Legal
Privacy Policy
Last updated: 26 August 2026
This Privacy Policy explains how Brokdel Teknoloji A.Ş. ("Brokdel", "we", "us") collects, uses and protects personal data when you visit brokdel.com, request access, or use the Brokdel platform (together, the "Service"). Residents of Türkiye should also read our KVKK Disclosure Notice, which is the authoritative notice under Turkish law.
1. Who we are
Brokdel is operated by Brokdel Teknoloji A.Ş., registered at Avcılar, İstanbul, Türkiye, Türkiye. We are the data controller for the personal data described in this policy. You can reach us at [email protected].
2. What we collect
Access requests
When you submit the "Request access" form we collect your name, work email address, firm and role, anything you write in the message field, and the IP address the request was sent from. We use this to review your request and to contact you about it.
Account data
If an account is created for you we store your email address, name, a hashed password (we never store the password itself), your organisation ("tenant") membership, and settings you choose in the platform.
Content you create
Notes, saved filters, watchlists, valuation assumptions, uploaded research documents and similar content are stored so that the Service can work. Content you mark as visible to your team is shared with members of that team only.
Usage and technical data
We log which pages and features are used, together with the IP address, browser type and time of the request. We use PostHog for product analytics, including page views, clicks and session replays in which all form inputs are masked. Security-relevant events (for example logins, password changes and failed attempts) are recorded separately.
Cookies
We use strictly necessary cookies to keep you signed in (short-lived access token, longer-lived refresh token, both HttpOnly) and to protect forms against cross-site request forgery. Analytics cookies and local storage are set by PostHog as described above. We do not use advertising cookies.
3. Why we process your data and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Reviewing access requests and onboarding | Access request data | Steps prior to a contract; legitimate interest |
| Providing and securing the Service | Account, content, technical and security data | Performance of a contract; legal obligation |
| Understanding and improving the product | Usage data (PostHog) | Legitimate interest |
| Service emails (verification, password reset, invitations) | Email address, name | Performance of a contract |
| Responding to enquiries | Contact details, message | Legitimate interest |
We do not sell personal data and we do not use it for third-party advertising.
4. Who we share data with
We use a small number of service providers who process data on our behalf under contract:
- Hetzner Online GmbH (Germany): hosting of the platform and database.
- Cloudflare, Inc.: content delivery, DDoS protection and TLS termination.
- PostHog, Inc. (United States): product analytics and session replay.
- Resend: transactional email delivery.
Some of these providers are located outside Türkiye and the European Economic Area. Where data is transferred abroad we rely on the safeguards available under applicable law, including the provider's standard contractual clauses, and, where Turkish law requires it, your explicit consent.
We may also disclose data where required by law, to protect our rights, or as part of a merger or acquisition, in which case this policy continues to apply.
5. How long we keep data
- Access requests: until the request is resolved and for a limited period afterwards, after which they are deleted.
- Account data and content: for as long as the account exists. Deleted accounts are removed permanently after a short grace period.
- Usage and activity logs: for a limited period, then deleted automatically.
- Security event logs: for as long as needed to detect and investigate security incidents.
- Records we must keep by law (for example invoices): for the statutory period.
6. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time. Account holders can update their profile and delete their account from the settings page. For all other requests, write to [email protected]. We answer within 30 days. You also have the right to lodge a complaint with your supervisory authority; in Türkiye this is the Personal Data Protection Authority (KVKK).
7. Security
We protect data with encryption in transit, access controls, hashed credentials, isolated tenant data and monitoring of security events. No system is completely secure; if we become aware of a breach affecting your data we will inform you and the relevant authority as required by law.
8. Children
The Service is intended for professionals and is not directed at anyone under 18. We do not knowingly collect data from children.
9. Changes
We may update this policy from time to time. The date at the top shows when it was last changed. Material changes will be announced on the Service or by email.
10. Contact
Brokdel Teknoloji A.Ş.
Avcılar, İstanbul, Türkiye
[email protected]

