X
X
X
X

EAK KVKK Privacy Notice

HomepageEAK KVKK Privacy Notice

EAK KVKK Privacy Notice

Last Updated: 9 September 2026

1. Data Controller

For the purposes of Turkish Personal Data Protection Law No. 6698 (“KVKK”), the data controller is:

EAK Elektronik Bilgisayar İnternet ve İletişim Hizmetleri Sanayi ve Ticaret Limited Şirketi (“EAK”).

Personal data obtained in connection with the use of services provided by EAK is processed for the purposes and on the legal grounds described in this Privacy Notice.

This Notice applies to individuals who:

  • visit EAK websites,
  • create a customer account,
  • purchase products or services,
  • act as representatives or authorised persons of corporate customers,
  • communicate with EAK through support or other communication channels.

2. Categories of Personal Data Processed

Depending on the nature of the service or relationship with EAK, the following categories of personal data may be processed.

Identity Information

This may include:

  • first name,
  • surname,
  • Turkish Republic identification number (T.C. Kimlik No),
  • tax identification number,
  • company or business information,
  • information relating to authorised representatives.

Identity information is collected only where required for the relevant service, invoicing, customer verification or compliance with applicable legal obligations.

Contact Information

This may include:

  • e-mail address,
  • telephone number,
  • postal address,
  • billing address.

Customer and Service Information

This may include:

  • customer number,
  • purchased products and services,
  • domain names,
  • assigned IP addresses,
  • server and hosting information,
  • quotations and contractual records,
  • transactions performed through the customer panel,
  • service status and service history.

Financial and Billing Information

This may include:

  • invoice information,
  • payment date,
  • payment amount,
  • payment method,
  • bank or payment transaction reference information.

EAK does not store full credit or debit card numbers, CVV/CVC security codes or similar card authentication information.

Where card payments are used, payment processing is performed through the secure infrastructure of the relevant bank or payment service provider.

Support and Communication Records

This may include:

  • support requests,
  • support ticket content,
  • written correspondence with EAK,
  • fault and technical support records,
  • records of technical actions performed in connection with a service.

EAK does not routinely record the audio content of telephone calls.

Technical and Transaction Security Data

Depending on the nature of the service, technical data may include:

  • IP addresses,
  • connection timestamps,
  • session information,
  • login and logout records,
  • browser and device information,
  • server and service logs,
  • security events,
  • error logs,
  • abuse and attack records.

Such data may be processed to maintain service security, investigate incidents, resolve technical problems and comply with applicable legal obligations.


3. Purposes of Processing Personal Data

EAK may process personal data for the following purposes:

  • creating and managing customer accounts,
  • receiving orders and activating services,
  • providing hosting, VPS/VDS, dedicated server, corporate e-mail, domain name and other services,
  • carrying out service renewal and termination procedures,
  • verifying customer identity or corporate authority where necessary,
  • issuing invoices and maintaining accounting records,
  • monitoring payment transactions,
  • responding to customer support requests,
  • investigating and resolving technical problems,
  • maintaining system and network security,
  • detecting unauthorised access, fraud, spam, abuse, malware and attacks,
  • maintaining service continuity,
  • investigating information security incidents,
  • fulfilling contractual rights and obligations,
  • complying with applicable legal and regulatory obligations,
  • responding to lawful requests from competent public authorities,
  • resolving disputes and protecting legal rights.

Personal data shall not be processed for purposes that are incompatible with the purpose for which the data was originally obtained.


4. Legal Grounds for Processing Personal Data

Personal data is processed on the legal grounds applicable to the relevant processing activity under Article 5 of KVKK.

These grounds principally include the following.

Processing Required by Law

Personal data may be processed where necessary for compliance with legal obligations relating to matters including:

  • invoicing,
  • accounting,
  • taxation,
  • telecommunications and internet services,
  • information security,
  • lawful requests from competent authorities.

Processing Necessary for the Establishment or Performance of a Contract

Personal data may be processed where directly necessary for the establishment or performance of a contract.

This includes activities such as:

  • creating a customer account,
  • receiving and processing orders,
  • activating services,
  • maintaining service records,
  • providing technical support,
  • processing service renewals and termination.

Processing Necessary for Compliance with a Legal Obligation

EAK may process personal data where processing is necessary for EAK to comply with its legal obligations.

Establishment, Exercise or Protection of a Legal Right

Necessary records may be processed and retained for purposes including:

  • resolving disputes,
  • monitoring receivables,
  • examining service and support history,
  • establishing, exercising or protecting legal rights.

Legitimate Interests of the Data Controller

Provided that the fundamental rights and freedoms of the data subject are not adversely affected, limited processing may be carried out for legitimate interests including:

  • maintaining information security,
  • preventing misuse of systems,
  • detecting fraud,
  • investigating technical incidents,
  • protecting service quality and infrastructure.

Explicit Consent

Where explicit consent is legally required for a specific processing activity, such consent shall be obtained separately.

Providing this Privacy Notice does not constitute obtaining explicit consent.

The information process and any explicit consent process shall be carried out separately in accordance with applicable law.


5. Methods of Collecting Personal Data

Personal data may be collected through:

  • EAK websites,
  • customer panels,
  • online order forms,
  • support systems,
  • e-mail communications,
  • information provided during telephone communications,
  • quotations and contractual processes,
  • transaction information received in connection with banking or payment processes,
  • server, network and security systems,
  • web and application logs.

Personal data may be collected electronically or, where necessary, physically and may be processed by automated, partially automated or non-automated means where such processing forms part of a data filing system.


6. Transfer of Personal Data

EAK transfers personal data only to the extent necessary for the relevant processing purpose and in accordance with applicable legislation.

Personal data may be transferred to the following categories of recipients.

Competent Public Authorities

Where required by law or pursuant to a lawful request, necessary information may be provided, to the extent permitted or required by applicable law, to authorities including:

  • courts,
  • public prosecutors,
  • law enforcement authorities,
  • the Information and Communication Technologies Authority (BTK),
  • tax authorities,
  • other legally authorised public institutions and organisations.

Accounting, Financial and Legal Service Providers

Necessary personal data may be shared with authorised service providers for:

  • accounting,
  • taxation,
  • financial reporting,
  • auditing,
  • legal proceedings and legal advice.

Banks and Payment Service Providers

Information required for payment processing, transaction verification and accounting may be processed or shared with the relevant bank or payment service provider.

Domain Name and Other Third-Party Service Providers

Where the Customer purchases a:

  • domain name,
  • SSL certificate,
  • software licence,
  • or another third-party service,

information necessary to provide that service may be transferred to the relevant:

  • registry,
  • registrar,
  • certificate authority,
  • manufacturer,
  • service provider.

Such transfers are limited to information necessary for providing the relevant service.


7. Location of EAK Infrastructure

EAK's core customer management, hosting, server and service infrastructure is primarily operated on systems controlled by EAK and located in Türkiye.

As a general principle, core customer account and service operation data is maintained within EAK's own infrastructure.

Certain external services used by EAK may, however, involve international infrastructure as explained below.


8. Cloudflare and International Data Transfers

EAK may use Cloudflare services for purposes including:

  • DNS,
  • content delivery,
  • DDoS protection,
  • web application security,
  • performance optimisation.

As a result, limited technical data such as:

  • IP addresses,
  • HTTP request information,
  • browser information,
  • security events,
  • connection metadata

may be processed through Cloudflare infrastructure.

Due to the global nature of Cloudflare's infrastructure, such technical data may be processed on, or made accessible through, systems located outside Türkiye.

Any international transfer of personal data shall be carried out in accordance with the provisions of KVKK governing transfers of personal data abroad and through an applicable lawful transfer mechanism.


9. Credit and Debit Card Data

EAK does not store:

  • full credit or debit card numbers,
  • CVV/CVC security codes,
  • card passwords or PINs

within its own systems.

Where payment by card is available, payment information may be processed directly through the infrastructure of the relevant bank or payment service provider.

EAK may process limited transaction information necessary for payment administration, such as:

  • payment status,
  • transaction amount,
  • transaction date,
  • transaction reference.

10. Support Records

Support requests, responses and records of technical actions performed through the EAK customer support system may be retained for purposes including:

  • maintaining service history,
  • investigating recurring technical issues,
  • information security,
  • protecting contractual and legal rights,
  • resolving disputes.

Customers are advised not to submit passwords, credit card details or special categories of personal data through support tickets unless strictly necessary and specifically requested through an appropriate secure process.


11. Telephone Communications

Telephone conversations with EAK are not routinely audio-recorded.

If EAK introduces a call-recording system in the future, callers shall be appropriately informed before recording begins and the necessary procedures under applicable personal data protection legislation shall be implemented.


12. Retention of Personal Data

Personal data is retained for the period necessary for the purposes for which it is processed and in accordance with applicable statutory retention requirements.

When determining retention periods, EAK may take into account:

  • whether the service relationship remains active,
  • contractual obligations,
  • accounting and taxation requirements,
  • applicable limitation periods,
  • information security requirements,
  • obligations arising from requests of competent authorities.

Where the purpose of processing and the applicable legal basis for retention cease to exist, personal data shall be deleted, destroyed or anonymised in accordance with applicable legislation.


13. Service and Traffic Records

EAK may process certain technical and traffic records for purposes including:

  • maintaining service security,
  • operating infrastructure,
  • preventing abuse,
  • complying with applicable legal obligations.

The scope and retention period of such records depend on the relevant service and the legal obligations applicable to EAK.

EAK does not use technical logging as a means of unnecessary or general monitoring of Customer content.

The existence of technical logging shall not be interpreted as meaning that EAK routinely records HTTP POST bodies, customer passwords, e-mail content or similar communications content.


14. Information Security

EAK implements reasonable technical and organisational measures appropriate to the nature of the personal data processed.

Depending on the relevant system or service, these measures may include:

  • access controls,
  • network security measures,
  • firewalls,
  • access logging,
  • backup systems,
  • malicious traffic filtering,
  • restrictions on administrative privileges.

Access to personal data is limited according to operational requirements and authorisation levels.


15. Rights of the Data Subject Under KVKK

Pursuant to Article 11 of KVKK, data subjects have the right to apply to EAK and:

  • learn whether their personal data is being processed,
  • request information where personal data has been processed,
  • learn the purpose of processing and whether the data is being used in accordance with that purpose,
  • learn the third parties to whom personal data has been transferred in Türkiye or abroad,
  • request correction where personal data has been processed incompletely or inaccurately,
  • request deletion or destruction of personal data under the conditions provided by law,
  • request notification of correction, deletion or destruction to third parties to whom the personal data has been transferred,
  • object to a result arising against the individual through analysis exclusively by automated systems,
  • request compensation where damage has been suffered as a result of unlawful processing of personal data.

16. Applications Concerning Personal Data

Data subjects may submit requests concerning their rights under KVKK to EAK using the methods permitted by applicable legislation.

Requests may be submitted by e-mail to:

kvkk@eak.com.tr

The request should contain sufficient information to identify the applicant and understand the request, including where appropriate:

  • first name and surname,
  • information sufficient to verify the applicant's identity,
  • subject of the request,
  • relevant customer or service information, where applicable,
  • contact details through which the applicant wishes to receive a response.

EAK may request additional information where reasonably necessary to verify the identity of the applicant and protect personal data against unauthorised disclosure.

Applications shall be evaluated and answered within the periods prescribed by KVKK and applicable legislation.

Requests may also be submitted through other application methods recognised under applicable legislation.


17. Updates to this Privacy Notice

EAK may update this Privacy Notice where:

  • personal data processing activities change,
  • new services are introduced,
  • infrastructure or service providers change,
  • applicable legislation changes.

The current version shall be published on the EAK website.

Where a new processing activity requires separate information to be provided to data subjects, the relevant information shall be provided separately.


18. Entry into Force

This KVKK Privacy Notice was last updated on 9 September 2026.

Data Controller

EAK Elektronik Bilgisayar İnternet ve İletişim Hizmetleri Sanayi ve Ticaret Limited Şirketi

KVKK Contact:
kvkk@eak.com.tr


Language and Interpretation

This English version is provided for the convenience of international customers.

The official and original version of this Privacy Notice is the Turkish version.

In the event of any discrepancy, inconsistency or difference of interpretation between the Turkish and English versions, the Turkish version shall prevail, to the extent permitted by applicable mandatory law.


Powered by WISECP
Top