Platform Solutions Security Pricing About
TR Book a Demo Start Free
PlatformSolutionsSecurityPricingAbout Book a Demo

Legal

Privacy Policy

This policy explains how we process your personal data when you use our corporate site, our product site and the AgentScope.HyperAgent platform. We have written down what we measured, exactly as we measured it — including what we do not collect.

Effective date
20 August 2026
Last updated
21 August 2026
Data controller
Agentscope Yapay Zeka Teknolojileri A.Ş.
MERSİS no
0271198476300001
Address
Mustafa Kemal Mah. Dumlupınar Bulv. ODTÜ Teknokent Bilişim İnovasyon Merkezi No:280/G, 06510 Çankaya/Ankara, Türkiye
Contact
hyperagent@agentscope.com

Contents

  1. What this policy covers
  2. Data controller
  3. What data we process
  4. Why we process it
  5. Cookies and browser storage
  6. Analytics: what we measure and what we do not
  7. Who we share it with
  8. Where your data is processed
  9. How long we keep it
  10. Security
  11. AI and your data
  12. Your rights
  13. Children
  14. Changes

1. What this policy covers

This policy covers all three surfaces below. All three belong to the same legal entity and are operated by the same data controller:

  • agentscope.ai — the company's corporate site (contact and newsletter forms)
  • hyper.agentscope.ai — the AgentScope.HyperAgent product site (demo request form)
  • platform.agentscope.ai — the AgentScope.HyperAgent platform (the application you use once you have an account)

Data processing terms agreed with enterprise customers prevail for their own data: if you use the platform on behalf of an organization, that organization is the data controller for its own data and we act as a data processor.

We meet our disclosure obligation under the Turkish Personal Data Protection Law in a separate document: the KVKK Notice. The rules for using the service are in the Terms of Use.

2. Data controller

The data controller is Agentscope Yapay Zeka Teknolojileri A.Ş., identified in the details at the top of this page. You can write to the e-mail address there with any question or request about this policy.

3. What data we process

What we collect depends on how you interact with us.

If you only browse our sites: the closed set of events listed below and your browser's country, and only if you have accepted analytics. Your IP address is not stored.

If you submit a form: your name, e-mail address, company name and the message you write; on the demo form, also your preferred date and time. If you arrived through a campaign link, the campaign parameters from that link are stored with your record.

Your IP address, browser details (user agent) and referring site are NOT written to the form record. Your IP address is only read to rate-limit bursts of submissions and to run the bot check, then discarded.

If you create an account on the platform: your first and last name, e-mail address, optional organization name and profile image; your last sign-in time; the content of your conversations and the files you upload; an audit record of actions taken in your account; and, if you purchase a plan, subscription and payment records. If you report a bug, the text of your report and an optional screenshot.

Sign-in is passwordless: a one-time code is sent to your e-mail address. We do not store passwords.

4. Why we process it

  • To provide the service: create your account, run your conversations, process the documents you upload.
  • To answer you: handling requests that arrive through the contact and demo forms.
  • Security: preventing abuse, automated attacks and unauthorized access; keeping an audit trail.
  • Billing and subscription management.
  • Improving the product: measuring which screens are used. This purpose only runs if you have given permission.
  • Meeting our legal obligations.

5. Cookies and browser storage

The table below is the complete set of cookies and browser storage used across the three surfaces. We use no advertising cookies, no tracking pixels and no social media cookies.

Cookies and browser storage
NameTypeWhat it doesWhereLifetime
ph_…_posthogCookie (third party: PostHog)Recognises the same visitor for analyticsAll three surfaces365 days
ph_…_posthogBrowser storage (localStorage / sessionStorage)The browser-side state of the same measurementAll three surfacesUntil you clear it / when the tab closes
agentscope_rtCookie (first party)Keeps you signed in. HttpOnly, Secure, SameSite=Strict; sent only to the API addressPlatform7 days, or 30 days if you chose 'remember me'
agentscope.utmsessionStorage (first party)If you arrived through a campaign link, carries the first-touch information into a form submissionThe two marketing sitesCleared when the tab closes
ui-storage, app-last-context, as_session_hintlocalStorage (first party)Theme preference, the app you last used, a session hintPlatformUntil you clear it
drafts-storagelocalStorage (first party)Message drafts you typed but did not send — they stay in your browser onlyPlatformUntil you clear it

The analytics cookie is not written before you accept it. If you decline, no analytics event is sent at all and the rest of the service works exactly the same. You can change your choice at any time.

The session cookie is required for the service to work: without it you cannot sign in, so it is not subject to separate consent.

We use Cloudflare Turnstile for bot protection. We measured it: Turnstile writes no first-party cookie on our sites — during verification your IP address reaches Cloudflare and a script served by Cloudflare is loaded in your browser.

6. Analytics: what we measure and what we do not

For product analytics we use PostHog's European Union hosted service. Measurement is subject to your consent, and what is collected is limited to a closed list of named events.

Events collected: on the marketing sites, page views, page loads and which call-to-action was clicked; on the platform, named usage steps such as sign-in, sign-up, app selection, sending a message and completion of a response.

The fields that may accompany an event are also limited to a predefined allowlist. This is a mechanism rather than a preference: a field that is not on the list does not travel even if something tries to send it.

  • Your e-mail address and your name are not sent to analytics.
  • Your conversation content, the files you upload and the agent's answers are not sent to analytics.
  • Identifiers in address bars are masked; for example, when a conversation address is recorded, a pattern is stored instead of the identifier.
  • Automatic click capture, session recording, heatmaps, surveys and remote module loading are switched off — both in code and in the PostHog project settings.

Your IP address is not stored in analytics; however, your IP address is converted to a country code on ingest and that country is stored. So 'we do not collect IP addresses' is accurate, while 'we do not process location data' would not be.

Analytics events are retained by PostHog for 12 months. That period is a fixed property of the plan we use; no option to shorten it is offered.

Until 17 August 2026, automatic click capture was enabled on the two marketing sites; it was switched off on that date, both in code and in the project settings. Records from that period are still held: our analytics provider offers no way to delete events by type or date, so they will fall away when the 12-month retention period expires.

For this provider's own privacy policy, see PostHog Privacy.

7. Who we share it with

We do not sell your personal data and we do not share it for advertising. The providers we use to deliver the service are listed below; each one only has access to the data its function requires.

Service providers
ProviderWhat forData that reaches it
Google CloudServers, database, file storage, loggingAll data processed on the platform
Google Cloud Vertex AIRunning the AI modelsThe messages and documents you send to the agent
PostHogProduct analyticsThe named set of events and the country code
CloudflareBot protection on forms and sign-in screensYour IP address at the moment of verification
ResendOne-time sign-in codes and invitation e-mailsYour e-mail address and your name
SlackNotifying the team of a new form submissionThe e-mail address and company name from the form
Firebase Hosting (Google)Serving the marketing sitesServer access logs

Beyond these, data is shared with public authorities only where we are legally required to do so.

8. Where your data is processed

The platform's database, file storage and application servers are in Google Cloud's Frankfurt (Germany) region. Search indexes are in the Netherlands region. In other words, the core of the service runs inside the European Union.

There are two exceptions to this, and we state them plainly:

Processing that leaves the European Union
WhereWhat forWhich data
Google Cloud — multi-region endpointRunning the default AI modelsThe messages and documents you send to the agent
Google Cloud — United States (Iowa)Running one higher-tier model, only when it is selectedThe messages and documents you send to the agent
Cloudflare — global networkBot protectionYour IP address at the moment of verification
Resend — United StatesSign-in codes and invitation e-mailsYour e-mail address and your name
Slack — United StatesForm notificationThe e-mail address and company name from the form

We deliberately chose PostHog's European Union service; analytics data does not leave the European Union.

For the legal framework and basis of international transfers, see the KVKK Notice.

9. How long we keep it

We write our retention periods as they are — some run automatically, others are deletion on request.

Retention periods
DataPeriodHow it is deleted
One-time sign-in code2 minutesAutomatic
Session refresh records30 daysAutomatic
Screenshot attached to a bug report90 daysAutomatic
The agent's long-term memory (if enabled)Depends on the setting; 30–180 days by defaultAutomatic
Form records24 months from last contactManual; immediately upon your request
Your account and conversation contentFor as long as your account is openYou can delete it yourself from within the application; also deleted upon your request
Subscription and payment recordsThe period required by tax legislationWhen the statutory period ends
Audit recordsKept for security and as legal evidenceOn request, the link to your identity is severed

For analytics events the period is 12 months on PostHog's side, and no option to shorten it is offered.

10. Security

The measurable technical safeguards we apply:

  • All traffic is encrypted with TLS; our sites instruct the browser to keep the connection secure.
  • The database and cache are closed to the public internet and reached over a private network; the cache connection is encrypted as well.
  • Sign-in and forms are rate limited per e-mail address and per IP address, with bot protection on top.
  • A web application firewall runs in front of the application.
  • Only signed application builds may run; creation of long-lived access keys is disabled by organisation policy.
  • Secrets such as provider and model access credentials are additionally encrypted at the application layer inside the database.
  • Session information is held in a cookie that scripts cannot read, and it is rotated on every use.
  • Actions taken in your account are written to an audit record.

If a support request requires our team to look inside your account, that is only possible through a time-boxed support session with a written reason: the session closes by itself after 30 minutes, every access is written to the audit record, and activity during that period is not counted as your usage.

We should also state that data is encrypted at rest by the cloud provider; beyond that, conversation content is not separately encrypted at the application layer.

11. AI and your data

When you talk to the agent, your message and any documents you attach are sent to the model provider to produce the answer. The provider we use is Google Cloud Vertex AI, which under its terms does not use customer data to train its own models. We do not use your data for model training either.

The platform has an optional content safety layer: when enabled, patterns such as Turkish national identity numbers, IBANs, tax numbers and phone numbers are masked in messages before they reach the model. This layer is enabled per application and is off by default; it does not cover personal data in free text such as names and addresses.

AI output can be wrong. You need to verify results before relying on them; see the Terms of Use for detail.

12. Your rights

You have the rights the law grants over your personal data: to learn whether your data is processed, to request information, to learn whether it is used for its purpose, to request that it be corrected, deleted or destroyed, to object to the outcome of processing, and to claim compensation for damages.

You can send your request to the e-mail address in the details above; for the application channels and time limits see the application section of the KVKK Notice.

Your request is concluded within thirty days at the latest. On a deletion request, the personal content in your account is deleted; in records we are legally required to keep, such as invoice records and the audit trail, the link to your identity is severed.

You can also delete your account and its content yourself from within the application, via the account deletion step in settings; deletion takes effect immediately and cannot be undone. You can likewise view and delete what the platform's agent memory holds about you from within the application.

13. Children

Our services are not designed for people under eighteen and we do not knowingly collect data from anyone below that age. We should state plainly that we do not verify age: this rests on your declaration. If we learn that we process data belonging to someone under eighteen, we delete the record; you can report such a case to the address in the details above.

14. Changes

We may update this policy from time to time. The effective and last-updated dates at the top of the page show which text applies; when a significant change is made we also notify you through the platform.

Related documents Terms of UseKVKK Notice

Agentscope Yapay Zeka Teknolojileri A.Ş.

AgentScope.HyperAgent — Know. Think. Act.

Product

PlatformSecurityPricing

Company

AboutSolutionsContact

Legal

Privacy PolicyTerms of UseKVKK Notice
AgentScope.HyperAgent is a product of Agentscope Yapay Zeka Teknolojileri A.Ş.

© 2026 Agentscope Yapay Zeka Teknolojileri A.Ş.

This product is being developed with support from the TÜBİTAK-TEYDEB (1501) Grant Programme. (Project No: 3251483) However, all responsibility for the product belongs to Agentscope Yapay Zeka Teknolojileri A.Ş.

To improve the product we measure a few predefined usage events, if you allow it. If you decline, no analytics event is sent at all and the site works exactly the same. Which cookies do we use?