Privacy Policy and KVKK Disclosure Notice
Last updated: 23 Ağustos 2026
This is a courtesy translation. The original of this page is in Turkish; if the translation and the original text differ, the Turkish text governs.
This text is prepared to inform you about personal data processed through Watch Your WP ("the Service") under Law No. 6698 on the Protection of Personal Data ("KVKK"), Turkey's data protection law. Watch Your WP is currently in closed beta; the Service is offered only to invited users, free of charge.
1. Data Controller
Watch Your WP is currently not operated under a separate legal entity (company), but individually by Erdinç Bulat. The data controller under KVKK is Erdinç Bulat. Once a company is formed for the Service, this text will be updated and the data controller information changed accordingly.
2. What Data We Collect
The following categories of data are processed while you use the Service:
- Account data: full name, email address, password (stored irreversibly hashed).
- Organization/workspace data: the workspace name you create, brand settings (logo, color).
- Data about the WordPress sites you manage: site address, WordPress/PHP version, plugin/theme list, WordPress user list, media library metadata, backup files (including site files and database content), PHP error logs, security scan findings, uptime, SSL/domain expiration information. This data is pulled through the Watch Your WP Connector plugin installed on your site, with your authorization.
- Usage/transaction logs: a record of the actions you take in the panel, login time, IP address.
- Technical data: browser/session information, cookies (see Section 7).
If a WordPress site you connect contains data belonging to other people (e.g. site users, media, commenter information), you are the data controller for that data with respect to those individuals; Watch Your WP acts on your behalf as a data processor in that respect.
3. Purposes of Processing
- Providing the Service: viewing/managing sites from the panel, backup, updates, monitoring.
- Security: preventing unauthorized access, detecting misuse, rate limiting.
- Notifications and email delivery: downtime/SSL/security alerts, monthly summary reports, password resets.
- Improving the Service and fixing bugs.
- Fulfilling legal obligations.
4. Legal Basis
Your personal data is processed primarily on the grounds, under KVKK Art. 5/2, of being directly related to the establishment or performance of a contract (being necessary for us to provide the Service) and legitimate interest. Where explicit consent is required (e.g. your acceptance of this text), consent is obtained separately.
5. Parties Data Is Transferred To
Data is shared with a limited number of subcontractors/infrastructure providers to deliver the Service:
- Resend: sending notification and transactional emails (password reset, alerts, monthly report).
- Railway: the server infrastructure hosting the application and database.
- Cloudflare R2: storing an encrypted second (off-site) copy of backup files.
- WordPress.org's official checksum APIs: for core/plugin file integrity checks; contains no personal data.
These providers' servers may be located abroad; in that case, the data transfer is carried out in accordance with KVKK's provisions on cross-border data transfer. Data is not shared with or sold to any third party beyond the ones listed above for marketing purposes.
6. Retention Period
Your data is retained for as long as your account is active. When you delete your account or request its deletion, data is deleted or anonymized within a reasonable period, except for data subject to a legal retention obligation.
7. Cookies
Watch Your WP does not use third-party advertising/tracking cookies. The cookies used are limited to keeping your session open (login session) and remembering your preferences (interface preferences such as theme, sidebar state).
8. Data Security
Passwords are hashed irreversibly, and the API keys used to connect to WordPress sites are protected the same way. All actions requiring authentication go through an authorization check, and critical actions (removing a site, core updates, deleting a user, etc.) are subject to an additional authorization check. That said, no data transmission or storage over the internet can be guaranteed to be 100% secure.
9. Your Rights (KVKK Art. 11)
Under Article 11 of KVKK, you may apply to us to:
- Learn whether your personal data is being processed,
- Request information about it if it has been processed,
- Learn the purpose of processing and whether it is used in accordance with that purpose,
- Request correction if it has been processed incompletely or incorrectly,
- Request its deletion or destruction,
- Object to a result arising against you through analysis exclusively via automated systems,
- Request compensation for damages you suffer due to unlawful processing
and you hold these rights.
10. How to Apply
To exercise the rights above, or for questions about this policy, you can reach us at [email protected].
11. Changes
This policy may be updated as the Service develops (e.g. the addition of payment infrastructure, moving under a company). You will be notified of material changes via your registered email address.