Privacy Notice
Last updated: 8 October 2026 · version 2026-10-08-2
This notice explains how we handle personal data on posta.preved.co and in emails you send us. We write it under Türkiye's Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu, "KVKK"), Article 10, and the KVKK Communiqué on the Duty to Inform. A Turkish version is at /tr/privacy. If the two differ, the Turkish version applies.
This notice covers the website, your posta account, and the mail services we run for you (mailboxes, IMAP, SMTP, webmail and the API), and payments for the Pro plan.
Who we are (data controller)
HEYVANKA YAZILIM LTD. ŞTİ.
Trade-registry name on file until the change is published: HEYV PHARMA KOZMETİK TİC. VE SAN. LTD. ŞTİ. (name change filed 5 October 2026, Mersin Trade Registry).
Demirtaş Mah. 77034 Sk. No: 11/A, Toroslar / Mersin, Türkiye · Tax ID 4621026952 (İstiklal Tax Office) · MERSİS 0462102695200001
Privacy questions: privacy@preved.co · KEP (registered e-mail): not yet registered (use e-mail) · Phone: +90 850 840 43 37
What we collect, why, and on what legal basis
1. When you visit this site
- Data: your IP address and port, date and time, the page you asked for, your browser's user-agent, the page you came from, and technical connection details (TLS version and a TLS fingerprint). From the IP address we look up your network provider (ASN). We also label each request as "human" or "bot".
- How: our web server records this automatically for every request.
- Why: to keep the site running and secure, block attacks and abusive bots, and fix errors.
- Legal basis: our legitimate interest in a secure website (KVKK Art. 5(2)(f)). If there is an attack or misuse, we also use these records to establish or defend our rights (KVKK Art. 5(2)(e)).
- This site uses no cookies, no analytics, no ads, and no third-party scripts or fonts. The dashboard at /app uses one session cookie so you can stay signed in; nothing else.
2. When you email us
- Data: your email address, your name if you include it, your message, and normal email details (time and sending server).
- How: you send it to us yourself.
- Why: to reply to you and handle requests such as more capacity.
- Legal basis: steps you asked for before or under a contract with us (KVKK Art. 5(2)(c)), and our legitimate interest in replying to messages (KVKK Art. 5(2)(f)).
- We don't send you marketing unless you ask for it. Reply "remove me" any time.
- Please don't send us sensitive data (for example health information). We don't need it.
3. When you create and use an account
- Data: your email address, a hash of your password (we never see the password itself), the date you accepted our terms and which version, your plan, the domains and mailboxes you create, API key names and when they were last used, and a log of actions in your account (for example "mailbox created").
- How: you give it to us when you sign up and use the dashboard or API.
- Why: to create and run your account, check that you own your domain, keep the service secure, and prove what you agreed to.
- Legal basis: performing our contract with you (KVKK Art. 5(2)(c)), our legal obligations (Art. 5(2)(ç)), and establishing or defending our rights (Art. 5(2)(e)).
- We email you about your account and the service (for example confirmation links, password resets, limits and changes to these terms). These are not marketing.
4. When you or your apps connect to your mailbox (IMAP, SMTP, webmail, API)
- Data: the IP address you connect from, the mailbox address you sign in with, the time, and whether the sign-in worked. For every message we send or receive: sender and recipient addresses, time, size, message ID and delivery result. These records can include people who are not our customers, such as the people you write to.
- Security blocking: if an IP address fails to sign in too many times, our systems block it automatically for a while. We keep the blocked IP address and the time.
- Spam and virus filtering: we scan incoming and outgoing messages automatically for spam and malware. Nobody reads them as part of this. We read a specific message only as explained in our Acceptable Use Policy.
- Why: to deliver mail, protect accounts from password guessing, stop abuse, and answer lawful requests from Turkish authorities.
- Legal basis: performing our contract (Art. 5(2)(c)), our legal obligations, including those of a hosting provider under Law No. 5651 (Art. 5(2)(ç)), and our legitimate interest in a secure service (Art. 5(2)(f)).
5. The mail in your mailboxes
You decide what mail you send, receive and keep. For that content, you are the data controller and we process it on your behalf, only to provide the service. If you use posta for other people (for example your staff or customers), you must give them the information the law requires.
6. When you buy Pro
- Data: your name or company name, country, billing address, tax or VAT number (if you give it), whether you buy as a business or a consumer, the order (plan, amount, date, order number), the payment result and payment ID from iyzico, and the date, time and IP address of your acceptance of the sales terms. We never receive your card number.
- Why: to take payment, deliver Pro, issue the invoice, handle refunds and cancellations, and prove what you agreed to.
- Legal basis: performing our contract (KVKK Art. 5(2)(c)) and our legal obligations under Turkish tax, commercial and consumer law (Art. 5(2)(ç)).
We don't sell your data. We don't build ad profiles. We don't make automated decisions about you. A person reads and answers your emails. We don't send them to AI services.
Who we share it with
- Our hosting provider in Türkiye, PH Bilişim Teknolojileri Tic. Ltd. Şti. (Poyraz Hosting), which runs the server hardware. Purpose: hosting.
- Google (Google Drive), outside Türkiye, which stores encrypted backup copies of our servers (see "Backups abroad" below).
- Other mail servers, when you send a message: we pass it to the recipient's mail server. That is how email works.
- Public authorities, only when Turkish law requires it and only on a written decision or request from a court, prosecutor or other competent authority (for example under the Code of Criminal Procedure No. 5271). We give only what the decision covers.
- iyzico (İyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.), Türkiye, a licensed payment institution, which processes your card payment. Our e-invoice provider in Türkiye and the Turkish Revenue Administration, for the electronic invoice the law requires.
- Nobody else.
Backups abroad
We keep encrypted backup copies of our servers (including website logs, account data and connection records) with Google (Google Drive), outside Türkiye. The copies are encrypted on our server before they are uploaded, and Google does not have the key. Backups are kept for up to 5 years. This is a transfer of personal data abroad under KVKK Art. 9. If you object to it, write to privacy@preved.co and tell us what you want us to do. Mail stored in customer mailboxes is not copied abroad; its backups stay in Türkiye.
How long we keep it
- Web server logs and visit records (IP address, time, page, user-agent, network provider, human/bot label): up to 12 months, then deleted automatically. TLS connection details: 90 days.
- Your emails to us: up to 12 months after our last exchange, or until you ask us to remove you. If your email is part of a business relationship with us, we may have to keep it longer under the Turkish Commercial Code No. 6102 (Türk Ticaret Kanunu).
- Account data: while your account is open, then up to 10 years for records we must keep under the Turkish Commercial Code (for example what you agreed to); the rest is deleted within 30 days of closing the account.
- Mail in your mailboxes: until you or we delete it. When you delete a mailbox or close your account, it is deleted from live systems at once and from backups when those backups expire (up to 5 years).
- Connection and delivery records, blocked IPs: up to 12 months, then deleted.
- Backups: up to 5 years (see above).
- Orders, invoices and payment records: 10 years (Law No. 6563 Art. 11 and Turkish tax law). Your acceptance of the sales terms: at least 3 years, and as long as we keep the order.
- After that we delete or anonymise the data (KVKK Art. 7).
Your rights (KVKK Article 11)
You can ask us to:
- tell you whether we process your data, and give you information about it;
- tell you why we process it and whether we use it for that purpose;
- tell you who we have shared it with, in Türkiye or abroad;
- correct it if it is incomplete or wrong;
- delete or destroy it under KVKK Art. 7, and tell the people we shared it with that we have corrected or deleted it;
- object if an automated analysis produces a result against you;
- pay compensation if you have suffered damage because we processed your data unlawfully.
How to apply: write to privacy@preved.co from the email address you used with us, or send a letter to our address above, or write to legal@preved.co. Tell us who you are and what you want. If you are asking about your visit records, include your IP address and the approximate time. We answer free of charge within 30 days (KVKK Art. 13). If we refuse, we tell you why. If you are not satisfied, you can complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr) (KVKK Art. 14).
Changes
If we change this notice, we update the date above and, for changes that affect your account, email you before they apply. Every version stays available at /privacy/