Skip to content

Privacy Policy

Last updated: 13 September 2026

1. Introduction

This policy explains how personal data is collected, used, retained and protected in the Xaly.ai service operated by Voratrix Yazılım ve Yapay Zeka Teknolojileri Anonim Şirketi (the "Provider").

It covers the xaly.ai website, the app.xaly.ai dashboard, the mobile application, and the call and messaging flows carried out as part of the service.

2. Our Roles: Controller and Processor

For our account holders' own information (registration, billing, support, website visits) the Provider is the data controller.

For personal data processed in conversations between a Subscriber and its own customers, the Subscriber is the controller and the Provider is the processor. We process such data only on the Subscriber's instructions and in order to deliver the service.

Informing end users and obtaining any required consent is the Subscriber's obligation as controller.

3. Data We Collect

  • Account and identity data: name, company name, email, phone, user role, and your profile photo if you upload one.
  • Billing data: tax office and number, invoice address, payment amount and date. Card number, expiry date and CVV never reach us.
  • Usage data: sign-in records, IP address, device and browser information, in-dashboard activity records.
  • Communication content: call recordings, transcripts, message content, documents and images you upload (e.g. a bank transfer receipt, a scanned business card) and lead records.
  • Support correspondence: requests, bug reports and attachments you send us.
  • Data collected through cookies and similar technologies: detailed in the Cookie Policy.

4. Purposes and Legal Bases

  • Providing the service, managing the account and offering support — performance of the contract.
  • Billing, collection and accounting records — legal obligation and performance of the contract.
  • Ensuring security, preventing abuse and fraud, logging registration attempts — legitimate interest.
  • Measuring service quality and improving the product — legitimate interest; using aggregated and de-identified data wherever possible.
  • Responding to legal requests and defending legal claims — legal obligation and legitimate interest.
  • Sending commercial electronic messages — only with explicit consent, with an opt-out in every message.

5. AI Models and Your Data

We do not use Subscriber data to train our own general-purpose AI models.

Language model and speech processing components run on our own infrastructure; conversation content is not transferred to third-party model providers for training purposes.

The only exception is the image features: when business-card scanning or image generation is used, the image concerned is sent to Google Gemini for processing. Audio and conversation content are never sent to that service.

Where debugging is required, we review only with the relevant Subscriber's request or approval and with the minimum data necessary; such access is logged.

6. Retention Periods

At the end of the period, data is deleted, destroyed or irreversibly anonymised. Where a Subscriber requests a shorter period, that request is applied.

  • Call recordings and transcripts: for the period configured by the Subscriber in the dashboard; twelve months by default if not configured.
  • Lead records and conversation metadata: for the duration of the subscription and thirty days thereafter.
  • Billing and accounting records: ten years, as required by applicable law.
  • Session, access and security logs: two years.
  • Registration attempt and abuse records: one hundred and eighty days.
  • Support correspondence: three years from closure of the request.

7. Disclosure and Sub-processors

We do not sell your data and do not share it with third parties for marketing. Sharing occurs only to the extent necessary to deliver the service:

  • Hosting and infrastructure providers — servers, backup and storage.
  • Telecommunications carriers and SIP providers — establishing calls.
  • Messaging platforms (Meta/WhatsApp, Telegram, Instagram) — where the relevant channel is used.
  • Image processing provider (Google Gemini) — only when you use the business-card scanning or image generation features; the image concerned is sent to that service.
  • Payment institutions (PayTR) and banks — taking payment; card data is processed directly on their infrastructure.
  • Email and notification providers — sending information and alerts.
  • Competent public authorities — under a legal obligation, after assessing the lawfulness of the request.

8. International Transfers

The core components of the service (database, call recordings, language model and speech processing) are hosted on our infrastructure in Türkiye.

Certain supporting services (messaging platforms, email delivery, error monitoring) may operate through providers located abroad. Such transfers are made on the conditions set out in Article 9 of Turkish Law No. 6698 and, where necessary, standard contractual clauses.

With the self-hosted (on-premise) option, data remains entirely on the Subscriber's infrastructure and no international transfer takes place.

9. Security Measures

  • TLS in transit and disk- and field-level encryption at rest; secrets stored separately and encrypted.
  • Role- and permission-based access control; two-factor authentication on administrator accounts.
  • Network-level access restriction; database and cache services kept off the public internet.
  • Session tracking, IP lockout on suspicious sign-ins, and rate limiting.
  • Regular backups and restore drills; vulnerability scanning of dependencies.
  • Audit logs: critical actions are recorded with who, when and from which IP.

10. Breach Notification

If a personal data breach is identified, the Turkish Data Protection Authority is notified as soon as possible and within seventy-two hours at the latest; affected Subscribers are informed without delay and told what measures have been taken.

11. Your Rights

Under KVKK and, to the extent applicable, GDPR, you have the right to learn whether your data is processed, to request information, rectification and erasure, to object to processing, to data portability and to object to automated decisions.

You may send requests to info@voratrix.com. Requests are concluded within thirty days at the latest. We may ask for additional information to verify your identity.

If your request relates to a conversation held in a Subscriber's account, that Subscriber is the controller; we will direct your request to them and support them through the process.

12. Children's Data

The service is intended for businesses and is not offered directly to persons under eighteen. If we learn that a child's data has been processed without our knowledge, we delete it without delay.

13. Changes and Contact

This policy may be updated. Material changes are announced in the dashboard or by email before they take effect; the date at the top of the page shows the last update.

Email: info@voratrix.com

Address: Yakuplu Mah. Hürriyet Blv. Skyport Residence No: 1 İç Kapı No: 62, Beylikdüzü / İstanbul