1. Scope and data controller
This policy explains personal data processed through the UST Bilişim website, client portal, product and service orders, proposal/contact forms, payment, invoicing, support and email processes.
| Business name | UST Bilişim |
|---|---|
| Legal name | UST Bilişim |
| Business type | |
| Tax office / number | |
| Registered address | Kuzeykent District, Karayılan Street No:1A/31 İŞGEM, Merkez/Kastamonu, Türkiye |
| Email / phone | [email protected] / 0534 943 60 33 |
2. Data categories
- Identity and contact data: name, company/legal name, email, phone, address, tax and billing information,
- Customer and transaction data: orders, products/services, licences, subscriptions, payment status, invoices and support records,
- Payment transaction data: transaction identifier, amount, currency, time, masked card data and payment result,
- Technical and security data: IP address, browser, device, session, logs and risk/security records,
- Communications, requests, complaints, consent records and marketing preferences.
3. Purposes and legal bases
Data is processed to receive enquiries and orders, establish and perform contracts, provide licences/subscriptions, operate payment and invoicing, provide support, prevent fraud, protect systems, maintain records and comply with legal obligations. Processing relies on contract performance, legal obligation, establishment/exercise/protection of rights, legitimate interests and consent where required.
4. Payment security
Card payments are processed through the secure infrastructure of the contracted payment-service provider. UST Bilişim does not store full card numbers or CVV data on its servers. Only limited transaction information required for processing, accounting, refunds and risk management may be returned to UST Bilişim.
5. Sharing
Data may be shared, limited to the relevant purpose, with payment institutions, banks, domain registries, hosting/email and cloud providers, accounting and e-invoicing services, technical providers, legal/financial advisers and authorized public authorities. Transfers are made under applicable law and security safeguards.
6. Retention and security
Data is retained for the periods required by the relevant purpose and contractual, tax/accounting, consumer, payment and dispute obligations, then securely erased, destroyed or anonymized. Reasonable administrative and technical measures such as access control, encryption, backups, logging and firewalls are used.
7. Cookies
Necessary cookies support security, sessions, forms and preference management. Analytics or marketing cookies are enabled only after a preference is provided. See the Cookie Policy.
8. Rights and requests
Requests under applicable data-protection law may be sent with information sufficient to verify identity to [email protected] or the registered address. Requests are handled under the applicable procedure and deadlines.
Last updated: 24 July 2026