Last updated: 13 September 2026
1. Scope and roles
The ZenitERP service provider is Ferhat Canberk Döğer (sole proprietorship, trading as ZenitERP), ESBİS: 1001549, Büyükçekmece Tax Office / VKN 3110172344, Cumhuriyet Mah. D-100 Karayolu Cad. ADM Konaklama Outlet Park AVM No: 374 İç Kapı No: 63, Büyükçekmece / Istanbul, Türkiye (“Zenit”). You can reach us at [email protected] or +90 850 840 96 04.
Zenit is controller for account creation, authentication, security, support, contracting and billing data. The customer company is controller for employee, applicant, customer, supplier and other business data it enters in ZenitERP; Zenit processes that Customer Data only on the customer's documented instructions.
2. Data, purposes and legal bases
Account and contact details are used to set up the service, verify users, provide support and perform the agreement. Session, IP, device and audit records are used to secure the service, enforce permissions and prevent misuse. Quotation, order and invoice data are used for contracting, accounting and tax obligations. Customer Data is processed only to provide the app functions selected by the customer.
The relevant bases are entering into and performing a contract, compliance with legal obligations, establishing or defending legal claims, and legitimate interests that do not override individual rights. Special-category data is processed only where an appropriate KVKK Article 6 and, where applicable, GDPR Article 9 condition and safeguards exist. Zenit does not request bundled consent for marketing or general processing during registration.
3. Recipients and international transfers
Data may be disclosed on a need-to-know basis to authorised personnel, customer administrators, the accountant and competent authorities. Technical providers may include Cloudflare; Google Workspace and Google Drive for transactional mail and encrypted backup; Firebase Cloud Messaging for Android notifications; and Apple for iOS notifications. Zenit has contracted with iyzico for card payments; checkout will be enabled after the website and production review, and full card data will not reach Zenit. A GİB e-document integrator is not currently active.
Personal data is not transferred outside Türkiye until an appropriate KVKK Article 9 condition and safeguard are in place. A Turkish standard contract is notified to the Authority within the statutory period where used. EEA-originating data also requires an effective GDPR Chapter V safeguard and transfer assessment.
4. Retention and deletion
Account data is retained during the agreement and for a 30-day export period after it ends; security records for one year; support correspondence for three years; and contracts, orders and accounting records for the applicable statutory period. Trial data that does not convert to a subscription remains read-only for 60 days after the trial. Deletion reminders are sent 7 days and 1 day before deletion. Residual copies in backups expire through the ordinary backup cycle.
5. Security and rights
Internet connections use HTTPS, access is role-based and administrator services use multi-factor authentication. Report a security or personal-data incident to [email protected].
To exercise KVKK Article 11 rights, send a request containing enough information to verify your identity from the e-mail address registered in our system to [email protected], or write to Cumhuriyet Mah. D-100 Karayolu Cad. ADM Konaklama Outlet Park AVM No: 374 İç Kapı No: 63, Büyükçekmece / Istanbul, Türkiye. Requests concerning Customer Data should first be addressed to the relevant customer company. GDPR rights of access, rectification, erasure, restriction, portability and objection apply where the GDPR applies.