Privacy Policy
How personal data is handled across the Xohre website and platform.
- Effective date
- 12 September 2026
- Contact
- info@projera.com
1. Data controller
Projera Partners Eğitim Danışmanlık Koçluk ve Dijital Hizmetleri AŞ. is the data controller for personal data processed to operate Xohre. Address: 19 Mayıs Mah. İnönü Cad. Samlı No: 97 İç Kapı No: 7, Kadıköy, İstanbul, Türkiye. Privacy contact: info@projera.com.
This Policy should be read with the Xohre Terms of Service and, for persons protected by Turkish data protection law, the KVKK Notice.
2. Data we process
- Identity and contact data, including name, business email, account identifiers, organization, and role.
- Account and workspace data, including memberships, permissions, tenant configuration, subscription entitlements, and activity records.
- Billing metadata, including plan, transaction, subscription, invoice references, amounts, currency, and payment status. Xohre does not store complete payment-card details.
- Service and security data, including IP address, device and browser information, sign-in events, audit records, diagnostic logs, and fraud or abuse signals.
- Support communications, feedback, and information you choose to provide.
- When AI functions are enabled, prompts, outputs, attachments, model selections, and related operational metadata needed to provide the requested function.
3. Purposes and legal bases
- Create and administer accounts, subscriptions, workspaces, roles, and access rights; perform our contract and take requested pre-contract steps.
- Process payments and reconcile financial events; perform our contract and comply with legal obligations.
- Provide, secure, troubleshoot, monitor, and improve Xohre; pursue legitimate interests in operating a reliable and secure service.
- Prevent fraud, misuse, and unauthorized access; comply with legal obligations and protect legal rights.
- Respond to support requests and communicate service, security, billing, and policy notices; perform our contract and pursue legitimate interests.
- Send optional marketing communications only where a valid legal basis exists; consent may be withdrawn at any time.
5. International transfers
Some providers may process personal data outside Türkiye or the country where you are located. Where required, we use an applicable transfer mechanism and contractual, organizational, or technical safeguards under KVKK and other relevant data protection law.
6. Retention
We retain personal data only for as long as needed for the purposes described here, including the duration of the customer relationship, security and audit requirements, dispute resolution, and statutory accounting or record-keeping periods. Data is then deleted, anonymized, or isolated from ordinary use unless continued retention is legally required.
7. Security
We use access controls, tenant isolation, encryption-supported cloud services, logging, secret management, controlled software releases, and other proportionate safeguards. No online service can guarantee absolute security, and customers remain responsible for authorized-user access and lawful content handling within their accounts.
8. Your rights
Depending on applicable law, you may request information about processing; access, correction, deletion, or restriction; object to certain processing; withdraw consent; or request data portability. You may also complain to the competent data protection authority. Send requests to info@projera.com. We may verify identity before acting on a request.
10. Changes and contact
We may update this Policy as the service, providers, or legal requirements change. Material changes will be communicated where required. Questions and privacy requests may be sent to info@projera.com or to our registered address above.
