Skip to main content

Cloyk Works

Privacy Policy

Last updated: 27 September 2026

This policy explains how Cloyk handles personal data in Cloyk Works. It supplements the company-wide Cloyk Privacy Policy; where the two differ for Cloyk Works, this one applies.

1. Who we are

CLOYK YAZILIM TEKNOLOJİLERİ ANONİM ŞİRKETİ ("Cloyk", "we"), established in Türkiye, provides Cloyk Works. It is the data controller (veri sorumlusu) under Turkish Personal Data Protection Law No. 6698 (KVKK) and, where it applies, the GDPR. For account, billing-contact, website and waitlist data we are the controller. For the content your organisation stores in a workspace we act as a processor on your organisation's behalf, and your organisation is the controller.

2. Data we collect

  • Account data: name, email address, password hash, profile photo, role title, language and time zone.
  • Workspace content: projects, tasks, comments, files, time entries and anything else you or your members add.
  • Usage data: device and browser type, IP address, pages and features used, and error logs.
  • Mobile app: a push notification token for your device, if you allow notifications.
  • Waitlist data: the email address you give us and the product you are interested in.
  • Communications: messages you send to support or sales.

3. Payment data and Paddle

Payments are handled by Paddle.com, our reseller and Merchant of Record. Paddle collects your card or other payment details, billing address and tax information directly and processes them as an independent controller under the Paddle Privacy Notice. We never see or store your full card details. Paddle shares with us what we need to manage your subscription: your name, email, country, plan, seat count and payment status.

4. How we use data and our legal bases

  • To provide, secure and support the Service — performance of our contract with you.
  • To manage subscriptions and billing with Paddle — contract and legal obligation.
  • To send service messages such as security alerts and billing notices — contract.
  • To understand and improve how the Service is used, using aggregated data — legitimate interests.
  • To send waitlist and product news — consent, which you can withdraw at any time from any email.
  • To comply with the law and enforce our terms — legal obligation and legitimate interests.

5. Sharing and sub-processors

We do not sell personal data. We share it only with service providers that help us run Cloyk Works, under contracts that require them to protect it:

  • Paddle.com — payments, invoicing and tax (independent controller);
  • Supabase — database, authentication and file storage, hosted in Frankfurt, Germany;
  • Vercel — application hosting;
  • Resend — transactional and waitlist email;
  • Anthropic — only where AI-assisted features are switched on, with as little personal data in each request as possible;
  • third-party services you choose to connect.

We may also disclose data where required by law, or to a successor in a merger or acquisition, subject to this policy.

6. International transfers

Cloyk is based in Türkiye and stores workspace data in the European Union (Frankfurt, Germany), so personal data is transferred abroad. We make these transfers under Article 9 of the KVKK, using the standard contractual clauses published by the Turkish Personal Data Protection Authority and notified to it as the law requires. Where the GDPR applies, transfers outside the EEA rely on an adequacy decision or the European Commission's Standard Contractual Clauses.

7. Retention

  • Workspace content: for as long as the workspace exists, then 30 days for export, then deleted. Backups expire within a further 35 days.
  • Account data: while your account is active, then deleted or anonymised.
  • Billing records: as long as tax law requires, typically up to 10 years (held by Paddle and, in summary form, by us). We keep only a summary of each payment event — identifiers, price, seat count, status and period — and delete the raw notification from Paddle after 90 days.
  • Waitlist data: until launch plus 12 months, or until you unsubscribe.

8. Security

Data is encrypted in transit and at rest by our infrastructure providers. Every table is protected by row-level security that keeps each organisation's data separate, guests see only the boards they are invited to, and changes are recorded in an activity log. Access to production systems is limited to staff who need it.

9. Your rights

Under Article 11 of the KVKK you may ask whether your data is processed and for what purpose, learn who it is shared with in Türkiye or abroad, have it corrected or deleted, object to outcomes of solely automated analysis and claim compensation for unlawful processing. Depending on where you live, the GDPR, UK GDPR or CCPA may give you similar rights, including data portability. You can also complain to the Turkish Personal Data Protection Authority (KVKK) or your local data protection authority.

Email privacy@cloyk.com to exercise these rights. If your data sits in a workspace managed by your employer or another organisation, we will pass your request to them as the controller. We respond within 30 days.

10. Cookies

The Cloyk Works app uses strictly necessary cookies to keep you signed in and secure. Our marketing site uses only the cookies described in the Cloyk Privacy Policy. We ask for consent before setting any non-essential cookie.

11. Children

Cloyk Works is a business service and is not directed at anyone under 16. We do not knowingly collect their data.

12. Changes to this policy

We will post any changes here and update the date above. For material changes we will notify workspace owners by email or in the app before they take effect.

13. Contact

  • Privacy requests: privacy@cloyk.com
  • General questions: hello@cloyk.com
  • Data controller: CLOYK YAZILIM TEKNOLOJİLERİ ANONİM ŞİRKETİ, Kurtuluş Mah. Atatürk Cad. Adanaspor Apt. No: 95 A, Seyhan / Adana, Türkiye