EU / EEA compliance

GDPR Policy

Pitbull's data processing principles, your rights and request procedures under the EU General Data Protection Regulation (GDPR).

Legal & Compliance KVKK · GDPR
Data residencyTR
Log separationOK
AuditACTIVE
SLA99.99%
Art. 6
Legal basis
30 days
Request response target
DPA
Data processing agreement
72 hours
Breach notification target

1. Scope

This GDPR Policy applies to processing of personal data of individuals residing in the European Union or European Economic Area (EU/EEA) in connection with Pitbull Secure Gateway services. Pitbull may act as controller or processor depending on contract and data flow.

2. GDPR principles — how we apply them

PrinciplePitbull practice
Lawfulness, transparencyPrivacy Policy and this document
Purpose limitationData processed only for mail security, delivery, support and contract
Data minimizationEmail content not stored by default; metadata and logs time-limited
AccuracyAccount updates via panel
Storage limitationRetention per package and agreement
Integrity & confidentialityTLS, RBAC, masking, Tier III infrastructure
AccountabilityAudit log, DPA, sub-processor list on request

3. Legal bases (Article 6)

Contract performance, legal obligation, legitimate interest (abuse prevention, security monitoring — balanced in your favour), explicit consent for marketing (withdrawable anytime).

4. Data subject rights (Articles 12–23)

Access, rectification, erasure, restriction, portability, objection to legitimate-interest processing and direct marketing, and protection against solely automated decisions with legal effect. Submit requests via contact form with subject "GDPR Data Subject Request". Response target: 30 days.

5. International transfers (Chapter V)

Transfers outside EU/EEA use adequacy decisions, Standard Contractual Clauses or other appropriate safeguards. Production runs primarily in Turkey; mechanisms defined in contract and DPA for EU customers.

6. Sub-processors (Article 28)

Hosting, AV REST API, payment infrastructure bound by written agreement. Sub-processor list available to enterprise customers on request.

7. Breach notification (Articles 33–34)

Notification to supervisory authority within 72 hours where Pitbull is controller; data subjects informed when high risk; immediate customer notification when Pitbull is processor.

8. DPO

Where Article 37 DPO appointment is not mandatory, data protection responsibility lies with operations and security. Route all GDPR requests via contact channels above.

9. Right to complain

You may lodge a complaint with your EU/EEA supervisory authority. We encourage contacting us first.

Last updated: June 2026