Back to Home

KVKK & GDPR Data Protection Notice

March 27, 2026

Centerium LLC ("Company", "we", "us") operates IPv4Center.com ("Platform") and is committed to protecting your personal data in accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR"). This notice explains how we collect, process, and safeguard your personal data when you use our Platform.

1. Data Controller

Under both KVKK (Article 10) and GDPR (Article 13), the data controller responsible for processing your personal data is Centerium LLC.

Contact Information

  • Company: Centerium LLC
  • Address: 109 Fowler Ct, New Castle, Delaware 19720-5409, United States
  • Email: [email protected]
  • Website: https://ipv4center.com

2. Purposes of Data Processing

Your personal data is processed for the following purposes, in accordance with KVKK Article 5 and GDPR Article 6:

2.1 Service Delivery and Contract Performance

  • Providing IPv4 address sale, lease, and transfer services
  • Delivering ASN services
  • Account creation, identity verification, and management
  • Processing orders and reservations
  • Executing transactions with RIRs (RIPE NCC, ARIN, APNIC, LACNIC, AFRINIC)
  • Invoicing and payment processing

2.2 Legal Obligations

  • Compliance with tax legislation and reporting requirements
  • Adherence to commercial law and e-commerce regulations
  • KYC (Know Your Customer) and AML (Anti-Money Laundering) obligations
  • Responding to lawful requests from competent authorities
  • Accounting and audit activities

2.3 Legitimate Interests

  • Platform security and fraud prevention
  • Service quality improvement and optimization
  • Statistical analysis and reporting
  • Customer satisfaction measurement and support
  • Business process development

2.4 Consent

  • Marketing and promotional communications
  • Analysis of usage patterns through cookies and similar technologies
  • Personalized service and content delivery

3. Categories of Personal Data Processed

We process the following categories of personal data through our Platform:

3.1 Identity Data

  • Full name
  • National ID / passport number (where required)
  • Tax identification number
  • Company name and trade registry information
  • Authorized representative name and title

3.2 Contact Data

  • Email address
  • Phone number
  • Billing and office address
  • Country of residence

3.3 Financial Data

  • Bank account details (for seller payments)
  • Invoice information and payment history
  • Transaction amounts and currency preferences
  • Tax office information

3.4 Transaction Data

  • IPv4 address block sale, purchase, and lease records
  • ASN service requests and history
  • Order, reservation, and contract details
  • RIR membership information (Org ID, Reg ID)

3.5 KYC Documents

  • Company registration documents
  • Articles of association or equivalent
  • Signature circulars and authorization documents
  • Signed and stamped contract copies

3.6 Technical Data

  • IP address
  • Browser type and version
  • Operating system information
  • Cookie data and session information
  • Access timestamps and page view data

4. Data Collection Methods and Legal Basis

Your personal data is collected through the following methods and processed under the legal bases provided by KVKK Article 5(2) and GDPR Article 6(1):

4.1 Collection Methods

  • Account registration and form submissions on the Platform
  • Communication via email, phone, and live chat support
  • During order and payment processes
  • Document uploads during KYC verification
  • Automatic collection through cookies and similar technologies
  • Transactions conducted through RIR systems

4.2 Legal Bases

  • Performance of a contract (KVKK Art. 5/2(c); GDPR Art. 6(1)(b))
  • Compliance with legal obligations (KVKK Art. 5/2(ç); GDPR Art. 6(1)(c))
  • Legitimate interests of the data controller (KVKK Art. 5/2(f); GDPR Art. 6(1)(f))
  • Explicit consent of the data subject (KVKK Art. 5/1; GDPR Art. 6(1)(a))
  • Establishment, exercise, or defense of legal claims (KVKK Art. 5/2(e))

5. Data Transfers to Third Parties

Your personal data may be transferred to the following parties in accordance with KVKK Articles 8–9 and GDPR Articles 44–49:

5.1 Domestic Transfers

  • Competent public authorities as required by law
  • Payment service providers and banks
  • Accounting and financial advisory service providers
  • Legal advisory service providers

5.2 International Transfers

  • RIR organizations (RIPE NCC — Netherlands, ARIN — USA, APNIC, LACNIC, AFRINIC) for IPv4 transfer and ASN transactions
  • Cloud infrastructure and hosting service providers
  • Email and communication service providers
  • Payment processing providers (e.g., Stripe)
  • Analytics and performance measurement tools

6. International Data Transfers

Due to the global nature of IPv4 address trading, your personal data may be transferred internationally. These transfers are conducted with the following safeguards:

  • Adequacy decisions: Transfers to countries recognized by the Turkish Personal Data Protection Authority or the European Commission as providing adequate protection
  • Appropriate safeguards: Standard Contractual Clauses (SCCs) approved by the European Commission for EU/EEA transfers
  • Data protection agreements with all third-party service providers
  • Technical and organizational security measures applied to transferred data
  • Explicit consent obtained where no other legal basis applies

7. Data Security Measures

In accordance with KVKK Article 12 and GDPR Article 32, we implement appropriate technical and organizational measures to ensure the security of your personal data:

7.1 Technical Measures

  • SSL/TLS encryption for all data communications
  • AES-256 encryption for sensitive data at rest
  • Firewalls and intrusion detection/prevention systems
  • Regular security audits and penetration testing
  • Access control and authorization mechanisms
  • Backup and disaster recovery systems
  • Timely application of software updates and security patches

7.2 Organizational Measures

  • Personal data processing inventory management
  • Data protection awareness training for employees
  • Confidentiality agreements and data protection commitments
  • Data processing policies and procedures
  • Data breach notification and response plan
  • Data protection agreements with third-party service providers
  • Regular internal audits and compliance assessments

8. Data Retention Periods

Your personal data is retained for the period necessary for the purposes for which it was processed and within the statutory limitation periods:

  • Account data: For the duration of the active account and the legally required retention period after account closure
  • Transaction and contract records: 10 years from the date of transaction (Turkish Commercial Code)
  • Invoice and financial records: 5 years following the calendar year of issuance (Tax Procedure Law)
  • KYC documents: 8 years after the end of the business relationship
  • Communication records: 3 years
  • Cookie and technical data: Up to 2 years
  • Upon expiration of the retention periods, personal data is deleted, destroyed, or anonymized in accordance with applicable law

9. Your Rights as a Data Subject

Under KVKK Article 11 and GDPR Articles 15–22, you have the following rights regarding your personal data:

  • Right to know whether your personal data is being processed
  • Right to request information about data processing activities
  • Right to learn the purpose of processing and whether data is used accordingly
  • Right to know the third parties to whom your data is transferred, domestically or internationally
  • Right to request correction of incomplete or inaccurate data
  • Right to request deletion or destruction of your data under the conditions set forth in KVKK Article 7 / GDPR Article 17
  • Right to request notification of correction or deletion to third parties to whom data has been transferred
  • Right to object to a decision made solely by automated processing that produces an adverse result
  • Right to claim compensation for damages arising from unlawful processing
  • Right to data portability (GDPR Article 20)
  • Right to restrict processing (GDPR Article 18)
  • Right to withdraw consent at any time without affecting the lawfulness of prior processing

10. How to Exercise Your Rights

You may exercise the rights listed above by contacting us through the following channels:

10.1 Application Channels

  • Email: Send a written request with identity verification to [email protected]
  • Mail: Send a notarized or registered letter to 109 Fowler Ct, New Castle, Delaware 19720-5409, United States

10.2 Application Requirements

Your request must include:

  • Full name and signature (if written)
  • National ID or passport number
  • Residential or business address for correspondence
  • Email address, phone, and/or fax number (if available)
  • Subject of the request

10.3 Response Time

Your requests will be processed free of charge and concluded within 30 days at the latest. If the request requires additional cost, the fee determined by the Turkish Personal Data Protection Board may apply. For GDPR-based requests, we will respond without undue delay and within one month, which may be extended by two further months for complex requests.

11. Changes to This Notice

We reserve the right to update this Data Protection Notice to reflect changes in legal requirements or our data processing activities. Updates will be published on the Platform, and you will be notified of significant changes via your registered email address.

12. Right to Lodge a Complaint

If your request is denied, the response is insufficient, or no response is provided within the specified period, you may lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) at https://www.kvkk.gov.tr within 30 days of receiving the response, and in any case within 60 days of the application date. For GDPR-related matters, you may also lodge a complaint with the relevant supervisory authority in your EU/EEA member state.

Contact Us

If you have questions about how your personal data is processed or wish to exercise your rights under KVKK or GDPR, please contact us.

  • Email: [email protected]
  • Company: Centerium LLC
  • Address: 109 Fowler Ct, New Castle, Delaware 19720-5409, United States