ZeroRecall (Astro Tasarım Simay Yenice) provides independent audits that test whether erased personal data still leaks from AI systems (chatbots, RAG pipelines, vector stores) and issues cryptographically signed evidence files. This notice explains how our service relates to the EU General Data Protection Regulation (GDPR) and how we process personal data in that context. The Turkish-law disclosure (KVKK) is published separately.
Article 17: the right to erasure, and why proof is hard
GDPR Article 17 gives data subjects the right to obtain erasure of their personal data. In modern AI stacks, deleting the database row is not the end of the story: embeddings can persist in vector stores, retrieval indexes can be rebuilt from stale exports, and model behavior does not read DELETE statements. A controller who closed an erasure request may therefore still be processing that data on AI surfaces without knowing it.
ZeroRecall exists for exactly this gap. An audit probes the AI surfaces you put in scope and reports, with signed evidence, whether the erased data is still observable there. It supports your Article 5(2) accountability obligation: not a guarantee of permanent removal from model weights, but documented, verifiable evidence of observed behavior on the listed surfaces at the stated date.
What an audit is, and is not
- It is an independent technical test with a signed, tamper-evident evidence file.
- It is not a certification, a legal opinion, or a guarantee that a model has permanently forgotten. The final legal judgment belongs to your counsel.
- We do not perform deletion or unlearning ourselves; auditing our own erasure work would be a conflict of interest.
Processing roles
For the data involved in an audit (the record whose erasure you are verifying, canary markers, connector configuration), you are the controller and ZeroRecall acts as your processor under Article 28: we process audit targets solely on your documented instructions, only to run the audit, and we do not reuse, sell or transfer them for our own purposes. Connector secrets are used at run time only and are never written to the evidence file or persistent storage.
For account data (name, email, organization) and for our own website, ZeroRecall is the controller. Details of categories, retention and infrastructure sub-processors are in the Privacy Policy.
Data subject rights
Data subjects have the rights of access, rectification, erasure, restriction, objection and portability (GDPR Articles 15 to 21). If you are a data subject whose data appears in a customer's audit, we will refer your request to the controller concerned, as a processor must. For requests about data ZeroRecall controls, contact us directly.
Contact
Controller of record: Astro Tasarım Simay Yenice, registered in Türkiye (full registered address available on request at hello@zerorecall.ai). Data protection contact: hello@zerorecall.ai. General contact: hello@zerorecall.ai.