DEEP FLOW SOFTWARE SERVICES – FZCO

Privacy Policy and Personal Data Text

"TypeAI"

09.03.2026

1.   Objective

Deep Flow Software Services – FZCO ("Company") aims to process the personal data of users in accordance with general principles of privacy and the provisions of the applicable data protection legislation to the relevant person, particularly Law on Personal Data Protection No. 6698, ("PDP Law") and other applicable legislation. Your personal data, which you provided/will provide to our Company and/or obtained by our Company by any external means, may be processed by our Company as "Data Controller";

This Privacy Policy is adopted for the continuance and improvement of the activities carried out by Company in line with the principles set forth in the PDP Law.

This Privacy Policy describes which data we collect, how we intend to use, store, protect and share the data we collect, how you can withdraw your consent for the processing of these data and how you can correct and revise the data.

Capitalized terms in this Policy shall have the meanings specified in the Terms and Conditions unless defined separately in this Policy.

2.   Collection of Personal Data and Method

Company may process your personal data for the purposes specified in this Privacy Policy.

The personal data of users collected and used by Company in particular, are as follows: your name and surname, e-mail address and phone number which we will receive once you contact Company, your order information if you make a purchase through in-app purchase, text which you have uploaded or transmitted to TypeAI application (TypeAI or TypeAI App) and identifier for advertisers designated in your mobile device used in accessing our services (The Identifier for Advertisers-IDFA), identifier for vendors/developers designated your mobile device (The Identifier for Vendors IDVF) and Internet Protocol Address-IP Address. We collect your username, password and e-mail address information only when you sign up to Keyboard and become a member through Registration.

Data Categories and Data Types

Identity Information Name and Surname
Contact Information Phone number, e-mail address
Process Security Internet traffic data (network movements, IP address, visit data, time and date information), device name, In-app purchase history, Token ID (when you allow notifications through your device), identifier for advertisers designated in your mobile device used in accessing our services (if you give a permission, the Identifier for Advertisers-IDFA), identifier for vendors/developers designated your mobile device (The Identifier for Vendors-IDVF)
User Content The texts, words, information, phrases, entries, material and any kind of data that you provide, upload, transmit, create, store, use, edit or share with or through TypeAI and/or with or through keyboard extension of TypeAI.
Customer Transaction Order Information
Marketing Data IDFA, IDVF

We may collect your abovementioned data directly from you through electronic or physical mediums, your mobile device, third party applications or third party sources which you can access our application through these mediums such as Apple App Store, Google Play App Store (similar platforms together with "App Stores"), for the purposes of compliance with legal obligations, enhancing our services, administering your use of our services, as well as enabling you to enjoy and easily navigate our services.

We may collect your log data generated while you are using our services/applications (through our products or third-party products). This log data may include information such as your device's Internet Protocol ("IP") address, device name, operating system version, the configuration of the app when utilizing our service/application, the time/date of your use of the service/application, and other statistics.

General Principles Regarding Personal Data Processing

In accordance with this Privacy Policy, personal data are processed by Company as a data controller in line with the basic principles named here: (i) being in accordance with law and good faith, (ii) being accurate and, where necessary, up-to-date, (iii) being processed for specific, explicit and legitimate purposes, (iv) being limited for the purpose for which they are processed and data minimization; and (v) being stored for the period stipulated in the relevant legislation or required for the purpose for which they are processed.

3.   Purposes of Processing Personal Data and Legal Reasons

Your personal data will be processed via automatic or non-automatic means for the purposes stated below, in accordance with the applicable legislation and articles 5 and 6 of the PDP Law where it is expressly permitted by the laws, the establishment of a contract or direct relation to the execution or performance of the contract and for the legitimate interests of Company provided that your fundamental rights and freedoms are protected.

a) Purposes of Processing Personal Data

In accordance with this text, your personal data is processed for the following purposes in accordance with the above general conditions:

Identity and Contact Information
  • execution of activities in compliance with legislation
  • execution of company/product/service commitment operations
  • execution of communication activities
  • execution/auditing of business activities
  • conducting after-sales support services for goods/services
  • execution of goods/services sales processes
  • conducting storage and archive activities
  • execution of agreement processes
Process Security
  • execution of information security processes
  • conducting audit/ethical activities
  • execution/audit of business activities
  • conducting activities to ensure business continuity
  • providing information to authorized persons, institutions and organizations
Customer Transaction
  • execution/auditing of business activities
  • conducting after-sales support services for goods/services
  • execution of goods/services sales processes
  • conducting activities for customer satisfaction
  • execution of agreement processes
User Content
  • operation of our product, e.g., to display writing suggestions
  • execution of activities in compliance with legislation
  • execution of agreement processes
  • conducting storage and archive activities
  • execution/auditing of business activities
  • conducting activities to ensure business continuity
  • execution of activities for customer satisfaction
Marketing Data
  • conducting marketing analysis studies
  • execution of advertising/campaign/promotion processes

Besides, the purposes of processing personal data may be updated in line with our obligations arising from our company policies and legislation; in particular,

b) Legal Reasons

Identity Information
Contact Information
Customer Transaction
  • It is necessary to process your personal data, provided that we establish a contractual relationship with you, or that it is directly related to our performance obligation arising from this contract
  • We have to process data in order to establish a right for you, to exercise and protect this right
User Content
  • It is necessary to process your personal data, provided that we establish a contractual relationship with you, or that it is directly related to our performance obligation arising from this contract
  • We have to process data in order to establish a right for you, to exercise and protect this right
  • Processing is necessary for our legitimate interests, provided that your fundamental rights and freedoms of are not harmed
Process Security
  • The law explicitly stipulates the process by which we process your personal data
  • Conditions that are necessary in order to fulfill our legal obligation
  • It is necessary to process your personal data, provided that we establish a contractual relationship with you, or that it is directly related to our performance obligation arising from this contract
Marketing Data
  • Your explicit consent (acquired via Apple and/or Google)

Third Party Websites and Applications

TypeAI; may contain links to other websites or apps that are unknown to Company and whose content is not controlled. These linked websites or apps may contain terms and conditions other than Company texts. Company cannot be held responsible for the use or disclosure of information that these websites or apps may process. Likewise, Company shall not have any responsibility for any links from other sites or apps provided to TypeAI owned by Company.

We collect information by fair and lawful means, with your knowledge and consent. We also let you know why we're collecting it and how it will be used. You are free to refuse our request for this information, with the understanding that we may be unable to provide you with some of your desired services without it.

While using the TypeAI App, you may provide information through third party websites and apps to Company, please be aware that your liability and obligations against third party apps or website will continue and Company shall not be held responsible any terms, conditions, rules or policies determined by third parties.

Cookies

Cookies are little text files that are stored on the browser or hard drive of your computer or mobile device when you visit a webpage or application. Cookies allow a website to run more efficiently in addition to ensuring the presentation of personalized web pages in order to make you live a faster visit experience which is more fit for your specific personal needs and demands. Containing only data on your website visit history via the internet, cookies do not collect any information, including your personal data/files stored on your computer or mobile device. We may use cookies when it is necessary for operating our services, to enhance our service performance and functionality, and to deliver content, including ads relevant to your interests, on our sites, or third-party sites. You can delete cookies which are already present on your computer and prevent the recording/location of cookies on your internet explorer.

Internet browsers are predefined to automatically accept the cookies as default. As the management of cookies varies from browser to browser, you may look at the help menu of the browser or application to get detailed information.

Push Notifications

Company may occasionally send you push notifications via its mobile applications regarding application upgrades or notifications about our services. You can always edit such communication and notifications through the settings on your device and stop receiving such communications and notifications.

Your data will be stored for the duration specified in the applicable legislation or for a reasonable time until the purpose of processing cease to exist, or during legal periods of limitation.

Company may continue to store your personal data, even after the expiry of the purpose of its use provided that it is required by other laws or a separate granted by you in this regard.

In cases that you allow Company to store your personal data for additional time by giving your consent, such data shall be immediately deleted, destructed or anonymized upon the expiry of such additional time or once the purpose of processing no longer exists.

Technical and Administrative Measures

Company stores the personal data it processes in accordance with relevant legislation for periods stipulated in relevant legislation or required for the purpose of processing. Company undertakes to take all necessary technical and administrative measures and to take the due care to ensure the confidentiality, integrity and security of personal data. In this context, it takes the necessary measures to prevent unlawful processing of personal data, unauthorized access to data, unlawful disclosure, modification or destruction of data. Accordingly, Company takes the following technical and administrative measures regarding the personal data it processes:

Anti-virus application. On all computers and servers in Company's information technology infrastructure, a periodically updated anti-virus application is installed.

Firewall. The data center and disaster recovery centers hosting Company servers are protected by periodically updated software-loaded firewalls; the relevant next generation firewalls control the internet connections of all staff and provide protection against viruses and similar threats during this control.

VPN. Suppliers can access Company servers or systems through SSL-VPN defined on Firewalls. A separate SSL-VPN identification has been made for each supplier; with the identification made, the supplier only provides access to the systems that it should use or is authorized to use.

User identifications. Company employees' authorization to Company systems is limited only to the extent necessary by job descriptions; in case of any change of authority or duty, systemic authorizations are also updated.

Information security threat and event management. Events that occur on Company servers and firewalls, are transferred to the "Information Security Threat and Event Management" system. This system alerts the responsible staff when a security threat occurs and allows them to respond immediately to the threat.

Encryption. Sensitive data is stored with cryptographic methods and if required, transferred through environments encrypted with cryptographic methods and cryptographic keys are stored in secure and various environments.

Logging. All transaction records regarding sensitive data are securely logged.

Two-factor authentication. Remote access to sensitive data is allowed through at least two-factor authentication.

Penetration test. Periodically, penetration tests are performed on servers in the Company system. The security gaps created as a result of this test are closed and a verification test is performed to show that the relevant security gaps have been closed. Besides, Information Security Threat and Event Management System automatically performs penetration tests. Test results are recorded.

Information Security Management System (ISMS). At the ISMS meetings made within Company, the topics contained in the control forum are audited monthly by the director of information technology and the director of financial operations.

Training. In order to increase the awareness of Company employees against various information security violations and to minimize the impact of the human factor in information violation incidents, trainings are provided to employees at regular intervals.

Physical data security. It ensures that personal data on papers is necessarily stored in lockers and accessed only by authorized persons. Adequate security measures (for situations such as electric leakage, fire, deluge, thievery etc.) are taken based on the nature of the environment where sensitive data is stored.

Backup. Company periodically backs up the data it stores. As a backup mechanism, it uses the backup facilities provided by the cloud infrastructure providers, as well as the backup solutions it develops when deemed necessary, provided that it is in compliance with relevant legislation and provisions of this Policy.

Non-disclosure agreement. Non-disclosure agreements are concluded with employees taking part in sensitive personal data processing.

Transfer of sensitive personal data. If transfer of sensitive personal data is required through email; such transfer is done through (i) encrypted corporate email or (ii) Registered E-mail.

In the event that the personal data is damaged as a result of attacks on TypeAI or on the Company system, despite Company taking the necessary information security measures, or the personal data is obtained by unauthorized third parties, Company notifies this situation to Users immediately and, if necessary, to relevant data protection authority and takes necessary measures.

4.   Transferring Personal Data to Third Parties

The procedures and principles to be applied for transferring of personal data are regulated in articles 8 and 9 of the PDP Law, and the personal and special categories of data of the supplier may be transferred to third parties within the country or abroad since we may use servers and cloud systems located abroad.

Your personal data may be transferred abroad for the following reasons:

Company may also transfer your personal data to services providers of our Company, third parties such as Facebook SDK, Adjust and Firebase Analytics which are embedded into our service for the following purposes:

Engagement with third-party AI models. Please note that we engage with third-party AI service providers ("Third-Party AI Service Providers"), which are essential for the duly operation of the Application by means of processing and creating AI-generated Output. If you voluntarily provide any User Content (Input), you explicitly consent to the transfer of such User Content (Input) to the specific Third-Party AI Service Providers, which operates the exact AI model that you currently view and utilize within our Application.

Transfer of data to Third-Party AI Service Providers is strictly and solely limited to the following:

Hereinafter, "Input (User Content)" and "Anonymized Message Identifier" shall be together referred to as "Shared Data".

Please note that this processing is required to enable the Application's core/primary function—creating an AI-generated response (Output) using the pre-selected model by the Application. If you do not want your Shared Data passed to Third-Party AI Service Providers, please refrain from entering any Input/User Content into the chat or from choosing any AI-powered feature that appears above the keyboard.

Moreover, please note that other than Shared Data, we do not share any further data with Third-Party AI Service Providers. Accordingly, we do not share any usage analytics, device information, personal information, or any other data with Third-Party AI Service Providers. Likewise, we do not share your contact details (such as name, email address, Apple ID, etc.), device identifiers, usage data, location data, payment information, or any other personal information with Third-Party AI Service Providers. As elaborated above, we only transmit Shared Data to Third-Party AI Service Providers, which is strictly and essentially required for the Application's core functionality. Only the specific text for which you voluntarily choose an AI-powered feature is shared with Third-Party AI Service Providers; the Application does not access or share other messages or content.

Shared Data sent to Third-Party AI Service Providers is solely used to generate a response (Outcome) to the text you submit in the chat or to any text for which you voluntarily choose an AI-powered feature in the keyboard (Input/User Content), and is subject to the relevant Third-Party AI Service Providers' own privacy policies.

Please refer to the table below, in which we share the details of Third-Party AI Service Providers, along with the relevant links to their privacy policies:

Third-Party AI Service Provider Services & Shared Data Privacy Policy
OpenAI, LLC. Services: Provision of AI-generated content

Shared Data: Input (User Content, Anonymized Message Identifier)
https://openai.com/privacy/
Anthropic PBC Services: Provision of AI-generated content

Shared Data: Input (User Content, Anonymized Message Identifier)
https://www.anthropic.com/legal/privacy

Each of the Third-Party AI Service Providers listed above is required to handle and process the data in compliance with the applicable data protection laws. Note that all Third-Party AI Service Providers listed in the table above provide at least the same or equal protection of user data with the protection mechanism explained in this Privacy Policy. Third-Party AI Service Providers process Shared Data solely for the purposes of creating Outputs (i.e. AI-generated content). Other than this purpose, Third-Party AI Service Providers are not authorized to use Shared Data for any other purposes.

Without your explicit consent and voluntary action, no data is transmitted. By submitting a prompt in the chat or using an AI-powered feature above the keyboard, you consent to that specific content being sent to the relevant third-party AI Service Provider.

You may revoke your consent at any time by ceasing to use the AI chat functionality or by refraining from choosing AI-powered features above the keyboard that would enable AI to process your Input. Once you stop submitting prompts or taking such actions, no additional data will be shared with any of the Third-Party AI Service Providers. If you choose not to provide consent, the AI chat or keyboard-based features will be unavailable, since the Application's core and main functionality is dependent on transmitting your prompts or selected actions to one of the Third-Party AI Service Providers in order to generate responses (Output).

5.   Your Rights as the Data Subject

Pursuant to Article 11 of the PDP Law, you may request the following regarding your personal data by applying to Company:

Where General Data Protection Regulation (GDPR) is applicable, data subjects have the following rights:

In the application that includes your explanations about the right you have as the data subject and exercise your rights stated above and that you request to exercise; your request must be explicit and understandable, if the subject of your request is related to you or if you are acting on behalf of someone else, you must be specially authorized in this regard and your authority must be documented, the application must contain identity and address information and documents proving your identity must be attached to the application. Our Company will enable you to file such requests through the "Data Subject Application Form" at typeai@codeway.co. In accordance with Article 13 of the PDP Law, our Company will finalize your requests, free of charge, within 30 (thirty) days at the latest depending on the nature of the request. In case the request is rejected, the reason or reasons for the rejection will be notified in writing or electronically along with its justification.

If you believe that we or someone with whom we have transferred your data is violating your rights, you can file a complaint to the data protection authority in your country and to other competent supervisory authorities.

This Privacy Policy may be revised by our Company when deemed necessary. If you continue to access TypeAI and use or access TypeAI without benefiting from the Services offered by Company after the notification period, you shall be deemed to have allowed the changes in this Privacy Policy.

Company Title: Deep Flow Software Services – FZCO

Address: IFZA Business Park, DDP, IFZA Property FZCO, Building A1 – 3641379065, 53751 – 001, Dubai, Digital Park, Dubai Silicon Oasis, UAE

E-mail: typeai@codeway.co

Tel: +971 4 354 0450