GNSAC
Privacy & Data Protection

Privacy Notice

Last updated: 24 August 2026

Effective date: 24 August 2026

1. Data controller and scope

For website visits, demo and contact requests, commercial communications and GNSAC’s own account-management activities, the data controller is: GNSAC Bilişim Teknolojileri Ltd. Şti. Şefikbey Sokak Archerson Köşkü No:3, Oda No:301 Kadıköy – Zühtüpaşa, TR-34724 İstanbul, Türkiye İstanbul Ticaret Sicili: 302689-5 MERSİS No: 0396135396400001 Vergi Dairesi: Göztepe V.D. · Vergi Kimlik No: 3961353964 This notice primarily explains processing under Türkiye’s Personal Data Protection Law No. 6698 (KVKK). Where another law applies, including the GDPR, the relevant customer agreement or a supplementary notice may also apply. For customer-configured product data, GNSAC’s role may instead be that of a data processor acting on the customer’s documented instructions.

2. Data categories and collection method

Depending on your interaction, we may process: • Identity and professional contact data: name, work e-mail, company, job-related context and optional phone number • Request content: selected subject, message, authorised domains or technical requirements you choose to provide • Communication records: replies, support correspondence and meeting records • Transaction records: quote, order, billing and account-administration data where a commercial relationship is established • Technical security data: IP address, request time, browser/device information, security and administrative logs • Product data: data processed within Vigil or Phishing according to the selected deployment and customer instructions Data is collected electronically through the website form, e-mail, phone, meetings, contracts, product interfaces and system logs, by wholly or partly automated means or, where applicable, non-automated means forming part of a filing system. Please do not submit special-category data, passwords, live credentials or unrelated third-party personal data through the public contact form.

3. Purposes and legal grounds

We process personal data only for specified purposes and on an applicable legal ground: • Answering a demo, sales, partnership or support request; arranging a meeting; preparing a quote: processing necessary to establish or perform a contract (KVKK Art. 5/2(c)) and GNSAC’s legitimate interest in managing requested business communications, provided that your fundamental rights are not harmed (Art. 5/2(f)) • Operating and securing the website and contact channel; preventing abuse and keeping security records: legitimate interests in service and information security (Art. 5/2(f)) • Billing, accounting and compliance records: compliance with legal obligations where applicable (Art. 5/2(a) and 5/2(ç)) • Establishing, exercising or protecting legal claims: Art. 5/2(e) • Marketing messages that require permission: only after obtaining the permission or consent required by applicable law; this is separate from the contact-form notice If a purpose materially changes, a separate or updated notice will be provided before the new processing begins.

4. Recipients and international transfers

Personal data may be disclosed, only to the extent necessary for the stated purpose, to authorised GNSAC sales, support, finance, legal and security personnel; hosting, e-mail, communications and information-security service providers acting under appropriate obligations; professional advisers and auditors; and competent public authorities where legally required. The contact form is delivered through Google Workspace e-mail infrastructure. Hosting, communications or support providers may process data outside Türkiye depending on their service architecture and subprocessors. Any international transfer must be handled in accordance with KVKK Art. 9, including an adequacy decision, an appropriate safeguard such as the applicable standard contract, or another legally available mechanism. Customer-specific data-location requirements are addressed during security and contractual scoping.

5. Security and retention

We apply risk-appropriate technical and organisational measures, which may include transport encryption, access controls, least privilege, activity logging, backups and incident-management procedures. No transmission or storage method can be guaranteed to be completely secure. Personal data is retained only for the period required by the stated purpose and applicable contractual, security, accounting, legal and limitation-period requirements. Contact correspondence is deleted, anonymised or access-restricted when it is no longer needed for the request or related record-keeping. Product-data retention and deletion follow the selected deployment, documented customer instructions and the applicable agreement.

6. Your rights and how to apply

Under KVKK Art. 11, you may ask whether your personal data is processed; request information about processing; learn the purpose and whether data is used accordingly; learn recipients in Türkiye or abroad; request correction; request deletion or destruction under Art. 7; request that correction, deletion or destruction be notified to recipients; object to an adverse result produced exclusively by automated analysis; and claim compensation if you suffer damage from unlawful processing. Send a clear request to [email protected], to our registered address, or by another method permitted under the Communiqué on Application Procedures and Principles. Include enough information to verify your identity and identify the requested processing; do not send passwords or unnecessary sensitive documents. We respond as soon as possible and no later than 30 days, free of charge unless a fee is permitted by the applicable tariff. Statutory complaint rights remain reserved.

7. Contact-form specific notice

When you submit the form, GNSAC processes your name, work e-mail, company, selected request subject, optional phone and message, together with limited anti-abuse and request logs. The purposes are to authenticate and route the request, respond, arrange an evaluation or support interaction, prepare requested commercial information, protect the channel and preserve necessary business records. Required fields are marked in the form. The phone number and message are optional. Form submission is not consent to unrelated advertising. A customer-domain assessment or security test begins only after scope and authority are separately confirmed. You may use [email protected], [email protected], [email protected], [email protected] or [email protected] for the relevant purpose.

8. Cookies and similar technologies

The public website currently uses only technology necessary to deliver the site and remember a language choice in your browser. We do not use the contact form as a condition for advertising consent. If non-essential analytics or marketing technologies are introduced, they must be separately disclosed and, where required, remain disabled until a valid preference is recorded. You can also manage stored data through your browser settings.

9. Updates and contact

We may update this notice when processing activities or legal requirements change. The current version and effective date are published on this page. Material changes affecting a contracted service are communicated through the applicable contractual or service channel. Privacy: [email protected] · Legal: [email protected] · Phone: +90 216 706 40 65
Privacy Notice | GNSAC