Privacy Policy
Tax ID 8800579984 (Şarköy Tax Office) · İSTİKLAL MAH. GANOS SK. NO: 5 B, 59800 Şarköy / Tekirdağ, Turkey.
1. Data Controller
The data controller responsible for your personal data is Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi, contactable at support@vulnytics.com.
2. Data We Collect
- Account information: your name, email address and company name, provided when you register or through our payment processor at checkout.
- Verified targets: the domains and internet-facing assets you add and verify (typically via a DNS TXT record) as belonging to you, so we know what you have authorized us to scan.
- Scan results and evidence: the findings, exploit-verification evidence packages, reports, dossiers and attestations produced when we scan your verified assets. This data describes your own infrastructure and is stored so you can review history, trends and share deliverables.
- Billing data: plan, transaction and invoice records associated with your account, provided by Paddle.
- Technical data: IP address, request timestamps and service logs, collected to operate and secure the service.
- Payment data: handled by our payment processor (see §5). We never store your full card details.
Scope of scanning: Vulnytics scans only assets you have added and verified as your own. We do not scan assets you have not authorized, and we do not collect data from third-party systems on your behalf.
3. Purpose of Data Processing
We process data to: verify ownership of the assets you add; scan those assets for vulnerabilities and misconfigurations and verify exploitability; generate findings, evidence packages, reports and attestations; validate your plan and process payments; provide support; and operate, secure and improve the service.
4. Legal Basis for Processing
We rely on (a) performance of a contract (providing the service you signed up for), (b) legitimate interests (operating and securing the service, preventing abuse), (c) legal obligations (tax, accounting), and (d) consent where required (e.g. optional analytics). This Policy is provided in accordance with the GDPR and Turkey's KVKK.
5. Data Sharing: Sub-processors
We share data only with the service providers necessary to run Vulnytics:
- Paddle: our Merchant of Record, which processes payments, billing and invoices. Paddle acts as a separate controller for payment data under its own privacy policy.
- Resend: our transactional email provider, used to send account, verification, report and support emails.
- Cloud hosting providers: to host the service and store scan data and evidence.
- Legal authorities: where required by law.
We do not sell your personal data. Your scan results and evidence are not shared with anyone other than as needed to operate the service; you control who you share your reports and attestations with.
6. Data Retention
Account and billing data are retained for the life of your account and as required for tax/accounting purposes afterward. Scan results and evidence are retained to provide history and trends and are deleted on request or when you remove an asset or close your account. Service logs are kept for a limited period for security and debugging.
7. Your Rights
Under the GDPR and KVKK you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability. To exercise any right, email support@vulnytics.com. We will respond within 30 days.
8. How We Scan: Authorization by Design
Authorization is a core design choice. Vulnytics performs testing only against assets you have explicitly added and verified as your own. Verification (typically a DNS TXT record) ensures we do not scan domains you do not control. You may remove an asset at any time, which stops future scanning of it.
9. Cookies
The vulnytics.com website uses only the cookies necessary for it to function and, where applicable, privacy-respecting analytics. See our Cookie Policy.
10. Security
We protect data with encryption in transit (TLS), access controls, and isolation of scan evidence per account. No system is perfectly secure, but we take reasonable, industry-standard measures to protect your data.
11. Account & Data Deletion
You may request deletion of your account and associated personal data at any time by emailing support@vulnytics.com. Data is deleted within 30 days, except where retention is required by law.
12. Children
Vulnytics is a business product not directed to children, and we do not knowingly collect personal data from anyone under 16.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to account holders.
14. Contact
Questions about this Policy or your data: support@vulnytics.com.
© 2026 Vulnytics, a product of Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi.