This policy explains how NMOS.NET collects, uses, and protects personal data when you use our crawl analysis service. By using the service, you acknowledge this policy.
1. Data controller
NMOS.NET is responsible for processing your personal data. Contact us at destek@nmos.net or via the contact form.
For users in Türkiye we consider KVKK; for EEA users we consider GDPR principles.
1.1 Our roles (controller / processor)
For account, login, plan, and support data, NMOS.NET is the data controller.
For crawler and visitor technical data collected via the meta tag / tracking.js on your website, you are generally the controller and NMOS.NET acts as processor under the Data Processing Agreement (DPA). Informing your visitors remains your responsibility.
2. Data we collect
We collect only what is needed to provide the service:
2.1 Account and contact data
- Full name
- Email address
- Password (stored hashed)
- Optional two-factor authentication (2FA/TOTP) secret (when enabled, stored securely)
- Email notification preferences (type and frequency: daily / weekly / monthly)
- Optional website field
- Plan / subscription info
2.2 Site and setup data
- Site name and URL you add
- Meta tag / tracking key
- Site status (active, pending, inactive)
2.3 Crawl and technical data (from customer sites)
- Crawler name/type, category, safety/risk level, and User-Agent
- Request IP and hostname when available (rDNS)
- Visited page URL and status code
- Visit time and verification status
- robots.txt block date, later visits by blocked bots, and violation flags (when recorded)
- If traffic analysis is enabled: visitor vs bot separation plus session / referrer / device info
2.4 Payment data
When payments are enabled, sensitive card data is not stored on our servers; it is handled by secure payment providers. We may receive limited billing status information.
3. Purposes of processing
We process data to:
- Create accounts, authenticate users (password and optional 2FA), and provide dashboard access
- Deliver crawl analysis, reporting, robots.txt violation monitoring, and verification signals
- Send transactional emails (e.g. password reset, 2FA) and optional digests you choose (bot visits, robots.txt violations, activity summary)
- Respond to support requests
- Prevent abuse, fraud, and security incidents
- Run subscriptions and billing (when enabled)
- Meet legal obligations
- Improve the product using aggregated/anonymous insights
4. Legal bases
Processing is based on contract performance, legitimate interests (security and product improvement), legal obligations, and consent where required. For customer-site data, NMOS generally processes as a processor under your instructions.
5. Sharing
We do not sell personal data. Sharing may occur only for:
- Legal requirements or authority requests
- Preventing security threats
- Service providers (hosting, email delivery such as CyberPersons CyberMail or equivalent SMTP/API, analytics, payments) under contract and only as needed; email providers may receive recipient address and template content
6. International transfers
Infrastructure or vendors may be located in other countries. When transfers occur, appropriate safeguards are applied.
7. Retention
We keep data only as long as needed:
- Account and site data while the account is active
- 2FA secrets: removed when 2FA is disabled or the account is deleted
- Typically 30 days after account closure, then deletion or anonymization
- Crawl logs for a limited operational period based on plan needs
- Longer where required by law
8. Security
We apply reasonable technical and organizational measures such as HTTPS, access controls, hashed passwords, optional 2FA, and security updates. No system can guarantee absolute security.
9. Cookies
We may use cookies or similar technologies. See the Cookie Policy for details.
- Essential: session, security, core features
- Preferences: language and UI choices
- Analytics: aggregated understanding of site usage (if used)
You can manage cookies in your browser; disabling essential cookies may break some features.
10. Your rights
Under KVKK and applicable GDPR rules you may have rights to:
- Access
- Rectification
- Erasure
- Objection or restriction
- Data portability
- Withdraw consent where processing is consent-based
11. How to exercise rights
You can download your data or delete your account in Dashboard → Settings. You may also contact destek@nmos.net or the contact form. We may need to verify your identity. Requests are handled within reasonable timeframes under applicable law. You may also lodge a complaint with a supervisory authority.
12. Children’s privacy
The service is not directed to children under 13. We do not knowingly collect their data and will delete it if discovered.
13. Policy changes
We may update this policy. For material changes we will try to notify you by email or in-product notice. The current version is always on this page.
14. Contact
For privacy requests:
- Email: destek@nmos.net
- Contact form: nmos.net contact page