KVKK Clarification Text

Within the scope of the Law on the Protection of Personal Data No. 6698

Last Updated: June 25, 2026

1. Data Controller

Within the scope of the Personal Data Protection Law No. 6698 ("KVKK"), your personal data is processed by SİBERLOCK Cyber Security and Consultancy Services ("Company") as the data controller for the purposes and legal reasons explained below.

Malazgirt District, Sarayburnu St. No:46, Apt:103, 42060 Selcuklu/Konya
+90 (332) 606 24 01

2. Processed Personal Data

Your following personal data is processed via our website:

📋 Identity Information

Name, surname, title, company/firm name; in paid services, contracts and invoicing processes (especially in the data recovery device delivery report) Turkish ID Number and/or Tax Number

📧 Contact Information

Email address, phone number, postal/billing address and other contact information you provide via the form

💻 Technical Data

IP address, browser information, cookie data, device fingerprint (FingerprintJS for security purposes)

🔒 Security Analysis Data

Screenshots, descriptions and cyber incident information sent via the "Under Attack" form

🛡️ Security Verification Data

Cloudflare Turnstile captcha solution data (for bot protection)

📊 Usage Data

Page views, quote request form information, service preferences

🤖 AI Assistant (ALISA) Chat History

Your chat history with our AI assistant (ALISA) is processed and matched with a visitor ID to provide support and detect malicious usage.

🔍 Free File Analysis Tool data

Under our free File Analysis Tool: content of the file you upload or digests derived from it, file name and type, size, MIME/technical metadata; multi-engine antivirus results and risk scoring; one-time access tokens for report download; where offered, data related to extended threat intelligence; and IP, session/rate limit and security logs to secure the service and prevent abuse. If your file contains special categories of personal data, Article 6 of the KVKK may apply; you must not upload such data knowingly.

🧾 Customer Transaction Data

Request, quote and complaint records; order and service history; call center/communication records and transaction information generated during the service process

💳 Financial Data

In data recovery and other paid services: service fee, invoice details, payment method and bank/IBAN information, and payment/transaction records

🖼️ Visual and Audio Records

Photos, videos and audio recordings shared by you or created as part of the process during service and support (e.g. images regarding device/delivery condition, phone call recordings)

🛠️ Data Recovery and Device Content Data

Identifying information about the device/media (disk, SSD, RAID, memory card, etc.) delivered to us within the scope of the data recovery service, and the data contained in and recovered from this device/media. This content may include special category personal data such as health, biometric data, religion, race and sexual life (KVKK art.6), and processing in this scope relies on your explicit consent. For details, please review the "Information Notices Within the Scope of Data Recovery Services" section at the bottom of this page.

📨 Marketing / Newsletter Data

If you subscribe to our newsletter and campaign notifications, your email address along with your message preferences and consent records. Commercial electronic messages are sent only based on your explicit consent within the scope of Law No. 6563 on the Regulation of Electronic Commerce and the IYS (Message Management System); you may unsubscribe free of charge at any time.

3. Purposes of Processing Personal Data

Your personal data is processed for the following purposes:

  • Receiving and responding to communication requests
  • Providing cyber security consultancy and services
  • AI-assisted evaluation of "Under Attack" form applications
  • Processing quote requests and providing services
  • Ensuring website security (bot protection, abuse prevention)
  • Analyzing website performance and improving user experience
  • Fulfilling legal obligations (log keeping per Law No. 5651)
  • Increasing service quality and ensuring customer satisfaction
  • Providing instant cybersecurity support via the AI assistant (ALISA)
  • Detecting and preventing malicious behavior by analyzing ALISA chat history and IP/Visitor pairs
  • Malware/suspicious file detection, reporting, and abuse and quota control via the free File Analysis Tool, and information security triage
  • Providing extended threat intelligence and relationship analysis when you request it (within technical and service policy limits)
  • Performing the data recovery service; receiving the device/media, conducting preliminary analysis and the recovery operation, keeping a chain of custody record, and managing the return/delivery processes of the device/data
  • Carrying out payment, invoicing and finance/accounting operations in paid services
  • Verifying your phone number (OTP) and delivering transaction/delivery notifications via SMS
  • Sending newsletters, campaigns and commercial electronic messages in line with your explicit consent (within the scope of Law No. 6563 and IYS)

4. Legal Grounds for Processing Personal Data

Your personal data is processed based on the following legal grounds specified in Articles 5 and 6 of the KVKK:

  • Explicit consent: For marketing and analytical cookies
  • Explicit consent (file analysis): When you upload a file to the free File Analysis Tool and tick the explicit consent box, to perform scanning and the analysis service
  • Performance of contract: To provide the services you requested
  • Legitimate interest: To ensure website security and service quality
  • Legal obligation: To comply with legal regulations
  • Explicitly stipulated by law: For fulfilling obligations arising from relevant legislation, primarily Turkish Commercial Code No. 6102, Tax Procedure Law No. 213, Turkish Penal Code No. 5237 and Consumer Protection Law No. 6502 (KVKK art.5/2-a)
  • Performance of a contract (data recovery): For providing the data recovery service and carrying out device delivery-return, payment and invoicing processes (KVKK art.5/2-c)
  • Explicit consent (special category data): For processing special category personal data (health, biometric data, religion, race, etc. — KVKK art.6) that may be present in the content of the device/media delivered to us within the data recovery service
  • Explicit consent (commercial messages): For sending newsletters, campaigns and commercial electronic messages within the scope of Law No. 6563 on the Regulation of Electronic Commerce and the IYS (Message Management System)

5. Transfer of Personal Data

Your personal data may be transferred to the following parties, limited to the purposes stated above:

🔹Google LLC: Analytics and advertising services (Google Analytics, Google Ads) - USA
🔹Cloudflare Inc: Bot protection and security verification services (Turnstile) - USA
🔹FingerprintJS Inc: Device fingerprint and security services - USA
🔹Hosting providers: Website infrastructure and database services
🔹Authorized public institutions: In case of legal obligation (courts, BTK, etc.)
🔹Google LLC (Gemini AI): AI assistant infrastructure and data processing - USA
🔹Multi-engine security scanning service providers: For malware scanning, reporting and (when enabled) extended threat intelligence, foreign-hosted cyber threat intelligence and scanning infrastructure partners (e.g. USA, EU and other countries); transfers are limited to scanning and reporting purposes
🔹NetGSM (SMS service provider): Transfer of phone number for sending phone verification (OTP) and transaction/delivery notification SMS - Türkiye
🔹Email infrastructure (SMTP / mail server): Processing of email address and related content for delivering notification, verification and transaction emails
🔹Accountant / accounting and audit service providers: For invoicing, finance and fulfilling legal obligations - Türkiye
🔹Courier / logistics companies: For delivery-return of the device/media or recovered data within the data recovery service (depending on the request and delivery method) - Türkiye

⚠️ In case of data transfer abroad, necessary guarantees are provided within the scope of Article 9 of the KVKK. The adequacy of the protection level of the countries to which data is transferred is evaluated and necessary measures are taken.

6. Retention Periods of Personal Data

Your personal data is retained for the period required by the processing purpose and within the scope of legal retention periods:

Data CategoryRetention Period
Contact and quote form data2 years
Under Attack report data1 year after completion
Cookie data1 year (analytics cookies 2 years)
Device fingerprint (visitorId)1 year
Log records (Law No. 5651)2 years (legal requirement)
User account informationUntil account is deleted
ALISA Chat Logs1 year (Indefinitely for banned users/violators)
File Analysis Tool records (file, digest/report metadata, security logs)Uploaded file on server: until deleted after analysis completes; database scan/report records: generally up to 2 years, subject to cessation of purpose or legal periods; longer retention may apply where required by law
Data recovery / device delivery report and contract records10 years within the scope of the obligation to retain commercial books and documents under relevant legislation (TCC/Tax Procedure Law)
Data contained in / recovered from device content (including special category)During the performance of the service; after delivery, temporary copies, backups and analysis environments in our systems are irreversibly destroyed within at most 30 days (a separate Data Destruction Report is issued)
Finance / invoice records10 years under the Tax Procedure Law
Newsletter / commercial message consent recordsUntil you withdraw your consent; pursuant to IYS and relevant legislation, consent records are kept for 3 years from the withdrawal of consent

7. Your Rights Under KVKK

Pursuant to Article 11 of the KVKK, you have the following rights:

  • a)To learn whether your personal data is processed
  • b)To request information if your personal data has been processed
  • c)To learn the purpose of processing personal data and whether they are used in accordance with their purpose
  • d)To know the third parties to whom personal data is transferred domestically or abroad
  • e)To request correction of personal data if it is incomplete or incorrectly processed
  • f)To request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK
  • g)To object to the occurrence of a result against you by analyzing the processed data exclusively through automated systems
  • h)To request compensation for damages in case you suffer damage due to unlawful processing of your personal data

8. Application Method

You can apply by one of the following methods to exercise your rights stated above:

Address: Malazgirt District, Sarayburnu St. No:46, Selcuklu/KONYA (written application)

Your applications will be concluded free of charge within 30 (thirty) days at the latest. If the transaction requires an additional cost, a fee may be charged according to the tariff determined by the Personal Data Protection Board.

Veri Kurtarma Hizmetleri Kapsamında Aydınlatma Metinleri

Aşağıdaki aydınlatma metinleri, veri kurtarma hizmetlerimiz kapsamında kişisel verilerinizin nasıl işlendiğini açıklar. Görüntülemek için ilgili başlığa tıklayın.

In accordance with the Personal Data Protection Law No. 6698 (“Law”), this Information Text explains what personal data is obtained from you by filling out the data recovery request form, the method of collecting your personal data, the legal reasons and purposes for processing it, the parties to whom your personal data is transferred, and your rights you can exercise regarding your personal data.

1. Veri Sorumlusu Kimdir?

Data Controller refers to the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.

In accordance with the law, your personal data; It may be processed by SİBERLOCK Cyber ​​Security and Consultancy Services (“SİBERLOCK” or “Company”) as the data controller, within the scope explained below.

2. Your Processed Personal Data, Legal Reasons and Purposes

Your personal data is processed based on the legal reasons in Articles 5 and 6 of the Law. What your personal data is processed, the legal reasons based on the processing of your personal data and the purposes of processing your personal data are shown in the table below.

Hukuki SebeplerPurposesProcessed Personal Data
Article 5/2(a): It is clearly provided for in the law.
  • Fulfilling the obligations arising from the legislation to which our Company is subject, especially the Turkish Commercial Code No. 6102, the Turkish Penal Code No. 5237 and the Consumer Protection Law No. 6502,
  • Carrying out our activities in accordance with the legislation,
  • Fulfillment of data sharing and preservation obligations by our Company in accordance with our obligations arising from the legislation.
  • Identity: Name-Surname, T.R. Identification Number
  • Contact: Email, Phone, Address
  • Customer Transaction: Call center records, order information, request/complaint information, order history, invoice information
  • Transaction Security: Device information, IP address, password/password information, cookie information, access records, login method
  • Finance: Personal account number, IBAN, payment card number, CVV, transaction amount, billing information
Article 5/2(c): It is necessary to process personal data of the parties to the contract, provided that it is directly related to the establishment or performance of a contract.
  • Communicating with the customer,
  • Providing information to the customer about the data recovery service,
  • Purchasing data recovery services and ensuring the performance of services,
  • Carrying out support services and informing the customer whether the data can be recovered or not,
  • Carrying out financial and accounting transactions.
  • Identity, Communication, Customer Transaction, Transaction Security, Finance
  • Visual and Audio Records: Photo, Video, Sound recording
Article 5/2(d): It is mandatory for the data controller to fulfill its legal obligation. Article 5/2(e): Data processing is mandatory for the establishment, exercise or protection of a right.
  • In case of legal disputes or when authorized institutions and organizations make a request or we are expected to notify these institutions.
  • Identity, Communication, Customer Transaction, Transaction Security, Finance, Visual and Audio Records
  • Legal Procedure: Information in correspondence with judicial authorities, information in the case file
  • Risk Management: Information processed to manage commercial, technical, administrative risks
Article 5/2(f): It is mandatory to process data for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the person concerned.
  • Providing information through the website, submitting the form,
  • Obtaining and recovering customer information within the scope of Data Recovery Service,
  • Ensuring customer satisfaction and establishing communication,
  • Receiving, evaluating and finalizing suggestions, requests and complaints.
  • Identity, Communication, Customer Transaction, Transaction Security, Risk Management, Finance, Visual and Audio Records
  • Other: Suggestion, Request and Complaint contents
Article 5/1: The relevant person must have explicit consent.
  • Within the scope of data recovery service, due to the risk of contacting sensitive data that may be contained in the disk content during the process of recovering and delivering the data lost on the disk, and cleaning the media brought by the customer if it is full.
  • Special Personal Data: Data regarding race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data that may be included in the disk/media examined within the scope of the data recovery service.

3. Methods of Collection of Your Personal Data

Your personal data mentioned above are collected by automatic or partially automatic or non-automatic means, provided that it is part of any data recording system, by filling out the data recovery request form you have accessed on the website and sending it to our Company.

4. Parties to whom your personal data is transferred

Your personal data obtained is shared with third parties in accordance with the purposes and legal reasons specified in this Information Text. When your personal data is shared with third parties, it is shared in accordance with Articles 8 and 9 of the Law and the rules regarding the transfer of personal data.

Transferred Personal Data GroupsPurpose of Data TransferLegal Reason for Data TransferTransfer Groups
Identity, Communication, Customer Transaction, Transaction Security, Legal Transaction, Risk Management, Finance, Visual and Audio Records, OtherExecuting business processes and ensuring business continuity; Obtaining product or service support to fulfill contractual requirements.Establishment or execution of a contract in accordance with KVKK article 8/2 (a) and KVKK article 5/f.2 (c).Service Providers (web, cloud, etc.), Cookie Providers, Suppliers, Consultants (Accounting, Legal, etc.), Shareholders, Business Partners.
(Data groups above)Proof of legal disputes, fulfillment of legal obligations; Situations where authorized institutions or organizations make a request to our Company or we are expected to notify these institutions.Legal liability in accordance with KVKK art.5/f.2 (d) with reference to KVKK art.8/2 (a).Authorized Public Institutions and Organizations, Judicial Authorities, Judicial Units.
(Data groups above)Public relations, press-media processes, carrying out commercial activities, improving the visit experience, improving the quality of goods and services and promotional activities.Legitimate interest in accordance with KVKK art.5/f.2 (f) with reference to KVKK art.8/2 (a).Suppliers, Shareholders, Natural Persons, Private Law Entities, Cookie Providers.

5. İlgili Kişi Hakları

The data controller ensures that your data is processed properly and securely. Your rights to apply to the data controller regarding the processing of your personal data are regulated in Article 11 of the Law. You can forward your requests within the scope of Article 11 of the Law to SİBERLOCK Cyber ​​Security and Consultancy Services, the data controller, through the following channels:

  • [email protected] adresine e-posta göndererek,
  • Malazgirt, Sarayburnu Cd. no: 46 inner door: 103, 42060 Selçuklu/Konya adresimize gönderilen yazılı bir talep şeklinde,
  • By personally making a written application with a wet signature to our company address stated above.

To exercise your rights, you can also choose the methods specified in the Communiqué on the Procedures and Principles of Application to the Data Controller. Depending on the nature of your request, your applications will be finalized free of charge as soon as possible and within thirty days at the latest. If the transaction requires an additional cost, you may be charged according to the tariff determined by the Personal Data Protection Board.

This document has been revised within SİBERLOCK in accordance with current data recovery processes.

Haklarınıza ilişkin başvurularınızı aşağıdaki kanallardan iletebilirsiniz:

Malazgirt, Sarayburnu Cd. no: 46 inner door: 103, 42060 Selçuklu/Konya