TR/EN

Privacy Policy

How your personal data is processed and protected by VECDC, and your rights.

Last updated: 2026

This page is an English translation provided for convenience. The Turkish version is the authoritative text for language purposes; in the event of any conflict or ambiguity between the two versions, the Turkish version prevails.

1. Introduction and Scope

This Privacy Policy governs how personal data is processed by VECDC CLOUD AND CONSULTANCY LIMITED ("VECDC") in connection with its websites, membership system, virtual server (VPS/VDS), dedicated server, consulting and other digital services. We recommend reading this text before using our Site or Services. If you do not accept this Policy, please do not carry out transactions on our Site.

This Privacy Policy applies only to domains and pages owned by VECDC; it is not binding for third-party sites not owned by our company. By accepting this text, you are deemed to accept VECDC's privacy terms. This Policy applies to all sub-sections and pages of VECDC.

VECDC is a cloud computing and server services provider incorporated and registered under the laws of England and Wales, serving customers internationally with a focus on Türkiye. Your personal data is processed in accordance with the UK GDPR (UK General Data Protection Regulation) and the Data Protection Act 2018 in force in the United Kingdom, and, for data subjects resident in Türkiye, additionally in accordance with Law No. 6698 on the Protection of Personal Data ("KVKK").

2. Data Controller and Legal Basis

VECDC is the data controller with respect to your personal data. Your personal data is processed for the establishment and performance of the service relationship, fulfilment of contractual and legal obligations, our legitimate interests, and, where applicable, your explicit consent, in accordance with Article 6 of the UK GDPR and, for data subjects resident in Türkiye, the conditions set out in Articles 5 and 6 of the KVKK.

This policy has been prepared within the framework of the UK GDPR and the Data Protection Act 2018 in force in the United Kingdom, and Law No. 6698 on the Protection of Personal Data and decisions of the Personal Data Protection Board in force in Türkiye, so as to meet both frameworks' standards together.

3. Personal Data Collected and Purposes of Processing

VECDC collects only the personal data necessary to provide you with quality and secure service. The table below summarizes which data categories are processed for which purposes.

Data CategoryPurpose of ProcessingLegal Basis
Identity and contact information (name, surname, email, phone, address) Account creation, order and support processes, invoicing and notifications Performance of contract, legal obligation
Identification number Invoicing and submission to authorities as required by law Legal obligation
Technical and session data (IP, cookies, device information) Site operation, security, statistics Legitimate interest, explicit consent
Payment and billing information Payment processing (card details are not stored) Performance of contract

Information such as the address, phone number and technical support email provided by members is not disclosed to third parties unless requested by official authorities.

4. Cookies and Payment Security

Cookies

VECDC websites may place cookies on visitors' devices. These cookies can only be read via VECDC domains and are used for the operation and security of the site and to compile statistical information; they are not used to track visitors' activity outside the site or for advertising purposes.

  • A cookie may be placed on the device customers use to log in to the customer panel; this information is used solely for session and preference retention.
  • You can restrict cookies via your browser settings; in that case, your ability to fully benefit from the site may be limited.

Credit Card and Payment Information

For payments made by credit or debit card, your card details are not stored on our systems; information is transmitted directly and securely to the relevant bank via the payment infrastructure. Your data is encrypted using SSL certificates on payment pages.

5. Transfer and Sharing of Personal Data

VECDC shares the personal data it collects only in the following circumstances and in compliance with applicable legislation:

  • Legal obligation: Pursuant to a court order, prosecutor's request, or written requests from legally authorized public authorities.
  • Service providers: Sharing with data processors such as payment institutions and infrastructure/server providers, within the framework of contractual and UK GDPR / KVKK-compliant security measures.
  • Explicit consent: Where your explicit consent has been obtained for a specific data-sharing purpose.

VECDC undertakes not to disclose customer information to third parties unless a formal request is received from judicial authorities. Statistical or anonymous data (visit counts, general usage data, etc.) is not shared in a way that reveals your identity.

6. Data Subject Rights under the KVKK and the UK GDPR

Pursuant to Article 11 of Law No. 6698 and the UK GDPR, you have the following rights regardless of where you reside. You may exercise these rights by contacting VECDC at [email protected] or in writing.

  • Learn whether your personal data is being processed;
  • Request information if it has been processed, and obtain a copy of the data processed;
  • Learn the purpose of processing and whether the data is used in accordance with that purpose;
  • Know the third parties to whom the data is transferred domestically or abroad;
  • Request correction of incomplete or inaccurate data;
  • Request deletion or destruction of your data, including the "right to be forgotten";
  • Request that the processing of your data be restricted in certain circumstances;
  • Request that correction, deletion, destruction or restriction be notified to the third parties to whom the data has been transferred;
  • Withdraw your consent at any time for processing activities based on consent;
  • Object to a result that arises to your detriment through analysis of the processed data exclusively via automated systems;
  • Request compensation for damages arising from unlawful processing;
  • Lodge a complaint with the competent supervisory authority — the Personal Data Protection Authority for data subjects resident in Türkiye, or the Information Commissioner's Office (ICO) for data subjects whose data is subject to UK law.

Your applications will be concluded within the periods stipulated by the applicable legislation (Article 13 of the KVKK for data subjects resident in Türkiye; the UK GDPR for data subjects subject to UK law), depending on the nature of the request. VECDC is obliged to respond to data subject requests appropriately.

How Can You Review, Update, or Delete the Data We Collect From You?

You have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please send an email to [email protected].

7. Security Measures and Legal Notice

VECDC takes technical and administrative measures to prevent the unlawful processing of personal data, unauthorized access, and data loss. While the technical environments hosting the site and server infrastructure are protected by software and hardware measures, security is limited to internet and computer security; no system can be guaranteed 100% secure.

  • Necessary measures are taken and informational notices are published to reduce the risk of misuse or unauthorized access.
  • Where a data security breach is detected, it is our policy to notify the competent supervisory authority (the Personal Data Protection Board and/or the Information Commissioner's Office, as applicable) and affected data subjects within 72 hours at the latest, as required by legislation.
  • Lawful requests from judicial authorities requiring disclosure of personal data are evaluated within the periods stipulated by legislation and fulfilled within the legal framework.

VECDC is obliged to cooperate with legal authorities. Where a duly made request is received from official authorities, customer information may be shared within the legal framework; in such cases it may not always be possible to notify the customer in advance.

8. Changes to this Policy and Contact

Changes

This Privacy Policy may be updated by VECDC. Changes take effect as soon as they are published on this page. We recommend checking the current text periodically. Continued use of the Services means you accept the current Policy.

Contact

For questions regarding the processing of your personal data or your rights under the KVKK and the UK GDPR, you can contact VECDC at [email protected]. Written applications can be sent to: Suite 11191, 5 Brayford Square, London, United Kingdom, E1 0SG.

The security and privacy information on this page may be updated by VECDC. As a VECDC customer or visitor, we declare that you have read and accepted this Privacy Policy, which protects your rights.