Last updated: 4 September 2026
This policy explains what personal data Ayaner collects through ayaner.com, why we collect it, how long we keep it and what rights you have over it. It covers the website, the free analysis form, our newsletter and every plugin licence sold from this site.
1. Who is responsible for your data
Ayaner operates ayaner.com and acts as the data controller for the personal data described here.
- Trading name: Ayaner
- Address: Esentepe, Talatpasa Cd. No:5, Ic Kapi No:1, 34394 Sisli / Istanbul, Turkiye
- Contact for data matters: hello@ayaner.com
We are established in Turkiye, so Turkish data protection law (KVKK, Law No. 6698) applies to our processing. Where we offer services to people in the European Union or the United Kingdom, we also process their data in line with the GDPR and the UK GDPR.
2. What we collect and why
| Data | Where it comes from | Why we process it | Legal basis |
|---|---|---|---|
| Name, email, phone, website URL, message | Contact form, free analysis form | To answer your question and produce the report you asked for | Steps taken at your request before entering a contract |
| Billing name, email, country, address, VAT or tax number | Checkout | To sell you a licence, issue an invoice and meet accounting law | Contract, plus legal obligation for the invoice |
| Licence key, activated domain, plugin version | Plugin licence activation | To deliver updates and enforce the seat count you bought | Contract |
| Email address for the newsletter | Subscription form | To send the articles and product news you opted into | Consent, withdrawable at any time |
| IP address, browser, pages viewed, referrer | Server logs and analytics | To keep the site secure and understand which pages work | Legitimate interest in a secure, usable site |
| Site URL and public technical signals | Free GEO analysis | To generate the audit report you requested | Steps taken at your request |
We do not ask for special category data, and we do not buy contact lists.
3. Payments
Card details are never sent to or stored on our servers. When card payments are enabled, they are handled by a PCI DSS compliant payment provider that receives the card data directly and returns only a transaction result to us. We keep the order record, not the card.
4. Who else sees your data
We share personal data only with the suppliers we need in order to run the service, and only as far as each one needs it:
- Our hosting provider, which stores the site and its database
- Our email provider, for transactional mail and the newsletter
- Our payment provider, for the transaction itself
- Our accountant, for invoices we are legally required to issue
We do not sell personal data, and we do not share it for anyone else’s advertising. If a public authority makes a lawful request, we comply with it and, where we are allowed to, we tell you.
5. International transfers
Our servers are in Turkiye. Some suppliers listed above process data in the European Economic Area or the United States. Where personal data of EU or UK residents leaves that jurisdiction, we rely on the European Commission Standard Contractual Clauses or an adequacy decision, and we keep a copy of the safeguard on file. Ask us at hello@ayaner.com and we will tell you which supplier handles what.
6. How long we keep it
- Enquiries that do not become projects: 12 months, then deleted
- Client and order records: 10 years, the retention period Turkish commercial and tax law requires
- Licence activation records: for the life of the licence plus 12 months
- Newsletter subscription: until you unsubscribe
- Server logs: 90 days
7. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to what we do with it, or send it to another provider in a portable format. Where processing rests on consent, you can withdraw that consent at any time without affecting what we did before you withdrew it.
Write to hello@ayaner.com. We answer within 30 days. There is no charge unless a request is manifestly excessive or repetitive.
If you are not satisfied with our answer, you can complain to the Turkish Personal Data Protection Authority (KVKK), or, if you are in the EU or UK, to your own supervisory authority.
8. Security
The site runs over TLS. Administrative accounts use unique credentials and two factor authentication. Backups are encrypted, and access to production data is limited to the people who need it. No system is perfectly secure, so if a breach ever puts your rights at risk we will notify you and the relevant authority within the statutory deadline.
9. Cookies
Cookies are covered separately in our Cookie Policy.
10. Changes
When we change this policy we update the date at the top. If the change materially affects your rights, we will say so on the site before it takes effect.