GDPR Compliance

Last updated: April 15, 2026

πŸ›‘οΈ GDPR Compliant

ERGENEKON Engine is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act (CCPA), and the Turkish Law on the Protection of Personal Data No. 6698 (KVKK).

1. Our Role Under GDPR

As a Software Tool: ERGENEKON Engine runs entirely on your infrastructure. We are not a data processor or sub-processor for your application data. Your recordings, sessions, and debugging data never leave your servers.

As a Website & License Provider: We act as a Data Controller for the personal data we collect when you purchase a license, contact support, or visit our website.

2. GDPR Compliance Checklist

RequirementStatusImplementation
Lawful basis for processingβœ…Contract, consent, and legitimate interest
Data minimizationβœ…We collect only what's necessary for license delivery
Purpose limitationβœ…Data used only for stated purposes
Storage limitationβœ…Defined retention periods for all data categories
Right to access (Art. 15)βœ…Request via privacy@ergenekon.dev
Right to rectification (Art. 16)βœ…Email us to update your information
Right to erasure (Art. 17)βœ…"Right to be forgotten" β€” request deletion
Right to data portability (Art. 20)βœ…Export your data in JSON format
Right to object (Art. 21)βœ…Opt out of processing based on legitimate interest
Right to restrict processing (Art. 18)βœ…Request limitation of processing
Data breach notification (Art. 33-34)βœ…72-hour notification to authorities; immediate user notification
Privacy by design (Art. 25)βœ…Minimal data collection, Ed25519 crypto, offline validation
Records of processing (Art. 30)βœ…Maintained internally
Data Protection Impact Assessmentβœ…Completed β€” low risk profile
International transfersβœ…Standard Contractual Clauses (SCCs) with sub-processors
Cookie consentβœ…Minimal essential cookies only; no tracking cookies

3. Data We Process

3.1 What We Collect

Data CategoryExamplesLegal BasisRetention
IdentityName, emailContractLicense term + 12 months
FinancialPayment info (via Stripe)Contract7 years (tax law)
TechnicalIP address (anonymized), browser typeLegitimate interest48 hours (IP), 30 days (logs)
CommunicationsSupport emailsLegitimate interest24 months after resolution
MarketingNewsletter emailConsentUntil unsubscribe

3.2 What We Do NOT Collect

4. Sub-Processors

Sub-ProcessorPurposeLocationSafeguards
Stripe, Inc.Payment processingUSASCCs, SOC 2, PCI DSS Level 1
Resend (if used)Transactional emailUSASCCs, SOC 2
Plausible AnalyticsPrivacy-first analyticsEUNo personal data processed
GitHub (Microsoft)Source code hostingUSASCCs, SOC 2, ISO 27001

5. Your GDPR Rights

As an EU/EEA resident, you have the following rights. All requests will be processed within 30 days:

How to exercise your rights:

Email privacy@ergenekon.dev with the subject line "GDPR Request: [Right Name]". Include your registered email address for identity verification. We will respond within 30 days.

6. Data Breach Response

In the event of a personal data breach:

  1. Within 24 hours: Internal investigation and containment.
  2. Within 72 hours: Notification to the relevant supervisory authority (as required by Article 33).
  3. Without undue delay: Notification to affected individuals if the breach poses a high risk to their rights and freedoms (Article 34).

7. Privacy by Design

ERGENEKON Engine is architected with privacy at its core:

8. California Residents (CCPA)

Under the California Consumer Privacy Act:

9. Turkish Data Protection (KVKK)

We comply with the Turkish Law on the Protection of Personal Data No. 6698 (KVKK). As the data controller:

10. Contact the Data Controller

Data Controller: İlhan Gâktaş

Email: privacy@ergenekon.dev

Website: ergenekon.dev

If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority: