Skip to content
Legal

Privacy Policy

Last updated: July 27, 2026

At Rapitek CRM, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

1. Information We Collect

Personal Information

We may collect personal information that you provide directly to us, such as:

  • Name and contact information (email address, phone number)
  • Company name and job title
  • Billing and payment information
  • Account credentials
  • Communications you send to us
  • Voice recordings and, only if you enable it, your biometric voiceprint (see Section 11)
  • Meeting audio you choose to record, and the transcripts derived from it
  • Messages, comments and attachments exchanged through connected channels such as WhatsApp and Instagram (see Section 12)
  • Photographs you upload, including scanned business card images
  • Your approximate or precise location when you check in to a visit from the mobile app

Automatically Collected Information

When you visit our website, we automatically collect certain information about your device, including:

  • IP address
  • Browser type and version
  • Operating system
  • Referring website
  • Pages viewed and time spent on pages

Special Categories of Personal Data

The only special-category (sensitive) personal data Rapitek processes is the biometric voiceprint described in Section 11, and only where you have given separate, explicit consent. Beyond that, Rapitek does not need health, religious, political, trade-union, sex-life, criminal-record or similar sensitive data in order to deliver the service, and we strongly ask that you do not enter such data into free-text CRM fields.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send you technical notices and support messages
  • Respond to your comments and questions
  • Send marketing communications (with your consent)
  • Monitor and analyze trends and usage
  • Detect and prevent fraudulent transactions
  • Comply with legal obligations

3. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following situations:

  • With your consent
  • With service providers who assist in our operations
  • To comply with legal obligations
  • To protect our rights and prevent fraud
  • In connection with a business transfer or merger
  • With the AI, email and messaging service providers named explicitly in Section 13, processing only on our instructions and on our behalf

4. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access and receive a copy of your personal information
  • Correct or update your personal information
  • Delete your personal information
  • Object to or restrict processing of your personal information
  • Data portability
  • Withdraw consent

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our website and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. See our Cookie Policy for details.

Measurement in e-mails. In the e-mails we send you, we measure whether the message is opened and whether the links inside it are clicked. To do this a small invisible image is placed in the message and links are routed through our measurement address; in the process the time of opening, your IP address and information about the e-mail program you use are recorded. This processing rests on our legitimate interest under article 5(2)(f) of Law No. 6698. For details and how to reach us, see our KVKK Privacy Notice.

E-mails sent by our customers. The same measurement runs when a business using Rapitek CRM e-mails its own customers. In that case the data controller is that business; Rapitek acts as a data processor. If you received an e-mail from such a business, you should direct any request about this measurement to that business.

8. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction. Our infrastructure is within the European Union and consists of three separate locations: the application and the database are in Helsinki (Finland), the files you upload (attachments, images and any meeting audio you choose to record) are in Frankfurt (Germany), and database backups are in Falkenstein (Germany). The specific recipients, the countries they operate in, and the legal basis for each transfer are set out in detail in Section 13.

9. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.

10. Mobile Application

The Rapitek mobile app accesses, with your permission: location (while-in-use only, for visit check-in and showing nearby records — never tracked in the background), camera (to scan business cards and barcodes), microphone (to record voice notes and to record meetings you choose to record), photo library (to attach card images), and your phone's contacts (only to WRITE a lead you pick into your address book — your address book is never read and never uploaded to our servers). The app also registers a push notification token so your company's CRM can alert you. This data is processed solely within your company's CRM account, encrypted in transit (HTTPS/TLS), never sold to third parties, and deletable on request. The app requires a Rapitek account provided by your company.

Meeting recording and voice notes. Audio you record is uploaded to your company's CRM account and transcribed on Rapitek's own servers — the audio file itself is never sent to any AI provider. As a file, it is held with the storage provider named in Section 13 (DigitalOcean Spaces, Frankfurt / Germany), in the space allocated to your company. What happens to the resulting text is described in Section 13. You are responsible for obtaining the consent of everyone present before recording a meeting. If you are considering enabling the optional voice profile feature, please read Section 11 — that feature processes biometric data.

11. Biometric Voice Profile (Voiceprint)

This feature is optional, off by default, and is never required in order to use Rapitek.

Only if you turn the feature on yourself in the mobile app (Profile → My Voice Profile), Rapitek records a roughly 30-second sample of you speaking and derives a voiceprint from it: a numeric representation of your voice (a vector of about 192 values). The voiceprint's sole purpose is to let meeting analytics tell your speech apart from everyone else's, so it can measure how much of a meeting you spoke versus the other side.

What happens to the raw clip. The 30-second clip is uploaded over an encrypted connection, used once to compute the voiceprint, and then deleted from our servers as soon as that is done. The only thing kept permanently is the voiceprint itself, stored encrypted at rest. The raw clip is never used to train any AI model and is never shared with any third party.

Whose voice. A voiceprint is only ever created for the person who enabled the feature, from their own account and their own voice. We do not create or store a voiceprint for anyone else in a meeting — other speakers' audio is compared segment by segment during the analysis and discarded immediately afterwards.

Legal basis. A voiceprint is biometric data and constitutes a special category of personal data under Article 6 of Turkish Personal Data Protection Law No. 6698 (KVKK) and Article 9 of the GDPR. We process it solely on the basis of the data subject's explicit consent. That consent is given by ticking a dedicated, purpose-specific box in the app before any recording starts; it is not bundled into acceptance of the general terms or any other permission. The consent is recorded with a version number and a timestamp.

Withdrawing consent and deletion. You can withdraw your consent at any time, without giving a reason and with no adverse effect on your use of the product: in the mobile app, go to Profile → My Voice Profile → Delete my voice profile. The voiceprint is then deleted immediately and permanently. Meeting analytics falls back to an approximate mode that uses no biometric data at all, and the rest of the feature keeps working. You can also request deletion through the contact details in Section 15 or via our data deletion page.

Retention. The voiceprint is kept only while your explicit consent stands and your account is active. It is deleted when you withdraw consent, when your account is closed, or when the feature is discontinued — whichever happens first. The voiceprint is never transferred to any AI provider, any advertising network or any third party; it never leaves your company's own database.

12. Instagram and Connected Messaging Channels

Rapitek's shared inbox connects to messaging channels on behalf of the business that uses it. When a business connects its WhatsApp Business number or its Instagram professional account, Rapitek receives and stores the following, inside that business's own CRM account only:

  • direct messages exchanged with the account, and any photos, voice notes, videos, documents and locations sent in them
  • public comments on the account's Instagram posts, and the replies made to them
  • the sender's platform identifier, public username or display name, and profile picture. For Instagram this identifier is a page-scoped ID — it is not a phone number and it does not include your Instagram password or login details
  • delivery, read and timestamp metadata

For this content Rapitek acts as the data processor; the business operating the account is the data controller and decides why the data is kept and for how long. Message and comment content is not used for advertising, is not sold, and is not used to train AI models. Instagram data reaches us through Meta's official Graph API, within the permissions the business granted when connecting the account, and the business can disconnect it at any time from the Setup screen, which stops all further processing immediately.

The Instagram direct-messaging connection is not open in customer setups today; the parts of this section that concern direct messages describe the processing that will apply once that connection is open. This limitation does not cover public comments on the account's Instagram posts.

If you messaged a Rapitek customer on Instagram or WhatsApp and want your messages deleted, you need to contact that business directly. If you messaged Rapitek's own account, use the contact details in Section 15 or our data deletion page.

13. AI Processing and Transfers Abroad

Some Rapitek features are powered by large language models. When those features are used, only the content needed for that specific task leaves our servers and is processed by the provider named explicitly below:

  • Rapi, the in-CRM assistant — the text of your request, or its speech-to-text transcription, together with the CRM records needed to answer it, is sent to Anthropic PBC (United States).
  • Business card scanning — the photo of the card you scan is sent to Anthropic PBC (United States) so the contact details on it can be read.
  • Meeting summaries and coaching notes — the audio is transcribed on Rapitek's own servers; the audio file itself is never sent to any AI provider. Only the resulting text transcript and the computed statistics are sent to Anthropic PBC (United States).
  • Your voiceprint is never sent to any AI provider. It stays inside your company's own database, encrypted.

Anthropic processes this content for one purpose only — returning the result to us. Under Anthropic's commercial terms of use, content sent through the API is not used to train their models — this rests on the provider's own publicly available commercial terms and is accurate as of August 2026. We do not use OpenAI or any other model provider for these features.

The other sub-processors we rely on to provide the service, and the countries they operate in:

  • Cloudflare, Inc. — content delivery network, TLS termination, web application firewall and bot protection; the edge server nearest the visitor, company headquartered in the United States. No content is stored there; connection traffic and the visitor's IP are processed at that layer.
  • Hetzner Online GmbH — application server and database hosting; Helsinki / Finland (European Union).
  • Hetzner Storage Box — storage of database backups; Falkenstein / Germany (European Union).
  • DigitalOcean Spaces — storage of the files you upload (attachments, images and any meeting audio you choose to record); Frankfurt / Germany (European Union). A separate storage space is used for each customer.
  • Amazon Web Services (Simple Email Service) — delivery of outbound email; Frankfurt / Germany (European Union).
  • Sentry — application error monitoring; Germany (European Union). It is configured with personal data transmission switched off.
  • Meta Platforms (United States / Ireland) — the WhatsApp Business and Instagram channels described in Section 12.

This is Section 8 in concrete terms. For data subjects located in Türkiye, these operations constitute a transfer of personal data abroad within the meaning of Article 9 of Law No. 6698, and there is no adequacy decision issued by the Board for the countries to which the transfer is made. For data subjects in the European Economic Area, transfers to the United States are made under the European Commission's Standard Contractual Clauses. As stated in Section 3, we do not sell, trade or rent your personal information; the providers named here process it only on our instructions.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the 'Last updated' date.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Rapitek Bilişim Teknolojileri A.Ş.
Maslak Mah. Büyükdere Cad.
Nurol Plaza 255, B02
34485 Sarıyer / Istanbul, Turkey

FAQ

Frequently asked privacy questions

What personal data does Rapitek collect?
Information you give us directly: your name and contact details, company name and job title, billing and payment information, account credentials, communications you send us, photographs you upload (including scanned business cards), meeting audio you choose to record and its transcripts, messages, comments and attachments exchanged through connected WhatsApp and Instagram channels, and your approximate or precise location when you check in to a visit from the mobile app. Visiting the website also collects your IP address, browser, operating system, referring site and the pages you viewed. The only special-category data we process is the biometric voiceprint, and only if you enable it yourself; we ask you not to enter health, religious or political data into free-text CRM fields.
Where is my data stored?
Our infrastructure is in the European Union and consists of three locations: the application and the database in Helsinki (Finland), the files you upload in Frankfurt (Germany), and database backups in Falkenstein (Germany). Outbound email is delivered through Amazon Web Services (Simple Email Service) in the Frankfurt region, also in the European Union. The specific recipients, the countries they operate in and the legal basis for each transfer are set out in detail in Section 13 of the policy.
Is my data transferred abroad, and to whom?
With the AI-powered features, only the content needed for that task leaves our servers: the text of your request to Rapi and the CRM records needed to answer it, the photo of a business card you scan, and a meeting transcript with its statistics — sent to Anthropic PBC (United States). Meeting audio is transcribed on our own servers and the audio file itself is never sent to any AI provider; as a file it is held with DigitalOcean Spaces (Frankfurt), named in Section 13. Your voiceprint is never sent to any AI provider either. For data subjects in Türkiye this is a transfer abroad under Article 9 of Law No. 6698, with no adequacy decision from the Board; for the EEA, US transfers use the Standard Contractual Clauses. Full list in Section 13.
What is the biometric voiceprint, is it required, and how do I delete it?
The voice profile feature is optional, off by default, and never required in order to use Rapitek. Only if you turn it on yourself (Profile → My Voice Profile) does Rapitek record a roughly 30-second sample and derive a voiceprint: a vector of about 192 values whose sole purpose is to let meeting analytics tell your speech apart from everyone else's. The raw clip is used once and deleted immediately; the only thing kept permanently is the voiceprint, stored encrypted. A voiceprint is special-category biometric data under Article 6 of Law No. 6698 and Article 9 of the GDPR, processed solely on the explicit consent you give through a dedicated checkbox before any recording starts. You can withdraw it at any time: Profile → My Voice Profile → Delete my voice profile.
What happens to the messages I send through WhatsApp or Instagram?
When a business connects its WhatsApp Business number or Instagram professional account, Rapitek stores the following inside that business's own CRM account only: direct messages and any photos, voice notes, videos, documents and locations in them; public comments on the account's Instagram posts and the replies; the sender's platform identifier, username and profile picture; and delivery, read and timestamp metadata. For Instagram that identifier is a page-scoped ID — not a phone number. Here Rapitek is the data processor, while the business operating the account is the data controller and decides why and how long data is kept. Content is not used for advertising, not sold, and not used to train AI models.
What rights do I have over my personal data and how do I exercise them?
Depending on your location you may have the right to access your personal information and receive a copy of it, to correct or update it, to have it deleted, to object to or restrict its processing, to data portability, and to withdraw consent you previously gave. If you are located in the European Union or Türkiye you have additional rights under the GDPR and Türkiye's data protection law (KVKK, Law No. 6698). To exercise your rights or ask for more information, reach us through our contact form; for deletion requests you can use our Data Deletion Instructions page. Our company name and postal address are given in Section 15 of the policy.

Note. The Instagram direct-messaging connection is not open in customer setups today; Section 12 of the policy and the parts of the FAQ answer above that concern direct messages describe the processing that will apply once that connection is open. This limitation does not cover public comments on the account's Instagram posts.

For EU and Turkish Residents

If you are located in the European Union or Turkey, you have additional rights under the GDPR and Turkey's data protection law (KVKK, Law No. 6698). For more information or to exercise your rights, please reach us through our contact form; for deletion requests you can use our Data Deletion Instructions page.

Made with RapitekGO

We would like to use optional cookies to measure your visit. The site works exactly the same if you decline. Cookie policy