Privacy Policy

Effective Date: 26 August 2026

1. Scope

This Privacy Policy explains how personal data is processed in connection with the MaviHost website, customer panel, cloud infrastructure and related digital Services, support channels, transactions, and business operations.

This Policy is intended to provide general information about personal data processing activities carried out by MaviHost.

Where MaviHost processes personal data contained in Customer-controlled environments solely on behalf of the Customer for the purpose of providing the relevant Service, MaviHost may act as a data processor in relation to that processing activity.


2. Privacy Notices and Explicit Consent

This Privacy Policy provides general information about MaviHost’s personal data processing activities.

Where required by the Turkish Personal Data Protection Law No. 6698 (KVKK) or other applicable legislation, a separate or activity-specific privacy notice may be provided at the point where personal data is collected for the relevant processing activity.

Such notices may include information specific to the relevant processing activity, such as account registration, identity or payment verification, support, marketing, cookies, or a particular Service.

Providing a privacy notice and obtaining explicit consent are separate matters. Acceptance of the Terms of Service or acknowledgment that this Privacy Policy has been read or viewed does not constitute explicit consent where separate explicit consent is legally required.

Where explicit consent is required, it is requested separately and specifically for the relevant processing activity.


3. Personal Data We May Process

Depending on your relationship with MaviHost and the Services you use, the following categories of personal data may be processed:

3.1. Identity, Account, and Contact Data

This may include name and surname, customer or account identifier, company name, authorized representative information, email address, telephone number, billing or correspondence address, and tax or business identification information where required.

3.2. Order, Billing, and Payment Data

This may include Services purchased, order and invoice information, billing period, transaction amount, currency, payment method, payment status, refund information, account balance, transaction identifiers, and limited payment information provided by payment institutions.

3.3. Verification Data

Where verification is reasonably necessary for payment security, fraud prevention, account security, or compliance with legal obligations, information necessary to verify identity, account ownership, or payment authorization may be processed.

Depending on the verification process, this may include identity document information, verification photographs, payment card images with masked card information, and related verification records or communications.

3.4. Service, Technical, and Security Data

This may include Service configuration, Service location, domain names, allocated IP addresses, resource information, activation and expiration information, renewal status, usage information, IP address, device or browser information, authentication records, login and access records, session information, security logs, and fraud or abuse indicators.

3.5. Support and Communication Data

This may include support requests, email or chat communications, complaints, technical troubleshooting information, attachments, Service identifiers, and other information provided when communicating with MaviHost.

3.6. Website, Cookie, and Marketing Preference Data

Where applicable, this may include cookie or session identifiers, website interaction information, language preferences, marketing permission or rejection records, and related communication preferences.


4. How We Collect Personal Data

Personal data may be collected:

  1. Directly from you: When you create an account, place an order, make a payment, complete a verification process, contact support, or provide information in connection with a Service;
  2. Automatically through MaviHost systems: When you use the website, customer panel, Services, APIs, authentication systems, or infrastructure;
  3. From service providers or other parties involved in a transaction: Including payment institutions, banks, fraud-prevention providers, domain registries or registrars, Certificate Authorities, software licensors, and infrastructure providers; and
  4. From your organization or authorized representative: Where an account or Service is managed on your behalf.

5. Purposes and Legal Bases of Processing

Personal data is processed only where a valid legal basis exists under applicable legislation.
Depending on the relevant processing activity, personal data may be processed for the following purposes and legal bases:

Account, Order, and Service Management

Personal data may be processed to create and manage accounts, authenticate users, process orders, activate and provide Services, manage configurations, renewals and cancellations, provide support, and perform contractual obligations.

Such processing may be based on necessity for the establishment or performance of a contract.

Billing and Payment

Personal data may be processed to process and verify payments, issue invoices, manage account balances and refunds, maintain financial records, and handle payment-related issues.

Depending on the relevant activity, such processing may be based on the establishment or performance of a contract, compliance with a legal obligation, or the establishment, exercise, or protection of a legal right.

Security, Verification, Fraud Prevention, and Abuse Prevention

Personal data may be processed to protect accounts and infrastructure, verify identity or payment authorization where necessary, detect and investigate unauthorized or fraudulent activity, prevent abuse, and maintain Service and network security.

Depending on the relevant activity, such processing may be based on legitimate interests, provided that the fundamental rights and freedoms of the data subject are not overridden, the establishment, exercise, or protection of a legal right, necessity for the establishment or performance of a contract, or compliance with a legal obligation.

Legal and Regulatory Compliance

Personal data may be processed to comply with tax, accounting, electronic commerce, record-keeping, judicial, administrative, regulatory, and other applicable legal obligations.

Such processing may be based on compliance with a legal obligation or where processing is expressly provided for by law.

Marketing

Personal data may be processed for marketing communications and the management of marketing permissions where legally permitted.

Where explicit consent or prior approval for commercial electronic communications is required, the relevant approval is obtained separately in accordance with applicable legislation.


6. Customer Content and Data Processor Role

MaviHost Services may enable Customers to store, host, transmit, back up, or otherwise process data relating to their own users, employees, customers, or other persons.

For personal data contained in Customer-controlled content or environments, the Customer may act as the data controller. MaviHost may act as a data processor to the extent that it processes such data solely on behalf of the Customer for the purpose of providing the relevant Service.

The Customer is responsible for ensuring that such personal data processing activities are lawful and for fulfilling the obligations applicable to it as a data controller.

MaviHost does not acquire ownership of Customer Content merely because it is stored or processed through MaviHost Services.

Where the purposes and means of a particular processing activity are independently determined by MaviHost, the responsibilities prescribed under applicable personal data protection legislation apply in relation to that activity.


7. Sharing of Personal Data

Personal data may be shared where necessary for the relevant purpose and permitted by applicable law.

Depending on the Service and processing activity, recipient categories may include:

  • Banks, payment institutions, payment processors, and fraud-prevention providers: For payment, refund, verification, fraud-prevention, or payment-dispute purposes;
  • Infrastructure, network, storage, security, communication, and technical service providers: Where necessary to provide or operate the Services;
  • Domain registries, registrars, Certificate Authorities, software licensors, and other product providers: Where necessary to provide a Service requested by the Customer;
  • Accountants, auditors, legal advisers, and other professional advisers: Where necessary for legal, financial, compliance, or professional purposes; and
  • Courts, law-enforcement bodies, tax authorities, regulators, administrative authorities, and other competent public bodies: Where disclosure is required or permitted by law.

Only personal data reasonably necessary for the relevant purpose is shared.


8. International Transfers

MaviHost offers Services that may use infrastructure or Service locations inside or outside Türkiye.

Where the Customer selects a Service located outside Türkiye, Customer Content and Service-related data necessary to provide that Service may be processed in the relevant location.

Where a foreign infrastructure, technology, communication, security, or other service provider is actually used for the relevant processing activity, personal data may be transferred outside Türkiye.

Where personal data is transferred outside Türkiye, the transfer is carried out in accordance with Article 9 of KVKK and, to the extent applicable, other applicable personal data protection legislation.


9. Cookies and Similar Technologies

The MaviHost website and customer panel may use cookies and similar technologies for authentication, session management, security, storing preferences, website functionality, analytics, and, where lawfully enabled, marketing purposes.

Where explicit consent is required under applicable law for non-essential cookies, the relevant cookies are not activated before the required explicit consent is obtained.

Additional information about cookies and available preference options may be provided through the relevant cookie notice or cookie preference interface.


10. Marketing Communications

Marketing communications are managed separately from communications necessary to operate an account, process a transaction, provide a Service, maintain security, or comply with legal obligations.

Where prior approval is required for commercial electronic communications, the required approval is obtained separately.

Where applicable, commercial electronic communication approvals and rejection requests may be recorded or managed through the İleti Yönetim Sistemi (İYS) in accordance with applicable Turkish electronic commerce legislation.

Withdrawal of marketing permission does not prevent necessary transactional, billing, security, support, or Service-related communications from being sent.


11. Data Security

Appropriate technical and administrative measures are taken to protect personal data against unlawful processing, unauthorized access, loss, alteration, disclosure, or destruction, in accordance with applicable legislation and the nature of the relevant processing activity.

Access to personal data is limited according to operational need and authorization.


12. Data Retention

Personal data is retained only for as long as necessary for the purpose for which it is processed and for any additional period required by applicable tax, accounting, commercial, consumer, electronic commerce, personal data protection, or other legal obligations.

Where a valid legal basis exists, retention periods may also take into account legitimate requirements relating to security, fraud prevention, dispute resolution, and the protection of legal rights.

When the legal grounds and purposes requiring processing no longer exist, personal data is deleted, destroyed, or anonymized in accordance with applicable legislation.

Customer Content and hosted data are also subject to the applicable Service term, cancellation conditions, backup cycles, and technical deletion processes.


13. Rights and Applications Under KVKK

Where KVKK applies, data subjects may exercise the rights granted to them under Article 11 of KVKK.

These rights may include requesting information about the processing of personal data, requesting correction of inaccurate data, requesting deletion or destruction where the legal conditions are met, obtaining information about transfers, objecting to certain processing carried out exclusively through automated systems, and requesting compensation where damage is suffered as a result of unlawful personal data processing.

Requests concerning these rights may be submitted through MaviHost’s current official communication or support channels using methods permitted under applicable legislation.

Information reasonably necessary to verify the identity of the applicant and protect personal data against unauthorized disclosure or modification may be requested.

Requests are handled as soon as possible and, where the statutory maximum period under KVKK applies, no later than 30 days. Requests are generally handled free of charge; however, a fee may be charged where permitted under the applicable tariff or legislation.

Where applicable, data subjects may also exercise their right to apply to the Turkish Personal Data Protection Board in accordance with the conditions and procedures established by applicable legislation.


14. Changes

MaviHost may update this Privacy Policy where necessary to reflect changes in applicable legislation, Services, personal data processing activities, technology, infrastructure, or operational practices.

The current version will be published together with its effective or last-updated date.

Where applicable legislation requires a separate privacy notice or explicit consent for a particular personal data processing activity, updating this Privacy Policy does not replace that requirement.