Skip to main content

KVKK/GDPR Compliance Notes

Information about DZDESK compliance with data protection regulations.

Overview

DZDESK is designed to help organizations comply with:

  • KVKK: Kişisel Verilerin Korunması Kanunu (Turkey)
  • GDPR: General Data Protection Regulation (EU)

Data Controller vs Processor

Your Organization

As a DZDESK customer, you are typically the Data Controller:

  • Determines purposes of processing
  • Decides what data to collect
  • Responsible for legal basis

DZDESK

DZDESK acts as Data Processor:

  • Processes data on your behalf
  • Follows your instructions
  • Implements security measures

Personal Data in DZDESK

What Personal Data

Data TypeExamples
User dataName, email, role
Request dataDescriptions, comments
Activity dataActions, timestamps
Technical dataIP addresses, devices

Data Subjects

People whose data may be processed:

  • Your employees (users)
  • Request submitters
  • Mentioned individuals

KVKK Compliance

Key KVKK Principles

PrincipleDZDESK Implementation
LawfulnessProcess based on your legal basis
Purpose limitationData used only for support
Data minimizationCollect only necessary data
AccuracyUsers can update their data
Storage limitationConfigurable retention
SecurityEncryption, access controls

KVKK Rights Support

DZDESK helps you fulfill data subject rights:

RightHow to Fulfill
AccessExport user data
CorrectionEdit user profiles
DeletionDeactivate/delete users
ObjectionDisable processing

Data Transfer

For KVKK compliance:

  • Data can be stored in Turkey (coming soon)
  • Currently in EU regions
  • Appropriate safeguards in place

GDPR Compliance

Key GDPR Principles

PrincipleDZDESK Implementation
LawfulnessProcess on valid legal basis
TransparencyClear data usage
Purpose limitationDefined purposes
Data minimizationNecessary data only
AccuracyUpdate mechanisms
Storage limitationRetention policies
SecurityTechnical measures
AccountabilityAudit trails

GDPR Rights Support

RightImplementation
InformationPrivacy notices
AccessData export
RectificationEdit capabilities
ErasureDeletion options
RestrictionProcessing limits
PortabilityExport formats
ObjectionOpt-out mechanisms

Data Processing Agreement

DPA Available

DZDESK provides:

  • Standard DPA
  • KVKK-specific terms
  • GDPR-compliant clauses

DPA Contents

Includes:

  • Processing instructions
  • Security measures
  • Sub-processor list
  • Breach notification
  • Audit rights

Security Measures

Technical Measures

  • Encryption at rest and in transit
  • Access controls
  • Audit logging
  • Regular security testing

Organizational Measures

  • Employee training
  • Access policies
  • Incident response
  • Regular reviews

Data Retention

Default Retention

Data TypeRetention
Active dataWhile account active
Closed requestsConfigurable
Audit logs2 years
Backups30 days

Customization

You can configure:

  • Retention periods
  • Auto-deletion rules
  • Archive policies

Breach Notification

Our Commitment

If a breach occurs:

  • Notification within 72 hours
  • Details of breach provided
  • Remediation actions
  • Support for your notifications

Your Responsibility

You are responsible for:

  • Notifying data subjects
  • Notifying authorities
  • Documenting incidents

Sub-Processors

Current Sub-Processors

ProviderPurposeLocation
Microsoft AzureHostingEU/Turkey
CloudflareCDN, SecurityGlobal

Changes Notification

  • Advance notice of changes
  • Objection rights
  • Documentation provided

Your Responsibilities

As Data Controller

  1. Determine legal basis for processing
  2. Provide privacy notices
  3. Handle data subject requests
  4. Report breaches to authorities
  5. Maintain records of processing

Configuration Recommendations

  1. Enable minimum necessary features
  2. Configure appropriate retention
  3. Limit data collection
  4. Train your users

Documentation

Available Documents

  • Data Processing Agreement
  • Security documentation
  • Sub-processor list
  • Compliance certificates

How to Obtain

Contact: