ZeroDoor — Zerone Security

Privacy & KVKK Notice

Version 2026-08-03

This notice explains how Zerone Security ("we") processes personal data in connection with the ZeroDoor platform. ZeroDoor is a B2B service: for most data processed through the platform (server telemetry your organization collects), your organization is the data controller and we act as a data processor on its documented instructions.

What we process

  • Account data — name, work email, hashed password, role, MFA status; sign-in metadata (IP address, user agent, timestamps).
  • Organization data — organization name, address (slug), plan and license state, settings.
  • Audit records — tamper-evident logs of actions taken in the platform (actor, action, IP, timestamp), kept for compliance purposes.
  • Server telemetry (processed for your organization) — file integrity events from servers your organization monitors: hostnames, file paths, file metadata and hashes, and where applicable system usernames associated with file changes or access.

Why and on what legal basis

  • To provide the Service under our contract with your organization (KVKK m.5/2-c; GDPR Art. 6(1)(b)).
  • To secure the platform — abuse prevention, audit trails, incident response — as a legitimate interest and legal obligation (KVKK m.5/2-a, ç, f; GDPR Art. 6(1)(c), (f)).
  • To send account verification and security notifications (contract performance).

Retention

Telemetry streams have configurable retention with per-plan ceilings; audit records are kept longer for compliance. When an organization is deleted, its data is purged from primary stores; backups roll off on a fixed schedule. Suspended trial organizations are retained for a reasonable period before deletion.

Cookies and browser storage

ZeroDoor is an authenticated console and sets no advertising, analytics or cross-site tracking cookies. What it does store on your device is limited to what the console needs to work:

  • Session cookie — issued at sign-in to keep you authenticated. Strictly necessary (KVKK m.5/2-c; GDPR Art. 6(1)(b)); cleared on sign-out.
  • Language preference (NEXT_LOCALE) — written only when you choose a language from the user menu, and holding only that choice (en, tr or ar). It carries no identifier. Clearing it returns the console to negotiating from your browser's language settings.
  • Local browser storage — interface preferences (theme, density, display time zone) and, for platform operators only, the tenant currently being operated as. These stay on your device; they are not sent to us as personal data.

Sharing and sub-processors

We do not sell personal data. We use a limited set of sub-processors (for example an email delivery relay for verification and notification mail, and — where your organization enables threat-intelligence features — lookups of file and package metadata against our threat-intelligence service). The current sub-processor list is available on request and will be published before general availability.

Your rights

Data subjects may exercise access, rectification, erasure and objection rights (KVKK m.11; GDPR Arts. 15-21) by contacting us at contact@zeronesecurity.com. Where we act as processor we will refer the request to your organization, the controller.

KVKK Aydınlatma Metni (Türkçe)

Bu bölüm, 6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") m.10 uyarınca aydınlatma yükümlülüğünün yerine getirilmesi amacıyla hazırlanmıştır. Veri sorumlusu: Zerone Security (iletişim: contact@zeronesecurity.com).

İşlenen kişisel veriler: ad-soyad, kurumsal e-posta, şifre özeti, rol ve oturum bilgileri (IP adresi, tarayıcı bilgisi, zaman damgaları) ile platform üzerinde gerçekleştirilen işlemlere ait denetim kayıtları. Kuruluşunuz adına izlenen sunuculardan gelen dosya bütünlüğü telemetrisi (sunucu adları, dosya yolları, dosya değişiklikleriyle ilişkili sistem kullanıcı adları) bakımından veri sorumlusu kuruluşunuzdur; Zerone Security veri işleyen sıfatıyla hareket eder.

İşleme amaçları ve hukuki sebepler: hizmetin sunulması ve sözleşmenin ifası (KVKK m.5/2-c), platform güvenliğinin sağlanması ve denetim kayıtlarının tutulması (KVKK m.5/2-a, ç ve f), hesap doğrulama ve güvenlik bildirimlerinin iletilmesi.

Çerezler ve tarayıcı depolaması: ZeroDoor reklam, analitik veya siteler arası izleme çerezi kullanmaz. Cihazınızda saklananlar konsolun çalışması için gerekli olanlarla sınırlıdır: oturum açtığınızda verilen oturum çerezi (zorunlu çerez, KVKK m.5/2-c; oturum kapatıldığında silinir); yalnızca kullanıcı menüsünden bir dil seçtiğinizde yazılan ve yalnızca bu tercihi (en, tr veya ar) tutan NEXT_LOCALE dil tercihi çerezi (kimlik bilgisi içermez; silindiğinde tarayıcı dil ayarlarınıza göre pazarlığa dönülür); ve cihazınızda kalan arayüz tercihleri (tema, yoğunluk, görüntüleme saat dilimi).

Aktarım: kişisel veriler, hizmetin sağlanması için gerekli sınırlı alt işleyenlere (ör. e-posta iletim altyapısı) aktarılabilir; güncel alt işleyen listesi talep üzerine paylaşılır. Yurt dışına aktarım söz konusu olduğunda KVKK m.9'daki usullere uyulur.

Haklarınız: KVKK m.11 kapsamındaki taleplerinizi (bilgi talep etme, düzeltme, silme, itiraz vb.) contact@zeronesecurity.com adresine iletebilirsiniz. Başvurular, Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ'e uygun olarak sonuçlandırılır.