English translation — for information purposes only. This document is an English translation of the Turkish original published at https://www.sunucucenter.com/terms/kvkk-aydinlatma-metni/. It is provided for convenience only and has no independent legal effect. In the event of any inconsistency, ambiguity or dispute regarding interpretation, the Turkish text shall prevail. The contractual relationship is governed by Turkish law.
Last updated: 10 August 2026
This Privacy Notice has been prepared by Pixoof Teknoloji Anonim Şirketi (hereinafter referred to as the “Company” or “Pixoof Teknoloji A.Ş.”), acting in the capacity of data controller, pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (“KVKK” or the “Law”) and the provisions of the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform.
SunucuCenter is a trademark and service name belonging to Pixoof Teknoloji A.Ş. The corporate website at https://www.sunucucenter.com and the client portal at https://portal.sunucucenter.com (ordering, payment, service management and support) are operated under this brand.
1. IDENTITY OF THE DATA CONTROLLER AND GROUP STRUCTURE
1.1. Türkiye operation — Pixoof Teknoloji A.Ş.
The data controller within the scope of the Law:
- Trade name: Pixoof Teknoloji Anonim Şirketi
- Brand / Website: SunucuCenter — https://www.sunucucenter.com
- Client portal: https://portal.sunucucenter.com
- Registered head office address: Beylikdüzü OSB Mahallesi, Birlik Sanayi Sitesi, 3. Cadde No: 5 Daire: 130, Beylikdüzü / İstanbul
- Office (correspondence) address: Yeşilköy Mahallesi, Atatürk Caddesi No: 12, EGS Business Park B3 Blok Daire: 268, Bakırköy / İstanbul
- MERSİS number: 0730088135100001
- Trade registry number: 1079045
- Tax office / tax identification number: Beylikdüzü Vergi Dairesi / 7300881351
- Registered electronic mail (KEP) address: pixoof@hs03.kep.tr
- Corporate telephone (company particulars / service of notice): 0212 963 05 05
- Customer support line: +90 850 270 0511
- E-mail: support@sunucucenter.com
- Application channels concerning the protection of personal data: pixoof@hs03.kep.tr (KEP) and support@sunucucenter.com
Pixoof Teknoloji A.Ş., based in İstanbul, provides Linux web hosting, virtual server (VPS), VDS, leased physical server (dedicated), co-location and domain name registration services.
1.2. United States operation — White Label Services, LLC
- Trade name: White Label Services, LLC
- Type: Limited Liability Company — Domestic
- State of formation: Wyoming, United States of America
- Filing ID: 2025-001629094
- Principal office address: 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801, USA
1.3. Which service is provided under which legal entity?
The group structure and the allocation of data controllership are as follows:
- All services provided from the İstanbul — Equinix data center (web hosting, VPS, VDS, dedicated server, co-location and domain name registration), together with all contractual relationships with customers resident in Türkiye, are conducted by Pixoof Teknoloji A.Ş. The co-location service is provided solely at the İstanbul Equinix location. In respect of these services, the data controller is Pixoof Teknoloji A.Ş.
- Server services provided from the New York location (hosting/server services targeting the United States and Europe) are supplied over infrastructure operated by White Label Services, LLC.
The capacity of White Label Services, LLC under the Law varies according to the party to the contractual relationship established with the data subject:
- As data processor: Where the contract has been established with Pixoof Teknoloji A.Ş. but the service is provided from the New York location, White Label Services, LLC bears the capacity of data processor (KVKK Art. 3/1-ğ) only to the extent that it operates the infrastructure in accordance with the instructions of Pixoof Teknoloji A.Ş. and on its behalf. This relationship shall be governed by a written data processing agreement; pursuant to KVKK Art. 12/2, the data controller is jointly liable together with the data processor as regards the taking of measures relating to data security.
- As a separate (independent) data controller: Where the customer enters into a contract directly with White Label Services, LLC (e.g. customers resident in the United States or in the EU), since White Label Services, LLC determines the purposes and means of processing, that company holds the position of a separate data controller.
Important: Irrespective of whether White Label Services, LLC acts in the capacity of data processor or of a separate data controller, any and all data transfers made from Pixoof Teknoloji A.Ş. to that company constitute a transfer abroad within the meaning of KVKK Art. 9; for Art. 9 of the Law has made transfers abroad subject to the same regime in respect of both data controllers and data processors. Such transfers are subject to the regime explained in Section 6 of this text.
1.4. Other capacities
Pixoof Teknoloji A.Ş. holds the capacity of hosting provider pursuant to Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications. This capacity gives rise to the obligations to retain traffic information and to provide information to the competent authorities, as explained in Sections 3, 5 and 7 below. Pursuant to Art. 5/2 of Law No. 5651, the hosting provider is not obliged to monitor the content it hosts or to investigate whether unlawful activity is involved; however, where it is notified of unlawful content, it shall act in accordance with the procedure prescribed in the legislation (notice-and-takedown). In respect of the content hosted by customers, Pixoof Teknoloji A.Ş. is not a content provider; the content provider (the customer) is responsible for the lawfulness of the content.
2. CATEGORIES OF PERSONAL DATA PROCESSED
The following categories of personal data are processed within the scope of our services:
- Identity data: Name, surname; for corporate customers, the name, surname and title of the authorized person; to the extent necessary for the issuance of invoices, the Turkish Republic identity number (T.C. kimlik numarası) or tax identification number; date of birth (in cases where age/legal capacity verification is required).
- Contact data: E-mail address, mobile/landline telephone number, invoice and notification address, country/city information.
- Customer transaction data: Order and service records, service type (hosting, VPS, VDS, dedicated, co-location, domain name), package and resource information, domain name registration/transfer/renewal records, contract commencement and renewal dates, invoice and payment history, self-service operations carried out via the panel (restart, ISO installation, console access, viewing of resource graphs), support request history.
- Financial data: Invoice information, payment amount and currency (TRY/USD), payment method, transaction reference number, refund and balance records.
- Transaction security data: IP address, traffic information (connection time, duration, port and similar records), server and application access/error logs, login and logout records, session cookie and token information, browser and device information (user-agent), password hash values, abuse/attack detection records.
- Marketing data: Consent and refusal records for commercial electronic messages (including İYS records), newsletter subscription preferences, usage and preference data obtained by means of non-mandatory cookies.
- Legal proceedings data: Notice-and-takedown (Law No. 5651 and Law No. 5846) and DMCA notification/counter-notification records, correspondence relating to letters and writs received from competent public institutions and organizations, formal warning notices, litigation and enforcement file information, consumer arbitration committee applications.
- Request/complaint management data: Support tickets, live chat correspondence, the content of requests, suggestions and complaints submitted by telephone and e-mail, together with the responses given thereto.
Special categories of personal data: The processing of the special categories of personal data enumerated in Art. 6 of the Law is not required for the provision of our services, and such data should not be transmitted to us. Special category data transmitted unintentionally by means of support requests or documents shall be deleted immediately upon detection.
Content hosted by the customer: In respect of the databases, e-mails, files and end-user data that our customers keep on their own servers or hosting spaces, the data controller is the customer itself; Pixoof Teknoloji A.Ş. holds the position of data processor within the meaning of KVKK Art. 3/1-ğ in respect of such data, and accesses the content in question only to the extent necessary for the performance of the service, the provision of security or the fulfilment of an obligation arising from the legislation, and in accordance with the customer’s instructions. In respect of this relationship, written data processing provisions shall apply between the customer and us.
3. PURPOSES AND LEGAL GROUNDS OF THE PROCESSING OF PERSONAL DATA
Your personal data is processed on the basis of the legal grounds set out separately for each purpose in the table below.
| Purpose | Categories of data processed | Legal ground (KVKK) | Method of collection |
|---|---|---|---|
| Creation of the portal membership, management of the account and identity verification | Identity, Contact, Transaction security | Art. 5/2-c — Being directly related to the establishment or performance of a contract | Registration form on portal.sunucucenter.com (WISECP infrastructure) |
| Receipt of the service order, resource allocation, setup and provision of the service (hosting, VPS, VDS, dedicated, co-location) | Identity, Contact, Customer transaction, Transaction security | Art. 5/2-c — Establishment or performance of a contract | Portal order steps, web form, support ticket |
| Domain name registration, transfer and renewal; recording before the registration organization (registrar/registry) and WHOIS/RDAP notification | Identity, Contact, Customer transaction | Art. 5/2-c — Performance of the contract; Art. 5/2-ç — Legal obligation arising from registration regulations | Portal order form |
| Pricing, display of the renewal fee prior to payment and daily synchronization of domain name price tables with the portal | Customer transaction | Art. 5/2-c — Performance of the contract; Art. 5/2-ç — Preliminary information obligation under Law No. 6502 and the Regulation on Distance Contracts | Portal order flow, system records |
| Invoicing, collection, refunds and keeping of accounting records | Identity, Contact, Financial, Customer transaction | Art. 5/2-ç — Legal obligation arising from the Tax Procedure Law (VUK) and the Turkish Commercial Code (TTK); Art. 5/2-c — Performance of the contract | Portal payment step, transaction records returned from the payment institution, accounting system |
| Provision of 24/7/365 support tickets, e-mail, pre-sales live chat and telephone support during working hours | Identity, Contact, Customer transaction, Request/complaint | Art. 5/2-c — Performance of the contract; Art. 5/2-f — Legitimate interest in measuring and improving the quality of support | Panel support ticket, tawk.to live chat, telephone, e-mail |
| Ensuring server, network and application security; prevention of unauthorized access, DDoS and abuse; keeping of logs | Transaction security | Art. 5/2-ç — Data security obligation arising from KVKK Art. 12; Art. 5/2-f — Legitimate interest in the integrity and continuity of the infrastructure | Server and application logs, firewall records, Cloudflare (CDN/DNS), LiteSpeed cache records |
| Retention of traffic information in the capacity of hosting provider, and protection of its accuracy, integrity and confidentiality | Transaction security, Identity | Art. 5/2-a — Expressly provided for in laws (Art. 5 of Law No. 5651); Art. 5/2-ç — Legal obligation | System and server logs |
| Evaluation and finalization of notifications within the scope of the notice-and-takedown procedure and of DMCA (17 U.S.C. §512) notifications/counter-notifications | Identity, Contact, Legal proceedings, Customer transaction | Art. 5/2-ç — Obligation arising from Laws No. 5651 and No. 5846; Art. 5/2-e — Establishment, exercise or protection of a right | E-mail, notification form, letters from competent authorities |
| Monitoring of the 99.98% availability commitment, keeping of outage records and application of the 5% credit compensation in the event that the commitment is not met | Customer transaction, Transaction security | Art. 5/2-c — Performance of the contract | Monitoring systems, support requests |
| Sending of transactional notifications concerning the service term, renewal, maintenance, planned outages and security warnings | Identity, Contact, Customer transaction | Art. 5/2-c — Performance of the contract (such notifications do not constitute commercial electronic messages within the meaning of Law No. 6563) | Portal records, e-mail delivery infrastructure |
| Sending of commercial electronic messages such as campaigns, discounts, new service announcements and newsletters | Identity, Contact, Marketing | Art. 5/1 — Explicit consent; additionally, the consent obtained via İYS pursuant to Law No. 6563 and the Regulation on Commercial Communication and Commercial Electronic Messages | Separate consent checkbox during ordering/registration, newsletter form, İYS |
| Measurement of site usage and remembering of preferences by means of non-mandatory cookies | Transaction security, Marketing | Art. 5/1 — Explicit consent (in respect of mandatory/technical cookies necessary for the provision of the service, Art. 5/2-c or Art. 5/2-f) | Cookie management tool, browser |
| Detection of fraud, spam, phishing, unauthorized crypto mining and similar abuse, together with order risk assessment | Identity, Customer transaction, Transaction security | Art. 5/2-f — Legitimate interest in the protection of the network and of other customers; Art. 5/2-e — Protection of a right | Order records, system logs, abuse notifications |
| Management of requests and complaints, conduct of consumer arbitration committee and court proceedings, exercise of the right of legal defense | Identity, Contact, Customer transaction, Legal proceedings, Request/complaint | Art. 5/2-e — Establishment, exercise or protection of a right; Art. 5/2-ç — Legal obligation | Applications and notifications served, support records, case files |
| Fulfilment of the requests of competent public institutions and organizations (the Information and Communication Technologies Authority (BTK), courts, public prosecutors’ offices, law enforcement, the tax administration, etc.) | All relevant categories, limited to the scope of the request | Art. 5/2-a — Expressly provided for in laws; Art. 5/2-ç — Legal obligation | System records, customer records |
| Evaluation and finalization of applications within the scope of KVKK Art. 11 | Identity, Contact, Legal proceedings | Art. 5/2-ç — Legal obligation arising from KVKK Art. 13 | Application form, KEP, e-mail bearing a secure electronic signature, written application |
| Internal audit, financial audit, reporting and business continuity planning | Customer transaction, Financial, Transaction security | Art. 5/2-ç — Legal obligation; Art. 5/2-f — Legitimate interest in corporate governance and audit | System and accounting records |
| Backup, disaster recovery and preservation of the integrity of data | Customer transaction, Transaction security | Art. 5/2-c — Performance of the contract; Art. 5/2-ç — Security obligation within the scope of KVKK Art. 12 | Automatic backup systems |
Processing based on explicit consent: In respect of the processing activities for which the legal ground is shown in the table as “explicit consent”, you may withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of the processing carried out up to the moment of withdrawal and shall not constitute an impediment to the provision of the service.
Capacity of the recipient in commercial electronic messages: Pursuant to Art. 6 of Law No. 6563, where the recipient is a merchant or a tradesperson, obtaining prior consent for the sending of commercial electronic messages is not mandatory; even in such case, the recipient’s right of refusal and the obligation of registration with İYS are reserved. Where the recipient is a natural person, the conditions set out in the KVKK shall additionally be sought in respect of the processing of personal data.
4. METHOD OF COLLECTION OF PERSONAL DATA
Your personal data is collected through the following channels by automated and partially automated means, and in certain cases (such as documents sent by post) by non-automated means:
- the contact and request forms on www.sunucucenter.com (Contact Form 7 infrastructure),
- the membership, order, payment and service management steps on the portal.sunucucenter.com client portal (WISECP infrastructure),
- the 24/7 support tickets opened via the panel and the files attached thereto,
- the pre-sales live chat conversations conducted over the tawk.to infrastructure,
- the telephone conversations conducted during business hours over the line numbered +90 850 270 0511,
- the e-mails sent to support@sunucucenter.com and to other corporate addresses,
- the logs automatically generated by server, network, application and security systems, together with traffic and session records,
- the cookies and similar tracking technologies used on the website and the portal (detailed information is set out in our Cookie Policy),
- the access records generated by CDN/cache layers such as Cloudflare and LiteSpeed,
- the transaction result and verification information returned from the payment institution,
- the letters received from authorized public institutions and organisations and the notifications of third parties (rights holders, persons submitting abuse reports).
5. DOMESTIC TRANSFER OF PERSONAL DATA
Pursuant to Article 8 of the Law and limited to the purposes stated above, your personal data may be transferred to the following recipient groups with the minimum data necessary:
| Recipient group | Purpose of transfer | Legal ground |
|---|---|---|
| Payment institutions / payment service providers | Receipt and verification of payment, conduct of refund and objection (chargeback) processes | Art. 5/2-c performance of the contract; Art. 5/2-ç legal obligation |
| Accounting and certified financial advisory service providers and independent audit service providers | Keeping of statutory books and records, declaration and audit processes | Art. 5/2-ç legal obligation |
| Legal advisors, attorneys, mediators, enforcement offices | Follow-up of legal disputes, collection of receivables, exercise of the right of defence | Art. 5/2-e establishment, exercise or protection of a right |
| Authorised public institutions and organisations (Information and Communication Technologies Authority (BTK), courts, Chief Public Prosecutors’ Offices, law enforcement, the tax administration, the Personal Data Protection Authority (KVKK Kurumu), the Ministry of Trade, consumer arbitration committees) | Fulfilment of requests for information and documents provided for in the laws, notifications within the scope of Law No. 5651 | Art. 5/2-a expressly provided for in the laws; Art. 5/2-ç legal obligation |
| Infrastructure and software suppliers resident in Türkiye (portal/WISECP, the data center operator, e-mail delivery providers, the Message Management System — İYS) | Technical provision of the service, delivery of notifications, keeping of consent records | Art. 5/2-c performance of the contract; Art. 5/2-f legitimate interest; Art. 5/1 explicit consent in respect of commercial messages |
| Domain name registration bodies and, in respect of the “.tr” extension, the competent authority and registry organisations (BTK/TRABİS) | Registration, transfer and renewal of the domain name | Art. 5/2-c performance of the contract; Art. 5/2-ç legal obligation |
Your personal data shall not be sold, rented out or transferred for marketing purposes to third parties other than the recipient groups stated in this text.
6. TRANSFER OF PERSONAL DATA ABROAD (KVKK Art. 9)
6.1. Applicable legal regime
The transfer of personal data abroad is subject to the regime of Article 9 of the KVKK as amended by Law No. 7499, which entered into force in 2024. This regime is three-tiered, provided that in every case one of the processing conditions set out in Article 5 or Article 6 of the Law is present:
- Adequacy decision (Art. 9/1): If an adequacy decision has been rendered by the Personal Data Protection Board in respect of the country, the sector within the country or the international organization to which the transfer will be made, the transfer may be carried out on the basis of that decision.
- Appropriate safeguards (Art. 9/2): In the absence of an adequacy decision, data controllers and data processors may carry out a transfer on the basis of one of the following appropriate safeguards, provided that the data subject also has the possibility of exercising his or her rights and of applying to effective legal remedies in the country to which the transfer will be made:
- a protocol which does not have the nature of an international agreement, concluded between public institutions and organisations or international organisations abroad and public institutions and organisations or professional organisations having the status of a public institution in Türkiye (with the permission of the Board),
- binding corporate rules for multinational groups of undertakings (with the approval of the Board),
- the standard contract announced by the Board,
- a written undertaking containing provisions that will provide adequate protection (with the permission of the Board).
Where reliance is placed on the standard contract, the contract shall be notified to the Personal Data Protection Authority (KVKK Kurumu) within five business days of its signature. Failure to fulfil this notification obligation is subject to the administrative fine sanction provided for in the Law.
- Incidental cases (Art. 9/6): In circumstances where neither an adequacy decision nor appropriate safeguards exist, a transfer may be carried out, provided that it is only incidental, where the data subject has given explicit consent to the transfer, where it is mandatory for the performance of the contract, where there is an overriding public interest, for the establishment/exercise/protection of a right, for the protection of vital interests in the event of factual impossibility, or where information is requested from registers open to the public. Incidental cases do not constitute a legal basis for regular and continuous transfers.
This regime applies irrespective of whether the party to which the transfer is made is a data controller or a data processor; a transfer made to a data processor abroad likewise constitutes a transfer abroad.
6.2. There is no adequacy decision in respect of the United States of America
As at the update date of this text, no adequacy decision whatsoever has been rendered by the Personal Data Protection Board in respect of the United States of America. For this reason, transfers to be made to the USA must be based on one of the appropriate safeguards listed in 6.1 above. Adequacy decisions rendered by the Board are announced on the Authority’s website, and this section is reviewed regularly against the current announced list.
6.3. The New York location and transfer to White Label Services, LLC
Should you choose the server services provided from the New York location, your account, order, billing and service management data, together with your transaction security data necessary for the operation of the service, shall be transferred to the USA infrastructure operated by White Label Services, LLC. Furthermore, the content you host at the New York location is in fact located in the USA.
The service data of customers who choose the İstanbul — Equinix location is located in Türkiye and is not transferred to the USA infrastructure for the purpose of providing these services. Since the co-location service is provided only at the İstanbul Equinix location, no data transfer to the USA is in question within the scope of this service.
The transfer in question is carried out by providing one of the appropriate safeguards set out in Article 9 of the Law and by completing the permission, approval and notification procedures provided for in the legislation in respect of that safeguard. The safeguard upon which the transfer is based shall be notified to you upon your request submitted through the channels indicated in Section 9.
In exceptional cases where none of the appropriate safeguards can be relied upon and the transfer is only incidental in nature, your explicit consent shall additionally be requested within the scope of Art. 9/6 and to the extent necessary; before such consent is obtained, you shall additionally be informed about the possible risks that your personal data may face in the country to which the transfer will be made.
6.4. Other transfers abroad made to infrastructure and service providers
| Recipient | Data transferred | Purpose | Country / safeguard relied upon |
|---|---|---|---|
| White Label Services, LLC | Identity, Contact, Customer transaction, Transaction security and hosted content | Operation and support of the server services provided from the New York location | USA — no adequacy decision; one of the appropriate safeguards within the scope of Article 9 of the Law, as explained in 6.3 |
| Cloudflare, Inc. (CDN / DNS / security layer) | IP address, request and access records, browser information, cookie identifiers | Acceleration of content, DNS resolution, DDoS and bot protection | USA and global edge servers — no adequacy decision; the transfer is carried out by providing one of the appropriate safeguards set out in Article 9 of the Law and by making the necessary notifications |
| tawk.to (live chat infrastructure) | Name, e-mail address, chat content, IP address, session information | Provision of pre-sales live chat support | Abroad — no adequacy decision; the transfer is carried out by providing one of the appropriate safeguards set out in Article 9 of the Law and by making the necessary notifications |
| Domain name registry and registrar organisations | Name, address, e-mail, telephone (WHOIS/RDAP records) | Registration of the domain name and the registration obligations arising from ICANN/registry rules | Varies according to the extension and the country in which the organization is located; transfers made to countries in respect of which there is no adequacy decision are carried out by providing one of the appropriate safeguards set out in Article 9 of the Law |
6.5. Data subjects resident in the USA and the European Union
In respect of data subjects resident in the European Union who establish a direct contractual relationship with White Label Services, LLC, the rights of access, rectification, erasure, restriction of processing, data portability and objection under the General Data Protection Regulation (GDPR); and in respect of data subjects resident in California, the rights under the CCPA/CPRA to know, to delete, to correct, to opt out of the sale/sharing of personal data, to request the limitation of the use of sensitive personal information and not to be subjected to discrimination on account of the exercise of these rights, are reserved. Such requests may likewise be submitted to support@sunucucenter.com. On the USA side, the DMCA (17 U.S.C. §512) notice and counter-notice procedure and the commercial e-mail rules under the CAN-SPAM Act additionally apply. DMCA notices and counter-notices are submitted to support@sunucucenter.com; notices are recorded and evaluated through this channel.
In disputes relating to the services provided by White Label Services, LLC, the law of the State of Wyoming shall apply and the competent courts shall be those located in the State of Wyoming. The mandatory rights of consumers resident in Türkiye arising from the legislation of their place of residence, and the remedies relating to those rights, are reserved.
7. RETENTION PERIODS FOR PERSONAL DATA
Your personal data are retained for the period necessary for the purpose for which they are processed and, in any event, taking into account the minimum periods stipulated in the relevant legislation and the applicable statutes of limitation.
| Data type / process | Retention period | Legal basis |
|---|---|---|
| Membership, contract and customer transaction records (identity, contact, customer transaction) | 10 years from the termination of the contractual relationship | Turkish Code of Obligations (TBK) Art. 146 general statute of limitations; KVKK Art. 5/2-e (establishment and protection of a right) |
| Invoice, payment, collection and accounting records (financial) | 5 years from the year following the relevant calendar year; 10 years in respect of commercial books and documents | Tax Procedure Law (VUK) Art. 253 (5 years); Turkish Commercial Code (TTK) Art. 82 (10 years) |
| Traffic information kept in the capacity of hosting provider | For the period determined in the secondary legislation, within the range stipulated by the Law (not less than one year and not more than two years) | Law No. 5651 Art. 5; Regulation on the Procedures and Principles Regarding the Regulation of Publications Made on the Internet |
| Server, application and security logs and session records falling outside the scope of Law No. 5651 | For the period necessary for the purpose of ensuring security; where the purpose ceases to exist, they are deleted in the periodic destruction cycle | KVKK Art. 12 (data security); KVKK Art. 5/2-f legitimate interest |
| Support ticket, e-mail and live chat records | 10 years from the creation of the record | TBK Art. 146; burden of proof under Law No. 6502 on Consumer Protection |
| Commercial electronic message consent records and records relating to the messages sent | Three years as from the date on which the validity of the consent ends in respect of consent records, and as from the date of the record in respect of other records | Law No. 6563; Regulation on Commercial Communication and Commercial Electronic Messages — provisions concerning the retention of records |
| Domain name registration, transfer and renewal records | 10 years from the expiry of the registration; where registry/registrar rules stipulate a longer period, that period | TBK Art. 146; regulations of the registration organization |
| Notice-and-takedown / DMCA notifications and records of legal proceedings | From the conclusion of the process, throughout the relevant civil and criminal statutes of limitation | Law No. 5651 and Law No. 5846; TBK Art. 146; statute of limitations provisions of the Turkish Penal Code (TCK) |
| Records relating to KVKK applications | From the conclusion of the application, throughout the statute of limitations applicable to the request that is the subject of the application | KVKK Art. 13; Communiqué on the Procedures and Principles of Application to the Data Controller |
| Data collected by means of cookies | For session cookies, for the duration of the session; for data stored on the browser, until the browser data are deleted; for other cookies, for the period announced in the Cookie Policy | KVKK Art. 5/1 explicit consent; Art. 5/2-c and Art. 5/2-f |
Where the retention period expires or the reasons requiring the processing cease to exist, your personal data shall, pursuant to KVKK Art. 7 and the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, be deleted, destroyed or anonymised ex officio or upon your request. Pursuant to the said Regulation, the periodic destruction period may not exceed six months.
8. RIGHTS OF THE DATA SUBJECT (KVKK Art. 11)
Pursuant to Article 11 of the Law, you may exercise the following rights by applying to Pixoof Teknoloji A.Ş. in its capacity as data controller:
- To learn whether your personal data are processed (Art. 11/1-a),
- To request information in this regard if your personal data have been processed (Art. 11/1-b),
- To learn the purpose of the processing of your personal data and whether they are used in accordance with such purpose (Art. 11/1-c),
- To know the third parties to whom your personal data are transferred domestically or abroad (Art. 11/1-ç),
- To request the rectification of your personal data in the event that they have been processed incompletely or inaccurately (Art. 11/1-d),
- To request the erasure or destruction of your personal data within the framework of the conditions stipulated in Article 7 of the Law (Art. 11/1-e),
- To request that the operations carried out pursuant to your rectification, erasure and destruction requests be notified to the third parties to whom your personal data have been transferred (Art. 11/1-f),
- To object to a result arising to your detriment by means of the analysis of your processed data exclusively through automated systems (Art. 11/1-g),
- To claim compensation for the damage in the event that you suffer damage due to the unlawful processing of your personal data (Art. 11/1-ğ).
In addition to the foregoing, you have the right to withdraw your consent at any time in respect of processing activities based on explicit consent, and the right to refuse messages (right of refusal) in respect of commercial electronic messages pursuant to Law No. 6563. You may exercise your right of refusal through İYS or by the easy and free-of-charge method indicated in the message.
9. APPLICATION PROCEDURE
9.1. Form of the application
Pursuant to the Communiqué on the Procedures and Principles of Application to the Data Controller, you may submit your requests within the scope of KVKK Art. 11 in Turkish and by one of the following methods:
- In writing: by sending your wet-signed petition in person, through a notary public or by registered mail with return receipt to the address Yeşilköy Mahallesi, Atatürk Caddesi No: 12, EGS Business Park B3 Blok Daire: 268, Bakırköy / İstanbul. Writing the phrase “Information Request within the Scope of the Personal Data Protection Law” on the envelope or on the petition expedites the processing of the request.
- By registered electronic mail (KEP): by sending from your own KEP address to pixoof@hs03.kep.tr.
- By secure electronic signature or mobile signature: by sending your signed application to support@sunucucenter.com.
- By the e-mail address registered in the system: by sending to support@sunucucenter.com using the e-mail address that you have previously notified to us and that is registered in your portal account.
Where the application is made on behalf of third parties, a power of attorney demonstrating that the applicant has been specifically authorized in this respect, or a similar document, must be attached to the application.
9.2. Information that must be included in the application
Pursuant to Article 5 of the Communiqué, your application must contain the following information:
- Name, surname and, if the application is in writing, signature,
- Turkish Republic identity number for citizens of the Republic of Türkiye; nationality, passport number or, if any, identity number for foreigners,
- Residential or business address serving as the basis for notification,
- If any, electronic mail address, telephone and fax number serving as the basis for communication,
- Subject matter of the request.
Attaching the information and documents relating to the request to the application expedites the process. In the event that your identity cannot be verified, additional information may be requested from you for the purpose of ensuring data security.
9.3. Response to the application and fee
Your application shall be concluded free of charge as soon as possible depending on the nature of the request and, in any event, within thirty (30) days at the latest from the date on which the application reaches us. Where the operation additionally entails a cost, the fee in the tariff determined by the Board may be charged. The response shall be communicated to you in writing or in electronic form, according to the preference stated in your application.
Your request may be accepted or may be rejected with the reasons explained. In the exceptional cases enumerated in Article 28 of the Law (for example, where the processing of personal data is necessary for the prevention of the commission of an offence or for a criminal investigation, where the data have been made public by the data subject himself/herself, where the processing is necessary for inspection, regulation, disciplinary investigation or prosecution to be carried out by duly assigned and authorized public institutions and organisations based on the authority conferred by law, or where it is necessary for the protection of the economic and financial interests of the State), Article 11 of the Law — with the exception of the right to claim compensation for the damage — shall not apply.
9.4. Complaint to the Board
In the event that your application is rejected, that the response given is found insufficient or that no response is given within the time limit; you may file a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within thirty (30) days from the date on which you become aware of the response and, in any event, within sixty (60) days from the date of the application (KVKK Art. 14). Recourse to a complaint before the Board may not be had without exhausting the remedy of application to the data controller. The right of persons whose personality rights have been violated to claim compensation under the general provisions is reserved.
10. MEASURES REGARDING DATA SECURITY
Pursuant to Article 12 of the KVKK, in order to prevent the unlawful processing of personal data and unlawful access to such data, and to ensure the preservation of the data, the measures set out below are implemented, taking into account technological possibilities and the cost of implementation.
10.1. Technical measures
- TLS/HTTPS encryption on the corporate website and the client portal; storage of portal passwords by means of one-way hashing algorithms,
- Session management and session termination controls,
- DDoS and bot protection components at the firewall and at the CDN/DNS layer (Cloudflare),
- Access based on an authorization matrix and restricted in accordance with the “need to know” and “least privilege” principles; logging of administrative access,
- Keeping logs at the server, application and network layers, preserving the integrity of the logs and reviewing them regularly,
- Regular application of security patches and version updates, vulnerability monitoring,
- Regular backups and keeping the backups under access control,
- Physical security controls at the Equinix data center in İstanbul, together with network-level redundancy over a redundant backbone fed by multiple carriers,
- Support of data integrity through the use of NVMe SSD on all server lines and ECC memory for critical workloads,
- Secure erasure and destruction practices in the course of the decommissioning of hardware.
10.2. Administrative measures
- Establishing and keeping up to date a personal data processing inventory together with a retention and destruction policy,
- Confidentiality undertakings and KVKK awareness training for employees and support teams,
- Concluding written data processing agreements with suppliers and data processors and contractually binding the security obligations falling within the scope of Article 12 of the KVKK,
- Periodic review of authorizations and access rights; immediate removal of access rights in the event of termination of employment,
- Data breach response procedure: pursuant to Article 12/5 of the KVKK and the Board’s decision on data breach notification, notification to the Personal Data Protection Board within the shortest time and in any event within 72 hours as from becoming aware of the breach, and to the data subjects within the shortest reasonable time,
- A traceable application management process in which requests and complaints are recorded,
- Observance of the principles of data protection by design (privacy by design) and data minimization in new services and processes.
11. GENERAL PRINCIPLES OBSERVED IN THE PROCESSING OF PERSONAL DATA
Your personal data are processed, pursuant to Article 4 of the KVKK, in accordance with the principles of being processed lawfully and in compliance with the rules of good faith; being accurate and, where necessary, kept up to date; being processed for specified, explicit and legitimate purposes; being relevant to, limited to and proportionate with the purposes for which they are processed; and being retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed.
12. AMENDMENTS AND ENTRY INTO FORCE
12.1. This Privacy Notice may be updated by Pixoof Teknoloji A.Ş. in line with amendments to the legislation, decisions of the Personal Data Protection Board, and changes occurring in our services or business processes.
12.2. The current text is published at https://www.sunucucenter.com and enters into force on the date on which it is published. The “Last updated” date appearing at the beginning of the text indicates the date of the version in force.
12.3. In the event of material amendments, separate information shall be provided through the e-mail address registered in your portal account or by way of an in-portal notification. In the event that a new processing activity based on explicit consent is envisaged, your consent shall be separately requested for such activity.
12.4. In the event of any conflict concerning the protection of personal data between this Privacy Notice and the Terms of Use, the Distance Service Agreement, the Cookie Policy and the Acceptable Use Policy, this text shall prevail.
12.5. In disputes qualifying as consumer transactions, application may be made to the Consumer Arbitration Committees within the monetary limits determined for the relevant year, and to the Consumer Courts in disputes exceeding such limits. Pursuant to Law No. 6502 on Consumer Protection, the provisions on mediation as a procedural prerequisite (condition of action) in lawsuits to be filed before the consumer courts are reserved. With respect to requests relating to the protection of personal data, the application and complaint procedure set out in Section 9 shall apply.
Data Controller: Pixoof Teknoloji Anonim Şirketi (SunucuCenter)
Registered head office: Beylikdüzü OSB Mahallesi, Birlik Sanayi Sitesi, 3. Cadde No: 5 Daire: 130, Beylikdüzü / İstanbul — Corporate telephone: 0212 963 05 05 — KEP (Registered Electronic Mail): pixoof@hs03.kep.tr
Office (correspondence and application) address: Yeşilköy Mahallesi, Atatürk Caddesi No: 12, EGS Business Park B3 Blok Daire: 268, Bakırköy / İstanbul
Customer support line: +90 850 270 0511 — E-mail: support@sunucucenter.com