How we process your personal data
This Privacy Policy explains what personal data may be processed when you visit or use the SustaTrace website, why it is processed, the applicable legal bases, and the rights available to you under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR").
Who is responsible for your data
Mersolution Teknoloji Ltd. Şti. ("Mersolution", "we", "us"), MERSIS No. 0618089899900001, with its registered address at Kötekli Mahallesi, Denizli Yolu, Teknopark Sitesi B, No: 4B/4, Muğla - Menteşe, Türkiye, is the data controller for personal data processed through this website.
For privacy-related questions, requests, or rights exercises, you may contact us at hello@mersolution.com.
Data, purposes and legal bases
The SustaTrace website provides product information, technical documentation, contact functionality, and demo-request functionality.
We seek to collect only the personal data reasonably necessary for the relevant purpose.
| Data / processing | Purpose and legal basis |
|---|---|
| Server and security logs | Technical information generated through normal operation of the website and hosting infrastructure, which may include IP address, date and time, requested URL, referrer, browser/user-agent information, and related technical data. These data are used for security, troubleshooting, service reliability, fraud and abuse prevention, and system administration. Depending on the applicable law and circumstances, the legal basis may include the legitimate interests of the controller (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)). |
| Contact and demo requests | Information submitted through contact or demo forms, such as name, company, email address, telephone number where provided, and the content of the request. These data are used to respond to enquiries, communicate with the requester, evaluate or arrange a requested demonstration, and manage the resulting correspondence. The applicable legal basis depends on the nature of the request and processing activity and may include consent where provided, taking steps at the request of the data subject before entering into a contract, or another applicable lawful basis under KVKK and/or GDPR. |
| Technical form-security data | Session and security information, including PHP session identifiers and CSRF-related values, may be processed to protect forms, maintain necessary technical state, and prevent unauthorized or malicious submissions. |
| Third-party web resources | The website may load fonts, icons, stylesheets, JavaScript libraries, and related resources from third-party providers. Requests for these resources may transmit technical information such as IP address and browser-related information to the relevant provider as part of delivering the requested resource. |
| Language, cookie and local-storage preferences | A functional preference cookie named st_lang may be used to remember the visitor's language preference. A local browser value may be used to remember whether a visitor has dismissed the site's cookie notice. The local-storage value is stored in the browser and is not transmitted to our servers. |
We do not request or knowingly collect wallet private keys, recovery phrases, passwords, authentication credentials, or similar sensitive security information through this website.
The SustaTrace website does not establish a cryptocurrency wallet session or request access to a user's wallet.
External providers and resources
The website may use or load resources from third-party providers, including:
-
Google Fonts
fonts.googleapis.com / fonts.gstatic.com
Used to load website fonts. Requests to these services may transmit technical information such as the visitor's IP address and browser-related information.
-
Font Awesome
kit.fontawesome.com / cdnjs
Used to provide icons and related resources displayed on the website.
-
jsDelivr
Used to serve selected third-party libraries and resources used by documentation or website components.
-
Other Web Libraries
Depending on the page and current implementation, the website may load libraries or resources such as Bootstrap, SweetAlert2,
intl-tel-input, marked.js, highlight.js, or similar libraries from public distribution networks.
The privacy practices, security measures, retention periods, and international transfer arrangements of independent third-party providers are governed by their respective policies and legal obligations.
Transfers outside Türkiye or the EEA
Where personal data is transferred to a country outside Türkiye or the European Economic Area, Mersolution will use an applicable transfer mechanism and safeguards required by the relevant data-protection legislation, where such requirements apply.
The appropriate mechanism may depend on the destination country, recipient, service provider, category of personal data, purpose of processing, and applicable legal framework. Depending on the circumstances, this may include an adequacy decision, standard contractual safeguards, or another legally recognized transfer mechanism.
How long we keep data
Server and security logs are retained only for as long as reasonably necessary for security, troubleshooting, operational, and abuse-prevention purposes, after which they are deleted, anonymized, or otherwise disposed of in accordance with applicable requirements.
Contact and demo-request messages and related correspondence are retained for no longer than two years from the last contact with us, unless a longer retention period is required or permitted by applicable law, necessary to establish, exercise, or defend legal claims, or required for another legitimate legal or operational purpose.
Retention periods may vary depending on the nature of the request and the applicable legal obligations.
Rights over your personal data
Depending on the applicable law and circumstances, you may have the following rights:
-
Access
To learn whether your personal data are being processed and, where applicable, obtain a copy of the personal data and relevant information about the processing.
-
Rectification
To request correction of inaccurate or incomplete personal data.
-
Erasure
To request deletion or destruction of personal data where the applicable legal conditions for erasure are satisfied.
-
Restriction
To request restriction of processing where the applicable legal conditions are met.
-
Objection
To object to certain processing activities, including processing based on legitimate interests where the applicable legal requirements are satisfied.
-
Withdrawal of Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
-
Data Portability
Where GDPR applies and the conditions of GDPR Article 20 are satisfied, you may have the right to receive certain personal data in a structured, commonly used, and machine-readable format and, where legally and technically applicable, to request transmission of those data to another controller.
-
Other Applicable Rights
Where GDPR applies, additional rights may apply in relation to automated decision-making and profiling, subject to the conditions and exceptions provided by applicable law.
To exercise your rights or raise a privacy-related concern, contact hello@mersolution.com.
You may also use the Complaints page for privacy-related concerns.
Where applicable, you may lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) or, where GDPR applies, the competent data protection supervisory authority in the European Union.
Cookies, session state, and local storage
The website does not use advertising or analytics cookies.
A strictly necessary PHP session cookie may be used on pages containing contact or demo forms where required for technical session state and CSRF protection.
The site may use a functional preference cookie named st_lang to remember language preference, and browser local storage for the limited purpose of remembering whether the cookie notice has been dismissed.
For further information, see the Cookie Policy.
This site is not directed at children
This website is not directed at children, and we do not knowingly collect personal data from children through the website.
GDPR Article 27
Mersolution has not currently appointed a representative in the European Union under GDPR Article 27.
Where Article 27 applies to Mersolution's processing activities, the applicable representative requirement will be complied with.
How we protect personal data
We apply reasonable technical and organizational measures intended to protect personal data against unauthorized access, alteration, disclosure, loss, misuse, or destruction.
Because no internet transmission or information system can be guaranteed to be completely secure, we cannot guarantee absolute security.
Information concerning the reporting of suspected technical vulnerabilities is available on the Security page.
Updates
We may update this Privacy Policy from time to time to reflect changes to the website, our processing activities, our service providers, or applicable legal requirements.
The updated version will be published on this website. The version in force at the time of processing will apply, subject to applicable law.