Note on this English translation
This English version is provided for information purposes only. It is a courtesy translation of the Turkish original. In the event of any discrepancy or conflict of interpretation, the Turkish version of this document shall prevail.
1. Data Controller
This disclosure notice has been prepared by Sysnet Yazılım ve Bilgi Teknolojileri Ltd. Şti. ("Sysnet", the "Company" or "we"), in its capacity as data controller, within the scope of Article 10 of Law No. 6698 on the Protection of Personal Data ("KVKK") and the Communiqué on the Principles and Procedures to be Followed in Fulfilling the Disclosure Obligation, in order to inform you about the processing of your personal data in connection with the SignLogger product and the signlogger.com website.
Our Company is registered with the Data Controllers' Registry (VERBİS) of the Personal Data Protection Authority (KVKK).
2. Definitions
The terms used in this disclosure notice shall have the following meanings:
- Personal Data: Any information relating to an identified or identifiable natural person.
- Special Categories of Personal Data: Your data concerning race, ethnic origin, political opinion, philosophical belief, religion, sect, dress and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
- Data Subject: The natural person whose personal data is processed (user, customer, applicant, visitor, etc.).
- Data Processing: Any operation performed on data, such as obtaining, recording, storing, retaining, altering, disclosing, transferring, classifying or preventing the use of data.
- Explicit Consent: Consent relating to a specific matter, based on information and declared through free will.
- Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
3. Categories of Personal Data Processed
In line with the nature of the services we provide and the scope of our relationship with you, our Company may process the following categories of personal data:
- Identity Data: First name, surname, Turkish national identity number (only within the scope of legal obligations), tax number, date of birth, title.
- Contact Data: E-mail address, telephone number, fax, postal address, country, province, district.
- Customer Transaction Data: Orders, invoices, licence keys, subscriptions, payment information, demo requests, download requests, support requests.
- Marketing Data: Your survey responses, habits, cookie records, campaign communication preferences.
- Transaction Security Data: IP address, user transaction records (logs), session cookies, password hashes, two-factor authentication (2FA) data, device/browser information.
- Legal Proceedings Data: Information contained in correspondence with judicial/administrative authorities, case files.
- Visual and Audio Records: Social media posts, call centre voice recordings (if any).
- Traffic Data within the Scope of Law No. 5651: IP, port, destination IP, session times (only pursuant to legal obligation).
4. Purposes of Processing Personal Data
As Sysnet, we process your personal data for the following purposes, in accordance with the principles set out in Article 4 of the KVKK: "compliance with the law and good faith; being accurate and, where necessary, kept up to date; being processed for specified, explicit and legitimate purposes; being relevant, limited and proportionate to the purposes for which they are processed; and being retained only for the period stipulated in the relevant legislation or required for the purposes for which they are processed":
- Performance of our contractual obligations (licence sales, dealership, subscription, support),
- Delivery of software installation files and dispatch of download links,
- Conducting customer request, complaint and technical support processes,
- Managing demo requests and pre-sales negotiation processes,
- Evaluating dealership applications and managing the dealer network,
- Invoicing and accounting operations (pursuant to Tax Procedure Law No. 213),
- Responding to the requests of authorised public institutions and organisations,
- Fulfilling obligations within the scope of Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications,
- Ensuring information security and preventing misuse, fraud and cyberattacks,
- Marketing, campaign and announcement activities (only where explicit consent exists),
- Website usage analytics and improvement of service quality (cookies).
5. Legal Grounds for Processing
We process your personal data on the basis of the following legal grounds set out in Articles 5/2 and 6/3 of the KVKK:
- Being necessary for the establishment or performance of a contract (KVKK Art. 5/2-c).
- Being necessary for the fulfilment of our legal obligation (KVKK Art. 5/2-ç) — in particular pursuant to Law No. 5651, Law No. 6563 on the Regulation of Electronic Commerce, Law No. 6502 on Consumer Protection, and Tax Procedure Law No. 213.
- Being necessary for the establishment, exercise or protection of a right (KVKK Art. 5/2-e).
- Being necessary for our legitimate interests, provided that it does not harm the fundamental rights and freedoms of the data subject (KVKK Art. 5/2-f).
- The existence of your explicit consent (KVKK Art. 5/1) — for marketing communications, use of cookies (except mandatory cookies) and processes involving special categories of personal data.
6. Method of Collecting Personal Data
Your personal data is collected in electronic form, by automated or partially automated means, through the following channels:
- Website forms (contact, demo request, download request, dealership application),
- E-mail, telephone and fax communication,
- Account creation and login via the customer portal, dealer portal and licence management system,
- Website cookies and server logs (IP, session, behaviour),
- Technical records generated while running the SignLogger product and our other software,
- Contract signing, invoicing, quotation and order processes,
- Social media, events, trade fairs and business card exchanges.
7. Transfer of Personal Data
Within the scope of Articles 8 and 9 of the KVKK, our Company may transfer your personal data to the following groups of recipients for the purposes stated above, provided that adequate security measures are taken:
- Authorised public institutions and organisations (BTK, KVKK, the Ministry of Finance, Public Prosecutor's Offices, courts, law enforcement),
- Legal counsel, financial advisors and lawyers,
- Infrastructure providers from whom a data security undertaking has been obtained by written contract (hosting, cloud, e-mail service, CDN, payment institution),
- Sysnet group companies and business partners,
- Our authorised dealers — only where the relevant dealer needs to contact or provide services to you as their customer,
- Audit firms and independent auditors,
- Third parties where required by a court or arbitration decision.
8. Transfer Abroad
Some of our cloud-based services (e-mail server, CDN, analytics service) may operate through servers located abroad. In such cases, pursuant to Article 9 of the KVKK, data is transferred to countries providing adequate protection or to persons with whom a contract has been concluded as a data controller providing an undertaking of adequate protection; otherwise, your explicit consent is obtained.
For services such as Microsoft 365 (e-mail), Google Analytics (web analytics) and Cloudflare (CDN), the server locations of the relevant provider apply.
9. Retention Period of Personal Data
Your personal data is retained for the periods stipulated in the relevant legislation and in accordance with the following criteria:
- Customer and invoice data: 5 years pursuant to Article 253 of Tax Procedure Law No. 213, and 10 years pursuant to Article 82 of the Turkish Commercial Code.
- Contracts and legal documents: Duration of the contract + 10 years (limitation period under Article 146 of the Turkish Code of Obligations).
- Traffic data within the scope of Law No. 5651: At least 6 months, at most 2 years.
- Marketing permissions: Until the date on which explicit consent is withdrawn.
- Download requests and token records: Automatically deleted after 30 days.
- Website server logs: 90 days.
- Cookie data: For the lifetime of the relevant cookie (session cookies are deleted when the browser is closed).
10. Data Security Measures
Pursuant to Article 12 of the KVKK, our Company implements the following administrative and technical measures in order to prevent the unlawful processing of and access to personal data and to ensure its safekeeping:
- Encrypted communication via TLS 1.2+ (HTTPS), HSTS, modern cipher suites,
- Hashing of passwords with bcrypt (cost 12), never stored in plain text,
- Mandatory two-factor authentication (TOTP / 2FA) on administration panels,
- Role-based access control (RBAC) and the principle of least privilege,
- Firewall and intrusion detection (fail2ban) systems at the server, network and application levels,
- Regular vulnerability scanning and penetration testing,
- Keeping records of authorised personnel's access to data (audit logs),
- KVKK and information security training for employees,
- Data backups, disaster recovery plans and encrypted backups,
- Data deletion, destruction and anonymisation procedures.
11. Rights of the Data Subject (Article 11 of the KVKK)
Pursuant to Article 11 of the KVKK, you may exercise the following rights by applying to our Company in its capacity as data controller:
- (a) To learn whether your personal data is being processed,
- (b) To request information if your personal data has been processed,
- (c) To learn the purpose of processing your personal data and whether it is used in accordance with such purpose,
- (ç) To know the third parties within the country or abroad to whom your personal data is transferred,
- (d) To request the correction of your personal data if it has been processed incompletely or inaccurately,
- (e) To request the erasure or destruction of your personal data within the framework of the conditions set out in Article 7 of the KVKK,
- (f) To request notification of the operations carried out pursuant to subparagraphs (d) and (e) to the third parties to whom your personal data has been transferred,
- (g) To object to the emergence of a result to your detriment through the analysis of your processed data exclusively by automated systems,
- (ğ) To request the remedy of any damage in the event that you suffer damage due to the unlawful processing of your personal data.
12. How to Exercise Your Rights (Application)
You may submit your requests concerning the rights listed above by using one of the following channels, in accordance with the procedures set out in the Communiqué on the Principles and Procedures for Applying to the Data Controller:
Our Company will conclude your application free of charge within 30 (thirty) days at the latest, depending on the nature of the request. However, if the transaction requires an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board may be charged to you.
- In writing: by wet-signed petition to the address of Sysnet Yazılım ve Bilgi Teknolojileri Ltd. Şti., İstanbul / Türkiye,
- By e-mail: from your registered electronic mail (KEP) address or the e-mail address registered in our Company's systems, to kvkk@sysnet.com.tr,
- Using a secure electronic signature, mobile signature or KEP.
- Your application must clearly state: first name, surname, signature, Turkish national identity number (for Turkish citizens), notification address and the subject of the request.
13. Use of Cookies
The following categories of cookies are used on our website:
You can manage your cookie preferences from the cookie management panel at the bottom of our site or from your browser settings.
- Mandatory Cookies: Required for the essential functions of the site (session, security, CSRF protection); used without obtaining consent.
- Functional Cookies: Used to remember your preferences (language, display).
- Analytics Cookies: For site usage statistics (Google Analytics, etc.) — used with your explicit consent.
- Marketing Cookies: For advertising and remarketing — used with your explicit consent.
14. Child Users
The SignLogger product and our website are intended for professional users and are not aimed at persons under the age of 18. We do not knowingly collect personal data from persons under the age of 18. If you become aware of such a situation, please contact us immediately at kvkk@sysnet.com.tr.
15. Amendments to the Disclosure Notice
Our Company may update this disclosure notice where it deems necessary and in line with changes in legislation. The current text is always accessible on our website. Significant changes are additionally announced by e-mail or site notification.
Last updated: 2026-05-25
16. Contact
You may direct any questions, opinions and requests regarding this disclosure notice or the processing of your personal data to:
- E-mail: kvkk@sysnet.com.tr
- General contact: info@sysnet.com.tr
- Post: Sysnet Yazılım ve Bilgi Teknolojileri Ltd. Şti., İstanbul / Türkiye
- Web: https://signlogger.com/contact