Skip to content
Legal

Privacy Policy

Last updated: 12 September 2026 · Türkçe

1. Who we are

This policy explains how Sendix processes personal data. For data about our website visitors and customers we are the controller within the meaning of Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and, where it applies, the EU General Data Protection Regulation (“GDPR”).

Service
Sendix
Legal status
Individual developer (not a registered company)
Address
Available on request at [email protected]
Web
sendix.dev
Country
Türkiye

Privacy questions and requests: [email protected]. Our Turkish-language KVKK Privacy Notice contains the information required by Article 10 of KVKK.

2. Whom this policy covers

  • Visitors of sendix.dev, docs.sendix.dev and status.sendix.dev.
  • Customers: people who create an account, their team members, and contacts at customer organisations.
  • People who contact us, for example through the contact form or by email.

It does not cover the personal data in the email our customers send or receive through Sendix (such as recipient addresses and message content). Each customer decides why and how that data is processed and is its controller; we process it only on the customer’s instructions, under the Data Processing Agreement. Section 4 explains more.

3. Data we collect

CategoryExamplesSource
Identity and contactName, email address, company nameYou, at sign-up or later; Google or GitHub if you sign in with them
Account securityPassword hash, two-factor settings, API key and SMTP credential hashes, session tokensCreated when you use the Service
BillingPlan, payment receipts, payment status, provider reference; for some providers phone number and billing addressYou and the payment provider you choose (we never receive your full card number)
Usage and technicalIP address, browser and device data, pages visited, actions in the dashboard, API requestsCollected automatically; security logs and audit records
CommunicationsSupport requests, messages to us, abuse reportsYou
Legal recordsWhich version of our terms you accepted, when and from which IP addressCreated when you accept

We do not intentionally collect special categories of personal data (such as health or religious data) about you.

4. Email sent and received through Sendix

When customers use Sendix, we process on their behalf: recipient and sender addresses, message content and attachments, contact lists and properties, inbound mail, and delivery events such as “delivered”, “bounced” or “complained”. If a customer enables open and click tracking, we also record the time, IP address and user agent when a message is opened or a link is clicked.

If you received an email sent through Sendix and have questions about it, or want to exercise your rights, please contact the sender: they are the controller. If you cannot reach them, write to [email protected] and we will forward your request. To report unwanted email, write to [email protected].

We keep addresses that unsubscribed, complained or hard-bounced on the customer’s suppression list so that they are not emailed again.

5. Why we process your data and on which legal basis

PurposeLegal basis (KVKK Art. 5/2 · GDPR Art. 6/1)
Creating and running your account, providing the Service, customer supportPerformance of a contract (KVKK 5/2-c · GDPR 6/1-b)
Processing payments, invoicing, accounting and tax recordsPerformance of a contract and legal obligation (KVKK 5/2-c, ç · GDPR 6/1-b, c)
Security, fraud and abuse prevention, protecting recipients, audit logsLegitimate interest (KVKK 5/2-f · GDPR 6/1-f) and legal obligation under Law No. 5651 where applicable
Service, security and legal notices by emailPerformance of a contract and legitimate interest
Keeping evidence of your acceptance of our terms, handling disputesEstablishment, exercise or defence of legal claims (KVKK 5/2-e · GDPR 6/1-f)
Improving the Service with aggregated, de-identified statisticsLegitimate interest
Responding to authorities and courtsLegal obligation (KVKK 5/2-ç · GDPR 6/1-c)

We do not send you marketing email without your consent, we do not use your data for advertising, and we do not sell it.

Automated sending controls: to protect recipients, Sendix automatically throttles or pauses sending when bounce or complaint rates cross the thresholds in the Acceptable Use Policy. If this affects you, you can ask us to review the decision by a person.

6. Who receives your data

We share personal data only with the service providers we need to run Sendix, under contracts that require them to protect it; with authorities, courts or other parties when the law requires it or to protect our rights; and with a successor if our business is transferred, in which case this policy continues to apply. Our current providers are:

ProviderPurposeDataLocation
ODEAWEB Bilişim Teknolojileri San. ve Tic. Ltd. Şti. (Bilhost)Hosting of the primary servers (application, databases, queues, file storage), a sending node and encrypted backupsAll account and customer dataTürkiye
Alastyr Telekomünikasyon A.Ş.Hosting of a sending and inbound mail nodeMessages in transit, delivery metadataTürkiye
Cloudflare, Inc.DNS, content delivery, TLS termination, DDoS and bot protection (including Turnstile) for the website, dashboard and APIIP address, request metadata, data in HTTPS requests passing through the networkUnited States (global network)
Stripe Payments Europe, Ltd. / Stripe, Inc.Card payments, if you choose Stripe at checkoutName, email, payment details, amountIreland / United States
PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş.Card payments, if you choose PayTR at checkoutName, email, phone, payment details, amountTürkiye
iyzico Ödeme Hizmetleri A.Ş.Card payments, if you choose iyzico at checkoutName, email, phone, payment details, amountTürkiye
Ödesin (odesin.com)Card payments, if you choose Ödesin at checkoutName, email, phone, payment details, amountSee the provider’s privacy notice
Dodo PaymentsCard payments and card-backed trials, if you choose Dodo Payments at checkoutName, email, payment details, amountOutside Türkiye
OxaPayCrypto payments, if you choose OxaPay at checkoutEmail, order reference, amount, wallet transaction dataOutside Türkiye
NOWPaymentsCrypto payments, if you choose NOWPayments at checkoutEmail, order reference, amount, wallet transaction dataOutside Türkiye
Google LLCSign in with Google, if you choose itName, email, Google account identifierUnited States
GitHub, Inc.Sign in with GitHub, if you choose itName, email, GitHub account identifierUnited States
Knoku (knoku.com)Documentation assistant on docs.sendix.dev, loaded only when you open itQuestions you type into the assistant, IP address, browser dataSee the provider’s privacy notice

7. International transfers

Our servers, databases and backups are located in Türkiye. Some providers listed above, such as Cloudflare, Google and GitHub, are located abroad or operate global networks, so some data is transferred outside Türkiye. These transfers are carried out in line with Article 9 of KVKK, relying on the safeguards it provides such as standard contracts, or on the exceptions in Article 9(6) where they apply.

If you are in the European Economic Area, the United Kingdom or Switzerland, note that your data is processed in Türkiye, which does not currently have an EU adequacy decision. For our customers, the Standard Contractual Clauses in the DPA apply. For other transfers we rely on the safeguards or derogations available under Chapter V of the GDPR.

8. How long we keep data

DataRetention
Account and customer dataWhile the account exists. Deleting the account erases it immediately.
Sent and received email, delivery eventsAccording to the plan: Free 7 days, Pro 90 days, Enterprise as agreed (up to 730 days). Delivery analytics are kept for at most 25 months.
Suppression listsUntil the customer removes the entry or deletes the account, so opt-outs keep being honoured.
Audit and security logs (including IP address)365 days
Server logsWeb server logs about 14 days, system logs up to 3 months
Encrypted backupsRolling 14 days, then overwritten
Payment recordsAs long as tax law requires (up to 10 years), also after account deletion
Records of acceptance of our termsUp to 10 years after the account is deleted (general limitation period), to defend legal claims
Support and contact messagesAs long as needed to handle your request and keep a record of our correspondence; deleted with the account or on request

When a retention period ends, data is deleted or irreversibly anonymised in line with our data destruction practice.

9. Security

We protect personal data with technical and organisational measures appropriate to the risk, including TLS encryption in transit, password hashing, envelope encryption of stored secrets such as DKIM keys, two-factor authentication, role-based access, audit logging, firewalls and encrypted backups. The full list is in Annex 2 of the DPA. No system is perfectly secure; if a breach affects your data we will inform you and the authorities as the law requires.

10. Your rights

Under Article 11 of KVKK you have the right to learn whether your data is processed, request information about it, learn the purpose and whether it is used accordingly, know the third parties it is transferred to in Türkiye or abroad, request correction of incomplete or inaccurate data, request deletion or destruction, request that third parties be notified of correction or deletion, object to a result against you arising solely from automated analysis, and claim compensation for damage caused by unlawful processing.

If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time where processing is based on consent.

Many of these rights can be exercised directly in the dashboard: you can correct your profile, export your data where your plan includes export, and delete your account. For anything else, write to [email protected] from the email address registered with your account, or use the methods in the KVKK Privacy Notice. We answer within 30 days, free of charge unless the law allows a fee for unusual costs. We may ask you to confirm your identity.

You can lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) and, if you are in the EEA or UK, with your local data protection authority.

11. Children

Sendix is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, contact [email protected] and we will delete it.

12. Cookies

We only use strictly necessary cookies. Details are in the Cookie Policy.

13. Changes to this policy

We may update this policy. For material changes we email account holders at least 30 days in advance and show the new version in the dashboard. The version date at the top of this page shows when it last changed.

Questions about this document: [email protected]