AI-built projects
Legal review for projects built with AI
Project-specific legal texts, KVKK (Turkish data protection law) compliance and a lawyer's pre-launch review for websites and mobile apps built with AI tools.

Frequently asked questions
Is it forbidden to use a privacy policy written by AI?
No. The problem is not the source of the text but its content: if it does not accurately reflect your project's actual processing, transfers and retention periods, the obligation may be considered unfulfilled. Using it as a draft and having it corrected by a lawyer for your project is the right approach.
Does a small project also need KVKK compliance?
Yes. KVKK applies to anyone processing personal data; project size does not remove the duties to inform, secure data and safeguard transfers. For some obligations, such as VERBİS registration, employee count and balance sheet thresholds matter.
I use an AI API such as OpenAI, Anthropic or Google. Is that a cross-border transfer?
If users' personal data is sent to these providers' servers abroad, generally yes. Which safeguard applies depends on the provider's contractual structure and the type of data sent.
App stores ask for a privacy policy; is any text enough?
Stores require an accessible privacy policy and in most cases an account deletion route, but the same text must also meet the duty to inform under Turkish law. Store approval does not mean legal compliance.
What do I need to prepare for a review?
The project's address or test version, a list of service providers used, any existing texts and information on who (individual or company) operates the project are enough to start.
Can meetings be held remotely?
Yes. Preliminary assessments and drafting work can be carried out by email and online meetings; in-person meetings are held at the Maltepe office by appointment. Consultations are conducted in Turkish.