Copron Teknoloji Hizmetleri LTD. ŞTİ.  ·  Database & Technology Consulting TR | EN
Copron Tech
Legal Notice

Privacy Policy

We manage mission-critical data infrastructures. Privacy is therefore a professional responsibility for us rather than a mere compliance obligation. This policy explains for what purposes Copron processes your and your clients’ personal data, how we protect it and how you can exercise your rights.

Effective Date
1 August 2026
Last Updated
31 July 2026
Version
v1.0
Scope
KVKK & GDPR
01

Scope and Parties

Copron Teknoloji Hizmetleri LTD. ŞTİ. (“Copron”, the “Company” or “we”) provides database management, database health checks, migration and modernization, scalable architecture planning and technology consulting services. This Privacy Policy concerns the processing of personal data of:

  • visitors to www.copron.com.tr,
  • our clients and prospective clients, and their employees and representatives,
  • the relevant personnel of our suppliers, partners and sub-processors,
  • our job applicants, employees and interns,
  • data subjects whose data resides in client databases we access while delivering our services.

For personal data residing in client systems we access during consulting engagements we act, as a rule, as a data processor; our client (the controller) determines the purposes and means of processing. In that case data-subject requests should be addressed to the client as controller, and we assist only on the client’s documented instructions.

02

Identity of the Data Controller

The data controller under Turkish Personal Data Protection Law No. 6698 (“KVKK”) is:

Legal name Copron Teknoloji Hizmetleri LTD. ŞTİ.
Address Fatih Sultan Mehmet Mah. Balkan Cad. Meydan İstanbul AVM No: 62/A Ümraniye / İstanbul
Website www.copron.com.tr
03

Personal Data We Process

We process only the data the service requires. Data minimization is a core principle for our technical teams.

Identity and Contact Data
Name, surname, role/title, company name, work email address, phone number, signature (in proposal and contract processes).
Customer Transaction and Finance Data
Proposal and contract records, service requests, support/incident records, invoicing and payment details, account transactions.
Transaction Security and Log Data
User names, privilege records, VPN/jump-host session data, database audit logs, IP addresses, timestamps, query and access records.
Technical Website Data
Pages visited, session duration, referrer, browser and device information, cookie identifiers.
Candidate and HR Data
CV, education and certification details (Oracle, PostgreSQL, MongoDB, cloud certifications), technical assessment results, references.
Data in Client Systems
Data that may be encountered in client databases while services are delivered. We do not seek to inspect, copy or export such data; access occurs only where technically necessary and on the client’s instruction.

As a rule we do not request special categories of personal data (health, biometric data, etc.). Where such data exists in client systems, access is granted only where strictly necessary and under masking and additional safeguards.

04

Our Processing Purposes

Service deliveryPlanning and delivering database management, health check, migration, modernization and architecture consulting services.
Contract processesPreparing proposals, concluding and performing contracts, invoicing and collection.
Support and incident managementRecording, resolving and reporting fault, performance and security incidents.
Information securityPreventing unauthorized access, keeping audit trails, log management and incident response.
Communication and marketingResponding to form and email requests and informing you about our services (with explicit consent where required).
Legal obligationsMeeting retention and notification duties arising from tax, commercial and labour law.
05

Legal Bases

We process personal data on the legal bases set out in Articles 5 and 6 of the KVKK:

Legal basis
Where it applies
Conclusion and performance of a contract
Service delivery, project execution, support, invoicing.
Legal obligation
Accounting and tax records, statutory log keeping.
Legitimate interest
Information security, audit trails, measuring service quality, corporate communication.
Establishment and protection of rights
Retaining evidence in disputes and claims.
Explicit consent
Non-essential cookies, commercial electronic messages, retention in the candidate pool.
06

Our Client-System Access Principles

Database consulting inherently requires access to the systems holding our clients’ most sensitive data. We govern that access with the following binding principles:

01 Least privilegeOur teams receive time-limited privileges only at the object and schema level the task requires. Instead of permanent administrator accounts we use request-based, time-bound access.
02 Masking instead of live dataFor test, development and performance work we request masked or synthetic data instead of live personal data.
03 Auditable accessAccess is made through the client’s VPN or jump host; sessions and executed operations are logged.
04 No data movementBackups, dumps and exports are never moved into Copron’s environment without client approval. Where unavoidable, encrypted transfer is used and the data is securely deleted once the work is complete.
05 Contractual confidentialityAll our employees and sub-processors are bound by confidentiality undertakings (NDAs); we sign data processing agreements with clients under KVKK Art. 8 and GDPR Art. 28.
07

Transfers and Sub-processors

We do not sell personal data. We may transfer data, strictly limited to the purpose and subject to the necessary security undertakings, to: competent public authorities, accountants and independent auditors, our lawyers, banks and payment institutions, cloud infrastructure and hosting providers, email and office software providers, support and ticketing systems, and specialist sub-processors engaged on a project basis.

Servers of cloud and software providers may be located abroad. In that case transfers are made under KVKK Art. 9 using appropriate mechanisms such as an adequacy decision, standard contractual clauses or binding corporate rules, and otherwise on the basis of your explicit consent. Where possible we prefer hosting data in regions within Türkiye.

Use of sub-processors is subject to the prior notification and approval terms of the agreements signed with our clients.

08

Cookies

Our website uses cookies that are strictly necessary for the site to function, plus analytics cookies that depend on your consent. Non-essential cookies are not executed unless you consent via the cookie notice. You can delete or block cookies at any time in your browser settings.

Type
Purpose
Duration
Strictly necessary
Session management, language preference, security and form submission.
Session – 12 months
Analytics
Visit statistics and page performance improvement (aggregated, anonymous reporting).
Up to 24 months
Functional
Displaying embedded content and map components.
Up to 12 months
09

Retention Periods

We delete, destroy or anonymize data once the processing purpose ceases and the maximum statutory periods expire.

Contract, proposal and accounting records
10 years from the end of the legal relationship
Support and incident records
Term of service + 3 years
Access and audit logs
2 years (longer where legislation requires)
Contact form and email requests
1 year after the request is closed
Job applications
2 years with explicit consent, otherwise deleted at the end of the process
10

Data Security Measures

Technical
  • Encryption in transit and at rest (TLS, TDE / disk encryption)
  • Multi-factor authentication and centralized privilege management
  • Privileged access management and password vaulting
  • Database audit trails and log correlation
  • Backups, restore testing and a business continuity plan
  • Endpoint protection and current patch management
Organizational
  • Privacy and information security policies, NDA obligations
  • Role-based access matrix and periodic privilege reviews
  • Staff awareness and data protection training
  • Sub-processor assessment and contractual audit rights
  • Data breach response plan: notification to the authority and data subjects as soon as possible and within 72 hours
  • Retention and destruction policy with periodic destruction
11

Your Rights as a Data Subject

Under Article 11 of the KVKK you have the following rights:

a.To learn whether your personal data is processed and, if so, to request information about it.
b.To learn the purpose of processing and whether the data is used in line with that purpose.
c.To know the third parties to whom data is transferred domestically or abroad.
d.To request rectification of incomplete or inaccurate data.
e.To request erasure or destruction of the data where the conditions are met.
f.To request that rectification, erasure and destruction be notified to third parties to whom data was transferred.
g.To object to an adverse outcome arising from analysis carried out solely by automated systems.
h.To claim compensation for damage suffered due to unlawful processing.
For data subjects located in the European Union
For activities within the scope of the GDPR you may also exercise the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability and objection. Where processing is based on consent you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
12

How to Submit a Request

You may submit requests in line with the Turkish Communiqué on Application Procedures to the Data Controller. We respond within 30 days free of charge; where the action entails additional cost, the fee in the Authority’s tariff may be charged.

E-postaFrom the email address registered in our systems, to kvkk@copron.com.tr .
Written applicationA wet-signed petition sent to our company address with identity documents, or via a notary.
Registered email / e-signatureAn application signed with a secure electronic signature sent to our registered electronic mail address.

Including your name, contact details, the subject of the request and any client/project reference helps us resolve it faster.

13

Changes to This Policy

We may revise this policy in light of legal developments, changes to our services or updates to our security practices. The current version is always published on this page; for material changes the version number and update date are changed and, where necessary, separate notice is given.

Have a question about privacy?

Our data protection contact is ready to answer questions on corporate compliance and data processing agreements.

Contact Us