Legal · Compliance

GDPR & KVKK Compliance

Last updated: June 2026

1. Overview

Seomatiq processes personal data lawfully, transparently, and in a way that protects the data subject's rights under the European Union General Data Protection Regulation (GDPR / Regulation (EU) 2016/679) and the Turkish Personal Data Protection Law (KVKK / Law No. 6698). This page is a summary of our compliance approach; for full data processing details, our Privacy Policy applies.

2. Data Processing Principles

Lawfulness and transparency

Data is processed only on a clear legal basis (contract, explicit consent, or legitimate interest).

Purpose limitation

Data is used only for the purpose for which it was collected to deliver the service; it is not sold or rented for marketing.

Data minimisation

No more personal data than necessary for the service is collected.

Security

Data is encrypted with TLS 1.3 (in transit) and AES-256 (at rest); WordPress credentials are stored in encrypted fields.

Retention limit

When an account is closed, personal data is permanently deleted within 30 days (except legally mandated records).

3. Data Subject Rights (GDPR & KVKK)

Under GDPR and KVKK you have the following rights:

Information and access

You can request a copy of the personal data processed about you (GDPR Art. 15 / KVKK Art. 11).

Rectification

You can request that inaccurate or incomplete data be corrected (GDPR Art. 16 / KVKK Art. 11).

Erasure / Right to be forgotten

You can have your account and associated data permanently deleted (GDPR Art. 17 / KVKK Art. 7).

Data portability

You can obtain your data in a machine-readable format (JSON) (GDPR Art. 20).

Objection to and restriction of processing

You can object to certain processing activities and request that processing be restricted (GDPR Art. 18, 21).

4. How to Exercise Your Rights

To exercise any of the rights above, write to privacy@seomatiq.com. Your requests are answered within 30 days at the latest, as required by GDPR and KVKK. We may request additional information to verify your identity.

5. Data Processors (Sub-processors)

To deliver the service, we work with GDPR-compliant infrastructure providers such as Anthropic, Supabase, Vercel, Stripe, Google, and Inngest. The role and purpose of each provider is listed in section 4 of our Privacy Policy.

6. Contact

For all data protection questions: privacy@seomatiq.com