English translation — for information purposes only. This document is an English translation of the Turkish original published at https://www.sunucucenter.com/terms/gizlilik-ve-cerez-politikasi/. It is provided for convenience only and has no independent legal effect. In the event of any inconsistency, ambiguity or dispute regarding interpretation, the Turkish text shall prevail. The contractual relationship is governed by Turkish law.
Last updated: 10 August 2026
Effective date: 10 August 2026
This Privacy and Cookie Policy (“Policy”) has been prepared for the purpose of explaining by which technical and operational methods personal data and other information are collected, processed, stored and protected within the scope of the websites and hosting services offered under the SunucuCenter brand.
This Policy does not replace the Disclosure Statement prepared pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (“KVKK”); it complements it. For the purposes of processing personal data, the legal grounds, the grounds for transfer and the procedure for exercising the data subject rights under Article 11 of the KVKK, please review the KVKK Disclosure Statement published at https://www.sunucucenter.com. This Policy explains the operational and technical implementation of the legal framework set out in the said Disclosure Statement: which systems generate which data, how cookies work, in which cases data on customer servers is accessed, and how security measures are applied.
1. Scope
1.1. Platforms covered by the Policy
This Policy applies in respect of the following digital assets and service channels:
- https://www.sunucucenter.com – corporate presentation and service catalogue website (WordPress infrastructure, LiteSpeed web server and cache, Contact Form 7 contact form, tawk.to live chat component, delivery via Cloudflare).
- https://portal.sunucucenter.com – client portal, ordering, invoicing, service management and support ticket system (WISECP infrastructure).
- Correspondence conducted through the support ticket system, the support@sunucucenter.com e-mail channel, the telephone line numbered +90 850 270 0511 and the pre-sales live chat channel.
- All services ordered through the above channels: Linux web hosting, virtual server (VPS), VDS, leased dedicated server, co-location and domain name registration services.
1.2. Legal entities providing the service
SunucuCenter is a body of services operated by two separate legal entities under a single trademark. Pursuant to Law No. 6563 and the Regulation on Service Providers and Intermediary Service Providers in Electronic Commerce, the service provider identification information is set out below:
- Pixoof Teknoloji Anonim Şirketi (hereinafter referred to as the “Company” or “Pixoof Teknoloji A.Ş.”) – Türkiye operations.
- Registered head office address: Beylikdüzü OSB Mahallesi, Birlik Sanayi Sitesi, 3. Cadde No: 5 Daire: 130, Beylikdüzü / İstanbul
- Office (correspondence and service of notice) address: Yeşilköy Mahallesi, Atatürk Caddesi No: 12, B3 Blok Daire 268, EGS Business Park, Bakırköy / İstanbul
- MERSİS No: 0730088135100001
- Trade Registry No: 1079045
- Tax Office / Tax Identification No: Beylikdüzü Vergi Dairesi / 7300881351
- Corporate telephone: 0212 963 05 05
- Registered Electronic Mail (KEP) address: pixoof@hs03.kep.tr
- White Label Services, LLC – United States of America operations.
- Company type: Limited Liability Company – Domestic
- State of formation: Wyoming
- Filing ID: 2025-001629094
- Principal Office address: 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801, USA
1.3. Which service is provided under which legal entity?
- All services provided from the İstanbul – Equinix data center (web hosting, VPS, VDS, dedicated server and co-location, which is offered only at this location) are operated by Pixoof Teknoloji A.Ş. With respect to the personal data processed within the scope of these services, the data controller within the meaning of the KVKK is Pixoof Teknoloji A.Ş.
- The server services provided from the New York location (VPS/VDS/dedicated server services targeting the USA and Europe) are provided by White Label Services, LLC; the infrastructure operation, DMCA notices and the obligations arising from US legislation in respect of these services are fulfilled by this legal entity. In disputes relating to the services provided by White Label Services, LLC, the law of the State of Wyoming shall apply and the competent courts shall be those located in the State of Wyoming; the rights of consumers resident in Türkiye arising from mandatory legislation are reserved.
- The determining criterion is the location from which the service is provided. Where a customer resident in Türkiye receives service from the New York location, the contracting party and the legal entity issuing the invoice in respect of that service are likewise clearly shown at the ordering step. The customer’s pre-sales communication, support and collection processes are conducted on behalf of the legal entity to which the relevant service belongs.
- Which service is provided by which legal entity is clearly shown at the ordering step and on the invoice issued. In case of doubt, the corporate title stated on the invoice shall prevail.
Both companies may share data to the extent required by the services offered under the joint brand and limited to the purpose of conducting the customer relationship. Every transfer from Türkiye to the USA is subject to the regime under Article 9 of the KVKK explained in section 6 below.
1.4. Out of scope
- Our customers’ own websites and applications hosted on our infrastructure, and the personal data they collect through those sites, are not within the scope of this Policy. With respect to such content, the data controller is the relevant customer (see section 3).
- Third party links that may appear on our sites (external sites, social media accounts) are subject to the privacy policies of the relevant parties.
2. Information We Collect
2.1. Account and identity information
The following data are collected when an account is created through the portal and throughout the account lifecycle: first name and surname, for commercial customers the company title and authorized person information, e-mail address, telephone number, address, country/city information, username and the password irreversibly hashed. Passwords are not stored in plain text and cannot be viewed by us.
In cases where identity verification is required by legislation (e.g. issuance of an invoice, situations where account ownership is in dispute, domain name disputes), the Turkish Republic identity number (T.C. kimlik numarası), tax number or an image of an identity document may be requested. The Turkish Republic identity number and identity document images are processed solely for verification purposes, in an area with restricted access and for the period required by the purpose; it is recommended that the fields contained in such documents which are not necessary for the performance of the service (e.g. religion, blood group) be masked.
2.2. Order, invoice and payment information
The order content, the selected package and term, pricing (TRY or USD), renewal dates, invoice information, payment status and transaction reference numbers are processed on the portal. There is no hidden item in the pricing; the renewal price is shown at the ordering step, before payment. Prices are presented on the order screen with a clear indication of whether taxes are included.
Card details are not stored on our systems. Card data is processed directly at the authorized payment institution/payment service provider; only limited information such as the result of the transaction and the transaction reference, together with the masked form of the card number to the extent provided by the payment institution, is returned to us. At the ordering step, it is shown through which payment method and through which authorized payment institution the payment will be carried out.
2.3. Technical data and logs
- IP address, connection time and duration, port/protocol information used;
- User-agent (browser, operating system, device type), language and time zone information;
- Web server access and error logs (requested URL, HTTP status code, referring address, bytes transferred);
- Portal authentication logs (successful/failed login attempts, password reset requests and the operations performed through the panel: reboot, ISO installation, console access, service cancellation);
- Security layer records (bot management triggers, rate limiting, abuse detections);
- System logs generated in connection with hosting services (e.g. e-mail queue records, DNS query statistics).
Since we hold the status of hosting provider pursuant to Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications, traffic information relating to hosting provider activity is retained for the period stipulated in the relevant legislation (for hosting providers, not less than one year and not more than two years) in such a way as to ensure its accuracy, integrity and confidentiality, and is not shared with third parties unless duly requested by the competent authorities.
2.4. Support correspondence
Support ticket contents, attachments, e-mail correspondence, live chat transcripts and the summary of a request submitted by telephone which is recorded under the ticket are processed. Access credentials voluntarily shared by the customer within the ticket for the resolution of the support request (panel/SSH/FTP usernames and passwords) also fall within this scope.
Important warning: We do not recommend writing passwords or access keys into support tickets. Where this is unavoidable, the access credentials shared must be changed by the customer after the operation is completed. Content sent as a ticket attachment, such as a database backup or log file, is processed for the period required for the resolution of the request.
2.5. Information collected within the scope of domain name registration
In domain name registration, transfer and renewal transactions, the registrant’s first name and surname/corporate title, address, e-mail and telephone information are processed and transferred on a mandatory basis pursuant to the rules of the registry of the relevant extension, the accredited registrar and ICANN. For domain names with the “.tr” extension, the rules of the relevant national registry additionally apply. This transfer is mandatory for the performance of the registration service and, if it is not carried out, the domain name cannot be registered.
2.6. Marketing preferences (optional)
Message preferences relating to campaign, discount and service announcements are processed with prior consent obtained within the framework of Law No. 6563 and the relevant Regulation. Since the obligation to prove the existence of consent belongs to the service provider, the consent status, the date and time at which consent was obtained, the channel and, for consents obtained by electronic means, the IP address and the refusal requests are recorded (see section 7).
2.7. Data we do not collect / do not request
- We do not request special categories of personal data such as health, biometric data, religion, political opinion or trade union membership for the performance of the service; if such data is transmitted to us, it is processed only to the extent strictly necessary and is destroyed as soon as possible.
- We do not store payment instrument data such as the card number, CVV and expiry date.
- We do not routinely scan, index or analyse the content on customer servers (see section 3).
3. Data Located on Customer Servers and in Hosting Areas
3.1. Allocation of roles: data controller – data processor
With respect to all data located in the hosting account, the VPS/VDS, the dedicated server that our customer leases from us, or the device in its co-location cabinet:
- The customer is the data controller. It is exclusively the customer’s responsibility to determine for which purpose and on which legal ground it processes the personal data of its own users, members, employees and visitors, to fulfil the disclosure obligation, to obtain explicit consent where required, to respond to data subject applications, to implement data security measures and, where it is obliged to do so, to complete VERBİS registration.
- Depending on the location from which the service is provided, Pixoof Teknoloji A.Ş. (İstanbul – Equinix) or White Label Services, LLC (New York) acts as data processor; it processes the hosted data only to the extent necessary for the provision of the service and in accordance with the customer’s instructions. Pixoof Teknoloji A.Ş. additionally holds the status of hosting provider within the meaning of Law No. 5651; a hosting provider is not obliged to monitor the content it hosts or to investigate whether an unlawful activity is involved; however, where it is duly notified of unlawful content, it is obliged, to the extent technically possible, to remove the content from publication.
Our corporate customers may request the execution of a separate data processing agreement (DPA) within the framework of the requirements of Article 12 of the KVKK and, to the extent applicable, Article 28 of the GDPR. For requests: support@sunucucenter.com.
3.2. Principle of access to hosted content
Access to customer data is an exceptional operation which is recorded. Our personnel may access hosted files, databases, mailboxes or virtual machine disks only in the following three cases:
- Upon the customer’s express request: Within the scope of a support ticket or a request verified by an authorized person, limited solely to the area necessary for the resolution of the request. Access ends upon the resolution of the issue.
- In the event of a security incident: Where an ongoing or imminent attack, distribution of malware/malicious content, spam outflow, resource abuse or a situation threatening the continuity of service of the network or of other customers is detected; limited to the minimum scope required by the intervention. In the event of such an intervention, the customer is informed without delay to the extent that security grounds permit.
- In the event of a legal obligation: Pursuant to a court decision, a public prosecutor’s instruction, a decision of the Information and Communication Technologies Authority (BTK) or another competent administrative authority, or an obligation arising from the legislation in force. When such a request is received, the procedural compliance and the scope of the request are assessed; unless there is a legal prohibition on notification, the customer is informed. For services provided from the New York location, such requests are assessed by White Label Services, LLC and within the framework of US law.
Outside these three cases, hosted content is not accessed, the content is not read, copied or transferred to third parties. Access authorisation is defined according to the least privilege principle, access operations are logged and reviewed regularly. Authorised personnel are bound by an employment contract and a confidentiality undertaking.
3.3. Management model and the customer’s control
In VPS, VDS and dedicated server services, the management of the operating system and application layer belongs, as a rule, to the customer. Reboot, ISO installation, console access and viewing of resource graphs are possible on a 24/7 self-service basis through the client portal; these operations are carried out at the customer’s own initiative, without any access by us to the content. In the co-location service (offered only at the İstanbul – Equinix location), the device hardware and its content are entirely at the customer’s disposal; physical access is provided only to the authorized persons notified by the customer, within the framework of the data center entry procedures.
3.4. Backup
Backup differs according to the type of service:
- The scope, frequency, retention period and storage location of backups are determined in accordance with the package features announced on the product page of the relevant service and at the ordering step.
- Backups are subject to the same confidentiality and access rules as production data; backup content is accessed only in the cases set out in section 3.2.
- The existence of a backup service does not remove the customer’s responsibility to take its own independent backup. It is recommended that the customer keep external and regular backups of critical data.
- In the event of a deletion request, even if the production data is deleted, data may temporarily remain in the backup sets until the rotation cycle is completed; such data is destroyed at the end of the cycle.
3.5. Termination of the service and destruction of data
In the event of cancellation of the service, expiry of its term or termination of the agreement, the data belonging to the relevant account is deleted irreversibly at the end of the period announced on the product page of the relevant service and in the client portal. Within this period, the customer may request a copy of its data. Destruction processes are carried out within the framework of the Regulation on the Deletion, Destruction or Anonymisation of Personal Data and the company’s Personal Data Retention and Destruction Policy. Invoice and accounting records and traffic information which must be retained by law continue to be stored separately for the relevant statutory periods.
3.6. Content complaints: notice-and-takedown and DMCA
- Türkiye: Applications alleging that content we host is unlawful or infringes personality rights are assessed within the framework of Articles 5, 8, 9 and 9/A of Law No. 5651. Pursuant to Article 9 of the Law, a person claiming that their personality rights have been infringed may apply first to the content provider and, if unable to reach the content provider, to the hosting provider; the application is answered within twenty-four hours. In the case of duly submitted requests, notification is made to the content provider and the content may be removed from publication within the framework provided by the legislation; the requirements of the decisions of the criminal judgeship of peace are fulfilled within the period specified in the decision. Applications: support@sunucucenter.com and, via registered electronic mail (KEP), pixoof@hs03.kep.tr.
- USA: For services provided from the New York location, the notice and counter-notice procedure under 17 U.S.C. §512 (DMCA) applies. Notices must contain the elements required under 17 U.S.C. §512(c)(3) and must be sent to support@sunucucenter.com.
- Spam and abuse complaints (within the scope of the CAN-SPAM Act and our acceptable use policy) may be submitted through the same channels.
4. Cookies and Similar Technologies
4.1. General explanation
A cookie is a small text file stored in your browser by the website you visit. In addition, preference records written into your browser’s localStorage area, server-side cache tags and security layer identifiers are also covered by this section as “similar technologies”. localStorage records are not sent to the server; they remain solely in your browser. Our cookie practices are carried out with due regard to the principles adopted in the Guidelines on Cookie Practices of the Personal Data Protection Authority (KVKK Kurumu).
4.2. Cookies and technologies used
The table below shows the technologies used on our websites. The cookie names and retention periods of third-party components may change in line with updates to be made by the relevant provider.
| Cookie / Technology | Purpose | Type | Retention period |
|---|---|---|---|
| Session cookie (portal.sunucucenter.com – WISECP session identifier) | Logging in to the client portal, maintaining the session across pages, correct display of the user’s order and service information | Strictly necessary (functional) | For the duration of the session – deleted when the browser is closed or upon logging out |
| Session security / form validation cookie (WISECP CSRF token) | Protection against cross-site request forgery (CSRF), validation of form submissions | Strictly necessary (security) | For the duration of the session |
| sc-theme (localStorage) | Remembering the light/dark theme preference | Preference (functional) | Until browser data is deleted |
| sc-announce-… (localStorage – the key is completed with a short value derived from the announcement text displayed) | Ensuring that the same announcement is not displayed again once you close the announcement/information banner shown at the top of the site | Preference (functional) | Until browser data is deleted |
| LiteSpeed cache cookies | Server-side caching of pages, preventing an incorrect cached version from being served to a logged-in user, page loading performance | Strictly necessary (technical/performance) | For the duration of the session or for the short period defined in the cache configuration |
| Cloudflare bot management and security verification (including those created only when a security check is triggered) | Distinguishing automated bot traffic from human traffic, preventing abuse and automated attacks, ensuring that a visitor who has passed the security verification (challenge) is not subjected to verification over and over again | Strictly necessary (security) / third party | Some of them are kept for the duration of the session; the names and lifetimes of the cookies created following security verification are determined by Cloudflare |
| tawk.to live chat (cookies and related localStorage records) | Operation of the pre-sales live chat component, preventing the chat from being interrupted during page transitions, matching a returning visitor with their previous chat | Third party (functional) | A mixture of session cookies and persistent identifiers; the names and periods are determined by tawk.to. localStorage records remain on your device until browser data is deleted |
| Contact Form 7 (contact form – temporary technical values used for form status and unsolicited submission control) | Submission of the contact form, display of the submission status (successful/failed), prevention of unsolicited submissions | Strictly necessary (functional) | For the duration of the session |
| WordPress technical cookies (testing of browser cookie support and session cookies of site administrators only) | Testing the browser’s cookie support and session management for site administrators only – not created for ordinary visitors | Strictly necessary (technical) | For the duration of the session |
4.3. The moment the live chat component is loaded
The tawk.to live chat component is not loaded immediately upon page opening; it is loaded upon the first user interaction (scrolling, clicking, key press, touch) or, if these do not occur, after a short delay. When the component is loaded, cookies and similar identifiers may be created by the provider even if you do not initiate a chat. If you do not want this component to be loaded at all, you may use a browser extension that blocks third-party scripts (see section 5.4).
4.4. Note on analytics and marketing cookies
As of the date on which this Policy was prepared, the technologies verified as being used on our websites are those listed in the table above; no cookie or pixel for analytics or advertising/retargeting purposes is used. In the event that a tool for analytics or advertising purposes is installed, this Policy shall be updated and, since such cookies are of a non-essential nature, they shall not be run without obtaining the visitor’s explicit consent.
5. Cookie Management and Control of Your Preferences
5.1. Strictly necessary cookies
The strictly necessary cookies used for the purposes of session management, form security, caching and bot/attack protection are technically required for the operation of the website and the client portal. In accordance with the approach adopted in the Authority’s Guidelines, these cookies are not subject to explicit consent but are based on the legal grounds under Article 5/2 of the KVKK, and they cannot be disabled through the website. In the event that they are entirely blocked at browser level, it will not be possible to log in to the portal, to place an order or to open a support ticket.
5.2. Browser settings
You may view, delete or block cookies and localStorage records from the settings section of your browser. General paths:
- Google Chrome: Settings → Privacy and security → Third-party cookies / Site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Settings → Privacy → Manage Website Data
- Microsoft Edge: Settings → Cookies and site permissions
Menu names may vary depending on the browser version. You may also use incognito/private browsing mode and enable your browser’s tracking preference signals (e.g. Global Privacy Control).
5.3. Resetting theme and announcement preferences
The sc-theme theme preference and the announcement dismissal record are stored only in the browser you use; when you clear your browser data, these preferences revert to their default state. These records are not associated with your identity and are not sent to our servers.
5.4. Disabling live chat
If you do not wish to use the live chat component, you may refrain from opening the chat window or use a browser extension that blocks third-party scripts; in this case, the other functions of the website are not affected. In order to ensure that the component is not loaded at all, third-party script blocking methods are required (see section 4.3).
6. Third-Party Service Providers and Transfers Abroad
6.1. Table of service providers
| Provider | Function | Data processed / accessible | Country of location |
|---|---|---|---|
| Equinix (İstanbul data center) | Data center colocation, physical hosting, power and climate control; the sole location of all services and of co-location | Physical infrastructure; there is no logical access to the data. Only physical access records (visitor entry logs) | Türkiye (İstanbul) |
| New York data center / colocation infrastructure provider | Data center infrastructure for the server services at the U.S. location (White Label Services, LLC operation) | Physical infrastructure; there is no logical access to the data | USA (New York) |
| Cloudflare | CDN, DNS, security and bot management layer (positioned in front of our websites) | IP address, user-agent, request metadata, security event records | USA-based; global edge network |
| tawk.to | Pre-sales live chat infrastructure | Chat content, name and e-mail shared on an optional basis, IP address, information on the page visited | USA-based |
| WISECP (client portal and billing software) | Order, billing, service management and support ticket system software | The software runs on our own servers; the data remains within our infrastructure in İstanbul. The provider may access it only within the scope of licensing/technical support and upon request | Türkiye |
| LiteSpeed (web server and cache software) | Licensed software; runs locally on our servers | There is no data transfer to the provider (except license verification traffic) | USA (software provider) |
| Domain name registries (registry) and accredited registrars (registrar) | Domain name registration, transfer and renewal transactions | Registrant name/title, address, e-mail, telephone (mandatory pursuant to ICANN and registry rules) | Varies according to the domain name extension; the country in which the registry of the relevant extension is located is taken as the basis |
| Authorized payment institutions / payment service providers | Processing of credit card and alternative payment methods | Payment amount, transaction reference, invoice information; card data is processed directly at the payment institution | Varies according to the payment method selected at the order step; the relevant institution is displayed at the order step |
| Message Management System (İYS) | Central maintenance of commercial electronic message consent and refusal records (statutory obligation) | E-mail address and/or telephone number, consent/refusal status and date | Türkiye |
| E-invoice / accounting integrator | Issuance of invoices and fulfillment of statutory retention obligations | Invoice and current account information, tax identification information | Türkiye |
| Pixoof Teknoloji A.Ş. ↔ White Label Services, LLC | Sales, support and infrastructure operation under the common brand | Account, order and support data – only to the extent necessary for the provision of the relevant service | Türkiye ↔ USA |
6.2. Regime for transfers abroad (KVKK art. 9)
Transfers made to the providers shown in the table above as being established abroad are carried out within the framework of Article 9 of Law No. 6698 on the Protection of Personal Data (KVKK), as amended by Law No. 7499, and of the Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad. This regime is tiered:
- Adequacy decision (art. 9/1): If there is an adequacy decision issued by the Personal Data Protection Board (Kurul) concerning the country, the sectors within that country or the international organizations to which the transfer is to be made, the transfer is carried out on the basis of that decision, provided that one of the conditions set out in articles 5 and 6 of the KVKK is present.
- Appropriate safeguards (art. 9/2): If there is no adequacy decision and one of the conditions set out in articles 5 and 6 of the KVKK is present, the transfer may be carried out by the parties furnishing one of the following appropriate safeguards and provided that the data subject has the opportunity to exercise their rights and to lodge an effective complaint in the country to which the transfer is made:
- A protocol not having the nature of an agreement concluded between public institutions and organizations or international organizations abroad and public institutions and organizations or professional organizations having the status of a public institution in Türkiye (this option is not applicable in respect of our companies, which are private law legal entities),
- Binding corporate rules (BCR) approved by the Board, with which the companies within a group of undertakings engaged in a joint economic activity are obliged to comply,
- The standard contract announced by the Board,
- A written undertaking signed with the permission of the Board.
The standard contract shall be signed without any amendment to the text announced by the Board and shall be notified to the Personal Data Protection Authority (KVKK Kurumu) within five business days from the date of signature. This notification obligation applies separately in respect of data controllers and data processors.
- Incidental cases (art. 9/6): In cases where neither an adequacy decision nor appropriate safeguards exist, the transfer may be carried out only on an incidental basis and by relying on one of the following grounds: the data subject giving explicit consent to the transfer, provided that they have been informed of the possible risks; the transfer being mandatory for the performance of the contract or for the performance of a contract established for the benefit of the data subject; the existence of an overriding public interest; the transfer being mandatory for the establishment, exercise or protection of a right; the protection of the life or bodily integrity of a person who is unable to express their consent due to actual impossibility; the request for information from registers open to the public or to persons having a legitimate interest. These grounds cannot be used for transfers of a continuous nature.
Critical notice: As of the date on which this Policy was prepared, there is no adequacy decision issued by the Board concerning the United States of America. For this reason, transfers of a continuous nature made to USA-based providers (including Cloudflare, tawk.to, the infrastructure provider at the New York location and White Label Services, LLC) are carried out by furnishing one of the appropriate safeguards provided for in article 9 of the Law and by making the required notifications; incidental cases do not constitute a legal basis for transfers of a continuous nature.
Receiving service from the New York location results in the customer’s data being hosted in the USA by the customer’s own choice. Customers who wish their data to remain within the borders of Türkiye must select the İstanbul – Equinix location; the location preference is displayed at the order step.
6.3. Cases in which no transfer is made
We do not under any circumstances sell or rent your personal data, nor do we share it with third parties for advertising purposes. Disclosures other than those shown in the table above may be made only pursuant to the duly submitted requests of public institutions and organizations legally authorized to do so, and to attorneys, expert witnesses and judicial authorities for the purpose of exercising the right of defense in legal disputes.
7. Commercial Electronic Messages
7.1. Principle of consent
Pursuant to Law No. 6563 on the Regulation of Electronic Commerce and the Regulation on Commercial Communication and Commercial Electronic Messages, commercial electronic messages containing campaign, promotional and marketing content are sent only with your prior consent. Consent is collected during registration through the portal or from the account settings, by expressly obtaining your affirmative declaration of intent, and is recorded in the Message Management System (İYS). Consents that are not recorded in the İYS are deemed invalid; commercial electronic messages are not sent to recipients having a refusal record in the İYS. The burden of proving the existence of consent lies with the service provider.
Pursuant to the legislation, where the recipient is a merchant (tacir) or tradesman (esnaf), commercial electronic messages may be sent without obtaining prior consent; in this case as well, the İYS record and the recipient’s right of refusal are reserved, and where the right of refusal is exercised, no further message is sent unless consent is obtained. The messages sent include the identifying information required by the legislation (trade name, MERSIS/trade registry number and contact details).
7.2. Notifications that do not require consent
Transactional notifications directly related to the performance of the service are not deemed commercial electronic messages and are not subject to consent. These are, for example: order and payment confirmations, invoice notifications, service term expiry and renewal reminders, domain name expiration warnings, support ticket replies, scheduled maintenance announcements, security warnings and fault/outage notifications. Since failure to receive these notifications directly affects the sustainability of the service, they cannot be turned off. No promotional or campaign content is inserted into transactional notifications.
7.3. Right of refusal
You may refuse to receive commercial electronic messages without stating any reason and free of charge. You may exercise your right of refusal by the following means:
- Through the unsubscribe / refusal link included in each message sent,
- From the client portal → account settings → communication preferences section,
- Directly through the İYS (https://iys.org.tr),
- By sending a request to support@sunucucenter.com.
Following receipt of the refusal request, the sending of messages is stopped within the three business days prescribed by the legislation and the refusal record is entered into the İYS. Following the refusal, the transactional notifications listed in 7.2 continue to be sent. Consent and refusal records are retained for the period prescribed by the legislation on account of the burden of proof.
8. Data Security
8.1. Transmission and storage security
- All web traffic, including the corporate website and the client portal, is encrypted with TLS; HTTP requests are redirected to HTTPS. Server management access is carried out over SSH and encrypted protocols.
- Passwords are stored with irreversible hashing algorithms; our personnel cannot view customer passwords.
- At the Cloudflare layer positioned in front of our websites, security filtering, DDoS protection, bot management and rate limiting are applied according to the scope of the plan used.
These measures are applied, according to the location at which the service is provided, by Pixoof Teknoloji A.Ş. (İstanbul – Equinix) and White Label Services, LLC (New York) in respect of the systems they each operate.
8.2. Access control and authorization
- Access to administrative systems is defined on a role basis in accordance with the least privilege principle; each staff member may access only the data required by their duties.
- We recommend that our customers enable two-step verification on their portal accounts.
- Personnel are bound by their employment contract and by a separately signed confidentiality undertaking; access authorizations are revoked upon departure from employment.
- Access authorizations are reviewed at regular intervals.
8.3. Logging and monitoring
- System, application and security logs are kept; authentication attempts, portal transactions and administrative access are recorded.
- Traffic information within the scope of Law No. 5651 is retained for the period prescribed by the legislation in such a manner that its accuracy, integrity and confidentiality are ensured.
- The infrastructure is monitored 24/7; anomaly and capacity alerts are generated automatically. On the network side, operations are conducted with multiple carriers; service continuity is supported by a redundant backbone.
- Our service availability commitment is 99.98%; for periods in which the commitment is not met, credit compensation at a rate of 5% of the relevant service fee is applied. The credit request shall be submitted by support ticket by the end of the month following the month in which the outage occurred. The scope, calculation method and exceptions of this commitment are regulated in the service agreement.
8.4. Backup and business continuity
Our backup practices are explained in section 3.4. Backups are kept in areas subject to access control and restore operations are recorded.
8.5. Notification in the event of a data breach
In the event it is determined that personal data has been obtained by others through unlawful means, pursuant to article 12/5 of the KVKK and the relevant decision of the Personal Data Protection Board, the situation shall be notified to the Board without delay and at the latest within 72 hours from the date on which it is learned, and to the affected data subjects within the shortest reasonable time.
If we detect a breach in hosted systems in respect of which our customers are the data controller, the customer is informed without delay so that the customer may fulfill its own notification obligation. In respect of customers established in the EU, in cases where we act in the capacity of data processor, notification is made to the data controller without undue delay pursuant to article 33/2 of the GDPR; the 72-hour period for notification to the supervisory authority under article 33/1 of the GDPR concerns the party bearing the capacity of data controller.
8.6. No absolute security commitment is given
Notwithstanding the measures set out above, no method of data transmission over the internet or of electronic storage provides absolute security. The confidentiality of your account password, the currency and security of the software you run on your server, and the protection of your access credentials are the responsibility of the customer.
9. Children’s Privacy
Our services are directed at natural persons who have reached the age of 18 and have legal capacity to act, and at legal persons. We do not knowingly collect personal data from persons under the age of 18 and we do not provide services to such persons. In order for an order to be placed, the person opening the account must declare that they have reached the age of 18 and possess the capacity to enter into a contract.
Where it is established or notified to us that data belonging to a person under the age of 18 has been transmitted to us without the consent of a parent/legal guardian, the relevant data shall be deleted without delay and the related account, if any, shall be closed. Notifications to this effect may be sent to support@sunucucenter.com.
Where data relating to children is processed on the sites hosted by our customers, obtaining the necessary parental/guardian consent and ensuring compliance with the applicable legislation (in Türkiye, the KVKK and the provisions of the Turkish Civil Code concerning capacity; in the USA, COPPA in respect of persons under 13; in the EU, Art. 8 GDPR, which as a rule provides for a threshold of 16 years – which Member States may lower to 13) is exclusively the responsibility of the customer.
10. Additional Rights for European Union (GDPR) and California (CCPA/CPRA) Customers
10.1. European Economic Area and United Kingdom customers
Data subjects who are resident in the EEA or the United Kingdom and who benefit from our services have the following rights, to the extent that the GDPR/UK GDPR is applicable:
- The right of access (Art. 15), the right to rectification (Art. 16), the right to erasure (right to be forgotten) (Art. 17), the right to restriction of processing (Art. 18);
- The right to data portability (Art. 20);
- The right to object to processing based on legitimate interests and to direct marketing (Art. 21);
- The right not to be subject to decisions based solely on automated processing and producing legal effects (Art. 22);
- The right to withdraw consent at any time in respect of processing based on consent;
- The right to lodge a complaint with the competent supervisory authority.
Depending on the configuration under which you receive the service, our Company acts in the capacity of data controller with respect to its own customer relationship data, and in the capacity of data processor with respect to the content you host. With respect to hosted data, you may request a data processing agreement compliant with Art. 28 of the GDPR. For transfers made from the EEA or the United Kingdom, Standard Contractual Clauses (SCC) or the UK Addendum/IDTA shall be applied to the extent necessary. You may submit your requests and applications within this scope to support@sunucucenter.com.
10.2. California customers (CCPA/CPRA)
Consumers resident in California have the following rights, to the extent that the CCPA/CPRA is applicable:
- The right to know: To request information about which categories of personal information are collected, their source, the purpose of use and the categories of parties with whom they are shared;
- The right of access: To request a copy of the specific personal information collected;
- The right to deletion and the right to correction;
- The right to opt out of “sale” or “sharing”;
- The right to limit the use of sensitive personal information;
- The right not to be subject to discrimination: No different price or quality of service shall be applied to a consumer who exercises their rights.
We do not sell personal information and we do not share it for the purpose of cross-context behavioral advertising. If your browser sends the Global Privacy Control (GPC) signal, this signal shall be taken into account as a valid opt-out request. Requests may be submitted to support@sunucucenter.com; after reasonably verifying your identity, we shall respond within the periods prescribed by the legislation. In applications made through an authorized agent, the authority of representation must be documented.
10.3. Data subjects resident in Türkiye
You may exercise your rights under Art. 11 of the KVKK in accordance with Art. 13 of the KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller. You may submit your written applications, bearing a wet signature, to our Company’s office (correspondence) address at Yeşilköy Mahallesi, Atatürk Caddesi No: 12, B3 Blok Daire 268, EGS Business Park, Bakırköy / İstanbul, or, bearing a secure electronic signature, to the registered electronic mail (KEP) address pixoof@hs03.kep.tr. Applications shall be concluded as soon as possible depending on the nature of the request, and in any event within thirty days; where the transaction additionally requires a cost, the fee in the tariff prescribed in the Communiqué may be charged. In the event that the application is rejected, the response given is found insufficient or no response is given within the prescribed period, you may lodge a complaint with the Board pursuant to Art. 14 of the KVKK within thirty days from the date on which you learned of the response and, in any event, within sixty days from the date of the application. For application channels and the detailed procedure, please see the Privacy Notice.
Our customers holding consumer status may, in disputes, apply pursuant to Law No. 6502 on Consumer Protection to the Consumer Arbitration Committees or to the Consumer Courts of their place of residence or of the place where the transaction was carried out; which authority is to be applied to shall be determined in accordance with the monetary thresholds determined for the relevant year.
11. Contact and Amendments
11.1. Contact
You may submit your questions, requests and complaints regarding this Policy, our cookie practices or data security through the following channels:
- E-mail: support@sunucucenter.com
- Telephone: +90 850 270 0511 (sales and general matters; during business hours)
- Support ticket: https://portal.sunucucenter.com – open 24/7/365
- Live chat: for pre-sales questions
- Corporate telephone (company details / service of notice): 0212 963 05 05
- Post (İstanbul office – correspondence and application address): Yeşilköy Mahallesi, Atatürk Caddesi No: 12, B3 Blok Daire 268, EGS Business Park, Bakırköy / İstanbul
- Registered head office address: Beylikdüzü OSB Mahallesi, Birlik Sanayi Sitesi, 3. Cadde No: 5 Daire: 130, Beylikdüzü / İstanbul
- KEP (Pixoof Teknoloji A.Ş.): pixoof@hs03.kep.tr
- Correspondence address of the U.S. operation (White Label Services, LLC): 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801, USA
Our telephone and live chat channels provide service during business hours; the technical support ticket channel is open 24/7/365. Channel-based response times shall be applied in accordance with the conditions announced on the product page of the relevant service and in the service agreement.
11.2. Amendments to the Policy
This Policy may be updated due to changes in legislation, updates in the technologies we use, engagement of new service providers or changes in our business processes. The current text shall always be published at https://www.sunucucenter.com and the “Last updated” date at the beginning of the document shall be renewed. Previous versions of the Policy shall be shared upon request.
In the case of amendments that materially affect your rights or the manner in which your data is processed, separate information shall be provided by e-mail or by a client portal notification before the amendment enters into force. If processing based on explicit consent is concerned, your consent shall be obtained again where necessary. Your continued use of the services after the amendment enters into force means that you are aware of the informative provisions of the updated Policy; this does not substitute for consent in cases where the legislation requires explicit consent.
11.3. Relationship with other documents
This Policy shall be applied together with the KVKK Privacy Notice, the Terms of Use / Service Agreement, the Acceptable Use Policy and the Distance Sales Agreement and Preliminary Information Form; the current versions of these texts are published at https://www.sunucucenter.com. Commercial and contractual terms, including the exceptions to the right of withdrawal – in particular Art. 15/1(ğ) of the Regulation on Distance Contracts (services performed instantaneously in the electronic environment and intangible goods delivered instantaneously to the consumer) and Art. 15/1(h) (services the performance of which has commenced with the consumer’s approval before the expiry of the right of withdrawal period) – are regulated not in this Policy but in the relevant contractual texts. In the event of a conflict between the texts, the Privacy Notice shall be taken as the basis on matters concerning the processing of personal data, and this Policy shall be taken as the basis with respect to technical and operational privacy practices.