Data Retention & Deletion Policy

Effective date: 15 August 2026

Company: Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş.

This Data Retention & Deletion Policy describes how Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş. ("Aspect") retains, deletes, destroys and anonymizes personal data and Customer Data processed through the Services. It is designed to support Aspect's obligations under applicable data protection law, including the KVKK, GDPR, UK GDPR and contractual commitments to customers.

1. Purpose and principles

Aspect retains personal data only for as long as there is a legitimate business, contractual or legal reason to keep it. Retention periods are based on the purpose of Processing, customer instructions, legal requirements, security needs, limitation periods and technical backup cycles. Data is not retained indefinitely merely because storage is technically available. When the legal basis and purpose for Processing end, data is deleted, destroyed or anonymized according to this Policy. Deletion from active systems and expiration from backups may occur on different timelines. Legal holds, regulatory obligations, fraud prevention or active disputes may require limited retention beyond the standard schedule. Deletion and destruction actions are documented as required by applicable law.

2. Scope

This Policy applies to personal data and Customer Data stored in Aspect-controlled databases, object storage, logs, backups, support systems, administrative tools and approved vendor systems. It applies to employees, contractors and service providers involved in storing or deleting such data.

3. Responsibilities

FunctionResponsibility
Management / PrivacyApproves retention rules, legal holds, exceptions and regulatory responses.
Engineering / OperationsImplements deletion, backup rotation, access restrictions, logging and technical destruction measures.
Customer Support / OperationsReceives customer and data subject requests, verifies requests and coordinates execution.
Finance / AdministrationMaintains billing, tax, accounting and contract records for legally required periods.
All personnelMust not create unauthorized copies or retain data outside approved systems beyond the applicable period.

4. Standard retention schedule

Data categoryStandard retentionDeletion rule
Active customer account and profile dataFor the active account or contract term.Deleted from active systems within 30 days after valid account deletion or termination, unless a different contractual period or legal obligation applies.
Customer Data, leads, contacts, scanned business cards or badges, event data, notes and enrichment dataFor the contract term or until Customer deletes the data.Deleted from active systems within 30 days after Customer deletion request or termination, subject to export period, legal hold and applicable law.
CRM and integration dataWhile the integration is active and as required to provide the Service.Tokens are revoked or deleted after disconnect where technically supported. Cached or synchronized data follows the Customer Data retention rule.
AI prompts and outputs stored by AspectOnly for as long as the relevant content forms part of Customer Data, product history or is reasonably required for security and support.No separate longer retention period applies solely because data was processed by AI. Provider-side retention follows applicable business/API terms and configuration.
Backups containing Customer DataRolling backup cycle.Deleted or overwritten through normal backup rotation within 90 days after deletion from active systems, unless a legal hold or incident investigation requires temporary preservation.
Security, authentication and audit logsGenerally up to 12 months.May be retained longer where needed to investigate a security incident, fraud, abuse or legal claim.
Support tickets and service communicationsGenerally 24 months after closure.May be retained longer where tied to a contract dispute, security incident or legal obligation.
Sales and business prospect recordsGenerally up to 24 months after the last meaningful business interaction, unless a longer period is justified by an active opportunity or legal requirement.Suppression or opt-out records may be retained longer to ensure marketing preferences continue to be honored.
Invoices, accounting, tax and contract recordsFor the statutory period required under applicable Turkish law and other applicable financial or commercial law.Deleted after the relevant statutory and limitation periods expire unless still required for an audit, dispute or legal hold.
Privacy requests, consent records and deletion/destruction recordsFor the period necessary to demonstrate compliance.Deletion, destruction and anonymization records are retained for at least 3 years where required by KVKK rules, and longer where necessary to establish or defend legal rights.
Aggregated or anonymized dataMay be retained without a fixed period if it can no longer reasonably be linked to an identifiable person.Must remain effectively anonymized and must not be used to re-identify individuals.

5. Customer termination and account deletion

After termination, Aspect may provide a limited period for Customer to export Customer Data where required by the Agreement or technically available. Unless a different period is agreed, Aspect targets deletion from active production systems within 30 days after the applicable termination or deletion event. Deletion may not be immediate in backups. Backup copies remain protected, are not used for ordinary business purposes, and are deleted or overwritten within the normal backup lifecycle, targeted at no more than 90 days after active-system deletion.

6. Data subject deletion requests

Where Aspect acts as Controller, valid deletion requests are handled within the period required by applicable law. Under KVKK, where all Processing conditions have ceased, a request to delete, destroy or anonymize personal data is completed and the requester is informed within the legally required response period. Where Aspect acts as Processor, Aspect will assist the relevant Customer in executing valid deletion requests. If the relevant data was disclosed to a Subprocessor and deletion is required, Aspect will pass the instruction to the Subprocessor as required by law and contract.

7. Periodic destruction under KVKK

For Processing activities subject to the Turkish Regulation on Deletion, Destruction or Anonymization of Personal Data, Aspect conducts a periodic review and destruction cycle every three months for data for which all Processing conditions have ceased. This interval will not exceed the maximum period permitted by applicable KVKK rules. Deletion, destruction and anonymization operations are recorded. Records of these operations are retained for at least three years unless another legal obligation requires longer retention.

8. Deletion, destruction and anonymization methods

Logical deletion: removing records from active application access and preventing ordinary users or personnel from retrieving or reusing them. Database deletion: deleting or overwriting records in production databases according to application and database controls. Object and file deletion: removing files from active object storage and allowing versioning or lifecycle rules to expire retained copies. Credential revocation: invalidating access tokens, API keys or integration credentials when no longer needed. Backup expiration: allowing protected backup sets to age out through the defined backup lifecycle rather than selectively restoring deleted data. Vendor deletion: submitting or propagating deletion instructions to relevant service providers when required and technically supported. Anonymization: irreversibly transforming data so it can no longer be associated with an identified or identifiable person using reasonably available means.

9. Legal holds and exceptions

Aspect may temporarily suspend deletion where data must be preserved for litigation, regulatory investigation, security response, fraud prevention, tax or accounting obligations, enforcement of agreements or another legal requirement. Access to data retained under a legal hold will be limited to the purpose requiring retention, and the data will be deleted when the hold ends unless another lawful basis remains.

10. Service providers and AI providers

Aspect requires service providers that Process personal data on its behalf to follow contractual retention and deletion obligations appropriate to their role. Provider-side retention may vary by service and configuration. Aspect seeks to use business or API configurations that limit retention to what is necessary for service delivery, security and legal compliance. For AI services, Aspect does not establish a separate indefinite retention period for Customer Data and does not intentionally opt Customer Personal Data into generalized model training programs without Customer authorization.

11. Review and changes

Aspect reviews this Policy periodically and updates it when Services, legal requirements, infrastructure or contractual commitments change. Material changes will be reflected in the effective date and, where appropriate, communicated to affected customers.

12. Contact

Questions or requests concerning retention and deletion may be sent to info@aspect.contact, aspectbilisim@hs01.kep.tr, 0 (850) 380 07 10, or Acarlar Mah. Derbent Sk. Acarkent A050 No: 23/1 Beykoz / Istanbul, Türkiye.