Skip to content
SEPA.tr

Privacy Policy

In short: sensitive data you enter into our tools — such as IBAN, BIC and amount — never leaves your device. Below you will find the data controller, the legal basis and your rights in detail.

Updated:

Data controller

This site (SEPA.tr) is operated by IdaOps Yazılım Ltd. Şti.. Under KVKK and GDPR, this company is the data controller.

  • Trade name: IDAOPS YAZILIM MÜHENDİSLİK MEDİKAL GAYRİMENKUL DANIŞMANLIK TİCARET VE SANAYİ LİMİTED ŞİRKETİ
  • Address: Güzeloba Mah. Havaalanı Cad. A Blok Sitesi No:13c, Muratpaşa / Antalya, Türkiye
  • MERSİS: 0465158512100001 · Trade Registry No: 138519
  • Contact: info@sepa.tr

Tool data stays on your device

For our IBAN, BIC, amount and calculation tools:

  • The full IBAN, BIC, amount or description you enter is not logged.
  • This data is not written to the browser's localStorage/cookies and is not added to the URL.
  • It is not sent to any analytics service.
  • The calculation is performed entirely in your browser (client-side); this data is not transmitted to a server.

Exception: only the bank-search tools (BLZ lookup, EPC Participant lookup), in order to run your search, send the search term you type (bank name / BLZ / BIC) to the query API on the server. These requests are held in the edge cache and are not associated with any identity; sensitive data such as a full IBAN or amount is not entered into these tools and is not sent.

Per-tool data flow

Saying "every tool works the same way" would be misleading. Most tools run entirely in your browser; some, in order to run a search, send a non-sensitive term (bank code, BIC, currency) to the query service. A full IBAN, account number, amount and description are never sent to a server by any tool.

ToolWhere it runsSent to the serverThird party
IBAN / BIC / Creditor ID validation, IBAN generator, bulk validationBrowserNoneNone
pain.001, camt, SDD mandate, error code, VoP simulatorBrowserNoneNone
SEPA/EPC QR generatorBrowser (QR generation)Only the bank code (BLZ) to find the BIC for a German IBAN; not the full IBAN/amountCloudflare (hosting)
BLZ lookupQuery APISearch term / BLZCloudflare (edge cache)
EPC participant lookupQuery APIBank name / BIC / countryCloudflare (edge cache)
SEPA route-cost, Local → EUR exchange-rate costBrowser (calculation) + rate APIOnly the currency code (e.g. EUR, TRY); not the amount/IBANECB rate (frankfurter.app), Cloudflare

Data processed on a general site visit

The site is hosted on Cloudflare infrastructure. As the hosting and security provider, Cloudflare may process technical logs (IP address, browser type/request metadata) for the purposes of running the service, preventing abuse/attacks and ensuring security. This is a technical processing that is necessary for the service to be provided.

  • Web analytics: No active web analytics/measurement tool is currently used on the site. If a privacy-friendly, cookieless measurement (e.g. Cloudflare Web Analytics) is enabled in the future, this page will be updated and the status will be stated clearly.
  • Contact: If you write to info@sepa.tr, the content and address of your email are processed only to respond to your request.

Purposes of processing and legal basis

  • Providing and securing the site (server/security logs) — KVKK Art. 5/2-(f) legitimate interest; GDPR Art. 6/1-(f).
  • Operating the search tools (processing the search term) — performance of the service; KVKK Art. 5/2-(c), GDPR Art. 6/1-(b).
  • Contact/response to requests — legitimate interest/consent; GDPR Art. 6/1-(f)/(a).

Retention periods

  • Tool inputs: not retained (only in browser memory, for the duration of the session).
  • Server/security logs: for Cloudflare's technical retention periods (typically short-term).
  • Email correspondence: for as long as the request requires and as legal obligations demand.

Processors and international transfers

For hosting/security, the services of Cloudflare, Inc. are used. Because Cloudflare is a global infrastructure, technical data may be processed on servers abroad (including in the EU and/or the US). Cloudflare provides transfer safeguards such as standard contractual clauses.

Your rights

Under KVKK Art. 11 and the GDPR, you have the right to access the data processed about you, to have it corrected or erased, to object to processing and (where applicable) to data portability. For your requests you can write to info@sepa.tr. You also retain the right to lodge a complaint with the relevant data protection authority (in Turkey, the KVKK Authority).

Cookies

The site does not use tracking/advertising cookies that are not essential to its function. No third-party cookies are currently placed. If a feature requires cookies in the future, this page will be updated and the necessary information/consent mechanism will be provided.

Version and changes

Policy version: 2026-07-17. When this policy is updated, the date above changes and significant changes are recorded in the change log.

Related content