
Last updated: January 2026
GDPR Compliance
1. Our Commitment
Zenix is committed to compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Turkey's KVKK Law No. 6698. We treat data protection as a fundamental right, not a compliance checkbox.
2. Data Protection Officer
Our DPO can be reached at dpo@zenix.net.tr. All data subject requests and regulatory inquiries should be directed to this address.
3. Your Rights as a Data Subject
- Right of access (Art. 15): Obtain a copy of your personal data
- Right to rectification (Art. 16): Correct inaccurate data
- Right to erasure (Art. 17): “Right to be forgotten” — subject to legal retention obligations
- Right to restriction (Art. 18): Limit processing in certain circumstances
- Right to portability (Art. 20): Receive your data in machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interest
- Rights re automated decisions (Art. 22): Human review of significant automated decisions
To exercise any right, email dpo@zenix.net.tr. We respond within 30 days.
4. Data Processing Agreement
If you use Zenix services to process personal data of third parties (making you a Data Controller and Zenix a Data Processor), a Data Processing Agreement (DPA) is required under Art. 28 GDPR. Request our standard DPA at /legal/dpa or contact your account manager.
5. Sub-processors
Zenix uses the following sub-processors for core service delivery:
- Stripe — payment processing (EU data centers)
- Hetzner Online / AWS EU — internal tooling (we do not host customer data there)
- Postmark — transactional email (EU)
Sub-processor changes are announced with 30 days' notice via email.
6. Data Residency
Customer data is processed in the jurisdiction(s) where the services are provisioned. We do not transfer customer infrastructure data outside the selected region.
7. Breach Notification
In the event of a personal data breach affecting EU residents, we will notify the relevant supervisory authority within 72 hours of becoming aware. Affected data subjects will be notified without undue delay where the breach is likely to result in high risk.
8. Contact
DPO: dpo@zenix.net.tr
Supervisory authority: KVKK (Turkey) / relevant EU DPA

