Privacy Policy

How we handle personal data — plainly, the way we build.

Last updated: July 16, 2026

Introduction

Heravox ("we") is a customer-experience intelligence platform. This policy explains what personal data we process across our website, the demo request form, and the platform itself — and what rights you have over it. It is written to match how the product actually works.

Data We Process

Account information

If you have a platform account:

  • Name, surname and work email address
  • Company / organization name
  • Notification and communication preferences

Demo requests

When you fill in the demo form, we process your name, work email, company, phone number and (optionally) sector — solely to respond to your request. The form is delivered through our form processor and is protected against bots.

Usage and security data

  • Session information (sign-in records, active sessions)
  • Browser and device information
  • Security and audit logs — kept free of message content

Analyzed feedback content

On behalf of our clients, the platform analyzes customer feedback from public channels and from the client's own internal sources. For this content:

  • Personal data is minimized and anonymized the moment it enters the system — raw text is never persisted
  • Each brand's data lives in its own isolated, encrypted database
  • The data belongs to the client and is processed solely for analysis
  • It is never shared across brands or with third parties

How We Use Data

  • To provide, operate and improve our services
  • To respond to demo requests and provide technical support
  • To keep the platform secure (authentication, abuse prevention, audit)
  • To fulfill our legal obligations

Security & Data Residency

Security is how Heravox is built, not an add-on:

  • Anonymization and minimization at ingestion — personal data never reaches durable storage in raw form
  • A dedicated, isolated database per brand, encrypted in transit and at rest
  • Per-brand encryption keys — destroying a brand's key makes its data permanently unreadable
  • Role-based access control and audit logging
  • Independent penetration testing
  • Cloud-tier data is hosted in Türkiye; an on-prem deployment inside your own datacenter is also available

Third Parties

We do not sell or rent personal data. It may be shared only:

  • With service providers acting under data-processing agreements (cloud hosting, form processing, bot protection)
  • When required by law or a competent authority
  • With your explicit consent

Retention

We keep personal data only as long as the service relationship and our legal obligations require. When a client relationship ends, the brand's data is deleted; per-brand encryption keys make that deletion final.

Your Rights

Under KVKK (Art. 11) and, where applicable, the GDPR, you can:

  • Learn whether your data is processed and request access to it
  • Request correction of inaccurate data
  • Request deletion or destruction of your data
  • Object to processing and request restriction
  • Request your data in a portable format

To exercise these rights, contact us at the address below. We respond within the statutory period (30 days under KVKK).

Contact

For cookie usage, see our Cookie Policy.

Changes

We may update this policy from time to time. Significant changes are announced on our website; the current version always lives on this page, with the date above.