GDPR privacy notice.
This notice explains how Opsida processes personal data collected through opsidatech.com and opsida.com.tr in line with the EU General Data Protection Regulation.
Scope: our products
This notice covers personal data we collect through opsidatech.com and opsida.com.tr and through the products listed below. If you use one of these products, the rights and contact routes described here apply to you as well.
- CarbonTrex — CarbonTrex — ISO 14064-1 karbon envanteri, AB CBAM/SKDM gömülü emisyon, su ve atık raporlama SaaS. İşlenen kişisel veri: kullanıcı hesapları (ad-soyad, e-posta, IP), müşteri firma verileri, satış lead'leri, denetçi bilgileri. Barındırma AB içinde (Supabase eu-west-1 / Vercel fra1); e-posta Brevo (giden) + Mailgun US (gelen). Yurt dışı aktarım mevcuttur; Türk standart sözleşmesi henüz kurulmamıştır (çoğu sağlayıcı Kurul formunu karşı-imzalamaz). Product privacy notice
- Dosyon — Excel dosyalarını çok kullanıcılı, yetkili ve denetlenebilir operasyon uygulamalarına dönüştüren web hizmeti. Kullanıcı hesabı, çalışma alanı üyelikleri ve yüklenen çalışma dosyalarındaki veriler işlenir.
- Muin Müşavir — Serbest muhasebeci mali müşavirler için mizandan kurumlar vergisi, geçici vergi ve yıllık gelir vergisi hesaplayan çevrimdışı masaüstü program. Mükellef mali verileri kullanıcının kendi bilgisayarında saklanır. Product privacy notice
Each product's own notice additionally describes the data flows specific to it (processors, international transfers, retention periods). This list is generated from our product inventory, so a product appears here as soon as it comes into scope.
Data controller
Opsida Teknoloji Yazılım Bilgisayar ve Danışmanlık Ltd. Şti. is the data controller for personal data collected through this website. The company is registered in İzmir, Türkiye. For privacy questions, contact privacy@opsidatech.com.
Personal data we process
When you submit a contact form, we process your name, email address, company name if provided, inquiry type, and message. When you visit the website, our hosting provider may process standard server logs such as IP address, user agent, requested page, timestamp, and basic security events.
Purposes of processing
- To respond to your inquiry and communicate with you.
- To assess, prepare, or manage a potential commercial relationship.
- To operate, secure, monitor, and protect the website.
- To comply with legal obligations where applicable.
Legal basis under GDPR
- Article 6(1)(b) — processing necessary to take steps before entering into a contract or to perform a contract.
- Article 6(1)(f) — legitimate interests, including responding to business inquiries, website security, abuse prevention, and service improvement.
- Article 6(1)(c) — compliance with legal obligations, where applicable.
- Article 6(1)(a) — consent, where we rely on optional cookies or other consent-based processing.
Cookies and analytics
We use minimal measurement only if you explicitly accept it: anonymous pageview counts via Vercel Web Analytics. This measurement uses no cookies and no storage on your device, and its script is never loaded if you decline. We do not use advertising cookies, advertising pixels, fingerprinting, or session replay tools. You can decline optional cookies without affecting your ability to use the website.
Data retention
Contact form submissions are retained only as long as necessary to respond to your inquiry, manage a potential or active business relationship, and meet legal obligations. Standard server logs are retained for 30 days for security and abuse prevention unless a longer period is required to investigate a security incident.
International transfers
Form submissions are stored on infrastructure located in the European Union. If personal data is transferred outside the European Economic Area, we use appropriate safeguards such as Standard Contractual Clauses or another valid transfer mechanism under GDPR.
Processors
We may use trusted service providers for hosting (Vercel), database (Supabase), email delivery (Resend), AI inference (Anthropic, OpenRouter), and CDN/security (Cloudflare). These providers process personal data only on our instructions and only for the purposes described in this notice. A separate Data Processing Agreement (DPA) based on our standard template is available on request for corporate customers — write to privacy@opsidatech.com.
Your rights
Under GDPR, you may request access to your personal data, correction, deletion, restriction of processing, portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time. To exercise your rights, contact privacy@opsidatech.com.
Supervisory authority
If you are located in the European Economic Area, you have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the opportunity to address your concern first if you contact us directly.

