Privacy Policy
Last updated: 28 August 2026
This policy explains, under Turkish Personal Data Protection Law no. 6698, the purposes for which and the legal grounds on which your personal data is processed when you use Clodo services, and sets out your rights.
The role of data controller is held by the natural persons running the Clodo project. Once incorporation is complete, the controller's trade name, address and contact details will be published on this page and notified to registered users.
1. Personal data processed
The following data is processed when you use our services:
- Identity and contact data: full name, email address
- Account data: an irreversible digest of your password, account status, language and currency preference, notification preferences, country code
- Transaction security data: session records, the IP address used at registration and sign in, browser and device information, failed sign in attempts and their timestamps, two factor authentication status
- Support data: the content, attachments and history of the support tickets you open
- Service data: the services you create, plan information, period and status records
- Payment data: if charging begins, the order amount, its date and the transaction reference returned by the payment institution
2. Data that is not processed
Your password is never stored in plain form. Only an irreversible digest produced with the scrypt algorithm is kept. It is not possible for us to view your password.
Your card details never reach our servers at any stage and are not stored by us. If charging begins, payment transactions will be carried out through the infrastructure of a payment institution subject to the applicable regulations.
The content of the services you host is examined only upon a technical support request from you and only to the extent that request requires. Your content is not otherwise routinely viewed.
No data is collected for advertising, profiling or behavioural tracking purposes.
3. Purposes of processing
- Creating, verifying and managing your account
- Provisioning, maintaining and terminating the service you request
- Handling your support requests and allowing them to be reviewed later
- Ensuring account and infrastructure security, preventing unauthorised access and abuse
- Delivering mandatory service notices, outage and maintenance announcements
- Carrying out payment and invoicing processes if charging begins
- Fulfilling obligations arising from legislation and responding to duly issued requests from competent authorities
4. Legal grounds
Your data is processed under article 5 of the Law on the grounds of the establishment and performance of a contract, compliance with a legal obligation, and legitimate interest provided that your fundamental rights and freedoms are not harmed.
Keeping security records rests on the legitimate interest ground of preventing abuse.
If marketing messages are to be sent, your explicit consent is obtained separately and you may withdraw it at any time. Mandatory service notices do not fall within this scope.
5. Transfer of data
Your data is not shared with anyone other than the parties strictly necessary for providing the service, and is never sold or transferred for commercial purposes.
- Server and infrastructure provider DEHOST İnternet ve Bilişim Teknolojileri Sanayi Ticaret Limited Şirketi: for the purpose of providing the hosting service. The servers are located in Türkiye, Ankara, so your data is not transferred abroad in this respect
- Cloudflare, Inc.: for domain resolution, attack protection and traffic encryption. By the nature of the service, the IP address and technical headers of your requests pass through Cloudflare servers located abroad
- Electronic mail provider: for delivering verification, password reset and notification emails. Once a provider is selected, its name and country will be published in this section
- Competent public authorities: only in the cases prescribed by law, upon a duly issued request and within the limits of that request
6. Transfers abroad
Your account and service data is held on servers located in Türkiye.
However, because site traffic passes through Cloudflare infrastructure, your IP address and technical request information are processed abroad. This transfer is carried out under article 9 of the Law for the purpose of ensuring the security and availability of the service, and is limited to that purpose.
If you wish to avoid this transfer, it may not be technically possible for you to use the service. You may raise questions on this subject through the application route below.
7. Retention periods
- Account data: for as long as your account remains open
- Session records: expire after thirty days where the session was kept open, or twelve hours otherwise, and are deleted regularly
- Two factor authentication pending record: ten minutes
- Failed sign in attempt records: lose their meaning after the security window and are cleared regularly
- Support correspondence: for as long as your account remains open, deleted when the account is closed
- Traffic and transaction records required to be kept by law: for the statutory period
- Payment and invoice records: for the period prescribed by financial legislation
8. Cookies
Only cookies strictly necessary for the operation of the service are used on the site. No advertising, analytics or third party tracking cookies are used.
- clodo_session: keeps you signed in, strictly necessary, marked so that it cannot be read by scripts in the browser and sent only over an encrypted connection
- clodo_pending_login: used temporarily during two factor authentication, expires after ten minutes
- clodo-locale: remembers the language you selected
- clodo-currency: remembers the currency you selected
- clodo-theme and clodo-theme-resolved: remember your light or dark theme preference
9. Your rights
Under article 11 of the Law you have the following rights in relation to your personal data:
- To learn whether your personal data is processed
- To request information if it has been processed
- To learn the purpose of processing and whether the data is used in accordance with that purpose
- To know the third parties to whom the data is transferred, domestically or abroad
- To request rectification if the data is incomplete or inaccurate
- To request erasure or destruction where the conditions are met
- To request that rectification and erasure be notified to the third parties to whom the data was transferred
- To object to an adverse outcome produced by analysis through automated systems
- To claim compensation if you suffer damage due to unlawful processing
10. How to exercise your rights
You can download all of your data as a single file immediately, using the Download my data link on the Account page in your panel. This lets you exercise your right of access without waiting.
You can close your account from the same page. On closure your identity details are anonymised and your support correspondence is deleted; payment and order records that must be kept under financial legislation continue to be held in a form that cannot be associated with you.
Rectification, erasure and other requests can be submitted by opening a support ticket in the panel. This route allows us to verify that the request comes from your account.
Your request is concluded within thirty days at the latest from the date it reaches us. Where the process entails an additional cost, the fee set out in the tariff determined by the Board may be charged.
If your application is rejected or not answered within the period, you retain the right to lodge a complaint with the Personal Data Protection Board.
11. Security measures
- Passwords are stored as irreversible digests
- Session keys are not held in plain form in the database, only their digest is stored
- Site traffic is served over an encrypted connection
- Consecutive failed sign in attempts are rate limited
- Optional two factor authentication and recovery codes are offered
- You can view the open sessions on your account and end any of them
- Administrator actions are written to an audit log
- Server access is protected by key based authentication and restricted by a firewall
- Customer services run in containers isolated from one another
12. Data breach notification
If it is established that your personal data has been unlawfully obtained by others, the situation is reported to the Personal Data Protection Board and to the affected data subjects as soon as possible, under article 12 of the Law.
The notification clearly states the nature of the breach, the categories of data affected, the measures taken and the steps you can take.
13. Changes to this policy
This policy may be updated. The revision date appears at the top of the document.
Material changes affecting the purposes of processing, the parties to whom data is transferred or the retention periods are notified by email and through the panel before they take effect.

