This Privacy Policy explains our practices concerning the personal data processed within the scope of the domain name registration, web hosting, e-mail, SSL certificate and related internet services provided by DomainQ. DomainQ attaches the utmost importance to the protection of your personal data within the framework of Law No. 6698 on the Protection of Personal Data (KVKK) and the relevant secondary legislation. This Policy covers which of your data we process, for which purposes and on which legal grounds, with whom we share it, how long we retain it, and the methods for exercising your rights under the Law.
1. Identity of the Data Controller
Within the scope of this Privacy Policy, the data controller of your personal data is DomainQ, which provides domain name registration, web hosting, e-mail, SSL and similar internet services (hereinafter referred to as "DomainQ", the "Company" or "we").
As defined in Article 3 of the KVKK, DomainQ is the legal entity that determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
You may submit any questions, requests and applications regarding the processing of your personal data to the e-mail address [email protected] or by the methods specified in the "Exercising Your Rights and Application Method" section of this Policy. You may access our Company's current trade name, full address, trade registry number and KEP (registered electronic mail) information from the contact and corporate sections of our website.
2. Purpose, Scope and Definitions of the Policy
The purpose of this Policy is to transparently set out the principles regarding the processing, in compliance with the KVKK and the relevant legislation, of the personal data of our customers, prospective customers, visitors to our website, representatives of our suppliers and business partners, and other natural persons who interact with our services within the scope of the services provided by DomainQ.
This Policy covers the personal data processing activities carried out through our website, customer panel, call and support channels, servers and infrastructure. Our "Cookie Policy" document complements this Policy with respect to details concerning cookies, and our "KVKK Disclosure Statement" document with respect to details concerning our disclosure obligation at the time of collection.
The fundamental concepts used in this Policy are based on the definitions set out in Article 3 of the KVKK: (a) Personal data: Any information relating to an identified or identifiable natural person. (b) Special categories of personal data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations/foundations/trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. (c) Data subject: The natural person whose personal data is processed. (ç) Explicit consent: Consent relating to a specific matter, based on information and expressed with free will. (d) Data controller: The person who determines the purposes and means of processing. (e) Data processor: The person who processes personal data on behalf of the data controller based on the authority granted by the data controller.
The processing of personal data means any operation performed on data, such as the obtaining, recording, storage, retention, alteration, disclosure, transfer, classification of data, or preventing its use, by fully or partially automated means or by non-automated means provided that they form part of a data recording system.
3. General Principles Regarding the Processing of Personal Data
DomainQ processes personal data in full compliance with the general principles set out in Article 4 of the KVKK.
These principles are: (a) being processed lawfully and in accordance with the rules of good faith, (b) being accurate and, where necessary, kept up to date, (c) being processed for specified, explicit and legitimate purposes, (ç) being relevant, limited and proportionate to the purposes for which they are processed, (d) being retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed.
We process your personal data only for the purposes specified in this Policy and to the extent required by these purposes; we do not use it for purposes outside these.
4. Categories of Personal Data We Process
Depending on the nature of our services, we process the following categories of personal data:
(a) Data you provide directly to us: Identity data (name, surname, Turkish ID number or tax identification number, date of birth); contact data (address, telephone, e-mail, billing address); customer account data (username, password and account preferences). Your passwords are not stored by us in plain text; they are kept in encrypted/hashed form.
(b) Domain name registration / WHOIS-RDAP data: The name-surname, organization, address, telephone and e-mail information of the registrant, administrative and technical contact person that you provide during the domain name registration application. Given the nature of the registration processes, this data is shared with the relevant registration authorities and registries (ICANN, TRABİS/nic.tr, along with the registry and accredited registrar operators) (see Sections 9 and 10).
(c) Financial and payment data: Invoice information, payment records, order and transaction history. In card payments, your card information is processed through authorized payment and electronic money institutions without being stored by DomainQ.
(ç) Transaction security and log data: IP address, access and traffic records, session information, device and browser information, server access logs, timestamp and integrity (hash) values.
(d) Customer service and support data: Support requests, correspondence content, call center conversation records and the information you share in this context.
(e) Marketing and preference data: Approval/rejection status for commercial electronic messages, newsletter subscription preferences, campaign interactions.
(f) Cookie and online identifier data: Data collected through cookies and similar technologies relating to the use of our website (see our Cookie Policy for details).
DomainQ does not request special categories of personal data for the provision of services. However, in the registration of certain types of domain names (for example, registrations requiring official documents), special categories of data such as the religion field may appear in the copies of identity documents you submit; such data is processed only within the framework of the conditions set out in Article 6 of the KVKK and by taking the adequate measures stipulated by the Board. For this reason, we recommend that you redact any unnecessary special categories of information in the documents you submit.
5. Methods of Collecting Personal Data
Your personal data is collected through forms you fill out on our website and customer panel, order and registration applications, e-mail, call center and support channels, contracts and our automated systems (server logs, cookies), by fully or partially automated or non-automated methods.
In addition, data may be obtained from registration authorities and registries during domain name query and registration processes, and from authorized payment institutions and identity verification providers during payment processes.
Your data is collected and processed for the purposes specified in Section 6 of this Policy and on the basis of the legal grounds specified in Section 7.
6. Purposes of Processing Personal Data
We process your personal data principally for the following purposes:
(a) The establishment and performance of the contract relating to our domain name registration, web hosting, e-mail, SSL and other services, the provision of the services, and ensuring their continuity and security.
(b) The creation and management of your customer account, verification of your identity, and the conduct of order and registration transactions.
(c) Carrying out billing, collection, accounting and financial processes and executing payment transactions.
(ç) Managing customer support and complaint processes and responding to your requests and questions.
(d) Ensuring information security, preventing misuse and fraud, monitoring system and network security and service quality.
(e) Fulfilling our legal obligations, meeting the requests of authorized institutions and organizations, and performing the log retention obligation under Law No. 5651.
(f) To the extent you permit, sending promotions, campaigns, newsletters and commercial electronic messages, and carrying out marketing activities.
(g) The management of legal disputes and the establishment, exercise or protection of a right.
7. Legal Grounds for Processing
We process your personal data based on the processing conditions set out in Articles 5 and 6 of the KVKK.
(a) Being directly related to the establishment or performance of a contract (KVKK Art. 5/2-c): Performance of the contract relating to our services, account management and service provision (Purposes 6/a, 6/b, 6/c).
(b) Being expressly provided for in the laws and fulfillment of a legal obligation (KVKK Art. 5/2-a and Art. 5/2-ç): In particular, the traffic/log retention obligation under Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications; obligations arising from Tax Procedure Law No. 213, Turkish Commercial Code No. 6102 and Turkish Code of Obligations No. 6098 (Purposes 6/c, 6/e).
(c) Processing being mandatory for the establishment, exercise or protection of a right (KVKK Art. 5/2-e): Management of legal disputes and the right of defense (Purpose 6/g).
(ç) Processing being mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject (KVKK Art. 5/2-f): Information security, prevention of fraud and improvement of service quality (Purpose 6/d).
(d) Explicit consent (KVKK Art. 5/1): In cases where none of the above conditions exist, in particular for optional cookies and marketing activities based on explicit consent, processing is carried out based on your explicit consent (Purpose 6/f). You may withdraw your explicit consent at any time; withdrawal does not affect the lawfulness of processing carried out based on explicit consent up to that moment.
Your special categories of personal data are processed only where the conditions set out in Article 6 of the KVKK exist and by taking the adequate measures determined by the Board.
8. Our Status as Data Controller and Data Processor
Depending on the circumstances, DomainQ may act as both a data controller and a data processor with respect to the services it provides; this distinction is important in terms of your rights and our obligations.
(a) Our status as data controller: DomainQ is the data controller with respect to your customer account information, identity and contact data, invoice and payment records, domain name registration/WHOIS data, and the data we obtain while providing these services to you. We process this data for the purposes and legal grounds specified in this Policy.
(b) Our status as data processor: With respect to the personal data belonging to third parties (your visitors, your own customers, your end users) that you, our customer, upload and host on your own website, application or systems through our hosting, server, e-mail and similar services, YOU are the data controller of such data; DomainQ acts merely as a data processor operating in accordance with your instructions.
(c) In this context, DomainQ processes the hosted data in question exclusively in accordance with the customer's instructions and does not carry out any independent processing activity with this data on its own behalf. The responsibility for fulfilling the disclosure obligation regarding the end-user data you host, obtaining the necessary explicit consents, and processing this data lawfully rests with you as the data controller.
(ç) In cases where we act as a data processor, DomainQ is, pursuant to Article 12 of the KVKK, jointly responsible together with the customer who is the data controller for taking appropriate technical and administrative measures to ensure the security of the data.
9. Transfer of Personal Data Domestically
Your personal data may be transferred to the following parties in accordance with the conditions set out in Article 8 of the KVKK and limited to the purposes stated above:
(a) Authorized banks, payment and electronic money institutions for payment and collection transactions (for example, payment service providers such as iyzico and PayTR).
(b) Authorized registration authorities and registrars for domain name registration and management processes: For ".tr" extension domain names, TRABİS and the relevant registrar (nic.tr). With respect to generic top-level domains (gTLDs), transfers made to ICANN, the relevant registry operators and accredited registrar operators are evaluated within the scope of Section 10, since such parties may be established abroad.
(c) Business partners, infrastructure, software and technical service suppliers and consultants (including legal, financial advisory and audit firms) with whom we cooperate for the provision of services.
(ç) Authorized public institutions and organizations and judicial/administrative authorities pursuant to our legal obligations.
Transfers are in any case carried out in accordance with the general principles and processing conditions of the KVKK, ensuring confidentiality and security measures.
10. Transfer of Personal Data Abroad
In the event that cloud infrastructure, server, content delivery network (CDN), e-mail, analytics and similar service providers, or generic top-level domain (gTLD) registries (ICANN and registry/registrar operators established abroad) are located abroad, your personal data may be transferred abroad in accordance with the current regime under Article 9 of the KVKK, as amended by Law No. 7499 and entered into force on 1 June 2024.
Transfer abroad is carried out where one of the processing conditions set out in Articles 5 and 6 of the KVKK exists and according to the following tiered structure:
(a) The existence of an adequacy decision issued by the Board regarding the country, sector or international organization to which the transfer will be made.
(b) In the absence of an adequacy decision, the provision of one of the appropriate safeguards listed in KVKK Art. 9/4: The signing of the standard contract announced by the Board (notification is made to the Authority within five business days of the completion of the signatures), binding corporate rules, or a written undertaking (the latter two with the Board's authorization).
(c) In cases where the above conditions do not exist, reliance on the exceptional circumstances set out in KVKK Art. 9/6 (for example, your explicit consent provided that the risks are notified, or necessity for the performance of the contract), provided that it is incidental only.
Contractual and technical safeguards ensuring the security of your personal data are provided with the technology service providers carrying out the transfer abroad.
11. Cookies and Online Identifiers
On our website, cookies and similar online identifier technologies are used for the purpose of the operation of the site and the improvement of user experience.
Mandatory cookies that are necessary for the proper functioning of the site are used without seeking explicit consent within the scope of the processing conditions set out in KVKK Art. 5/2 (in particular, the performance of the contract and the legitimate interest of the data controller). Optional cookies for advertising, marketing, targeting and performance/analytics purposes, however, are activated only based on your explicit consent (opt-in) and by your active preference.
You may change or withdraw your cookie preferences at any time through the cookie management panel provided on our site. For detailed information on cookie types, durations and purposes, you may review our Cookie Policy.
12. Commercial Communication and Marketing Preferences
Commercial electronic messages containing campaigns, discounts, newsletters and promotions (e-mail, SMS, calls) are sent only with your prior consent pursuant to Law No. 6563 on the Regulation of Electronic Commerce and the relevant legislation.
Your consents are, as required by the legislation, recorded in the Message Management System (İYS), and before messages are sent, your approval/rejection status on İYS is checked. Consents not recorded in İYS are invalid.
You may refuse to receive commercial electronic messages at any time without stating a reason. You may submit your rejection request through the free method provided in the message or through İYS; your rejection request is implemented within three business days at the latest.
Mandatory messages for informational, change, maintenance and security purposes relating to the operation of our services are outside this scope and are sent as a requirement of the service relationship.
13. Security of Personal Data
Pursuant to Article 12 of the KVKK, DomainQ takes the necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of and access to personal data and to ensure its retention.
Within the scope of technical measures, measures such as firewalls, encryption, access authorization controls, up-to-date software and patch management, network and system monitoring, backup and penetration tests are implemented. Within the scope of administrative measures, the confidentiality obligation of personnel, the limitation of access according to the "need to know" principle, training, contractual safeguards and periodic audits are in place.
In the event that your data is processed on our behalf by another natural or legal person, we are jointly responsible with these parties for taking appropriate measures and carry out the necessary audits.
In the event that personal data is obtained by others through unlawful means (a data breach), the situation is notified to the relevant data subjects as soon as possible; notification is made to the Personal Data Protection Board, in accordance with the procedure determined by the Board, within seventy-two (72) hours at the latest from becoming aware of the breach.
14. Retention Periods and Destruction
Your personal data is retained for the period stipulated in the relevant legislation or required for the purpose for which it is processed. In the event that the reasons requiring its processing cease to exist, it is deleted, destroyed or anonymized, ex officio or upon your request, pursuant to Article 7 of the KVKK and the Regulation on the Deletion, Destruction or Anonymization of Personal Data.
Principal retention periods: (a) Invoice, accounting and commercial records are retained for the relevant periods (as a rule, periods of up to ten years) pursuant to the Tax Procedure Law and the Turkish Commercial Code. (b) Traffic/log records kept in the capacity of a hosting provider under Law No. 5651 are retained within the limits stipulated in the legislation (no less than one year and no more than two years). (c) Data relating to the contract and service relationship is retained during the service period and thereafter throughout the relevant limitation periods.
Upon the expiry of the retention periods, your personal data is destroyed within the framework of the periodic destruction processes stipulated in our Company's personal data retention and destruction policy.
15. Personal Data of Children
Our services are intended for natural and legal persons having contractual capacity; they are not designed for children.
DomainQ does not knowingly collect personal data belonging to children. In the event that we detect that personal data belonging to a child is being processed without the consent of a parent/guardian, we will delete such data as soon as possible in accordance with the legislation.
If you become aware of such a situation, we kindly ask you to contact us via the address [email protected].
16. Your Rights as a Data Subject
Pursuant to Article 11 of the KVKK, by applying to DomainQ in its capacity as data controller, you have the following rights:
(a) To learn whether your personal data is processed,
(b) To request information if your personal data has been processed,
(c) To learn the purpose of processing your personal data and whether it is used in accordance with its purpose,
(ç) To know the third parties to whom personal data is transferred domestically or abroad,
(d) To request the rectification of your personal data in the event that it has been processed incompletely or incorrectly,
(e) To request the deletion or destruction of your personal data within the framework of the conditions set out in Article 7 of the KVKK,
(f) To request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom the personal data has been transferred,
(g) To object to the emergence of a result against you by means of the analysis of the processed data exclusively through automated systems,
(h) To request the compensation of the damage in the event that you suffer damage due to the unlawful processing of your personal data.
17. Exercising Your Rights and Application Method
You may submit your requests regarding your above rights to DomainQ pursuant to the "Communiqué on the Procedures and Principles of Application to the Data Controller".
You may make your application; (a) in writing with a wet signature (in person, by notary or by registered mail with return receipt) to our Company's address, (b) using a registered electronic mail (KEP) address, secure electronic signature or mobile signature, or (c) by sending it to the address [email protected] from the e-mail address that you have previously notified to us and that is registered in our system.
Your application must clearly include your name-surname, signature (in written applications), Turkish ID number (nationality and passport number for foreigners), address for notification, e-mail and telephone information if any, and the subject of your request.
Your request is finalized free of charge as soon as possible and within thirty (30) days at the latest, depending on its nature. In the event that the operation also requires a cost, the fee in the tariff determined by the Board may be charged (no fee is charged up to ten pages; the relevant tariff is applied for each page over ten pages; for responses to be provided on a recording medium, the fee may not exceed the cost of the recording medium).
In the event that your application is rejected, the response is found insufficient, or no response is provided within the period; you may lodge a complaint with the Personal Data Protection Board within thirty (30) days from the date you learn of the response and, in any case, within sixty (60) days from the date of application. To file a complaint with the Board, the remedy of applying to the data controller must first be exhausted.
18. Data Controllers' Registry (VERBİS)
Pursuant to Article 16 of the KVKK, data controllers processing personal data are obliged, except for the exceptions stipulated by the Board, to register with the Data Controllers' Registry (VERBİS) before commencing data processing.
DomainQ fulfills its VERBİS registration obligation to the extent it is subject to this legal obligation and updates changes in the information notified to the Registry in accordance with the legislation.
19. Amendments to the Policy
DomainQ reserves the right to update this Privacy Policy in line with legislative amendments, developments in services, or changes in data processing practices.
The current Policy is published on our website, specifying the effective and last update dates. In the event of significant changes, separate notification is additionally made when necessary. Your continued use of our services means that the current Policy applies.
20. Contact
You may contact us for any questions, opinions and requests regarding this Privacy Policy and the processing of your personal data.
E-mail: [email protected]
You may access our Company's current trade name, full address, KEP address and other communication channels from the "Contact" section of our website.
This document is provided for informational purposes only. Please refer to the current version for the final, legally binding text.