1. Who we are
CDKeySell Digital Limited operates cdkeysell.com and is the primary controller of personal information submitted through this website.
For privacy enquiries or requests, contact:
Email: [email protected]
CDKeySell works with authorized affiliated and regional operating entities where required for service delivery, support, billing or regional operations. These may include AMIN FARIDOUN DEVELOPMENT in Oman and other authorized operating entities identified in the relevant commercial arrangement.
2. Scope of this Policy
This Policy applies to personal information processed through:
- cdkeysell.com;
- our Contact Us form;
- Cost Optimization enquiries;
- Request This Plan / Cloud IT Management enquiries;
- business communications connected to a website enquiry;
- service-delivery, support and commercial records where this Policy is referenced.
This Policy does not replace the privacy notices or terms of third-party platforms such as Microsoft, Google, WhatsApp, Telegram, LinkedIn or other providers you choose to use.
3. Information you provide to us
Depending on the form or service, we may collect:
- your name;
- company name;
- work email address;
- country;
- WhatsApp number, where you choose WhatsApp as a contact method;
- Telegram phone number or username, where you choose Telegram;
- preferred contact method;
- subject and message content;
- information about your Microsoft 365 Business or Google Workspace environment;
- selected platform, management plan, billing option and number of managed users;
- user-count ranges and business requirements submitted for Cost Optimization;
- any information you voluntarily include in free-text fields.
Please do not submit passwords, authentication codes, payment-card details, highly sensitive personal data or other information that is not reasonably necessary for your request through general website forms.
4. Technical and anti-abuse information
When a public form is submitted, our systems may temporarily process technical information needed to protect the service from misuse.
This currently includes:
- the originating IP address, received transiently from hosting/network headers;
- a one-way SHA-256 hash derived from the IP address for rate limiting;
- a one-way SHA-256 hash derived from the submitted email address for rate limiting;
- the page URL and language/locale associated with the request;
- server-generated request numbers and timestamps.
Raw IP addresses used for this purpose are not stored in the public request database. Hashed anti-abuse identifiers are currently retained for approximately 60 minutes and then pruned as part of the rate-limiting process.
We also use technical controls such as an origin allowlist, request-size limits, strict server-side validation and a hidden anti-spam field.
5. How we use personal information
We may use personal information to:
- respond to enquiries and service requests;
- understand your requirements and prepare recommendations, quotations or service proposals;
- determine suitable Microsoft 365 Business, Google Workspace, managed IT, migration, security, backup/recovery or cost-optimization services;
- communicate with you through your chosen contact channel;
- deliver, administer and support agreed services;
- coordinate regional service delivery, billing and customer support;
- create and maintain business, support, operational and service-history records;
- prevent spam, fraud, abuse and unauthorized activity;
- secure, troubleshoot and improve our service-delivery processes;
- establish, exercise or defend legal rights;
- meet accounting, tax, regulatory and other legal obligations.
We do not currently use website enquiry data for automated advertising profiles or behavioral advertising.
6. Legal bases
Where applicable law requires a legal basis for processing, the basis depends on the purpose and may include:
- taking steps at your request before entering into a contract;
- performing a contract or service agreement;
- complying with a legal obligation;
- our legitimate interests, including responding to B2B enquiries, operating and securing our services, preventing abuse, maintaining appropriate business records and establishing or defending legal claims;
- consent, where applicable law specifically requires consent or where we expressly ask for it.
Where we rely on consent, you may withdraw that consent for future processing, subject to applicable law. Withdrawal does not affect processing that was lawful before withdrawal.
7. Affiliated and regional operating entities
Depending on the customer's location, requested service and commercial arrangement, relevant customer information may be shared with authorized affiliated or regional operating entities where reasonably necessary.
AMIN FARIDOUN DEVELOPMENT may, in specific regional arrangements, assist with service delivery, customer support, operational coordination, invoicing or payment collection. Where necessary for those functions, it may receive authorized access to relevant customer information on a need-to-know basis.
CDKeySell Digital Limited maintains primary oversight of access controls, security governance and data-protection practices within the CDKeySell service framework.
Where AMIN FARIDOUN DEVELOPMENT or another authorized entity issues an invoice or receives payment in its own name, that entity may process the billing and transaction information required for its own accounting, tax, regulatory and legal obligations. In that limited context, it may act as an independent controller where applicable law provides.
The entity responsible for invoicing or payment collection for a particular engagement will normally be identified in the relevant Quote, Order, Service Agreement, invoice or payment instruction.
8. Service providers and other recipients
We may disclose personal information, only as reasonably necessary, to categories of recipients such as:
- cloud database and infrastructure providers used to operate the website and store service requests;
- hosting, security and technical service providers;
- professional advisers such as accountants, auditors and legal advisers where necessary;
- authorized affiliated or regional operating entities;
- public authorities, regulators, courts or law-enforcement bodies where disclosure is legally required or reasonably necessary to protect legal rights.
The website currently uses Supabase as the database infrastructure for public service-request storage.
We do not sell personal information to advertisers.
9. International processing and transfers
CDKeySell serves customers across multiple regions. Personal information may therefore be processed in Türkiye and, where relevant to a regional engagement, by authorized operating entities such as AMIN FARIDOUN DEVELOPMENT in Oman. Infrastructure and other service providers may also process information in other countries.
International transfers are made subject to applicable data-protection law. Where a specific legal safeguard is required for a transfer, that safeguard must be in place before the transfer is relied upon.
We do not represent that every country in which a service provider operates has been formally recognized as providing an equivalent level of data protection.
10. Retention
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, subject to applicable legal, accounting, security and dispute-resolution requirements.
Our general retention targets are:
- Prospective-customer enquiries and leads that do not become an active customer relationship: generally up to 6 months after the last meaningful interaction.
- Routine closed service and support request records held directly by CDKeySell: generally up to 12 months after the relevant request is closed, unless the record remains necessary for an active customer relationship or another lawful purpose.
- Temporary technical or diagnostic copies, where created for troubleshooting or service delivery: generally up to 90 days after the issue is resolved or the temporary purpose ends.
- Ordinary security and operational logs: generally up to 6 months, unless a longer period is reasonably necessary for an active security investigation, fraud/abuse matter, dispute, legal claim or regulatory obligation.
- Hashed public-form anti-abuse identifiers: approximately 60 minutes under the current rate-limiting implementation.
- Records evidencing erasure, destruction or anonymization operations: retained for at least 3 years where applicable Turkish data-protection rules require that minimum period.
- Contracts, Orders, invoices, payment, tax and accounting records: retained only for the minimum period required by applicable law and legitimate accounting, tax or legal-record obligations.
We may retain specific records for longer where reasonably necessary and legally permitted to establish, exercise or defend legal rights, comply with lawful requests, investigate security or fraud incidents, resolve disputes, or satisfy legal, tax or regulatory duties.
These are general retention targets. Where records are subject to a legal or retention hold, or where a record must be retained to protect a lawful interest, the applicable record may be kept for the additional period reasonably required by that purpose.
11. Security
We use technical and organizational measures designed to protect personal information against unauthorized access, unlawful processing, accidental loss and misuse.
Current website-request controls include server-side validation, restricted database access, role-based administrative permissions, service-side database writes, request-size limits, anti-abuse rate limiting and avoidance of raw-IP storage in the public request database.
Authorized regional access should be limited to information reasonably necessary for the relevant service, support, billing or operational purpose.
However, no internet, cloud or information system can be guaranteed to be completely secure. Accordingly, we cannot promise absolute security or zero risk.
12. External platforms and links
Our website provides links to third-party services, including WhatsApp, Telegram, LinkedIn, Microsoft Marketplace and email applications.
These links do not automatically transmit your form data to those providers before you activate them. If you choose to follow a third-party link or use a third-party platform, that provider's own terms and privacy practices apply.
14. Your privacy rights
Depending on your location and applicable law, you may have rights to:
- ask whether we process personal information about you;
- request access to personal information;
- request correction of inaccurate or incomplete information;
- request deletion or anonymization where the legal conditions are met;
- request restriction of processing;
- object to certain processing;
- request portability where applicable;
- withdraw consent where processing is based on consent;
- request information about recipients or international transfers where applicable;
- complain to the competent data-protection authority.
These rights are not absolute. We may need to retain or continue processing information where permitted or required by law, including for contracts, accounting, fraud prevention, legal claims or regulatory obligations.
To exercise a privacy right, email [email protected]. We may ask for reasonable information to verify your identity and protect customer information before acting on a request.
15. Business-to-business service and children
CDKeySell is a business-to-business cloud IT service provider. Our website and service-request forms are not directed to children, and we do not knowingly solicit personal information from children through these forms.
16. Changes to this Policy
We may update this Privacy Policy to reflect changes in our services, technology, operating structure or legal obligations.
The "Last updated" date at the top of the Policy indicates the latest revision. Material changes will be reflected in the published Policy and, where required by law, communicated through an appropriate additional notice.
17. Contact us
For privacy questions, requests or concerns:
CDKeySell Digital Limited Email: [email protected] Website: cdkeysell.com