Gizlilik Beyanı
Sürüm 1.0 · Yürürlük tarihi: 25 Eylül 2026
Bu Gizlilik Beyanı, bir müşteri Controlio Security'yi ("Hizmet") Microsoft ticari
mağazası üzerinden edindiğinde ve kullandığında Tworks Bilişim Hizmetleri Ticaret Ltd. Şti.
("Tworks") tarafından hangi verilerin toplandığını ve işlendiğini, bu verilerin nerede saklandığını,
nasıl korunduğunu ve müşterilerin ve kullanıcılarının hangi haklara sahip olduğunu açıklar. Yalnızca
Controlio Security'yi kapsar; Tworks'ün diğer ürünleri kendi beyanlarına tabidir.
01Kimiz
| Alan | Bilgi |
| Veri sorumlusu / hizmet sağlayıcı | TWORKS Bilişim Hizmetleri Ticaret Ltd. Şti. |
| Kayıtlı adres | Quasar İstanbul, Fulya Mah. Büyükdere Cad. No:76 Kat:1 İç Kapı No:104, 34394 Mecidiyeköy / Şişli / İstanbul, Türkiye |
| VKN / MERSİS | 8591464631 / 0859 1464 6310 0001 |
| Gizlilik iletişim | info@tworks.com.tr |
| KEP adresi | tworksbilisimhizmetleri@hs01.kep.tr |
| Microsoft ortaklığı | Microsoft Solutions Partner |
Rolümüz. Hizmet'i sunmak, güvenliğini sağlamak ve faturalandırmak için işlediğimiz
verilerde (hesap, iletişim, telemetri ve destek verisi) Tworks veri sorumlusudur.
Müşterinin Microsoft 365 ortamından türetilen değerlendirme sonuçlarında ise Tworks, veriyi müşteri
adına ve müşterinin talimatı doğrultusunda işler; müşteri kendi Microsoft 365 içeriğinin veri
sorumlusu olmaya devam eder.
02Hizmet ne yapar, kiracınıza nasıl bağlanır
Controlio Security, müşterinin Microsoft 365 ortamının güvenlik yapılandırmasını sürekli olarak
izler; bulguları ve önerileri müşteriye ayrılmış bir panelde sunar.
Salt okunur, uygulama düzeyinde erişim. Controlio, müşterinin Microsoft 365
kiracısına yalnızca uygulama düzeyinde (app-only) ve salt okunur izinlerle bağlanır. Müşteri
kiracısındaki hiçbir ayarı, posta kutusunu, dosyayı veya kullanıcıyı değiştiremez.
Müşteri içeriği kiracıda kalır. Controlio; e-postaları, belgeleri, sohbet
mesajlarını, dosyaları veya diğer son kullanıcı içeriğini kopyalamaz ve saklamaz. Yalnızca
değerlendirme sonuçları ve bunlardan türetilen yapılandırma verisi saklanır.
Onay bir kiracı yöneticisi tarafından verilir. Erişim, müşteri yöneticisinin
Microsoft Entra üzerinden verdiği yönetici onayıyla başlar ve müşteri tarafından Microsoft Entra
yönetim merkezinden istediği an geri alınabilir. Onay kaldırıldığında Controlio'nun kiracıyı okuma
imkânı derhâl sona erer.
03İşlediğimiz veriler
| Kategori | Örnekler | Kaynak |
| Kiracı ve hesap verisi | Microsoft Entra kiracı kimliği, kuruluş adı, abonelik ve plan tanımlayıcıları, mağaza satın alma tanımlayıcıları | Müşteri yöneticisi; Microsoft ticari mağazası |
| Yönetici kimlik verisi | Controlio paneline giriş yapan yöneticilerin adı, kurumsal e-posta adresi ve Entra nesne kimliği | Microsoft Entra oturum açma |
| Değerlendirme ve yapılandırma verisi | Müşterinin Microsoft 365 kiracısından salt okunur olarak okunan güvenlik duruşu bulguları, ilke ve yapılandırma durumu, bunlardan türetilen sayımlar ve puanlar (örneğin çok faktörlü kimlik doğrulama kapsamı, koşullu erişim durumu, paylaşım ayarları). Bu kapsamda, yalnızca yapılandırmayı tarif etmek için gereken ölçüde kullanıcı adı, e-posta adresi ve rol bilgisi işlenir. | Microsoft Graph ve Microsoft 365 API'leri (salt okunur) |
| Bildirim verisi | Müşterinin uyarıları almak için belirlediği e-posta adresleri ve Microsoft Teams kanal tanımlayıcıları | Müşteri yöneticisi |
| İşletimsel telemetri ve günlükler | İstek kayıtları, tanılama olayları, hata izleri, panele erişimin IP adresi ve zaman damgası | Otomatik olarak üretilir |
| Destek ve iletişim verisi | Destek taleplerinin içeriği, yazışmalar ve toplantı notları | Müşteri |
Controlio özel nitelikli kişisel veri (sağlık, biyometrik, dinî ve benzeri) işlemez;
son kullanıcıları profillemez ve hukuki sonuç doğuran otomatik karar üretmez.
04Amaçlar ve hukuki dayanak
- Hizmet'in sunulması — değerlendirmelerin çalıştırılması, bulguların sunulması, uyarıların gönderilmesi (sözleşmenin ifası; KVKK m.5/2-c, GDPR m.6/1-b).
- Güvenlik, erişilebilirlik ve olay müdahalesi — Hizmet'in ve verisinin güvende tutulması (meşru menfaat; KVKK m.5/2-f, GDPR m.6/1-f).
- Faturalandırma ve hesap yönetimi — Microsoft ticari mağazası üzerinden tamamlanan işlemler dâhil (sözleşme ve hukuki yükümlülük; KVKK m.5/2-c ve ç).
- Destek ve iletişim — taleplere yanıt verilmesi ve hizmet değişikliklerinin bildirilmesi (sözleşme; meşru menfaat).
Kişisel veriyi satmayız, reklam amacıyla kullanmayız ve müşteri verisini üçüncü
taraflar için model eğitiminde kullanmayız.
05Verinizin bulunduğu yer
Controlio Security'nin tüm üretim altyapısı, Microsoft Azure üzerinde ve Avrupa Birliği
sınırları içinde çalışır.
| Veri / bileşen | Birincil bölge | İkincil / yedek |
| Veritabanları, API'ler, anahtar yönetimi, depolama | Kuzey Avrupa (İrlanda) | Batı Avrupa (Hollanda) — coğrafi yedek kopyalar |
| Müşteri paneli (statik web barındırma) | Batı Avrupa (Hollanda) | — |
| İşletimsel günlükler ve tanılama | Kuzey Avrupa (İrlanda) | — |
| E-posta ve Teams bildirim hizmetleri | Avrupa (Azure Communication Services veri konumu: Avrupa) | — |
Türkiye'de yerleşik müşteriler için: işleme İrlanda ve Hollanda'da gerçekleştiği
için Hizmet, KVKK'nın 9. maddesi anlamında yurt dışına aktarım içerir. Tworks bu
aktarımı, müşteri sözleşmesinde ve ekindeki Veri İşleme Eki'nde belirlenen aktarım mekanizmasına
dayandırır; müşteriler Hizmet etkinleştirilmeden önce bu aktarımdan haberdar edilir.
AB/AEA'da yerleşik müşteriler için: veri AB/AEA içinde kalır. Tworks, Türkiye'de
kurulu bir şirket olarak bu veriye yönetim ve destek amacıyla Türkiye'den erişir; bu erişim, müşteri
sözleşmesi ve Veri İşleme Eki'ne dâhil edilen Standart Sözleşme Hükümleri ile düzenlenir.
06Alt işleyenler
Tworks, Hizmet'i barındırmak ve işletmek için aşağıdaki alt işleyeni kullanır. Hukuken zorunlu
olmadıkça veya müşteri açıkça yetkilendirmedikçe başka hiçbir üçüncü taraf müşteri verisi almaz.
| Alt işleyen | Amaç | Konum / dayanak |
| Microsoft Ireland Operations Limited (Microsoft Azure) | Bulut barındırma: veritabanı, işlem, depolama, anahtar yönetimi, günlük kaydı, e-posta ve Teams bildirim hizmetleri | İrlanda ve Hollanda; Microsoft Products and Services Data Protection Addendum; Microsoft'un kendi alt işleyenleri aka.ms/subprocessors adresinde yayımlanır |
Alt işleyen eklenmesi veya değiştirilmesi hâlinde müşteriler, değişiklik yürürlüğe girmeden önce
bilgilendirilir.
07Güvenlik önlemleri
- İletimde şifreleme: tüm uç noktalarda HTTPS zorunludur; asgari TLS sürümü 1.2'dir.
- Durağan hâlde şifreleme: tüm Azure veritabanları ve depolama hesapları, Microsoft tarafından yönetilen anahtarlarla şifrelenir.
- Sır yönetimi: bağlantı dizeleri, sertifikalar ve API anahtarları Azure Key Vault'ta tutulur; kaynak kodunda veya yapılandırma dosyalarında saklanmaz.
- Ağ izolasyonu: depolama hesaplarında genel (anonim) erişim kapalıdır; bildirim bileşenleri sanal ağ içinde ve özel uç noktalar arkasında çalışır.
- En az yetki: müşteri kiracılarına yalnızca salt okunur uygulama izinleriyle erişilir; son kullanıcı içeriğine etkileşimli veya kullanıcı adına (delegated) erişim kullanılmaz.
- Yedekleme: yedi günlük kurtarma penceresini kapsayan sürekli ve periyodik veritabanı yedeklemesi; yedekleme sağlığı ve kimlik doğrulama değişiklikleri için otomatik uyarı.
- Erişim yönetimi: üretim ortamına erişim, gizlilik yükümlülüğü altındaki yetkili Tworks personeliyle sınırlıdır.
08Saklama
| Veri | Saklama süresi |
| Değerlendirme ve yapılandırma verisi | Abonelik süresince; sona ermeden veya yazılı talepten sonra 30 gün içinde silinir |
| Kiracı, hesap ve yönetici verisi | Abonelik süresi ve Türk ticaret ve vergi mevzuatının gerektirdiği süre (yalnızca fatura kayıtları için 10 yıla kadar) |
| İşletimsel günlükler ve tanılama | 90 gün |
| Veritabanı yedekleri | 7 günlük döngü; süre sonunda üzerine yazılır |
| Destek yazışmaları | Talebin kapanmasından 3 yıl sonra |
Müşteri, Controlio'nun erişimini Microsoft Entra'dan kaldırdığında kiracıdan başka veri okunmaz.
Saklanan değerlendirme verisi yukarıdaki takvime göre silinir.
09Haklarınız
Müşteriler ve kullanıcıları, ilgili mevzuat çerçevesinde Tworks'ten kişisel verilerinin işlenip
işlenmediğini öğrenmeyi, bunlara erişmeyi, düzeltilmesini veya silinmesini istemeyi, işlemeye itiraz
etmeyi, işlemenin kısıtlanmasını talep etmeyi ve uygun hâllerde veriyi taşınabilir bir biçimde almayı
talep edebilir. KVKK'nın 11. maddesi uyarınca ilgili kişiler ayrıca verinin aktarıldığı üçüncü kişileri
öğrenme ve hukuka aykırı işleme nedeniyle uğradıkları zararın giderilmesini talep etme hakkına
sahiptir.
Talepler info@tworks.com.tr adresine veya Türkiye'de hukuken bağlayıcı bildirimler
için tworksbilisimhizmetleri@hs01.kep.tr KEP adresine iletilebilir. Taleplere 30 gün
içinde yanıt veririz. Türkiye'deki ilgili kişiler Kişisel Verileri Koruma Kurumu'na şikâyette
bulunabilir; AB/AEA'daki ilgili kişiler kendi ulusal denetim makamlarına başvurabilir. Talep, bir
müşteri adına işlediğimiz bir veriye ilişkinse talebi ilgili müşteriye yönlendirir ve gereken desteği
veririz.
10Microsoft'un mağaza işlemindeki rolü
Hizmet, Microsoft ticari mağazası üzerinden satın alındığında Microsoft; işlemin tamamlanması için
gereken satın alma, faturalandırma ve hesap bilgilerini kendi gizlilik beyanı kapsamında toplar ve
işler. Microsoft, aboneliğin sağlanabilmesi ve desteklenebilmesi için sınırlı alıcı bilgilerini
(kuruluş adı, iletişim ve abonelik tanımlayıcıları gibi) Tworks ile paylaşır. Tworks bu bilgiyi
yalnızca bu amaçla işler.
11Veri İşleme Eki
Bu beyan, müşteri sözleşmesinin ayrılmaz parçası olan Veri İşleme Eki'ne atıfta
bulunur. Ek; tarafların rollerini, işlemenin konusunu, veri ihlali bildirim süresini, alt işleyen
değişikliği usulünü, denetim hakkını, aktarım mekanizmasını ve uygulanan teknik ve idari tedbirleri
düzenler. Veri İşleme Eki'nin bir örneği info@tworks.com.tr adresinden talep
edilebilir.
12Bu beyandaki değişiklikler
Bu beyanı, Hizmet'teki veya ilgili mevzuattaki değişiklikleri yansıtmak için güncelleyebiliriz.
Güncel sürüm, yürürlük tarihi ve esaslı değişikliklerin özeti her zaman mağaza listesinde ve Controlio
panelinde gösterilen gizlilik bağlantısında yayımlanır. Esaslı değişiklikler, yürürlüğe girmeden en az
15 gün önce müşteri yöneticilerine e-posta ile bildirilir.
13İletişim
TWORKS Bilişim Hizmetleri Ticaret Ltd. Şti.
Quasar İstanbul, Fulya Mah. Büyükdere Cad. No:76 Kat:1 İç Kapı No:104
34394 Şişli / İstanbul, Türkiye
E-posta: info@tworks.com.tr
KEP: tworksbilisimhizmetleri@hs01.kep.tr
Privacy Statement
Version 1.0 · Effective date: 25 September 2026
This Privacy Statement explains what data Tworks Bilişim Hizmetleri Ticaret Ltd. Şti.
("Tworks", "we", "us") collects and processes when a customer acquires and uses
Controlio Security (the "Service") through the Microsoft commercial marketplace, where
that data is stored, how it is protected and what rights customers and their users have. It covers
Controlio Security only; other Tworks products are subject to their own notices.
01Who we are
| Field | Detail |
| Data controller / service provider | TWORKS Bilişim Hizmetleri Ticaret Ltd. Şti. |
| Registered address | Quasar İstanbul, Fulya Mah. Büyükdere Cad. No:76 Kat:1 İç Kapı No:104, 34394 Mecidiyeköy / Şişli / İstanbul, Türkiye |
| Tax ID (VKN) / MERSİS | 8591464631 / 0859 1464 6310 0001 |
| Privacy contact | info@tworks.com.tr |
| Registered electronic mail (KEP) | tworksbilisimhizmetleri@hs01.kep.tr |
| Microsoft partnership | Microsoft Solutions Partner |
Role. For the data we process to provide, secure and bill the Service (account,
contact, telemetry and support data), Tworks acts as data controller. For assessment
results derived from a customer's Microsoft 365 environment, Tworks processes data on the customer's
behalf and on the customer's instructions, and the customer remains the controller of its own
Microsoft 365 content.
02What the Service does and how it connects to your tenant
Controlio Security continuously monitors the security configuration of a customer's Microsoft 365
environment and presents findings and recommendations in a customer portal.
Read-only, application-level access. Controlio connects to the customer's
Microsoft 365 tenant with app-only (application) permissions that are read-only. It cannot modify
settings, mailboxes, files or users in the customer tenant.
Customer content stays in the customer tenant. Controlio does not copy or store
e-mails, documents, chat messages, files or other end-user content. Only the assessment results and
derived configuration data are stored.
Consent by a tenant administrator. Access is granted by a customer administrator
through Microsoft Entra admin consent and can be revoked by the customer at any time from the
Microsoft Entra admin center, which immediately ends Controlio's ability to read the tenant.
03Data we collect and process
| Category | Examples | Source |
| Tenant and account data | Microsoft Entra tenant ID, organization name, subscription and plan identifiers, Marketplace purchase identifiers | Customer administrator; Microsoft Marketplace |
| Administrator identity | Name, business e-mail and Entra object ID of the administrator(s) who sign in to the Controlio portal | Microsoft Entra sign-in |
| Assessment and configuration data | Security posture findings, policy and configuration state, counts and scores derived from the customer's Microsoft 365 tenant (e.g. MFA coverage, conditional-access state, sharing settings). This includes user names, e-mail addresses and role information only to the extent needed to describe the configuration. | Microsoft Graph and Microsoft 365 APIs (read-only) |
| Notification data | E-mail addresses and Teams channel identifiers chosen by the customer to receive alerts | Customer administrator |
| Operational telemetry and logs | Request logs, diagnostic events, error traces, IP address and timestamp of portal access | Automatically generated |
| Support and communication data | Content of support requests, correspondence and meeting notes | Customer |
Controlio does not process special categories of personal data (health, biometric,
religious or similar data) and does not perform profiling of end users or automated decision-making
producing legal effects.
04Purposes and legal basis
- Providing the Service — running assessments, presenting findings, sending alerts (performance of the contract; KVKK Art. 5(2)(c), GDPR Art. 6(1)(b)).
- Security, availability and incident response — keeping the Service and its data safe (legitimate interest; KVKK Art. 5(2)(f), GDPR Art. 6(1)(f)).
- Billing and account administration — including transactions completed through the Microsoft commercial marketplace (contract and legal obligation; KVKK Art. 5(2)(c) and (ç)).
- Support and communication — responding to requests and notifying customers of service changes (contract; legitimate interest).
We do not sell personal data, use it for advertising or use customer data to train
models for third parties.
05Where your data is stored
All Controlio Security production infrastructure runs on Microsoft Azure within the
European Union.
| Data / component | Primary region | Secondary / backup |
| Databases, APIs, key management, storage | North Europe (Ireland) | Geo-redundant copies in West Europe (Netherlands) |
| Customer portal (static web hosting) | West Europe (Netherlands) | — |
| Operational logs and diagnostics | North Europe (Ireland) | — |
| E-mail and Teams notification services | Europe (Azure Communication Services data location: Europe) | — |
For customers established in Türkiye: because processing takes place in Ireland and
the Netherlands, the Service involves a transfer of personal data abroad within the
meaning of Article 9 of the Turkish Personal Data Protection Law (KVKK). Tworks relies on the transfer
mechanism set out in the customer agreement and the accompanying Data Processing Addendum, and
customers are informed of this transfer before the Service is enabled.
For customers established in the EU/EEA: data remains within the EU/EEA. Tworks, as
a Turkish entity, accesses that data for administration and support from Türkiye; this access is
governed by the customer agreement and the Standard Contractual Clauses incorporated in the Data
Processing Addendum.
06Sub-processors
Tworks uses the following sub-processor to host and operate the Service. No other third party
receives customer data unless required by law or expressly authorized by the customer.
| Sub-processor | Purpose | Location / terms |
| Microsoft Ireland Operations Limited (Microsoft Azure) | Cloud hosting: database, compute, storage, key management, logging, e-mail and Teams notification services | Ireland and Netherlands; Microsoft Products and Services Data Protection Addendum; Microsoft's own sub-processors are listed at aka.ms/subprocessors |
Customers will be notified of any addition or replacement of sub-processors before the change takes
effect.
07Security measures
- Encryption in transit: HTTPS is enforced on all endpoints; minimum TLS version 1.2.
- Encryption at rest: all Azure databases and storage accounts are encrypted at rest using Microsoft-managed keys.
- Secrets and credentials are held in Azure Key Vault; no credentials are stored in code or configuration files.
- Network isolation: public blob access is disabled on all storage accounts; notification components run behind a virtual network with private endpoints.
- Least privilege: read-only application permissions to customer tenants; no interactive or delegated access to end-user content.
- Backups: continuous and periodic database backups with a seven-day recovery window; automated backup-health and authentication-change alerting.
- Access management: access to production is restricted to authorised Tworks personnel bound by confidentiality obligations.
08Retention
| Data | Retention period |
| Assessment and configuration data | For the subscription term; deleted within 30 days after termination or on written request |
| Tenant, account and administrator data | For the subscription term plus the period required by Turkish commercial and tax law (up to 10 years for invoicing records only) |
| Operational logs and diagnostics | 90 days |
| Database backups | 7-day rolling window; backups are then overwritten |
| Support correspondence | 3 years after closure of the request |
When a customer revokes Controlio's access in Microsoft Entra, no further data is read from the
tenant. Stored assessment data is deleted according to the schedule above.
09Your rights
Customers and their users may, subject to applicable law, ask Tworks to confirm whether their
personal data is processed, obtain access to it, request correction or deletion, object to processing,
request restriction and, where applicable, receive the data in a portable format. Under KVKK Article 11
data subjects also have the right to learn the third parties to whom data has been transferred and to
claim compensation for damage caused by unlawful processing.
Requests may be sent to info@tworks.com.tr or, for legally binding notices in
Türkiye, to tworksbilisimhizmetleri@hs01.kep.tr. We respond within 30 days. Data
subjects in Türkiye may lodge a complaint with the Personal Data Protection Authority (KVKK); data
subjects in the EU/EEA may contact their national supervisory authority. Where a request concerns data
we process on a customer's behalf, we will refer the request to that customer and assist as needed.
10Microsoft's role in the Marketplace transaction
When the Service is purchased through the Microsoft commercial marketplace, Microsoft collects and
processes the purchase, billing and account information required to complete the transaction under its
own privacy statement. Microsoft shares limited purchaser details (such as organization name, contact
and subscription identifiers) with Tworks so that the subscription can be provisioned and supported.
Tworks processes this information only for that purpose.
11Data Processing Addendum
This statement refers to the Data Processing Addendum, which forms an integral part
of the customer agreement. The Addendum sets out the roles of the parties, the subject matter of the
processing, the data-breach notification deadline, the sub-processor change procedure, the audit right,
the transfer mechanism and the technical and organisational measures applied. A copy of the Data
Processing Addendum can be requested at info@tworks.com.tr.
12Changes to this statement
We may update this statement to reflect changes in the Service or in applicable law. The current
version, its effective date and a summary of material changes will always be published at the privacy
link shown in the Marketplace listing and in the Controlio portal. Material changes will be notified to
customer administrators by e-mail at least 15 days before they take effect.
13Contact
TWORKS Bilişim Hizmetleri Ticaret Ltd. Şti.
Quasar İstanbul, Fulya Mah. Büyükdere Cad. No:76 Kat:1 İç Kapı No:104
34394 Şişli / İstanbul, Türkiye
E-mail: info@tworks.com.tr
KEP: tworksbilisimhizmetleri@hs01.kep.tr