Privacy policy
Last updated: September 4, 2026 · Effective
PROCUX Teknoloji Anonim Şirketi, trading as Paycux, is the controller for personal data it collects about visitors, account holders and business contacts through paycux.com and the Paycux platform. This policy explains what we process and the choices available to you.
Controller and contact details
PROCUX Teknoloji Anonim Şirketi, Çağış Mah. Çağış 15. Sk., Balıkesir Teknokent No: 2 İç Kapı No: 39, Bigadiç, Balıkesir, Türkiye. MERSİS: 0733122829700001; trade registry: 23482; tax number: 7331228297. Privacy requests may be sent to [email protected].
Data we collect
- Account and identity data, such as name, verified email, workspace membership, role and authentication identifiers.
- Business and support data, such as organisation name, messages, requests and correspondence.
- Service configuration and usage data, including projects, environments, catalog and entitlement configuration, usage events and audit records.
- Technical and security data, such as IP address, device and browser information, timestamps, request identifiers and security events.
- Billing-contact and subscription data. Paddle independently collects and processes payment-card, tax and transaction information as merchant of record; Paycux does not store full card details.
Purposes and legal bases
- To create accounts, authenticate users, provide the platform and administer subscriptions — performance of a contract and steps requested before a contract.
- To protect accounts, prevent abuse, investigate incidents and maintain auditability — our legitimate interests in operating a secure and reliable service and, where applicable, legal obligations.
- To answer support, sales and privacy requests — performance of a contract or our legitimate interest in communicating with users and prospective customers.
- To maintain financial, tax and corporate records and respond to lawful requests — compliance with legal obligations.
- To send optional marketing or use non-essential cookies — consent where required; consent may be withdrawn at any time.
Who receives data
We disclose only what is reasonably necessary to:
- Infrastructure, identity, email, monitoring and other service providers listed on our subprocessors page.
- Paddle, acting independently as merchant of record and controller for the sale, subscription management, payments, tax compliance and invoicing of Paycux plans.
- Professional advisers, auditors, insurers and financial institutions where needed for legitimate business or legal purposes.
- Courts, regulators, law enforcement or other authorities where disclosure is legally required or necessary to protect rights and safety.
- A successor in a merger, acquisition or reorganisation, subject to appropriate confidentiality and legal safeguards.
Paycux does not sell or rent personal data for third-party advertising.
International transfers
Some providers may process data outside Türkiye, the EEA or the UK. Where applicable, we use an adequacy decision, standard contractual clauses, an international data transfer agreement, or another lawful safeguard, together with technical and organisational controls appropriate to the transfer.
Retention
We keep account and service data while the account is active and for the limited period needed to provide export, resolve disputes, prevent fraud and meet contractual or legal duties after closure. Security, billing, tax and audit records may be retained for longer where law or a legitimate compliance need requires it. When data is no longer needed, it is deleted or irreversibly anonymised; backup copies expire through the normal backup lifecycle.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction or portability of personal data, object to processing, and withdraw consent without affecting earlier lawful processing. Send requests to [email protected]. We may need to verify your identity and normally respond to GDPR requests within one month, subject to lawful extensions. You may also complain to the Turkish Personal Data Protection Authority or the competent supervisory authority where you live.
Security
We use appropriate technical and organisational safeguards, including encryption in transit, access controls, tenant isolation, secret management, logging and security monitoring. No internet service is risk-free; suspected security issues should be reported to [email protected].
Changes
We may update this policy to reflect changes in the Service, providers or law. Material changes will be posted here with a new effective date and additional notice where required.