🔐 Data Location and Infrastructure
Where is the data kept? Stored on cloud servers located in Türkiye.
Your data does not leave the country.
- ✔ Servers located in Türkiye
- ✔ AES-256 encryption (data at rest)
- ✔ TLS 1.3 encryption (data in transit)
- ✔ ISO 27001 compliant data center
💾 Backup and Disaster Recovery
Are there backups? Daily automatic backups with 30-day recovery.
- ✔ Daily automatic backups
- ✔ 30-day point-in-time recovery
- ✔ Geographically separate backup locations
- ✔ Disaster recovery plan (RTO: 4 hours, RPO: 24 hours)
🔑 Authorization and Access Control
How is access managed? Role-based access control (RBAC) with all operations
recorded in an audit log.
- ✔ Role-based access (Admin/Manager/Viewer)
- ✔ Unit-based access control
- ✔ Two-factor authentication (2FA) support
- ✔ Audit log of all operations
📋 Logging and Traceability
Is there logging? All user operations, data access and system events are logged.
- ✔ User operation logs (who, when, what)
- ✔ Data access logs
- ✔ System event logs
- ✔ 1-year log retention
🛡️ Data Protection Compliance
Is it compliant? Fully compliant with Turkish data protection law
(KVKK, Law No. 6698); a DPA is available.
- ✔ Explicit consent management and records
- ✔ Data minimization principle (only required data is collected)
- ✔ Deletion/anonymization on request
- ✔ DPA (Data Processing Agreement) available
- ✔ Privacy notices and disclosure obligations
📁 Data Retention and Deletion
How do deletion/portability requests work? Data is deleted or exported within
30 days upon request.
- ✔ Retention for the duration of the service
- ✔ Deletion within 30 days upon request
- ✔ Data export (JSON/CSV format)
- ✔ Anonymization option
- ✔ Automatic deletion when the contract ends
🔒 Encryption and Security Standards
Which standards are used? Industry-standard encryption and security protocols.
- ✔ AES-256 encryption (data at rest)
- ✔ TLS 1.3 encryption (data in transit)
- ✔ Secure password policies
- ✔ Regular security audits (twice a year)
- ✔ Penetration testing
👤 User Rights
Can users control their data? Yes, all rights under data protection law
can be exercised.
- ✔ Data access (view your own data)
- ✔ Correction requests
- ✔ Right to deletion
- ✔ Right to object
- ✔ Data portability (export)