İçeriğe geç
Katalojik

Legal

Privacy Policy

What data we collect, where the product photos you upload go for AI generation, and how to exercise your rights under KVKK and GDPR.

Last updated: August 3, 2026

Data controller

This policy explains how your personal data is processed when you use the katalojik.com platform.

The data controller— “veri sorumlusu” under Turkey’s Law No. 6698 on the Protection of Personal Data (KVKK), and controller under the EU General Data Protection Regulation (GDPR) — is Anıl Naci Çelik.

Address: Gaziantep, Türkiye
Data protection requests: privacy@katalojik.com

KVKK applies to users located in Türkiye; GDPR applies to users located in the European Economic Area. This document provides the disclosures required by both regimes together.

Data we collect

We only collect what the service needs to run. We do not do ad profiling, behavioral tracking, or data enrichment.

Account data

  • Email address — for authentication, sign-in, and service notifications. Required.
  • Password — stored as an irreversible hash by our authentication provider. We never see your password in plain text.
  • Business / workspace name — to label your account. Optional at signup.

Content data

  • Product photos you upload — garment or jewelry images. These are processed for AI generation.
  • Images you generate, plus technical records of each job (model chosen, job type, timestamp, status).

Payment data

  • Purchase history— amount, date, package purchased, and the payment provider’s transaction id.
  • Credit ledger — when credits were granted, spent, or refunded.
  • We do not collect your card details. Card number, expiry, and CVC go directly to our payment provider; they never reach our systems and we never store them.

Technical data

  • Session cookie (see Cookies below).
  • Error and operational logs — kept so we can diagnose a failed generation or payment.

Purposes and legal basis

We process your data only for these purposes:

  • Running the service — creating your account, generating images from what you upload, delivering and storing the result.
  • Payment and credit management — turning your purchase into credits, tracking your balance, refunding credits on a failed generation.
  • Required communication — email verification, password flows, and important service notices.
  • Security and troubleshooting — detecting abuse, fixing failures.
  • Legal obligations — record-keeping required under financial regulation.

Our legal basis is performance of a contract under KVKK art. 5/2(c) and GDPR art. 6(1)(b); compliance with a legal obligation under KVKK art. 5/2(ç) and GDPR art. 6(1)(c); and, for security and troubleshooting, legitimate interest under KVKK art. 5/2(f) and GDPR art. 6(1)(f).

We do not use your data to train AI models. The photos you upload and the images you generate are never fed into model training.

Third-party processors we use

To run the service, we share some data with providers that act on our behalf and under our instructions — a data processor under KVKK, processorunder GDPR. These providers may only use the data for the task we’ve assigned them.

Supabase — infrastructure

Authentication, database, and file storage. Your account data, the photos you upload, and the images you generate are stored here.

Fal.ai — AI image generation

Your uploaded product photos are sent to Fal.ai for image generation. This transfer is required for the service to function — no image can be generated without your photo reaching Fal.ai’s infrastructure. Once a generation completes, the result is copied into our own storage so we’re not dependent on the provider’s temporary link. Images sent to Fal.ai are used only to process your request.

Lemon Squeezy — payments

Processes credit purchases and acts as merchant of record for these sales. They handle your card details directly; we only receive the transaction amount, date, and order id.

Resend — transactional email

Delivers verification and account-notice emails. This provider only receives your email address and the content of the message sent.

We don’t share your data with anyone else. Disclosure beyond this list only happens in response to a legally binding request, court order, or legal obligation, and is limited to what that request covers.

International transfers

Every provider listed above operates servers outside Türkiye. Your account data, uploaded photos, and generated images are accordingly processed and stored abroad.

Under KVKK art. 9, this transfer is necessary to provide the service and is based on the explicit consent you give by accepting this policy when you create an account. For GDPR purposes, these transfers rely on the providers’ safeguards, including standard contractual clauses (SCCs).

If you do not want your data processed abroad, you cannot use the service — image generation is not technically possible without this transfer.

Retention periods

  • Account data and content — kept for as long as your account is open. Images you generate stay in your dashboard until you delete them or close your account.
  • When you close your account — your account data, uploaded photos, and generated images are deleted within a reasonable period. Deletion is irreversible; download your images before closing your account.
  • Payment and accounting records — must be kept for the retention period required by financial regulation, and cannot be deleted before that period ends even if you close your account.
  • Technical logs — kept for the short period needed to investigate an issue, then deleted.

Your rights

Under KVKK art. 11 and GDPR arts. 15–22, you have the following rights:

  • Access — find out whether we process your personal data, and request details about it.
  • Rectification — have incomplete or inaccurate data corrected.
  • Erasure— request deletion of your data (“right to be forgotten”).
  • Data portability — receive your data in a structured, commonly used, machine-readable format.
  • Object to processing and request that processing be restricted.
  • Withdraw consent where processing is based on it (withdrawal does not affect the lawfulness of processing before that point).
  • Claim compensation if you suffer harm from unlawful processing of your data.

Send requests to privacy@katalojik.com. We respond within thirty days under KVKK and within one month under GDPR.

If you’re not satisfied with the outcome, you may lodge a complaint with Türkiye’s Personal Data Protection Authority, or, in the EEA, with your country’s data protection authority.

Cookies

The site uses only strictly necessary cookies — the authentication cookie that keeps you signed in. Without it you cannot log in or see your dashboard.

We do not use advertising cookies, third-party tracking pixels, or behavioral analytics tools. We do not track you across sites or send data to ad networks.

Because strictly necessary cookies are required for the service to work, no separate cookie consent banner is shown. Blocking cookies in your browser means you cannot sign in.

Data security

The main technical measures we take to protect your data:

  • All traffic runs over an encrypted connection (HTTPS).
  • The database applies row-level security (RLS): each workspace can only reach its own data — access to another brand’s images is blocked at the database layer.
  • Write access to storage is restricted by workspace identity.
  • Service keys and secrets are kept server-side only and are never sent to the browser.
  • Passwords are stored as irreversible hashes.

No system offers absolute security. If a breach affecting your data occurs, we will notify you and the relevant authority within the period required by law.

Data we don't sell or share

We commit to the following, plainly and without exception:

  • We do not sell your personal data.
  • We do not share your data with third parties for marketing purposes.
  • We do not use the photos you upload or the images you generate as promotion, reference, or showcase material without your explicit permission.
  • We do not use your content to train AI models.

Age limit

The service is not directed at anyone under 18 and is built for business-to-business (B2B) use. We do not knowingly collect personal data from anyone under 18.

If we become aware that data belonging to a minor is in our systems, we close the account and delete the data. If you know of such a case, please tell us at privacy@katalojik.com.

Changes and contact

We may update this policy as our service or the law changes. For material changes, we will notify you at the email address on your account. The “Last updated” date at the top of this page shows when the text last changed.

Data protection requests: privacy@katalojik.com
General questions: support@katalojik.com
Address: Gaziantep, Türkiye

For the commercial terms of the service, see the Terms of Service.