1. Who is who
The data controller is the company using the Solk installation (for example, the employer who invited you): it decides what data is entered, who can access it and how long it is kept. Solk is the data processor that hosts the data and operates the software on that company's instructions. Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and, where applicable, the GDPR follow this distinction.
Your user account is created by your company's administrator, not by Solk. There is no sign-up or membership on Solk's website (solk.app).
2. Data we process
| Data | Source | Examples |
|---|---|---|
| User account | Your company's administrator | name, username, e-mail, role, assigned modules, password hash (the password itself is not stored) |
| CRM records | Entered by you and your team | customer company details; contacts' names, titles, phone numbers and e-mail addresses; visit, call and trial notes; quotes, orders, contracts and support tickets; files attached to records (data sheets, photos, signed documents); calendar events; trade-fair leads |
| Usage records | System | sign-in time and IP address (security), audit trail of deletions and blocked edit attempts, which user used which module (licence metering) |
| Calendar sync | Optional | if you add a calendar account on your iPhone / Mac, CRM events appear on your phone and events you create on the phone are brought into the CRM |
| E-mail sync | Optional, connected by the user | if you connect your mailbox (with an IMAP/SMTP app password, or by granting access with your Google / Microsoft account), only your two-way correspondence with contacts in the CRM, with customer companies' domains or with business addresses (sender, recipients, subject, date, body) is brought into the CRM; public webmail addresses (Gmail, Hotmail, etc.), newsletters, auto-replies, delivery reports and addresses your company has excluded are not stored, and your other e-mails are read and discarded. You choose whether the body is shared with your team; you can remove the connection at any time. Section 7 describes Google user data in detail |
| Automatic company and contact records from e-mail | Turned on or off by your company's administrator (on by default) | when there is two-way correspondence with an unknown business domain (at least one e-mail sent from you to that domain), the company is created as a "prospect" and the correspondent as a contact: name, e-mail address, and the title, phone number and company name from the e-mail signature. For this, the number of incoming / outgoing messages per address is kept (not the content). Generic addresses (info@, sales@ …), public and educational institutions, banks, couriers and software services are never created as companies or contacts. A wrongly created company can be deactivated with one click and its domain excluded for good |
| E-mail sequences, scheduled and bulk sending | The user | recipient's name and e-mail address, which step was sent when, whether a reply arrived or the recipient unsubscribed; drafts waiting to be sent and their attachments |
| Ask (assistant) questions | The user | the question you asked, a summary of the answer and the records linked in it (for chat history and usage limits) |
Solk does not ask for or store national ID numbers, card details, location history or your phone's contacts. Your company decides what is written in free-text fields and sets guidance to avoid entering sensitive data.
3. What it is used for
- Sales tracking: keeping company, contact, visit, opportunity, quote and order records; generating reminders and tasks.
- Management: team dashboard, forecasts and reports (only on your company's own data).
- Security and accountability: sign-in checks, lockout after failed password attempts, audit trail.
- Linking e-mail correspondence to the right records: conversations are linked to the company and project, and to quotes, contracts, visits and similar records through the quote / contract / record number in the subject or body; recent visits and tasks are only shown as suggestions and are not linked without the user's confirmation.
- Licensing and billing: how many user-days each module was used — counts only, never record content.
- E-mail sequences: sending follow-up e-mails started by the user on time; sending stops automatically when the recipient replies, unsubscribes or a meeting with the company is logged. Every sequence e-mail contains a one-click unsubscribe link. Sending in line with commercial electronic message law (Law No. 6563, İYS) and obtaining the required consents is the responsibility of the data controller company.
No profiling, ad targeting or third-party analytics is performed. The website and app use no tracking cookies; only the essential cookie that keeps you signed in is used.
4. Where it is stored
Each company's installation runs on its own subdomain with its own database; no tables are shared with another company. Data is kept on servers managed by Solk and backed up daily; backups are also per company. Data in transit is always encrypted (HTTPS; .app domains do not open without encryption).
The server location and any cross-border transfer terms are set out in the service agreement with your company; you can ask for details at info@solk.app.
5. Mobile app (iOS / Android)
The Solk mobile app is a client that connects to your company's installation (the address you enter on the sign-in screen). The app itself collects no data; everything you see comes from your installation.
- Stored on the device: the sign-in token, in the device's secure storage, and the server address. Your password is not stored on the device.
- Permissions not requested: location, contacts, camera and notifications are not requested. The "Call", "WhatsApp" and "Directions" buttons pass the number or address to the relevant app only when you tap them.
- E-mail and Ask: e-mails you write in the app are sent through your installation from the e-mail account you connected on the web, and saved in the CRM (section 2). Questions on the "Ask" screen go to your installation; if AI is turned on, the answer is prepared as described in section 6. The app never sees or stores your e-mail account's password or access token.
- No third-party SDKs: there is no analytics, crash-reporting or advertising library.
- Sign-out: signing out revokes the token on the server; tokens also expire automatically after at most 90 days.
- Account deletion: because your account was created by your company, send your request to close it to your company's administrator, who can deactivate or delete the user. If you cannot reach them, write to info@solk.app; we will forward the request to your company and follow it up.
6. Who it is shared with
- Your company's users: according to their permissions (sales users edit their own records, administrators see everything).
- Solk: only for operations and support, when needed and with your company's knowledge; only licence status and usage counts go to the vendor panel.
- Infrastructure providers: server hosting and, if your company has configured one, an e-mail delivery service. They process data only on Solk's instructions.
- Your own e-mail provider: if you connected your e-mail account, e-mails you write in the CRM are sent from your own account (Gmail, Yandex, Outlook or your company mail). If you connected with "Sign in with Google" or "Sign in with Microsoft", Google / Microsoft grant your Solk installation only the mailbox access (read and send) you approved; your password never reaches Solk. You can revoke this access at any time from your Google account's Security → Third-party connections page or your Microsoft account's Apps and services page. Details for Google accounts are in section 7.
- AI assistant — optional, off by default: the "Assistant" on the opportunity page normally runs rule-based on the server and no data leaves it. If your company's administrator turns on AI text in the Security settings, when a user opens the Assistant only the CRM summary of that opportunity and company (stage, amount, recent activities, notes; excluding contacts' phone numbers and e-mail addresses) is sent to the AI service provider to generate the answer. With the same setting on, using "draft from description" on the workflow screen sends only the description you wrote and the field list. When you ask a question in the Ask panel (Ctrl+J), the question and the CRM record summaries needed to answer it (name, stage, amount, date, meeting notes, e-mail subjects; excluding contacts' phone numbers and e-mail addresses) are sent; the AI can access only data within your own permissions. With the setting off, Ask answers rule-based on the server and no data leaves it. AI requests are forwarded to the provider through Solk's relay server (the vendor panel); the relay does not store request or response content and only keeps the company's monthly request and token counts (for billing and limits). The provider and its data-use terms are set out in the service agreement with your company; the setting can be turned off at any time.
- Legal obligation: upon a lawful request from competent authorities.
Data is never sold, rented or shared for advertising.
7. Signing in with Google (Google user data)
This section describes the data received from Google when a user connects a Gmail or Google Workspace account with "Sign in with Google" on the E-mail account page. Connecting is optional; if a user does not connect, no data in their Google account is accessed.
| Permission requested | Why |
|---|---|
| openid email | To learn the e-mail address of the connected Google account and match the mailbox to the right address. |
| https://mail.google.com/ | To connect to Gmail over IMAP and SMTP: read incoming and sent correspondence and save the messages that match contacts and companies in the CRM, and send e-mails the user writes in the CRM from their own Gmail account. Gmail grants IMAP / SMTP access only with this permission. |
- Data accessed: the account's e-mail address; the headers (sender, recipients, subject, date, message ID) and body of messages in the Inbox and Sent folders. Attachments are not downloaded. On first connection, the app looks back over the period the user chooses (by default, the last 30 days).
- How it is used: only for user-facing CRM features: linking two-way correspondence with contacts and customer companies in the CRM to the related company, project and records (sections 2 and 3); where the company leaves the setting on, creating a prospect company and contact from two-way correspondence with a new business domain; and sending the e-mails the user writes in the CRM. Messages that do not match the CRM are read and discarded without being stored.
- Sharing: the data is kept only in the Solk installation belonging to the user's company. Depending on the user's choice, teammates see either the full message or only its subject and participants. Data received from Google is not sold, not used for advertising, and not transferred to data brokers or other apps. If the AI feature turned on by the company is used (off by default, section 6), the record summary needed to answer a user's question may include only an e-mail's subject and date; message bodies and e-mail addresses are never sent. This summary is sent only to generate that answer and is not used by the provider to train models.
- Human access: Solk staff do not read e-mail content received from Google. The only exceptions are: with the user's explicit consent for specific messages (for example, in a support request); for security purposes (investigating abuse or a vulnerability); to comply with applicable law; and for internal operations using aggregated, de-identified statistics.
- No AI training: data received from Google is not used to develop, improve or train generalised artificial intelligence or machine-learning models.
- Protection: Google access and refresh tokens are stored encrypted on the server, used only for syncing and sending, and never sent to the user's browser or the mobile app. All connections are encrypted with TLS. Each company's installation runs on a separate database, and access is limited by role, module and record permissions (section 10).
- Retention and deletion: correspondence saved in the CRM becomes part of the company's records and is kept for as long as the installation exists. When the user clicks "Remove connection" on the E-mail account page, the Google access and refresh tokens are deleted from the installation immediately and no new data is fetched. You can also revoke access from your Google account's Third-party connections page. You can ask your company's administrator or info@solk.app to delete correspondence saved in the CRM: the request is fulfilled within 30 days, and deleted data drops out of backups within 60 days at the latest. When the company's agreement ends, the installation and its backups are deleted as described in section 8.
8. How long it is kept
Records are kept for as long as your company's installation exists; customer company records are not deleted but deactivated (history is preserved), and permanent deletion is done only by an administrator, after a backup. When the agreement ends, your company can export its data within 30 days; the installation is then deleted, and the archive backup taken before deletion is destroyed within 90 days at the latest. Security records (sign-ins, IP addresses) are kept for a limited, reasonable period. E-mail addresses that have unsubscribed are kept on a "do not send" list for as long as the installation exists, so they are not sent sequence e-mails again.
9. Your rights
Under Article 11 of KVKK you have the right to learn whether your data is processed, request information, learn whether it is used for its intended purpose, request correction if it is incomplete or inaccurate, request its deletion or destruction, object, and claim compensation if you suffer damage. Because your company is the data controller, you should first apply to your company; Solk technically assists your company in responding. You can also write to us and we will forward the request to the company concerned.
10. Security
- TLS in transit; passwords stored as one-way hashes; temporary lockout after repeated failed sign-ins.
- A separate database and backups per installation; permission-based access (role + module + record ownership). If your company's administrator chooses team visibility, a sales user sees only their own customer records, those of colleagues in the same department, and companies without an assigned owner; this restriction applies equally on the web, in the mobile app, in reports and in the AI assistant.
- All deletions and blocked edit attempts are recorded in the audit trail.
- Optional two-step verification (authenticator-app code, on web and mobile) and access restricted to IP addresses set by the company.
- Files attached to records are served only to authorised users through a session- and permission-checked address; no public links are created.
- Mobile tokens are stored only as hashes and are valid for a limited time.
- The connected mailbox's app password or Google / Microsoft access tokens are stored encrypted on the server and used only for syncing and sending; when the mail server's certificate cannot be verified, the connection is made only to a certificate the user has explicitly trusted. Unsubscribe links are signed (nobody can unsubscribe on someone else's behalf); team invitation links are single-use, expire after 7 days and are stored only as hashes.
11. Children
Solk is a business application and is not intended for anyone under 18; we do not knowingly collect data from children.
12. Changes
When this policy changes, the effective date and version number are updated, and material changes are also announced to installation administrators. The current version is always at solk.app/en/privacy.html; the Turkish version at solk.app/gizlilik.html prevails in case of a discrepancy.