Last updated: 2026
This is an English translation of our Turkish security and data storage notice, provided for the convenience of our English-speaking readers. In the event of any discrepancy, the Turkish version is authoritative.
The information your company shares with us regarding its legal standing — given both its commercial sensitivity and its confidential nature — is treated as an entrustment requiring the utmost care. On this page, in our capacity as data controller, we set out in concrete, verifiable terms — rather than abstract assurances — the technical and administrative measures through which your corporate and personal data are protected.
Your company's information — the answers you provide as part of the survey and the documents you submit to us — is held in a PostgreSQL database and a separate file store, both hosted on Supabase, an infrastructure provider in widespread enterprise use. This data is encrypted both in transit and at rest, and is never transmitted over an unencrypted channel.
Access control is not limited to a single layer; rather, it is secured through two independent mechanisms. On one hand, the application layer separately verifies, for every request, whether the record in question actually belongs to the requesting account; on the other, the database itself structurally enforces this isolation through Row Level Security policies. As a result, only the account holder of a given company can access that company's data — and this holds even in the event of a possible error in the application code, since it is independently and separately safeguarded at the database level.
The content of your survey answers and the documents you submit to us is sent to OpenAI's API solely for the purpose of generating a legal risk analysis for your company, and is not processed for any other purpose nor shared with third parties. Under OpenAI's publicly published API data usage policy, data transmitted via the API — unlike data submitted through chat interfaces — is not used in any way to train AI models; this is OpenAI's standard commitment regarding its API integrations.
Every connection to our application is, without exception, encrypted end-to-end via the HTTPS protocol, and no data may be transmitted over an unencrypted connection. Authentication is carried out through Supabase Auth, an infrastructure regarded as an industry standard in its field; your password is stored only after being hashed with bcrypt, a one-way algorithm. Accordingly, the plain-text form of your password neither reaches us nor can be viewed by us under any circumstance.
Your data is retained solely for as long as your account remains active and as long as necessary to provide you with service, and is not held for any other purpose beyond that. Should you submit a request for the permanent deletion of your account or of a particular assessment, that request will be processed within a reasonable period and the relevant data will be permanently removed from our systems.
We regard data security not as a one-time obligation discharged once and for all, but as an ongoing practice of oversight and improvement. Our access policies and data-processing procedures are reviewed at regular intervals, and any area for improvement identified is implemented without delay. Our ultimate aim is to ensure that the information your company entrusts to us is safeguarded with the diligence it deserves.
If you believe you have found a security vulnerability in our systems, please report it to us at destek@hukukcheckup.com with enough detail for us to reproduce it, rather than disclosing it publicly. Good-faith, responsible reports are reviewed promptly and we will get back to you as soon as possible.
If you have any questions regarding our security practices or our data-processing activities, you are welcome to reach out to our team at destek@hukukcheckup.com.