Privacy Policy
Last updated: 29 September 2026 · Version 2026-09
At a glance
- We do not use advertising or tracking cookies, third-party analytics or social-media pixels.
- Audio you upload to the demo is never retained: it is processed only temporarily for the analysis and deleted as soon as the analysis ends. It is never used for model training.
- We do not sell your personal data or share it with third parties for marketing.
- SynVoi is deployed on the customer's own infrastructure; in those deployments audio and results never leave the customer's network.
- The online demo runs in Germany (Google Cloud, Frankfurt). Every case in which data is processed outside Türkiye is listed in Section 7.
1. Scope
This Privacy Policy explains how Spiron Teknoloji A.Ş. (“Spiron”, “we”) processes your personal data when you use the spiron.io website, the access request form on the site and the online demo offered at spiron.io. Further details are also set out in our KVKK Disclosure Text; the two documents should be read together.
Deployments of our products for customers are outside the scope of this policy; data processed in those deployments is governed by our agreement with the customer. SynVoi is deployed on the customer's own infrastructure (on-premise): the audio, analysis results and logs it processes stay within the customer's network and are not transferred to Spiron; the customer is the data controller for that data.
2. Data Controller
For the purposes of the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where applicable, the EU General Data Protection Regulation (“GDPR”), the data controller is:
- Legal name: Spiron Teknoloji A.Ş.
- Address: İTÜ ARI Teknokent 2, Block B, Sarıyer, Istanbul, Türkiye
- Central Registration System (MERSİS) No.: 0781117179300001
- Email: info@spiron.io
3. Personal Data We Process
3.1 When you visit the website
- Connection and security data: IP address, browser and operating-system information, the page requested and the time of access. This data is processed by our hosting provider's servers and content delivery network (CDN) to deliver the site to you and to protect it.
- Preferences: your language and theme choice and whether you have dismissed the information banner. These are kept only in your browser's local storage and are not sent to us.
3.2 When you submit the access request form
- First name, last name, email address, company name and country.
- A hashed value derived from your IP address and the times of your requests, used to prevent abuse of the form.
3.3 When you sign in to the online demo
- Account: your email address (with Google sign-in, the verified email address of your Google account), account status (pending, approved or blocked), sign-in method, registration, approval and last sign-in times, your analysis allowance and the number of analyses used; with Google sign-in, also whether the account is an organisational (Google Workspace) account.
- Sign-in security: your authenticator-app secret (stored encrypted); recovery codes, session tokens and one-time sign-in codes sent by email (stored only as cryptographic hashes); the number of failed attempts and any temporary lock-out time.
- Session records: session start and last-activity times and IP address.
- Security log: sign-in, sign-out, failed code attempts, approval and blocking actions. Your email address is masked in these records (e.g. k***@example.com); the IP address and time are recorded.
- Consent record: the time consent was given and the version of the text you accepted.
3.4 When you analyse audio in the demo
- Audio file: processed only for the duration of the analysis; for this purpose it is written to a temporary file on the server, which is deleted as soon as the analysis ends. It is never retained, never used for model training and never shared with third parties.
- Analysis output: synthetic-speech score, verdict, model version used, audio quality class (e.g. narrowband), audio duration and processing time. This output is written to the server's operational log together with your masked email address and IP address; the log contains no audio.
Your voice is not processed as biometric data. A voice constitutes biometric (special category) personal data only when it is processed to verify or identify a person. The purpose of the demo is not to identify you but to measure whether the audio was artificially generated; no identity matching, voiceprint extraction or speaker recognition is performed.
Only upload recordings you are entitled to upload. If you analyse a recording containing another person's voice, you are responsible for having the necessary legal basis to do so. Please do not upload recordings containing special category data such as health information.
3.5 When you correspond with us
- Your name, email address and the content of the correspondence.
4. Purposes and Legal Bases
| Purpose | Data | Legal basis |
|---|---|---|
| Delivering the website and keeping it running and secure | Connection and security data | KVKK Art. 5/2-f (legitimate interests) · GDPR Art. 6(1)(f) |
| Assessing and responding to access requests | Form data, correspondence | KVKK Art. 5/2-c (entering into a contract) and 5/2-f · GDPR Art. 6(1)(b) and 6(1)(f) |
| Opening your demo account; running sign-in and two-factor authentication | Account, sign-in security and session data | KVKK Art. 5/2-c · GDPR Art. 6(1)(b) |
| Analysing the audio you submit and showing you the result | Audio (temporarily, only during the analysis), analysis output | KVKK Art. 5/1 (explicit consent) · GDPR Art. 6(1)(a) |
| Preventing abuse: rate limits, analysis allowance, detection of unauthorised access | IP address, security log, operational log | KVKK Art. 5/2-f · GDPR Art. 6(1)(f) |
| Complying with legal obligations | Relevant data | KVKK Art. 5/2-ç · GDPR Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Relevant records | KVKK Art. 5/2-e · GDPR Art. 6(1)(f) |
You may withdraw the explicit consent you give for audio analysis in the demo at any time by writing to info@spiron.io; withdrawal does not affect the lawfulness of processing carried out before it. We do not use your data for automated decisions or profiling that produce legal effects concerning you.
5. Cookies and Local Storage
We do not use cookies for advertising, tracking or analytics. The items below are used only to make the site and the demo work and to remember your preferences:
| Name | Type | Purpose | Duration |
|---|---|---|---|
spiron-lang | Local storage | Your language preference | Until you clear it |
spiron-theme | Local storage | Your theme preference | Until you clear it |
spiron-consent | Local storage | That you dismissed the information banner | Until you clear it |
spiron-demo-surum | Local storage (demo) | The model version you selected | Until you clear it |
spv_g | Session storage (demo) | Security values during “Continue with Google” | Removed on return from sign-in or when the tab is closed |
spv_session | Cookie (demo; HttpOnly, Secure) | Recognises your session | Up to 8 hours; deleted on sign-out |
spv_session_csrf | Cookie (demo; Secure) | Protection against cross-site request forgery (CSRF) | Up to 8 hours; deleted on sign-out |
When our hosting provider's security layer detects unusual traffic, it may ask your browser to complete a brief automatic check; this check may use the provider's technical cookies.
If you choose “Continue with Google”, you are redirected to Google's sign-in page; cookies on that page are governed by Google's own policy. Unless you choose this option, no Google sign-in or tracking service is contacted. Fonts and interface components are self-hosted; no requests are made to external font or library services.
We do not currently use web analytics. If we start using a cookieless analytics tool in the future, we will update this policy beforehand.
6. Sharing and Service Providers
We do not sell your personal data or share it with third parties for marketing. To provide the service we work with the providers below, which process data only on our behalf and to the extent the service requires (data processors):
| Provider | Service | Data processed | Location |
|---|---|---|---|
| Hostinger | Website hosting, content delivery network (CDN), forwarding the access request form by email | Connection and security data, form data | Hostinger data centres outside Türkiye; CDN edge servers in regions close to the visitor |
| Google Cloud | Online demo infrastructure: server, load balancer, firewall | Connection data; demo account, session, security and analysis data; audio (temporarily, only during the analysis) | Germany (Frankfurt) |
| Microsoft 365 | Corporate email; sending demo sign-in code emails | Form emails, correspondence, sign-in code emails (your email address and the code) | Microsoft data centres outside Türkiye |
If you choose “Continue with Google”, authentication is performed by Google; for the information shared in that step Google is a separate data controller subject to its own privacy policy.
Audio recordings are used for no purpose other than the analysis and are never shared with any third party; they are processed only on our demo server on Google Cloud, by us, for the analysis. Your data may be disclosed to competent public authorities and courts only where required by law and to the extent requested.
7. International Data Transfers
Spiron is established in Türkiye. In the cases below your personal data is processed outside Türkiye; these transfers fall under Article 9 of the KVKK:
- Online demo: Germany (Google Cloud, Frankfurt region).
- Website hosting and CDN: Hostinger data centres outside Türkiye; CDN edge servers may be located in a region close to you.
- Corporate email: Microsoft data centres outside Türkiye.
- Google sign-in: Google's global infrastructure (only if you choose this option).
Our service providers process this data under the data-protection terms of their service agreements with us and only to the extent the service requires. To obtain information about the safeguards we rely on for international transfers, write to info@spiron.io.
If you use the demo from the European Economic Area (EEA): your demo data is hosted within the EEA (Germany). Within Spiron, only our authorised personnel, located in Türkiye, access this data, to the extent necessary to operate the service. The European Commission has not adopted an adequacy decision for Türkiye; this access is necessary to provide the demo service you requested.
8. Retention Periods
We keep your data only for as long as the purpose of processing requires; when that period ends it is deleted, destroyed or anonymised. Where the law requires a longer period (for example, commercial correspondence under the Turkish Commercial Code), that period applies.
| Data | Retention |
|---|---|
| Audio uploaded to the demo | Not retained — the temporary file created for the analysis is deleted as soon as the analysis ends |
| Analysis output (in the operational log; no audio) | 12 months, then deleted automatically |
| Demo account | Until you request deletion or the demo service ends; deleted within 30 days of your deletion request |
| One-time sign-in code (hash only) | Valid for 10 minutes and single-use; expired codes are deleted automatically |
| Session cookies and session records | Cookies are valid for up to 8 hours and deleted on sign-out; expired session records are deleted automatically |
| Security log (masked email, IP, time) | 12 months, then deleted automatically |
| Rate-limit counters | Deleted automatically after the counter window ends |
| Form rate-limit record (IP hash, request times) | Used only for a one-hour rate limit; times older than one hour are deleted when a new request arrives from the same address |
| Access request form emails | 2 years from the resolution of the request |
| Web server, load balancer and firewall access logs | For the providers' retention periods, up to 12 months |
9. Data Security
- The site and the demo are served only over encrypted connections (HTTPS/TLS); HTTP requests are redirected to HTTPS.
- The demo server has no external IP address; it is reachable only through a load balancer and a web application firewall.
- The demo uses no passwords; two-factor authentication is mandatory.
- Authenticator-app secrets are stored encrypted; session tokens and recovery codes are stored only as cryptographic hashes.
- Accounts are temporarily locked after failed attempts; per-IP rate limits and a per-user analysis allowance apply.
- Audio is never kept in permanent storage; the temporary file created for the analysis is deleted as soon as the analysis ends.
- Administrative access is restricted to authorised personnel and is logged.
- In the event of a data breach, we notify the Turkish Personal Data Protection Board and the affected individuals within the periods required by law.
10. Automated Analysis
The demo result is the automated output of a machine-learning model and is an estimate of the likelihood that the uploaded audio was artificially generated. The model can make mistakes; the result is not a definitive verdict on its own and is for information only. It is not used to make any decision that produces legal effects concerning you or similarly significantly affects you. If you believe an outcome resulting solely from automated analysis is to your detriment, you may object.
11. Your Rights
Under Article 11 of the KVKK you have the right to: learn whether your personal data is processed; request information if it is; learn the purpose of processing and whether data is used in line with that purpose; know the third parties to whom data is transferred in Türkiye or abroad; request rectification of incomplete or inaccurate data; request erasure or destruction under Article 7 of the KVKK; request that these actions be notified to third parties to whom data has been transferred; object to an outcome to your detriment arising solely from automated analysis; and claim compensation for damage caused by unlawful processing.
If the GDPR applies to you, you also have the right of access, rectification, erasure, restriction of processing, data portability, to object to processing based on legitimate interests and to withdraw your consent.
12. How to Exercise Your Rights
You can send your request, together with information sufficient for us to verify your identity, in the following ways: to info@spiron.io from the email address registered in our system or using a secure electronic signature or mobile signature; or by a signed letter to the address in Section 2. Requests are resolved free of charge within 30 days at the latest, depending on their nature; if the action involves an additional cost, the fee set by the Turkish Personal Data Protection Board may be charged.
If you are not satisfied with our response, you may lodge a complaint with the Turkish Personal Data Protection Board (kvkk.gov.tr). If you are in the EEA, you may also contact the data protection authority of your country.
13. Children's Data
Our services are intended for business users and are not directed at anyone under 18. We do not knowingly collect personal data from children; if we become aware of such data, we delete it.
14. Changes to This Policy
We may update this policy from time to time. The current version and its date appear at the top of this page; we announce material changes on our website.
15. Contact
Spiron Teknoloji A.Ş.
İTÜ ARI Teknokent 2, Block B, Sarıyer, Istanbul, Türkiye
Email: info@spiron.io
In the event of any inconsistency between the Turkish and English versions of this policy, the Turkish version prevails.