Skip to content
KVKK & GDPR Compliant Turkey Data Center 24/7 Technical Support destek@mxgate.com.tr
New: IP reputation monitoring is now free on every plan Start your 14-day free trial →
LEGAL DOCUMENT · KVKK AND GDPR

KVKK and GDPR Compliance Statement

This document explains which data we process and for what purpose while providing the email security service, how long we keep it and which technical measures we apply. In one sentence: email content is never stored permanently, the data we process never leaves Turkey, and the technical records we do keep are deleted automatically within 90 days at the latest.

In force since
02.2026
Our role
Data processor
Data location
Turkey; no transfer abroad
Max. retention
90 days
1 · CORE PRINCIPLE

Data minimisation and purpose limitation

An email security service has to see messages in order to do its job. The real question is not whether it sees them, but how long it keeps what it sees and what it uses it for.

2 · PARTIES AND ROLES

Who is the controller and who is the processor?

This distinction is not just a legal label; it determines which side carries which obligation and where a data subject should apply.

Controller The customer organisation The party that determines the purpose and means for its own users’ and correspondents’ personal data. The duty to inform, consent management and responding to data subject applications belong to it.
Processor MXGate İnetmar İnternet Hizmetleri Bil. Tek. San. Tic. Ltd. Şti. Processes data only on the controller’s instructions and within the limits the contract draws. It does not set a purpose of its own, does not use the data for anything else and does not share it with third parties.
3 · DATA PROCESSED AND RETENTION

Which data is processed, and for how long?

The top row is the most important one in this table: email content is processed but not stored. The technical data in the rows below forms the reasoning behind a filtering decision and the delivery record.

Data type Processed? Stored? Retention
Email content During filtering, in the moment Not stored None
Header information Yes Yes 30 – 90 days
IP address Yes Yes 30 – 90 days
SPF, DKIM and DMARC results Yes Yes 90 days
Quarantined message Yes Depending on the customer’s choice 7 – 30 days

Retention periods are upper limits; when a period ends the record is deleted by a scheduled job. For quarantined messages the period follows the customer’s choice in the panel, and the message is deleted when that period ends.

4 · WHERE THE DATA SITS

Data is processed in Turkey and stays in Turkey

The question asked most often under KVKK is whether data is transferred abroad. Our answer is clear: it is not.

Side by side with other providers: the comparison table Backup and recovery commitments: the SLA, section 4
5 · TECHNICAL AND ORGANISATIONAL MEASURES

The concrete measures taken to protect the data

The measures below are not declarations but the architecture itself: content never touching disk, or deletion running as a scheduled job, is how the system works rather than a policy added later.

Content is never written to disk

Email content is processed in memory only and leaves memory when filtering ends. The only thing written to disk is technical log data, never the content.

Logs sit on a separate server, encrypted

Technical logs are held on a separate log server and encrypted on disk with AES-256. Access to the logs is limited by role-based authorisation.

Customers are isolated from each other

In a multi-tenant setup each customer’s data is logically separated per domain. A customer can reach only their own traffic and their own records.

Encryption in transit and on access

Inbound and outbound connections are encrypted with TLS. Two-factor authentication is mandatory for administrator access to the log server.

Administrator actions are recorded

Actions taken by administrator accounts are written to an audit trail. API access is rate limited and tracked in the same record.

Deletion runs automatically

Records past their retention period are deleted automatically by scheduled jobs; deletion is not left to a manual decision. On export, IP addresses can be anonymised on request.

6 · BREACH NOTIFICATION

What happens if there is a breach?

As a processor our notification obligation runs to the controller; notifying the authority and the individuals concerned is the controller’s task. Our job is to give it what it needs, without delay, so it can do that in time.

7 · DATA SUBJECT RIGHTS

Your rights under Article 11 of KVKK

Everyone whose personal data is processed has the rights below. They largely correspond to their counterparts under GDPR.

8 · APPLICATIONS AND CONTACT

Enquiries about this document

Ask a Data Privacy Question Service Level Agreement
In force since: · Last updated: · İnetmar İnternet Hizmetleri Bil. Tek. San. Tic. Ltd. Şti.