Legal · Compliance
GDPR & KVKK Compliance
Last updated: June 2026
1. Overview
Seomatiq processes personal data lawfully, transparently, and in a way that protects the data subject's rights under the European Union General Data Protection Regulation (GDPR / Regulation (EU) 2016/679) and the Turkish Personal Data Protection Law (KVKK / Law No. 6698). This page is a summary of our compliance approach; for full data processing details, our Privacy Policy applies.
2. Data Processing Principles
Lawfulness and transparency
Data is processed only on a clear legal basis (contract, explicit consent, or legitimate interest).
Purpose limitation
Data is used only for the purpose for which it was collected to deliver the service; it is not sold or rented for marketing.
Data minimisation
No more personal data than necessary for the service is collected.
Security
Data is encrypted with TLS 1.3 (in transit) and AES-256 (at rest); WordPress credentials are stored in encrypted fields.
Retention limit
When an account is closed, personal data is permanently deleted within 30 days (except legally mandated records).
3. Data Subject Rights (GDPR & KVKK)
Under GDPR and KVKK you have the following rights:
Information and access
You can request a copy of the personal data processed about you (GDPR Art. 15 / KVKK Art. 11).
Rectification
You can request that inaccurate or incomplete data be corrected (GDPR Art. 16 / KVKK Art. 11).
Erasure / Right to be forgotten
You can have your account and associated data permanently deleted (GDPR Art. 17 / KVKK Art. 7).
Data portability
You can obtain your data in a machine-readable format (JSON) (GDPR Art. 20).
Objection to and restriction of processing
You can object to certain processing activities and request that processing be restricted (GDPR Art. 18, 21).
4. How to Exercise Your Rights
To exercise any of the rights above, write to privacy@seomatiq.com. Your requests are answered within 30 days at the latest, as required by GDPR and KVKK. We may request additional information to verify your identity.
5. Data Processors (Sub-processors)
To deliver the service, we work with GDPR-compliant infrastructure providers such as Anthropic, Supabase, Vercel, Stripe, Google, and Inngest. The role and purpose of each provider is listed in section 4 of our Privacy Policy.
6. Contact
For all data protection questions: privacy@seomatiq.com