Products
Pitbull Secure Gateway Advanced Threat & Quarantine Outbound Filtering Smarthost SMTP Relay Features Release Notes Platform Security AnalysisSolutions
Hosting & ISP Banks & Financial Services Universities & Education ESP & High Volume Enterprise IT MSP & Reseller All Solutions CompatibilityCompany
About Us Why Pitbull? Contact Our Data Center Roadmap Compare Privacy Policy Terms of Use Service Level Agreement KVKK Policy GDPR PolicyThis GDPR Policy applies to processing of personal data of individuals residing in the European Union or European Economic Area (EU/EEA) in connection with Pitbull Secure Gateway services. Pitbull may act as controller or processor depending on contract and data flow.
| Principle | Pitbull practice |
|---|---|
| Lawfulness, transparency | Privacy Policy and this document |
| Purpose limitation | Data processed only for mail security, delivery, support and contract |
| Data minimization | Email content not stored by default; metadata and logs time-limited |
| Accuracy | Account updates via panel |
| Storage limitation | Retention per package and agreement |
| Integrity & confidentiality | TLS, RBAC, masking, Tier III infrastructure |
| Accountability | Audit log, DPA, sub-processor list on request |
Contract performance, legal obligation, legitimate interest (abuse prevention, security monitoring — balanced in your favour), explicit consent for marketing (withdrawable anytime).
Access, rectification, erasure, restriction, portability, objection to legitimate-interest processing and direct marketing, and protection against solely automated decisions with legal effect. Submit requests via contact form with subject "GDPR Data Subject Request". Response target: 30 days.
Transfers outside EU/EEA use adequacy decisions, Standard Contractual Clauses or other appropriate safeguards. Production runs primarily in Turkey; mechanisms defined in contract and DPA for EU customers.
Hosting, AV REST API, payment infrastructure bound by written agreement. Sub-processor list available to enterprise customers on request.
Notification to supervisory authority within 72 hours where Pitbull is controller; data subjects informed when high risk; immediate customer notification when Pitbull is processor.
Where Article 37 DPO appointment is not mandatory, data protection responsibility lies with operations and security. Route all GDPR requests via contact channels above.
You may lodge a complaint with your EU/EEA supervisory authority. We encourage contacting us first.
Last updated: June 2026