KVKK privacy notice
Personal data processed through the website, our contact channels and the reseller panel, your rights and how to submit a request.
Data controller
This notice has been prepared pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (the “Law”) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform. Data controller:
- Business: WebJoiner Bilişim Teknolojileri (sole proprietorship)
- Address: Göztepe Mah. Batışehir Cad. Batışehir K Blok No:2/2 İç Kapı No:115, Bağcılar / İstanbul
- Tax office: Güneşli V.D.
- KVKK requests: kvkk@webjoiner.com
WebJoiner is part of the Wayave Bilişim Teknolojileri group; the data controller within the scope of this notice is solely the business named above.
Who does this notice cover?
- Website visitors: anyone who views the pages of webjoiner.com.
- People who contact us: persons who write to or call us by e-mail, WhatsApp or telephone, or who apply to become a reseller.
- Our customers and their authorized representatives: agencies and resellers using the reseller panel at panel.webjoiner.com, together with their employees and team members.
Data belonging to our resellers' clients. Our resellers use the panel to provide hosting, domain and e-mail services to their own clients. With respect to data entered into the panel by the reseller or generated through the reseller client's services (client contact and billing details, domain registration details, hosted website and e-mail content, backups), the data controller is the relevant reseller. WebJoiner processes such data on behalf of the reseller as a data processor, in accordance with the instructions set out in the reseller agreement and the data processing agreement annexed to it, and does not use it for any other purpose.
WebJoiner acts as a data controller in its own right in the following cases: (i) traffic data retained in its capacity as a hosting provider under Law No. 5651; (ii) the investigation of abuse of the services, spam and security incidents; (iii) verification obligations arising from the rules of domain name registries and registrars; (iv) requests from competent authorities and judicial bodies.
To exercise your rights as a reseller's client, please first contact the reseller from which you receive the service. We forward any such requests we receive, together with your identification details, to the relevant reseller without delay and notify you accordingly; requests relating to the cases listed above in which we are the data controller are handled and concluded directly by us.
Personal data processed and method of collection
Website visits. The website has no user accounts and no analytics or advertising tools; the only form is the contact form described below. When pages are served, access logs such as IP address, browser and device information (user agent), requested address, date and time, and response code are generated by fully automated means by the server hosting the website and by the CDN and security service provider.
Contact and reseller applications. The “Create application e-mail” button on the website merely opens a pre-filled draft in your own e-mail program; no information is sent to our website through this button. When you submit the form on the contact page, what you enter (first and last name, company, e-mail, telephone, subject, message), the date and time at which you confirmed that you have read the privacy notice, the page from which the form was submitted, truncated browser information and, to prevent abuse, a truncated and keyed hash of your IP address are recorded in the request records in our panel; the form may be protected against automated submissions by bot verification. When you contact us via the form, e-mail, WhatsApp or telephone, the following data are processed to the extent you share them:
- Identity and contact: first name, last name, e-mail address, telephone number
- Professional information: company or agency name, job title, website, number of clients and infrastructure preferences
- Content of correspondence and the date and time of the communication
These data are obtained upon your submission, through the contact form, e-mail, WhatsApp and telephone, by partially automated means, and, with respect to notes taken during telephone calls, by non-automated means.
Panel customers. When a reseller relationship is established, the following data are processed in the course of the agreement and the use of the panel:
- Account and security: first name, last name, e-mail, telephone, user role, password hash (the password itself is not stored), two-factor authentication records, session and activity logs, IP address
- Billing and customer transactions: depending on the type of business, Turkish national identification (T.C. kimlik) number or tax identification number, tax office, billing address, order, payment and invoice records
- Support and communication: support tickets and correspondence
These data are obtained through the panel and contractual processes, as entered by you or by the reseller with which you are affiliated, by fully or partially automated means; session and activity logs are generated automatically by the system. The details of team members added to the panel by the reseller administrator are provided to us by the reseller; a link to this notice is shown to these persons in the account invitation e-mail and upon their first login to the panel.
Card details are transmitted directly to a licensed payment institution during payment; the card number is neither seen nor stored by us. We do not request special categories of personal data (such as health or biometric data); please do not share them in correspondence.
Purposes of processing and legal grounds
Personal data are processed for the specific purposes below, based on the following legal grounds set out in paragraph 2 of Article 5 of the Law. Your explicit consent is not relied upon for these activities.
- Serving the website securely and detecting attacks and abuse: our legitimate interest, provided that it does not harm your fundamental rights and freedoms (Art. 5/2-f).
- Evaluating your application, answering your questions, and conducting quotation and pre-contractual discussions: being directly related to the establishment of a contract (Art. 5/2-c); for those who only ask questions, our legitimate interest (Art. 5/2-f).
- Understanding from which page you reached us and improving our website (by means of the short source code shown in your message): our legitimate interest (Art. 5/2-f).
- Establishing and performing the reseller agreement; opening the account, providing the service, providing support, collecting payment: establishment and performance of the contract (Art. 5/2-c).
- Issuing invoices and e-Invoices / e-Archive invoices, retaining commercial books and records, responding to requests from competent authorities: being expressly provided for by law and compliance with our legal obligation (Art. 5/2-a and ç).
- Retaining hosting provider traffic data; investigating reports of abuse and unlawful content: being expressly provided for by law and compliance with our legal obligation (Art. 5/2-a and ç), and our legitimate interest (Art. 5/2-f).
- Panel security and keeping access and activity logs: compliance with our legal obligation (Art. 5/2-ç) and our legitimate interest (Art. 5/2-f).
- Establishment, exercise or protection of rights in potential disputes: Art. 5/2-e.
Promotional messages. Promotional e-mails concerning our products and services may be sent to our resellers and to merchants and tradespeople with whom we have a business relationship without prior consent, pursuant to Law No. 6563 and the Regulation on Commercial Communications and Commercial Electronic Messages; such messages contain an opt-out link, and sending is stopped upon your opt-out notice. They are sent to individual recipients only if they have separately given their consent. The legal ground for processing your contact details for this purpose is our legitimate interest, provided that it does not harm your fundamental rights and freedoms (Art. 5/2-f).
Transfer of personal data
Personal data may be transferred to the following groups of recipients only to the extent necessary for the purposes above and in accordance with Articles 8 and 9 of the Law:
- Hosting and infrastructure: the website, panel, hosting and e-mail servers are located in data centers in Türkiye (providing the service and transmitting and storing e-mail correspondence).
- Backup: encrypted backups of panel data (data security); resellers' account backups are sent, on the reseller's instruction, to the SFTP/FTP storage defined by the reseller in the panel.
- CDN and security service provider: fast and secure delivery of pages, attack and bot protection, and bot verification at panel login (legitimate interest). This provider is located abroad; see below.
- Payment institution: collection of card payments (performance of the contract).
- E-invoice service provider and the Revenue Administration (Gelir İdaresi Başkanlığı): issuing e-Invoices / e-Archive invoices (legal obligation).
- Domain name registrar and domain name registries: fulfilling registration orders placed through the panel (performance of the contract).
- SSL certificate providers: fulfilling certificate orders placed through the panel (performance of the contract). For domain-validated (DV) certificates, only the domain name and the technical information required for validation are transmitted.
- WhatsApp service provider: transmission and storage of correspondence if you choose to write to us via WhatsApp. This provider is located abroad; see below.
- Financial advisor (accountant), legal counsel and auditors: legal obligations and the protection of rights.
- Competent public authorities and institutions and judicial bodies: upon requests they are legally authorized to make.
Transfer abroad. Our website, panel, hosting and e-mail servers are located in Türkiye. Transfer abroad occurs only in the following two cases:
- CDN and security service provider (Cloudflare, Inc., USA). Since the website and the panel are served through this provider's servers worldwide, traffic-related records (IP address, browser and device information, requested address, date and time) and the device signals used in bot verification at panel login and on the contact form are processed abroad. The purpose is to serve the website and the panel securely and to prevent attacks.
- WhatsApp (Meta). If you choose to write to us via WhatsApp, your messages are processed on the servers abroad of the Meta companies that provide the WhatsApp service and are stored in our business account. You are not required to use this channel; you can carry out the same actions by e-mail or telephone. Please do not share identity, billing or special category data via WhatsApp; we recommend that you send such details by e-mail.
The Personal Data Protection Board has not yet issued an adequacy decision for any country. These two transfers are carried out within the framework of the service and data processing terms accepted with the relevant service providers upon opening the account, and are limited solely to the data necessary for providing the service. This notice will be updated if there is any change in the basis for the transfer.
Domain name registration. For domain name orders placed through the panel, the information mandatory for registration (first and last name or trade name, address, e-mail, telephone) is transmitted through the domain name registrar in Türkiye, and to the extent required by the registry rules, to the domain name registry responsible for the extension; the registries of generic extensions such as .com, .net and .org are located abroad. This transmission takes place under the registrar's own data controllership and with the safeguards it provides. Registration details belonging to our resellers' clients are transmitted on the instruction of the reseller, which is the data controller. For supported extensions, WHOIS privacy is enabled by default; for these extensions, contact details are not displayed in the public WHOIS record.
You may exercise your rights regarding data transferred abroad through the application procedure set out in this notice.
Retention periods
Personal data are retained for as long as necessary for the purpose for which they are processed and for the period prescribed by the relevant legislation. The main periods are:
- Invoices, commercial books and accounting records, payment records: 10 years from the end of the relevant year (Turkish Commercial Code No. 6102, Art. 82; Tax Procedure Law No. 213, Art. 253).
- Contract and customer account records: for the term of the contract and 10 years from its termination (Turkish Code of Obligations No. 6098, Art. 146, general statute of limitations).
- Hosting provider traffic data relating to websites hosted in the panel: 2 years (Law No. 5651, Art. 5/3; not less than one year and not more than two years). WebJoiner is the data controller with respect to these records.
- Panel security and activity logs: for as long as the account remains open and 2 years from the closure of the account.
- Website access and security logs: up to 1 year.
- Applications and contact correspondence that do not result in a contract: 2 years from the last correspondence.
- Records relating to KVKK requests: 2 years from the conclusion of the request (for the periods for complaints to the Board and potential disputes).
- Records relating to erasure, destruction and anonymization operations: at least 3 years (Regulation on the Erasure, Destruction or Anonymization of Personal Data, Art. 7/3).
When the period expires or the grounds for processing cease to exist, the data are erased, destroyed or anonymized within no more than three months as part of periodic destruction; upon your request, where all of the conditions for processing have ceased to exist, within no more than 30 days. Cases in which another law requires longer retention are reserved.
Data security
Pursuant to Article 12 of the Law, we take technical and administrative measures to prevent unlawful access to and processing of personal data; these include, for example, encrypted connections (HTTPS), two-factor authentication for administrator accounts, role-based authorization, segregation of resellers' data from one another, storage of passwords as irreversible hashes and encrypted storage of sensitive keys, an append-only audit log, and access restricted to necessary personnel only.
Your rights under Article 11 of the Law
By applying to the data controller, you have the right, with respect to yourself, to:
- learn whether your personal data are being processed,
- request information in this regard if they have been processed,
- learn the purpose of processing and whether the data are used in accordance with that purpose,
- know the third parties to whom the data are transferred domestically or abroad,
- request rectification if the data have been processed incompletely or inaccurately,
- request erasure or destruction of the data within the framework of the conditions set out in Article 7 of the Law,
- request that the rectification, erasure or destruction be notified to the third parties to whom the data have been transferred,
- object to a result to your detriment arising from the analysis of the data exclusively through automated systems,
- request compensation for damages if you suffer damage due to unlawful processing
You hold each of the rights listed above.
Data subject requests
You may submit requests regarding your rights in Turkish, pursuant to the Communiqué on the Procedures and Principles of Application to the Data Controller, by one of the following means:
- In writing: by a petition bearing a wet signature, delivered by hand or by post to Göztepe Mah. Batışehir Cad. Batışehir K Blok No:2/2 İç Kapı No:115, Bağcılar / İstanbul,
- Signed with a secure electronic signature or mobile signature: to kvkk@webjoiner.com,
- From your e-mail address registered in our system: from the e-mail address you have previously notified to us, to kvkk@webjoiner.com.
Your request must include:
- first name, last name and, if the request is in writing, signature,
- for citizens of the Republic of Türkiye, the T.C. identification number; for foreign nationals, nationality, passport number or, if any, identification number,
- residential or business address for service of notices,
- e-mail address, telephone and fax number for notifications, if any,
- the subject of the request.
Attach any information and documents relevant to the matter to your request. Where we are unable to verify your identity, we may request additional information in order to protect your data.
Response time and fee. Your request will be concluded free of charge as soon as possible depending on the nature of the request, and within 30 days at the latest; the response will be communicated in writing or electronically. As a rule, no fee is charged. If the process additionally entails a cost, only the fee set out in the Communiqué may be charged: TRY 1 for each page exceeding ten pages of a written response, and, if the response is provided on a recording medium such as a CD or flash drive, the cost of the recording medium. If the request arises from our error, the fee charged will be refunded.
If your request is rejected, if you find the response insufficient, or if no response is given in due time, you may file a complaint with the Personal Data Protection Board within 30 days from the date you learn of the response and, in any event, within 60 days from the date of the request (Art. 14 of the Law).
Changes
This notice is updated when our processing activities or the legislation change; the current version is published on this page. Effective date and date of last update: 27.09.2026.