Skip to content
Legal

Privacy Policy

Last updated: September 26, 2026

At Rapitek CRM, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

1. Information We Collect

Personal Information

We may collect personal information that you provide directly to us, such as:

  • Name and contact information (email address, phone number)
  • Company name and job title
  • Billing and payment information
  • Account credentials
  • Communications you send to us
  • Voice recordings and, only if you enable it, your biometric voiceprint (see Section 11)
  • Meeting audio you choose to record, and the transcripts derived from it
  • Messages, comments and attachments exchanged through connected channels such as WhatsApp and Instagram (see Section 12)
  • Photographs you upload, including scanned business card images
  • Your approximate or precise location when you check in to a visit from the mobile app

Automatically Collected Information

We never measure how long you spend on our pages. If you accept the cookie banner, we record the pages you visit in that session, the page language, the site that referred you, and the time of your visit on our website's server, linked to the rgo_oturum measurement cookie (a random identifier); if you don't accept, no such record is created, and you can withdraw your consent at any time. This browsing record is deleted after 90 days. If you submit a form on our site while the consent you gave in the cookie banner is in effect, a short summary of your browsing (at most 50 steps) is saved with your enquiry, and that summary is not deleted after 90 days: on our site it is kept with your enquiry for 24 months from the date the form was submitted, and its copy in our customer relationship management (CRM) system is kept there together with your enquiry record for as long as that record exists.

Our website's server also keeps technical access logs for security and troubleshooting: for normal requests, only the last segment of your IP address is truncated (the last octet for IPv4, all but the first three groups for IPv6) — kept for at most 15 days together with the requested address, the referring site, your browser information, the status code and duration. If a request errors, that request's log entry keeps your IP address untruncated, also for at most 15 days. Application and security logs (which may contain IP addresses) are kept for security and debugging purposes; on our website's server, these logs are kept for at most 90 days. On the servers of the Rapitek CRM application, server access and error logs (which contain full IP addresses) are kept for at most 365 days and API usage records (which contain IP addresses) for at most 400 days; no automatic deletion period is yet applied to application error and login records (which may contain IP addresses). Records matching a security incident (an attack, harassment or a threat) are additionally kept as evidence, as a copy. This copy is not subject to the automatic periods above; it is kept for as long as the investigation and any legal proceedings require, and deleted when it is no longer needed.

We do not use Google Analytics or any other third-party analytics, advertising or remarketing cookies.

Special Categories of Personal Data

The only special-category (sensitive) personal data Rapitek processes is the biometric voiceprint described in Section 11, and only where you have given separate, explicit consent. Beyond that, Rapitek does not need health, religious, political, trade-union, sex-life, criminal-record or similar sensitive data in order to deliver the service, and we strongly ask that you do not enter such data into free-text CRM fields.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send you technical notices and support messages
  • Respond to your comments and questions
  • Send marketing communications (with your consent)
  • Monitor and analyze trends and usage
  • Detect and prevent fraudulent transactions
  • Comply with legal obligations

3. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following situations:

  • With your consent
  • With service providers who assist in our operations
  • To comply with legal obligations
  • To protect our rights and prevent fraud
  • In connection with a business transfer or merger
  • With the AI, email and messaging service providers named explicitly in Section 13, processing only on our instructions and on our behalf

4. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access and receive a copy of your personal information
  • Correct or update your personal information
  • Delete your personal information
  • Object to or restrict processing of your personal information
  • Data portability
  • Withdraw consent

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our website and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. See our Cookie Policy for details.

Measurement in e-mails. In the e-mails we send you, we measure whether the message is opened and whether the links inside it are clicked. To do this a small invisible image is placed in the message and links are routed through our measurement address; in the process the time of opening, your IP address and information about the e-mail program you use are recorded. This processing rests on our legitimate interest under article 5(2)(f) of Law No. 6698. For details and how to reach us, see our KVKK Privacy Notice.

E-mails sent by our customers. The same measurement runs when a business using Rapitek CRM e-mails its own customers. In that case the data controller is that business; Rapitek acts as a data processor. If you received an e-mail from such a business, you should direct any request about this measurement to that business.

8. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction. Our infrastructure is within the European Union and consists of three separate locations: the application and the database are in Helsinki (Finland), the files you upload (attachments, images and any meeting audio you choose to record) are in Frankfurt (Germany), and database backups are in Falkenstein (Germany). The specific recipients, the countries they operate in, and the legal basis for each transfer are set out in detail in Section 13.

9. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.

10. Mobile Application

The Rapitek mobile app accesses, with your permission: location (while-in-use only, for visit check-in and showing nearby records — never tracked in the background), camera (to scan business cards and barcodes), microphone (to record voice notes and to record meetings you choose to record), photo library (to attach card images), and your phone's contacts (only to WRITE a lead you pick into your address book — your address book is never read and never uploaded to our servers). The app also registers a push notification token so your company's CRM can alert you. This data is processed solely within your company's CRM account, encrypted in transit (HTTPS/TLS), never sold to third parties, and deletable on request. The app requires a Rapitek account provided by your company.

Meeting recording and voice notes. Audio you record is uploaded to your company's CRM account and transcribed on Rapitek's own servers — the audio file itself is never sent to any AI provider. As a file, it is held with the storage provider named in Section 13 (DigitalOcean Spaces, Frankfurt / Germany), in the space allocated to your company. What happens to the resulting text is described in Section 13. You are responsible for obtaining the consent of everyone present before recording a meeting. If you are considering enabling the optional voice profile feature, please read Section 11 — that feature processes biometric data.

11. Biometric Voice Profile (Voiceprint)

This feature is optional, off by default, and is never required in order to use Rapitek.

Only if you turn the feature on yourself in the mobile app (Profile → My Voice Profile), Rapitek records a roughly 30-second sample of you speaking and derives a voiceprint from it: a numeric representation of your voice (a vector of about 192 values). The voiceprint's sole purpose is to let meeting analytics tell your speech apart from everyone else's, so it can measure how much of a meeting you spoke versus the other side.

What happens to the raw clip. The 30-second clip is uploaded over an encrypted connection and used once to compute the voiceprint. The raw voice recording taken to create the voiceprint is deleted immediately after it has been processed (the version copy at the storage provider is removed within 30 days at most); if processing is interrupted, the recording may remain until it is deleted separately. The only thing kept permanently is the voiceprint itself, stored encrypted at rest. The raw clip is never used to train any AI model and is never shared with any third party.

Whose voice. A voiceprint is only ever created for the person who enabled the feature, from their own account and their own voice. We do not create or store a voiceprint for anyone else in a meeting — other speakers' audio is compared segment by segment during the analysis and discarded immediately afterwards.

Legal basis. A voiceprint is biometric data and constitutes a special category of personal data under Article 6 of Turkish Personal Data Protection Law No. 6698 (KVKK) and Article 9 of the GDPR. We process it solely on the basis of the data subject's explicit consent. That consent is given by ticking a dedicated, purpose-specific box in the app before any recording starts; it is not bundled into acceptance of the general terms or any other permission. The consent is recorded with a version number and a timestamp.

Withdrawing consent and deletion. You can withdraw your consent at any time, without giving a reason and with no adverse effect on your use of the product: in the mobile app, go to Profile → My Voice Profile → Delete my voice profile. When you withdraw your consent, when your user account is closed or when your account is scheduled for deletion, your voiceprint is deleted from the live system immediately and irreversibly; it is deleted from backup copies when those backups are deleted (backup retention periods and their exceptions are set out on our security page). Once consent is withdrawn, meeting analytics falls back to an approximate mode that uses no biometric data at all, and the rest of the feature keeps working. You can also request deletion through the contact details in Section 16 or via our data deletion page.

Retention. The voiceprint is kept only while your explicit consent stands and your account is active. It is deleted from the live system when you withdraw consent, when your account is closed or when your account is scheduled for deletion — whichever happens first; it is deleted from backup copies when those backups are deleted. If we discontinue the feature, we will also delete voiceprints from the live system. The voiceprint is never transferred to any AI provider, any advertising network or any third party; it never leaves your company's own database.

12. Instagram and Connected Messaging Channels

Rapitek's shared inbox connects to messaging channels on behalf of the business that uses it. When a business connects its WhatsApp Business number or its Instagram professional account, Rapitek receives and stores the following, inside that business's own CRM account only:

  • direct messages exchanged with the account, and any photos, voice notes, videos, documents and locations sent in them
  • public comments on the account's Instagram posts, and the replies made to them
  • the sender's platform identifier, public username or display name, and profile picture. For Instagram this identifier is a page-scoped ID — it is not a phone number and it does not include your Instagram password or login details
  • delivery, read and timestamp metadata

For this content Rapitek acts as the data processor; the business operating the account is the data controller and decides why the data is kept and for how long. Message and comment content is not used for advertising, is not sold, and is not used to train AI models. Instagram data reaches us through Meta's official Graph API, within the permissions the business granted when connecting the account, and the business can disconnect it at any time from the Setup screen, which stops all further processing immediately.

If you messaged a Rapitek customer on Instagram or WhatsApp and want your messages deleted, you need to contact that business directly. If you messaged Rapitek's own account, use the contact details in Section 16 or our data deletion page.

13. AI Processing and Transfers Abroad

Some Rapitek features are powered by large language models. When those features are used, only the content needed for that specific task leaves our servers and is processed by the provider named explicitly below:

  • Rapi, the in-CRM assistant — the text of your request, or its speech-to-text transcription, together with the CRM records needed to answer it, is sent to Anthropic PBC (United States).
  • Business card scanning — the photo of the card you scan is sent to Anthropic PBC (United States) so the contact details on it can be read.
  • Meeting summaries and coaching notes — the audio is transcribed on Rapitek's own servers; the audio file itself is never sent to any AI provider. Only the resulting text transcript and the computed statistics are sent to Anthropic PBC (United States).
  • Your voiceprint is never sent to any AI provider. It is encrypted at the application level and stays inside your company's own database.

Anthropic processes this content for one purpose only — returning the result to us. Under Anthropic's commercial terms of use, content sent through the API is not used to train their models — this rests on the provider's own publicly available commercial terms and is accurate as of August 2026. We do not use OpenAI or any other model provider for these features.

The other sub-processors we rely on to provide the service, and the countries they operate in:

  • Cloudflare, Inc. — content delivery network, TLS termination, web application firewall and bot protection; the edge server nearest the visitor, company headquartered in the United States. No content is stored there; connection traffic and the visitor's IP are processed at that layer.
  • Hetzner Online GmbH — application server and database hosting; Helsinki / Finland (European Union).
  • Hetzner Storage Box — storage of database backups; Falkenstein / Germany (European Union).
  • DigitalOcean Spaces — storage of the files you upload (attachments, images and any meeting audio you choose to record); Frankfurt / Germany (European Union). A separate storage space is used for each customer.
  • Amazon Web Services (Simple Email Service) — delivery of outbound email; Frankfurt / Germany (European Union).
  • Sentry — application error monitoring; Germany (European Union). It is configured with personal data transmission switched off.
  • Meta Platforms (United States / Ireland) — the WhatsApp Business and Instagram channels described in Section 12.
  • Google LLC (United States) — the Gmail (sending) and Google Calendar (reading, creating, updating and deleting events) connection described in Section 14, only when a user connects their own Google account.

This is Section 8 in concrete terms. For data subjects located in Türkiye, these operations constitute a transfer of personal data abroad within the meaning of Article 9 of Law No. 6698, and there is no adequacy decision issued by the Board for the countries to which the transfer is made. For data subjects in the European Economic Area, transfers to the United States are made under the European Commission's Standard Contractual Clauses. As stated in Section 3, we do not sell, trade or rent your personal information; the providers named here process it only on our instructions.

14. Google Workspace Data (Gmail and Google Calendar)

Rapitek lets a user connect their own Google account so that the CRM can act on their behalf. The connection is made through Google OAuth: Rapitek never sees, receives or stores your Google password. A user connects only their own Google account. Rapitek reads and writes events only in that account's primary calendar and does not access the user's other calendars; connecting one account gives Rapitek no access to any other person's Google account.

When a Google account is connected, Rapitek requests these permissions and no others:

  • Send email on your behalf (gmail.send) — to send quotes, follow-ups and campaign messages that you compose in Rapitek from your own address, so that replies come back to you. Rapitek never sends without an action you started or a campaign you configured yourself.
  • See and download your calendars (calendar.readonly) — to show your meetings on the timeline of the matching customer record, and to check your availability when scheduling.
  • View and edit events on your calendars (calendar.events) — to let you create, update or delete calendar events (for example, customer meetings) from inside Rapitek so that the change is reflected in the primary calendar of your own connected Google account. Deleting an event in Rapitek also deletes it from that Google calendar; marking a meeting as cancelled in Rapitek does not change it in Google. When an event has guests, Google may email them an invitation, update or cancellation; Rapitek does not send update or cancellation notices for events that have already taken place.
  • Your email address and basic profile (userinfo.email, userinfo.profile) — to identify which mailbox was connected and to show it back to you.

Events in the connected primary calendar within a limited time window (30 days back, 90 days ahead), including invitations received from other people, are copied into Rapitek (title, start and end time, description and location). Attendee, organizer and creator email addresses are used only to link an event to a matching Rapitek user, lead or contact and are not stored as separate fields. Copied events are visible to other users in your Rapitek organization only as permitted by its sharing and permission settings. When a lead or contact is attached to a meeting in Rapitek, that person's email address is sent to Google as an attendee.

Rapitek does not request permission to read the contents of your Gmail mailbox. Where an account was granted mailbox reading separately and explicitly, incoming and outgoing mail is recorded on the matching customer record inside that organisation's own CRM account; where it was not granted, Rapitek has no technical ability to read your messages at all.

Access and refresh tokens are stored encrypted, inside the separate database belonging to the customer organisation whose CRM account you use. Calendar events and messages copied into the CRM are visible only within that organisation's own CRM account and are subject to its own sharing rules. For this content the organisation operating the CRM account is the data controller and Rapitek acts as the data processor.

If you use Rapi, our in-app AI assistant, it may read email messages and calendar events that were copied into the CRM from your connected Google account — such as subject, sender and recipients (including Cc/Bcc), dates, labels, the first 500 characters of the message body (plain-text and HTML versions), and event title, time, location and description — and send them to Anthropic PBC (see Section 13) only as needed to answer a request you make to Rapi.

Rapitek's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: data obtained through these scopes is used only to provide and improve the user-facing features described above; it is never sold, and never transferred to advertising platforms, data brokers or information resellers; it is not used for advertising; it is not used to train generalised artificial intelligence or machine-learning models; and it is not read by our staff except with your explicit permission, for security purposes such as investigating abuse, to comply with applicable law, or in aggregated and anonymised form for internal operations.

You can disconnect a Google account at any time from the Setup screen in Rapitek. Disconnecting stops all further access by Rapitek — no further mail is sent and no further calendar data is read. Because disconnecting inside Rapitek does not by itself withdraw the permission you granted at Google, we recommend that you also remove Rapitek from your Google Account permissions page. To have data that was already copied into a CRM account deleted, contact the organisation that operates that account, or use the contact details in Section 16 and our data deletion page.

15. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the 'Last updated' date.

16. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Rapitek Bilişim Teknolojileri A.Ş.
Maslak Mah. Büyükdere Cad.
Nurol Plaza 255, B02
34485 Sarıyer / Istanbul, Turkey
E-mail: info@rapitek.com

FAQ

Frequently asked privacy questions

What personal data does Rapitek collect?
Information you give us directly: your name and contact details, company name and job title, billing and payment information, account credentials, communications you send us, photographs you upload (including scanned business cards), meeting audio you choose to record and its transcripts, messages, comments and attachments exchanged through connected WhatsApp and Instagram channels, and your approximate or precise location when you check in to a visit from the mobile app. If you accept cookies, we log pages visited, referrer and visit time; else no such record exists; time-on-page is never measured. The only special-category data we process is the biometric voiceprint, and only if you enable it yourself; we ask you not to enter health, religious or political data into free-text CRM fields.
Where is my data stored?
Our infrastructure is in the European Union and consists of three locations: the application and the database in Helsinki (Finland), the files you upload in Frankfurt (Germany), and database backups in Falkenstein (Germany). Outbound email is delivered through Amazon Web Services (Simple Email Service) in the Frankfurt region, also in the European Union. The specific recipients, the countries they operate in and the legal basis for each transfer are set out in detail in Section 13 of the policy.
Is my data transferred abroad, and to whom?
With the AI-powered features, only the content needed for that task leaves our servers: the text of your request to Rapi and the CRM records needed to answer it, the photo of a business card you scan, and a meeting transcript with its statistics — sent to Anthropic PBC (United States). Meeting audio is transcribed on our own servers and the audio file itself is never sent to any AI provider; as a file it is held with DigitalOcean Spaces (Frankfurt), named in Section 13. Your voiceprint is never sent to any AI provider either. For data subjects in Türkiye this is a transfer abroad under Article 9 of Law No. 6698, with no adequacy decision from the Board; for the EEA, US transfers use the Standard Contractual Clauses. Full list in Section 13.
What is the biometric voiceprint, is it required, and how do I delete it?
The voice profile feature is optional, off by default, and never required to use Rapitek. Only if you turn it on yourself (Profile → My Voice Profile) does Rapitek record a roughly 30-second sample and derive a voiceprint: a vector of about 192 values whose sole purpose is to let meeting analytics tell your speech apart from everyone else's. The raw clip is used once and deleted immediately unless processing is interrupted; the only thing kept permanently is the voiceprint, stored encrypted. A voiceprint is special-category biometric data under Article 6 of Law No. 6698 and Article 9 of the GDPR, processed solely on the explicit consent you give through a dedicated checkbox before any recording starts. You can withdraw it at any time: Profile → My Voice Profile → Delete my voice profile.
What happens to the messages I send through WhatsApp or Instagram?
When a business connects its WhatsApp Business number or Instagram professional account, Rapitek stores the following inside that business's own CRM account only: direct messages and any photos, voice notes, videos, documents and locations in them; public comments on the account's Instagram posts and the replies; the sender's platform identifier, username and profile picture; and delivery, read and timestamp metadata. For Instagram that identifier is a page-scoped ID — not a phone number. Here Rapitek is the data processor, while the business operating the account is the data controller and decides why and how long data is kept. Content is not used for advertising, not sold, and not used to train AI models.
What rights do I have over my personal data and how do I exercise them?
Depending on your location you may have the right to access your personal information and receive a copy of it, to correct or update it, to have it deleted, to object to or restrict its processing, to data portability, and to withdraw consent you previously gave. If you are located in the European Union or Türkiye you have additional rights under the GDPR and Türkiye's data protection law (KVKK, Law No. 6698). To exercise your rights or ask for more information, reach us through our contact form; for deletion requests you can use our Data Deletion Instructions page. Our company name and postal address are given in Section 16 of the policy.

For EU and Turkish Residents

If you are located in the European Union or Turkey, you have additional rights under the GDPR and Turkey's data protection law (KVKK, Law No. 6698). For more information or to exercise your rights, please reach us through our contact form; for deletion requests you can use our Data Deletion Instructions page.

Made with RapitekGO

We would like to use optional cookies to measure your visit. The site works exactly the same if you decline. Cookie policy