ZeroRecall (Astro Tasarım Simay Yenice) is a service that provides independent audits of erasure requests in AI systems and produces signed evidence files. This policy explains how your personal data is processed when you use the service. It is based on the GDPR and Turkish Law No. 6698 (KVKK).
Roles: controller and processor
When you run an audit, the data about the audited target (the record whose erasure was requested) is data you define. For that data you are the controller; ZeroRecall processes it solely to run the audit, on your instructions, as a processor. We do not use audit targets for our own purposes, sell them, or transfer them to models or third parties.
Data we process
- Account data: name, email, organization (when you sign up).
- Audit inputs: target label, identifiers, canaries, context hints, connector configuration.
- Connector secrets (API keys, database DSNs): used only at run time, in memory or via environment variables; they are never written to the evidence file or persistent storage.
- Audit outputs: findings, score, the signed evidence file (integrity seal).
Retention and deletion
Audit outputs are stored under your account; you can delete them at any time. Connector secrets are cleared from memory after each run and never stored. Astro Tasarım Simay Yenice manages retention periods and deletion in line with the KVKK Deletion, Destruction and Anonymization Guideline. We keep our own practice auditable as well (dogfooding).
Legal basis and sharing
Processing is based on performance of contract and legitimate interest; marketing communication requires your separate, explicit consent. We share data only with the infrastructure providers that run the service (hosting, database), acting as processors under contract.
Your rights
Under KVKK Article 11 and the GDPR you have the rights of access, rectification, erasure, objection and portability. For requests: hello@zerorecall.ai.