1. Data Controller
Cybernet Bilişim Ltd. Şti.
MERSİS No: 0216097866400001
İpek Yolu Mah. Ali Fuat Paşa Cad. No: 19 İç Kapı No: A, Gölcük/Kocaeli
[email protected] · [email protected]
2. Scope of this Notice
This notice covers data processed through the CBBOT website, dashboard, digital-licence and session APIs, payments, support and client crash diagnostics. It is not a contract or a consent declaration.
3. Categories of Personal Data
- Identity and account: username, user/customer ID, full name and company name when corporate invoicing is selected.
- Contact: email address and billing/application address.
- Account security: a one-way password hash rather than the password itself, successful/failed sign-in times, IP address, user agent, sessions and security events.
- Customer transactions: cart, order number, plan, quantity, licence days, subscription and delivery status.
- Finance and billing: amount, currency, payment status, provider/transaction reference, invoice type, tax office and tax/identity number. CBBOT has no card-number or CVV form fields and does not store those values in its order database.
- Device and licence: hashed hardware identifier, machine name, client build/type, architecture, authorised device, active connection, heartbeat and remaining usage time.
- Support and legal records: ticket number, subject, category, correspondence, order association, acknowledgement/document version, time and application records.
- Diagnostics: when the client submits a report, error reason, module/exception details, encrypted crash package, file hash, size and upload record.
- Marketing and cookies: optional commercial-communication choice, essential session/security cookies and, when selected, language preference.
4. Purposes of Processing
Data is processed for membership and account administration; identity, session and device verification; licence activation and time tracking; orders, payments, invoicing and digital delivery; technical support; investigation of errors and security events; prevention of fraud and unauthorised use; legal/financial compliance; reliability improvements; and commercial messages only where separately chosen.
5. Collection Methods
Data is collected electronically through membership, order and dashboard forms, CBBOT licence/session APIs, support correspondence, payment-provider notifications, first-party cookies, server/security logs and diagnostic packages directly submitted by the client.
6. Legal Bases
7. Recipients
Where necessary: PayTR for the selected payment method or another payment provider configured in the admin panel; the hosting infrastructure operator; accounting/financial and legal advisers; Cloudflare Turnstile if security verification is enabled; and legally authorised public bodies. Support and crash reports are managed in CBBOT’s own database/file area; no external support, analytics, advertising or email-delivery provider was identified in the code.
8. International Transfers
Source code alone cannot establish every provider’s storage location, so no absolute domestic/international-storage claim is made. If international infrastructure such as Cloudflare Turnstile is enabled, IP and challenge data may be processed abroad. Provider locations, contracts and the applicable lawful transfer mechanism must be verified before production.
9. Cookies and Similar Technologies
Essential cookies support sign-in, sessions, cart and form security. Language preference becomes persistent only after preference permission; otherwise it remains within the current server session. Analytics and advertising technologies are not run in this release. View the cookie inventory.
10. Information Security and Logs
Controls include access restrictions, one-way password hashing, secure cookies, CSRF protection, rate limits, payment-callback verification, device/session controls, security logging and restricted access to sensitive files. These reduce risk; no internet service can guarantee absolute security.
11. Retention
Account and subscription data is retained for the account/contract relationship; order, invoice and payment records for applicable financial/legal periods; and support, security, device and diagnostics for the period needed for their purpose and possible dispute/limitation periods. The source code does not define exact automated deletion periods for these groups; production operations must establish them in a written retention/destruction policy. Cookie durations are listed separately.
12. Your Rights
Subject to applicable law, you may ask whether and how data is processed, request access and correction, learn recipients, request deletion where conditions apply, request notification of corrections/deletion to recipients, object to qualifying automated decisions and seek compensation for unlawful processing.
13. How to Apply
You may apply through [email protected] or at İpek Yolu Mah. Ali Fuat Paşa Cad. No: 19 İç Kapı No: A, Gölcük/Kocaeli. Necessary and proportionate information may be requested to verify the requester; do not send passwords, card data or unnecessary personal information.
14. Changes to this Notice
The notice and version are updated when data flows, providers or law change. Material changes are announced on relevant pages; a separate choice is obtained for any new processing that requires consent.