Back to home

Privacy Notice

What personal data we handle, why, and what you can ask us to do about it.

Effective date: 13 August 2026

1. Who we are

BLACK REIN TEKNOLOJİ ANONİM ŞİRKETİ ("we", "us", "the Company"), operating the EximLabs product, is the controller of the personal data described in this notice.

Registered address: Sanayi, Teknopark Blv. No:1/4C, Door No: 112, 34906 Pendik / İstanbul. Trade registry no. 1113140. MERSIS no. 178184906200001.

For any question about this notice or your rights, write to info@eximlabs.ai.

2. Scope

This notice covers two different situations, and it matters which one applies to you:

Visitors and customers — people who use this website or hold an EximLabs account. We are the controller of that data.

Business contacts inside the platform — people whose professional contact details our customers discover and reach through EximLabs. For that data our customer is the controller and we act as processor on their instructions. See our Data Processing Addendum.

3. What we collect

Account data — name, business email, phone, company name, role, and the credentials needed to sign in.

Billing data — invoicing details and payment records. Card details are processed by our payment provider and never stored on our systems.

Usage data — pages viewed, features used, actions taken in the platform, error logs, approximate location derived from IP, device and browser type.

Content you upload — product photos, catalog text, company details and any document you choose to process through the platform.

Correspondence — messages you send us by email, contact form or the chat widget.

4. Why we process it, and on what basis

To provide the service you contracted for — performance of a contract.

To bill you and keep the accounting records the law requires — legal obligation.

To keep the service secure, prevent abuse and investigate incidents — legitimate interests.

To improve the product using aggregate, non-identifying usage statistics — legitimate interests.

To send service notices such as renewal reminders — performance of a contract.

To send marketing messages — only with your consent, withdrawable at any time.

5. Third-party business contact data

EximLabs helps customers find and reach potential buyers. Those buyer records are professional, business-context contact details compiled lawfully from licensed third-party data providers, public directories, public trade registers and companies' own published information.

Personal mobile numbers, personal email addresses at free providers, special category data and any consumer-facing data are out of scope by design. The full sourcing, verification and legal architecture is documented on our How We Find Customers page.

We do not generate this data. We do not warrant that it is accurate, current or complete: phone numbers change, addresses are retired, companies close and people move roles.

Individuals whose business contact details appear in our sources may exercise their rights against us as described in section 9, and we will act on a valid request regardless of which of our customers holds the record.

Customers are contractually required to use this data lawfully, to honour opt-out requests, and to comply with the marketing and anti-spam rules of the markets they contact.

6. Who we share it with

We do not sell personal data. We share it only with:

Service providers that operate parts of the platform on our behalf — hosting, email delivery, AI model providers, payment processing. These act as processors under contract. Our current list is published on the Subprocessors page.

Authorities, where a valid legal obligation requires it.

An acquirer, if the business is sold or merged — with prior notice to you.

7. International transfers

Our infrastructure is operated within Türkiye and the European Union. Some processors are established outside these regions; where that is the case we rely on the transfer mechanisms required by Turkish Law No. 6698 (KVKK) and, where applicable, the EU Standard Contractual Clauses.

8. How long we keep it

Account and content data — for the life of the subscription, then up to 12 months so that you can request an export, unless you ask for earlier deletion.

Billing and invoicing records — 10 years, as required by Turkish Tax Procedure Law and the Turkish Commercial Code.

Security and access logs — up to 24 months.

Contract approval records (date, time, IP, contract version) — for the duration of the limitation period applicable to the contract.

9. Your rights

Under KVKK Article 11 and, where applicable, the GDPR, you may ask us to confirm whether we process your data, to give you a copy, to correct it, to delete it, to restrict or object to processing, and to receive it in a portable format. You may also object to automated decisions that produce legal effects.

Send requests to info@eximlabs.ai. We respond within 30 days. If you are not satisfied you may complain to the Turkish Personal Data Protection Authority (KVKK) or your local supervisory authority.

We do not charge for these requests unless they are manifestly excessive or repetitive.

10. Security

We apply access controls, encryption in transit, environment separation, least-privilege administration and logging. No system is perfectly secure; if a breach affects your personal data we will notify you and the competent authority within the periods the law requires. Our technical measures are described on the Security page.

11. Cookies

This website uses only the cookies strictly necessary to serve the page and remember your display preferences. See the Cookie Policy for details.

12. Changes

We publish the current version on this page with its effective date. If a change materially affects your rights we will notify account holders by email before it takes effect.