Brokdel

Legal

Privacy Policy

Last updated: 26 August 2026

This Privacy Policy explains how Brokdel Teknoloji A.Ş. ("Brokdel", "we", "us") collects, uses and protects personal data when you visit brokdel.com, request access, or use the Brokdel platform (together, the "Service"). Residents of Türkiye should also read our KVKK Disclosure Notice, which is the authoritative notice under Turkish law.

1. Who we are

Brokdel is operated by Brokdel Teknoloji A.Ş., registered at Avcılar, İstanbul, Türkiye, Türkiye. We are the data controller for the personal data described in this policy. You can reach us at [email protected].

2. What we collect

Access requests

When you submit the "Request access" form we collect your name, work email address, firm and role, anything you write in the message field, and the IP address the request was sent from. We use this to review your request and to contact you about it.

Account data

If an account is created for you we store your email address, name, a hashed password (we never store the password itself), your organisation ("tenant") membership, and settings you choose in the platform.

Content you create

Notes, saved filters, watchlists, valuation assumptions, uploaded research documents and similar content are stored so that the Service can work. Content you mark as visible to your team is shared with members of that team only.

Usage and technical data

We log which pages and features are used, together with the IP address, browser type and time of the request. We use PostHog for product analytics, including page views, clicks and session replays in which all form inputs are masked. Security-relevant events (for example logins, password changes and failed attempts) are recorded separately.

Cookies

We use strictly necessary cookies to keep you signed in (short-lived access token, longer-lived refresh token, both HttpOnly) and to protect forms against cross-site request forgery. Analytics cookies and local storage are set by PostHog as described above. We do not use advertising cookies.

3. Why we process your data and on what basis

PurposeDataLegal basis
Reviewing access requests and onboardingAccess request dataSteps prior to a contract; legitimate interest
Providing and securing the ServiceAccount, content, technical and security dataPerformance of a contract; legal obligation
Understanding and improving the productUsage data (PostHog)Legitimate interest
Service emails (verification, password reset, invitations)Email address, namePerformance of a contract
Responding to enquiriesContact details, messageLegitimate interest

We do not sell personal data and we do not use it for third-party advertising.

4. Who we share data with

We use a small number of service providers who process data on our behalf under contract:

  • Hetzner Online GmbH (Germany): hosting of the platform and database.
  • Cloudflare, Inc.: content delivery, DDoS protection and TLS termination.
  • PostHog, Inc. (United States): product analytics and session replay.
  • Resend: transactional email delivery.

Some of these providers are located outside Türkiye and the European Economic Area. Where data is transferred abroad we rely on the safeguards available under applicable law, including the provider's standard contractual clauses, and, where Turkish law requires it, your explicit consent.

We may also disclose data where required by law, to protect our rights, or as part of a merger or acquisition, in which case this policy continues to apply.

5. How long we keep data

  • Access requests: until the request is resolved and for a limited period afterwards, after which they are deleted.
  • Account data and content: for as long as the account exists. Deleted accounts are removed permanently after a short grace period.
  • Usage and activity logs: for a limited period, then deleted automatically.
  • Security event logs: for as long as needed to detect and investigate security incidents.
  • Records we must keep by law (for example invoices): for the statutory period.

6. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time. Account holders can update their profile and delete their account from the settings page. For all other requests, write to [email protected]. We answer within 30 days. You also have the right to lodge a complaint with your supervisory authority; in Türkiye this is the Personal Data Protection Authority (KVKK).

7. Security

We protect data with encryption in transit, access controls, hashed credentials, isolated tenant data and monitoring of security events. No system is completely secure; if we become aware of a breach affecting your data we will inform you and the relevant authority as required by law.

8. Children

The Service is intended for professionals and is not directed at anyone under 18. We do not knowingly collect data from children.

9. Changes

We may update this policy from time to time. The date at the top shows when it was last changed. Material changes will be announced on the Service or by email.

10. Contact

Brokdel Teknoloji A.Ş.
Avcılar, İstanbul, Türkiye
[email protected]