Privacy policy

How we handle your data.

This policy covers the Solk web application (company.solk.app) and the Solk mobile app (iOS / Android). We have kept it plain; if anything is unclear, write to us.

Effective: 1 October 2026Version 1.7Scope: web · iOS · Android
In short: Solk is a CRM installed for your company's sales team. Your company enters the records, the data belongs to your company and stays only in your company's installation. Solk shows no ads, sells no data and does no behavioural tracking; the mobile app asks for neither location nor contacts.

1. Who is who

The data controller is the company using the Solk installation (for example, the employer who invited you): it decides what data is entered, who can access it and how long it is kept. Solk is the data processor that hosts the data and operates the software on that company's instructions. Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and, where applicable, the GDPR follow this distinction.

Your user account is created by your company's administrator, not by Solk. There is no sign-up or membership on Solk's website (solk.app).

2. Data we process

DataSourceExamples
User accountYour company's administratorname, username, e-mail, role, assigned modules, password hash (the password itself is not stored)
CRM recordsEntered by you and your teamcustomer company details; contacts' names, titles, phone numbers and e-mail addresses; visit, call and trial notes; quotes, orders, contracts and support tickets; files attached to records (data sheets, photos, signed documents); calendar events; trade-fair leads
Usage recordsSystemsign-in time and IP address (security), audit trail of deletions and blocked edit attempts, which user used which module (licence metering)
Calendar syncOptionalif you add a calendar account on your iPhone / Mac, CRM events appear on your phone and events you create on the phone are brought into the CRM
E-mail syncOptional, connected by the userif you connect your mailbox (with an IMAP/SMTP app password, or by granting access with your Google / Microsoft account), only your two-way correspondence with contacts in the CRM, with customer companies' domains or with business addresses (sender, recipients, subject, date, body) is brought into the CRM; public webmail addresses (Gmail, Hotmail, etc.), newsletters, auto-replies, delivery reports and addresses your company has excluded are not stored, and your other e-mails are read and discarded. You choose whether the body is shared with your team; you can remove the connection at any time. Section 7 describes Google user data in detail
Automatic company and contact records from e-mailTurned on or off by your company's administrator (on by default)when there is two-way correspondence with an unknown business domain (at least one e-mail sent from you to that domain), the company is created as a "prospect" and the correspondent as a contact: name, e-mail address, and the title, phone number and company name from the e-mail signature. For this, the number of incoming / outgoing messages per address is kept (not the content). Generic addresses (info@, sales@ …), public and educational institutions, banks, couriers and software services are never created as companies or contacts. A wrongly created company can be deactivated with one click and its domain excluded for good
E-mail sequences, scheduled and bulk sendingThe userrecipient's name and e-mail address, which step was sent when, whether a reply arrived or the recipient unsubscribed; drafts waiting to be sent and their attachments
Ask (assistant) questionsThe userthe question you asked, a summary of the answer and the records linked in it (for chat history and usage limits)

Solk does not ask for or store national ID numbers, card details, location history or your phone's contacts. Your company decides what is written in free-text fields and sets guidance to avoid entering sensitive data.

3. What it is used for

No profiling, ad targeting or third-party analytics is performed. The website and app use no tracking cookies; only the essential cookie that keeps you signed in is used.

4. Where it is stored

Each company's installation runs on its own subdomain with its own database; no tables are shared with another company. Data is kept on servers managed by Solk and backed up daily; backups are also per company. Data in transit is always encrypted (HTTPS; .app domains do not open without encryption).

The server location and any cross-border transfer terms are set out in the service agreement with your company; you can ask for details at info@solk.app.

5. Mobile app (iOS / Android)

The Solk mobile app is a client that connects to your company's installation (the address you enter on the sign-in screen). The app itself collects no data; everything you see comes from your installation.

6. Who it is shared with

Data is never sold, rented or shared for advertising.

7. Signing in with Google (Google user data)

This section describes the data received from Google when a user connects a Gmail or Google Workspace account with "Sign in with Google" on the E-mail account page. Connecting is optional; if a user does not connect, no data in their Google account is accessed.

Permission requestedWhy
openid emailTo learn the e-mail address of the connected Google account and match the mailbox to the right address.
https://mail.google.com/To connect to Gmail over IMAP and SMTP: read incoming and sent correspondence and save the messages that match contacts and companies in the CRM, and send e-mails the user writes in the CRM from their own Gmail account. Gmail grants IMAP / SMTP access only with this permission.
Limited Use: Solk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. How long it is kept

Records are kept for as long as your company's installation exists; customer company records are not deleted but deactivated (history is preserved), and permanent deletion is done only by an administrator, after a backup. When the agreement ends, your company can export its data within 30 days; the installation is then deleted, and the archive backup taken before deletion is destroyed within 90 days at the latest. Security records (sign-ins, IP addresses) are kept for a limited, reasonable period. E-mail addresses that have unsubscribed are kept on a "do not send" list for as long as the installation exists, so they are not sent sequence e-mails again.

9. Your rights

Under Article 11 of KVKK you have the right to learn whether your data is processed, request information, learn whether it is used for its intended purpose, request correction if it is incomplete or inaccurate, request its deletion or destruction, object, and claim compensation if you suffer damage. Because your company is the data controller, you should first apply to your company; Solk technically assists your company in responding. You can also write to us and we will forward the request to the company concerned.

10. Security

11. Children

Solk is a business application and is not intended for anyone under 18; we do not knowingly collect data from children.

12. Changes

When this policy changes, the effective date and version number are updated, and material changes are also announced to installation administrators. The current version is always at solk.app/en/privacy.html; the Turkish version at solk.app/gizlilik.html prevails in case of a discrepancy.

13. Contact

Solk Privacy and data requests: info@solk.app Web: solk.app