PhiShark Logo
Legal & Trust Center

Global Privacy Notice

How PhiShark processes personal data when you visit our website or use our dashboard, API, browser extension, mail protection and email add-ins.

Version
1.0-draft
Effective date
Upon publication following legal approval
Last updated
25 July 2026
Change summary
Initial consolidated draft covering the website, platform, API and client integrations.

1. Controller, roles and scope

PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ (“PhiShark”, “we”) is the controller for website, account, billing, support and direct-customer data. For enterprise content submitted under a customer agreement, PhiShark may act as processor and the customer remains controller. The applicable agreement and Data Processing Addendum govern that relationship.

This notice covers phishark.io and associated dashboards, APIs, browser extensions, Gmail and Outlook add-ins, mail-protection features, URL/domain, PDF and QR analyses, and prompt-injection detection features. It does not govern third-party sites or services reached through links.

2. Data categories and sources

  • Account and contact data: name, business contact details, authentication identifiers, organization, role and communications.
  • Commercial data: plan, transaction reference, invoice and subscription status. Payment card details are handled by Dodo Payments under its own terms; PhiShark should not receive full card data.
  • Submitted security data: URLs, domains, IP indicators, email sender/recipient and header data, subject, selected or masked body content, links, attachment metadata or hashes, files such as PDF/QR content, webpage signals, and user-provided context.
  • Product and device data: scan identifiers and results, security verdicts, API activity, browser/extension version, operating system, timestamps, coarse network and diagnostic data.
  • Website storage and consent data: language, cookie/local-storage choice and necessary session or security state.
  • Support, abuse and rights-request data, including evidence reasonably needed to authenticate and resolve the request.

Security submissions can contain third-party personal data, secrets or confidential information. Submit only what you are authorized to analyze and remove unnecessary sensitive content.

3. Purposes and legal bases

We process data to provide and secure requested services, authenticate users, generate and explain security results, operate subscriptions, support customers, detect abuse, maintain auditability, improve reliability, comply with law and establish or defend legal claims.

Depending on the jurisdiction and context, our bases are performance of a contract or pre-contract steps, legal obligations, legitimate interests in operating and securing the service, explicit or other valid consent where required, and establishment, exercise or defence of legal claims. Consent may be withdrawn prospectively without affecting prior lawful processing.

4. Product-specific processing

  • Browser extension: may access the active URL and page security signals and, where the user invokes an email workflow, relevant email DOM fields. Broad host permissions such as <all_urls> are used only for user-requested security analysis, warning and page integration. Preferences and minimum session state may be kept in Chrome Storage.
  • Gmail add-in: requests temporary read access to the message currently open. It extracts sender, subject, links, selected headers, thread signals and attachment metadata. Body content is used only for an expressly initiated or configured analysis and sensitive patterns are masked where supported. Screenshots and attachment file contents are not uploaded by the current add-in.
  • Outlook add-in: accesses the item currently opened or selected for a user-requested analysis. The exact manifest permissions and whether body or attachment data is used must be verified before publication of the Outlook store listing.
  • Mail protection: may analyze routing/authentication signals, message metadata, links, attachment indicators and configured content. Enterprise administrators control deployment and should inform authorized users.
  • URL, PDF and QR analysis: may fetch or render submitted destinations and retain technical artefacts for investigation, abuse prevention and result delivery.
  • Prompt-injection detection: may inspect submitted content for malicious instructions. Raw prompt-injection content is not intended for persistent storage; production behavior must be verified before publication.

5. AI-assisted and automated analysis

PhiShark combines deterministic security checks, reputation sources and AI-assisted models. Depending on the enabled feature and configuration, submitted content or derived technical signals may be processed by contracted cloud, threat-intelligence or AI providers. PhiShark does not use results as the sole basis for decisions producing legal or similarly significant effects about individuals.

AI and security outputs can be inaccurate, incomplete or affected by adversarial content. See the AI & Cybersecurity Disclaimer. Until production minimization and provider-routing controls are fully verified, users must avoid submitting unnecessary personal data, credentials, special-category data or trade secrets.

6. Recipients and international transfers

Data may be disclosed on a need-to-know basis to hosting, cloud, security, AI inference, communications, support and payment providers; professional advisers; competent authorities; and a successor in a lawful corporate transaction. We do not sell personal data.

Processing may occur in Türkiye, the EEA, the United States and other provider locations. Where required, transfers rely on an adequacy decision, standard contractual clauses, the UK Addendum, a KVKK-compliant transfer mechanism or another lawful safeguard. Provider, role, region and contract status must be confirmed in the Subprocessor List before publication.

7. Retention and security

Our target schedule is: scan results 24 months; raw HTML, screenshot, favicon, PDF/QR and comparable artefacts 90 days; mail-analysis summaries 30 days; no persistent raw prompt-injection content; security/audit logs 12 months; support and contact records 24 months; and deletion from backups within 30 days. Billing, tax, fraud and dispute records remain for legally required or defensible periods.

We use proportionate access, encryption, logging, segmentation and incident-response measures. No system is completely secure, and these measures do not guarantee prevention of every incident. Actual TTL, lifecycle and backup controls must be technically validated before these periods are represented as enforced.

8. Your rights and choices

Subject to applicable law, you may request access, information, correction, deletion, restriction, objection, portability or withdrawal of consent, and may complain to a competent data-protection authority. Türkiye residents also have the rights in Article 11 of Law No. 6698 described in the KVKK Notice.

Send requests to [email protected]. We may request proportionate identity verification. Enterprise users should generally contact their organization first where that organization is controller. We will not discriminate for exercising a statutory privacy right.

9. Age limit, changes and contact

The services are intended only for persons aged 18 or older. We do not knowingly offer consumer accounts to children.

Material changes will be identified by version and date and, where required, notified or presented for renewed acceptance. Questions and rights requests: [email protected].

Company information

PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ

Cevizli Mah. Zuhal Cad. Ritim İstanbul Sitesi A5 Blok No:46E İç Kapı No:179 Maltepe/İstanbul

Tax office / tax number: Kartal V.D. – 729 137 4297

MERSİS: 0729137429700001

Telephone information will be added as soon as possible.

Contact: [email protected] · [email protected] · [email protected]

Previous versions

No previous public version is archived for this draft.