Legal

Privacy Policy

Last updated: 3 Şubat 2026

Summary: At e9e, we care about your privacy. This policy explains how we collect, use and protect your personal data.

1. Introduction

As Tabbyte Teknoloji ve Danışmanlık Limited Şirketi ("e9e", "we", "our"), we place great importance on protecting the personal data of all users ("you", "user") of our platform. This Privacy Policy explains how your personal data is collected, processed and protected when you use the services we offer through the e9e.io website and mobile applications.

2. Data We Collect

2.1. Data You Provide Directly

  • Account information: First name, last name, email address, phone number, company name
  • Profile information: Profile photo, job title, industry information
  • Contact information: Your support requests and feedback
  • Payment information: Billing address and payment method details (credit card data is processed by our secure payment infrastructure)

2.2. Data Collected Automatically

  • Usage data: Your activity on the platform, click data, session durations
  • Device information: IP address, browser type, operating system, device identifier
  • Cookie data: Session cookies, preference cookies, analytics cookies
  • Location data: Approximate location derived from your IP address

2.3. Data Received From Third Parties

  • Profile information from platforms you connect through integrations, such as LinkedIn and Google
  • Transaction confirmation information from payment processors
  • Prospect (lead) information compiled from publicly available sources (Google Maps, business directories, professional networks, social media platforms, corporate websites)
  • Business contact information obtained from search engine results
  • Contact information enriched through third-party data providers and API services

3. Purposes of Data Use

We use the data we collect for the following purposes:

  • To provide and improve our services
  • To create and manage your account
  • To provide customer support
  • To process payments
  • Security and fraud prevention
  • To meet legal obligations
  • Marketing communications (with your consent)
  • Analytics and service improvement
  • Collecting, compiling and enriching data from publicly available sources in order to provide prospect information to our users
  • AI-powered lead scoring and prioritization
  • Verifying lead data and checking that it is up to date

4. Data Sharing

We do not share your personal data with third parties except in the following cases:

  • Service providers: We work with third-party service providers in the following categories for infrastructure, analytics, payment processing, data collection and enrichment services: Cloud Infrastructure - Server hosting and database (EU / UK); Search API Services - Querying search engine results (US); Web Data Collection Services - Compiling data from publicly available sources (EU / US); Artificial Intelligence Services - Data enrichment and analysis (US); Payment Processing - Payment infrastructure (EU / UK); Email Infrastructure - Email delivery services (EU / US); Analytics - Usage analytics (EU / US). Data Processing Agreements have been concluded with all service providers. Standard Contractual Clauses (SCC) are applied for cross-border data transfers.
  • Legal requirements: With authorized authorities where legally required
  • Business transfers: In the event of a company merger or acquisition
  • With your consent: Within the scope of your explicit permission

5. Data Security

We take the following measures to protect your data:

  • Data transmission with SSL/TLS encryption
  • Data storage with AES-256 encryption
  • Regular security audits
  • Access control and authorization
  • Employee training
  • Security incident response plans

6. Data Retention Periods

Data Type / Retention Period table:

Account information: As long as the account is active + 2 years

Transaction records: 10 years (legal requirement)

Usage data: 2 years

Support requests: 3 years

Marketing consents: Until consent is withdrawn

Prospect (lead) data: As long as the user account is active; deleted within 30 days upon a deletion request

7. Your Rights

Under KVKK and GDPR, you have the following rights:

  • Right of access: You can request access to your data
  • Right to rectification: You can request correction of inaccurate data
  • Right to erasure: You can request deletion of your data
  • Restriction of processing: You can request that data processing be restricted
  • Data portability: You can receive your data in a portable format
  • Right to object: You can object to data processing

8. Google API Services and Gmail Data

e9e integrates with Google API Services, including the Gmail API, to provide email marketing and communication features. This section explains how we handle data obtained through Google APIs.

8.1. Gmail Data We Access

When you connect your Gmail account to e9e, we request the following permissions:

  • Sending email (gmail.send): To send marketing emails and automated campaigns on your behalf
  • Reading email (gmail.readonly): To track email delivery status, replies and engagement metrics
  • Modifying email (gmail.modify): To manage email labels for campaign tracking and to organize your inbox
  • Basic profile information: Your email address and name for account identification

8.2. How We Use Gmail Data

We use Gmail data only for the following purposes:

WE DO NOT:

  • Send the email campaigns and automated sequences you create
  • Email warm-up to improve the deliverability of your email account
  • Track email opens, clicks and replies for campaign analytics
  • Manage your campaign-related inbox organization
  • WE DO NOT - Read, scan or analyze the content of your personal emails
  • WE DO NOT - Share your Gmail data with third parties for advertising
  • WE DO NOT - Use Gmail data for any purpose other than providing our email services
  • WE DO NOT - Store email content beyond what is necessary to provide the service

8.3. Gmail Data Storage and Security

  • OAuth tokens are stored securely, encrypted with AES-256
  • We store only metadata (delivery status, timestamps), not email content
  • Access tokens are refreshed automatically and old tokens are invalidated
  • All Gmail API communication uses HTTPS/TLS encryption

8.4. Revoking Gmail Access

You can disconnect your Gmail account at any time:

Once disconnected, we delete your Gmail access tokens within 24 hours.

  • From your e9e dashboard: Settings → Email Accounts → Disconnect
  • From Google: Google Account Permissions (https://myaccount.google.com/permissions)

8.5. Google API Services Limited Use Disclosure

e9e's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

9. Lead Data Processing (Prospect Data)

The e9e platform collects and processes data from publicly available sources in order to provide prospect (lead) information to its users. This section explains how such data is collected, processed and protected.

9.1. Lead Data Collected

  • Business information: Trade name, address, phone number, email address, website
  • Professional profile information: First and last name, job title, company name, city/country information
  • Social media profile information: Username, bio/description, follower count, profile URL
  • Business ratings: Star rating, number of reviews, business category
  • Geographic location information: Latitude/longitude coordinates, city, country

9.2. Data Collection Sources

  • Google Maps and mapping services (business information)
  • Search engine results and web directories
  • Publicly available professional profile information
  • Publicly available social media profiles
  • Contact information on corporate websites

9.3. Data Collection Methods

  • Automated search and compilation via search engine APIs
  • Web scraping (automated data extraction) technologies
  • Third-party data providers and API services
  • AI-powered data enrichment and verification

9.4. Legal Basis

The processing of lead data is based on the following legal grounds:

  • Legitimate interest (GDPR Article 6(1)(f) / KVKK Article 5(2)(f)): Compiling and presenting publicly available information in order to provide our users with prospect data for commercial communication
  • Performance of a contract: Fulfilling the lead-finding service committed to our users

9.5. Legitimate Interest Assessment

The following factors have been assessed under the legitimate interest basis:

  • Only publicly shared information is processed
  • The reasonable expectations of data subjects are taken into account (that business contact information may be used for commercial purposes)
  • Data subjects are granted the right to erasure and the right to object
  • Collected data is used only for legitimate commercial communication purposes
  • Sensitive (special category) personal data is not collected

9.6. Lead Data Retention Periods

  • Lead data is retained as long as the user account is active
  • If the user closes their account, lead data is deleted within 30 days
  • Upon a deletion request from the data subject, data is permanently deleted within 30 days
  • Inactive lead data (not accessed for more than 6 months) is automatically anonymized or deleted

9.7. Rights of Leads (Data Subjects)

The individuals (leads) whose data is collected through the platform have the following rights:

Requests regarding these rights can be submitted to info@e9e.io or through the Data Deletion Request Form on the platform (/tr/legal/data-request).

  • The right to learn what data is collected about them
  • The right to request rectification of their data
  • The right to request erasure of their data (right to be forgotten)
  • The right to object to the processing of their data
  • The right to request restriction of data processing

10. Cookies

For detailed information about our use of cookies, please review our Cookie Policy (/tr/legal/cookie-policy).

11. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect data from anyone under 18. If we become aware of such a case, the data is deleted immediately.

12. International Data Transfer

Your data is processed within the United Kingdom and the European Union. When a transfer to a different country is required, appropriate safeguards (such as standard contractual clauses) are applied.

13. Policy Changes

We may update this policy from time to time. When significant changes occur, we will notify you by email or via an in-platform notification.

14. Contact

For questions about privacy, you can reach us:

  • Email: info@e9e.io
  • Address: TABBYTE TECHNOLOGIES LTD, London, United Kingdom

Contact

Tabbyte Teknoloji ve Danışmanlık Limited Şirketi (e9e). Email: info@e9e.io. Address: TABBYTE TECHNOLOGIES LTD, London, United Kingdom. Data subject rights requests can be submitted to info@e9e.io or through the Data Deletion Request Form on the platform (/tr/legal/data-request).

For any questions, get in touch.