Privacy Policy

Last updated: 9 October 2026

If you are in Türkiye, our KVKK notice (KVKK Aydınlatma Metni) explains how ZincirX A.Ş., as data controller, processes your personal data; for people in Türkiye it prevails over this policy.

This is an English translation of the Turkish notice. If the two versions differ, the Turkish version prevails.

1. Data Controller

PatentYazar is provided by ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş.(“ZincirX A.Ş.”, “We”). For people in Türkiye the data controller is ZincirX A.Ş.. Customers who buy from outside Türkiye contract with ZincirX Inc., which is the controller of their data; ZincirX A.Ş. processes that data on ZincirX Inc.’s behalf under a data processing agreement between the two companies. The companies’ details (address, MERSIS and tax number) are in section 1 of the KVKK Aydınlatma Metni. Contact: info@patentyazar.com or legal@patentyazar.com. Once registration with VERBIS (the Turkish data controllers’ registry) is complete, the registry number will be published on this page.

2. Personal Data Processed

The Tool processes personal data in two categories:

A. User (attorney, assistant) data:
  • Identity: full name
  • Contact: e-mail, phone (optional)
  • Professional: TÜRKPATENT patent attorney registration number, firm name
  • Account: password (hashed — bcrypt), session tokens
  • Logs: IP address, user agent, activity timestamps
  • Billing: billing country, company name or full name, billing address, tax office and tax number; for individual buyers in Türkiye, optionally the Turkish ID number (not stored by us, only passed to ZincirX A.Ş., which issues the invoice)
B. Client/inventor data (entered by the User):
  • Invention disclosure (technical content — typically a trade secret)
  • Inventor names, applicant company name, internal reference codes
  • AI-generated description, claims and abstract drafts, diagrams
  • Patent drawing images uploaded in the mobile app via camera or photo library (from an inventor’s notebook or a technical drawing)

A User who enters this data into the Tool undertakes that they have obtained the necessary permission from the data subject.

2.A. Mobile App Permissions and Device Data

The mobile app (iOS / Android) accesses only the following device resources; each access depends on an explicit action by the User (there is no automatic or background access):

  • Camera: when the User taps “Take photo”, to take a single photo to be used as a patent drawing. The image is sent directly to our servers through the API (api.patentyazar.com) and is not saved to the device’s photo library. There is no continuous camera recording.
  • Photo library: when the User taps “Choose from library”, so they can select the images they want to upload. The system photo picker (iOS PHPickerViewController / Android Photo Picker) is used; the app does not request access to the whole library, only to the files the User selects.
  • Internet connection: for API calls, AI models (Anthropic Claude) and system updates.
  • Local storage: session tokens (encrypted shared preferences), user preferences and temporary file caches (until the system share sheet opens when a DOCX/PDF is downloaded). User data is not stored permanently on the device.

The mobile app does not access location, contacts, calendar, microphone, health data, advertising identifiers (IDFA / GAID) or device identifiers. It uses no third-party advertising or analytics SDKs.

3. Purposes of Processing (KVKK Art. 5)

  • Providing the service (account management, project creation)
  • AI draft generation (invention disclosure → description, claims and abstract generated via the Anthropic Claude API)
  • Prior-art search (invention summary → queries to EPO Espacenet OPS and Google Patents)
  • Legal audit trail — a traceable record of every AI suggestion and every attorney edit (spatie/laravel-activitylog)
  • Account security, fraud prevention and compliance with legal obligations
  • Subscription payments and invoicing (through ZincirX A.Ş. and iyzico for buyers in Türkiye, and through ZincirX Inc. and Stripe for everyone else)

4. Legal Grounds (KVKK Art. 5–6)

Personal data is processed on the following legal grounds:

  • Formation and performance of a contract (KVKK Art. 5/2-c) — the service agreement concluded with the User
  • Legal obligation (Art. 5/2-ç) — tax, commercial and Industrial Property Law audit requirements
  • Legitimate interest (Art. 5/2-f) — service improvement, security
  • Explicit consent (Art. 5/1) — separate consent is obtained for marketing communications

5. Recipients of Personal Data

  • Anthropic (Claude API)— for the invention disclosure and description generation. Under Anthropic’s terms of service this data is not used for model training and is deleted after 30 days.
  • EPO Espacenet OPS — for prior-art queries, only the search keywords entered by the User are sent; no inventor or project data is sent.
  • Google Patents — the same principle applies.
  • ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. — for buyers in Türkiye only: as the seller of the web subscription it takes the payment on zincirx.com and issues the e-Archive invoice. Name/company name, e-mail, billing address, tax office and tax number (and the Turkish ID number, if an individual buyer enters it) are passed to it for this purpose.
  • iyzico (iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.) — for buyers in Türkiye only: processes the card payment on behalf of ZincirX A.Ş.; name, e-mail and billing address are passed to it. Card details are entered directly with iyzico and never reach us. iyzico is a separate data controller.
  • Stripe — for buyers outside Türkiye: processes the card payment and invoice on behalf of ZincirX Inc., the seller of the web subscription; name/company name, e-mail, billing address and any tax ID the buyer enters on the payment page. Card details are entered directly with Stripe and never reach us. Stripe is a separate data controller.
  • Hostinger International Ltd. — server hosting (Lithuania) and e-mail; outgoing e-mail is relayed through MailChannels (United States).

Transfers abroad are made under the appropriate safeguards provided for in Art. 9 of KVKK (standard contracts). We do not rely on your explicit consent for regular transfers abroad, and using the service never depends on it. The full list of recipients, countries and data transferred is in section 5 of the KVKK Aydınlatma Metni.

6. Retention Periods

  • Account data: while the account is active + 1 year
  • Project and draft data: until deleted by the User (soft delete + 30-day holding period)
  • Activity log (audit trail): 10 years — the limitation period for Industrial Property Law and industrial property damages claims
  • Invoice/payment records: 10 years (Turkish Tax Procedure Law, Art. 253)

7. Rights of the Data Subject (KVKK Art. 11)

As a data subject, you have the right to:

  • Learn whether your personal data is processed
  • Request information about it if it has been processed
  • Learn the purpose of processing and whether it is used in line with that purpose
  • Know the third parties in Türkiye or abroad to whom it has been transferred
  • Request correction of incomplete or inaccurate data
  • Request deletion or destruction of unlawfully processed data
  • Object to a result against you arising from automated analysis
  • Claim compensation for damage

To exercise your rights, send a written request to legal@patentyazar.com (identity verification is required). We respond within 30 days. All the ways to apply and the full list of rights are in sections 7 and 8 of the KVKK Aydınlatma Metni.

8. Security Measures

  • Passwords are hashed with bcrypt (cost 12); plain text is never stored
  • All traffic runs over TLS 1.3 (certificates from Let’s Encrypt + Cloudflare)
  • Database disk encryption (tenant-level isolation is applied)
  • API access tokens are rotated with Sanctum, every 90 days
  • Access to the production environment requires an SSH key + 2FA; no one uses plain passwords
  • In the event of a breach, the Turkish Personal Data Protection Board is notified within 72 hours (KVKK Art. 12/5)

9. Cookie Policy

The Tool uses cookies and your browser’s local storage for two purposes. It uses no advertising or marketing cookies.

Strictly necessary (not subject to consent)

  • NEXT_LOCALE (first-party cookie): remembers your interface language; 1 year.
  • patentyazar_token (browser local storage): keeps you signed in; deleted when you sign out.
  • zx_consent (first-party cookie): stores your cookie choice (version of the choice, its date, and yes or no to analytics); 6 months. After that you are asked again.

Analytics (only if you accept)

  • Google Analytics 4 — the _ga and _ga_2CK04J44K1 cookies: tell visits apart and measure how the site is used; up to 2 years. The provider is Google LLC (USA); the data may be processed in the USA. Google receives the pages visited (with the parts of addresses that carry a session token, e-mail address or similar removed), browser and device information and the IP address, and sign-up, checkout and purchase events (plan, amount, order number); never your name, e-mail address or project content.
  • zx_ga_sent:… (browser local storage): so the same purchase is not counted twice.

Without your consent the Google Analytics script is not loaded at all and no request is sent to Google. The legal basis for analytics cookies is your explicit consent (KVKK Art. 5(1)); strictly necessary storage is processed under KVKK Art. 5(2)(c) and (f). You can change your choice or withdraw your consent at any time with the “Cookie settings” link at the bottom of every page; withdrawing stops Google Analytics and deletes the _ga cookies we can reach. You can also delete cookies in your browser settings. Details are in section 9 of the KVKK Aydınlatma Metni.

10. Changes

When this notice is updated, the “Last updated” date changes; material changes are announced by e-mail.