GDPR Notice
Last updated: May 20, 2026
Data controller
This notice is published by Umut Seyarcı ("Pitchko"). For the purposes of EU data protection law (GDPR — General Data Protection Regulation, 2016/679), this legal entity is the data controller. Reach the controller at info@pitchko.io.
Personal data we process
Account data (name, email), usage data (decks created, pages visited, device type), payment data (only via our payment provider iyzico — we never store card numbers on our servers), and any data submitted through our customer/agency contact form.
Lawful basis for processing (Art. 6 GDPR)
Performance of the service contract (Art. 6(1)(b)), your explicit consent for marketing communications (Art. 6(1)(a)), compliance with legal obligations (Art. 6(1)(c)), and our legitimate interests in product improvement and fraud prevention (Art. 6(1)(f)). The specific basis for each processing activity is disclosed on request.
Purposes of processing
Service delivery (pitch deck generation), invoicing and payment management, product analytics, security and fraud detection, communications you requested. We do not use your data for advertising profiling or sell it to third parties.
Third-party recipients
Your data is shared with third-party providers strictly to the extent necessary to deliver the service — hosting and data storage, transactional email, live chat, payment processing, AI model APIs, error monitoring and product analytics. The complete and current list, naming every provider, what it is used for and which data it receives, is published in our Trust Center and is generated from the application's own configuration. Each provider processes personal data under its own published data processing terms; transfers outside the EEA rely on Standard Contractual Clauses where the provider offers them.
See the full provider list in the Trust Center →International data transfers
Pitchko's primary database and file storage are hosted in the EU (Frankfurt, eu-central-1). Pitchko is established in Türkiye and accesses that data from Türkiye; under GDPR Chapter V such access is itself a transfer to a third country. Türkiye has no adequacy decision under Art. 45, so these transfers rely on appropriate safeguards under Art. 46(2) — Standard Contractual Clauses (SCCs). A copy of the SCCs is available on request. Some providers listed in our Trust Center process data outside the EU under their own transfer mechanisms.
Data retention
After your account deletion request, your data is processed in three classes: (1) DELETED — account profile, feedback, team memberships, pending invitations addressed to you, notification history and marketing-list entries; automatically purged after the 90-day cancellation window by the sweep cron. (2) ANONYMIZED — pitch decks you created, API cost logs and credit transaction history; a deck stays with the agency it was made for and your identity is removed from it, so the audit trail is retained without naming you. (3) RETAINED — invoice and commercial ledger records, kept under Turkish Commercial Code Art. 82 (10 years) and Tax Procedure Law Art. 253 (5 years); the stricter period applies. Marketing-consent data is deleted immediately upon withdrawal. Detailed retention matrix available on request.
Your rights as a data subject (Art. 15–22 GDPR)
If you reside in the EU, you have the rights to: be informed (Art. 13–14), access (Art. 15), rectification (Art. 16), erasure — "right to be forgotten" (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), object (Art. 21), and not be subject to automated decision-making including profiling (Art. 22). Send requests to info@pitchko.io; we respond within 30 days (Art. 12(3)).
Right to lodge a complaint
If you believe a processing operation violates the GDPR, you may lodge a complaint with the supervisory authority of your EU member state of residence (Art. 77). List of EU supervisory authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Contact
For GDPR-related questions and data subject requests: info@pitchko.io. We have not appointed a Data Protection Officer (DPO); given our headcount and processing scale, GDPR Art. 37 does not require one. A DPO will be appointed if and when needed.