Sectors
Energy & InfrastructureAgri & FoodTextile & FashionReal Estate & PropertyManufacturing & IndustryMaritime & LogisticsTourism & HospitalityHealthcare & MedicalTechnology & DigitalInvestment & FinanceConstruction & Building MaterialsAutomotive & MachineryChemicals & PlasticsMining & MetalsPackaging & PaperFurniture & Home GoodsExplains how we process your personal data in compliance with applicable data-protection law (GDPR, KVKK, etc.).
Last updated: 2026-08-09
Asinora ("we", the "Platform") acts as the data controller under the data-protection law applicable in each user's jurisdiction — including the General Data Protection Regulation (GDPR, 2016/679) in the EU/EEA, the Turkish Personal Data Protection Law (KVKK, Law No. 6698), and equivalent frameworks in other countries. This Privacy Policy explains what personal data we process, why, who we share it with, and how you can exercise your rights. For any data-protection request, question, or complaint: hello@asinora.co. A formal Data Protection Officer (DPO) will be appointed once the corporate structure is finalized, and contact details will be updated on this page.
Identity and contact data: full name/company name, email, phone, country, language preference. Verification (KYC/KYB) data: identity document image, facial biometrics (processed during liveness/matching checks; raw biometric data is NOT stored on Asinora's own servers — see §5), tax identification number, commercial registry/company registration details, professional license documents. Commercial transaction data: listing/request content, messaging history, deal terms, payment and escrow transaction records (card details themselves are NOT stored by Asinora; they are processed directly by the payment provider). Technical and usage data: IP address, device/browser information, session logs, cookie data (see Cookie Policy), in-platform interaction metrics. Content data: uploaded documents, images, voice messages, written/voice interactions with NORA.
We process your data for the following purposes: (a) account creation and identity/company verification, (b) providing commercial matching and listing/request services, (c) executing escrow and payment transactions, (d) enabling the NORA AI assistant to provide personalized guidance, (e) ensuring platform security and preventing fraud/abuse, (f) fulfilling legal obligations (KYC/AML, tax, accounting), (g) providing customer support, (h) — only with your explicit consent — product announcements and marketing communications. Regarding voice notes sent in chat: the recording is stored as a file attachment; if your browser supports it, the audio may be sent to your browser's own speech-recognition service (e.g. Google) to produce a transcript — this is third-party processing outside Asinora's direct control and is governed by that service's own privacy policy.
When processing your personal data, we rely on the following lawful bases: (a) contract performance — processing necessary to manage your account and provide matching/escrow services (GDPR Art. 6/1-b); (b) legal obligation — KYC/AML law, tax and accounting record-keeping requirements (GDPR Art. 6/1-c); (c) legitimate interest — platform security, fraud prevention, service improvement, to the extent our legitimate interest does not override your fundamental rights (GDPR Art. 6/1-f); (d) explicit consent — marketing communications, optional features; you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal. For special categories of data such as biometrics (face matching), additional explicit consent is obtained, and this data is processed only by the verification provider, for a limited period (see §5).
We do NOT sell your personal data. Your data is shared only with the following categories of recipients, and only for the stated purpose: (a) service providers/data processors — hosting (Vercel), database (Supabase), payments (Stripe), identity verification (Didit), email (Resend), AI infrastructure (OpenAI), error tracking (Sentry); the full list and the data categories each processes is detailed in the Data Processing Agreement (/legal/dpa); (b) other platform users — only data you have chosen to make visible, such as your listing/profile, and only in the context of a commercial match/introduction; (c) authorities — in the event of a lawful request, court order, or regulatory obligation; (d) professional advisors — only our own legal/financial advisors, under confidentiality obligations. Your biometric verification data (facial image/matching) is processed by our verification provider and deleted after verification is complete, per that provider's own retention policy; Asinora does not store this raw biometric data in its own database — it receives only the verification RESULT (pass/fail, level).
Our users are located worldwide, and our platform infrastructure (hosting, database, payment and verification providers) operates in more than one country. Your data may be transferred to a country other than the one you are located in. For such transfers: (a) for transfers from the EU/EEA to third countries, the European Commission's Standard Contractual Clauses (SCCs) are used; (b) for transfers from Türkiye abroad, the mechanisms prescribed by KVKK apply (adequacy decision, SCCs, Board authorization) — per the September 2024 KVKK update, TR↔EU transfers are notified to the Board within 5 business days; (c) in every other region, a GDPR-equivalent level of protection is maintained unless local law prescribes a different standard. Data Processing Agreements are in place with all of our sub-processors (Stripe/US, OpenAI/US, Didit/multi-region with EU presence, Sentry/US, and others); details are on the /legal/dpa page.
We retain your data only for as long as the purpose of collection requires: KYC/KYB verification documents — 10 years (AML and equivalent international compliance obligations); commercial transaction and invoice records — 10 years (tax law requirement); messaging content — 3 years; NORA memory summary — for as long as the account remains active, until your deletion request; cookie/session data — see Cookie Policy; customer support requests — 2 years. When you delete your account, your active profile and content data is anonymized or deleted within 30 days; data subject to a legal retention obligation (e.g. completed transaction records) continues to be retained, solely for that purpose, until the relevant legal period expires.
We implement reasonable technical and organizational measures to protect your data: encryption of data in transit (TLS), application-layer AES-256-GCM encryption of sensitive fields (e.g. the NORA memory summary), database-level isolation via Row Level Security, role-based administrator authorization and access logs (audit log), and regular dependency/vulnerability scanning. No system is 100% secure; if, despite reasonable measures, a data breach occurs, we will notify the competent authority and affected users within the period prescribed by applicable law (generally 72 hours under GDPR) — see §14.
The platform offers potential buyer/seller suggestions through an AI-assisted matching system based on the information you enter, and uses automated checks such as forgery detection/risk scoring during verification. These automated processes are ADVISORY: no automated system makes a decision that significantly affects you (such as refusing to establish a deal or closing your account) ON ITS OWN, without human review by an Asinora administrator. Significant decisions such as verification rejection or account suspension always involve human review and a right to object (GDPR Art. 22). Matching suggestions are non-binding; accepting or rejecting a suggestion is always your own decision.
The NORA AI assistant stores a short, ENCRYPTED summary of your past interactions (such as your preferred Incoterm, frequently asked topics, and trade context) to personalize your experience (AES-256-GCM encryption; plaintext is never stored in the database). This data: (a) is linked ONLY to your own account, (b) is used solely so NORA can respond more accurately to you, (c) is never used for advertising or marketing, (d) is never shared with third parties (other than the AI provider used in NORA's own infrastructure — see §5 and /legal/dpa). You may delete this memory entirely at any time from the relevant section of your account settings (the "right to be forgotten", GDPR Art. 17); your deletion request takes effect immediately and irreversibly.
The listing/request information you enter on the platform (title, description, category, etc.) and the documents you upload (e.g. product/service specification files, gallery images) may be viewed by authorized Asinora administrators in a per-user, chronological "digital footprint" view, for purposes of platform security, fraud prevention, dispute resolution, and support requests. This view is read-only, available only to role-authorized admins, and the access itself is recorded in the audit_log. This data is not used for advertising or marketing and is not shared with third parties.
The platform is designed for B2B trade and is not directed at persons under 18. We do not knowingly collect data from persons under 18. If a parent or guardian becomes aware that a person under 18 has provided us with data, please contact us at hello@asinora.co; we will delete the relevant data immediately.
Under applicable data-protection law, you have the following rights: access (to learn what data of yours we process), rectification (to have inaccurate or incomplete data corrected), erasure (the "right to be forgotten", subject to legal retention obligations), restriction of processing, data portability (to receive your data in a structured, machine-readable format), objection (to object to processing based on legitimate interest), and withdrawal of consent. To exercise these rights, email hello@asinora.co; we may ask you to verify your identity. We respond to requests within 30 days at the latest (for complex requests this period may be extended within legal limits, with notice to you). If you have a complaint, you retain the right to lodge it directly with the competent data-protection authority in your country — for example, the Hellenic Data Protection Authority (HDPA) in Greece, or the KVKK Board in Türkiye. Users outside the EU/Türkiye may identify their own country's competent authority and contact it directly.
If we detect a breach affecting the security of your personal data, we notify the competent supervisory authority within the period prescribed by applicable law (generally within 72 hours of becoming aware, under GDPR). If the breach poses a high risk to your rights and freedoms, we will also notify you without undue delay, describing the nature of the breach, the measures taken or planned, and recommended actions.
We may update this Privacy Policy from time to time; for material changes we will provide at least 30 days' notice via the platform or by email. The "last updated" date at the bottom of the page always reflects the most current version.