KVKK and GDPR Compliance Statement
This document explains which data we process and for what purpose while providing the email security service, how long we keep it and which technical measures we apply. In one sentence: email content is never stored permanently, the data we process never leaves Turkey, and the technical records we do keep are deleted automatically within 90 days at the latest.
Data minimisation and purpose limitation
An email security service has to see messages in order to do its job. The real question is not whether it sees them, but how long it keeps what it sees and what it uses it for.
- Only the data needed: only the minimum data required to provide the service is processed. No data is collected for marketing, profiling or training purposes.
- Only the stated purpose: data is not used for any purpose beyond technical delivery, spam filtering, threat analysis and delivery verification.
- Content is not kept: email content is evaluated at the moment of filtering and is not stored permanently. What is retained is technical log data, not content.
- Deleted when the period ends: records past their retention period are deleted automatically; deletion is not a manual decision.
Who is the controller and who is the processor?
This distinction is not just a legal label; it determines which side carries which obligation and where a data subject should apply.
Our undertakings as processor
- We do not store email content permanently.
- We process only header information and technical log data.
- We do not use the data for any purpose outside the contract.
- We do not share or sell the data to third parties.
- If a sub-processor is to be used, we notify the controller in writing beforehand.
This page is for information. The binding text between the parties is the Data Processing Agreement signed alongside the service contract; in the event of a conflict, that document prevails.
Which data is processed, and for how long?
The top row is the most important one in this table: email content is processed but not stored. The technical data in the rows below forms the reasoning behind a filtering decision and the delivery record.
| Data type | Processed? | Stored? | Retention |
|---|---|---|---|
| Email content | During filtering, in the moment | Not stored | None |
| Header information | Yes | Yes | 30 – 90 days |
| IP address | Yes | Yes | 30 – 90 days |
| SPF, DKIM and DMARC results | Yes | Yes | 90 days |
| Quarantined message | Yes | Depending on the customer’s choice | 7 – 30 days |
Retention periods are upper limits; when a period ends the record is deleted by a scheduled job. For quarantined messages the period follows the customer’s choice in the panel, and the message is deleted when that period ends.
Data is processed in Turkey and stays in Turkey
The question asked most often under KVKK is whether data is transferred abroad. Our answer is clear: it is not.
- Place of processing: traffic is processed in an in-country data center. Filtering, queuing and delivery all take place in Turkey.
- Place of storage: technical logs, the quarantine and backups are held in-country. Redundancy is provided in-country as well.
- Transfer abroad: none. For that reason you do not have to run a separate permission or undertaking process under the transfer provisions of KVKK.
- Evidence for audits: the purpose, duration, retention terms and sub-processor information are shared in writing for your audits.
The concrete measures taken to protect the data
The measures below are not declarations but the architecture itself: content never touching disk, or deletion running as a scheduled job, is how the system works rather than a policy added later.
Content is never written to disk
Email content is processed in memory only and leaves memory when filtering ends. The only thing written to disk is technical log data, never the content.
Logs sit on a separate server, encrypted
Technical logs are held on a separate log server and encrypted on disk with AES-256. Access to the logs is limited by role-based authorisation.
Customers are isolated from each other
In a multi-tenant setup each customer’s data is logically separated per domain. A customer can reach only their own traffic and their own records.
Encryption in transit and on access
Inbound and outbound connections are encrypted with TLS. Two-factor authentication is mandatory for administrator access to the log server.
Administrator actions are recorded
Actions taken by administrator accounts are written to an audit trail. API access is rate limited and tracked in the same record.
Deletion runs automatically
Records past their retention period are deleted automatically by scheduled jobs; deletion is not left to a manual decision. On export, IP addresses can be anonymised on request.
What happens if there is a breach?
As a processor our notification obligation runs to the controller; notifying the authority and the individuals concerned is the controller’s task. Our job is to give it what it needs, without delay, so it can do that in time.
- 72 hours: the controller is informed within 72 hours of the breach becoming known at the latest.
- What the notice contains: the nature of the breach, the categories of data affected and the approximate number of records, its likely consequences, and the measures taken or proposed.
- Afterwards: the technical information and records needed for the controller’s notification to the authority and to the individuals are provided without delay.
- Root cause: the cause of the incident and the measures taken to prevent a recurrence are reported in writing.
Your rights under Article 11 of KVKK
Everyone whose personal data is processed has the rights below. They largely correspond to their counterparts under GDPR.
- Learn whether their personal data is being processed
- Request information if it has been processed
- Learn the purpose of processing and whether the data is used accordingly
- Know the third parties to whom the data is transferred, in Turkey or abroad
- Request correction where data is incomplete or inaccurate
- Request erasure or destruction where the conditions are met
- Request that correction, erasure and destruction be notified to the third parties the data was transferred to
- Object to an adverse outcome arising solely from automated analysis
- Claim compensation for damage suffered as a result of unlawful processing
Enquiries about this document
- İnetmar İnternet Hizmetleri Bil. Tek. San. Tic. Ltd. Şti.
- Mansuroğlu Mah, 286/1 Sokak No:16, Bayraklı / İzmir
- +90 850 455 35 01
- destek@mxgate.com.tr · for questions about processing, the DPA and sub-processors
- Changes to this statement are published on this page; changes affecting the basis of processing are also notified to the controller.