This policy explains how SAFETY PLASTİK AMBALAJ MAKİNA VE BİLİŞİM HİZMETLERİ SANAYİ TİCARET LİMİTED ŞİRKETİ, trading as Ena Hosting handles personal data about our own customers. It covers our obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the California Consumer Privacy Act as amended (CCPA/CPRA).
This policy concerns data for which we are the controller: your account, your invoices, your support correspondence. For visitor data you host on your own site, you are the controller and we are only a processor — that relationship is governed by the Data Processing Addendum.
1. Controller
| Registered name | SAFETY PLASTİK AMBALAJ MAKİNA VE BİLİŞİM HİZMETLERİ SANAYİ TİCARET LİMİTED ŞİRKETİ |
|---|---|
| Trading as | Ena Hosting |
| Address | Hadımköy Mahallesi, Minyatür Sokak No: 15/B, 34555, Arnavutköy / İstanbul, Türkiye |
| Telephone | +90 540 072 33 89 |
| destek@enahosting.com | |
| Website | https://enahosting.com |
| Tax office | Büyükçekmece |
| Tax number | 7371252273 |
2. Data we process
| Category | Data | Source |
|---|---|---|
| Identity and contact | Name, company name, email, telephone, address, country | From you, at sign-up |
| Billing and financial | Tax office and number, invoice records, payment amounts and dates, transfer references | From you and from our bank |
| Account and service | Username, password hash, service and domain records, resource usage | Generated by our systems |
| Domain registration | Name, address, email and telephone required for registration | From you; passed to the registrar |
| Technical records | IP address, browser information, sign-in times, server and security logs | Collected automatically |
| Support | Tickets, email correspondence, attachments | From you |
We do not collect or store card details. Card payments run through a PCI DSS compliant payment institution; the card number, expiry date and security code never enter our systems. We receive only the outcome of the payment (authorised or declined), the amount, and identifiers such as the card type and last four digits that let us match the transaction.
3. Purposes and lawful bases
| Purpose | Lawful basis (GDPR Art. 6 / KVKK Art. 5) |
|---|---|
| Provisioning, delivering and managing the service | Performance of a contract |
| Invoicing, collection and accounting | Legal obligation and performance of a contract |
| Domain registration and WHOIS obligations | Performance of a contract and legal obligation |
| Providing support | Performance of a contract |
| Network and system security, preventing abuse | Legitimate interests |
| Mandatory service notices (outages, maintenance, invoices) | Performance of a contract |
| Marketing emails (offers, announcements) | Consent — withdrawable at any time |
| Establishing, exercising or defending legal claims | Legitimate interests and legal obligation |
Where we rely on legitimate interests we have assessed that our interest does not override your rights and freedoms. You may request a summary of that assessment.
4. Retention
| Data | Period | Reason |
|---|---|---|
| Invoices and accounting records | 10 years | Turkish Commercial Code and Tax Procedure Law |
| Account and contract records | 10 years after the service ends | Limitation period |
| Traffic and access logs | 2 years | Turkish Law No. 5651 |
| Server and security logs | 90 days | Legitimate interest — incident investigation |
| Support correspondence | 3 years after closure | Service quality and potential disputes |
| Content of a suspended account | 30 days | To allow recovery |
| Marketing consent records | 3 years after withdrawal | To evidence that consent was withdrawn |
5. Disclosure and transfers
We do not sell your data. We share it only with parties necessary to deliver the service, and only to the extent needed:
- Domain registrars and registries — for domains you register, limited to the registration data ICANN and the registry require.
- Our data centre and infrastructure provider — our servers are hosted in Germany (Hetzner Online GmbH), within the EU data protection regime.
- Our bank and our payment institution — only what is needed to take the payment. In respect of card data the payment institution acts as an independent controller under its own privacy policy.
- Our accountant and auditors — for accounting and tax obligations.
- Competent public authorities — only on a legally binding and properly issued request.
Where a transfer outside the EEA or Türkiye is necessary, it is made on the basis of the European Commission's Standard Contractual Clauses or an adequacy decision, and in accordance with the transfer provisions of Turkish Law No. 6698.
6. Security
- All site and panel traffic is encrypted with TLS; certificates renew automatically.
- Passwords are stored as irreversible hashes and are never held in plain text.
- Administrative access is key-based and protected by two-factor authentication.
- Each customer account is isolated from the others at operating-system level.
- A host firewall, ModSecurity and malware scanning are active.
- Database backups are taken daily and held in a restricted directory.
In the event of a breach affecting your personal data we notify the supervisory authority within 72 hours and affected individuals as soon as reasonably possible.
7. Your rights
Depending on where you live, you have the right to:
- know whether we process your personal data and obtain a copy,
- have inaccurate or incomplete data corrected,
- have data erased, where we are not legally required to keep it,
- restrict processing,
- receive your data in a structured, machine-readable format (portability),
- object to processing based on legitimate interests,
- withdraw consent where processing is based on it,
- object to a decision produced solely by automated analysis that affects you adversely,
- claim compensation for damage caused by unlawful processing.
If you are a California resident, the CCPA/CPRA gives you the right to know the categories we collect, to request deletion, and to opt out of sale or sharing. We do not sell your personal information and do not share it for advertising. You will not be discriminated against for exercising these rights.
How to exercise them
Write to destek@enahosting.com. We respond within 30 days. Complex requests may be extended once, and we will tell you if that happens. Requests are free; we may charge a reasonable fee for manifestly unfounded or repetitive ones.
If you are not satisfied with our response you may complain to your national data protection authority. In Türkiye that is the Personal Data Protection Authority (kvkk.gov.tr).
8. Cookies
The cookies this site sets and how to control them are described in the Cookie Policy.
9. Children
Our services are not directed at anyone under 18 and we do not knowingly collect personal data from children. Where we learn of such data, we delete it without delay.
10. Changes
We may update this policy. Material changes are notified by email at least 30 days before they take effect. The effective date at the foot of the page tells you which version applies.