14-day free trial, no credit card required

Privacy Policy

Last updated: September 12, 2026

Draft awaiting legal review. This text may change when the review is complete.

This policy explains what personal data Geovium processes when you visit our website or use the platform, why we process it, who receives it, how long we keep it, and the rights you have under the Turkish Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR). The information notice under Article 10 of the KVKK is in section 13.

1. Who is responsible for your data

Geovium is offered by the companies shown on our website:

  • KUTBU YAZILIM BİLİŞİM TEKNOLOJİLERİ SANAYİ VE TİCARET A.Ş. (Turkey office), Küçükbakkalköy Mah. Sonay Sok. No: 6, Kat: 4, 34750 Ataşehir, İstanbul, Turkey
  • KUTBU, LLC. (US office), 651 N Broad St, Suite 201, Middletown, Delaware 19709, USA

Under this policy, the data controller is KUTBU YAZILIM BİLİŞİM TEKNOLOJİLERİ SANAYİ VE TİCARET A.Ş. (“Geovium”, “we”, “us”). For privacy questions and requests, write to privacy@geovium.com.

2. Scope: when we are controller and when processor

This policy covers visitors to our website, people who contact us, and the users of Geovium accounts.

We are the controller for account, billing, security and website data. Our customers decide what goes into their workspaces: brand names, competitors, questions, team members and connected integrations. Where that content contains personal data (for example a person's name in a question, or the phone number of a business location imported from Google Business Profile), the customer organization is the controller, and we process that data on its behalf, as its processor, to provide the service.

3. Personal data we process

  • Account data

    What it includes
    Name, email address, password (stored only as a one-way hash), language preference, profile photo if you upload one, role, email verification status, a pending email change, a scheduled account deletion and the reason you give, and, if you turn on two-factor authentication, the encrypted authenticator secret and hashed recovery codes.
    Where it comes from
    You, when you sign up, accept an invitation or edit your profile.
  • Organization and billing data

    What it includes
    Organization name, invoice type (individual or company), name or company name, billing email, country, address, city, district or state, postcode, Turkish ID number (TCKN) for individuals in Turkey, tax number (VKN) and tax office, VAT ID, and subscription, invoice and refund history. Card details are entered directly into Stripe; we only keep the card brand, the last four digits and the expiry date.
    Where it comes from
    Organization admins; Stripe.
  • Workspace content

    What it includes
    Brand names and variants, domains, competitors, questions (prompts) and topics, markets (country, region or city), scan schedules, analysis settings, tasks and briefs, and team members and invitations (name, email, role).
    Where it comes from
    Workspace members.
  • AI answers

    What it includes
    The answers AI assistants give to your questions, the sources they cite, and what we derive from them: mentions of your brand and competitors, positions, sentiment, scores and reports.
    Where it comes from
    OpenAI, Google, Anthropic, Perplexity and xAI, through their APIs.
  • Integration data

    What it includes
    If you connect them: Google Merchant Center product data, Google Business Profile locations (name, address, website, phone numbers, categories), Shopify shop details as Shopify returns them (which can include the shop owner's name, email and phone number), and the access tokens needed to read them.
    Where it comes from
    Google and Shopify, after a workspace admin connects them.
  • Security and usage logs

    What it includes
    Audit log entries (the action, who did it, the time, IP address and browser user agent), sign-in attempts (email, IP address, user agent, time), temporary login lockouts (IP address), active sessions (IP address, user agent, last activity), and daily usage and cost records per workspace.
    Where it comes from
    Created as you use the service.
  • Contact and demo requests

    What it includes
    Name, email, company, role, message, language, IP address and browser user agent.
    Where it comes from
    You, through the contact or demo form.
  • Email campaigns

    What it includes
    Email address, name, phone number if provided, delivery status and whether you unsubscribed. Opens and link clicks may be measured.
    Where it comes from
    Recipient lists we upload; Postmark.
  • Website analytics

    What it includes
    Pages visited, device and browser information and an analytics identifier, collected by Google Analytics.
    Where it comes from
    Your browser, only if analytics is enabled and you accept analytics cookies.
  • Server and error logs

    What it includes
    Request logs that include the IP address, and technical error reports.
    Where it comes from
    Our servers and, when enabled, Sentry.

4. Why we process it and on what legal basis

The articles below refer to the KVKK (Law No. 6698) and the GDPR (Regulation (EU) 2016/679). The GDPR column applies where the GDPR applies to the processing.

  • Creating and running your account and workspaces, running scans, showing results and reports

    Data
    Account, workspace, AI answer and integration data
    KVKK legal basis
    Art. 5(2)(c): necessary to conclude or perform a contract
    GDPR legal basis
    Art. 6(1)(b): contract
  • Billing, issuing invoices, and tax and accounting obligations

    Data
    Organization and billing data
    KVKK legal basis
    Art. 5(2)(c), and Art. 5(2)(ç): legal obligation
    GDPR legal basis
    Art. 6(1)(b) and 6(1)(c)
  • Keeping accounts and the service secure: sign-in protection, two-factor authentication, lockouts, session management, audit logs, backups

    Data
    Account data, security and usage logs
    KVKK legal basis
    Art. 5(2)(f): legitimate interest; Art. 5(2)(ç) where the law requires records
    GDPR legal basis
    Art. 6(1)(f): legitimate interest; 6(1)(c) where applicable
  • Service emails: email verification, password reset, invitations, scan results, weekly summaries, usage and trial reminders, payment notices

    Data
    Account and workspace data
    KVKK legal basis
    Art. 5(2)(c)
    GDPR legal basis
    Art. 6(1)(b)
  • Customer support, including viewing an account as its user sees it for a limited time

    Data
    Account and workspace data
    KVKK legal basis
    Art. 5(2)(c) and 5(2)(f)
    GDPR legal basis
    Art. 6(1)(b) and 6(1)(f)
  • Answering contact and demo requests

    Data
    Contact request data
    KVKK legal basis
    Art. 5(2)(c) (steps before a contract) and 5(2)(f)
    GDPR legal basis
    Art. 6(1)(b) and 6(1)(f)
  • Product news and marketing emails

    Data
    Email campaign data
    KVKK legal basis
    Explicit consent (Art. 5(1)) and the rules on commercial electronic messages
    GDPR legal basis
    Art. 6(1)(a): consent
  • Website analytics

    Data
    Website analytics data
    KVKK legal basis
    Explicit consent (Art. 5(1))
    GDPR legal basis
    Art. 6(1)(a): consent
  • Finding and fixing errors, operating and monitoring the service

    Data
    Server and error logs
    KVKK legal basis
    Art. 5(2)(f)
    GDPR legal basis
    Art. 6(1)(f)
  • Establishing, exercising or defending legal claims

    Data
    The data relevant to the claim
    KVKK legal basis
    Art. 5(2)(e)
    GDPR legal basis
    Art. 6(1)(f)

We do not make decisions about you based solely on automated processing that have legal effects on you or affect you similarly significantly. Scores in Geovium describe how AI assistants mention brands, not individuals.

5. Who receives your data

We share personal data only with the service providers that help us run Geovium, and only as far as each of them needs it. Some are used only when they are configured or when you use a feature.

  • Railway

    What for
    Hosting of the application, the database (PostgreSQL) and the cache and queue (Redis); volume backups
    Data involved
    All data stored in Geovium
    When
    Always
  • Stripe

    What for
    Payments, subscriptions, invoices and tax IDs; fraud prevention. While you enter a billing address, Stripe's address autocomplete can use Google Maps.
    Data involved
    Organization and billing data; the card details you enter into Stripe
    When
    When you add billing details or pay
  • Postmark

    What for
    Sending service emails and email campaigns; handling unsubscribes
    Data involved
    Name, email address, email content
    When
    Always
  • OpenAI, Google (Gemini), Anthropic (Claude), Perplexity, xAI (Grok)

    What for
    Answering your questions during scans; AI helpers that draft topics, competitors, brand variants, analysis settings and task briefs
    Data involved
    Question text, language and market; for AI helpers also brand terms, competitors, topics, sample questions and excerpts of earlier answers (see section 6)
    When
    When scans or AI helpers run
  • Google (Merchant Center and Business Profile APIs)

    What for
    Reading data from the accounts you connect
    Data involved
    Access tokens and the account IDs you enter
    When
    Only if a workspace admin connects them
  • Shopify

    What for
    Reading your shop details
    Data involved
    Store address and access token
    When
    Only if a workspace admin connects it
  • Sentry

    What for
    Error monitoring
    Data involved
    Technical error reports; by default our configuration sends no IP addresses, cookies or request bodies
    When
    When error monitoring is enabled
  • Cloudflare (R2)

    What for
    Storing nightly database backups with a second provider
    Data involved
    A full copy of the database
    When
    When off-site backups are configured
  • Google (Analytics)

    What for
    Website analytics
    Data involved
    Website analytics data
    When
    Only if analytics is enabled and you accept
  • Public authorities and courts

    What for
    Meeting legal obligations and lawful requests
    Data involved
    The data the request covers
    When
    When the law requires it

Organization admins can see the members of their organization, and workspace members can see the workspace's content. Authorized Geovium staff can access data for support and operations. Support sessions in which staff act as a user are limited in time (at most 15 minutes) and recorded in the audit log.

6. What we send to AI assistants

Measuring AI visibility means asking AI assistants the questions you define. For each scan we send the question text to the assistants you enable, with the answer language and the country, region or city you set. We do not add your brand name to the question; if a question contains a brand or a person's name, it is sent as written. When web search is on, the assistant may search the web to answer.

AI helpers (drafts of topics, competitors, brand spelling variants, analysis settings and task briefs) send the relevant workspace content to an AI provider: brand terms, domains, competitors, topics, sample questions and short excerpts of earlier answers. The Perplexity integration sends your workspace name to ask which sources Perplexity would cite.

These calls use Geovium's API accounts or, if your workspace adds its own API key, your own account with that provider; in that case your agreement with the provider also applies. The providers process this data under their own API terms. Do not put special categories of personal data (such as health data) or confidential information into questions.

7. International transfers

Our hosting provider and the AI, email, payment and monitoring providers listed above are outside Turkey; most of them are based in the United States, outside the European Economic Area. Using Geovium therefore involves transferring personal data abroad.

Transfers from Turkey are made under Article 9 of the KVKK, on the basis of the appropriate safeguards it lists (such as standard contracts) or, where they apply, its exceptions for occasional transfers. Transfers of data subject to the GDPR are made under Chapter V of the GDPR, for example on the basis of adequacy decisions or the European Commission's Standard Contractual Clauses. You can ask which safeguard applies to a recipient at privacy@geovium.com.

8. How long we keep data

We keep personal data only as long as the purposes above require. The current periods are:

  • Account data

    Retention
    While the account exists. When you delete your account, a 30-day grace period starts (you can cancel the deletion during it); then the account is deleted.
  • Organization, workspace and billing data

    Retention
    While the organization exists. When the last user's account is deleted, the organization is permanently deleted with its workspaces, and its customer record and saved cards at Stripe are removed.
  • Stored AI answers

    Retention
    180 days
  • Score history (daily and weekly snapshots)

    Retention
    730 days
  • Audit logs

    Retention
    365 days
  • Sign-in attempts and login lockouts

    Retention
    30 days
  • Sessions

    Retention
    Until you sign out or the session expires; with “Remember me”, up to 30 days
  • Daily usage and cost records

    Retention
    400 days
  • Sample records read from connected integrations

    Retention
    30 days
  • Technical job and integration logs

    Retention
    30 to 90 days
  • Results of AI helpers

    Retention
    7 days
  • Data export files

    Retention
    7 days from the request
  • Email campaign recipients

    Retention
    180 days after the campaign ends; unsubscribe records are kept so that we do not email you again
  • Contact and demo requests

    Retention
    No automatic deletion period has been set yet; we delete a request when you ask us to
  • Backups

    Retention
    Database backups are kept for up to 89 days (daily backups 6 days, weekly 27 days, monthly 89 days) and off-site copies for 14 days. Deleted data can remain in backups until they expire; backups are only used to restore the service.

Legal retention obligations, for example for invoices under tax law, take precedence over these periods. Server logs and error reports are kept for the periods set by our hosting and monitoring providers.

9. How we protect data

  • All traffic is encrypted in transit (HTTPS).
  • Passwords are stored only as one-way hashes. Two-factor recovery codes are hashed and the authenticator secret is encrypted.
  • API keys, integration credentials and access tokens are stored encrypted and only ever shown masked.
  • Optional two-factor authentication with an authenticator app, and a list of active sessions that you can sign out of.
  • Rate limits on sign-in and temporary lockouts after repeated failed attempts.
  • Role-based access at organization and workspace level, with each organization's workspaces kept separate.
  • An audit log of sign-ins, security changes, invitations, billing changes and exports.
  • Daily database backups and a tested restore procedure.

No system is completely secure. If a breach affects your personal data, we will inform you and the competent authorities as the law requires.

10. Your rights

Under the KVKK (Article 11)

You have the right to:

  • learn whether your personal data is processed;
  • request information about the processing if it is;
  • learn the purpose of the processing and whether the data is used for that purpose;
  • know the third parties in Turkey or abroad to whom the data is transferred;
  • ask for incomplete or inaccurate data to be corrected;
  • ask for the data to be deleted or destroyed under the conditions of Article 7;
  • ask for a correction, deletion or destruction to be notified to the third parties the data was transferred to;
  • object to a result against you that arises from analysis exclusively by automated systems;
  • claim compensation if you suffer damage from unlawful processing.

Under the GDPR (Articles 15 to 22)

  • access to your data (Art. 15);
  • rectification (Art. 16);
  • erasure (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • objection to processing based on legitimate interest, and to direct marketing at any time (Art. 21);
  • not to be subject to decisions based solely on automated processing (Art. 22);
  • withdrawing consent at any time, without affecting processing carried out before (Art. 7(3)).

How to exercise them

  • Correction: change your name and language in the account settings. Changing your email address needs confirmation from the new inbox. Organization admins can edit the organization and billing details.
  • Export: organization admins can prepare a full export (JSON) of the organization's data in the billing settings. We email a download link; the file is kept for 7 days. Secrets such as password hashes, two-factor data, API keys and integration credentials are not included.
  • Account deletion: in the account settings. Deletion is scheduled for 30 days later and can be cancelled until then. If other people remain in the organization, its owner must transfer ownership first. When the last user is deleted, the organization is deleted too.
  • Email preferences: organization admins can turn off scan result, weekly summary and usage warning emails. Every marketing email contains an unsubscribe link.
  • Cookies: change your analytics choice at any time with “Cookie settings” in the website footer.
  • Anything else: email privacy@geovium.com. For applications under the KVKK you can also write to our address in section 1 or use the other methods in the Communiqué on the Procedures and Principles of Application to the Data Controller.

We may ask you to confirm your identity. We answer within 30 days (KVKK), or within one month, which can be extended by two months for complex requests (GDPR), free of charge unless the law allows a fee. If your request concerns workspace content of a customer organization, we pass it on to that customer or help it respond.

11. Right to complain

If you are in Turkey, you can complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) after applying to us: within 30 days of learning our answer, or within 60 days of your application if we do not answer (KVKK Article 14).

Where the GDPR applies, you can complain to the data protection supervisory authority of the EU or EEA country where you live or work, or where the alleged infringement took place.

If you contact us first at privacy@geovium.com, we will try to resolve your concern.

12. Children

Geovium is a service for businesses and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children; if you believe a child has given us personal data, contact us and we will delete it.

13. KVKK information notice (Aydınlatma Metni)

This section is the information notice under Article 10 of Law No. 6698 and is read together with the sections of this policy it refers to.

  • Data controller: KUTBU YAZILIM BİLİŞİM TEKNOLOJİLERİ SANAYİ VE TİCARET A.Ş., Küçükbakkalköy Mah. Sonay Sok. No: 6, Kat: 4, 34750 Ataşehir, İstanbul (section 1).
  • Purposes of processing: section 4.
  • Recipients and purposes of transfer: the service providers in section 5, and public authorities where the law requires; transfers abroad are described in section 7.
  • Method and legal basis of collection: personal data is collected electronically through the forms on our website and in the application, cookies, the integrations you connect, the AI providers and Stripe, on the legal bases of Article 5 shown in section 4 (explicit consent for analytics and marketing).
  • Your rights under Article 11 and how to apply: section 10.

14. Changes to this policy

We may update this policy when our service or the law changes. The date at the top shows the current version. We will announce material changes by email or in the application before they take effect.

15. Contact

Privacy questions and requests: privacy@geovium.com. Postal address: KUTBU YAZILIM BİLİŞİM TEKNOLOJİLERİ SANAYİ VE TİCARET A.Ş., Küçükbakkalköy Mah. Sonay Sok. No: 6, Kat: 4, 34750 Ataşehir, İstanbul, Turkey.