Privacy Policy
This page explains what personal data the CeeOGreen platform processes, for what purposes, on what legal basis, and for how long it is retained. Data collection, sharing, retention periods, and your rights under KVKK and EU GDPR are explained section by section below.
Last updated: January 1, 2025
1 Data Controller
This Privacy Policy applies to the CeeOGreen platform operated by CeeOTech Software & Consulting ("Company", "we", "us").
Address: Akse Dist., Street 452, Çayırova / Kocaeli, Türkiye
Email: [email protected]
2 Personal Data Collected
When you use our platform, we may process the following personal data:
| Data Category | Examples |
|---|---|
| Identity Data | First name, last name, username |
| Contact Data | Email address, phone number |
| Corporate Data | Company name, industry, tax number |
| Emission Data | Energy consumption, fuel usage, activity data |
| Technical Data | IP address, browser type, session information |
3 Purposes of Use
We process your personal data for the following purposes:
- Providing platform services and account management
- Performing emission calculations and generating reports
- Providing customer support and technical assistance
- Fulfilling legal and regulatory obligations
- Ensuring platform security and error detection
- Improving service quality and developing new features
4 Legal Basis for Processing
We process your personal data under the following legal bases under KVKK No. 6698 and EU GDPR:
- Contract Performance: Operations necessary for fulfilling the subscription agreement
- Legal Obligation: Tax, accounting, and environmental reporting legislation
- Legitimate Interest: Platform security and service improvement activities
- Explicit Consent: For marketing communications
5 Data Sharing
We do not share your personal data with third parties except in the following cases:
- Infrastructure Provider: Hetzner Online GmbH (Germany-based, with data centres within EU borders) — under an EU GDPR-compliant Data Processing Agreement (DPA)
- Consulting Firms: Consultant access to client data accessed via consultant account
- Legal Requirement: Authorized institutions as required by court order or legal regulation
Your emission data is never sold or transferred to third parties for commercial purposes under any circumstances.
Data Location and Cross-Border Transfer
Your data is hosted within the European Union, in Hetzner's ISO 27001-certified data centres located in Germany. This constitutes a cross-border data transfer from Türkiye to the EU and is carried out within the framework of KVKK Article 9. Your data is processed under technical and administrative safeguards equivalent to the protection standards provided by EU GDPR.
6 Retention Periods
We retain your data only for as long as necessary:
- Account data: During subscription + 2 years
- Emission/report data: 10 years (legal reporting obligation)
- Technical log data: 12 months
- Communication/support records: 3 years
7 Cookies
Our platform uses the following types of cookies:
- Necessary Cookies: Required for session management and security; cannot be disabled
- Preference Cookies: Language and theme preferences (e.g. localStorage: appLang)
- Analytics Cookies: Help us understand platform usage (anonymous)
You can manage cookies from your browser settings. Disabling necessary cookies may affect service usage.
8 Your Rights
Under KVKK Article 11 and GDPR Articles 15–22, you have the following rights:
- Right to know whether your personal data is being processed
- Right to access your personal data and request a copy
- Right to request correction of inaccurate or incomplete data
- Right to request deletion of your data under certain conditions (right to be forgotten)
- Right to request restriction of data processing
- Right to data portability
- Right to object to processing based on legitimate interest
To exercise your rights, you can write to [email protected]. We respond to requests within 30 days.
9 Data Security
We implement the following technical and administrative measures to protect your personal data:
- Data transmission encrypted with TLS 1.3
- Database encryption with AES-256
- Role-based access control (RBAC) and granular permissions
- Audit log for every data change (who, when, what changed)
- Regular vulnerability scans
- Data integrity protection via soft delete and period locking
10 Contact and Complaints
For questions about our privacy policy or the processing of your personal data:
Data Protection Contact:
[email protected]
You also have the right to lodge complaints with the Personal Data Protection Authority (KVKK) or your local data protection authority.