Data protection and KVKK
Denetta is designed with KVKK, Türkiye’s personal data protection law, in mind: data is hosted in Türkiye, scans that connect to a device are limited by the customer’s signed and stamped written consent and the scope it freezes, retention periods are fixed in the system, and notifications never carry configuration values or IP addresses. This page is a summary of the product’s data handling principles, not a compliance statement.
Where is data hosted?
The Denetta core runs on a server in Türkiye. Only the collector runs on the customer network; it reads only from its own segment and pushes data to the core.
Why is written consent mandatory?
The dashboard generates a consent form specific to the company: sites, IP blocks, excluded addresses, device addresses and domains are printed on the form and frozen as they were at signing. The customer signs and stamps the form, the scanned document is uploaded, and the MSP owner opens and approves it. If the scope grows (a new site, a new IP block, a new domain), a new signature is required; no connection is made to a target outside the scope.
How long is data kept?
Periods are fixed in the database, not the application; the application can neither shorten nor extend them. Some periods are being confirmed by legal review.
- Signed consent document: 10 years for a document that was approved and later closed, 90 days for one that was never approved; the file is then destroyed and only the number and digest remain.
- Configuration backup (early access): each version for 1 year after it was last seen on the device.
- Notification recipient addresses: deleted 90 days after the notification is settled.
- First-report requests: unapproved requests 90 days; trial data destroyed 30 days after delivery.
Which external services are used?
- Microsoft 365: sending alert and account emails. Emails never carry configuration values, IP addresses or policy names.
- Cloudflare Turnstile: only on the first-report request form, against automated abuse. No third-party script is loaded on any other page; the site has no cookie-based analytics.
- CVE.org, CISA KEV and FIRST EPSS: inbound vulnerability feeds only; no customer data is sent out.
Who can access what?
Roles are separate: the MSP owner, MSP operators limited to assigned companies, and customer users who see only their own company, read-only. Downloads of consent documents and backups require a reason and are written to the audit log.