SayMatik

Privacy Policy

Last updated:

This policy explains what personal data is processed when you use the SayMatik mobile app for iPhone and Android, the website saymatik.com with its web wallet, and the saymatik.com servers the app talks to (together, “SayMatik”): what we process, why, on what legal basis, who receives it, how long we keep it and what your rights are. If you are in Türkiye, the same information is given in Turkish in our KVKK Aydınlatma Metni.

In short

Self-custody: your recovery phrase, private keys and app password stay on your device, and the app never sends them to us or anyone else. We cannot see or recover them.

You do not need an account. We do not ask for your name, e-mail address or phone number to use SayMatik.

What our servers keep is linked to public wallet addresses: Buy SCI purchases, swaps on the SCI exchange, token listing requests, referrals, transfers you make from the web wallet and documents stored with DeCerta in older versions of the app.

ChitChat messages are public and permanent: they are written to the blockchain unencrypted and can never be deleted. Do not put personal data in them.

Wallet addresses and transactions are public on the blockchain, and nobody, including us, can delete them there.

The app contains no analytics, advertising, crash-reporting or tracking tools.

1. Who is responsible

The controller of your personal data (the “veri sorumlusu” under Turkish Law No. 6698, KVKK) is ZİNCİRX BİLİŞİM TEKNOLOJİ VE DANIŞMANLIK A.Ş. (“ZincirX A.Ş.”), the company in Türkiye that provides SayMatik (“we”, “us”), for users in every country:

Company
ZİNCİRX BİLİŞİM TEKNOLOJİ VE DANIŞMANLIK A.Ş.
Registered office
Gülbahçe Mah. Gülbahçe Cad. İYTE Sitesi No: 1/40 İç Kapı No: 51, 35430 Urla/İzmir, Türkiye
MERSİS No
0999144137300001
Tax office and number
Urla Tax Office, 9991441373
E-mail (privacy requests and questions)
info@zincirx.com

2. Self-custody: what we never receive

3. What we process, why and on what basis

The legal bases below are those of the EU and UK General Data Protection Regulation (GDPR, Art. 6(1)) and, for people in Türkiye, KVKK Art. 5. The KVKK notice sets out the Turkish bases in detail.

WhenDataWhyLegal basis
Every visit to saymatik.com and every request from the app to our servers IP address, date and time, requested address (which can contain a wallet address), referring page, browser or app identification (user agent), response status Delivering the website and the app’s data, security, preventing abuse, fixing errors Legitimate interests (GDPR Art. 6(1)(f)); KVKK Art. 5(2)(f)
Buy SCI: after you send a stablecoin payment from the app Payment transaction hash, network, paying wallet address, stablecoin, amount, SCI amount and price, the time, and the IP address and app identification (user agent) of the request Checking the payment on the blockchain, sending you the SCI, preventing double claims and fraud, showing your purchase history, keeping commercial records Contract (GDPR Art. 6(1)(b)); legitimate interests in fraud prevention and in complying with Turkish commercial and tax law (Art. 6(1)(f)); KVKK Art. 5(2)(c), (ç) and (f)
Region check: when a Buy SCI payment notification arrives, and when versions of the app that include the check ask which features are offered where you are (below) The IP address of the request, used only to look up its country and not kept for this check; for a Buy SCI payment notification refused because the IP address is registered in Türkiye, its country, network and transaction hash Not offering Eppay QR payments and Buy SCI in Türkiye; tracing a refused payment Legitimate interests in complying with Turkish law (GDPR Art. 6(1)(f)); KVKK Art. 5(2)(ç) and (f)
Swaps and liquidity on the SCI exchange in the app Wallet address, token, buy/sell/add-liquidity, amount, price, value, transaction hash, contract address, time, gas and block details Price charts and trading statistics for SCI tokens Legitimate interests (Art. 6(1)(f)): providing market data for the exchange; KVKK Art. 5(2)(f)
Token listing requests Wallet address, payment transaction hash, network, amount paid; the token’s name, symbol, contract address, decimals, supply, description and logo Checking the listing payment, reviewing the request and showing the token in SayMatik Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c)
Activating swap, locker or peer-to-peer tools for a token you manage Token address, contract addresses, transaction hash, network (no wallet address) Connecting the token to its trading and locking contracts in SayMatik Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c)
Referrals: when you set who referred you Your wallet address, the referrer’s wallet address, a signature from your wallet proving the request is yours, the time Sending the referrer their share of transfer fees Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c)
Sending tokens from the web wallet on saymatik.com Wallet address, recipient, token, amount, transaction hash, status, gas, time, a short description Showing your transaction history on the website Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c)
DeCerta document storage (older versions of the app; see below) Wallet address, document name, description, file type, the contents of the file (stored unencrypted), the hashes of its parts, upload time Storing your document and giving it back to you Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c)
When you e-mail us Your e-mail address, name if you give it, the content of your message and anything you attach, such as a wallet address or transaction hash Answering you and handling your request Legitimate interests (Art. 6(1)(f)) or contract (Art. 6(1)(b)); KVKK Art. 5(2)(c) and (f)
Legal requests and disputes The data relevant to the request or dispute Answering authorities where the law requires, establishing or defending legal claims Legitimate interests (Art. 6(1)(f)); KVKK Art. 5(2)(ç) and (e)
Only if you accept analytics in the cookie banner on saymatik.com Pages visited (without wallet addresses or transaction hashes), browser, device, approximate location (see Google Analytics) Understanding how the website is used Consent (Art. 6(1)(a)); explicit consent, KVKK Art. 5(1)

We do not ask for or collect identity documents (no KYC), and we do not process special categories of data such as health or biometric data. We do not sell personal data, use it for advertising or make decisions about you based solely on automated processing. Where we rely on legitimate interests, you can object (section 10).

The sign-up and sign-in forms on saymatik.com do not create accounts: what you type into them is not sent to our servers.

Eppay QR payments (paying an Eppay QR code and making “Get paid” codes) and Buy SCI are not offered in Türkiye. To apply this:

Legal basis for these checks: GDPR Art. 6(1)(f), our legitimate interest in complying with Turkish law; KVKK Art. 5(2)(ç), legal obligation, and Art. 5(2)(f), legitimate interest.

saymatik.com does not keep the IP address for these checks. As with every request to our servers, the IP address still appears in the web server’s access log (section 9), and every Buy SCI payment notification, refused or not, also creates or updates the short-lived session record described in section 11 and, to limit how often notifications can be sent, leaves a hashed form of the IP address, which expires after about a minute and is deleted within the following hour (section 9). These server records rest on our legitimate interest in running the service securely (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f); section 3).

DeCerta documents

Older versions of the SayMatik app offered DeCerta, a feature for storing documents. The current version no longer does, but the documents uploaded with it are still kept on our server:

4. Data that stays on your device

The app keeps the following on your device only. We have no access to it.

5. Public blockchains

Every transaction you sign is sent to a public blockchain. Your wallet address, the addresses you deal with, amounts, tokens and any data contained in the transaction become public and permanent: anyone can see them, others may link your address to you, and neither we nor anyone else can change or delete them. Before you write data to a blockchain, keep in mind in particular that:

Apart from DeCerta documents (see above), these on-chain records are not stored by us on our servers, and the rights described in section 10 cannot remove them from a blockchain.

6. Services your device connects to directly

To work, the app and the website connect directly to services we do not operate. They receive your IP address and the request itself, and process them under their own privacy policies:

7. Who receives data

The services in section 6 receive data from your device directly, not from us.

8. Transfers outside Türkiye and the EEA

Our servers are in the EU (Lithuania), so data about users in Türkiye is transferred abroad. Some of the services above are in the USA or other countries that may not protect personal data to the same standard as Türkiye or the EU. For people in Türkiye, transfers abroad other than the transfer to Google for analytics are subject to Article 9 of the KVKK, and we do not rely on your explicit consent for them; you can ask for details of these transfers at info@zincirx.com. The transfer to Google for analytics relies on your consent (section 11).

9. How long we keep data

DataKept for
Web server access logsUp to 15 days
Application logs (errors and payment checks, including the IP address and transaction hash of Buy SCI payment notifications; the country, network and transaction hash of Buy SCI payment notifications refused because the IP address is registered in Türkiye; and the transaction hash of “Get paid” payment notifications, with the IP address for those received before 10 October 2026)As long as needed for security, fraud prevention, troubleshooting and handling refused payments
Buy SCI purchase recordsAs long as Turkish commercial and tax law requires commercial records to be kept: up to 10 years (Turkish Commercial Code Art. 82: 10 years; Tax Procedure Law Art. 253: 5 years)
Token listing requestsWhile the listing is shown or under review; payment records as for purchases
Swap records, web wallet transaction history, referrals and token contract linksWhile SayMatik offers the feature they serve, unless you ask us to delete them earlier and we have no legal reason to keep them
DeCerta documents on our serverUntil you delete them or ask us to delete them
E-mails with usAs long as needed to handle your request and any follow-up, and longer only where a legal claim is possible
Session and security cookies, and the session record on our server (IP address, browser or app identification, and the address of the last page or request, which can contain a wallet address)2 hours; expired session records are deleted automatically some time after they expire
Rate-limit entries for payment notifications (a hashed form of the IP address)They expire after about a minute and are deleted within the following hour
Google Analytics_ga cookies up to 2 years; Google keeps the analytics data for 14 months
Data on public blockchainsPermanently; it cannot be deleted

When a period ends, we delete or anonymise the data.

10. Your rights

Depending on the law that applies to you, you have the right to:

To use these rights, e-mail info@zincirx.com. Because most data we hold is linked only to a wallet address, we may ask you to sign a message with that wallet to show it is yours. We answer within 30 days, free of charge. People in Türkiye can also apply in the ways set out in the KVKK notice.

11. Cookies and browser storage

The website and our servers use only what they need to work, and nothing for tracking or advertising:

Strictly necessary cookies need no consent and rely on our legitimate interest in providing a secure website.

Google Analytics

The only optional tool on the website is Google Analytics 4, provided by Google Ireland Limited (for visitors in the EEA and Switzerland) and Google LLC (USA). It runs only on the home page and the sign-in and sign-up pages, and only if you choose “Accept all”, or turn on Analytics under “Preferences”, in the cookie banner; until then no request is sent to Google and no analytics cookie is set. It never runs in the app or on the wallet, exchange, transactions or admin pages.

It measures the pages you visit, page titles, the page you came from, when and how long you visit, interactions such as scrolling and outbound clicks, your browser, device and language, and an approximate location (country, city) derived from your IP address; Google Analytics 4 does not log or store IP addresses. Before anything is sent, wallet addresses and transaction hashes are removed from page addresses and the query string is dropped (except campaign utm_ tags); a page whose address carries other parameters is not measured, and measurement stops on a page as soon as it shows a connected wallet address. No name, e-mail address, wallet address, account or user ID is sent to Google, and Google signals and ad personalisation are switched off. It sets the _ga and _ga_<ID> cookies, which stay in your browser for up to 2 years; Google keeps the analytics data for 14 months, then deletes it.

Legal basis: your consent (GDPR Art. 6(1)(a) and ePrivacy Art. 5(3); for visitors in Türkiye, explicit consent under KVKK Art. 5(1)). The data is processed by Google, including on servers in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; for visitors in Türkiye the transfer abroad relies on your explicit consent under KVKK Art. 9(6)(a), given knowing that the USA may not offer the same level of protection as Türkiye and that US authorities may be able to access the data.

You can change your choice or withdraw consent at any time with the “Cookie settings” link at the bottom of the home page or under the sign-in and sign-up forms. Withdrawing stops Google Analytics and deletes the _ga cookies the site can delete. Rejecting does not affect your use of the site.

12. Security

The website and our servers use encrypted connections (HTTPS), access to our servers is restricted, and the app keeps your keys in your device’s encrypted storage. No system is completely secure, so protect your device, keep your recovery phrase offline and be wary of anyone asking for it.

13. Children

SayMatik is not intended for anyone under 18, and we do not knowingly process children’s personal data. If you believe a child has sent us personal data, contact us and we will delete it.

14. Changes to this policy

We update this policy when SayMatik or the law changes. The date at the top shows the current version; for significant changes we will also tell you in the app or on the website.

15. Contact

For questions or requests about your personal data, write to info@zincirx.com.