NEW Continuous mobile application security across every release. See the platform overview
Mobexa
Features
The platform

Continuous mobile AppSec

Every release scanned with static, dynamic and runtime analysis for Android and iOS, with signed evidence.

Analysis Static analysisSAST · source & bytecode Dynamic analysisDAST · runtime behaviour Runtime instrumentationIAST · live hooks Secret detectionbundled credentials
Supply chain Software bill of materialsSBOM · dependency risk Framework coverageOWASP MASVS / MASTG Ecosystemconnectors & webhooks
Operations IntegrationsCI / SIEM / ticketing SSO & access controlSAML 2.0 · OIDC · RBAC Flexible deploymentSaaS · VPC · air-gap
Use Cases
By team Product & Engineeringfail builds on new criticals Application Securityone unified portfolio view
  Compliance & Auditsigned evidence bundles Leadershipportfolio risk over time
Compare

Mobexa vs Competitor

How continuous, evidence-first testing differs from point-in-time scans.

View comparison
Resources Compare Pricing
Company
Company About Uswho we are Careersopen roles Contacttalk to us
Legal Terms of Use Privacy Policy Trust Center
Evaluate

See it on your own app

We scan one of your applications and hand over the evidence bundle.

Request a demo
Console login Free Trial
Mobexa
Features Use Cases Resources Ecosystem Compare Pricing About Us Contact Careers Console login
Start Free Trial See how it works

Legal

Privacy Notice

Last updated: July 21, 2026 · Governing law: Personal Data Protection Law of the Republic of Turkiye (Law No. 6698 - "KVKK") and, where applicable, EU General Data Protection Regulation (Regulation 2016/679 - "GDPR").

1. Data Controller

The data controller within the meaning of Article 3(1)(i) of KVKK and Article 4(7) of GDPR is Seccops Siber Güvenlik Teknolojileri A.Ş. ("Seccops", the "Company", "we", "us"), a joint-stock company registered in the Republic of Türkiye that operates the Mobexa platform. The controller's corporate identification and registration details are stated on the invoices issued to customers and are available on request. Contact for data-protection matters: .

2. Personal data we process

  • Account data - full name, business e-mail address, company name, job title, password hash.
  • Authentication / session data - session identifiers, IP address (KVKK Art. 6 categorisation: regular personal data), browser user-agent, login timestamps, two-factor authentication metadata.
  • Customer content - mobile application binaries (APK, AAB, IPA), scan reports, vulnerability findings, custom rules, audit trails uploaded by authenticated users.
  • Billing data - billing name, invoice address, tax/VAT ID, transaction reference. Card data is captured and processed exclusively by our PCI-DSS Level 1 payment service provider (Stripe); we never see, receive or store full card numbers, CVV codes or 3-D Secure passwords.
  • Communications - support tickets, sales enquiries, e-mail correspondence, telephone records (where you have consented), webinar / meeting attendance.
  • Telemetry - aggregate usage events strictly necessary for service quality, billing accuracy, capacity planning, security monitoring and fraud prevention.

We do not knowingly process special-category personal data (KVKK Art. 6 / GDPR Art. 9) such as health, biometric, racial-ethnic, religious or political data. If such data is uploaded by the Customer as part of a binary or finding payload, the Customer remains the controller of that data and is solely responsible for its lawful processing.

3. Purposes of processing & legal bases

PurposeKVKK basis (Art. 5)GDPR basis (Art. 6)
Provision of the contracted Services to authenticated users5/2(c) - Necessary for performance of contract6(1)(b) - Performance of contract
Billing, invoicing, collection, tax / accounting compliance5/2(ç) - Legal obligation6(1)(b) + 6(1)(c)
Security, fraud detection, abuse prevention5/2(f) - Legitimate interest6(1)(f)
Compliance with regulator / law enforcement requests5/2(ç) - Legal obligation6(1)(c)
Direct marketing (newsletters, event invitations)5/1 - Explicit consent (revocable)6(1)(a) - Consent
Service improvement & aggregate analytics5/2(f) - Legitimate interest6(1)(f)

4. How personal data is collected (KVKK Art. 10)

Personal data is collected directly from the data subject through (a) account creation forms, (b) the checkout / billing flow, (c) support and sales correspondence, (d) automatic technical means when the user interacts with the platform (cookies, server logs), and (e) lawful third-party sources where applicable (Stripe for payment confirmations).

5. Disclosure to third parties

Personal data is disclosed strictly on a need-to-know basis to:

  • our authorised employees, contractors and processors operating under written confidentiality and KVKK / GDPR-aligned data-processing agreements;
  • infrastructure sub-processors (cloud hosting, e-mail relay, monitoring) listed at /dpa;
  • the payment service provider (Stripe) for transaction processing;
  • professional advisors (lawyers, accountants, auditors) under their statutory duty of confidentiality;
  • competent public authorities and courts, where compelled by law;
  • a successor entity in the case of merger, acquisition or sale of substantially all assets, subject to equivalent confidentiality obligations.

6. International transfers

Primary processing infrastructure is located in Turkiye and the European Economic Area. Where transfer outside these jurisdictions is necessary, transfers occur under (a) Standard Contractual Clauses 2021/914 Module 2 (EU), and/or (b) commitments lodged with the Turkish Personal Data Protection Authority (KVKK Art. 9). A current list of sub-processors and their locations is published on the DPA page.

7. Retention

  • Account & billing: term of subscription + 10 years (Turkish Commercial Code Art. 82, KVKK Art. 7).
  • Customer content: term of subscription + 30 days grace, then cryptographically erased within 30 days, unless longer retention is contractually agreed.
  • Authentication / log data: 12 months (Law No. 5651 minimum).
  • Marketing consent records: until consent is withdrawn + 3 years to evidence withdrawal.

8. Data subject rights (KVKK Art. 11 / GDPR Art. 15 - 22)

The data subject has the right to:

  • (a) ascertain whether his/her personal data is processed,
  • (b) request information regarding such processing,
  • (c) learn the purpose of processing and whether the data is used in conformity with that purpose,
  • (d) know the third parties to whom data is transferred domestically or abroad,
  • (e) request rectification of incomplete or inaccurate data,
  • (f) request erasure or destruction of personal data within the limits of KVKK Art. 7 and GDPR Art. 17,
  • (g) request that the rectification, erasure or destruction be notified to third-party recipients,
  • (h) object to results adverse to the data subject arising solely from automated processing,
  • (i) request data portability under GDPR Art. 20 where applicable,
  • (j) request compensation for damage arising from unlawful processing - subject to the liability limits stated in Section 12 of this notice and in our Terms of Service.

Requests must be submitted in accordance with the Communiqué on the Application Procedures and Principles to Data Controllers (the "Application Communiqué"), in writing or by registered electronic mail to . We respond within thirty (30) days as required by KVKK Art. 13. Residents of the EU/EEA may additionally lodge a complaint with their national supervisory authority.

9. Cookies & similar technologies

We use strictly-necessary first-party cookies for session, CSRF protection and security. We use opt-in analytics or marketing cookies only with explicit consent. See the Cookie Notice for the complete inventory.

10. Security measures

We apply ISO 27001-aligned organisational and technical safeguards: TLS 1.3 in transit; AES-256-GCM at rest with hardware-backed key management; mandatory multi-factor authentication for privileged roles; least-privilege role-based access; complete tamper-evident audit trails; quarterly penetration testing; vulnerability disclosure programme; documented incident response with a 72-hour supervisory-authority notification target. Despite these controls, the Company makes no warranty that the controls cannot be defeated by sophisticated attack or zero-day exploit, and Section 12 limits liability accordingly.

11. Children

The Services are intended for business users acting in a professional capacity. We do not knowingly collect personal data of persons under 18. Any inadvertent collection will be deleted upon notice.

12. Limitation of liability & release of the Company, owners and personnel

To the maximum extent permitted by KVKK, GDPR, Turkish Code of Obligations Art. 115-116, and any other applicable mandatory law:

  • the data subject acknowledges that personal data is processed on a best-efforts basis and that no information system can be guaranteed against unauthorised access, malicious interception, force majeure events, infrastructure failure, sub-processor compromise, regulatory injunction, court order, or extraordinary criminal acts;
  • the Company's aggregate civil liability for any claim relating to the processing of personal data shall not exceed the fees paid by the affected Customer in the twelve (12) months immediately preceding the event giving rise to liability;
  • the Company shall not be liable for indirect, incidental, consequential, special, exemplary or punitive damages, including loss of profit, loss of business opportunity, loss of goodwill, regulatory fines imposed on the data subject by another authority, or any downstream loss whatsoever;
  • the data subject expressly releases and waives all claims, demands, causes of action and damages of every kind against the shareholders, directors, officers, founders, owners, employees, contractors, agents, advisors and licensors of the Company (collectively, the "Released Parties"), individually and jointly, in their personal capacities. The Released Parties shall not be personally liable for any consequence arising out of, or in any way connected to, the processing or alleged mis-processing of personal data, save in cases of intent (kasıt) or gross negligence (ağır kusur) where mandatory law renders such waiver unenforceable;
  • any liability that cannot be excluded by mandatory law remains strictly limited to direct damage actually suffered, evidenced and demonstrably caused by the Company's breach.

This Section 12 reflects an allocation of risk that is fundamental to the bargain between the parties and survives termination or expiry of any subscription.

13. Updates to this notice

This notice is updated when our processing activities change. The version date at the top of the page reflects the current revision. For material changes we notify subscribers by e-mail and display an in-product banner. Continued use of the Services after the effective date of an update constitutes acceptance.

14. Contact & complaints

To exercise any of the rights listed in section 5 (access, rectification, erasure, portability, restriction, objection), use our self-service request form at /legal/data-request. Statutory response window: 30 days.

Other data-protection enquiries: . Postal address available upon request. EU/EEA residents may lodge a complaint with their national supervisory authority. Residents of Turkiye may apply to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu - KVKK) at www.kvkk.gov.tr.

This notice is a binding legal document of Mobexa. The English version is provided for international convenience; in case of conflict the Turkish version prevails. Template reviewed by qualified legal counsel before publication.

Mobexa

Continuous mobile application security for every organization that ships a mobile app.

Product updates and mobile security research. No spam, unsubscribe anytime.

Product

Features Android App Security iOS App Security Use Cases Blog Glossary Standards Resources FAQ Ecosystem Careers Mobexa vs Competitor Pricing Penetration Testing Manual Pentest API Docs

Industries

Banking Fintech Insurance Healthcare Public Sector E-commerce Telecom Gaming Education Logistics

Company

About Us Contact System Status Customer console

Legal

Terms of Use Trust Center Privacy Policy Cookie Policy Data Processing Agreement Explicit Consent Acceptable Use Refund Policy Service Level Agreement

OWASP, OWASP MASVS and OWASP MASTG are marks of the OWASP Foundation. NIST, ISO, PCI-DSS, HIPAA, KVKK and GDPR are standards of their respective bodies. References describe how the platform maps to these open standards; they do not imply certification, partnership or endorsement.

© 2026 Seccops Siber Güvenlik Teknolojileri A.Ş. All rights reserved. · Essential cookies only.
53ms

Contact us

Send us a message - we reply by email.

Message sent

Thanks for reaching out. We'll get back to you by email shortly.

Spam-protected. Only your name & email are required.