete or anonymise it. The periods are:

  • Account data: for as long as the account exists. When an application to delete the account is completed, your personal details are removed as described in section 12.
  • Team data: for as long as the person is a member of the business. A membership is removed when the business removes the member or the member's account is deleted.
  • Business data: for as long as the customer's contract runs and the period afterwards in which it can export its data, as our Account Closure and Cancellation page at https://zincirx.com/cancellation-policy describes. The business details shown on issued passports stay online for each passport's availability term, and those on invoices are kept with the invoices.
  • Customer content, such as templates, batches, steps, files and passport information, which we hold for the customer: while the customer keeps it in ZincirX and, after its contract ends, until the retrieval period described on our Account Closure and Cancellation page at https://zincirx.com/cancellation-policy is over. Issued passports stay online for their availability term (section 3), on the customer's instruction, unless erasure was chosen for their order at checkout or the customer asks for them to be erased when it leaves.
  • Purchase, invoice and payment records: for the periods tax and commercial law require. In Türkiye, commercial books and the documents behind them are kept for ten years.
  • Acceptance records: for the life of the account and then for the limitation periods that apply to claims under the contract, even after the account is deleted.
  • Account deletion applications: three years after our decision.
  • Passport scan records: 12 months.
  • Logs of access to restricted passport information: 36 months.
  • Assistant messages: not stored by us.
  • Sessions and sign-in tokens: until you sign out, the session expires or the token is revoked, and in any case when your account is deleted. Links to Google, Facebook or Apple sign-in are removed when your account is deleted.
  • Correspondence and reports of illegal content: as long as we need them to deal with the matter and any follow-up, unless they become part of the records listed above.
  • Applications to introduce ZincirX: while we consider the application and, if we accept it, for as long as you introduce ZincirX for us.
  • Business contact data: while there is a reasonable prospect of doing business with that business. If a person objects, we stop contacting them.
  • Security and server logs: only as long as needed to keep the service secure and to investigate faults and incidents, and longer only where a specific log is needed for an incident or a legal claim.
  • Google Analytics cookies: up to two years, unless you delete them or withdraw your consent.

12. Deleting your account

You can apply to delete your account from your profile on the website, or in our mobile apps with “Delete Account” at the bottom of your profile. On the website you confirm the application with your password, so if you sign in only with Google or Facebook, apply in the app, which supports Google sign-in, or by email. The steps are explained at https://zincirx.com/account/delete-instructions. If you can no longer sign in, write to info@zincirx.com from the email address registered to your account.

We answer every application within 30 days. Our review only confirms that the application comes from you and, if you are the only owner of a business, checks whether anyone else can still manage it. It is not a discretionary decision.

You can withdraw the application at any time until it is completed.

When it is completed, we remove your name, email address, phone number, password, two-factor settings, sign-in tokens and sessions, links to Google, Facebook or Apple sign-in, profile photo, memberships of businesses and any application you made to introduce ZincirX to businesses, and the account can no longer be used to sign in. We tell you by email when this is done.

Where a business's records name you by email address as the creator of a template or batch, as the person responsible for a production step or as the person who uploaded a file, that address is replaced with one that identifies nobody.

Some records are kept, because the law or our contracts with customers require it:

  • The businesses you belonged to, with their templates, batches and passport packages, including passports not yet issued. These belong to the business, and its other members keep their access.
  • Passports already issued, which stay online for their availability term.
  • Passport revisions, which are append-only by design: every change to a passport's attributes, certifications and product group is added as a new revision and earlier revisions are kept, so that the record of what those parts of a passport said, and when, stays complete.
  • The record of who made each passport revision, which keeps the email address you used at the time. It is part of the business's record, and the business, as its controller, decides on it: ask the business to have it removed, or write to us and we will pass your request on.
  • Payment and invoice records, for the periods tax and commercial law require.
  • Records of which versions of our terms were accepted, and of each purchase's confirmation that it was final, for the limitation periods that apply to claims under the contract.
  • The record of your application: the name and email address it came from, the reason if you gave one, when it was made and how it was answered, for three years after our decision.

Deleting your account does not close a business or delete its passports. How a customer ends its contract with us is described on our Account Closure and Cancellation page at https://zincirx.com/cancellation-policy.

We decline an application only if we cannot confirm that it came from you. We then tell you why, and that you can complain to a supervisory authority or go to court, and you can apply again.

13. Your rights

Depending on the law that applies to you, you have the right to:

  • Access the personal data we hold about you and get a copy of it, including the names of the recipients we have shared it with.
  • Have inaccurate or incomplete data corrected. You can correct most account details yourself on your profile page.
  • Have your data erased. For an account, this works through the application described in section 12.
  • Restrict our use of your data, for example while we check a complaint that it is inaccurate.
  • Receive the data you gave us in a structured, machine-readable format and have it sent to another provider. “Download my data” on your web profile, or “Export My Data” in the app, gives you your account data as a JSON file. Customers can download all their passports in the zincirx.dpp format and read each one as JSON-LD and GS1 EPCIS 2.0 events, as our Data Formats and Infrastructure page at https://zincirx.com/data-formats describes.
  • Object at any time, on grounds relating to your situation, to processing based on our legitimate interests, and object to direct marketing, in which case we stop.
  • Withdraw your consent at any time, without affecting what we did before. For Google Analytics, use the “Cookie settings” link described in section 15.
  • Complain to a data protection supervisory authority, in particular in the EU Member State where you live or work or where you believe the problem arose, and, under the KVKK, to the Personal Data Protection Board, as section 14 explains.

To use any of these rights, write to info@zincirx.com, or call +90 536 587 41 81; both are on our contact page at https://zincirx.com/contact. You can write to us in English, Turkish, German or Spanish.

We answer free of charge and without undue delay. Under the GDPR we answer within one month; where a request is complex or we receive many, we may extend this by two further months, and we then tell you why within the first month. Under the KVKK we conclude applications within 30 days. Applications to delete an account are always answered within 30 days.

We ask for proof of identity only if we have reasonable doubts about who is making the request. If we do not do what you ask, we tell you why, and that you can complain to a supervisory authority and go to court.

For data a customer controls, such as the contents of a passport, we pass your request to that customer and help it respond.

14. Your rights under the KVKK

Under Article 11 of the KVKK, you have the right to:

  • Learn whether your personal data is processed.
  • Request information about it if it is.
  • Learn why it is processed and whether it is used for that purpose.
  • Know the third parties in Türkiye or abroad to whom it is transferred.
  • Have it corrected if it is incomplete or inaccurate.
  • Have it deleted or destroyed once the reasons for processing it no longer apply.
  • Have corrections and deletions notified to the third parties who received the data.
  • Object to a result against you that arises from analysis of your data exclusively by automated systems.
  • Claim compensation if unlawful processing causes you damage.

You can apply in writing to the company responsible for your data at the address given in section 1, by email to info@zincirx.com from the address you have registered with us, or, for account deletion, through the application in our website and apps. Please include the details we need to identify you and say what you are asking for.

We conclude applications free of charge, as soon as possible and within 30 days at the latest. If an action has a separate cost, such as copying a large number of pages, we may charge the fee set by the Personal Data Protection Board.

If we reject your application, you find our answer inadequate or we do not answer in time, you can complain to the Personal Data Protection Board within 30 days of learning of our answer, and in any case within 60 days of your application.

15. Cookies

Our website uses a few cookies and similar technologies. The strictly necessary ones are always on, because the website cannot work without them. Google Analytics, where we use it, runs only if you accept it.

  • Session cookie, set by ZincirX: keeps you signed in and remembers your choices, such as your language, during your visit. It expires after a period of inactivity.
  • XSRF-TOKEN, set by ZincirX: protects forms against cross-site request forgery. It expires with the session.
  • Remember-me cookie, set by ZincirX only if you tick “Remember me” when you sign in: keeps you signed in on that browser until you sign out, for up to 400 days.
  • Consent choice, kept by ZincirX in your browser's local storage: records your answer to the cookie banner so that we do not ask on every page. It stays until you change your choice or clear your browser's storage.
  • Menu setting, kept by ZincirX in your browser's local storage when you open or close the side menu in the signed-in app: remembers whether the menu is open.
  • Google Analytics cookies, _ga and _ga_ followed by an identifier, set by Google only after you accept: let Google count visits and show us how the website is used. They last up to two years, and Google, a third party, has access to them.

Until you accept, our website sends nothing to Google Analytics; its script is not even loaded. If you accept, we shorten page addresses before they are sent, so that query strings, tokens and passport identifiers are never included. Google Analytics data is linked to the identifier in its cookie, so we treat it as personal data, not as anonymous data.

We use Google Analytics only on the pages of our public website, including the sign-in pages, and never on passport pages or in the app once you are signed in.

Rejecting is as easy as accepting. You can change your choice at any time with the “Cookie settings” link in the website footer, and withdrawing consent also removes the Google Analytics cookies already set.

Our apps keep your sign-in token in your device's secure storage and your settings, such as the business you are working in, on your device, so that you stay signed in. They contain no analytics or advertising tools.

We rely on your consent for Google Analytics and, for everything else in this section, on the exemption for storage that is strictly necessary to provide the service you asked for.

16. Security

We protect personal data with measures that include:

  • Encrypted connections (HTTPS/TLS) to our website, apps and interfaces.
  • Passwords stored only as hashes, optional two-factor sign-in, and sign-in tokens for our apps that can be revoked.
  • Access inside the service limited by each person's role in each business, and access by our own staff limited to the people who need it to run, support or secure the service.
  • IP addresses in passport scan and access records kept only as keyed hashes.
  • A SHA-256 fingerprint on every uploaded evidence file, so that it can be shown the file has not changed since it was uploaded.
  • Backups of our database.
  • Card details handled by payment service providers, never by us.

No system is completely secure. If you think your account has been misused, write to info@zincirx.com straight away.

17. Children

ZincirX is a service for businesses and is not meant for children. We do not knowingly collect children's personal data. If you believe a child has given us personal data, please write to info@zincirx.com.

18. Changes to this policy

This version takes effect on September 18, 2026. We update the policy when our service or the law changes, and the date at the top always shows the version in force.

If we make a significant change, we will ask account holders to confirm that they have read the new version before they continue using the web app.

Before we use personal data for a new purpose, we will tell you.

19. Contact us

For questions about this policy or your personal data, write to info@zincirx.com or call +90 536 587 41 81. Both are on our contact page at https://zincirx.com/contact.

By post, write to ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. at Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye, or to ZincirX Inc. at Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye.

Full company details, including our representatives in the European Union and their contact details, are in the Legal Notice at https://zincirx.com/legal-notice. Whatever your question, info@zincirx.com is always open to you.