For seatlocklicense.com and the Seatlock demo site · Last updated: 22 September 2026
This Privacy Policy explains how we process personal data. It is also our information notice (aydınlatma metni) under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (“KVKK“). Where the EU General Data Protection Regulation or the UK GDPR (“GDPR“) applies, it also gives the information those laws require. A Turkish version (Aydınlatma Metni ve Gizlilik Politikası) is available at [LINK]. Both versions have the same content.
Items marked [TO CONFIRM] must be checked against the live website before this policy is published.
1. Who is responsible
Seatlock is a brand of Mesut SAYGIOĞLU, sole proprietorship, Antalya, Türkiye.
The data controller (veri sorumlusu) is:
Mesut SAYGIOĞLU (sole proprietorship, trading under his own name) Kütükçü Mah. 2974 Sk. Emre Eren Apt. No:4 D:3, Kepez, Antalya, Türkiye E-mail: legal@seatlocklicense.com
We have not appointed a data protection officer.
[SELLER TO DECIDE. If appointed: Our representative in the European Union under Article 27 GDPR is [NAME], [ADDRESS], [E-MAIL]. Our representative in the United Kingdom under Article 27 UK GDPR is [NAME], [ADDRESS], [E-MAIL]. You may contact them instead of us about any privacy question. If not appointed: delete this paragraph.]
In this policy, “we” and “us” mean the controller named above.
2. What this policy covers, and what it does not
This policy covers: the website seatlocklicense.com (the “Website“); the public demo site at https://demo.seatlocklicense.com (the “Demo Site“); e-mail and other communication with us; and the customer and licence records we keep.
This policy does not cover:
- Payments. Paddle processes checkout and payment data as an independent controller under its own privacy notice (see section 4).
- Seatlock software run by our customers. The Seatlock License Server, the Seatlock SDK and seatlock-tool run on our customers’ own systems. We receive no data from those systems about our customers’ end users or their devices. If you use a product that is protected by Seatlock, the company that sold you that product is responsible for your data. Please contact that company.
- Third-party websites that we link to.
3. What data we process, why, on what legal basis, and for how long
3.1 Visits to the Website and the Demo Site (server and security logs)
- Data: IP address; port; date and time of access; requested page or file; HTTP method and status code; referring page; browser and operating system (user agent); amount of data transferred; security events, such as failed logins and blocked requests.
- How we collect it: automatically, by electronic means, through the web server and security systems of our hosting provider, when your browser connects.
- Purposes: to deliver the pages; to keep our systems secure; to detect and prevent attacks, abuse and misuse of the Demo Site; and to fix technical problems.
- Legal basis: KVKK Article 5(2)(f) (legitimate interests). GDPR Article 6(1)(f) (legitimate interests). [IF LAW NO. 5651 APPLIES TO THE DEMO SITE: for Demo Site traffic data, KVKK Article 5(2)(ç) (legal obligation). TO CONFIRM]
- Do you have to give us this data? Your browser sends it when you visit. Without it, we cannot show the pages.
- Retention: [30 days: TO CONFIRM]. [IF LAW NO. 5651 APPLIES: Traffic data of the Demo Site (IP address, port, start and end time, type of service, amount of data) is kept for one (1) year because Turkish Law No. 5651 requires it. TO CONFIRM] We keep logs longer only when we need them to investigate a specific incident or to establish, exercise or defend legal claims.
3.2 Contacting us
- Data: name; e-mail address; phone number; company; job title (if you give it); the content of your message and any attachments; dates; our replies.
- How we collect it: non-automatically (partly automatically where e-mail systems are used), directly from you, by e-mail, phone [or contact form: TO CONFIRM].
- Purposes and legal basis:
- answering questions about a purchase, a licence or support: KVKK Article 5(2)(c) (setting up or performing a contract); GDPR Article 6(1)(b);
- answering other questions and keeping a record of our communication: KVKK Article 5(2)(f); GDPR Article 6(1)(f).
- Do you have to give us this data? No. But without your e-mail address or phone number we cannot reply.
- Retention: [three (3) years after our last contact: TO CONFIRM], unless the message becomes part of the customer records in section 3.3, or we need it for legal claims.
3.3 Customers and licence records
- Data: name; company name; business address and country; e-mail address; VAT, tax or company registration number; order number and Paddle transaction ID; product, licence tier, number of production sites or brands, update period; price, currency and taxes; order date; payment, refund and chargeback status (never full card details); records of your acceptance of our terms (document versions, date, time, e-mail address, IP address); where one is signed, a licence acceptance form (name and position of the signatory, signature data); the licence details and delivery records we issue, including the identifying marks that link each delivered copy to an order; download records (date, time, IP address) [TO CONFIRM]; support history; names and e-mail addresses of the customer’s contact persons; where a customer gives them to us under the Licence Agreement, names of its authorised users and contractors and their access dates, and compliance statements.
- How we collect it: partly automatically (from Paddle’s systems and our acceptance and delivery systems) and partly non-automatically (from you, by e-mail or signed form).
- Purposes and legal basis:
- delivering software, licences, updates and support, and managing renewals: KVKK Article 5(2)(c); GDPR Article 6(1)(b);
- recording acceptance of our terms and keeping accounting and tax records: KVKK Article 5(2)(ç) (Tax Procedure Law No. 213, Article 253) and 5(2)(e); GDPR Article 6(1)(f) (our interest in complying with Turkish law and proving the contract);
- checking entitlement, linking each delivered copy to its order through identifying marks, and preventing misuse: KVKK Article 5(2)(f); GDPR Article 6(1)(f) (our interest in protecting our software);
- investigating and enforcing breaches of licences and infringements, and handling disputes, refund requests and chargebacks: KVKK Article 5(2)(e); GDPR Article 6(1)(f) (our interest in establishing, exercising and defending legal claims).
- Do you have to give us this data? To buy and receive a licence, you must give the data marked as required at checkout. Without it, the order cannot be completed and we cannot deliver the licence. We must keep accounting and tax data by law.
- Retention: for as long as the licence exists, and afterwards for the periods required by Turkish commercial and tax law and until the limitation periods for claims have expired, [up to ten (10) years after the end of the calendar year in which the licence ends: TO CONFIRM WITH ACCOUNTANT].
3.4 Customer accounts on the Website [ONLY IF ACCOUNTS ARE OFFERED: TO CONFIRM]
- Data: username; e-mail address; password (stored only as a secure hash); licence and download information; login times and IP addresses.
- How we collect it: partly from you, partly automatically when you sign in.
- Purposes and legal basis: to let you sign in and to deliver your downloads and licence details: KVKK Article 5(2)(c); GDPR Article 6(1)(b).
- Do you have to give us this data? Only if you want an account. Without an account, [we deliver by e-mail: TO CONFIRM].
- Retention: for as long as your account exists. We delete account data within [90 days: TO CONFIRM] after the account is closed, except data we must keep under section 3.3.
3.5 The Demo Site
- Data: login and session cookies for the shared demo account; log data as in section 3.1; anything visitors type into the Demo Site, such as test orders, names, e-mail addresses, licence keys, device names and notes.
- How we collect it: automatically, when you use the Demo Site.
- Important: all visitors share the same demo login. Anything entered can be seen by other visitors until the next reset. The Demo Site comes with made-up sample data. Please use made-up data only. The Demo Site does not send any e-mails. [TO CONFIRM once e-mail sending is verified as disabled] If we notice real personal data on the Demo Site, we delete it without waiting for the next reset.
- Purposes and legal basis: to let you evaluate Seatlock, to keep the Demo Site secure and to prevent abuse: KVKK Article 5(2)(f); GDPR Article 6(1)(f).
- Do you have to give us this data? No. Please do not enter real personal data.
- Retention: content entered on the Demo Site is deleted at each reset, which happens [every hour: TO CONFIRM] and may happen earlier. Log data is kept as in section 3.1.
3.6 Reports of infringement, abuse and security weaknesses
- Data: the reporter’s name, contact details and report; information about the reported copy or person, such as URLs and account names.
- How we collect it: non-automatically, from the reporter, and from public sources that the report points to.
- Purposes and legal basis: to assess and act on the report, to protect our rights and the rights of others, and to reply: KVKK Article 5(2)(e) and 5(2)(f); GDPR Article 6(1)(f).
- Do you have to give us this data? No. Without contact details we cannot reply or ask questions.
- Retention: for as long as we need to handle the matter, and afterwards until the limitation periods for related claims have expired.
3.7 Legal claims and compliance
We may use any of the data above where this is necessary to establish, exercise or defend legal claims, to answer lawful requests from courts and authorities, or to check compliance with sanctions laws. Legal basis: KVKK Article 5(2)(ç) and 5(2)(e). GDPR Article 6(1)(f).
3.8 What we do not do
- We do not intentionally collect special categories of personal data (sensitive data). Please do not send them to us.
- We do not make decisions about you based solely on automated processing.
- We do not sell personal data, and we do not use it for advertising or profiling.
- We send marketing e-mails only if you have agreed to receive them. Every marketing e-mail contains a link to unsubscribe. We do not use order data received from Paddle for marketing without your consent. [NO NEWSLETTER PLANNED: TO CONFIRM]
4. Purchases through Paddle
Our online orders are processed by Paddle.com Market Limited or another Paddle group company named at checkout (for example, Paddle.com Inc. for buyers in the United States) (“Paddle“), as merchant of record and reseller.
Paddle collects and processes your checkout and payment data as an independent data controller, under its own privacy notice (https://www.paddle.com/legal/privacy). We do not receive your full card or bank account details. Paddle shares with us the order data listed in section 3.3 so that we can deliver your licence and support you. For questions about how Paddle processes your data, please contact Paddle.
5. Cookies and similar technologies
[TO CONFIRM ONCE THE SITE EXISTS] Replace this section with a complete list of the cookies actually set, stating for each one its name, provider, purpose and duration. Check the live Website and Demo Site with a cookie scanner first.
| Category | Examples | Legal basis | Consent needed? |
|---|---|---|---|
| Strictly necessary | Security and load-balancing cookies; cookies that remember your cookie choices; customer-account login cookies (if accounts are offered); login and session cookies set by WordPress and WooCommerce when you use the demo login | KVKK Article 5(2)(c) or 5(2)(f); GDPR Article 6(1)(b) or 6(1)(f) | No. The site cannot work without them. |
| Checkout | Cookies or similar technologies that Paddle uses after you click a Buy button and its checkout opens, for payment and fraud prevention. Paddle’s code is not loaded on our other pages. | Paddle’s own responsibility; see Paddle’s privacy and cookie information | As determined by Paddle |
| Analytics and marketing | We do not use analytics, advertising, order-attribution or social media tracking cookies. [TO CONFIRM] | Only with your consent: explicit consent under KVKK Article 5(1); GDPR Article 6(1)(a) | Yes. We will ask before setting any. |
If we add analytics or marketing cookies in the future, we will ask for your consent first, and you will be able to withdraw it at any time.
You can delete or block cookies in your browser settings. If you block strictly necessary cookies, sign-in and the Demo Site may not work.
6. Who receives personal data
We share personal data only as far as necessary, with:
- Our hosting provider, Hostinger (servers in Germany; backups in France), which hosts the Website and the Demo Site and processes log data on our behalf, as our data processor.
- Our e-mail service provider, Hostinger (servers in Germany), as our data processor.
- Cloudflare, Inc. (United States), which provides authoritative DNS and domain registration for seatlocklicense.com. Cloudflare’s proxy is switched off, so visitor traffic does not pass through Cloudflare; it resolves the domain name only.
- Paddle, as an independent controller: for orders, and to handle refund requests, chargebacks and payment disputes. For these purposes we may share your order data, our delivery and download records and our correspondence with you.
- Our accountant or financial adviser in Türkiye, to meet our accounting and tax obligations.
- Lawyers, mediators, arbitrators, courts, enforcement offices and public authorities, where the law requires it or where it is necessary to establish, exercise or defend our rights.
- Platforms and intermediaries, such as hosting providers, code repositories and online stores, when we report unauthorised copies. We share only what is needed for the report.
- A successor to the Seatlock business, if the business is transferred.
These transfers rely on the same legal bases as the processing described in section 3 (KVKK Article 8).
7. International transfers
Some recipients are outside Türkiye. Paddle operates from the United Kingdom, the United States and other countries, and our hosting and e-mail providers may be located abroad [TO CONFIRM]. If you are outside Türkiye, the data you send us is processed by us in Türkiye.
- Under KVKK Article 9, we transfer personal data abroad only on one of these grounds: an adequacy decision for the country concerned, where one exists; otherwise appropriate safeguards, such as the standard contracts published by the Personal Data Protection Board, which we notify to the Personal Data Protection Authority within five (5) business days of signing; or, for occasional transfers only, one of the exceptions in Article 9(6). Sharing data with Paddle about a refund request, chargeback or payment dispute is such an occasional transfer, necessary to establish, exercise or protect a right.
- Under the GDPR, where it applies, transfers rely on an adequacy decision, on standard contractual clauses, or on another ground permitted by Chapter V of the GDPR.
- Order data we receive from Paddle. Paddle sends us order data from the United Kingdom and the European Union under the European Commission’s standard contractual clauses for controller-to-controller transfers (Module One) and the UK International Data Transfer Addendum, which form part of Paddle’s Data Sharing Addendum. We are bound by those clauses as data importer. You have the right to obtain a copy of them. Write to legal@seatlocklicense.com. Our contact point for complaints about this processing is legal@seatlocklicense.com.
You can ask us for more information about these safeguards.
8. How we protect personal data
We use technical and organisational measures that suit the risk. These include encrypted connections (TLS), access controls, strong authentication, prompt security updates, collecting only the data we need, and deleting data when its retention period ends. On the Demo Site, the demo account has restricted rights, outgoing e-mail is disabled and the content is reset regularly [TO CONFIRM]. No system is completely secure. Remember that the Demo Site is shared and public.
9. Your rights
9.1 Your rights under KVKK (Article 11)
You have the right to: (a) learn whether we process personal data about you; (b) request information about that processing; (c) learn the purpose of the processing and whether the data is used for that purpose; (d) know the third parties, in Türkiye or abroad, to whom the data is transferred; (e) request correction of incomplete or inaccurate data; (f) request deletion or destruction of the data under the conditions in Article 7 of KVKK; (g) request that we notify the third parties to whom the data was transferred of any correction, deletion or destruction under (e) or (f); (h) object to a result that is to your disadvantage and arises exclusively from the analysis of your data by automated systems; and (i) claim compensation for damage caused by unlawful processing.
9.2 Your rights under the GDPR, where it applies
You have the right to access, rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal. You also have the right to lodge a complaint with a supervisory authority, in particular in the country where you live, where you work, or where you believe an infringement took place.
9.3 How to exercise your rights
Send your request to legal@seatlocklicense.com or by post to Kütükçü Mah. 2974 Sk. Emre Eren Apt. No:4 D:3, Kepez, Antalya, Türkiye. For requests under KVKK, you may also use registered electronic mail (KEP), a secure electronic signature, a mobile signature, or an e-mail address that you have previously given us and that is registered in our systems. Your request should include your name and surname (and your signature if the request is on paper); your Turkish identity number or, if you are not a Turkish citizen, your nationality and your passport or identity card number; your address for notifications, and your e-mail address and telephone number, if any; and what you are requesting.
We accept requests in Turkish or English. We may ask you to confirm your identity. We reply as soon as possible and at the latest within thirty (30) days, free of charge. If replying causes an extra cost, we may charge the fee set in the tariff of the Personal Data Protection Board.
9.4 Complaints
Under KVKK: if we reject your request, if you find our reply insufficient, or if we do not reply in time, you may complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within thirty (30) days after you learn of our reply, and in any case within sixty (60) days after the date of your request.
Under the GDPR: you may complain to a supervisory authority at any time, as described in section 9.2.
10. Children
The Website and the Demo Site are intended for businesses. They are not directed at children, and we do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
We may update this policy, for example when our services or the law change. We will publish the new version on this page with a new date. If a change significantly affects you, we will inform you in a suitable way.
12. Contact
Mesut SAYGIOĞLU (Seatlock) · Kütükçü Mah. 2974 Sk. Emre Eren Apt. No:4 D:3, Kepez, Antalya, Türkiye Privacy requests: legal@seatlocklicense.com