Data Controller Information, In-Browser Processing Principles, and Data Subject Rights
Legal Entity: CERİLAS Yüksek Teknoloji San. ve Tic. AŞ • Contact: [email protected] • Effective: September 2026
1. Data Controller Identification (KVKK & GDPR)
Pursuant to the Turkish Law on the Protection of Personal Data No. 6698 ("KVKK") and the General Data Protection Regulation ("GDPR") of the European Union, the Data Controller responsible for your personal data is:
Company: CERİLAS Yüksek Teknoloji San. ve Tic. AŞ
Tax Identification Number (VKN): 2061561435
Headquarters: Gaziantep, Türkiye
Legal & Privacy Inquiries: [email protected]
Corporate Website: https://cerilas.com
2. In-Browser Local Processing Architecture
The defining architectural principle of Cerilas Tools is Client-Side Privacy:
• Zero Server Document Uploads: When you compress an image, merge PDF documents, split PDF pages, edit PDF text, remove backgrounds, or calculate mathematical models, the raw binary files are loaded into your device's random-access memory (RAM) and processed entirely via client-side WebAssembly and HTML5 Canvas.
• Temporary Memory Lifecycle: The moment you close the browser tab or refresh the page, the memory allocations are immediately freed by your browser engine. Cerilas does not inspect, copy, intercept, or transmit the contents of your processed files to external servers.
3. Categories of Data Collected
We only collect and process personal data when strictly necessary to deliver, bill, and protect our services:
a) Account & Identity Information (For Registered / Pro Users):
• Email address, full name, company name (if applicable), and encrypted password hashes.
b) Billing & Transactional Information (For Paid Tiers):
• Order history, subscription tier, billing address, tax identification number, and masked card identifiers (last 4 digits). Note: Full credit card numbers, CVVs, and banking credentials are processed directly by certified payment processors (e.g. Stripe, Iyzico) and never touch our servers.
c) Technical & Usage Telemetry:
• Client IP address, browser type, operating system, timestamp of requests, and anonymous telemetry required to distinguish human visitors from automated malicious scrapers (bot vs human detection).
d) Customer Support Communications:
• Information submitted when emailing [email protected] or [email protected] regarding inquiries, refunds, or technical support.
Your personal data is processed under the following lawful bases:
• Performance of a Contract (KVKK Art. 5/2-c, GDPR Art. 6/1-b): Fulfilling subscription orders, delivering account management, and providing user support.
• Compliance with Legal Obligations (KVKK Art. 5/2-ç, GDPR Art. 6/1-c): Retaining accounting, financial transaction records, and tax documentation in compliance with Turkish Tax Procedure Law and relevant commercial codes.
• Legitimate Interests (KVKK Art. 5/2-f, GDPR Art. 6/1-f): Ensuring cybersecurity, preventing payment fraud, distinguishing web bots from legitimate traffic, and maintaining platform uptime.
• Explicit Consent (KVKK Art. 5/1, GDPR Art. 6/1-a): Where specifically requested, such as for voluntary newsletter communications.
5. Third-Party Data Transfers & Infrastructure
Cerilas does not sell, rent, or monetize your personal data. Data is shared exclusively with necessary infrastructure and operational vendors under strict data processing agreements:
• Cloud Infrastructure: PostgreSQL and server instances deployed on secure, ISO 27001-certified cloud infrastructure.
• Payment Gateways: Certified PCI-DSS Level 1 compliant processors for recurring billing and subscription invoicing.
• Statutory Authorities: Competent judicial, regulatory, or tax authorities when mandated by Turkish court orders or statutory reporting laws.
6. Your Rights under KVKK Art. 11 & GDPR
Under Article 11 of the KVKK and Chapter III of GDPR, you hold the legal right to:
1. Learn whether your personal data is processed;
2. Request information regarding the processing of your data;
3. Learn the purpose of data processing and whether it is used in line with that purpose;
4. Know the domestic or foreign third parties to whom your data has been transferred;
5. Request rectification of incomplete or inaccurate personal data;
6. Request the deletion or destruction of your personal data pursuant to statutory retention guidelines;
7. Object to the occurrence of any adverse result against you resulting solely from automated analysis systems;
8. Claim compensation for damages incurred as a consequence of unlawful data processing.
To exercise any of these rights, submit a written inquiry specifying your request to [email protected].