This disclosure statement has been prepared by cerez.io ("Company" or "cerez.io"), in its capacity as data controller, within the scope of Article 10 of Law No. 6698 on the Protection of Personal Data ("Law" or "KVKK") and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Disclosure Obligation.
1. Identity of the Data Controller
The legal entity holding the capacity of data controller pursuant to KVKK Article 3/1-ı of Law No. 6698:
| Trade Name | cerez.io |
| Trademark | cerez.io (cerez.io) |
| Address | Altıeylül, Balıkesir / Turkey |
| MERSIS Number | [cerez.io to be completed by] |
| Trade Registry No | [cerez.io to be completed by], Balıkesir Trade Registry Directorate |
| Tax Office / No | Kurtdereli V.D. / 1400185229 |
| VERBİS Registry No | [cerez.io to be completed by] (The data controller's VERBİS registration process is ongoing) |
| KEP Address | [cerez.io to be completed by] |
| Contact Person | [Data Protection Officer, to be appointed] |
| Contact | destek@cerez.io · +90 540 059 40 40 (WhatsApp) |
2. Categories of Personal Data Processed
The categories and scope of personal data processed by our company are shown in the table below:
| Data Category | Scope |
|---|---|
| Identity | First name, last name, username, Turkish ID number (in Enterprise agreements) |
| Contact | E-mail address, phone number, postal address |
| Customer Transaction | Order information, subscription plan, invoice information, request and complaint record |
| Financial | Bank account information (in the case of bank transfer/EFT), invoice records |
| Legal Transaction | Contract records, KEP correspondence, legal notice/response documents |
| Transaction Security | IP address, log records, cookie records, user session information, password hash information |
| Marketing | Newsletter subscription, cookie preferences, campaign interaction data |
| Visual/Audio | Support call recordings (only with explicit consent), profile photo |
| Professional Experience | CV, education information, references in career applications |
3. Purposes of Processing Personal Data
Within the framework of the general principles set out in Article 4 of the Law and the processing conditions specified in Articles 5 and 6, your personal data is processed for the following purposes:
- Conduct of contract processes (membership, subscription, SaaS service provision)
- Conduct of activities in compliance with legislation (in particular KVKK Article 12, VUK Article 253, TTK Article 82)
- Conduct of finance and accounting affairs (billing, payment collection)
- Conduct of customer relationship management processes (support, request, complaint)
- Conduct of information security processes (detection of unauthorized access, log records)
- Conduct of communication activities (information, e-mail sending)
- Follow-up and conduct of legal affairs (disputes, court proceedings)
- Follow-up of requests and complaints (support requests)
- Conduct and supervision of business activities
- Provision of information to authorized persons, institutions and organizations (judiciary, public prosecutor's office, BTK, KVKK Board, etc.)
- Conduct of marketing analysis work (with explicit consent)
- Conduct of advertising, campaign, promotion processes (with explicit consent)
- Conduct of employee candidate selection and placement processes (career applications)
4. Legal Basis for Processing Personal Data
Your personal data is processed based on the following legal bases within the scope of Article 5 of the Law:
| Article | Legal Basis | Application |
|---|---|---|
| 5/2-a | Being expressly provided for in the laws | VUK, TTK, KVKK compliance requirements |
| 5/2-c | Establishment or performance of the contract | Membership, subscription, service provision |
| 5/2-ç | Legal obligation of the data controller | Tax legislation, retention of commercial books |
| 5/2-e | Establishment, exercise or protection of rights | Legal dispute, debt collection |
| 5/2-f | Legitimate interest (provided that fundamental rights and freedoms are not harmed) | Information security, fraud prevention, system logs |
| 5/1 | Explicit consent of the data subject | Marketing e-mails, marketing cookies, voice recording |
5. Parties to Whom Personal Data Is Transferred and Purpose of Transfer
Your personal data is transferred to the following parties within the conditions set out in Articles 8 and 9 of the Law:
| Recipient Group | Purpose of Transfer | Location |
|---|---|---|
| Business partners and suppliers | Support required for service provision (e-mail delivery, CDN, payment) | Domestic + EU + USA (with SCC) |
| Legally authorized public authorities | As required by the provisions of relevant legislation (KVKK Board, BTK, courts, public prosecutor) | Domestic |
| Financial advisor / Independent audit firms | Tax and financial advisory services | Domestic |
| Banks and payment institutions | Payment collection, EFT/wire transfer transactions | Domestic |
| Cloud infrastructure provider (AWS) | Data hosting, backup | EU, Frankfurt (eu-central-1) |
| CDN and security provider (Cloudflare) | Content distribution, DDoS protection | Global (US HQ), DPF certified |
| E-mail service provider (SendGrid) | Transactional e-mail delivery | EU + USA, DPF certified |
| Payment processor (Stripe, coming soon) | Credit card payment processing | EU, Ireland |
| Legal counsel | Legal advice and follow-up | Domestic |
Cross-border transfers are carried out within the scope of KVKK Article 9/2 by means of Standard Contractual Clauses (SCC) and/or safeguard mechanisms approved by the Data Protection Board. For the detailed sub-processor list, see our DPA page see.
6. Method of Collecting Personal Data
Your personal data is collected by our Company through the following methods, by automated and partly automated means:
- Automated methods: Cookies during website visits, IP address, log records, API usage logs, automated form submission.
- Partly automated methods: Membership form, contact form, demo request, support request, invitation acceptance process, cookie preference banner, contract signing.
- Physical medium: Notifications received via KEP, contracts or applications delivered by post, telephone calls (with explicit consent in the event of recording).
7. Rights of the Data Subject (KVKK Article 11)
Pursuant to Article 11 of the Law, in your capacity as data subject (relevant person) you have the following rights:
- To learn whether your personal data is processed
- To request information regarding this if your personal data has been processed
- To learn the purpose of processing your personal data and whether they are used in accordance with their purpose
- To know the third parties to whom your personal data is transferred domestically or abroad
- To request the correction of your personal data in the event that it has been processed incompletely or incorrectly
- To request the erasure or destruction of your personal data within the framework of the conditions stipulated in Article 7 of the Law
- To request that the operations carried out pursuant to subparagraphs (5) and (6) be notified to the third parties to whom the personal data has been transferred
- To object to the emergence of a result against you arising from the analysis of the processed data exclusively by means of automated systems
- To claim compensation for the damage in the event that you suffer damage due to the unlawful processing of your personal data
8. Application Procedure
To exercise the rights set out in Article 7, you may submit an application using one of the following channels pursuant to the "Communiqué on the Procedures and Principles of Application to the Data Controller":
| Application Method | Address / Information |
|---|---|
| In-Person Application (written) | Altıeylül, Balıkesir / Türkiye, identity verification is performed |
| Via Notary | Notification to the above address via notary |
| KEP (Registered Electronic Mail) | [cerez.io to be completed by] |
| Secure Electronic Signature | destek@cerez.io (pursuant to Law No. 5070) |
| E-mail Registered in the System | From your e-mail address registered in the Company systems destek@cerez.io |
Your application must contain the following information:
- Name, surname and, if the application is written, signature
- T.C. identity number (for citizens of the Republic of Türkiye), or, if you are a foreign national, passport/nationality
- Residence or workplace address forming the basis for notification
- E-mail, telephone and fax number for notification, if any
- Subject of the request
Applications are concluded within 30 (thirty) days at the latest. The process is free of charge; however, in the event that the process additionally entails a cost, the fee in the tariff determined by the Board may be charged.
Our relevant policies: Privacy Policy · Cookie Policy · Data Processing Agreement (DPA)
For your questions: destek@cerez.io · This page was last updated on 31 May 2026.