Cernio
← Back to signup

Privacy Policy

Service: Cernio (getcernio.com, app.getcernio.com) Controller: GADULABS YAZILIM LİMİTED ŞİRKETİ (a Turkish limited liability company), Mustafa Kemal Paşa Mah. Yalova-Bursa Yolu Cad. A Blok 1. Kademe No: 123/1 İç Kapı No: 10, Merkez / YALOVA, Türkiye; trade registry no. 14632; MERSIS no. 0388200542700001; tax office Yalova, tax ID 3882005427. Data protection contact: privacy@getcernio.com Effective date: 18 September 2026


1. Who We Are

Cernio is a B2B SaaS platform for AI-assisted buyer discovery, lead scoring and contact management, operated by GADULABS YAZILIM LİMİTED ŞİRKETİ ("we", "us"). Registered address: Mustafa Kemal Paşa Mah. Yalova-Bursa Yolu Cad. A Blok 1. Kademe No: 123/1 İç Kapı No: 10, Merkez / YALOVA, Türkiye. Trade registry no. 14632 · MERSIS no. 0388200542700001 · tax office Yalova, tax ID 3882005427. This Privacy Policy explains what personal data we process, why, on what legal basis, who we share it with, and what your rights are.

For the purposes of this Policy:

  • We act as a controller for data about our account holders and website visitors (Sections 3–4).
  • We act as a processor for the personal data our customers submit or generate through the Service about third parties (see Section 5 and our DPA).

VERBİS (Turkish Data Controllers' Registry). We are not registered with VERBİS. Under the exemption criterion currently in force, a data controller with fewer than 50 employees and an annual balance-sheet total below TRY 100 million, whose main activity is not the processing of special-category personal data, is not required to register. GaduLabs is below both thresholds and Cernio does not process special-category data (health, biometric, religion, origin and the like), so no registration obligation arises today. We re-check this every financial year and will register if a threshold is exceeded.

2. Scope

This Policy applies to the Platform and related communications. It does not apply to third-party websites or services that we link to or integrate (see Section 8).

3. Personal Data We Process (as Controller)

CategoryExamplesSource
Account & identityName, business email, organization name, password (hashed), MFA settingsYou, at sign-up
Authentication & securityLogin timestamps, session identifiers, IP address, device/browser info, MFA recovery codesAutomatically
Usage & productSearches performed, service usage applied, features used, activity logAutomatically
Billing (limited)Legal billing identity (including tax identifiers: legal name, tax number, tax office, address, phone, billing email), plan, transaction records, remaining service usage. These details and the immutable record of the invoice issued are also stored by GaduLabs itself and retained for the periods required by applicable tax and commercial law; they are shared with payment providers only to the extent required to process a payment. We do not store full card data — card details stay with the payment institutionYou, before a purchase
Support & communicationsEmails and messages you send us, including a message sent from the contact form on our website (your name, email address, an optional company name and the message text)You
Optional analytics & session replayPage views and named clicks via Google Analytics (website and application); interaction recordings via Microsoft Clarity on ordinary product screens of the application only, with sensitive fields masked. Both run only after you allow analytics in the cookie preferences (see the Cookie Policy)Only after your choice
DiagnosticsError and performance data with personal data scrubbed (via Sentry)Automatically

We do not knowingly collect special categories of personal data or data from minors.

4. Why We Process It and Legal Bases (Controller)

PurposeLegal basis (GDPR)KVKK basis
Provide and operate the Service, manage your accountPerformance of a contract (Art. 6(1)(b))Contract necessity
Answer an enquiry you send us, including from the contact form on our websiteLegitimate interests (Art. 6(1)(f)), or steps before a contract at your request (Art. 6(1)(b))Legitimate interest / steps before a contract
Authenticate users, secure the Service, prevent abuseLegitimate interests (Art. 6(1)(f))Legitimate interest / legal obligation
Process payments and keep financial recordsContract + legal obligation (Art. 6(1)(b),(c))Contract / legal obligation
Product improvement through optional analytics and session replayConsent (Art. 6(1)(a)), withdrawable at any timeExplicit consent
Send service and, where permitted, marketing communicationsLegitimate interests / consent (Art. 6(1)(f)/(a))Explicit consent for commercial messages
Comply with legal obligations, respond to lawful requestsLegal obligation (Art. 6(1)(c))Legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights (see our LIA for the buyer-discovery processing). Where we rely on consent, you may withdraw it at any time.

5. Customer Data Processed on Behalf of Customers (Processor)

5.1. When a customer uses the Service to discover buyers or find decision-makers, the Service processes information about third-party businesses and their contacts (e.g. company name, website, business phone, address, job title, and business email), obtained from publicly available web sources via AI and search providers.

5.2. For discovery/headhunt that a customer runs, the customer is the controller and we are the processor, acting on the customer's documented instructions under our Data Processing Agreement (DPA).

5.2a. Our own controller role for the cached dataset. To operate the Service, we also maintain a global, cross-customer catalog of business information derived from public web sources (for caching, deduplication, and quality scoring). To the extent we determine the purposes and means of this cached/derived dataset, we act as an independent controller and rely on legitimate interests (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)), as assessed in our Legitimate Interests Assessment. Business contacts have the right to object and to request erasure of their data from this dataset (see Sections 5.4 and 10).

5.3. The customer is responsible for having a lawful basis (typically legitimate interest for B2B contact) and for honoring data-subject rights regarding this data. We assist customers with such requests as described in the DPA.

5.4. If you are a business contact who appears in results and wish to exercise your rights, please contact us at privacy@getcernio.com; we will route your request to the relevant controller (our customer) and/or act on it where we are able.

6. How We Share Data — Subprocessors and Recipients

We share personal data with vetted service providers ("subprocessors") who process it on our behalf, and with our payment processor. Key recipients:

ProviderRoleLocation
SupabaseDatabase, authenticationEU (Frankfurt)
VercelApplication hosting / CDNGlobal edge; primary region EU
iyzico (İyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.)Payment collection (payment institution — not a Merchant of Record; Cernio is the seller and issues the invoice)Türkiye
ResendTransactional email deliveryUSA/EU
SentryError monitoring (PII scrubbed)USA/EU
Google Analytics (Google Ireland Limited / Google LLC)Optional website and application usage analytics, only after your consent; advertising features disabledUSA/EU
Microsoft ClarityOptional session replay on ordinary product screens of the application, only after your consent (PII masked)USA
Google (Gemini), Anthropic, OpenAI, Perplexity, CohereAI model providers used to process queries and generate resultsUSA
Exa, Serper, TavilyWeb search providers for public-web discoveryUSA

Note on data location: Core data is hosted in the EU (Frankfurt). See Section 7 for international transfers involving providers outside the EU/EEA.

We do not sell your personal data. We may disclose data where required by law, to protect our rights, or in connection with a merger or acquisition (with notice where required).

An up-to-date list of subprocessors is maintained in our DPA (Annex B).

7. International Transfers

Some subprocessors are located outside the EU/EEA and Türkiye (e.g. in the USA). Where we transfer personal data internationally, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), adequacy decisions where available, and, for KVKK, the applicable transfer mechanisms (explicit consent or undertakings/authorization as required). You may request more information at privacy@getcernio.com.

8. Third-Party Links and Services

The Service may surface links to third-party websites (e.g. company websites found during discovery). We are not responsible for the privacy practices of those sites. The hosted payment page is operated by the payment institution under its own privacy policy.

Cookies and similar browser storage — including the optional analytics services above, which run only after your consent, and how to change your choice — are described in our Cookie Policy.

9. Data Retention

  • Account data: kept for the life of your account. A deletion request starts a 30-day waiting period — there so you can undo an accidental deletion — after which the data is permanently deleted, unless a longer period is required by law.
  • Session records: deleted together with your account.
  • Activity and security logs: retained for security, abuse detection and accountability. When your account is deleted, the personal data in those records is scrubbed and the record is de-identified so it can no longer be linked to you; what remains is no longer personal data.
  • Payment provider event records: deleted automatically after 90 days.
  • Billing and financial records: retained for the period required by tax and commercial law (10 years for commercial books and records under Turkish law).
  • Website enquiries: the message you send from the contact form, and the address you gave us, are kept as correspondence in our mailbox so we can answer you and keep a record of what was discussed. We do not copy them into a separate database, and you may ask us to delete them (Section 10).
  • Customer Data (processor): deleted or returned per the DPA following termination.
  • Deletion mechanics: the Service implements soft-deletion followed by scheduled hard-deletion (right-to-be-forgotten) of queued requests.

10. Your Rights

Subject to applicable law (GDPR and/or KVKK), you have the right to:

  • access your personal data and obtain a copy;
  • rectify inaccurate data;
  • erase data ("right to be forgotten");
  • restrict or object to processing (including profiling and direct marketing);
  • data portability;
  • withdraw consent at any time (without affecting prior processing);
  • under KVKK, to learn whether your data is processed, request correction/deletion, and object to results arising exclusively from automated analysis;
  • lodge a complaint with a supervisory authority — in the EU/EEA your local Data Protection Authority; in Türkiye the Turkish Personal Data Protection Authority (KVKK).

These rights are available to you except where retention is required by applicable law. Billing and invoice records are retained for the periods required by applicable tax and commercial law, including after an account is closed (Section 9); a deletion request cannot be honoured for those records before the statutory period expires.

To exercise your rights, contact privacy@getcernio.com. We will respond within the timeframes required by law (generally one month under GDPR; 30 days under KVKK).

11. Automated Decision-Making

The Service uses AI to rank and score potential buyers ("lead scoring"). These outputs are decision-support tools, not automated decisions producing legal or similarly significant effects on the scored individuals. Human review by our customers is expected. If you believe you are subject to a decision based solely on automated processing, contact us.

12. Security

We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, row-level security for tenant isolation, hashed credentials, optional MFA, PII masking in session-replay/analytics, and error-data scrubbing. No system is perfectly secure; we cannot guarantee absolute security.

13. Children

The Service is not intended for anyone under 18. We do not knowingly process children's data. If you believe a child has provided us data, contact us for deletion.

14. Changes to This Policy

We may update this Policy. For material changes we will provide reasonable notice (email or in-app). The "Effective date" indicates the latest version.

15. Contact

  • Data protection: privacy@getcernio.com
  • Controller: GADULABS YAZILIM LİMİTED ŞİRKETİ, Mustafa Kemal Paşa Mah. Yalova-Bursa Yolu Cad. A Blok 1. Kademe No: 123/1 İç Kapı No: 10, Merkez / YALOVA, Türkiye
  • KVKK data controller contact: privacy@getcernio.com

This Policy is provided for transparency and does not constitute legal advice.