Morfoz speaks every language on Earth
Legal

Privacy Policy

Last updated: 1 January 2025

This Privacy Policy explains how AİGAP YAPAY ZEKA VE ROBOTİK TEKNOLOJİ ANONİM ŞİRKETİ ("Morfoz", "we") collects, processes, and protects your personal data when you use morfoz.ai and our related services (the "Service"). This policy is prepared in accordance with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the Turkish Personal Data Protection Law (KVKK 6698).

1. Data Controller

[Coming soon — English translation in progress]

2. Data We Collect

The following personal data may be processed when you use the Service:

  • Account information: First name, last name, email address, password hash, billing address.
  • Assistant/clone training data: Text you upload, voice samples, images, product information, and other content.
  • Conversation data: Records of your assistants' conversations with end users (for quality and training).
  • Usage data: IP address, browser type, session duration, clickstream, cookie information.
  • Payment data: We do not store card details; our payment service provider (Stripe) tokenizes and processes them.

3. Purposes and Legal Basis for Processing

We process your data only for the following purposes, based on a valid legal ground:

  • Contract performance: Service provision, account management, billing.
  • Legitimate interest: Service quality improvement, fraud prevention, security.
  • Explicit consent: Marketing communications, cookies (other than necessary), optional analytics.
  • Legal obligation: Tax, accounting, response to legal requests.

4. Data Retention

We retain your account data until you delete your account. After a deletion request, all personal data is permanently deleted within 30 days; backups are cleared within 90 days at the latest. Data we are required to retain by law (e.g., invoices, tax records) is kept for the period specified in the relevant law.

5. Data Sharing

We do not sell your data. We share it with third parties only in the following cases:

  • Our processors: Cloud infrastructure providers (AWS, Cloudflare), payment processor (Stripe), email service (Postmark) — all under GDPR-compliant contracts.
  • Legal talepler: When required by a valid court order or legal obligation.
  • Transfer/merger: In case of company transfer or merger, to the new owner (with 30 days prior notice to you).

6. International Data Transfers

Morfoz infrastructure is hosted in the European Union (Germany). Data collected from Türkiye is transferred on the basis of explicit consent and standard contractual clauses; the safeguards required for cross-border transfers are provided in accordance with Article 9 of KVKK.

7. Your Rights

You have the following rights under GDPR and KVKK:

  • Access your personal data and obtain a copy
  • Request correction of inaccurate data
  • Request erasure of your data ("right to be forgotten")
  • Restrict processing or object to it
  • Port your data in a machine-readable format
  • Withdraw your consent (without retroactive effect)

To exercise these rights, write to support@morfoz.ai. We respond within 30 days.

8. Cookies and Advertising

Our site uses necessary cookies for session management, anonymous analytics cookies (with consent), and — on our public web pages and in the Klonosphere feed — advertising cookies placed by third parties. You can update your cookie preferences at any time from your browser or the cookie panel on the site.

Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this site or other sites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our site and/or other sites on the Internet. You can opt out of personalised advertising in Google Ads Settings, and learn more about how Google uses data at policies.google.com/technologies/ads. In the EEA and the UK we ask for your consent through a consent message; without consent we serve only non-personalised ads. Ads we sell directly inside Morfoz are targeted using your activity within Morfoz alone — we never share your personal data with advertisers. Our mobile applications do not display third-party ads.

9. Security

Data is encrypted with TLS 1.3 in transit and AES-256 at rest. Access is bound to strict role-based permissions and audited. We are in the SOC 2 Type II preparation process. In case of suspected breach, we notify the relevant authority and affected users within 72 hours.

10. Children's Data

The Service is not intended for individuals under 16. We do not knowingly collect data from a child under 16.

11. Policy Changes

We may update this policy from time to time. Material changes will be notified at least 30 days in advance via email and on the site.

12. Complaints

If you are not satisfied with how we handle your data, you may lodge a complaint with the Turkish Personal Data Protection Authority (kvkk.gov.tr) or, if you are in the European Union, with your local data protection authority.

13. Games and Bump (Tokuş)

The mobile app includes games and "Tokuş" (bumping two phones). When you bump, the app sends only a single motion-magnitude value and, if you have separately consented, your approximate location at that moment; location data and bump attempts are deleted within one hour. A keyed hash of your IP address is kept during the season for fraud review only. Your name, @handle and points appear on leaderboards; your city appears only if you opt in. Points are earned only, cannot be purchased and have no cash value. Prizes are delivered by the sponsor; delivery addresses are stored encrypted and deleted 90 days after the order is closed. In clone battles, text generated by your clone may be shown to other users and, only with both owners' consent, on a public page; such content can be reported in the app.

For questions: support@morfoz.ai