Privacy Policy
Last Updated: 20 September 2026This Privacy Policy has been prepared by Önder Yazılım ("Company") to inform you about the purposes, legal grounds, collection methods and your rights regarding the processing of your personal data.
Email: info@onderyazilim.com
Website: https://onderyazilim.com
1. Collection of Personal Data
Your personal data is collected through the following channels:
- Contact Form: Your name, surname, email address and message content.
- Cookies: When you visit the website, your IP address, device information, browser type and site usage data via your browser.
- Email Correspondence: Personal information you provide directly via email.
- ZREST Installation Notification: a one-way notification sent by the browser after the SAP documentation page loads, containing the licence key (if any), server name, the service path that was opened, package version and notification time. Referrer, user-agent and client IP address are not collected. The server name and service path are stored encrypted.
2. Purposes of Processing Personal Data
The personal data collected is processed for the following purposes:
- Responding to your contact requests and managing customer relations
- Providing information about available services
- Analysing and improving website performance
- Fulfilling legal obligations
- Conducting statistical analyses (anonymously)
- Tracking ZREST installations and noticing unregistered or problematic licences (expired, host mismatch, etc.)
3. Sharing of Personal Data
Your personal data may be shared with the following third-party service providers:
| Service Provider | Purpose | Data Type |
|---|---|---|
| Google Analytics (GA4) | Website usage analysis | IP address, device info, usage data |
| Formspree | Contact form processing | Name, email, message |
| Google (Gmail SMTP) | ZREST install/issue alert — an automated email to the Company's own corporate inbox on events such as a new install, an unrecognised licence, a host mismatch or an expired licence | Server name, service path, licence key (if any), matched customer name (if any), package version and notification time. The email reaches only the Company; it is not forwarded to any other service provider. |
Your personal data is not shared with third parties other than the service providers listed above and is not used for commercial purposes.
4. Protection of Personal Data
Önder Yazılım takes the necessary technical and administrative measures to ensure the security of your personal data:
- The website is protected with SSL (HTTPS) encryption.
- Access to personal data is limited to authorised persons only.
- The privacy policies of third-party service providers are regularly evaluated.
5. Your Rights
You have the following rights regarding your personal data:
- The right to know whether your personal data is being processed
- The right to request information if your personal data has been processed
- The right to know the purpose of processing your personal data and whether it is used in accordance with that purpose
- The right to know the third parties to whom personal data is transferred domestically or abroad
- The right to request correction if your personal data is incomplete or inaccurately processed
- The right to request deletion or destruction of your personal data
- The right to object to a result arising against you through analysis of processed data exclusively via automated systems
- The right to claim compensation for damages in case your personal data is processed unlawfully
To exercise the above rights, contact info@onderyazilim.com. Your request will be finalised within 30 days at the latest.
6. Cookie Policy
The website uses cookies to improve user experience and analyse site performance.
6.1 Types of Cookies Used
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Theme and cookie-consent preferences | Persistent (localStorage) |
| Analytics Cookies | Google Analytics (GA4) - site usage statistics | 2 years |
6.2 Cookie Management
You can change your analytics preference at any time with the Change Cookie Preference button in the footer. When analytics is declined, Google Analytics storage is not permitted; the Google tag may send limited cookieless measurement signals. You can separately delete existing cookies in your browser settings.
7. Retention of ZREST Installation Notifications
When the ZREST documentation page loads on the SAP side, the browser sends the Company a one-way, non-blocking installation notification; its result never reaches the SAP side. ZREST does not collect or store the client IP address, referrer or user-agent in this notification. Records containing the licence key (if any), server name, service path opened, package version, notification time and licence-matching result are kept for 180 days; records beyond that period are deleted automatically during daily maintenance. If no notifications arrive for an extended period, maintenance runs with the next one. The server name and service path are stored with reversible encryption in the database; the index value used for search is derived with a separate key and cannot be reversed to the original value.
Repeat notifications from the same installation (the licence-and-server-name pair) do not create a new row; they update the existing record. This summary record is not deleted automatically after a fixed period.
When a new installation is observed, or an issue is detected (unrecognised licence, host mismatch, an expired/inactive/not-yet-valid licence, or the same licence seen on an unusually high number of servers), an automatic email is sent to the Company's own corporate inbox via Gmail SMTP. The email contains only the server name, service path, licence key (if any), matched customer name (if any), package version and the related counters; it is not forwarded to any third-party service provider.
Once a week, a weekly summary email that summarises the fields above (including server name, service path, licence key and matched customer name) is sent to the same inbox; it reaches only the Company. Emails may wait in an encrypted queue in the database before they are sent; once sent, their content is deleted from the database and only a row carrying the delivery status and date is kept for 90 days. The processing result of each notification (recorded, unreadable, quota reached, system error) is kept for 90 days only as a daily counter and a system error message.
8. Changes
This Privacy Policy may be updated from time to time in line with changes in legal regulations or company policies. The updated policy will be published on this page.