Legal

GDPR & Data Protection

How Narvinprotects personal data under the EU GDPR, the UK GDPR, and Türkiye’s Personal Data Protection Law (KVKK) — your rights, the lawful bases we rely on, the subprocessors we use, and how we respond to requests from public authorities.

Last updated
June 18, 2026
Operated by
PİXİR YAZILIM DANIŞMANLIK PAZARLAMA LTD. ŞTİ.
01

Our commitment

PİXİR YAZILIM DANIŞMANLIK PAZARLAMA LTD. ŞTİ. builds Narvin, an uptime, performance, and domain monitoring service. We are committed to protecting personal data in line with the EU General Data Protection Regulation (GDPR), the UK GDPR, and Türkiye’s Personal Data Protection Law (KVKK).

This page summarizes our data-protection commitments and how we respond to requests from public authorities. For the full detail of what we collect, why, and how long we keep it, see our Privacy Policy.

02

Data controller & contact

PİXİR YAZILIM DANIŞMANLIK PAZARLAMA LTD. ŞTİ. is the data controller for personal data processed through the Service. You can reach our data protection contact at privacy@narvin.io or by post at Kızılırmak Mah. Dumlupınar Blv. No: 3C1 - 160, 06530 Çankaya / Ankara, Türkiye.

If you are in the EEA or the UK and we cannot resolve your concern, you also have the right to lodge a complaint with your local data protection supervisory authority.

03

Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Eraseyour data (“right to be forgotten”).
  • Restrict or object to certain processing.
  • Port your data to another provider in a machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with a supervisory authority.

You can exercise many of these directly in the app, or email privacy@narvin.io. We respond within the time required by law (generally one month under the GDPR). See also How to delete your data.

05

International data transfers

PİXİR YAZILIM DANIŞMANLIK PAZARLAMA LTD. ŞTİ.is based in Türkiye, and we and our subprocessors may process personal data in countries outside your own, including outside the EEA. Where we transfer personal data across borders, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses — to protect it in accordance with applicable law.

06

Subprocessors

We use a limited set of subprocessors to operate and grow the Service. The categories are:

  • Cloud hosting and database providers.
  • Payment processing.
  • Email and message delivery, including Meta’s WhatsApp Business Platform and the other alert channels you enable.
  • Analytics and advertising measurement (such as Google Ads) on our marketing site.

Each subprocessor is bound by a data processing agreement and processes data only on our instructions. We can provide the current list on request at privacy@narvin.io.

07

Government & law-enforcement requests

From time to time, a government body or law-enforcement agency may request personal data about our users. We treat these requests seriously and handle every one under the following process:

  • Legality review. Every request from a public authority is reviewed before any disclosure. We verify that it comes from a legitimate authority, is properly served, and has a valid legal basis under applicable law (including KVKK and, where relevant, the GDPR). Requests are handled by our data protection contact, privacy@narvin.io.
  • Challenging unlawful requests. If a request appears overly broad, lacks a valid legal basis, or is otherwise unlawful, we push back — seeking to narrow or clarify it, and challenging it through the appropriate legal channels, including legal counsel where appropriate — before disclosing anything.
  • Data minimization. We disclose only the minimum personal data strictly required to satisfy a valid request, and nothing beyond its scope.
  • Documentation. We log each request and our response, including the requesting authority, date, the legal basis cited, our legal reasoning, the data disclosed (if any), and the people involved in handling it. Records are retained for accountability.
  • User notification. Where we are legally permitted to do so, we notify affected users of a request for their data.

We disclose personal data to public authorities only where we are legally required to do so, and only to the extent required.

08

Get in touch

For any data-protection question or to exercise your rights, contact us:

PİXİR YAZILIM DANIŞMANLIK PAZARLAMA LTD. ŞTİ.

Address
Kızılırmak Mah. Dumlupınar Blv. No: 3C1 - 160, 06530 Çankaya / Ankara, Türkiye