VENOXIS / LEGAL
Customer data-processing terms
Processor obligations for customer website data, completed with the project’s processing schedule.
Service provider and data controller
Özcan Hacımustafaoğlu – Mythra Craft
Seyrani Mah, Bekir Yıldız Blv, Bademaltı Sk, No: 162/A, 38040 Kocasinan/Kayseri, TürkiyeTax office / tax number: Gevher Nesibe / 4540344464
Contact and privacy requests
Use our contact form or write to the postal address above. For privacy requests, identify the request and your relationship with us. We may request proportionate verification through a secure channel; do not send passwords, card details or identity documents through the public form. Let’s talk
Updated: 2026-10-05
Roles and processing schedule
The customer controls the purposes and means of personal-data processing on its own website unless the parties document otherwise. Venoxis processes that data only on documented lawful instructions, while acting independently for its own account, billing and business records. Before processing begins, the parties complete and accept a schedule naming the customer/controller, service, duration, purposes, data categories, affected people, approved locations/providers, contact points and applicable transfer arrangement. This general page does not replace that schedule or a statutory transfer contract.
Instructions and confidentiality
Processing is limited to delivering the agreed service and the schedule, or a binding legal duty after notice where permitted. We notify the customer if an instruction appears to violate applicable data law. Personnel are bound to appropriate confidentiality and receive only necessary access. Data may not be used for unrelated advertising or sold. Special-category data, children’s data, payment-card data and regulated records require an expressly assessed scope and safeguards before acceptance.
Safeguards and subprocessors
We apply proportionate access controls, account security, transmission protection, restricted storage, operational logging and maintenance appropriate to the agreed risks. The schedule identifies authorized subprocessors and locations, including DigitalOcean infrastructure in New York where used. Material changes require the agreed notice/authorization and objection process; equivalent processing duties flow down to providers. International transfers need their own valid legal mechanism before they occur.
Incidents, rights and evidence
We notify the customer without undue delay after becoming aware of a personal-data breach affecting its data, share available facts and updates, and cooperate in mitigation. We assist proportionately with individual-rights requests, risk assessments and lawful regulator obligations; we do not answer customer-site requests independently unless instructed or required by law. We provide reasonable compliance evidence and agreed audits that protect other customers, secrets and service security. Statutory deadlines remain binding.
Return, deletion and precedence
At the end of the service, return or delete customer data as instructed, except legally required records. Residual backups remain restricted until scheduled expiry and are not reused for another purpose. The schedule identifies export formats, timing, backup handling and agreed assistance fees. Mandatory GDPR Article 28 clauses apply where GDPR governs the processing; approved transfer clauses prevail over conflicting text. The signed project arrangement, not an unrelated later CMS edit, determines the accepted version.