The core point. Conarium is self-hosted: it runs entirely inside your own infrastructure. In the product path, the vendor does not receive, access, store or process your data or your customers' personal data. You remain the sole controller and processor of your own data. There is, by design, nothing for us to mishandle.
This addendum sets out how personal data is handled between you ("Customer", the controller) and Emek Can Doğru, trading as Conarium ("Conarium") in connection with the website, the design-partner pilot and support. It is aligned with Turkey's KVKK (Law No. 6698) and the EU GDPR. For a signed, engagement-specific agreement, contact e.dogru@conarium.dev.
The only personal data Conarium processes is what you voluntarily send us: your contact email (to arrange access/pilots) and the content of your messages (to respond and support you). No customer database content, no end-customer PII, ever reaches Conarium.
For the website/support processing only:
Because the product is self-hosted, there are no product sub-processors — your data does not flow to any third party through Conarium.
Product data stays wherever you host it — it never transfers to us. For the limited website data, our sub-processors may operate outside your country; we rely on their standard contractual safeguards.
For product data, you handle data-subject requests directly, since only you hold it. For website/support data, email e.dogru@conarium.dev and we will assist promptly. We will notify you without undue delay of any breach affecting personal data you shared with us.
This addendum applies for as long as we process any personal data you have shared. On request we will delete or return it.