Last updated: April 15, 2026
ERGENEKON Engine is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act (CCPA), and the Turkish Law on the Protection of Personal Data No. 6698 (KVKK).
As a Software Tool: ERGENEKON Engine runs entirely on your infrastructure. We are not a data processor or sub-processor for your application data. Your recordings, sessions, and debugging data never leave your servers.
As a Website & License Provider: We act as a Data Controller for the personal data we collect when you purchase a license, contact support, or visit our website.
| Requirement | Status | Implementation |
|---|---|---|
| Lawful basis for processing | β | Contract, consent, and legitimate interest |
| Data minimization | β | We collect only what's necessary for license delivery |
| Purpose limitation | β | Data used only for stated purposes |
| Storage limitation | β | Defined retention periods for all data categories |
| Right to access (Art. 15) | β | Request via privacy@ergenekon.dev |
| Right to rectification (Art. 16) | β | Email us to update your information |
| Right to erasure (Art. 17) | β | "Right to be forgotten" β request deletion |
| Right to data portability (Art. 20) | β | Export your data in JSON format |
| Right to object (Art. 21) | β | Opt out of processing based on legitimate interest |
| Right to restrict processing (Art. 18) | β | Request limitation of processing |
| Data breach notification (Art. 33-34) | β | 72-hour notification to authorities; immediate user notification |
| Privacy by design (Art. 25) | β | Minimal data collection, Ed25519 crypto, offline validation |
| Records of processing (Art. 30) | β | Maintained internally |
| Data Protection Impact Assessment | β | Completed β low risk profile |
| International transfers | β | Standard Contractual Clauses (SCCs) with sub-processors |
| Cookie consent | β | Minimal essential cookies only; no tracking cookies |
| Data Category | Examples | Legal Basis | Retention |
|---|---|---|---|
| Identity | Name, email | Contract | License term + 12 months |
| Financial | Payment info (via Stripe) | Contract | 7 years (tax law) |
| Technical | IP address (anonymized), browser type | Legitimate interest | 48 hours (IP), 30 days (logs) |
| Communications | Support emails | Legitimate interest | 24 months after resolution |
| Marketing | Newsletter email | Consent | Until unsubscribe |
| Sub-Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Stripe, Inc. | Payment processing | USA | SCCs, SOC 2, PCI DSS Level 1 |
| Resend (if used) | Transactional email | USA | SCCs, SOC 2 |
| Plausible Analytics | Privacy-first analytics | EU | No personal data processed |
| GitHub (Microsoft) | Source code hosting | USA | SCCs, SOC 2, ISO 27001 |
As an EU/EEA resident, you have the following rights. All requests will be processed within 30 days:
How to exercise your rights:
Email privacy@ergenekon.dev with the subject line "GDPR Request: [Right Name]". Include your registered email address for identity verification. We will respond within 30 days.
In the event of a personal data breach:
ERGENEKON Engine is architected with privacy at its core:
Under the California Consumer Privacy Act:
We comply with the Turkish Law on the Protection of Personal Data No. 6698 (KVKK). As the data controller:
If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority: