Legal

Privacy policy

What we collect, why, how long we keep it, and what you can make us do about it.

This policy explains how Rynexor Software handles personal data when you use this website and related contact channels.

Who is responsible

Rynexor Software, based in Istanbul, Türkiye, is the data controller for this website. Contact: hello@rynexor.com.

We operate under Türkiye's KVKK (Law No. 6698). Where we handle the data of people in the EU or the UK, we apply the GDPR standard as well, not because two frameworks are twice as good, but because holding one bar for everyone is simpler to actually follow.

What we collect

DataWhenWhyKept for
Name, email, company, and what you write in the brief When you submit a project brief To reply to you and, if it goes further, to scope the work 24 months from last contact, then deleted
A one-way hash of your IP address and browser On any page view Counting visits and stopping automated form abuse Salt rotates daily; raw values are never stored
Page address, referring site, and rough device type On any page view Understanding which pages are read and how people arrive 90 days in detail, then only daily totals
Server logs On any request Security and fault diagnosis 30 days

What we do not do

  • We do not sell or rent personal data. There is no arrangement under which this could happen.
  • We do not run advertising or analytics scripts from third parties. None of their code is loaded, so none of them receive your visit.
  • We do not add you to a mailing list because you sent a brief. If we ever run one, you will have to ask for it.
  • We do not build profiles or make automated decisions about you.

Legal basis

For replying to an enquiry: taking steps at your request before entering a contract. For counting page views and preventing abuse: legitimate interest, weighed against a design that deliberately cannot identify anyone. For anything a client instructs us to process during an engagement: a separate data processing agreement, signed per project.

Who else sees it

Our hosting provider, which stores the data at rest on infrastructure in the EU or Türkiye. That is the complete list for this website. Where an engagement requires another processor, it is named in the engagement agreement before work starts and you can object.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to how we are using it, or ask for it in a portable format. Write to the address above; we respond within 30 days and we do not charge for it.

You can also complain to a supervisory authority: the KVKK in Türkiye, or your national data protection authority in the EU or UK. We would rather you told us first, but you are not required to.

Security

Data in transit is encrypted. Access to the administration panel requires two factors and every change is recorded in an audit log. Our own handling practices, including how client evidence is stored and destroyed, are set out on the Trust Center page.

Changes

If this policy changes materially, the date below changes with it, and anyone with an open enquiry is told directly rather than being expected to re-read the page.

Last updated .