Legal

Privacy Policy

We explain where we keep your data, how we protect it and who can access it.

Last updated:

1. Scope

This policy applies to the vectonn.com.tr website and the application, support and account operations carried out through it. For the commercial data of customers using the VectONN application, the service agreement and its data-processor annexes apply.

2. Customer data vs. site data

There are two distinct data sets that do not mix:

  • Site data: the information you submit through forms on this site. We are the data controller.
  • Customer data: the commercial records you operate in the VectONN application. You are the data controller; we act as data processor.

3. Where data is kept

In the VectONN application, each customer's data is kept in its own separate database. One business's records never sit in the same table as another's. This is not a setting added later, but the foundation of the architecture.

Access is limited by independent layers and these rules are re-verified with automated tests on every release.

4. Authorization

In the application, authorization is off by default: a user can only enter screens within the scope of permissions explicitly granted. Authorization is checked on the server side. Sensitive operations are distributed with separate permissions and who did what is written to the audit log.

5. Immutability of records

Finalized financial and stock records are not deleted or overwritten. If there is an error, the correction is made with a reverse entry (storno) and both records remain in the ledger. This follows Tax Procedure Law art. 217 and Turkish Commercial Code art. 65.

6. Backups

Databases are backed up regularly. Having taken a backup is not enough on its own; the backup's restorability is also verified. A verified backup is a precondition for every production release.

7. Technical measures on the site side

  • All traffic is carried encrypted over HTTPS.
  • Forms are protected against session forgery with a token (CSRF).
  • Passwords are stored irreversibly.
  • Forms use an invisible field against automated submission.
  • All data from users is escaped before being written to the screen.

8. Third-party services

A limited number of external services are used to run the site: hosting, e-mail delivery, font distribution and analytics. Analytics cookies run only with your consent; for details see the Cookie Policy page.

9. Data deletion requests

You can request the deletion of your personal data. Your request is fulfilled except for records that legislation requires to be retained. When financial records cannot be deleted, fields containing personal data are made inaccessible and you are informed.

10. Security incidents

If we detect that personal data has been unlawfully obtained by others, we notify the relevant persons and the Personal Data Protection Board as soon as possible.

11. Changes

This policy may be updated. The current version is always published on this page with the last update date at the top.

Requests and contact

For questions about this document or requests regarding your personal data, write to kvkk@laicos.com.tr or to Caferağa Mah. General Asım Gündüz Cad. Bahariye Plaza No: 62/5, Kadıköy / İstanbul.

Legal nameLAICOS Bilişim Yazılım ve Bilgi Sistemleri İthalat İhracat Limited Şirketi
AddressCaferağa Mah. General Asım Gündüz Cad. Bahariye Plaza No: 62/5, Kadıköy / İstanbul
Tax office / Tax IDKadıköy Vergi Dairesi (034272) / 6081463620
MERSIS no0608-1463-6200-0001
Trade registry no367228-5
Corporate e-mailinfo@laicos.com.tr
E-mailinfo@vectonn.com.tr
Phone0216 606 54 84