Denetta Terms of Service
Effective: 2 October 2026 · Version 1
These Terms of Service (the "Terms") govern the use of the Denetta service. Please read them carefully before using the service. Sections 4 (nature of the service), 5 (meaning of findings), 18 (limitation of liability), 22 (changes), 24 (evidence agreement) and 25 (governing law and jurisdiction) directly affect your rights.
These Terms are published in Turkish and English. In case of conflict, the Turkish version prevails.
1. Parties and scope
1.1. Service provider: Bilgi Teknoloji Danışmanlık Ticaret Limited Şirketi ("Bilgi Teknoloji"), address: İcadiye Mahallesi Ayarcıbaşı Sokak No:7/1 D:1 Bağlarbaşı 34674 Üsküdar, İstanbul, MERSIS no: 0172037093400017, registered electronic mail (KEP) address: bilgiteknoloji@hs02.kep.tr, e-mail: destek@bilgiteknoloji.com.tr.
1.2. Service recipient: a legal entity or merchant that establishes a service relationship with Bilgi Teknoloji by placing an order, accepting a quotation or signing another written agreement (the "Customer"). A company applying for the free first report is subject to these Terms as set out in Section 8.
1.3. These Terms apply to the denetta.com website, the Denetta panel, the Collector software, reports and all related services.
1.4. Denetta is a business-to-business (B2B) service offered for commercial or professional purposes only. The Customer acknowledges that it receives the service within the scope of its commercial or professional activity; the relationship between the Parties is not subject to Turkish Consumer Protection Law No. 6502.
2. Definitions
- Service: read-only infrastructure auditing provided through the Denetta platform, including inventory, findings, scores, reports, notifications and related support.
- Denetta: the trade name of the platform provided by Bilgi Teknoloji that audits infrastructure in a read-only manner.
- Customer: as defined in 1.2; the owner of the audited infrastructure or a person authorised to have it audited.
- Partner: a managed service provider (MSP), reseller or service provider that has entered into a separate partnership agreement with Bilgi Teknoloji in order to offer the Service to its own customers.
- User: a natural person authorised to access the panel on behalf of the Customer or a Partner.
- Panel: the web-based management and reporting interface of the Service.
- Centre: the server infrastructure of the Service, hosted in Türkiye.
- Collector: optional read-only collection software installed in the Customer's network, which transmits collected data to the Centre over outbound 443/tcp connections only.
- Target: a device, IP block, domain name or Microsoft 365 tenant included in scope by the Consent Form.
- Consent Form: the Customer-specific "Security Set and Access Consent Form", delivered signed and stamped, which declares the technical scope of the audit, the data read and the external connections made.
- Finding: the result of applying an audit rule to data read from a Target.
- Score: the 0-100 Infrastructure Health Score and the category scores calculated from Findings.
- Report: the audit output shown in the Panel or produced as a PDF.
- Module: a separately licensed part of the Service (for example firewall audit, scheduled scanning, vulnerability matching, network device audit, domain and e-mail security, Microsoft 365 audit).
- Site: a business location of the Customer defined in the Panel (head office, branch, facility). For Modules licensed per Site, the licensing unit is the Site; a high-availability (HA) pair at one Site counts as a single firewall.
3. Formation of the agreement and order of precedence
3.1. The agreement is formed when the Customer accepts a Bilgi Teknoloji quotation in writing, places an order, or the Parties sign a separate agreement. The Customer acknowledges that it had the opportunity to read and negotiate these Terms before the agreement was formed.
3.2. In case of conflict between the documents forming the agreement, the following order applies:
- a separate agreement or data processing agreement signed by the Parties (only for the matters it governs);
- the signed Consent Form approved by Bilgi Teknoloji — with respect to audit scope, data read, external connections, retention periods and technical statements;
- the order or accepted quotation — with respect to fees, Modules, number of Sites and term;
- these Terms;
- privacy notices (provided for information; they neither extend nor restrict the obligations in these Terms).
3.3. These Terms do not narrow the technical statements and assurances in the Consent Form. The text of the Consent Form version that was signed remains valid for that document.
4. Nature of the Service
4.1. Read-only audit. Under no circumstances does Denetta write to, change the configuration of, or delete anything on a Target. Only read requests are sent to devices; the connection types used, the sections read and, without exception, all external connections are declared item by item in the Consent Form.
4.2. What is not done. The Service does not perform active vulnerability exploitation, port scanning, credential guessing (password attempts), open-relay testing or any test that places load on a Target. Vulnerability detection is limited to comparing software versions with public vulnerability records.
4.3. Remediation suggestions. Remediation texts shown in Reports and in the Panel (for example FortiOS commands, PowerShell commands, DNS records) are suggestions only; Denetta never executes them or sends them to a Target. The decision whether to apply a suggestion, its validation in the Customer's own environment, change planning, taking backups and the consequences of applying it are the Customer's responsibility.
4.4. Written consent and scope. No connection to a Target, whether from the Centre or through the Collector, starts before the Customer's signed and stamped Consent Form has been reviewed and approved by Bilgi Teknoloji. Connections are limited to the scope at the time of signature; if the scope expands (a new Site, IP block, device address, domain name or Microsoft 365 domain), the new Target is not contacted until a new Consent Form is signed. Narrowing the scope does not require a new signature.
4.5. Full configuration backup. The full config backup service operates in the Module in which it is offered and once the Customer's IT team has set up the required automation on the device; the device sends the backup itself, and Denetta never restores a backup to a device. Retention and access conditions are set out in the Consent Form.
4.6. Positioning. Denetta is an expert audit layer; it does not replace RMM, network monitoring (NMS), SIEM, intrusion detection or incident response products, it sits on top of them. The Service does not monitor in real time; audits run periodically, on a schedule or when triggered manually.
4.7. Early access. Features offered in the Panel or on the website as "early access", "preview" or similar are under development; they may be changed or withdrawn and are provided as is.
4.8. Evolution of the Service. Bilgi Teknoloji continuously updates rule sets, the scoring model and Module contents. Such updates may change Findings and Scores for the same Target; this does not mean the Target has changed. Bilgi Teknoloji will not materially narrow the core function of a paid Module to the Customer's detriment during a paid term.
5. Meaning of findings, scores and reports
5.1. Findings and Scores are an assessment based on rules applied to the data that could be read. The Service does not guarantee that Targets are secure, that all vulnerabilities or configuration errors have been detected, that an attack will be prevented, or that compliance with any law, standard or contract has been achieved.
5.2. "Unknown" and "visibility gap". If the data required for a check could not be read (for example a section for which no permission was granted, a field absent from a backup file, an unreachable service), that check is not counted as "passed"; it is shown in the Report as "unknown" or as a "visibility gap". This means the area in question could not be audited and no assurance is given about it.
5.3. "Out of scope" and "not licensed". Checks that are invalid given the state of the Target are shown as "out of scope", and checks belonging to an unlicensed Module as "not licensed". The Score is calculated only over discovered and licensed categories; it says nothing about an area that was not audited.
5.4. Notifications. E-mail notifications are sent only under the conditions defined in the Panel (for example a new critical or high-severity finding). The Service does not undertake that every configuration change or every risk will be notified; e-mail delivery depends on third-party infrastructure.
5.5. Third-party data. Vulnerability matching relies on public sources (Section 17). A record that is missing or wrong at the source may be missing or wrong in the Report. If source data is not current, the related checks return "unknown".
6. Customer obligations
The Customer agrees:
6.1. to include in scope only devices, IP blocks, domain names and Microsoft 365 tenants that it owns or is authorised in writing to have audited;
6.2. to deliver the Consent Form signed and stamped by its authorised representative, to ensure that the scope information (Sites, IP blocks, device addresses, domain names) is accurate, and to inform Bilgi Teknoloji when the scope changes;
6.3. to set up the access granted to Denetta under the principle of least privilege — a read-only permission profile, a source IP restriction limited to the Centre's egress address and a separate account opened solely for auditing — and to remediate Report findings about Denetta's own access (for example the account carrying write permission);
6.4. to transmit API keys, passwords and similar credentials only through a secure channel and never in plain text by e-mail or messaging applications; to keep the passwords of Panel User accounts confidential; and to notify Bilgi Teknoloji without delay of any suspected unauthorised use;
6.5. if it uses the Collector, to install it on a server under its own management and security, and to be responsible for the security of that server's operating system and for the Collector running only in approved segments;
6.6. to comply with the terms of use and licence terms of the providers of the audited products and services (for example Fortinet, Microsoft); to have the consent screen for the Microsoft 365 connection approved by an authorised administrator of the tenant; and to acknowledge that its licence, support and subscription relationships with those providers are its own responsibility;
6.7. as data controller for personal data, to fulfil its own obligations regarding privacy notices, legal basis and, where required, registry registration;
6.8. to evaluate suggestions in the Report in its own environment and to back up its configuration before applying them.
The Customer shall indemnify Bilgi Teknoloji for losses arising from third-party claims against Bilgi Teknoloji because the Customer included a Target it was not authorised to include or breached its obligations under this Section.
7. Partners (MSPs and resellers)
7.1. A Partner may use the Service on behalf of its own customers only on the basis of a separate partnership agreement with Bilgi Teknoloji. These Terms apply in addition to that agreement.
7.2. For every Target it includes in scope on behalf of its customer, the Partner must obtain the end customer's signed Consent Form, inform the end customer about the nature of the Service as described in Sections 4 and 5 of these Terms, and remains responsible for the commitments it makes to the end customer. A Partner may not give its end customer, on behalf of Bilgi Teknoloji, any assurance not contained in these Terms.
7.3. With respect to personal data, the end customer is the data controller, the Partner is the data processor and Bilgi Teknoloji is a sub-processor acting on the Partner's instructions; details are set out in the partnership agreement.
7.4. White-label use is possible only where expressly permitted in the partnership agreement and under the conditions set out there.
8. Free first report
8.1. At its discretion, Bilgi Teknoloji may provide a one-time free FortiGate configuration report to companies that apply through the request form on the website. Requests are reviewed by the Bilgi Teknoloji team; Bilgi Teknoloji may decline a request without giving reasons.
8.2. Who may apply. Only an employee of the company that owns the device to be reported may apply, on behalf of their own company. MSPs, resellers, IT service providers and consultants may not apply or upload on behalf of their customers or any third company. Applications must be made with a corporate e-mail address; applications from personal or disposable e-mail addresses are not accepted.
8.3. Entitlement limit. Through the request form, only one free report is granted per corporate e-mail domain, and that report covers a single device per company (preferably the FortiGate at the head-office site). The company's other sites and devices are the subject of the paid audit.
8.4. Upload. For an approved request, a single-use upload link valid for 7 days is sent to the applicant's corporate e-mail address. The uploader declares their name, title and company, that the device belongs to their company, that they are not uploading on behalf of a third company and that they are authorised to upload, and accepts the privacy notice. Liability for an untrue declaration lies with the declarant and the company they represent.
8.5. No connection to the device. No connection is made to the device for the free report; only the uploaded backup file is examined. The uploaded file itself is not retained; it is processed in memory, and only the parsed configuration summary, findings and score, together with the file's SHA-256 digest and size, are kept.
8.6. Summary report. The free report is a summary: it contains the Score, severity distribution, the titles of critical and high-severity findings and the number of known vulnerabilities; it does not contain evidence, device-specific remediation commands or the full list of findings. The report is presented only to the company that owns the device and its authorised representative, in a meeting; no results are shown on the upload page.
8.7. Destruction. Analysis data for the free report is automatically destroyed 30 days after the report is marked as delivered; if delivery is not marked, 30 days after the first upload; if no upload is made, 30 days after the record was created. After destruction, only the company name, the file digest, dates, the authority declaration and processing records containing no configuration content remain. If the company notifies in writing that it has decided to become a customer, destruction stops; even then, connection to the device starts only with a signed Consent Form.
8.8. The free report is a pre-sales assessment; it does not oblige Bilgi Teknoloji to provide any service and is subject to the liability regime in 18.4.
9. Acceptable use
The Customer, Partners and Users may not:
9.1. use the Service to audit, or have audited, systems they do not own or are not authorised in writing to audit;
9.2. reverse engineer or decompile the Service, the Panel, the Collector or reports, extract or copy rule sets in bulk, or use the Service to develop a competing product or service or to publish comparative product analyses (except where expressly permitted by applicable law);
9.3. attempt to circumvent or test tenant or customer isolation, permission boundaries, rate limits or security controls, or place excessive load on the Service with automated tools;
9.4. share their accounts with third parties, use the Service for Sites or companies outside the licensed scope, or resell or rent the Service to third parties without a Partner agreement;
9.5. attempt to use the free first report entitlement repeatedly through different domains or individuals;
9.6. use the Service for any unlawful purpose or in a manner that infringes the rights of third parties.
Anyone who discovers a security vulnerability in the Service is expected to report it to destek@bilgiteknoloji.com.tr without exploiting it.
10. Accounts, roles and audit trail
10.1. Access to the Panel is provided through role-based authorisation. As a rule, Customer Users see only their own company's data, read-only; scope and role assignments are made by an administrator of Bilgi Teknoloji or the Partner.
10.2. New Users are not sent a password; they receive a single-use, time-limited link to set their password. Users set and keep their own passwords confidential.
10.3. Actions such as accepting a finding, reviewing a consent document, credential operations and downloading backups are recorded in the audit trail together with the User who performed them. For this reason User accounts are not deleted but disabled: a disabled account cannot access the Panel and its open sessions are terminated immediately, but the account's name and e-mail address are retained together with the audit trail to prove who performed the actions carried out with that account.
10.4. In case of a security risk or suspected unauthorised use, Bilgi Teknoloji may temporarily disable an account and will inform the Customer.
11. Fees, invoicing and payment
11.1. Pricing unit. Modules licensed per Site are charged per Site; Modules licensed per company (for example domain and e-mail security; the number of domains included and the fee for additional domains are stated in the price list) are charged per company. The number of devices is not a basis for fees.
11.2. Price list. List prices are published on denetta.com; they are in US Dollars (USD), monthly and exclusive of VAT. Where an order or quotation specifies a different price, that price applies.
11.3. Term. Subscriptions may be monthly or annual. For annual prepayment, the discount stated in the price list applies (15% at the time of publication).
11.4. Invoicing. Invoices are issued in Turkish Lira (TRY); fees denominated in USD are converted into TRY at the CBRT (Central Bank of the Republic of Türkiye) foreign exchange selling rate on the invoice date, and VAT is added. Monthly subscriptions are invoiced in advance at the beginning of each month for that month; annual subscriptions are invoiced in advance for one year at the start of the term. A Site or Module added during a term is invoiced from the month in which it is added; a Site or Module removed drops off the invoice at the end of the paid term.
11.5. Payment. Invoices are payable by the due date stated on the invoice or, if none is stated, within 15 days of the invoice date. Overdue amounts bear default interest from the date of default at the advance interest rate pursuant to Article 2 of Law No. 3095. If payment is not made within 30 days of the due date, Bilgi Teknoloji may suspend the Service, 10 days after written notice, until payment is made; data is not deleted during suspension.
11.6. Price changes. Bilgi Teknoloji may change prices by notifying the Customer at least 30 days in advance. The new price applies from the first subscription term starting after the notice; the price of a paid or already started term does not change. A Customer that does not accept the new price may end the subscription before the new term starts.
11.7. Refunds. Fees paid are not refunded except in the cases listed in 20.5.
12. Service level, maintenance and support
12.1. Bilgi Teknoloji uses commercially reasonable efforts to keep the Service available and working correctly. Uninterrupted or error-free operation is not guaranteed. Numerical service level commitments (SLA) are given only under a separately signed service level agreement.
12.2. Planned maintenance is performed outside business hours where possible and, where possible, announced in advance in the Panel or by e-mail. Maintenance that is urgent for security reasons may be performed without prior notice.
12.3. Support requests are sent to destek@bilgiteknoloji.com.tr and handled on business days during business hours.
12.4. A scheduled audit that cannot be performed because the Target is unreachable, credentials are invalid or the Target is outside the consent scope does not constitute a Service interruption; such cases are shown in the Panel.
13. Personal data protection
13.1. Roles. With respect to personal data read from the audited Targets and processed through the Service, the Customer is the data controller and Bilgi Teknoloji is the data processor acting on behalf of and on the instructions of the Customer. Bilgi Teknoloji is itself the data controller for Panel User accounts, billing and contact records and data from the request form on the website, and publishes separate privacy notices for these.
13.2. Data processed and purpose. The categories of personal data processed, the data not processed and the purpose are declared in the data protection annex of the Consent Form. Bilgi Teknoloji processes this data solely to provide the Service; it does not process it for marketing and does not transfer it to third parties other than the service providers in 13.4. Customer configurations are not entered into artificial intelligence tools during support and development.
13.3. Hosting. Customer data is processed and stored on servers hosted in Türkiye; the database is not reachable from the internet. Credentials and signed documents are stored encrypted; every record is separated per company by row-level access control at database level.
13.4. External services and sub-processors. By the nature of the Service, data is shared with the following services; the details are set out in the Consent Form:
- Microsoft 365 (Microsoft Corporation, Exchange Online): sending notification e-mails, password-setting e-mails and upload link e-mails. The e-mails carry the company, site and device name, finding code, title and severity, score change and the names of changed configuration sections; they do not carry configuration values, IP addresses or policy names. The content and recipient address of e-mails may be processed by Microsoft, including outside Türkiye, during sending.
- Cloudflare Turnstile (Cloudflare, Inc.): only on the request form on the website, for verification against automated abuse; technical browser signals and the IP address are sent directly from the browser to Cloudflare and processed outside Türkiye.
- Domain audit: the domain names queried go to public DNS resolvers (Cloudflare 1.1.1.1, Google 8.8.8.8) and, for the registration expiry date, to the RDAP service of the relevant registry or to the TRABİS WHOIS server.
- Microsoft 365 audit: only read requests are sent to Microsoft's identity and Graph services for the Customer's own tenant.
- Hosting: the Centre runs on the infrastructure of a hosting (server) provider in Türkiye.
Bilgi Teknoloji informs the Customer before starting to use a new service provider that processes personal data; if the Customer objects on justified grounds, it may terminate the agreement under 20.4.
13.5. Security breach. When Bilgi Teknoloji becomes aware of a security breach affecting Customer data, it informs the Customer without delay and provides reasonable information and assistance so that the Customer can fulfil its obligations as data controller.
13.6. Data subject requests. Requests reaching Bilgi Teknoloji directly concerning data for which the Customer is data controller are forwarded to the Customer. On request, the Parties will sign a separate data processing agreement.
14. Retention periods
The periods below are the same as in the Consent Form and the privacy notices; where the signed version of a Consent Form states a different period, the Consent Form applies to that document.
- Audit data (inventory, parsed configuration, findings, scores, alerts): retained for the term of the agreement; deleted within 90 days after the agreement ends. The Customer may request earlier deletion in writing.
- Full config backup: each version is retained for 1 year from the time it was last seen on the device; when the period expires, the content is deleted and only its digest (SHA-256), size and dates remain. The Customer may request earlier deletion in writing.
- Signed Consent Form: retained while the consent is valid. When an approved document is withdrawn or replaced by a new form, it is retained for 10 years as evidence in case of dispute; a document that was never approved (rejected, or withdrawn before approval) is destroyed after 90 days. After destruction only the document number, dates and the file digest remain.
- Microsoft 365 audit: masked user names are deleted 90 days after the audit in which they were collected or, in finding evidence, 90 days after the finding was last seen; counts and audit results remain.
- Notification records (including recipient e-mail addresses): deleted 90 days after completion.
- Free first report and requests: the periods in 8.7 apply; requests that are not approved are deleted after 90 days. The authority declaration record is retained for 10 years as evidence. The record of the single entitlement granted per domain (domain name and company name) contains no personal data and is retained indefinitely so that the entitlement limit can be applied.
- Audit trail and disabled User accounts: retained for 10 years from the end of the agreement as evidence in case of dispute. The audit trail does not contain configuration content.
- Commercial records and invoices: retained for the periods required by the Turkish Commercial Code and tax legislation.
15. Confidentiality
15.1. Each Party uses information learned under the agreement that is expressly designated as confidential or is confidential by its nature (including the Customer's configurations, findings and reports, and Bilgi Teknoloji's rule sets, software and quotations) solely for the performance of the agreement and does not disclose it to third parties.
15.2. This obligation does not apply to information that is public, independently developed by the other Party, or disclosed because of a legal obligation or a decision of a competent authority; in the case of a legal obligation, the other Party is informed in advance where legally permitted.
15.3. The confidentiality obligation continues for 3 years after the agreement ends, and indefinitely for trade secrets and Customer configurations.
16. Intellectual property
16.1. All rights in the Denetta software, the Panel, the Collector, rule sets, expertise knowledge bases, the scoring model, report templates, documentation and the Denetta trademark belong to Bilgi Teknoloji. These Terms grant the Customer a non-exclusive, non-transferable, non-sublicensable right of use for the term of the agreement and limited to the licensed scope.
16.2. Data and configurations read from the Customer's Targets belong to the Customer. The Customer may freely use Reports produced for it in its internal affairs and share them with its independent auditors, insurers, consultants and business partners for its own purposes.
16.3. Bilgi Teknoloji may use aggregated statistics that contain no personal data and no information identifying the Customer or its Targets to improve the accuracy of rules and the scoring model; it does not publish such statistics in a way that makes the Customer identifiable.
16.4. Feedback and suggestions about the Service provided by the Customer may be used by Bilgi Teknoloji to improve the Service without any obligation arising.
17. Third-party services and data
17.1. Vulnerability matching relies on public sources such as CVE.org (CVE records, under the CVE Terms of Use), NVD, the CISA Known Exploited Vulnerabilities (KEV) catalogue and FIRST EPSS. Bilgi Teknoloji does not guarantee the accuracy, completeness or timeliness of these sources.
17.2. The Service reads data from the products and application programming interfaces (APIs) of Fortinet, Microsoft and other manufacturers. Changes these manufacturers make to their interfaces, permission models or terms of use may restrict or stop the related feature; in that case Bilgi Teknoloji uses reasonable efforts to adapt the Service within a reasonable time, and such changes do not constitute a breach of the agreement.
17.3. Denetta is not affiliated with or endorsed by any of the manufacturers named; product names belong to their owners.
18. Limitation of liability
18.1. Bilgi Teknoloji's liability for damage caused by its intent or gross negligence is not limited (Turkish Code of Obligations, Article 115).
18.2. In all other cases, Bilgi Teknoloji is not liable for loss of profit, loss of business, loss of reputation, loss of data, business interruption or other indirect damage.
18.3. In all other cases, Bilgi Teknoloji's total liability arising from the agreement is limited to the fees actually paid by the Customer to Bilgi Teknoloji for the relevant Service in the 12 months preceding the event giving rise to the damage.
18.4. For the free first report and other services provided free of charge, Bilgi Teknoloji is not liable except in cases of intent and gross negligence.
18.5. Bilgi Teknoloji is not liable for damage arising from the Customer applying or not applying suggestions in the Report, changes the Customer makes to its own systems, incorrect or incomplete information provided by the Customer, the Customer's breach of its obligations, the security of the Collector server installed by the Customer, or third-party services and data (Section 17).
18.6. The Service is an assessment (Section 5); the occurrence of an attack, data breach or security incident does not in itself mean that the Service was performed in breach of the agreement.
19. Force majeure
Natural disasters, epidemics, war, terrorism, general strikes, decisions of competent authorities, widespread energy or communication infrastructure outages, large-scale cyber attacks occurring despite Bilgi Teknoloji's reasonable measures, and similar events beyond the Parties' control constitute force majeure. During force majeure, the affected Party's related obligations are suspended; if force majeure lasts longer than 60 days, either Party may terminate the agreement by notice. Payment obligations continue for amounts that fell due before the force majeure event.
20. Term, suspension and termination
20.1. Term and renewal. The agreement is concluded for the term specified in the order and renews automatically for the same period. Either Party may cause the agreement to end at the end of the term by written notice given before the term ends; for monthly subscriptions, notice must be given by the last business day of the month concerned at the latest, and for annual subscriptions at least 30 days before the end of the term.
20.2. Changes to Sites and Modules. The Customer may request to add Sites or Modules at any time; removals take effect at the end of the paid term.
20.3. Suspension. Bilgi Teknoloji may suspend the Service in whole or in part in case of late payment (11.5), in a situation threatening the security of the Service or other customers, or in case of breach of Section 9. Unless security requires otherwise, suspension is notified in advance.
20.4. Termination for cause. Either Party may terminate the agreement if the other Party breaches a material obligation and fails to remedy the breach within 15 days of written notice. In case of breach of 9.1, Bilgi Teknoloji may terminate the agreement without a notice period.
20.5. Refund cases. If the Customer terminates the agreement due to Bilgi Teknoloji's material breach (20.4), by objecting to a change to its detriment (Section 22) or by objecting on justified grounds to a new sub-processor (13.4), the portion of the prepaid fees corresponding to the unused period is refunded.
20.6. Withdrawal of consent. The Customer may unilaterally cut off the access it has granted to Targets at any time and withdraw its consent under the Consent Form in writing; connections to the related Targets then stop. Withdrawal of consent does not by itself end the obligation to pay fees; the subscription is ended in accordance with 20.1.
21. When the agreement ends
21.1. When the agreement ends, connections to Targets and scheduled audits stop and User access is closed.
21.2. Within 30 days after the agreement ends, the Customer may request in writing the delivery of its latest Reports as PDF.
21.3. Data is deleted or destroyed in accordance with the periods in Section 14.
21.4. The Customer is responsible for removing the Collector from its own server and the accounts, API keys and the Denetta application in Microsoft Entra that it created for Denetta from its own systems. Microsoft 365 access continues on Microsoft's side until the application is deleted from the Customer's tenant.
21.5. Provisions that by their nature must survive the end of the agreement (in particular the last paragraph of Section 6 and Sections 14, 15, 16, 18, 24 and 25) remain in force.
22. Changes to these Terms
22.1. Bilgi Teknoloji may update these Terms. The current text is published on denetta.com with its effective date and version number.
22.2. Changes to the Customer's detriment are notified to the Customer by e-mail at least 30 days before they take effect and do not apply to the current subscription term; they apply from the first term starting after the notice. A Customer that does not accept the change may end the agreement before the new term starts; continued use of the Service in the new term constitutes acceptance of the change.
22.3. Changes in the Customer's favour, mandatory changes resulting from changes in legislation or decisions of competent authorities, and provisions governing only a new feature take effect on the date of publication.
22.4. This Section does not change the text of a signed Consent Form; a change to a statement in the Consent Form requires a new form version to be signed.
23. Notices
23.1. Notices concerning day-to-day operation are given by e-mail: to Bilgi Teknoloji at destek@bilgiteknoloji.com.tr, and to the Customer at the authorised e-mail address it has provided in the order or in the Panel.
23.2. Notices of termination, default and formal warnings are given by registered electronic mail (KEP), through a notary public or by registered mail with return receipt. Bilgi Teknoloji's KEP address: bilgiteknoloji@hs02.kep.tr.
23.3. Unless a Party notifies the other of a change in its address and contact details, notices sent to the last known address are deemed valid.
24. Evidence agreement
The Parties agree that, in disputes arising from this agreement, Bilgi Teknoloji's electronic records (including audit trails, server and transaction logs, e-mail records and SHA-256 digests of signed documents) constitute valid and binding evidence pursuant to Article 193 of the Turkish Code of Civil Procedure No. 6100. The Customer's right to prove the contrary is reserved.
25. Governing law and jurisdiction
These Terms and the agreement are governed by Turkish law. The Istanbul (Central) Courts and Enforcement Offices have jurisdiction over disputes.
26. Miscellaneous
26.1. Severability. If a provision of these Terms is held invalid or unenforceable, the validity of the other provisions is not affected; the invalid provision is deemed replaced by the valid provision closest to its purpose.
26.2. Assignment. The Customer may not assign its rights and obligations under the agreement to third parties without Bilgi Teknoloji's written consent. Bilgi Teknoloji may assign the agreement upon notice to the Customer in the event of a merger, demerger or transfer of the relevant business.
26.3. Waiver. Failure or delay in exercising a right does not constitute a waiver of that right.
26.4. Entire agreement. These Terms, together with the documents listed in Section 3, constitute the entire agreement between the Parties.
26.5. Language. These Terms are published in Turkish and English. In case of conflict, the Turkish version prevails.
27. Contact
Bilgi Teknoloji Danışmanlık Ticaret Limited Şirketi · İcadiye Mahallesi Ayarcıbaşı Sokak No:7/1 D:1 Bağlarbaşı 34674 Üsküdar, İstanbul · MERSIS no: 0172037093400017 · KEP: bilgiteknoloji@hs02.kep.tr
E-mail: destek@bilgiteknoloji.com.tr