Sub-processors
Current list of sub-processors that access personal data to operate iştebu! services. The list may be updated; changes take effect on publication.
This English page is a support translation. The Turkish text prevails in case of inconsistency.
This page lists the sub-processors that access personal data to operate iştebu! services,
together with the applicable KVKK Article 9 cross-border transfer mechanism. The machine-readable
source of truth is compliance/legal-registry.yml.
The list may change. When a new sub-processor is added or a mechanism is updated, the change takes effect on publication of this page; we do not provide advance notice. Read this table together with the KVKK Disclosure Notice and Privacy Policy.
| Sub-processor | Purpose | Country | Transfer mechanism | Retention |
|---|---|---|---|---|
| Hetzner Online GmbH | Hosting | Germany | In progress (safeguard pending) | Active service period plus 30-day infrastructure backup rotation. |
| Cloudflare Inc. | CDN, security, and caching | United States | In progress (safeguard pending) | 30 days for edge logs unless security events require longer retention. |
| Cloudflare R2 | Object storage and backups | United States | In progress (safeguard pending) | Public uploads remain until replaced or deleted; uncommitted support-image uploads expire after one day; committed private support images follow their support thread's active-customer-plus-2-years period but are destroyed through a durable retry queue when account erasure is processed; private database backups rotate after 30 days. |
| Google Workspace | Business email | United States | In progress (safeguard pending) | Support and privacy request emails are retained according to the related request type; billing and legal messages may be retained up to 10 years. |
| Google LLC (Firebase Cloud Messaging) | native_push_delivery | United States/global infrastructure | In progress (safeguard pending) | Firebase retains Firebase installation IDs until the customer invokes the provider deletion API; after that call, Firebase states that the data is removed from live and backup systems within 180 days. A pending message is retained only for its configured delivery TTL (currently one hour for the capability test). |
| Sentry | Error monitoring and session replay | United States | In progress (safeguard pending) | 90 days for error and replay diagnostics. |
| Healthchecks.io | Cron and backup monitoring | Latvia | In progress (safeguard pending) | Check and account data remain for the active service account; deleted data may remain in provider database backups for up to 2 months. |
| Microsoft Clarity | Analytics and session replay (optional) | United States | In progress (safeguard pending) | 13 months for analytics recordings and heatmap data. |
| Vatansms | Transactional SMS (OTP / notifications) | Turkey | Domestic (no transfer) | 10 years for legal/accounting message records. |
| Paraşüt (Paraşüt Yazılım Teknolojileri A.Ş.) | E-invoicing and accounting | Turkey | Domestic (no transfer) | 10 years for invoice and accounting records. |
| Meta Platforms Ireland Ltd. (WhatsApp) | inbound_messaging | Ireland/United States | In progress (safeguard pending) | 1 year for user-initiated inbound sales inquiry conversations. |
| Capawesome Cloud (Genz IT Solutions GmbH) | mobile_live_updates | Germany/United States | In progress (safeguard pending) | Plan-dependent delivery metadata and inactive update bundles are retained for 30, 60, or 90 days (90 days maximum); after service termination active data is deleted after a 30-day export period and immutable backups rotate within 30–90 days. |
| OpenAI, L.L.C. | generative_ai_dish_enrichment | United States/global infrastructure | In progress (safeguard pending) | API prompts and outputs may be retained in default abuse-monitoring logs for up to 30 days unless law requires longer; the integration requests no Responses API application state (`store=false`), and image generation stores no application state. |
"In progress (safeguard pending)" means the KVKK Article 9 cross-border transfer mechanism (Standard Contractual Clauses, written undertaking, Binding Corporate Rules, or a Board adequacy decision) is not yet finalized for that processor. We disclose the gap on purpose; each row is updated once a mechanism is in place.
For questions or feedback, contact privacy@istebuyemek.com.