Security and privacy

Technical boundaries for institutional trust.

EmlakIQ applies security design, retention policies and access controls to protect property and user data. It also states clearly what sits outside its role.

Trust model Sourced and traceable

Each output links back to a snapshot and source record.

Access Key and role based

Institutional usage can be segmented through separate permission layers.

Boundary Policy plus technical controls

Privacy and data-rights limits are enforced in the product surface too.

Control layers

The main security and privacy controls that protect the data pipeline.

Transport

Data transmission

All API communication is encrypted over TLS 1.2+. HTTPS is required on every access point, including the sandbox.

Lifecycle

Retention and deletion

Dossier and snapshot data are retained for defined periods. Deletion workflows apply on user request or at contract end.

Identity

Access control

API-key based authentication is used. Institutional integrations can be restricted with IP allowlisting and role-based authorization.

Rights

Data rights

Raw source data is never resold. EmlakIQ outputs are produced in a way that respects source-provider rights.

Traceability

Audit trail

Every Dossier is recorded with a snapshot ID and source reference. That model supports reproducible outputs.

Privacy

Privacy policy

Personal data is processed only for the stated purposes. KVKK compliance remains a core requirement.

Read the privacy policy

Contact

Write to us for a security disclosure or data-rights question.

Use the contact page for vulnerability reports, institutional data-rights questions or access-model clarifications.