SustaTrace
Privacy Policy

How we process your personal data

This Privacy Policy explains what personal data may be processed when you visit or use the SustaTrace website, why it is processed, the applicable legal bases, and the rights available to you under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR").

Data Controller

Who is responsible for your data

Mersolution Teknoloji Ltd. Şti. ("Mersolution", "we", "us"), MERSIS No. 0618089899900001, with its registered address at Kötekli Mahallesi, Denizli Yolu, Teknopark Sitesi B, No: 4B/4, Muğla - Menteşe, Türkiye, is the data controller for personal data processed through this website.

For privacy-related questions, requests, or rights exercises, you may contact us at hello@mersolution.com.

What We Collect

Data, purposes and legal bases

The SustaTrace website provides product information, technical documentation, contact functionality, and demo-request functionality.

We seek to collect only the personal data reasonably necessary for the relevant purpose.

Data / processing Purpose and legal basis
Server and security logs Technical information generated through normal operation of the website and hosting infrastructure, which may include IP address, date and time, requested URL, referrer, browser/user-agent information, and related technical data. These data are used for security, troubleshooting, service reliability, fraud and abuse prevention, and system administration. Depending on the applicable law and circumstances, the legal basis may include the legitimate interests of the controller (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
Contact and demo requests Information submitted through contact or demo forms, such as name, company, email address, telephone number where provided, and the content of the request. These data are used to respond to enquiries, communicate with the requester, evaluate or arrange a requested demonstration, and manage the resulting correspondence. The applicable legal basis depends on the nature of the request and processing activity and may include consent where provided, taking steps at the request of the data subject before entering into a contract, or another applicable lawful basis under KVKK and/or GDPR.
Technical form-security data Session and security information, including PHP session identifiers and CSRF-related values, may be processed to protect forms, maintain necessary technical state, and prevent unauthorized or malicious submissions.
Third-party web resources The website may load fonts, icons, stylesheets, JavaScript libraries, and related resources from third-party providers. Requests for these resources may transmit technical information such as IP address and browser-related information to the relevant provider as part of delivering the requested resource.
Language, cookie and local-storage preferences A functional preference cookie named st_lang may be used to remember the visitor's language preference. A local browser value may be used to remember whether a visitor has dismissed the site's cookie notice. The local-storage value is stored in the browser and is not transmitted to our servers.

We do not request or knowingly collect wallet private keys, recovery phrases, passwords, authentication credentials, or similar sensitive security information through this website.

The SustaTrace website does not establish a cryptocurrency wallet session or request access to a user's wallet.

Third Parties

External providers and resources

The website may use or load resources from third-party providers, including:

  1. Google Fonts

    fonts.googleapis.com / fonts.gstatic.com

    Used to load website fonts. Requests to these services may transmit technical information such as the visitor's IP address and browser-related information.

  2. Font Awesome

    kit.fontawesome.com / cdnjs

    Used to provide icons and related resources displayed on the website.

  3. jsDelivr

    Used to serve selected third-party libraries and resources used by documentation or website components.

  4. Other Web Libraries

    Depending on the page and current implementation, the website may load libraries or resources such as Bootstrap, SweetAlert2, intl-tel-input, marked.js, highlight.js, or similar libraries from public distribution networks.

The privacy practices, security measures, retention periods, and international transfer arrangements of independent third-party providers are governed by their respective policies and legal obligations.

International Data Transfers

Transfers outside Türkiye or the EEA

Where personal data is transferred to a country outside Türkiye or the European Economic Area, Mersolution will use an applicable transfer mechanism and safeguards required by the relevant data-protection legislation, where such requirements apply.

The appropriate mechanism may depend on the destination country, recipient, service provider, category of personal data, purpose of processing, and applicable legal framework. Depending on the circumstances, this may include an adequacy decision, standard contractual safeguards, or another legally recognized transfer mechanism.

Retention

How long we keep data

Server and security logs are retained only for as long as reasonably necessary for security, troubleshooting, operational, and abuse-prevention purposes, after which they are deleted, anonymized, or otherwise disposed of in accordance with applicable requirements.

Contact and demo-request messages and related correspondence are retained for no longer than two years from the last contact with us, unless a longer retention period is required or permitted by applicable law, necessary to establish, exercise, or defend legal claims, or required for another legitimate legal or operational purpose.

Retention periods may vary depending on the nature of the request and the applicable legal obligations.

Your Rights

Rights over your personal data

Depending on the applicable law and circumstances, you may have the following rights:

  1. Access

    To learn whether your personal data are being processed and, where applicable, obtain a copy of the personal data and relevant information about the processing.

  2. Rectification

    To request correction of inaccurate or incomplete personal data.

  3. Erasure

    To request deletion or destruction of personal data where the applicable legal conditions for erasure are satisfied.

  4. Restriction

    To request restriction of processing where the applicable legal conditions are met.

  5. Objection

    To object to certain processing activities, including processing based on legitimate interests where the applicable legal requirements are satisfied.

  6. Withdrawal of Consent

    Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

  7. Data Portability

    Where GDPR applies and the conditions of GDPR Article 20 are satisfied, you may have the right to receive certain personal data in a structured, commonly used, and machine-readable format and, where legally and technically applicable, to request transmission of those data to another controller.

  8. Other Applicable Rights

    Where GDPR applies, additional rights may apply in relation to automated decision-making and profiling, subject to the conditions and exceptions provided by applicable law.

To exercise your rights or raise a privacy-related concern, contact hello@mersolution.com.

You may also use the Complaints page for privacy-related concerns.

Where applicable, you may lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) or, where GDPR applies, the competent data protection supervisory authority in the European Union.

Cookies and Similar Technologies

Cookies, session state, and local storage

The website does not use advertising or analytics cookies.

A strictly necessary PHP session cookie may be used on pages containing contact or demo forms where required for technical session state and CSRF protection.

The site may use a functional preference cookie named st_lang to remember language preference, and browser local storage for the limited purpose of remembering whether the cookie notice has been dismissed.

For further information, see the Cookie Policy.

Children

This site is not directed at children

This website is not directed at children, and we do not knowingly collect personal data from children through the website.

EU Representative

GDPR Article 27

Mersolution has not currently appointed a representative in the European Union under GDPR Article 27.

Where Article 27 applies to Mersolution's processing activities, the applicable representative requirement will be complied with.

Security

How we protect personal data

We apply reasonable technical and organizational measures intended to protect personal data against unauthorized access, alteration, disclosure, loss, misuse, or destruction.

Because no internet transmission or information system can be guaranteed to be completely secure, we cannot guarantee absolute security.

Information concerning the reporting of suspected technical vulnerabilities is available on the Security page.

Changes to This Privacy Policy

Updates

We may update this Privacy Policy from time to time to reflect changes to the website, our processing activities, our service providers, or applicable legal requirements.

The updated version will be published on this website. The version in force at the time of processing will apply, subject to applicable law.