Legal

KVKK Disclosure Text

Last updated: 29 September 2026 · Version 2026-09

1. Data Controller

Under the Personal Data Protection Law No. 6698 ("KVKK"), your personal data is processed by Spiron Teknoloji A.Ş. ("Spiron") as data controller, within the scope described below.

Address: İTÜ ARI Teknokent 2, Block B, Sarıyer, Istanbul, Türkiye
Central Registration System (MERSİS) No.: 0781117179300001
Email: info@spiron.io

2. Personal Data Processed

a) When you visit the website:

  • Transaction security data: IP address, browser type, access time
  • Preferences: language and theme (kept in your browser's local storage)

b) When you submit the access request form or correspond with us:

  • Identity and contact data: name, surname, email address, company name, country and the content of any correspondence
  • Transaction security data: a hashed value derived from your IP address and the times of your requests, used to prevent abuse of the form

c) When you sign in to the online demo:

  • Your email address (with Google sign-in, the verified email of your Google account)
  • Account data: account status (pending / approved / blocked), sign-in method, sign-up, approval and last sign-in times, your analysis allowance and the number of analyses used; with Google sign-in, also whether the account is an organisational (Google Workspace) account
  • Sign-in security: the two-factor authentication secret is stored encrypted; recovery codes, session tokens and one-time sign-in codes sent by email are stored only as hashes; the number of failed attempts and any temporary lock-out time
  • Session data: session and CSRF cookies, session start and last-activity times, IP address
  • Audit records: sign-in/out, failed codes, approval and blocking actions; email addresses are written masked (e.g. k***@example.com)
  • Consent record: the date-time of your consent and the version of the text you accepted

d) When you upload audio to the demo:

  • The audio itself — processed only for the duration of the analysis; for this purpose it is written to a temporary file on the server, which is deleted as soon as the analysis ends. It is never retained and never used for model training.
  • Analysis output: synthetic-speech score, verdict, model version used, audio quality class, audio duration and processing time. This output is written to the server's operational log together with your masked email address and IP address; the log contains no audio.

Your voice is not processed as biometric data. Under KVKK Art. 6, voice qualifies as biometric (special category) data only when processed to verify or identify a person. The demo's purpose is not to identify you but to measure whether the audio was artificially generated; no identity matching, voiceprint extraction or speaker recognition is performed.

3. Purposes of Processing

  • Delivering the website and keeping it running and secure
  • Receiving, assessing and approving your request for demo access
  • Securing sign-in and operating two-factor authentication
  • Analysing whether the audio you submit is synthetic and showing you the result
  • Preventing abuse: rate limiting, analysis allowances (quotas), detection of unauthorised access attempts
  • Responding to access requests and correspondence
  • Meeting legal obligations and providing evidence in potential disputes

Your data is never sold or rented to third parties for marketing, and no automated profiling producing legal effects about you is carried out.

4. Legal Bases

The legal basis relied upon for each category (KVKK Art. 5):

  • Analysing audio: Art. 5/1 — your explicit consent. Analysis cannot start before you tick the consent box; you may withdraw consent at any time.
  • Account, sign-in and 2FA data: Art. 5/2-c — directly related to establishing and performing the demo access relationship
  • Website connection data, audit and operational logs, IP and rate-limit data: Art. 5/2-f — our legitimate interest in information security and in preventing abuse
  • Access request form and correspondence data: Art. 5/2-c — directly related to entering into a contract, and Art. 5/2-f — our legitimate interest in responding to requests
  • Statutory retention: Art. 5/2-ç — compliance with a legal obligation
  • Use of records in potential disputes: Art. 5/2-e — establishing, exercising or defending a right

Where processing relies on consent, withdrawing it stops that processing from the moment of withdrawal.

5. Transfers, Including Abroad

This disclosure covers the spiron.io website, the access request form and the online demo. The SynVoi product is deployed on the customer's own infrastructure (on-premise); in those deployments audio, analysis and records never leave the customer's network, no data is transferred to Spiron, and Spiron is not the data controller.

Audio recordings are used for no purpose other than the analysis and are never shared with any third party; they are processed only on our demo server on Google Cloud, by us, for the analysis.

The demo infrastructure runs on Google Cloud in the Germany (Frankfurt) region, on a server with no external IP address. Your demo data (account, session, security and analysis data; audio during the analysis) is therefore processed on infrastructure of a data processor located abroad within the meaning of KVKK Art. 9. Google Cloud acts as a data processor and its access is limited to what the hosting service requires.

Our website hosting and corporate email are also provided by service providers located abroad. The full list of providers and their locations, and information on the safeguards we rely on for international transfers, are set out in Sections 6 and 7 of our Privacy Policy.

If you use "Continue with Google", authentication is performed by Google and the information shared with Google during that step is subject to Google's own privacy policy. Using this option is not mandatory — the demo also offers sign-in with a one-time code sent to your email address.

Your personal data may additionally be shared with competent public authorities only where legislation requires it.

6. Method of Collection

Your personal data is collected electronically and by partly automated means through website forms, the demo sign-in screen, technical information sent by your browser, and audio you upload to the demo.

7. Retention Periods

DataPeriod
Uploaded audioNot retained — the temporary file created for the analysis is deleted as soon as the analysis ends
Analysis output (in the operational log; no audio)12 months, then deleted automatically
Account record (email, status, 2FA)Until you request deletion or the demo service ends; deleted within 30 days of your deletion request
One-time sign-in code (hash only)Valid for 10 minutes and single-use; expired codes are deleted automatically
Session cookies and session recordsCookies are valid for up to 8 hours and deleted on sign-out; expired session records are deleted automatically
Audit records (masked email, IP, time)12 months, then deleted automatically
Access request form emails2 years from the resolution of the request

All retention periods are listed in Section 8 of our Privacy Policy.

8. Data Security

  • All traffic is encrypted with TLS; HTTP requests are redirected to HTTPS
  • The server has no external IP address and is reachable only through the load balancer and a web application firewall
  • No passwords are used; two-factor authentication (a code sent to your email or your Google account + an authenticator app) is mandatory
  • Authenticator-app secrets are stored encrypted; session tokens and recovery codes are stored only as cryptographic hashes
  • Accounts are temporarily locked after repeated wrong codes; per-IP rate limits and a per-user analysis allowance apply
  • Audio is never kept in permanent storage; the temporary file created for the analysis is deleted as soon as the analysis ends
  • Access and security logs are kept; administrative actions are logged

9. Your Rights as a Data Subject

Under KVKK Art. 11 you have the right to: learn whether your personal data is processed; request information if it is; learn the purpose of processing and whether it is used accordingly; know the third parties to whom data is transferred in Türkiye or abroad; request correction of incomplete or inaccurate data; request erasure or destruction under Art. 7; request that correction/erasure be notified to third parties; object to results produced solely by automated analysis; and claim compensation for damage arising from unlawful processing.

10. How to Apply

You may send your requests, together with information sufficient for us to verify your identity, in the following ways: to info@spiron.io from the email address registered in our system or using a secure electronic signature or mobile signature; or by a signed letter to the address in Section 1. Depending on its nature, your request is concluded free of charge within 30 days at the latest; if the action involves an additional cost, the fee set by the Personal Data Protection Board may be charged. If you find our response insufficient or receive none in time, you may lodge a complaint with the Personal Data Protection Board.

To withdraw your consent or request deletion of your demo account, writing to the same address is sufficient.