biriqim
← biriqim

Data Protection & Privacy Policy

July 19, 2026

Personal Data Protection & Privacy Policy

Biriqim Mobile App

Last Updated: August 19, 2026

DATA CONTROLLER

Company Name: EQLEM SOFTWARE AND INFORMATION TECHNOLOGIES CORPORATION

Address: Çamlık Mah. Mercimek Sk. No: 39/16 Ümraniye / Istanbul

App Support Email: destek@biriqim.com

Corporate Email: info@eqlem.com

DATA SUBJECT (USER)

A natural person who downloads the Biriqim mobile application (“Application”), uses it as a guest, or creates a registered account, and whose personal data is processed under the terms of this agreement.

This Privacy Policy explains how your personal data and device data are collected, processed, stored, explains how your personal data and device data are collected, processed, stored, shared with third parties, and outlines your rights in full compliance with the Personal Data Protection Law No. 6698 (“KVKK”). Biriqim is a mobile app that offers personal finance management, portfolio tracking, expense and receivables/payables tracking, document scanning, and AI-powered financial assistant services. This text pertains solely to the Biriqim mobile app; it does not cover ERP, e-invoicing, or corporate web services.

1. Purpose and Scope

This Agreement governs all policies regarding personal data processed within the App, device telemetry, and artificial intelligence processing activities. By downloading the App, using it in guest mode, or creating a registered account, you are deemed to have accepted the terms of this Agreement. In accordance with Apple App Store Review Guidelines 5.1.1(i), the required transparency—including what data is collected, how it is collected, with which third parties it is shared, and when it is shared—is clearly stated in this document.

1.1. In-App Explicit Consent Principle

Important: The transfer of personal data to artificial intelligence providers, cloud storage infrastructure, or processors located outside the country may only occur after you provide in-app explicit consent through the explicit consent screen/notification presented to you within the App. Simply reading or accepting this Agreement does not, by itself, constitute sufficient consent for the transfer of data to third-party AI processors. Separate in-app consent is obtained for each category of sensitive processing (document scanning/OCR, AI chat, voice commands, etc.).

2. Data Collected

The Company collects the following categories of data during your interactions with the App:

2.1. Device ID and Bootstrap Telemetry

The App uses a unique, persistent device ID generated during initial setup (deviceId). At each app launch (cold start), the device platform (iOS/Android), app version, operating system version, device model, system language (locale), and build number are transmitted to the backend API as bootstrap telemetry and stored in a PostgreSQL database.

2.2. Guest and Registered Account Data

In guest mode, only local data associated with the device ID is processed. When you create a registered account, your email address, first and last name, password hash, and—if you sign in with Google Sign-In or Apple Sign-In—unique user identifiers (ID tokens) provider are collected. Data from the guest period is merged with the registered profile when an account is created.

2.3. Portfolio, Asset, Expense, and Receivables/Payables Data

Currency, precious metal, and stock symbols; purchase prices, quantities, purchase dates, storage locations; estimated values of physical assets such as real estate and vehicles; expense records (merchant, amount, category, date); and receivables and payables records (counterparty name, amount, due date, payment status) are processed.

2.4. Document Images

Images in JPEG format of grocery receipts, invoices, credit card statements, and other expense documents scanned using the device’s camera or a document scanner are collected and processed.

2.5. Speech-to-Text (STT) and AI Chat Data

The text versions of conversations conducted via the Riqi voice assistant (STT/speech-to-text) and the transcripts of chats you have with AI assistants (your questions, answers, and contextual information) are processed.

3. Data Collection Methods

  • In-App Input: Portfolio, asset, expense, receivables/payables, and profile information are entered directly by you through in-app forms.
  • Camera and Document Scanner: Document images are collected by scanning them with the device’s camera or the device’s built-in document scanner .
  • Backend API: Bootstrap telemetry, data synchronization, and AI processing requests are transmitted via secure API connections.
  • Google and Apple OAuth: When authentication is performed via Google Sign-In or Apple Sign-In, only the tokens necessary for authentication are obtained from the relevant provider.

4. Purposes and Legal Grounds for Data Processing

The collected data is processed for the following purposes based on the legal grounds specified in Articles 5 and 6 of the KVKK:

  • Service Provision: Providing consolidated financial visibility, portfolio profit/loss analysis, document OCR scanning, accounts receivable/payable tracking, and artificial intelligence assistant services.
  • Performance of the Contract: Account creation, merging of guest and registered data, and the execution of subscription services.
  • Legitimate Interest: System stability, error tracking, cybersecurity, and prevention of misuse (API activity and error logs).
  • Explicit Consent: AI processing, document analysis, and data transfer activities abroad.

4.1. Subscription Quotas

Usage quotas are as follows:

  • Free Plan: 500 entries per year (portfolio, expenses, receivables/payables, etc.) + 100 AI Credits (for artificial intelligence processing).
  • Pro Plan: Unlimited entries + 500 AI Credits per year.

Quota monitoring, prevention of misuse, and tracking of additional package purchases are handled through transaction counters .

5. AI Assistants

The Biriqim App offers the following AI-powered assistants. These assistants can process your portfolio, expense, and document data after you provide the relevant in-app consent:

  • Riqi: A voice and text-based financial assistant; processes speech-to-text (STT) and chat transcripts.
  • Savings Coach (Savings Coach): Analyzes your spending patterns to provide savings recommendations.
  • Portfolio Risk (Portfolio Risk): Evaluates your portfolio allocation and asset risks.
  • Cash Flow Forecast (Cash Flow Forecast): Generates cash flow projections based on your income and expense data.
  • Document Auditor (Document Auditor): Analyzes scanned receipts and invoices using OCR and extracts amount, date, and vendor information.

6. Third-Party AI and Data Transfer

Biriqim transfers data to the following third-party providers to deliver document analysis, OCR, AI chat, and financial summary generation services. The transfer occurs only after you provide your explicit consent within the app.

6.1. What Is Transferred (WHAT)

  • Scanned receipts, invoices, and expense report images (JPEG)
  • Portfolio, asset, expense, and receivables/payables summaries, as well as financial summary data
  • Transcripts of chats with AI assistants and speech-to-text (STT) transcriptions

6.2. Who Receives It (WHO)

  • Google Cloud Gemini / Document AI: Document OCR and AI analysis
  • OpenAI (gpt-4o-mini): AI chat and financial summary generation
  • Providers Configured via the Admin Panel: Additional AI/OCR integrations determined by the company based on capabilities and priority
  • Bunny.net CDN (Storage & Pull Zone): Secure storage and distribution of document images

6.3. When Data Is Transferred (WHEN)

Data transfer to third-party AI providers or cloud storage infrastructure is performed only after you provide in-app consent via the explicit consent screen presented to you within the App. Simply reading or accepting this Privacy Policy is not sufficient on its own for third-party data transfers. Separate in-app consent is obtained for each category of processing.

6.4. Commitment to Equivalent Protection

The Company ensures that, when sharing data with third-party artificial intelligence and cloud providers, these providers are required to meet data protection standards equivalent to those applied within the Company’s own systems, and that contractual safeguards (data processing agreements, confidentiality commitments) are established. Your personal data is used by third-party providers only in accordance with the specified processing purposes and limited to the scope of the transfer.

6.5. Data Transfer Abroad (Article 9 of the KVKK)

Data transfers to Google Cloud, OpenAI, and similar U.S.-based artificial intelligence providers constitute cross-border transfers of personal data under Article 9 of the KVKK. These transfers are carried out based on your explicit consent within the application, data processing agreements signed with the relevant providers, and the safeguards provided for in Article 9 of the KVKK (transfer to countries with adequate protection or a commitment letter).

7. Other Third-Party Integrations

7.1. Apple Sign-In

If you sign in using Apple Sign-In, the authentication token provided by Apple is processed. Apple’s privacy policy is subject to the terms set by Apple.

7.2. Firebase Cloud Messaging (FCM)

The Firebase FCM infrastructure is used for due date reminders, account notifications, and service announcements. To receive push notifications, the device notification token (FCM token) is processed.

7.3. Market Data Providers

Market data APIs such as Finnhub, EODHD, or Twelve Data are used to update stock, foreign exchange, and precious metal prices. Only symbol/code-level queries are sent to these integrations; your personal identification information is not transferred to these providers.

8. Data Retention Periods and Security

Portfolio, asset, expense, and receivable/payable records are stored in a PostgreSQL database as long as your account is active. API activity and error logs are retained for a maximum of 90 (ninety) days for cybersecurity purposes and are then automatically deleted. Document images are stored on the Bunny.net CDN infrastructure; only the CDN access URLs are stored in the database.

8.1. Security Measures

  • Scope Isolation: User data is subject to strict scope isolation at the database and API levels; a user’s data cannot be shared with another user or device ID.
  • Rate Limiting: A limit of 15 requests per second per IP address is enforced; suspicious activity is blocked for 24 hours.
  • Encryption: API keys and credentials are encrypted on the server side using cryptographic methods; they are not leaked to the mobile client in plain text.

9. Account Deletion (Soft-Delete)

You can delete your account through the app settings or by contacting destek@biriqim.com. The account deletion process is carried out using the soft-delete method: your account and associated personal data are made inaccessible within the mobile app and removed from active use. Certain data may be retained for a limited period to fulfill legal obligations, maintain legitimate cybersecurity logs (90-day period), and resolve disputes; at the end of this period, it is permanently deleted or anonymized. Your deletion request will be processed within 30 days at the latest.

10. User Rights (Article 11 of the KVKK)

Pursuant to Article 11 of the KVKK, you have the following rights:

  • To learn whether your personal data has been processed
  • If processed, to request information regarding such processing
  • To learn the purpose of the processing and whether it is being used in accordance with that purpose
  • To know the third parties to whom your data has been transferred, whether within the country or abroad
  • To request the correction of your personal data if it has been processed incompletely or incorrectly
  • Requesting that it be deleted or destroyed in accordance with the conditions set forth in Article 7 of the KVKK
  • Request that the third parties to whom the data has been transferred be notified of the above requests for correction or erasure
  • Object to a decision made solely through analysis by automated systems that results in adverse consequences for you
  • Request compensation for damages if you have suffered harm due to unlawful processing

To exercise your rights, you may contact us at destek@biriqim.com or info@eqlem.com. Your requests will be resolved within 30 days at the latest.

11. Policy Changes

The Company reserves the right to unilaterally update this Privacy Policy at any time. Updates will be announced within the App or through support channels. In the event of significant changes, an in-app notification will be displayed. Your continued use of the App following an update constitutes your acceptance of the updated terms; however, separate in-app consent will continue to be obtained for new third-party data transfers.

12. Governing Law and Jurisdiction

Turkish law and the KVKK legislation shall govern the interpretation and application of this Privacy Agreement. The Istanbul Central (Çağlayan) Courts and Enforcement Offices shall have exclusive jurisdiction over any disputes that may arise.

For all questions regarding privacy and data protection, please contact us at destek@biriqim.com.

© 2026 EQLEM SOFTWARE AND INFORMATION TECHNOLOGIES INC.
Çamlık Mah. Mercimek Sk. No: 39/16 Ümraniye / Istanbul