GDPR and KVKK
Privacy Policy
Transparency is at the core of Shim. This policy designates how we process, store, and protect your data in alignment with GDPR and KVKK regulations.
1. Data Controller (Veri Sorumlusu)
In accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK") Art. 10 and EU General Data Protection Regulation ("GDPR"), the controller of your personal data is:
Shim Technologies
Istanbul, Turkey
support@getshim.tech
2. Information We Collect
We collect minimal data necessary to provide our gateway and governance services. We explicitly distinguish between:
- Account Data: Email address, name, account authentication data, and tenant-bound provider credential references.
- Usage Data: API usage metrics, token counts, and performance logs.
- Transient Data: Raw prompt and response bodies are processed transiently and are not stored in durable request records. For OpenAI Responses continuations, encrypted, tenant-bound PII restoration mappings may be stored in Redis for up to 30 days.
3. Legal Basis for Processing (Hukuki Sebepler)
We process your data based on the following legal grounds under KVKK Art. 5/6 and GDPR Art. 6:
Contractual Necessity
To provide the Shim Gateway services you request through your account.
Legitimate Interest
To optimize system performance, prevent fraud, and ensure security.
Legal Obligation
To comply with tax and financial regulations.
4. Data Sharing & International Transfers
We do not sell your data. We share data only with service providers required to operate Shim, including hosting, authentication, and the upstream model provider configured for the request: OpenAI, Anthropic, or Google. Configured PII controls run before prompt content is sent to that provider.
International Transfer Notice (KVKK Art. 9)
Some of our infrastructure is hosted on global cloud providers. By using our services, you consent to the necessary transfer of data to secure servers located outside of Turkey, strictly for service provision.
Keeping data in your own infrastructure
Enterprise customers can avoid this transfer by running Shim on-prem, on their own servers. In that setup, prompts, provider keys and audit records never reach our infrastructure. The only data that leaves your network is the request sent to the model provider you choose, with configured PII masked. See Shim Enterprise
5. Your Rights (Haklarınız)
Under GDPR and KVKK Art 11, you have the right to:
- Request access to your personal data
- Request correction of errors
- Request deletion (Right to be Forgotten)
- Object to processing
- Request data portability
To exercise these rights, contact us at privacy@getshim.tech. We will respond within 30 days.
6. Cookies & Tracking
We use only essential cookies for authentication and security. We do not use third-party tracking cookies for advertising purposes.