Summarises in one place the principles under which we collect, use, share and protect your personal data. It also shows which document to consult for details.
1. Purpose
This Privacy Policy summarises in one place the principles under which we, as TTEN Teknoloji A.Ş., collect, use, share and protect your personal data. Its purpose is to show which document you should refer to.
The policy does not repeat three separate documents; it directs you to them:
The purposes, legal grounds and collection methods for processing your data: KVKK Privacy Notice
Cookie types, the cookies used on the site and managing your cookie settings: Cookie Policy
Rules for the use of our websites and services: Terms of Use
The form of the application you will make to exercise your rights: KVKK Application Form
In the event of any conflict between the Privacy Notice and this policy, the Privacy Notice prepared under Article 10 of the Law shall prevail.
2. Scope
This policy applies to the following domain names operated by TTEN Teknoloji A.Ş. and the services offered through them:
tten.net (promotional site)
store.tten.net (online sales)
core.tten.net (customer panel)
Our websites may contain links to sites belonging to third parties. This policy covers only the domain names listed above. We are not responsible for the privacy practices of the sites we link to.
3. Data controller
Trade name: TTEN Teknoloji A.Ş.
Tax office / number: Ziyapaşa / 8591442515
Trade registry number: 94489 (Adana)
MERSİS number: 859144251500001
Address: Cemalpaşa Mah. Gazipaşa Blv. No: 20/11 Seyhan / Adana
General e-mail: [email protected]
KVKK application e-mail: [email protected]
Telephone: 0850 307 31 31
VERBİS registration information: tten is not registered with the Data Controllers Registry because it falls below the VERBİS registration obligation threshold
4. Categories of personal data processed
The categories below vary according to the type of your relationship. The data of a person who merely visits our website is not the same as the data of a customer who purchases a service.
Identity information: First name, surname and, within the scope of the invoicing obligation, Turkish ID number
Contact information: Telephone number, e-mail address, address
Financial information: Invoice information, payment information, bank or card information
Transaction security data: IP address, log records, username, website activity
Customer transaction information: Purchase history, service usage information, support requests
Marketing information: Cookie records, survey and campaign responses
We do not collect date of birth, gender, marital status, education status or photograph information. We do not process special categories of personal data. In accordance with the data minimisation principle of the Law, we do not collect any category that the service does not require.
During payment, your card information is processed through the payment infrastructures of PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş. and iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. Your card information is not stored in tten's systems.
5. Processing purposes
We process your data in order to provide the service, to invoice, to ensure security, to fulfil our legal obligations and, to the extent you permit, to carry out promotional activities. The full list of purposes, the legal ground on which each purpose is based and the methods of data collection are set out in the KVKK Privacy Notice.
Processing for marketing and advertising purposes is additionally based on the explicit consent you give. You may withdraw your consent at any time. Your withdrawal request takes effect from the moment it reaches us.
6. Sharing of data
We do not sell your personal data. Sharing takes place only in the following cases and only to the extent required by the purpose that necessitates the sharing:
With public institutions and organisations authorised by law, when there is a request or obligation arising from legislation
With the suppliers and service providers we work with in order to provide the service (such as payment, invoicing, e-mail delivery, measurement)
With our lawyers and competent authorities in order to protect our rights in a legal dispute
When working with our suppliers, we contractually guarantee that your data is processed only for the purpose we determine and that appropriate security measures are taken.
7. Transfer abroad
We distinguish between two sets of data:
The data on your servers remains at service points in Türkiye and is not transferred abroad by tten.
Your personal data within the scope of this policy is, as a rule, processed in Türkiye. Transfer abroad occurs in three cases: (a) The providers of the measurement, advertising and session recording tools we use on our sites (section 9) may transfer the data collected through these tools to their servers abroad. For example, Mouseflow session recordings are kept in Europe (Amsterdam) and retained for 30 days. These transfers are based on the consent to transfer abroad submitted for your approval in the Explicit Consent Text. (b) Our live chat window runs on the infrastructure of Tidio LLC. The company is registered in the USA; the data is kept in Europe. The tool is not loaded when the page opens: it is activated only when you start the chat, and from that moment on what you write is transferred to the provider's infrastructure. If you do not start the chat, this transfer does not take place. (c) We send transactional notifications relating to your account (proforma, payment reminder, suspension warning) through the infrastructure of MailerSend, Inc., registered in the USA. This transfer is mandatory for the performance of the contract and is not dependent on explicit consent. Details are in section 8 of the KVKK Privacy Notice.
8. Data controller and data processor roles
When one of our customers processes the data of its own users on tten's infrastructure, the roles change: the customer is the data controller and tten is the data processor. tten touches that data only to the extent necessary to provide the service and upon the customer's instruction. The data inside the servers is at the customer's layer.
This relationship is governed by the standard Data Processing Agreement (DPA) approved in the order flow. It is also signed separately with corporate customers who request it. The full text of the agreement is on the Data Processing Agreement page.
9. Cookies and measurement
We use cookies and similar technologies on our website. Cookie types, the individual cookie list and the steps for managing cookies from your browser settings are set out in the Cookie Policy. Below you see only the third-party tools active on the site:
Google Tag Manager · Identifier: GTM-KJ8SPR44 · Purpose of use: Management of measurement tags · Cookie type: Management layer
Google Analytics 4 · Identifier: G-P8WVGYR16K · Purpose of use: Analysis of visitor behaviour · Cookie type: Analytics
Google Ads conversion linker · Identifier: Conversion Linker · Purpose of use: Matching an advertisement click with a conversion · Cookie type: Advertising
LinkedIn Insight Tag · Identifier: 2.0 · Purpose of use: Advertisement measurement and audience building · Cookie type: Advertising
X (Twitter) pixel · Identifier: Base Pixel + Website Pixel · Purpose of use: Advertisement measurement and audience building · Cookie type: Advertising
Mouseflow · Identifier: — · Purpose of use: Session recording and heat map: recording of mouse movement, clicks and page navigation. What you type into form fields is masked and is not included in the recording. Recordings are kept in Europe (Amsterdam) and retained for 30 days · Cookie type: Analytics, session recording
Tidio · Identifier: — · Purpose of use: Live chat: loaded only when you start the chat. The chat content and the contact details you leave are processed on the provider's infrastructure. The provider is Tidio LLC (registered in the USA); the data is kept in Europe · Cookie type: Functional, live chat
Framer · Identifier: The site's publishing platform · Purpose of use: Operation of the site · Cookie type: Strictly necessary, functional
We obtain your consent for non-necessary cookies through the cookie notice. In the notice, the accept and reject options are presented with equal ease. You can turn functional, analytics and advertising cookies on and off separately. Until you make a selection, none of these tools are loaded. A type you reject is not loaded at all. You may withdraw your consent at any time and delete cookies from your browser settings. Details are in section 7 of the Cookie Policy.
10. Retention periods
We retain your personal data for the period necessary for the purpose for which it is processed and for the retention periods stipulated by legislation. When the period expires, the data is erased, destroyed or anonymised.
Retention periods by category are set out, as the single source, in the table in section 11 of the KVKK Privacy Notice. This policy does not repeat that table.
11. Data security
We take technical and administrative measures to protect your personal data against unauthorised access, loss and unlawful processing. These measures include access authorisation, transaction-based log records and regular backups.
Operations performed through Core Panel and Public API are logged and customers can view these records in Core Panel. The applications and sessions running inside your servers are within your layer of responsibility. tten does not log this layer. The details of the responsibility split are set out on our Responsibility Model page.
12. Your rights
Pursuant to Article 11 of the Law, as a data subject whose personal data is processed, you have the following rights:
To learn whether your personal data is processed
To request information if your personal data has been processed
To learn the purpose of processing your personal data and whether it is used in accordance with that purpose
To know the third parties to whom your personal data is transferred in Türkiye or abroad
To request the rectification of your personal data if it has been processed incompletely or inaccurately
To request the erasure or destruction of your personal data within the framework of Article 7 of the Law
To request that the rectification, erasure or destruction operations be notified to the third parties to whom your data has been transferred
To object to a result arising against you through the analysis of the processed data exclusively by automated systems
To claim compensation for the damage if you suffer damage due to the unlawful processing of your personal data
13. Exercising your rights
You may submit your requests by completing the KVKK Application Form. The form contains the information required by the Communiqué on the Procedures and Principles of Application to the Data Controller and sets out one by one the accepted application channels (written application, registered electronic mail, secure electronic signature, mobile signature, the e-mail address registered in our system).
Your application is concluded as soon as possible and in any case within thirty days, depending on the nature of your request. We cannot conclude applications where we are unable to verify your identity, in order not to disclose another person's data to a third party.
14. Changes to the policy
We may update this policy due to changes in legislation and updates to our services. The current version is always published on this page and the date of last update appears at the beginning of the document. When we make a comprehensive change, we will also inform you separately.
15. Contact
You may send your questions about this policy to [email protected]. For general matters you may use the address [email protected] and the number 0850 307 31 31.