Last updated: 13 September 2026
This notice explains how personal data is handled when you visit zeniterp.com or contact us. Processing in the application is covered separately by the Zenit Privacy Policy and Privacy Notice.
1. Controller
| Business | Ferhat Canberk Döğer (sole proprietorship, trading as ZenitERP) |
|---|---|
| ESBİS registration no | 1001549 |
| Tax office / tax no | Büyükçekmece Tax Office / 3110172344 |
| Address | Cumhuriyet Mah. D-100 Karayolu Cad. ADM Konaklama Outlet Park AVM No: 374 İç Kapı No: 63, Büyükçekmece / Istanbul, Türkiye |
| [email protected] | |
| Phone | +90 850 840 96 04 |
2. Data we process
Website visits: Server and Cloudflare security logs may contain IP address, date/time, requested page, browser type and referring address. Aggregate visits are measured with Umami, which writes no cookie or browser identifier. Only if you enable the analytics preference, Google Analytics 4 (GA4) processes page views, traffic source, approximate device/browser information and truncated IP data. We do not use advertising personalisation or cross-site advertising tracking.
Enquiries and quotations: Your name, company, e-mail, phone and message are used to answer the enquiry, prepare a quotation and continue correspondence.
Registration and payment: If you create a free trial account, account, company and security data is processed under the application notices. Zenit has contracted with iyzico; card checkout will be enabled after the website and production review is complete. Once enabled, full card data is processed on iyzico's hosted page and never reaches Zenit. Until then, orders and payment methods are confirmed in writing.
3. Purposes and legal bases
Data is processed to answer requests and take pre-contract steps, secure the website, prevent misuse and protect legal rights. The relevant KVKK Article 5(2) grounds are steps needed before a contract, legal obligation, establishment or defence of rights, and legitimate interests that do not override fundamental rights. GA4 runs only while your revocable analytics preference is enabled. Marketing messages are not sent without the required permission and an unsubscribe method.
4. Recipients and international transfers
Data may be disclosed on a need-to-know basis to authorised personnel, the accountant and competent authorities. Cloudflare may provide security and content delivery; Google Workspace transactional e-mail; iyzico card payment; and Google Ireland Limited and Google LLC GA4 analytics, but only while your analytics preference is enabled. GA4 data may be processed outside Türkiye. International transfers use an applicable KVKK Article 9 transfer condition and safeguard. The analytics choice controls cookie access on your device; it does not replace the legal mechanism required for an international transfer. The cookieless Umami setup does not use a browser identifier that recognises a person across visits.
5. Retention and security
Correspondence is retained for three years, security logs for one year, pre-contract records for the relevant limitation period and GA4 event data for no more than 14 months. Your cookie preference remains in the browser for one year. Statutory records follow the mandatory period. Data is then erased, destroyed or anonymised. Internet connections use HTTPS/TLS and access is limited by role.
6. Rights and requests
Send a KVKK Article 11 request containing enough information to verify your identity from the e-mail address registered in our system to [email protected], or write to the postal address above. Requests are handled under the statutory procedure and time limit. For data entered into the application by a customer company, contact that company first.
7. Changes
The current notice is published on this page. Material changes are announced, where appropriate, by e-mail or in-app notice to registered users.