Legal
Last updated: 23 August 2026
This is a courtesy translation.
In case of any discrepancy the Turkish version prevails. Türkçe sürüm
This notice is prepared under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") to inform users about personal data processed in connection with the NotusShip software operated or provided by Notussoft Bilgi Teknolojileri Limited Şirketi ("Notussoft") and visits to notusship.com.
Data controller:
Notussoft Bilgi Teknolojileri Limited Şirketi
Güzelyalı Yalı Mah. Yunusemre Sok. No: 6/1
Mudanya / Bursa, Türkiye
destek@notussoft.com
| Category | Fields | Purpose | Legal ground (Art. 5) |
|---|---|---|---|
| Identity and contact | name, e-mail address, invited e-mail addresses | account creation, user verification, invitations | performance of a contract (5/2-c) |
| Account security data | password hash, refresh and password-reset token hashes, failed sign-in count, lockout state | account security, preventing unauthorised access | legitimate interest (5/2-f), legal obligation (5/2-ç) |
| User preferences | interface language, time zone, theme, avatar colour, notification frequency | personalising the experience | performance of a contract (5/2-c) |
| Activity and audit trail | change history (who changed what and when), work logs, membership and role | running project processes, integrity of the audit trail | performance of a contract (5/2-c), legitimate interest (5/2-f) |
| User content | issue titles and descriptions, comments, wiki pages, file attachments | core project-tracking functions | performance of a contract (5/2-c) |
| Network and security logs | client IP address, request path, status code, duration, user and organisation id, proxy headers | rate limiting, abuse and attack detection, system stability | legal obligation (5/2-ç), legitimate interest (5/2-f) |
Passwords and tokens are never stored in plain text. Passwords are hashed with ASP.NET Core Identity’s PBKDF2-based hasher and tokens with SHA-256; raw values are not retained anywhere.
notusship_rt): 30 daysIn the hosted installation, backups are taken by Notussoft at the infrastructure layer. The 14-day period above is the default of the product’s own backup job; in the hosted installation backups are handled at the database infrastructure level.
Issues, comments, wiki pages, work logs and audit history are retained for as long as the account remains open, for project continuity and the integrity of the audit trail. The product contains no automatic deletion policy.
Erasure is implemented as anonymisation. When erasure is requested, the record is anonymised so the audit trail is not broken: the name becomes Silinmiş kullanıcı ("deleted user") and the e-mail an unreachable .invalid address; the password hash, session tokens, notifications and saved filters are permanently deleted. Content produced by the person and the "this field was changed by this person" trail are preserved.
There are no third-party analytics or trackers. Neither notusship.com nor the NotusShip application uses advertising, external tracking cookies or third-party analytics. All resources, including fonts, are served from our own servers; there is no external CDN connection (measured on 23 August 2026: zero requests outside our own origin).
In self-hosted installations no data leaves the installation. Licence validation is fully offline; there is no telemetry and no version-check call.
In the hosted installation data is kept in Türkiye. The servers are Notussoft’s own hardware and are physically located in Türkiye; the database, logs and backups remain on those servers.
The network layer passes through Cloudflare. The domain is published via Cloudflare and the connection is established through a Cloudflare tunnel; therefore TLS terminates at the Cloudflare location nearest to you and traffic is carried over Cloudflare’s international network. Cloudflare, Inc. acts as a service provider in this respect and this flow may constitute a transfer abroad. Content data is not stored at Cloudflare; it is only processed in transit.
E-mail delivery is not configured. No SMTP server is defined for the hosted installation; notifications stay inside the application and invitation links are shown on screen. No data is therefore transferred to an e-mail provider.
File attachments are stored on the server’s own disk. No external (S3-compatible) object storage service is used; no attachment data is transferred to a third-party storage provider.
Data subjects have the right to access their data, to have it corrected, to request its erasure or anonymisation, and to object to processing.
Data export is built into the product: a user can download their own data within the current organisation as a machine-readable JSON file from Settings → Preferences → My data.
How to apply: you may send your requests by e-mail to destek@notussoft.com or in writing to the address above. Requests are concluded within 30 days at the latest.