LEGAL DOCUMENT
Privacy Policy and KVKK Disclosure Notice
Explains why and on what legal basis we process your personal data on aiorvision.com and in the customer portal, with whom we share it, how long we keep it, how we protect it, and how you can exercise your rights.
Last updated: 30 September 2026
- Effective
- 2026-09-30
- Basis
- Law no. 6698 arts. 4, 5, 9, 10, 11, 12, 13 · Communiqué on the Disclosure Obligation · Communiqué on Applications to the Data Controller
This English text is a translation. In case of any discrepancy, the Turkish version prevails.
1. Data Controller
Your personal data is processed by AIOR TEKNOLOJİ LİMİTED ŞİRKETİ (AIOR Technology Limited Company) as data controller. Full identity, address, registered e-mail and contact details are in the “Service Provider Details” section at the end of this page.
aiorvision.com is the website and customer portal of AIOR Vision, a brand of AIOR Teknoloji Limited Şirketi.
This text fulfils the disclosure obligation under article 10 of the Turkish Personal Data Protection Law no. 6698 (“KVKK”) and follows the same principles as AIOR's Personal Data Protection Policy in force.
2. Who This Notice Covers
This notice covers the personal data of:
- visitors to the aiorvision.com website;
- people who contact us through the contact form, by e-mail or by phone;
- people who use the customer portal on behalf of a customer organisation that has a contract with AIOR (portal users).
Our role for the production data transferred from customer stations to the portal is explained separately in section 11.
3. Personal Data We Process
| Data category | Examples | Whose data |
|---|---|---|
| Identity | Name and surname | Form senders, portal users |
| Contact | E-mail address; optionally a phone number | Form senders, portal users |
| Professional | The name of your company or organisation | Form senders, portal users |
| Request | The topic you choose on the form and the text of your message; our correspondence | Form senders |
| Customer account | The customer organisation you belong to, whether the account is active, the time of the last sign-in | Portal users |
| Transaction security | IP address, time of access, requested address and browser details; portal session records; sign-in, failed sign-in, account lock and password change records; an irreversible hash of the password | All visitors, portal users |
Your password itself is never stored; only an irreversible hash of it is kept.
We do not request special categories of personal data (health, biometric, religion, membership, etc.); our service processes do not require them. Please do not include such data in forms or messages.
4. Purposes of Processing
- Requests and offers: answering the requests you send through the contact form, by e-mail or by phone; running demo, technical information and offer processes.
- Providing the customer portal: opening accounts for the people a customer authorises, verifying sign-ins and ensuring that each user can access only their own organisation's data.
- Information security: preventing unauthorised access, detecting abuse and attacks, keeping logs.
- Legal obligations: record-keeping and retention duties under the law, and duly made requests from competent authorities.
- Disputes: establishing, exercising or protecting a right.
5. Legal Bases
- Necessary for the formation or performance of a contract (KVKK art. 5/2-c): answering your request and the offer process; providing the portal account under the customer contract.
- Compliance with a legal obligation (art. 5/2-ç): record-keeping duties and duties to inform competent authorities.
- Legitimate interests (art. 5/2-f): security of the site and portal infrastructure, prevention of abuse, keeping portal access and security records.
- Establishment, exercise or protection of a right (art. 5/2-e): dispute and claim management.
- No processing relies on consent; if optional cookies or promotional messages are ever added, we will ask for your explicit consent separately and in advance.
6. Collection Methods
Data is collected through the contact form on aiorvision.com, the customer portal, e-mail and phone communication, and server and application logs, by automated and partly automated means.
7. Transfers and Recipients
- Data is shared only to the extent necessary to provide the service and on a legal basis: with the data centre provider that hosts the site and the portal, and with the e-mail infrastructure provider that delivers contact form notifications.
- The site and the portal are hosted in a data centre in the European Union (OVHcloud); hosting therefore constitutes a transfer abroad.
- Transfers abroad are made under article 9 and decisions of the Data Protection Board; where required, standard contractual clauses or undertakings are used.
- Personal data is disclosed to competent public authorities only where the law provides for it and upon a duly made request.
- In the customer portal each user sees only their own organisation's data; one customer's data is never shared with another.
- Data is never sold or rented to third parties for advertising purposes.
8. Retention and Destruction
| Data | Retention period |
|---|---|
| Contact form entries and correspondence | 2 years from the last correspondence; if the request leads to a contract, the retention period of contract records applies. |
| Server access logs | 90 days |
| Portal account | For the term of the customer contract; 30 days after the account is closed |
| Portal session records | A session is valid for at most 12 hours; session records are kept for 90 days. |
| Portal security and audit records (sign-in, failed sign-in, account lock, password change) | 1 year |
- Server backups are kept for 3 days; deleted data leaves the backups within that cycle.
- Expired data is deleted, destroyed or anonymised; destruction activities are recorded.
- Where a dispute or a request from a competent authority is pending, the relevant records may be kept until it is concluded.
9. Data Security
We apply technical and organisational measures to protect personal data against unauthorised access, loss and alteration. The measures we apply are described on the Data Security page.
10. Data Breach Management
- On detection of a personal data breach, notification is made to the Personal Data Protection Board as soon as possible and in any case within 72 hours.
- Affected data subjects are informed as soon as possible.
- Every breach is recorded; root-cause analysis is performed and corrective action is applied.
11. Customer Production Data
Production data transferred from customer stations to the portal (cycles, part and barcode IDs, weld records, OEE, 3D part models) belongs to the customer and is designed to contain no personal data.
AIOR processes this data only on the customer's instructions and to provide the service. Should personal data be present, AIOR acts as a data processor and a data processing agreement is signed where required. When the contract ends, the data is returned to the customer or deleted.
12. Your Rights and How to Apply
Under article 11 you have the right to learn whether your data is processed; to request information if it is; to learn the purpose and whether it is used accordingly; to know the third parties to whom it is transferred domestically or abroad; to request rectification if incomplete or inaccurate; to request erasure or destruction where conditions are met; to request that rectification/erasure be notified to third parties; to object to an adverse outcome produced solely by automated analysis; and to claim compensation for damages arising from unlawful processing.
- You may submit requests in writing to our company address, by registered e-mail (KEP) to aior@hs01.kep.tr, or to hi@aior.com from an e-mail address you have previously given to AIOR and that is in our records (for example, the address of your portal account).
- Your request is concluded free of charge within 30 days at the latest; where the process incurs an additional cost, the fee in the tariff set by the Board may be charged.
- So that we can verify your identity, please clearly state your name, contact details and the subject of your request.
- If your request is rejected or not answered in time, you retain the right to complain to the Personal Data Protection Board.
14. Changes
This text is updated when legislation or processes change; the current version is published on this page with its effective date. For material changes, consent is re-obtained where required for consent-based processing.
Service Provider Details
- Legal name
- AIOR TEKNOLOJİ LİMİTED ŞİRKETİ
- Address
- Geçit Mahallesi 6. Gümüş Sokak No: 6
Balkar Plaza A Blok Kat: 1 Daire: 2
Osmangazi / Bursa / Türkiye - Tax office / Tax ID
- Osmangazi Tax Office · 0102359120
- MERSIS
- 0010235912000001
- Trade registry no
- 137841
- Chamber registry no
- 147909
- hi@aior.com
- Registered e-mail (KEP)
- aior@hs01.kep.tr
- Phone
- +90 850 309 80 80
All official registry data: Company details (opens in a new tab)