Last Updated: September 13, 2026
At Growtyx ("Growtyx", "Platform", "Service", "we", "us" or "our"), we take the privacy and security of personal data seriously.
This Privacy and Cookie Policy ("Policy") explains what personal data is collected, for what purposes it is processed, with whom it may be shared, for how long it may be retained, and what rights data subjects have, when using the Growtyx website, application and SaaS services.
Growtyx is primarily a B2B SaaS platform aimed at businesses, professional users, and their authorized employees, representatives or consultants.
For personal data processed in connection with the provision of Growtyx's own services, the management of user accounts, communication, billing, security and the fulfillment of legal obligations, Growtyx or [Full Name], the legal provider of the service, may act as the Data Controller under applicable law.
For personal data that the User transfers to the Growtyx Platform about their own customers, visitors, employees or other third parties, or that the User provides to Growtyx through authorized integrations, the User may act as the Data Controller and Growtyx as the Data Processor, under the agreement between the parties and applicable law.
In this context, the User represents and warrants that:
Growtyx, in its capacity as Data Processor, processes personal data in accordance with the User's instructions and for the purpose of providing the Service under the agreement between the parties.
Depending on the nature of the Service and how the User uses the Platform, Growtyx may process the following categories of data:
The following, provided by the User, may be processed:
In connection with the subscription and service relationship, the following may be processed:
Holding credit card details within Growtyx's own systems may not be necessary, depending on the technical structure of the payment service used. Where payment information is processed directly by the payment institution or the Merchant of Record, the relevant data is not stored on Growtyx's payment infrastructure.
Depending on the third-party services the User connects to Growtyx and the permissions they grant, the following may be processed:
Growtyx aims to access only the data that is necessary for the Service and that the User has authorized.
The following technical and usage data may be collected automatically while the Platform is used:
This data may be used to secure the Service, detect errors, monitor performance, prevent misuse, and improve the Service.
When an integration with a third-party service is established, OAuth authorization data, access tokens, API keys or similar technical authentication data may be used, depending on the technical structure of the integration.
Growtyx aims not to request or store user passwords for third-party services. That said, the specific technical authorization data processed may vary depending on the integration method used.
Personal data processed by Growtyx may be used, within the framework of applicable law, for the following purposes:
Where applicable, the following legal bases under Article 5 of KVKK (Turkey's Law on the Protection of Personal Data) may be relied upon for processing personal data:
Where a specific processing activity legally requires explicit consent, the necessary consent is separately obtained.
The User is responsible for ensuring that the information, data, integrations, connections and access rights they provide to Growtyx are accurate, current and lawful.
Except where resulting from Growtyx's own fault, Growtyx is not responsible for outcomes arising from incomplete, incorrect, outdated or unauthorized information, data or access provided by the User.
When an integration with a third-party service is established, data may be received by Growtyx from that service, or certain data may be transferred from Growtyx to that service, depending on the technical structure of the integration and the permissions granted by the User.
Growtyx processes personal data for specified, explicit and legitimate purposes, and to the extent required by those purposes.
Growtyx does not sell personal data without a legal basis, nor does it use personal data as part of an independent data brokering activity.
Sharing User data with third-party service providers is limited to necessary purposes such as providing the Service, ensuring its security, operating the technical infrastructure, carrying out payment and communication processes, running AI-powered features, or fulfilling legal obligations.
Where personal data is anonymized or sufficiently aggregated such that it can no longer be associated with an identified or identifiable natural person, this data may be used to analyze service performance, conduct statistical studies, develop products and features, and make security/performance improvements.
Growtyx may make use of third-party service providers in various categories in order to provide the Service.
These may include:
Third-party service providers acting on Growtyx's behalf have their access to personal data limited to what the service they provide requires.
Where applicable, agreements governing confidentiality, data security and data processing obligations are entered into with these service providers.
An up-to-date list of sub-processors may be published separately.
Some of the infrastructure, hosting, payment, communication, analytics or AI services Growtyx uses may be located abroad, or data may be processed on systems located abroad.
In such cases, the transfer of personal data abroad is carried out within the framework of Article 9 of KVKK and other applicable legislation.
Depending on the nature of the transfer, an adequacy decision, appropriate safeguards, standard contractual clauses, or other transfer mechanisms provided for under applicable law may be relied upon.
Where a standard contract is used for the international transfer of data, the necessary procedures — including notifying the relevant Turkish Data Protection Authority as required by law — are carried out separately.
International data transfers are not intended to rely solely on a general and unlimited "explicit consent" mechanism.
Growtyx retains personal data for as long as necessary for the purpose of processing and to the extent required by applicable legal obligations.
Retention periods may vary depending on the category of data, the purpose of processing, the service relationship with the User, legal obligations, and technical requirements.
We aim not to retain the following, generated during the technical operation of the Crawler and the Platform, for longer than necessary:
Where a specific retention period is defined for a particular type of log, that period may be described in the relevant system or service documentation.
Account, subscription, billing and transaction records may be retained for as long as necessary to carry out the service relationship and to fulfill related legal obligations.
Where certain records need to be kept longer for reasons such as tax, accounting, commercial recordkeeping, or dispute resolution, those records may be retained until the end of the applicable legal period.
When the User closes their account or the service relationship ends, data is deleted, anonymized or removed from access to the extent possible.
That said:
may be retained for their applicable retention periods.
Growtyx aims to implement technical and administrative measures appropriate to the nature and risk level of the Service, in order to prevent the unlawful processing of personal data, unauthorized access, and data loss.
These measures may include access authorization, encryption, secure authentication, access controls, logging, security monitoring, infrastructure security, and other necessary technical/administrative controls.
The technical security mechanisms Growtyx uses may change and be improved over time.
For this reason, no binding commitment is made here that any specific software, library or security technology will continue to be used indefinitely.
If personal data is unlawfully obtained by others, or a personal data security breach occurs, Growtyx fulfills the notification obligations under applicable law in cases where it acts in its own capacity as Data Controller.
Under KVKK, the Turkish Data Protection Authority's practice — requiring notification to the Board without delay and within 72 hours at the latest from when the data controller becomes aware of the breach — is taken into account. Notifications to affected data subjects are also made based on the nature of the incident and applicable law.
In cases where Growtyx acts in its capacity as Data Processor, the relevant data breach is reported to the User, as Data Controller, within the procedure and timeframes set out in the agreement between the parties, and the necessary cooperation is provided.
Growtyx uses data accessed through Google APIs — including Google Search Console and Google Analytics 4 (GA4) — solely to provide the relevant integration, organic search analysis, performance reporting, conversion analysis, and to provide or improve the related features offered in the User interface.
When a Google account is connected, only the data authorized by the User and necessary for Growtyx to provide the relevant feature is accessed.
This may include, for example:
Data obtained from Google APIs may be used to provide the User with reports, charts, analysis and related performance features on the Growtyx Platform.
We do not share, transfer, or disclose any Google user data (whether raw, derived, or anonymized) to any third parties, data brokers, or advertising platforms under any circumstances. Data is only used to provide the app's core features.
Data obtained from Google APIs is not used to train an independent AI or machine learning model in any way not permitted by Google's applicable API user data policies.
Where Google data is used in Growtyx's AI features, that use is limited in a manner compliant with the Google API Services User Data Policy and applicable Limited Use requirements. Google's policies limit the use of data obtained to the appropriate features provided to the relevant user, and prohibit data transfer except in certain specified exceptions.
If the Google integration is removed, Growtyx's access to the relevant Google account is terminated.
We retain Google user data only for as long as your account is active to provide the requested services. When you disconnect your Google integration or delete your Growtyx account, all associated Google user data is permanently and irrevocably deleted from our servers within 30 days.
Data held in technical backups may be retained for a longer period as part of the applicable backup and retention cycles.
The use and transfer of raw or derived user data that Growtyx receives from Google APIs is subject to policies applicable to Growtyx as set by Google, including the Google API Services User Data Policy.
Limited Use Statement:
Growtyx's use and transfer to any other app of information received from Google APIs (Workspace or other APIs) will adhere to the Google User Data Policy, including the Limited Use requirements.
Growtyx may use cookies and similar technologies to ensure the website and Platform function securely and correctly.
Cookies necessary for session management, authentication, security, and the core functioning of the Platform may be used.
To the extent these cookies are necessary for the Service to function, they may not be capable of being disabled by the user.
Growtyx may use analytics technologies to understand how the website and Platform are used, measure performance, and improve the user experience.
Where the use of analytics cookies requires explicit consent under applicable law, the necessary consent mechanisms are implemented.
Users can also control or block cookies through their browser settings. However, disabling certain cookies may cause certain features of the Platform to stop working.
Access to personal data within Growtyx, or at third-party service providers acting on Growtyx's behalf, is limited to what is necessary to provide or secure the Service, and is granted in line with authorization principles.
For data requiring special protection, such as Google API user data, the relevant service provider's and platform's own data usage policies are additionally complied with.
Personal data may be shared with the relevant authority or parties, only to the extent necessary, where a legally valid reason exists, such as:
Under Article 11 of Turkey's Law No. 6698 on the Protection of Personal Data, to the extent applicable, you have the right to:
You may submit your requests under KVKK through the contact channel below:
Email: hello@growtyx.com
Data Controller: [Full Name]
Address: [Notice / contact address]
Requests are evaluated within the procedure and timeframes set out in KVKK and its related secondary legislation.
Growtyx may update this Privacy and Cookie Policy due to changes in its services, data processing activities, the technologies used, or applicable law.
If changes are made that materially affect the purposes of processing personal data or the rights and obligations of users, additional notice may be given via the Platform or by email, where appropriate.
The current version of the Policy is published on the Growtyx website or Platform.
If you have questions about this Policy, your personal data, or your rights under KVKK, you can contact us through the following channel:
Growtyx
Email: hello@growtyx.com
Data Controller: [Full Name]
Address: [Address]