Data Processing and Retention Policy
<h2>DATA PROCESSING AND RETENTION POLICY</h2><p><strong>Data controller:</strong> Nettescil Yazılım Bilişim Reklam Organizasyon Hizmetleri. Contact: kurumsal@nettescil.com.tr | 0850 307 01 18.</p><p>This policy explains the purposes, methods, security and retention principles for data processed through the Nettescil website, customer panel, support channels, hosting and server services, licence operations, orders and payments. The Privacy Notice and service agreements remain applicable.</p><h3>1. Data groups</h3><p>Identity and contact details, customer and billing information, orders and services, support communications, domain and licence data, technical access and security logs, transaction dates and preference records may be processed. Payment card data is not stored by Nettescil; the payment provider’s secure infrastructure is used.</p><h3>2. Purposes and legal grounds</h3><p>Data is processed to enter into and perform contracts, issue invoices, activate services, provide support, maintain security, investigate abuse, comply with legal duties, protect rights and conduct communications where consent has been given. Data not necessary for the relevant purpose is not collected.</p><h3>3. Hosting customer content</h3><p>The customer is responsible for the lawfulness of content, mail, databases and applications uploaded to servers. As a technical provider, Nettescil accesses such data only to operate the service, maintain security or comply with law and does not perform general content monitoring.</p><h3>4. Logs and security</h3><p>IP, session, device, error, access, transaction and security records may be retained to prevent unauthorised access, investigate incidents, maintain continuity and establish evidence. Security measures may include access restriction, password reset, restoration from backup or temporary suspension.</p><h3>5. Backups and retention</h3><p>Retention periods depend on purpose and legal requirements. Orders, invoices and contracts are kept for statutory periods; support and security records for a reasonable period required by the incident and service relationship; cancelled service data according to legal retention duties and a reasonable deletion schedule. Deleted data may remain in backups for a limited technical cycle.</p><h3>6. Sharing and providers</h3><p>Data may be shared to the extent necessary with authorised payment, e-mail, domain, licence, data-centre, security, backup and technical-support providers. Purpose, data categories and safeguards are limited to the relevant process.</p><h3>7. Security and incidents</h3><p>Access controls, least privilege, backups, updates, logging and reasonable technical and organisational measures are applied. No internet system can guarantee absolute security. Suspected personal-data incidents are investigated and notified where required by law.</p><h3>8. Rights and requests</h3><p>Data subjects may send verifiable requests under applicable data-protection law to kurumsal@nettescil.com.tr. Requests are handled within legal procedures and time limits, subject to mandatory retention.</p><h3>9. Effective date</h3><p>This policy is effective from 15 September 2026. Updates are published on the website and material changes may be announced through appropriate channels.</p>