Privacy Policy

SITEY privacy policy: what personal data we collect, why, and how long we keep it. Your scan data stays in your own infrastructure. GDPR and KVKK rights.

The short version. SITEY is sold self-service and runs inside your own infrastructure. We never see your scan results, your asset inventory, your vulnerability data or your hosts. What we hold is small and boring: the name and email on your account, billing records handled by Stripe (we never store card numbers), license activation metadata sent by your deployment when it checks its license, support email, and basic website analytics. We do not sell personal data, we do not run advertising trackers, and we do not profile you. You can ask for a copy of your data, correct it, or have it deleted by writing to info@siteyvm.com. The rest of this page is the detail.

Last updated: [DD Month YYYY]

1. Who we are

SITEY is a vulnerability management platform published by [Company legal name], a company established in Türkiye, registered at [registered address], [city], Türkiye ([trade registry / tax number]).

For the personal data described in this policy, we act as the data controller under the EU General Data Protection Regulation (GDPR) and as the veri sorumlusu under Turkish Law No. 6698 on the Protection of Personal Data (KVKK).

All privacy requests go to one address: info@siteyvm.com. Written requests may also be sent to the registered address above.

2. What this policy covers

This policy covers personal data we process when you:

  • visit siteyvm.com and its subpages, including /pricing/ and /features/;
  • create a SITEY account and buy a monthly or lifetime license;
  • download installers, agents and engine updates;
  • run a licensed SITEY deployment that activates and validates its license against our license server;
  • contact us by email or through /contact/.

3. What we do not collect, and why that matters

SITEY is not a SaaS scanner. You buy the license, download the installer, and deploy the platform and its agents yourself, on your own servers. Because of that architecture:

  • Vulnerability findings, scan results, CVE matches and remediation plans stay on your systems. They are written to your database. They are never transmitted to us.
  • Asset inventories, hostnames of scanned targets, IP ranges, credentials, agent telemetry and attack surface data stay on your systems.
  • Personal data belonging to your employees inside the platform, the users you create, the task assignees, the ticket owners, lives in your instance. You are the controller of that data. We have no access to it, no copy of it, and no technical ability to retrieve it.
  • We do not receive telemetry, usage analytics or crash reports from your deployment. The only traffic that reaches us from an installed instance is license activation and validation (see section 4.3), plus downloads of updates you request.

If you ever want to send us data for support, a log file, a stack trace, a screenshot, that is your decision, made per-case. Nothing leaves your network automatically. If you do send such material, please redact anything you do not want us to hold; we treat it under section 4.4 and delete it on request.

4. What personal data we collect

4.1 Account data

Data Why we have it Source
Name, work email address Identify the license holder, send the license key and download links, password reset You, at signup
Company name, country Invoicing, tax treatment, export-control screening You, at signup or checkout
Password (hashed, not recoverable) Authentication You
Account events: signup date, logins, license issuance, downloads Account security, entitlement checks, abuse investigation Generated by our systems

An account is required. It is how we bind a license to a buyer and how you re-download installers and updates later.

4.2 Billing data

Payments are processed by Stripe. Card numbers, CVC and full payment credentials are entered directly into Stripe’s payment form and never reach our servers. From Stripe we receive and store: billing name, billing address, country, VAT/tax ID where supplied, card brand and last four digits, currency, amount, subscription status, invoice numbers, and the outcome of each charge.

Prices are USD: $599/month recurring or $5,999 one-time for a lifetime license. Subscription status is the data point that determines whether your license stays active, so we retain it for as long as the subscription exists and for the statutory accounting period afterwards.

4.3 License activation and validation metadata

This is the only data your installed deployment sends us. Each activation and each periodic validation call transmits:

Field Detail Purpose
License key The key issued to your account Verify the license is valid and not revoked
Machine fingerprint (hash) A one-way hash derived from stable hardware and OS identifiers of the server running SITEY. We store the hash, not the underlying identifiers, and the hash cannot be reversed back into them. Enforce the seat/instance limit and detect key sharing
Hostname of the SITEY server As reported by the host running the platform. Not the hostnames of your scanned assets. Let you tell your own instances apart when several are licensed; support
IP address of the request The public IP the validation call arrives from Security, fraud and license-abuse detection, rate limiting
Product and engine version, OS family, timestamp, activation result Technical context of the call Compatibility, support, update eligibility

Hostname and IP address can, depending on your environment, be treated as personal data or as data that identifies your organisation. We treat them as personal data and describe them here rather than hiding them in a footnote. No scan data, asset data or finding data is included in these calls.

4.4 Support and correspondence

When you email info@siteyvm.com or use the contact form, we process your email address, your message, any attachments you choose to send, and our replies.

4.5 Website analytics and server logs

On siteyvm.com we collect aggregate usage statistics: pages viewed, referrer, approximate country- or city-level location derived from IP, device and browser type, and session duration. Our web server also writes standard access logs containing IP address, timestamp, requested URL and user agent.

We use [analytics tool, e.g. a privacy-focused, cookieless analytics provider]. Non-essential analytics are only loaded where consent is required and you have given it (see section 10).

5. Lawful basis for processing

Purpose GDPR basis (Art. 6) KVKK basis (Art. 5)
Creating and running your account; issuing licenses; providing downloads and updates Contract, Art. 6(1)(b) Necessary for performance of a contract, Art. 5(2)(c)
Taking payment and managing subscriptions Contract, Art. 6(1)(b) Art. 5(2)(c)
Issuing invoices, keeping accounting and tax records Legal obligation, Art. 6(1)(c) Legal obligation of the controller, Art. 5(2)(a)
License validation, anti-piracy and abuse detection Legitimate interests, Art. 6(1)(f): protecting our software from unlicensed use Legitimate interests, Art. 5(2)(f)
Platform, server and account security; rate limiting; log retention Legitimate interests, Art. 6(1)(f) Art. 5(2)(f)
Answering support requests Contract / legitimate interests, Art. 6(1)(b) or (f) Art. 5(2)(c) or 5(2)(f)
Non-essential analytics cookies; marketing email to prospects Consent, Art. 6(1)(a) Explicit consent, Art. 5(1)
Establishing, exercising or defending legal claims Legitimate interests, Art. 6(1)(f) Art. 5(2)(e)-(f)

Where we rely on legitimate interests, we have weighed those interests against your rights and concluded the processing is limited, expected and proportionate. You can object. See section 9.

6. How we use the data

  • Deliver what you bought: license key, installer, agent packages, engine and rule updates.
  • Verify that a running deployment holds a valid, non-revoked, non-shared license.
  • Bill you, renew or cancel a subscription, and issue invoices.
  • Answer support requests and, for lifetime customers, prioritise them.
  • Notify you about security-relevant product updates, end-of-life notices and breaking changes. These are service messages tied to your license; they are not marketing.
  • Detect and stop license abuse, credential stuffing, fraudulent payments and attacks on our own infrastructure.
  • Meet accounting, tax and legal obligations in Türkiye.
  • Understand, in aggregate, which pages of siteyvm.com are useful.

We do not sell, rent or trade personal data. We do not use your data to train models. We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you for advertising.

7. Who we share it with

We use a short list of service providers (processors). Each is bound by a data processing agreement and may only act on our instructions.

Processor What it handles Where
Stripe Card payments, subscriptions, invoices, payment fraud prevention. Stripe is an independent controller for its own fraud and regulatory purposes. Ireland / United States
[Hosting provider] Hosting of siteyvm.com, the account system, the license server and download distribution [Region, e.g. Türkiye / EU]
[Email provider] Transactional email (license keys, receipts, password resets) and our support mailbox [Region]
[Analytics provider] Aggregate website statistics [Region]

We may also disclose data to professional advisers (accountants, lawyers) under confidentiality, to authorities where a valid legal order requires it, and to an acquirer in the event of a merger or sale of the business. In which case we would tell you before your data becomes subject to a different policy.

Where a legal request is made to us, we check that it is valid and lawful, we disclose the minimum required, and we tell the affected person unless we are legally barred from doing so.

8. International transfers

We are established in Türkiye, so data you send us is processed in Türkiye and in the regions listed in section 7.

  • For customers in the EU/EEA and the UK: Türkiye is not covered by a European Commission adequacy decision. Transfers from the EEA/UK to us, and onward transfers to processors outside the EEA, are made under the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with the technical and organisational measures in section 12. A copy of the relevant clauses is available on request.
  • For transfers out of Türkiye under KVKK: transfers abroad are made on the grounds permitted by Article 9 of Law No. 6698 as amended: standard contracts notified to the Personal Data Protection Authority, undertakings, or your explicit consent where no other ground applies.

9. How long we keep it

Data Retention
Account record (name, email, company) For the life of the account, then 12 months after closure, then deleted or anonymised
Invoices, payment and accounting records 10 years, as required by the Turkish Commercial Code and tax legislation. This period overrides an erasure request.
License records (key, entitlement, subscription status) For the life of the license. A lifetime license is perpetual, so its record is retained for as long as it can be validated.
License activation and validation logs (fingerprint hash, hostname, IP, version, timestamp) 24 months rolling, then deleted. Aggregate counts may be kept without identifiers.
Web server access logs 90 days
Website analytics 14 months, in aggregate form
Support email and attachments 24 months from the last message in the thread
Marketing consent records Until consent is withdrawn, plus 3 years as proof that consent existed
Records of privacy requests and our responses 3 years, as evidence of compliance

10. Your rights

Under the GDPR

  • Access, get confirmation of whether we process your data and a copy of it.
  • Rectification, have inaccurate or incomplete data corrected.
  • Erasure, have data deleted where we no longer have a basis to keep it.
  • Restriction, have processing paused while a dispute about accuracy or legitimate interests is resolved.
  • Portability, receive the data you gave us in a structured, machine-readable format (we provide JSON or CSV), or have it sent to another controller where technically feasible.
  • Objection: object to processing based on legitimate interests, and object to direct marketing at any time, with no justification needed.
  • Withdraw consent: at any time, without affecting processing that already happened.
  • Complain, to your local supervisory authority.

Under the KVKK (Law No. 6698, Article 11)

  • Learn whether your personal data is processed, and request information if it is.
  • Learn the purpose of processing and whether the data is used consistently with that purpose.
  • Know the third parties, in Türkiye or abroad, to whom the data is transferred.
  • Request correction of incomplete or inaccurate data, and request that the correction be notified to those third parties.
  • Request deletion or destruction under Article 7, and request that this be notified to third parties.
  • Object to a result produced against you solely by automated analysis (we do not carry out such analysis).
  • Claim compensation for damage caused by unlawful processing.

How to exercise them

Email info@siteyvm.com with the subject line “Data request”, or write to our registered address. Tell us which right you are exercising and, if your request concerns a license, include the account email so we can locate the record.

We answer within 30 days (KVKK Article 13) and, for GDPR requests, within one month, extendable by two further months for complex requests. We will tell you if that happens. Requests are free; we may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and we will explain why.

We may ask for information to confirm your identity before acting. We will not ask for identity documents where the account email itself is sufficient proof.

If you are unhappy with our response, you may complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, in the EEA/UK, to your national data protection supervisory authority.

11. Cookies

We keep cookies to a minimum.

Type Purpose Consent needed
Session cookie Keeps you signed in to your account and protects forms against CSRF No, strictly necessary
Stripe checkout cookies Set by Stripe during payment for fraud prevention and session integrity No, strictly necessary for the payment you requested
Consent record Remembers your cookie choice so we do not ask again No, strictly necessary
Analytics Aggregate page statistics Yes, where required

We run no advertising cookies, no cross-site tracking pixels, no social media trackers and no data-broker tags. You can change or withdraw your cookie choice at any time, and you can block or delete cookies in your browser, strictly necessary cookies aside, nothing on this site breaks if you do.

12. How we protect it

  • TLS in transit for the website, the account system, the license server and all downloads.
  • Encryption at rest for the account and license databases; passwords stored with a modern one-way hash.
  • Machine fingerprints stored as hashes, not as raw hardware identifiers.
  • Access to production systems limited to named staff, on a least-privilege basis, with multi-factor authentication.
  • Signed installer and update packages, so the artefacts you download can be verified.
  • Logging and monitoring of administrative access to systems holding personal data.

No system is perfectly secure, and we will not pretend otherwise. If a personal data breach occurs, we notify the competent supervisory authority within 72 hours of becoming aware of it where the breach is likely to result in a risk to individuals, notify the Turkish Personal Data Protection Authority in line with its 72-hour expectation, and inform affected individuals without undue delay where the risk is high.

Note that a breach at our end cannot expose your vulnerability data, because we never hold it. The blast radius of a compromise of our systems is the account, billing and license records described above.

13. Children

SITEY is an enterprise security product sold to organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to info@siteyvm.com and we will delete it.

14. Your obligations as a controller

Because SITEY runs in your infrastructure, the personal data your deployment processes, your users, your assignees, data discovered on your assets, is yours to govern. You decide the retention, the access controls and the lawful basis inside your own instance. We are not a processor for that data and cannot act on it. If your organisation needs a data processing agreement for the limited data we hold (account, billing, license activation), contact us and we will provide one.

15. Changes to this policy

We update this policy when our processing changes. The “Last updated” date at the top always reflects the current version. For material changes, a new processor, a new purpose, a shorter or longer retention period, we email account holders at least 30 days before the change takes effect. Continuing to use SITEY after that date means the updated policy applies. Previous versions are available on request.

16. Contact

Privacy questions, data requests and complaints: info@siteyvm.com. Postal mail: [Company legal name], [registered address], [city], Türkiye.

For commercial questions, see /pricing/ or /contact/.