How BeforeTomorrow collects, uses, and protects your personal data under GDPR, KVKK, and CCPA/CPRA.
Ideasets Teknoloji Yapay Zeka Ticaret Anonim Şirketi (trading as BeforeTomorrow), a company registered in Üsküdar, İstanbul, Türkiye (Tax Office: Üsküdar Vergi Dairesi, Tax No: 4651615036; MERSİS No: 0465161503600001; Trade Registry No: 1113512), is the data controller under Regulation (EU) 2016/679 ("GDPR") and the data responsible party ("veri sorumlusu") under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") for the personal data described in this Privacy Policy.
Not required to register with VERBİS (Data Controllers' Registry) under KVKK Kurulu Decision 2018/68 — the company employs fewer than 50 people and has an annual balance-sheet total under 100 million TRY, and does not process special-category personal data as its main field of activity.
For any question, request, or complaint about this Policy or your personal data, contact us at contact@beforetomorrow.io. We do not currently have a legal obligation to appoint a Data Protection Officer under GDPR Art. 37 or a KVKK-registered representative, given our size and processing activities; this contact address receives and answers all data-protection requests directly.
This Policy applies to everyone who visits https://www.beforetomorrow.io, creates an account, or uses any BeforeTomorrow studio or API — whether you are in the European Economic Area, the United Kingdom, Turkey, the United States, or elsewhere. We apply one global standard rather than a different policy per region: our default is opt-in consent for anything not strictly necessary (the GDPR/KVKK standard), which is a strict superset of what opt-out regimes like the CCPA/CPRA require. This means every visitor, everywhere, gets the same strongest-applicable protection.
We collect the following categories of personal data:
What we do NOT collect: we do not collect precise geolocation, biometric identifiers, government ID numbers, or health data, and we do not knowingly collect data from anyone under 16 (see §12).
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account | Account data, authentication data | Contract necessity (GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c)) |
| Generate content you request | Content you create, account data | Contract necessity (GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c)) |
| Process payments and manage credits | Billing data | Contract necessity + legal obligation (GDPR Art. 6(1)(b)/(c)) |
| Prevent fraud, abuse, and security incidents | Device/technical data, usage data | Legitimate interest (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)) |
| Understand product usage and improve the service | Usage data (Analytics category) | Consent (GDPR Art. 6(1)(a) / KVKK Art. 5(1)) |
| Measure and personalize advertising | Usage data (Advertising category) | Consent (GDPR Art. 6(1)(a) / KVKK Art. 5(1)) |
| Respond to your support requests | Communications, account data | Contract necessity / legitimate interest |
| Comply with tax, accounting, and legal obligations | Billing data, account data | Legal obligation (GDPR Art. 6(1)(c) / KVKK Art. 5(2)(ç)) |
We do not sell your personal data. We share data only with the following categories of recipients, each acting as our processor/sub-processor under a data processing agreement (GDPR Art. 28) or equivalent contractual safeguard:
We never share your account data, prompts, or generated content with other users, except content you explicitly choose to publish to a public gallery.
Our primary infrastructure runs in AWS eu-central-1 (Frankfurt, EU), so most personal data never leaves the European Economic Area. Where a transfer outside the EEA/UK/Turkey is necessary (for example, a global CDN edge node or a US-based sub-processor), we rely on the European Commission's Standard Contractual Clauses (2021/914/EU), the UK International Data Transfer Addendum, or an equivalent safeguard recognized under KVKK Art. 9, and we verify the recipient provides an adequate level of protection before any transfer occurs.
Depending on where you live, you have some or all of the following rights over your personal data. We honor the strongest applicable version of each right, for every user, regardless of location:
To exercise any of these rights, email contact@beforetomorrow.io. We verify your identity before acting on a request and respond within 30 days (KVKK Art. 13(2)) or one month, extendable by two further months for complex requests (GDPR Art. 12(3)). If you are in Turkey and unsatisfied with our response, or receive no response within the statutory period, you may complain to the Kişisel Verileri Koruma Kurumu (KVK Kurumu) within 30 days of our response or 60 days of the request if we do not respond. If you are in the EEA/UK, you may complain to your local supervisory authority.
The core of our service is AI-assisted content generation: your prompts and briefs are sent to large language models (run on AWS Bedrock, within the EU where residency requires it) to produce the presentations, documents, and other artifacts you request. This is a service you directly request and control — it is not automated decision-making that produces legal or similarly significant effects about you (GDPR Art. 22), since you review and choose whether to use every output. We do not use your data to train third-party foundation models, and your prompts/content are not used to profile you for purposes unrelated to delivering the service you asked for.
BeforeTomorrow is not directed at, and we do not knowingly collect personal data from, anyone under 16 years of age (the GDPR's default age of digital consent, which we apply globally as the stricter standard even where local law sets a lower age, e.g. 13 under CCPA/COPPA). If we learn that a user under 16 has provided us with personal data, we will delete it promptly. Parents or guardians who believe their child has provided us data should contact contact@beforetomorrow.io.
We will update this Policy as our processing activities evolve. Material changes will be communicated by email or a prominent in-product notice, and — where the change affects the scope of your consent (e.g. a new tracking category) — we will ask for fresh consent before the change takes effect. The version number and "Effective" date at the top of this page always reflect the current, binding version.
For any privacy question, request, or complaint:
Ideasets Teknoloji Yapay Zeka Ticaret Anonim Şirketi
Üsküdar, İstanbul, Türkiye
Email: contact@beforetomorrow.io