At a glance

Collect the contract, payments, registrant details, hosting account and access correspondence. Publishing a site, granting access, returning data and assigning IP rights are different obligations.

01 /

First assessment

Collect the contract, payments, registrant details, hosting account and access correspondence. Publishing a site, granting access, returning data and assigning IP rights are different obligations.

02 /

Technical control is not the same as legal entitlement

Domain registration, DNS and hosting access, agreed deliverables and rights in source code are distinct. Ending agency services does not automatically transfer every account or IP right. Use the contract, registrar records and a written handover request rather than trying to force access.

03 /

Is price the only issue in a SaaS agreement?

Scope, access, support, data return, intellectual property, liability and termination also matter. The business’s reliance on the service is relevant to the review.

04 /

Does commissioning software transfer all intellectual property rights?

Rights to use, modify, reproduce or transfer are assessed under the agreement and applicable law. Technical delivery and transfer of rights are distinct matters.

05 /

What should a hosting agreement clearly cover?

Define the service scope, availability target, maintenance and outage notice, backup responsibility, data return/deletion, security, subcontractors and exit process. The provider’s and site owner’s duties should be allocated expressly.

06 /

What if an agency will not publish my website or hand over admin access?

Review delivery, payment, source-code, domain and account terms. Preserve invoices, acceptance records and correspondence; any access or handover demand depends on the contract and proven rights.

07 /

How can I recover data when a cloud or SaaS service ends?

Agree in advance on export format, access period, backups, deletion confirmation and migration assistance. Where personal data is involved, assess controller/processor roles and transfer requirements under the applicable data-protection rules.

08 /

What are the first legal steps after a cyberattack or data breach?

Secure the systems while preserving logs, notices and evidence integrity. Identify affected data and parties, then assess contractual notices and whether a statutory data-breach notification and deadline apply.

09 /

Which records should you start with?

Gather the contract, notices, payments and correspondence in date order. Identify the other party and state the exact outcome sought. Do not calculate deadlines from general web guidance alone; the document date and type of proceeding both matter.

Relevant legislation and official sources

General information about Turkish law. Documents, current rules and deadlines require case-specific review.

Content is for general information and is not personal legal advice. Contact alone does not establish a lawyer-client relationship.

Related practice areasIT & Technology Law