Service provider and data controller
| Registered business name | Kuzgun Yazılım Bilişim ve Danışmanlık Limited Şirketi |
|---|---|
| Brand | KuzgunHost |
| Registered office / postal address | Y.T.Ü. Davutpaşa Kampüsü Teknopark B1 Blok No:305 K:1 Esenler / İstanbul |
| info@kuzgunsoftware.com | |
| Phone | +90 554 769 48 48 |
| Website | kuzgunhost.com |
| Tax office / tax number | Must be verified and completed by an authorized company representative before publication. |
| MERSIS / trade registry number | Must be verified and completed by an authorized company representative before publication. |
| Registered electronic mail (KEP) address | Must be verified and completed by an authorized company representative before publication. |
1. Scope and categories of data subjects
This notice covers website visitors, members, individual and corporate customers, corporate account representatives, persons submitting quotation and contact forms, support request owners, domain name registrants, and other natural persons who use the services.
The services are not directed at children. Personal data concerning children must not be entered into the system without authority as a legal representative.
2. Categories of personal data processed
| Data category | Principal examples of data |
|---|---|
| Identity | First and last name; Turkish national identity or foreign identity information where required by law or domain registration rules. |
| Contact | Email, telephone, address, province/district and notification preferences. |
| Customer and company | Business name, authorized representative, tax office, tax number, billing profile and corporate user roles. |
| Account and transaction security | User ID, password hash, verification status, IP address, device/browser information, session, failed sign-ins and security incidents. |
| Orders and services | Cart, configuration, order, subscription, domain name, server, backup, business email and service usage records. |
| Finance and billing | Invoice line items, payment method, payment status, transaction number, bank/transfer record, refunds and the last four digits of a masked card. |
| Legal matters | Agreement and notice version, confirmation time, document digest, dispute, request and official correspondence records. |
| Support and contact | Request subject, messages, call notes, uploaded files, technical logs and satisfaction records. |
| Marketing | Commercial communication preferences, campaign interactions and preference history, only where permission has been granted. |
The full card number, CVV/CVC and card authentication data are not stored in KuzgunHost systems. Card data is processed in the secure payment environment of the selected payment institution; only the transaction result and, where applicable, a token or masked card information are returned to KuzgunHost.
3. Purposes and legal grounds for processing
Personal data is processed to establish membership and corporate accounts; verify identity and email; manage carts and orders; conclude and perform agreements; provide services; conduct domain registration and transfer operations; process payments and refunds; manage billing and accounting; provide support and notifications; ensure information security; prevent fraud and abuse; conduct audits; comply with lawful requests; and protect rights.
Depending on the specific processing activity, processing is based on the legal grounds in Article 5(2) of the KVKK: express provision by law; compliance with a legal obligation; establishment or performance of a contract; establishment, exercise or protection of a right; and the data controller's legitimate interests, provided that the data subject's fundamental rights are not harmed.
Commercial electronic communications, non-essential cookies and other processing that legally requires explicit consent are managed through separate preferences and are not made a mandatory condition of the service. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
4. Methods of collecting data
Data is collected electronically by wholly or partly automated means through registration and sign-in screens; sign-in with Google; cart, order, payment, quotation, domain name, support and contact forms; the customer portal; email and telephone communications; cookies and system logs; and payment, banking, domain name, e-invoice, data center, virtualization, email and backup integrations.
A person entering domain name or corporate user information on behalf of another person must confirm that they are authorized to share the information and that the data subject has received the required notice.
5. Domestic recipient groups and purposes of transfer
Data that is necessary and proportionate for its purpose may be transferred to payment institutions and banks for payments and refunds; the e-invoice/e-archive integrator for billing; the domain registrar for registration, transfer and ownership verification; data center, license, email and backup providers for service setup; and communications delivery, security, audit and technical support providers for the relevant service.
Data is shared with legally authorized public bodies, regulatory authorities, courts and enforcement authorities only to comply with a legal obligation or duly issued request. As a principle, agreements with service providers include obligations concerning data security, confidentiality, processing on instructions and deletion.
6. International data transfers
Where sign-in with Google, foreign-based security or communications infrastructure, or domain registration services are selected, an international transfer may arise from technical necessity. Such a transfer will not take place unless an appropriate mechanism for the specific processing under Article 9 of the KVKK is in place, such as an adequacy decision, an appropriate safeguard (for example, a standard contract), or an exceptional transfer condition prescribed by law.
Before a foreign-based service is activated, the provider's location, subprocessors, scope of transfer and appropriate safeguard mechanism are assessed. Additional information is provided to the User only to the extent necessary.
7. Retention periods and disposal
Data is retained for periods determined by the purpose of processing, limitation periods, and obligations under accounting, tax, electronic commerce, consumer, internet publication and domain name legislation. When an account is closed, data not required for an active service is placed on the deletion schedule; records subject to a statutory retention obligation are access-restricted and retained until the end of the applicable period.
Data for which the reason for retention has ended is erased, destroyed or anonymized through the periodic disposal process. Copies in backups are securely overwritten at the end of the backup cycle and are used solely for disaster recovery during that period.
8. Data security measures
Measures include an authorization matrix and least privilege; strong password hashing; session and rate limiting; multi-factor authentication; TLS/HTTPS; logging and audit trails; encryption of sensitive fields; secure key management; backups; updates; malicious file scanning; access reviews; and incident response processes. Security incidents are assessed in light of risk and applicable law.
The User must not include unnecessary special categories of personal data, passwords, card details or access keys in a support request. Server access secrets are delivered through time-limited and controlled methods instead of plain-text email.
9. Data subject rights under Article 11 of the KVKK
The data subject has the right to learn whether their personal data is processed; request information if it has been processed; learn the purpose of processing and whether it is used in accordance with that purpose; know the third parties to whom it is transferred in Türkiye or abroad; request correction if it has been processed incompletely or inaccurately; request erasure or destruction where the applicable conditions are met; and request notification of those operations to third parties to whom the data has been transferred.
The data subject also has the right to object to a result arising against them through analysis exclusively by automated systems and to claim compensation for damage suffered as a result of unlawful processing.
10. Applications to the data controller
The application must include the applicant's full name; signature for a written application; Turkish national identity or foreign identity number; address for service or business address; email address or telephone number for notifications, if any; and the subject of the request. Information and documents needed to verify identity may be requested proportionately.
An application may be submitted in writing to the data controller's postal address above or, using an email address previously registered and verified in the system, to info@kuzgunsoftware.com , or to the KEP address to be announced by the company. The KEP address must be added to this notice when it is provided by an authorized company representative.
Applications are concluded free of charge as soon as possible according to the nature of the request and no later than thirty days. If the operation entails an additional cost, the fee in the tariff set by the Personal Data Protection Board may apply.
11. Cookies, authentication and payment
Essential cookies are used to enable sessions, security, the cart and preferences. Analytics or marketing cookies are not activated until the User gives separate permission. Cookie preferences may be changed later.
When sign-in with Google is selected, minimum profile data such as email address, full name and provider user ID is obtained for authentication. On the payment screen, card details are processed by the payment institution; KuzgunHost records the payment result, transaction ID and necessary masked information.
12. Updates to this notice
When processing activities or legislation change, this notice is updated with its version and effective date. Previous versions are retained in association with the relevant transaction and consent records. Material changes are announced through an appropriate communication channel.
Effective date: July 30, 2026