WHAT THIS POLICY COVERS
This Privacy Policy explains how the Microsoft Word add-in known as JUS. for Word (the "App") and the associated JUS. cloud service required for the App to operate (the "Service") process personal data.
This Policy is specific to the App and the Service; separate policies may apply to JUS.'s website, marketing activities and other products. It is addressed to everyone who uses the App, including the lawyers, compliance professionals and other authorised users covered by an enterprise licence.
This Policy has been prepared to discharge the transparency obligation under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and, to the extent applicable, to provide the information required under the EU General Data Protection Regulation ("GDPR"). The contractual terms governing use of the App are set out in the End User License Agreement (EULA); in the event of conflict, this Policy prevails in respect of personal data.
1. DESCRIPTION OF THE SERVICE
JUS. for Word is an add-in that runs inside Microsoft Word. The App analyses the Word document the user is working on, summarises it, generates draft text and clause suggestions, performs formatting and consistency checks, and assesses the document against data protection and compliance requirements.
In order to perform these functions, the App transmits document content to the JUS. cloud service. Processing takes place on JUS.'s infrastructure and — depending on the configuration chosen by the user's organisation — through large language model providers. The result is presented to the user within the Word interface.
The App forms part of JUS.'s privacy and compliance management platform and is offered under an enterprise licence. Technical details of how the App operates and its system requirements are set out in the Support Document.
The App accesses the user's document content. The decision as to which documents may be processed with the App must therefore be made by the organisation the user works for. For documents covered by professional secrecy, follow your organisation's policy.
2. DATA CONTROLLER AND ROLES
2.1 The party that publishes the App and operates the Service is: JUS. — Veri Security Bilişim ve Danışmanlık Hizmetleri A.Ş., Ahmet Yesevi Mah. Kerem Sok. No:9/202 Pendik / İstanbul, Türkiye, Türkiye. E-mail: [email protected]. Telephone: +90 216 606 5877.
2.2 In respect of document content. Where the App is used under an enterprise licence, the organisation the user works for is the data controller (the "Customer Organisation") in respect of personal data contained in documents. JUS. acts as data processor in respect of that data and processes it only on the Customer Organisation's instructions. Requests concerning data contained in documents should therefore be directed to your own organisation in the first instance.
2.3 In respect of account and contact data. JUS. acts as data controller in respect of data processed to create user accounts and to manage licences, billing, support and security.
2.4 This allocation determines responsibility under the KVKK and the GDPR; in both cases JUS. complies with the security and confidentiality commitments described in this Policy.
3. PERSONAL DATA PROCESSED
The table below sets out the categories of data processed through the App and the Service, the purposes of processing and the legal bases relied upon.
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Identity and contact data | Name, business e-mail address, job title, employer organisation | Account creation, licence and seat management, support | Performance of a contract (KVKK Art. 5/2-c) — GDPR Art. 6(1)(b) |
| Account and session data | User identifier, session token, authentication records, IP address, device and Word version | Access security, prevention of unauthorised use, fault resolution | Legitimate interests and legal obligation (KVKK Art. 5/2-e, 5/2-f) |
| Document Data | Content of the Word documents processed, user prompts, generated output, file name and metadata | Performance of the App's functions | The legal basis determined by the Customer Organisation — JUS. acts as processor |
| Transaction logs | Request time, user identifier, model identifier, token counts, error codes | Security, abuse detection, capacity management | Legitimate interests and legal obligation |
| Support data | Support requests, screenshots, correspondence | Resolution of support requests | Performance of a contract and legitimate interests |
| Billing and payment data | Organisation name, tax details, invoice records | Invoicing and compliance with financial legislation | Legal obligation (KVKK Art. 5/2-a, 5/2-ç) |
3.1 The App does not request or process location data, personal contact lists, calendars, camera or microphone access.
3.2 The App collects no data for advertising purposes and JUS. never sells, rents or shares personal data with advertising networks.
4. PROCESSING OF DOCUMENT CONTENT
4.1 How it is transmitted. When the user runs a function in the App, the relevant document content or the selected passage is transmitted to the JUS. cloud service over a connection encrypted with TLS 1.2 or above. Transmission begins with an explicit action by the user; the App does not scan documents in the background.
4.2 Where it is stored. Document Data is hosted in the region specified in the Customer Organisation's licence configuration and is stored in association with that organisation's account. Storage serves to maintain processing history, to allow drafts to be reopened, and to retain compliance records.
4.3 Who can access it. Access to Document Data is limited to the organisation's own authorised users. JUS. personnel may access content only in order to resolve a support request raised by the organisation or to investigate a specific security incident, limited to those who need to know, and through logged and auditable access. Such access is exceptional and is not a routine practice.
4.4 Deletion. The Customer Organisation may delete Document Data through the administration console. Deletion requests are fulfilled within thirty (30) days at the latest; copies held in backups are deleted upon completion of the backup cycle. On expiry of the licence, data is permanently deleted within ninety (90) days at the latest, following a thirty (30) day export window.
4.5 Operations that stay on the device. Certain formatting and checking functions run entirely on the user's device and content is not transmitted to the cloud for those functions. The Support Document lists which functions run locally.
5. PROCESSING BY ARTIFICIAL INTELLIGENCE
5.1 The App's analysis, summarisation and text generation functions operate by means of large language models (LLMs). The Customer Organisation may configure which model providers are enabled; some or all of the providers listed below may be disabled.
| Model provider | Role | Data processed | Location |
|---|---|---|---|
| Microsoft (Azure OpenAI Service) | Model inference and cloud hosting | Prompts, relevant document extracts, output | European Union [Azure] or Türkiye region |
| OpenAI | Model inference | Prompts, relevant document extracts, output | European Union |
| Anthropic | Model inference | Prompts, relevant document extracts, output | European Union |
| JUS. local language model | Model inference on infrastructure under JUS.'s own control | Prompts, document content, output | European Union [Azure] or Türkiye region |
5.2 No model training. JUS. does not use Document Data, user prompts or generated output to train, fine-tune or distil general-purpose artificial intelligence models. In its agreements with model providers, JUS. secures the exclusion of data from model training together with zero or minimal data retention terms.
5.3 Local-model-only option. For categories of documents covered by professional secrecy or containing special categories of data, the Customer Organisation may require that processing be carried out solely on JUS.'s own local language model, with no transfer whatsoever to third-party model providers.
5.4 Nature of the output. AI output is generated by probabilistic methods, may be incorrect or incomplete, and does not constitute legal advice. It must be verified by a competent person before use. Further detail is set out in Clause 11 of the End User License Agreement.
6. TELEMETRY, ANALYTICS AND TRACKING
6.1 No third-party analytics. The App contains no third-party analytics or tracking tools whatsoever — no Google Analytics, Mixpanel, Hotjar, advertising pixel or equivalent. No measurement is carried out within the App for the purpose of profiling user behaviour.
6.2 No cross-site tracking. The App does not track users across sites or applications and creates or shares no identifier for that purpose.
6.3 Operational logs. Technical logs are maintained on the server side so that the Service can operate securely: request time, user identifier, source IP address, operation type, model identifier, token counts and error codes. Their purpose is security, abuse detection, fault diagnosis and capacity management; they are not used for marketing or profiling. Logs are retained with restricted access for 12 months and then deleted.
6.4 Local storage. The App stores technically necessary data on the device so that the session can be maintained and user preferences (language, panel layout) remembered. This data is not in the nature of a marketing cookie and is not shared with third parties. It is deleted when the App is removed.
7. DISCLOSURES AND SUB-PROCESSORS
7.1 Personal data is disclosed only to the extent necessary to provide the Service and only to the following parties:
- Cloud infrastructure and model providers — the parties listed in Clause 5;
- Payment and billing provider — PayTR or Stripe;
- Microsoft — in respect of licence and billing data where the App is acquired through the Microsoft Marketplace;
- Competent public authorities — where there is an obligation under Applicable Law or a duly made request, and limited to the scope of that request. 7.2 JUS. binds its sub-processors by contract to security and confidentiality obligations equivalent to its own commitments and remains responsible for their acts. Changes to the list of sub-processors are notified to the Customer Organisation at least thirty (30) days in advance.
7.3 Personal data is not sold. JUS. does not sell, rent or trade personal data and does not transfer it to third parties for advertising or marketing purposes.
8. INTERNATIONAL TRANSFERS
8.1 Some of the providers referred to in Clauses 5 and 7 are located outside Türkiye. Personal data may therefore be transferred to the European Union and the United States.
8.2 For such transfers JUS. applies the appropriate mechanism provided for in Article 9 of the KVKK: an adequacy decision, a standard contract notified to the Personal Data Protection Board, binding corporate rules, or an exception provided for by law. For transfers within the scope of the GDPR, the European Commission's standard contractual clauses (SCCs) apply, together with a transfer impact assessment and supplementary technical measures where required.
8.3 For categories of documents in respect of which no transfer outside Türkiye may take place, the local-model- only option described in Clause 5.3 may be used.
9. RETENTION PERIODS
| Data | Retention period |
|---|---|
| Document Data and output | For the period configured by the Customer Organisation; and in any event no more than 90 days after expiry of the licence |
| Account and identity data | For as long as the account is active; 6 months after closure |
| Transaction logs | 12 months |
| Support correspondence | 24 months after closure of the request |
| Invoices and financial records | 10 years, in accordance with tax and commercial legislation |
| Security incident records | 5 years after closure of the incident |
9.1 At the end of the applicable period, data is deleted, destroyed or irreversibly anonymised. Retention obligations under Applicable Law are reserved; in such case data is held only to the extent required by that obligation and with restricted access.
10. DATA SECURITY
JUS. operates an information security management system aligned with the ISO/IEC 27001 framework and implements, as a minimum, the following measures:
- encryption of data in transit using TLS 1.2 or above;
- encryption of data at rest using AES-256 or an algorithm of equivalent strength;
- role-based access control, the principle of least privilege, and separate logging of privileged access;
- multi-factor authentication;
- logical separation of customer organisations' data;
- maintenance of audit logs protected against unauthorised alteration;
- separation of production and test environments, with no use of live document data in test environments;
- regular vulnerability scanning and independent penetration testing at least annually;
- confidentiality undertakings and regular awareness training for personnel;
- backup, business continuity and disaster recovery plans. 10.1 Breach notification. Upon identifying a security breach affecting personal data, JUS. shall notify the affected Customer Organisation without undue delay and in any event within seventy-two (72) hours, sharing the nature of the breach, the categories of data affected, its likely consequences and the measures taken. Reasonable assistance is provided to enable the Customer Organisation to discharge its notification obligations towards the Turkish Personal Data Protection Authority and affected individuals.
11. YOUR RIGHTS
11.1 Under Article 11 of the KVKK you have the right to: learn whether your personal data is being processed; request information if it has been processed; learn the purpose of processing and whether the data is used in accordance with that purpose; know the third parties in Türkiye or abroad to whom the data has been transferred; request correction of incomplete or inaccurate data; request erasure or destruction of the data in the circumstances provided for by law; request that correction and erasure be notified to third parties to whom the data has been transferred; object where an outcome adverse to you results from analysis carried out by automated systems; and claim compensation for loss suffered as a result of unlawful processing.
11.2 For processing within the scope of the GDPR you additionally have the rights of access, rectification, erasure, restriction of processing, data portability and objection.
11.3 How to make a request. Requests concerning personal data contained in documents should be addressed in the first instance to your own organisation, which is the controller of that data; JUS. supports your organisation in responding to such requests. For requests concerning your account and contact data, write to [email protected] with the subject "Data Protection Request", or make a written application to the registered office above.
11.4 Response time. Requests are answered free of charge within thirty (30) days of reaching JUS. at the latest. Where responding entails an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board may be charged.
11.5 Right to complain. If your request is refused, if you consider the response inadequate, or if no response is given within the applicable period, you may lodge a complaint with the Turkish Personal Data Protection Board. For processing within the scope of the GDPR, your right to lodge a complaint with the competent supervisory authority is reserved.
12. AUTOMATED DECISION-MAKING AND PROFILING
12.1 The App is not designed to take decisions concerning individuals based solely on automated processing that produce legal effects or otherwise significantly affect them, and JUS. does not use the App for that purpose.
12.2 The assessments and suggestions generated by the App are supporting outputs presented for human review. The final decision always rests with the user.
12.3 JUS. does not profile users for marketing or scoring purposes.
13. CHILDREN'S DATA
13.1 The App is an enterprise product designed for professional use and is not directed at persons under the age of 18. JUS. does not knowingly collect personal data from children.
13.2 Documents processed through the App may contain personal data relating to children. It is the responsibility of the Customer Organisation to establish a legal basis for processing such data and to apply any additional measures required.
14. THE ROLE OF THE MICROSOFT PLATFORM
14.1 The App runs on Microsoft Word and Microsoft 365. Data collected by Microsoft in connection with its own services (sign-in, tenant administration, Office telemetry) is governed by Microsoft's privacy statement and is outside JUS.'s control.
14.2 Where the App is acquired through the Microsoft Marketplace, purchase and billing are governed by Microsoft's terms.
14.3 JUS. is not responsible for Microsoft's data processing activities. For Microsoft's privacy practices, please consult Microsoft's own statements.
15. CHANGES TO THIS POLICY
15.1 JUS. may update this Policy in response to changes in Applicable Law, product developments or operational requirements. The current text is published at this address, with the version number and effective date updated accordingly.
15.2 Material changes — in particular the processing of a new category of data, the addition of a new sub- processor, or a change in the countries to which data is transferred — are notified to the Customer Organisation by e-mail or in-product notice at least thirty (30) days before they take effect.
15.3 Previous versions are available on request.
16. CONTACT
You may contact us with any question about this Policy or about the processing of your personal data:
| Subject | Contact |
|---|---|
| Data protection requests | [email protected] — subject: Data Protection |
| General support | [email protected] · +90 216 606 5877 |
| Security vulnerability reports | [email protected] — subject: Security Report |
| Postal address | Ahmet Yesevi Mah. Kerem Sok. No:9/202 Pendik / İstanbul, Türkiye |