KVKK & GDPR Compliant Turkey Data Center 24/7 Support
+90 850 455 35 01 | destek@mxgate.com.tr
MXGate
Türkçe Contact

DATA PROTECTION NOTICE

In accordance with applicable data protection regulations (GDPR), we fulfill our obligation to inform you about the processing of your personal data.

1. DATA CONTROLLER INFORMATION

  • Company Name: İnetmar İnternet Hizmetleri Bil. Tek. San. Tic. Ltd. Şti.
  • Address: Mansuroglu Mah, 286/1 Sokak No:16, Bayrakli / Izmir, Turkey
  • Email: privacy@mxgate.com.tr
  • Phone: +90 850 455 35 01

2. DATA PROCESSOR INFORMATION

MXGate acts as a Data Processor in the context of Email Security Gateway services. The Customer (the organization using the service) is the Data Controller for their employees'/users' data.

3. PERSONAL DATA CATEGORIES PROCESSED

3.1 Directly Collected Data (Customer Account Information)

Data CategoryExample Data
Identity InformationFirst name, last name, title
Contact InformationEmail address, phone number, address
Corporate InformationCompany name, tax number
Account InformationUsername, password (encrypted), IP address

3.2 Data Processed During Email Gateway Service

Data TypeDescriptionContent Read?
Email MetadataSender, recipient, CC, BCC, subject, timestamp, sizeYes (for security scanning)
Email ContentEmail body textYes (only during security scanning)
Email AttachmentsDocuments, archive filesYes (for malware scanning)
Security LogsDetected threats, quarantine recordsNo (automatically generated)

Important Note: MXGate processes email content solely for security scanning (spam, phishing, malware detection). Contents are scanned by automated systems without human reading. Content is not stored after scanning (unless archiving service is purchased).

4. PURPOSES OF PERSONAL DATA PROCESSING

Processing PurposeLegal BasisDescription
Service DeliveryContract performanceEmail traffic routing and security scanning
Security and ProtectionLegal obligationPrevention of cyber threats, phishing and malware detection
BillingLegal obligationInvoice preparation in accordance with tax regulations
ArchivingLegal obligationRetention of commercial records
Technical SupportContract performanceProblem resolution and customer support

5. SCANNING AND PROCESSING OF EMAIL CONTENT

5.1 Security Scanning Process

  • Entry Control: IP/reputation check, blacklist verification
  • Header Analysis: SPF, DKIM, DMARC validation
  • Content Scanning: Spam filtering, phishing detection
  • Attachment Scanning: Malware scanning (sandbox)
  • Data Leakage Control: DLP (Data Loss Prevention) rules

5.2 Automated Processing and Human Intervention

  • All scanning operations are performed by automated systems
  • Email contents are not read by MXGate employees
  • Access is only provided upon customer request and solely for support purposes
  • Quarantined suspicious content is managed at the customer's own discretion

6. DATA RETENTION PERIODS AND ARCHIVING POLICY

6.1 Retention Periods

Data CategoryRetention PeriodRetention Reason
Account and Contact InformationContract period + 10 yearsLegal obligations
Email Metadata (Logs)30 days (default)Security and problem resolution
Security Logs1 yearThreat analysis and audit
Archived Emails*Customer-defined (min. 5 years)Legal archiving obligation

* Archiving service is valid when purchased separately.

6.2 Data Anonymization Policy

Data whose retention period has expired:

  • Is completely deleted (secure deletion - NIST 800-88 standard)
  • Or is anonymized and retained for statistical analysis purposes
  • Anonymized data cannot be associated with an identified or identifiable person

7. DATA TRANSFERS AND THIRD PARTIES

7.1 Data Not Sold

MXGate does not:

  • Sell your personal data under any circumstances
  • Share data with third parties for marketing purposes
  • Use data for commercial purposes without your permission

7.2 Service Provider Transfers

Limited data transfer may occur in the following cases:

  • Cloud infrastructure provider (encrypted data)
  • Payment institutions (billing information)
  • Security databases (hash values, IPs for threat intelligence)

7.3 International Data Transfers

MXGate does not transfer personal data outside Turkey. All data processing activities are carried out on servers located in Turkey.

8. DATA SECURITY MEASURES

8.1 Technical Measures

  • Encryption: TLS 1.3 for transmission, AES-256 for data encryption
  • Access Control: Role-based access control (RBAC), multi-factor authentication
  • Network Security: Firewall, IDS/IPS, DDoS protection
  • Data Masking: Masking and tokenization of sensitive data

9. DATA SUBJECT RIGHTS (GDPR)

Under applicable data protection regulations, you have the following rights:

RightDescription
Right to AccessObtain confirmation and information about your personal data processing
Right to RectificationRequest correction of inaccurate personal data
Right to ErasureRequest deletion of personal data under certain conditions
Right to Restrict ProcessingRequest restriction of processing under certain conditions
Right to Data PortabilityReceive your data in a structured, machine-readable format
Right to ObjectObject to processing based on legitimate interests or direct marketing

9.1 Exercising Your Rights

To exercise your rights, please contact us:

  • Email: privacy@mxgate.com.tr
  • Subject: Data Subject Rights Request

Requests will be processed free of charge within 30 days.

10. COOKIE POLICY

10.1 Cookies Used

Cookie TypeCookie NamePurposeDuration
Necessarysession_id, csrf_tokenSession management, securitySession / 1 year
Preferenceslanguage, themeLanguage and theme preferences1 year
Analytics_ga, _gid (Google Analytics)Website usage analysis2 years / 24 hours
Marketing_fbp (Facebook Pixel)Advertising targeting3 months

10.2 Cookie Management

You can manage your cookie preferences through your browser settings:

  • You can reject all cookies except necessary ones
  • You can disable cookies completely in your browser settings

11. PERSONAL DATA BREACH NOTIFICATION

In the event of a personal data breach:

  • Authority Notification: Relevant authorities will be notified within 72 hours
  • Data Subject Notification: You will be immediately notified of breaches with adverse consequences
  • Measures: Necessary technical and administrative measures will be taken after notification

12. POLICY CHANGES

We may update this privacy policy in accordance with legal regulations and service changes. Significant changes:

  • Will be notified by email
  • Will be published on our website 30 days in advance
  • Will appear as a notification in your account panel

13. CONTACT

Data Subject Request Address:

İnetmar İnternet Hizmetleri Bil. Tek. San. Tic. Ltd. Şti.

Bayrakli / Izmir, Turkey

Email: privacy@mxgate.com.tr

Phone: +90 850 455 35 01

This privacy policy last updated: February 2026. For your data protection rights, please use the contact information above.

1000+ enterprise customers
trust MXGate