1. Who we are
This policy explains how Sendix processes personal data. For data about our website visitors and customers we are the controller within the meaning of Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and, where it applies, the EU General Data Protection Regulation (“GDPR”).
- Service
- Sendix
- Legal status
- Individual developer (not a registered company)
- Address
- Available on request at [email protected]
- [email protected]
- Web
- sendix.dev
- Country
- Türkiye
Privacy questions and requests: [email protected]. Our Turkish-language KVKK Privacy Notice contains the information required by Article 10 of KVKK.
2. Whom this policy covers
- Visitors of sendix.dev, docs.sendix.dev and status.sendix.dev.
- Customers: people who create an account, their team members, and contacts at customer organisations.
- People who contact us, for example through the contact form or by email.
It does not cover the personal data in the email our customers send or receive through Sendix (such as recipient addresses and message content). Each customer decides why and how that data is processed and is its controller; we process it only on the customer’s instructions, under the Data Processing Agreement. Section 4 explains more.
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, email address, company name | You, at sign-up or later; Google or GitHub if you sign in with them |
| Account security | Password hash, two-factor settings, API key and SMTP credential hashes, session tokens | Created when you use the Service |
| Billing | Plan, payment receipts, payment status, provider reference; for some providers phone number and billing address | You and the payment provider you choose (we never receive your full card number) |
| Usage and technical | IP address, browser and device data, pages visited, actions in the dashboard, API requests | Collected automatically; security logs and audit records |
| Communications | Support requests, messages to us, abuse reports | You |
| Legal records | Which version of our terms you accepted, when and from which IP address | Created when you accept |
We do not intentionally collect special categories of personal data (such as health or religious data) about you.
4. Email sent and received through Sendix
When customers use Sendix, we process on their behalf: recipient and sender addresses, message content and attachments, contact lists and properties, inbound mail, and delivery events such as “delivered”, “bounced” or “complained”. If a customer enables open and click tracking, we also record the time, IP address and user agent when a message is opened or a link is clicked.
If you received an email sent through Sendix and have questions about it, or want to exercise your rights, please contact the sender: they are the controller. If you cannot reach them, write to [email protected] and we will forward your request. To report unwanted email, write to [email protected].
We keep addresses that unsubscribed, complained or hard-bounced on the customer’s suppression list so that they are not emailed again.
5. Why we process your data and on which legal basis
| Purpose | Legal basis (KVKK Art. 5/2 · GDPR Art. 6/1) |
|---|---|
| Creating and running your account, providing the Service, customer support | Performance of a contract (KVKK 5/2-c · GDPR 6/1-b) |
| Processing payments, invoicing, accounting and tax records | Performance of a contract and legal obligation (KVKK 5/2-c, ç · GDPR 6/1-b, c) |
| Security, fraud and abuse prevention, protecting recipients, audit logs | Legitimate interest (KVKK 5/2-f · GDPR 6/1-f) and legal obligation under Law No. 5651 where applicable |
| Service, security and legal notices by email | Performance of a contract and legitimate interest |
| Keeping evidence of your acceptance of our terms, handling disputes | Establishment, exercise or defence of legal claims (KVKK 5/2-e · GDPR 6/1-f) |
| Improving the Service with aggregated, de-identified statistics | Legitimate interest |
| Responding to authorities and courts | Legal obligation (KVKK 5/2-ç · GDPR 6/1-c) |
We do not send you marketing email without your consent, we do not use your data for advertising, and we do not sell it.
Automated sending controls: to protect recipients, Sendix automatically throttles or pauses sending when bounce or complaint rates cross the thresholds in the Acceptable Use Policy. If this affects you, you can ask us to review the decision by a person.
7. International transfers
Our servers, databases and backups are located in Türkiye. Some providers listed above, such as Cloudflare, Google and GitHub, are located abroad or operate global networks, so some data is transferred outside Türkiye. These transfers are carried out in line with Article 9 of KVKK, relying on the safeguards it provides such as standard contracts, or on the exceptions in Article 9(6) where they apply.
If you are in the European Economic Area, the United Kingdom or Switzerland, note that your data is processed in Türkiye, which does not currently have an EU adequacy decision. For our customers, the Standard Contractual Clauses in the DPA apply. For other transfers we rely on the safeguards or derogations available under Chapter V of the GDPR.
8. How long we keep data
| Data | Retention |
|---|---|
| Account and customer data | While the account exists. Deleting the account erases it immediately. |
| Sent and received email, delivery events | According to the plan: Free 7 days, Pro 90 days, Enterprise as agreed (up to 730 days). Delivery analytics are kept for at most 25 months. |
| Suppression lists | Until the customer removes the entry or deletes the account, so opt-outs keep being honoured. |
| Audit and security logs (including IP address) | 365 days |
| Server logs | Web server logs about 14 days, system logs up to 3 months |
| Encrypted backups | Rolling 14 days, then overwritten |
| Payment records | As long as tax law requires (up to 10 years), also after account deletion |
| Records of acceptance of our terms | Up to 10 years after the account is deleted (general limitation period), to defend legal claims |
| Support and contact messages | As long as needed to handle your request and keep a record of our correspondence; deleted with the account or on request |
When a retention period ends, data is deleted or irreversibly anonymised in line with our data destruction practice.
9. Security
We protect personal data with technical and organisational measures appropriate to the risk, including TLS encryption in transit, password hashing, envelope encryption of stored secrets such as DKIM keys, two-factor authentication, role-based access, audit logging, firewalls and encrypted backups. The full list is in Annex 2 of the DPA. No system is perfectly secure; if a breach affects your data we will inform you and the authorities as the law requires.
10. Your rights
Under Article 11 of KVKK you have the right to learn whether your data is processed, request information about it, learn the purpose and whether it is used accordingly, know the third parties it is transferred to in Türkiye or abroad, request correction of incomplete or inaccurate data, request deletion or destruction, request that third parties be notified of correction or deletion, object to a result against you arising solely from automated analysis, and claim compensation for damage caused by unlawful processing.
If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time where processing is based on consent.
Many of these rights can be exercised directly in the dashboard: you can correct your profile, export your data where your plan includes export, and delete your account. For anything else, write to [email protected] from the email address registered with your account, or use the methods in the KVKK Privacy Notice. We answer within 30 days, free of charge unless the law allows a fee for unusual costs. We may ask you to confirm your identity.
You can lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) and, if you are in the EEA or UK, with your local data protection authority.
11. Children
Sendix is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, contact [email protected] and we will delete it.
13. Changes to this policy
We may update this policy. For material changes we email account holders at least 30 days in advance and show the new version in the dashboard. The version date at the top of this page shows when it last changed.
Questions about this document: [email protected]

