Contents
This notice explains how I process personal data when the EU General Data Protection Regulation (GDPR) or the UK GDPR applies. It covers this website, the contact and quote forms, blog comments, the newsletter and my work with clients, and it gives the information required by Articles 13 and 14 GDPR. In this notice, “blog posts” means the posts in both the Blog and the Personal sections of the site. My Privacy policy gives a general overview, and my Cookie policy lists every cookie and browser storage item with its purpose and lifetime.
Who I am and how to contact me
The controller is Utku Sakallıoğlu, a freelance sole trader (serbest çalışan) based in Ankara, Türkiye, who runs utkusakallioglu.com.
For any question about your data, and to exercise your rights, write to [email protected]. I do not publish a postal address. If you need one, for example to send a signed letter, ask me by email and I will give it to you.
When this notice applies
I am established only in Türkiye. The GDPR applies to my processing where it relates to offering my services to people in the European Union or the European Economic Area (EEA), or to monitoring their behavior on this website, for example through analytics and advertising cookies (Article 3(2) GDPR). The UK GDPR applies in the same way to people in the United Kingdom. Unless I say otherwise, a reference to the GDPR in this notice also means the corresponding provision of the UK GDPR.
Turkish data protection law (KVKK) also applies to all my processing. The Turkish notice under that law is the KVKK aydınlatma metni.
EU and UK representative, data protection officer
I have not designated a representative in the EU under Article 27 GDPR or in the UK under Article 27 UK GDPR, because my processing of personal data of people in the EU and the UK is occasional, does not include large-scale processing of special categories of data or of personal data relating to criminal convictions and offenses, and is unlikely to result in a risk to your rights and freedoms (Article 27(2)(a)). You can contact me directly at the email address above.
I have not appointed a data protection officer, because Article 37 GDPR does not require one for my activities.
What I process, why and on what legal basis
Each activity below lists the data, how I obtain it, the purposes and the legal basis under Article 6(1) GDPR. Where I rely on legitimate interests (Article 6(1)(f)), I name the interest, and you can ask me for the balancing test. Recipients, transfers and retention periods follow in separate sections, which refer to the activities by number.
1. Website delivery and security
- Data: your IP address; the date and time of each request; the requested URL, HTTP method and status code; the referring page; your browser and operating system (user agent); connection and encryption (TLS) data; the approximate location that Cloudflare derives from your IP address; Cloudflare’s bot score and challenge result; and the values of the security cookies cf_clearance and __cf_bm.
- How I obtain it: automatically, whenever your browser requests a page or file. Cloudflare receives it at the edge of its network, and the web server records access and error logs on my hosting account. Cloudflare sets its security cookies only when needed: cf_clearance after you pass a security check, and __cf_bm while bot management is active.
- Purposes: delivering the pages over an encrypted connection and caching them; detecting and blocking attacks, malicious bots, abuse and denial-of-service traffic; diagnosing faults and keeping the site available.
- Legal basis: legitimate interests (Article 6(1)(f)). My interest is the security of my network and information systems and the reliable delivery of the site (Recital 49 GDPR). The security cookies are strictly necessary for the service you request, so they need no consent.
2. Interface preferences and pop-up counters
- Data: the language (tr or en), theme (light or dark) and currency (EUR or USD) you use; a timestamp that lets the language-switch transition play; and counters kept by Elementor Pro, the site builder, of your page views and sessions and of which information panels you have seen or closed. None of these values contains your name, email address or any other identifier.
- How I obtain it: the language cookie (pll_language) is set by the site’s multilingual plugin (Polylang) when you first open a page, is updated when you switch language and is kept for one year. The theme value is stored in your browser on your first visit and updated whenever you use the theme toggle. The currency is stored only when you pick one. The other items are written in your browser by site scripts. Only the language cookie is sent to the web server with each request; everything else stays on your device.
- Purposes: showing the site consistently in the language and appearance you are using or have chosen, and in the currency you picked; playing the language-switch transition; applying the display rules of information panels, for example not showing again a panel you have closed.
- Legal basis: these values do not identify you on their own. To the extent they are personal data, I rely on legitimate interests (Article 6(1)(f)) for the language, theme, currency and transition values, namely showing the site consistently in the language and appearance you are using or have chosen, and on your consent (Article 6(1)(a)) for the pop-up counters, which run only if you allow the “functional” category in the cookie settings. The Cookie policy explains the rules on device storage that apply to each item.
3. Your cookie choices
- Data: your choice for each category (functional, analytics, marketing), the date and time, the version of the banner and policy, and a pseudonymous consent ID. I do not store your full IP address in the consent log.
- How I obtain it: automatically, when you click “Accept all” or “Reject all,” save your choices under “Preferences,” or change them through the “Cookie settings” link in the footer. Your choice is kept in a first-party cookie in your browser and in a consent log on my hosting server.
- Purposes: applying your choices, so that no analytics or marketing tags run before you opt in; not showing the banner on every visit; being able to show that consent was given.
- Legal basis: legitimate interests (Article 6(1)(f)), namely demonstrating consent, as Article 7(1) GDPR requires.
4. Cookieless statistics (Cloudflare Web Analytics)
- Data: when the statistics script from static.cloudflareinsights.com reports a page view, Cloudflare receives your IP address and user agent with the request. The report itself contains the page URL without its query string, the referring page, page-load timings measured in your browser, the country derived from your IP address and a timestamp. The script uses no cookies or browser storage, and Cloudflare states that it does not fingerprint visitors.
- How I obtain it: automatically, through the script, which loads only after you consent to analytics.
- Purposes: aggregated statistics on page views, visits, referring sites and page-load speed, which I use to improve content and performance. I do not build individual profiles and do not use this data for advertising.
- Legal basis: your consent (Article 6(1)(a)). The script reads information in your browser and sends it to Cloudflare, which also requires consent under the ePrivacy rules on access to your device.
5. Google Analytics 4
- Data: a random client ID in the _ga cookie and a session ID in the _ga_<container-id> cookie; the pages you view and the events I have set up; the referring page and campaign parameters; device type, browser, operating system, screen size and language; and your approximate location (city, region, country). Google uses your IP address to derive the location but does not log or store it. Data of visitors in the EU, Switzerland and the UK is collected through servers in those regions, and the IP address is dropped before logging. I do not send your name, email address or form contents to Google.
- How I obtain it: automatically, through the Google tag. I use Google Consent Mode v2 in basic mode: the tag does not load, and nothing is sent to Google, until you consent to analytics. Only then does it set its cookies.
- Purposes: measuring how the site is used, such as which pages and services attract interest, where visitors come from and how they move through the site, in order to improve content and structure, mainly through aggregated reports. Google signals is switched off, and I do not link Analytics with Google Ads.
- Legal basis: your consent (Article 6(1)(a)), which also covers storing and reading the cookies on your device.
Google explains its own use of this data in How Google uses information from sites or apps that use our services.
6. Google Ads conversion tracking and remarketing
- Data: Google Ads cookies (_gcl_au, _gcl_aw and other cookies beginning with _gcl_), the ad-click ID (GCLID) and Google advertising cookie IDs such as IDE; the pages you visit and conversion events such as “quote form submitted,” without the contents of the form; your IP address, user agent, referring page and a timestamp; and your consent signals. I use neither enhanced conversions nor Customer Match, so no email address or phone number is sent to Google.
- How I obtain it: automatically, through the Google tag, which loads only after you consent to marketing (Consent Mode v2, basic mode). The advertising signals ad_user_data and ad_personalization are granted only with marketing consent.
- Purposes: measuring which Google ads lead to inquiries (conversion measurement), and showing ads on Google’s networks to people who have visited the site (remarketing).
- Legal basis: your consent (Article 6(1)(a)), which also covers storing and reading the cookies on your device.
- Roles: I am responsible for collecting this data on my site and transmitting it to Google through the tag. Google then processes it as an independent controller under the Google Privacy Policy: Google Ireland Limited for visitors in the EU and EEA, Google LLC for visitors in the UK.
7. Meta Pixel
- Data: a browser ID in the _fbp cookie; the ad-click ID in the _fbc cookie, taken from the fbclid parameter in the link you followed; the ID in Meta’s fr cookie if your browser already holds Meta cookies; the page URL and events such as PageView or Lead, without the contents of any form; your IP address, user agent, referring page and a timestamp.
- How I obtain it: automatically, through the Pixel script. Meta offers no consent mode, so the script does not load at all until you consent to marketing.
- Purposes: measuring inquiries that come from ads on Facebook and Instagram, building remarketing audiences and optimizing the delivery of ads.
- Legal basis: your consent (Article 6(1)(a)), which also covers storing and reading the cookies on your device.
- Joint controllership: for visitors in the EU and EEA, Meta Platforms Ireland Limited and I are joint controllers for collecting the event data on this site and transmitting it to Meta (Article 26 GDPR). Under our arrangement, the Meta Controller Addendum, I give you this information and obtain your consent, and Meta Platforms Ireland handles requests under Articles 15 to 20 GDPR for the data after it has been transmitted. You can exercise your rights against either of us. After transmission, Meta processes the data for matching and measurement on my behalf and otherwise under its own responsibility, as described in the Meta Privacy Policy. For visitors in the UK, Meta Platforms, Inc. processes the data as my processor.
8. Contact form
- Data: your name, email address, phone number (optional) and message; the date and time of submission; bot-protection signals; and your IP address, which I use to limit the number of submissions.
- How I obtain it: you enter it in the form. It is then stored automatically in the WordPress database on my hosting server in Türkiye and sent to me by email through my own mail server in Türkiye.
- Purposes and legal bases: answering your message and corresponding with you, based on legitimate interests (Article 6(1)(f)), namely answering inquiries sent to me; where you ask about a service for yourself, taking the steps you request before entering into a contract (Article 6(1)(b)); protecting the form against spam and abuse through bot protection, rate limiting, a security token (nonce) and server-side validation, based on my legitimate interest in security (Article 6(1)(f)).
9. Email, messaging apps and social media
- Data: your name; your email address or, if you write on a messaging app or social network, your phone number or username and your profile name and photo; the content of your messages and any files you send; the date and time.
- How I obtain it: you send it directly to [email protected] or through WhatsApp, Signal, Telegram, LinkedIn, Instagram or X. I keep it in my mailbox or in the app concerned.
- Purposes and legal bases: answering and corresponding with you (Article 6(1)(f), my interest in answering inquiries sent to me), and taking the steps you request before entering into a contract (Article 6(1)(b)). Communication with existing clients falls under activity 14.
- Channels other than email: Writing to me on WhatsApp, Signal, Telegram, LinkedIn, Instagram or X is your choice. Delivering your message and storing it on the platform are governed by the platform’s own privacy terms, and the company that runs it is responsible for that processing as an independent controller. Because you send the message to the platform yourself, this is not a transfer by me. I use these messages only to reply to you and to consider your request. If we start working together, I move what is needed to the client file; otherwise I delete the copies in my account and on my devices 12 months after the last message. If you prefer not to use these platforms, write to me by email or use the forms on the site.
10. Quote form and preliminary quote
- Data: your name, email address, phone number (optional) and company; the service you need, project details, budget range, timeline and current website URL; up to five attachments (10 MB each; JPG, PNG, WebP, PDF, TXT, MD, DOCX, ODT or RTF) and any personal data they contain; your choices on the optional AI and newsletter boxes, with timestamps; and security data: a security token (nonce), the submission time and your IP address, which I use to limit the number of submissions.
- How I obtain it: you enter it in the form. It is stored automatically as a nonpublic record in the WordPress database on my hosting server in Türkiye. Uploads are checked on the server (file extension, real file type and file signature) and cannot be executed.
- Purposes and legal bases: assessing your request, preparing the preliminary quote you asked for and corresponding with you about it, as steps taken at your request before entering into a contract (Article 6(1)(b)); if you send the request for a company, you are not yourself the contracting party, and I rely on legitimate interests (Article 6(1)(f)), namely answering business quote requests; protecting the form through bot protection, rate limiting, a security token (nonce), server-side validation and upload checks (Article 6(1)(f), my interest in security).
- No consent needed for the quote: the form asks you only to confirm that you have read this notice. The quote never depends on any consent.
- Attachments: please do not upload health data or other special categories of data, or personal data of other people that your request does not need.
11. Optional AI-assisted preliminary analysis (Google Gemini)
- When it happens: only if you check the separate AI box in the quote form. The box is not checked in advance, and the quote does not depend on it. If you leave it unticked, I review your request manually and send it nowhere.
- Data: the service you need, project details, budget range, timeline, website URL and attachments. Your name, email address and phone number are left out of what is sent. Attachments and project details are sent as they are, so any personal data in them also reaches Google; please follow the attachment guidance in activity 10. The draft analysis that comes back is stored with your request.
- Purpose: a preliminary analysis (summary, scope and effort estimate) that helps me prepare your preliminary quote. I review every result and make every decision myself.
- Legal basis: your consent (Article 6(1)(a)). You can withdraw it at any time by email. Withdrawal stops any further analysis, and I continue with a manual review. It cannot recall data already held in Google’s logs.
- Provider: Google Cloud EMEA Limited, Dublin, Ireland, acting as my processor for the paid Gemini API. On the paid service, Google does not use prompts or responses to improve its products. Google keeps prompts and outputs in abuse-monitoring logs for 55 days, and authorized Google staff may review them. Files uploaded to Google are deleted right after the analysis, and at the latest after 48 hours. I use neither grounding with Google Search or Maps nor Gemini’s explicit context caching.
12. Newsletter
- Data: your email address (required) and name (optional); the date and time you signed up; the double opt-in record (time of confirmation and IP address); the lists you are on; your subscription status and unsubscribe date; the wording and version of the consent text and the form you used; and the data registered in İYS, the Turkish register of consents to commercial electronic messages. If you sign up on a blog post, I also keep a consent record: your email address; if you signed up through the comment form, your name and the ID of your comment; the date and time you submitted the form (UTC); the exact wording of the consent box; the language of the post; the source (the newsletter box at the end of the post, or the comment form); and the post. The record does not include your IP address. I do not track whether you open newsletters or click links in them.
- How I obtain it: you submit the sign-up form, or check the newsletter box in the quote form. My newsletter system (listmonk) then sends you a confirmation email, and you are subscribed only after you click the link in it (double opt-in). The newsletter system and its mail server run on my own servers in Türkiye.
- Signing up on a blog post: there are two ways, both using the same consent wording and feeding the same consent records. The newsletter box at the end of every post, before the related posts and comments, is only for signing up: it asks only for your email address, and you need to check its consent box, which is not checked in advance, to submit it. It is protected on the site itself by a hidden honeypot field and a signed timestamp, uses no third-party service and sets no cookies. The comment form also has an optional newsletter box, which is separate from the required box confirming that you have read this notice and is not checked in advance; you can comment without checking it. The consent box reads: “I would like to read the latest tech news and hear about new guides and blog posts.” On Turkish posts it shows the same text in Turkish. The consent record is stored in the WordPress database on my hosting server in Türkiye, separately from comments, so it remains if your comment is not published or is deleted. My newsletter system is not set up yet, so I send nothing on the basis of these records today. When it is set up, I will import them and send you the confirmation email described above, which also explains what the newsletter contains and how to leave. You are subscribed, your consent is registered in İYS and you receive newsletters only after you click the link in that email. If you do not click it within 30 days, your record is deleted. You can withdraw your consent at any time, including before the newsletter system is set up, by writing to [email protected]; your address is then not imported.
- Purposes: sending the newsletter (articles, updates and news about my services); managing subscriptions and unsubscribes; proving consent; meeting my duties under Turkish Law No. 6563 on the regulation of electronic commerce, including registration in İYS and record keeping.
- Legal basis: for sending the newsletter, your consent (Article 6(1)(a)), which also meets the consent rule for email marketing in the ePrivacy Directive (Article 13) and, in the UK, regulation 22 of the Privacy and Electronic Communications Regulations (PECR). Keeping the consent record from a blog post and sending you the confirmation email once the newsletter system is set up are also based on the consent you give by checking the box. For registering your consent and any refusal in İYS, and for keeping proof of them, including consent records from blog posts before they are registered in İYS, during your subscription and after you unsubscribe or withdraw, legitimate interests (Article 6(1)(f)), namely demonstrating consent (Article 7(1) GDPR) and complying with my obligations under Turkish Law No. 6563.
- Unsubscribing: every newsletter contains an unsubscribe link, and you can also unsubscribe or withdraw your consent by writing to me.
13. Blog comments
- Data: the name and email address you enter and your comment; the date and time; the post you comment on and, for a reply, the comment you reply to; and your IP address. Your email address is never published or shown to visitors. The form has no website field, and you do not need an account. Your browser’s user agent is not stored with the comment. If you check the optional newsletter box, activity 12 applies to that sign-up.
- How I obtain it: you enter your name, email address and comment in the form under a blog post, and the date, time, post and IP address are recorded automatically when you submit it. Comments are stored in the WordPress database on my hosting server in Türkiye, and I receive an email notification of each new comment through my own mail server in Türkiye. The notification contains your name, email address and comment, but not your IP address. Spam protection runs on the site itself, with a hidden honeypot field and a minimum time for filling out the form; no third-party spam or CAPTCHA service is used. The comment form sets no cookies. Avatars are switched off on the whole site, so your email address is never sent to Gravatar.
- Moderation and publication: I review every comment before it is published. I do not publish a comment I have not approved; I mark it as spam or delete it. Once I approve a comment, your name, the comment and its date appear publicly under the post, together with any replies. Anyone can read them, search engines can index them and others can copy them. Your email address and IP address are never published. Please do not include special categories of data, other people’s personal data or your contact details in a comment; I may decline to publish comments that do.
- Purposes and legal bases: receiving, reviewing and publishing your comment, based on legitimate interests (Article 6(1)(f)), namely offering readers a public discussion under my posts and keeping spam and unlawful or infringing content off my site. You send the comment so that it is published, and you can ask me to remove it at any time. Keeping your IP address to detect and prevent spam and abuse of the comment form, and to be able to establish, exercise or defend legal claims arising from a comment, is also based on legitimate interests (Article 6(1)(f)).
- Your email address: I keep it with your comment to contact you about your comment if needed, for example to ask a question before publishing it or to tell you why I did not publish it or removed it. WordPress also uses it to recognize earlier comments written with the same address, but I still approve every comment manually. The legal basis is legitimate interests (Article 6(1)(f)), namely running the comment section properly and fairly. I also use it to verify that a request about a comment comes from its author (activity 16). I do not use it for any other purpose, and I do not use it for marketing unless you check the newsletter box.
- Required fields: your name, email address and comment are required. Without your name and comment I cannot publish it, and without your email address I cannot contact you about it or verify requests about it. The form also has a required box confirming that you have read the notice on how I process your data. It records that you have been informed; it is not a request for consent. The newsletter box is separate, optional and not checked in advance.
- Removal and correction: you can ask me to delete a published comment or to correct your name or the text. To confirm that the comment is yours, I may ask you to write from the email address you used for the comment, or to reply to a verification message I send to that address. The address is not verified when you submit the form, so I will not disclose nonpublic data, such as your email or IP address, unless I am satisfied that the request comes from you. When a comment is deleted, the email address stored with it is deleted too; a newsletter consent record is kept separately under activity 12. When I erase a published comment, I cannot control copies held by search engines or other sites, but I take reasonable steps to ask search engines to drop outdated copies (Article 17(2)).
Comments moved from the old site: comments written on the earlier version of the site between 2010 and 2021 were moved with the posts, with the name, comment text and date only; email and IP addresses were not moved. Publishing them is based on my legitimate interest in keeping the discussion under the posts complete. If you want a comment removed or your name hidden, write to [email protected].
14. Working with clients
- Data: name, surname and job title; email address, phone number and address; company details; contract terms; project briefs and the content and files you provide; temporary access credentials to your systems; meeting notes and correspondence; delivery and acceptance records.
- How I obtain it: from you, by email, through WhatsApp, in meetings and through shared files.
- Purposes: concluding and performing our contract (web design, brand identity, SEO/GEO, WordPress maintenance, repair and migration, technical consulting); project communication, delivery and support; keeping the records needed to establish or defend legal claims.
- Legal basis: performance of the contract with you (Article 6(1)(b)). If you are an employee or contact person of a corporate client: legitimate interests (Article 6(1)(f)), namely performing the contract with your organization. For establishing or defending legal claims: legitimate interests (Article 6(1)(f)).
- Your own users’ data: when I maintain, repair, migrate or optimize a client’s website, I may process personal data of that client’s own users on the client’s behalf. For that data I act as the client’s processor, and this notice does not cover it.
15. Invoicing and payments
- Data: for direct bank transfers, the payment details shown on my bank statement: payer name, IBAN, amount, date and bank. I do not collect invoicing details (name or trade name, address, tax number, Turkish ID number); Ruul, which issues the invoice, collects them from you itself.
- How I obtain it: from my bank statement. I keep no separate record of these details.
- Purposes: receiving payment through Ruul or by direct bank transfer in Turkish lira, euros or US dollars, and matching the payment to the work it is for.
- Legal basis: performance of the contract (Article 6(1)(b)).
16. Requests about your data
- Data: your name and contact details; the subject and content of your request and any supporting documents; records of how I verified your identity; our correspondence and my response.
- Purposes: verifying your identity, answering within the legal deadline, keeping proof of my answer, and informing recipients of corrections or erasures (Article 19 GDPR).
- Legal basis: legal obligation (Article 6(1)(c)) under Articles 12 to 22 GDPR, which apply to me through Article 3(2); for UK requests, the UK GDPR.
17. Legal obligations, authorities and legal claims
- Data: only the data from the activities above that is relevant to the specific request or dispute.
- Purposes: responding to lawful requests from courts and authorities; establishing, exercising or defending legal claims.
- Legal basis: legitimate interests (Article 6(1)(f)), namely complying with my legal obligations in Türkiye and establishing, exercising or defending legal claims.
Who receives your data
The newsletter system and the mail server that sends form notifications run on my own servers in Türkiye; they are my own infrastructure, not recipients. The recipients are:
| Recipient | Role | Location | Activities |
|---|---|---|---|
| Veridyen Bilişim Teknolojileri Sanayi ve Ticaret Limited Şirketi (web hosting) | Processor: hosting of the website, database, uploaded files and server logs | İstanbul, Türkiye | 1–3, 8, 10–13 |
| Cloudflare, Inc. | Processor: content delivery, encryption, firewall, DDoS and bot protection, Web Analytics | USA; global network | 1–4, 8, 10, 12, 13 |
| Google LLC | Processor: Google Analytics 4 | USA and other countries where Google has facilities | 5 |
| Google Ireland Limited (EU and EEA visitors); Google LLC (UK visitors) | Independent controller: Google Ads | Ireland; USA; data processed on Google servers in the USA and other countries | 6 |
| Google Cloud EMEA Limited | Processor: Gemini API (paid service) | Ireland; transient storage or caching in any country where Google has facilities | 11 |
| Meta Platforms Ireland Limited (EU and EEA visitors) | Joint controller for collection and transmission; processor for matching and measurement; controller of its own later processing | Ireland; Meta also processes data in the USA and elsewhere | 7 |
| Meta Platforms, Inc. (UK visitors) | Processor | USA | 7 |
| The companies that run WhatsApp, Signal, Telegram, LinkedIn, Instagram and X | Independent controllers of the service you choose to message me on | Depends on the platform (for example the USA or Ireland) | 9, 14 |
| Ruul Inc., which issues the invoice as legal counterparty; Ruul OÜ | Independent controller as merchant or agent of record | USA; Estonia | 15 |
| My bank in Türkiye, the payer’s bank and correspondent banks | Independent controllers under banking law | Türkiye; other countries for transfers from abroad | 15 |
| İleti Yönetim Sistemi A.Ş. (İYS) | Recipient required by Turkish Law No. 6563: register of newsletter consents and refusals | Türkiye | 12 |
| Turkish courts, enforcement and prosecution offices, the Turkish Personal Data Protection Board, the Revenue Administration and other authorities empowered by law; lawyers I engage; an EEA supervisory authority or the ICO in a complaint | Independent controllers, only on a lawful request, in a complaint or where needed for legal claims | Türkiye; EEA; UK | 15–17 |
Published comments (activity 13) can be seen by anyone who visits the site and by search engines. I do not disclose the email addresses and IP addresses stored with comments, except to authorities or lawyers as described in activity 17.
Every page request, form submission and comment passes through Cloudflare’s network. Veridyen also keeps traffic data of its hosting service under its own legal duty as a Turkish hosting provider (Law No. 5651, Article 5(3)). If you and I agree to use a file-sharing, meeting or collaboration tool for a project, I will tell you beforehand who provides it and where it processes data.
Where your data is processed and international transfers
I am based in Türkiye. The data I hold myself (form submissions and attachments, blog comments, the consent log and the newsletter list) is stored on servers in Türkiye. Some of the services I use hold data in other countries, as the table below shows. Türkiye has no adequacy decision from the European Commission or the United Kingdom. When you send data to me directly, for example through a form, that is not a transfer under Chapter V GDPR, but the GDPR applies directly to my processing and you have the same rights as against a controller in the EU. Cloudflare terminates the encrypted connection for all traffic to the site, so your requests, form submissions and comments pass through Cloudflare’s global network before they reach my hosting server.
When I pass data on, the following safeguards apply:
| Recipient | Country | Safeguard |
|---|---|---|
| Veridyen (hosting) | Türkiye | A data processing agreement under Article 28 GDPR, with clauses based on the EU standard contractual clauses (Module 2). It is not a formally approved safeguard under Article 46 GDPR, because the EU has not yet adopted standard clauses for a provider that is itself subject to the GDPR. |
| Cloudflare, Inc. | USA and Cloudflare’s global network | EU standard contractual clauses (Modules 2 and 3) and the UK Addendum in the Cloudflare Customer DPA; in addition, Cloudflare’s certification under the EU–US Data Privacy Framework, its UK Extension and the Swiss–US Data Privacy Framework. |
| Google LLC (Analytics) | USA and other countries | Standard contractual clauses where required under Google’s data processing terms; in addition, Google LLC’s certification under the EU–US Data Privacy Framework, its UK Extension and the Swiss–US Data Privacy Framework. |
| Google Ireland Limited (Ads, EU and EEA visitors) | Ireland | No transfer to a third country by me. Google’s onward transfers are its own responsibility under its terms and its Data Privacy Framework certification. |
| Google LLC (Ads, UK visitors) | USA | The transfer terms in Google’s Controller-Controller Data Protection Terms; in addition, Google LLC’s certification under the UK Extension to the EU–US Data Privacy Framework. |
| Google Cloud EMEA Limited (Gemini) | Ireland; transient storage elsewhere | No transfer to a third country by me. The return of results to me in Türkiye and Google’s own sub-processing are covered by the standard contractual clauses in Google’s data processing terms for processor products, which govern the paid Gemini API. |
| Meta Platforms Ireland Limited (EU and EEA visitors) | Ireland | No transfer to a third country by me. Meta’s onward transfers to the USA rely on Meta Platforms, Inc.’s certification under the EU–US Data Privacy Framework. |
| Meta Platforms, Inc. (UK visitors) | USA | Meta’s Data Privacy Framework disclosure covers the EU–US and Swiss–US frameworks but not the UK Extension, and I have not confirmed another safeguard for UK data. This transfer happens only if you consent to marketing cookies. |
| Ruul OÜ | Estonia (EEA) | No transfer to a third country by me. |
| Ruul Inc. | USA | I have not confirmed a safeguard for this transfer. |
| İYS | Türkiye | There is no adequacy decision and no safeguard under Article 46 GDPR for this disclosure. It is limited to your email address and the record of your consent or refusal, and it is made to meet my obligations under Turkish Law No. 6563. |
| Turkish courts and authorities | Türkiye | Assessed case by case. Where the disclosure is necessary for legal claims, Article 49(1)(e) GDPR; I take Article 48 GDPR into account. |
In the table I list the standard contractual clauses first and a Data Privacy Framework certification as additional protection. These clauses and certifications are designed for transfers from the EEA and the UK. I am established in Türkiye, and several recipients are themselves subject to the GDPR for this processing, so it is not settled that they are an approved safeguard under Article 46 GDPR for my transfers; the same limitation applies to the agreement with Veridyen. They are the contractual and certification protections in place, and you can ask me for a copy of any of them.
Messages you send through a messaging app or social network go to that platform because you choose it; this is not a transfer by me. The same applies to newsletters delivered to your own mailbox provider and to bank transfers you initiate.
How long I keep data
I keep data for the periods below. The numbers in parentheses refer to the activities above, and the Cookie policy gives the lifetime of every cookie and browser storage item.
| Data | Retention period |
|---|---|
| Web-server logs on my hosting account (1) | At most 30 days |
| Hosting traffic data kept by Veridyen under Turkish Law No. 5651 (1) | 1 to 2 years, under Veridyen’s own legal obligation |
| Request data at Cloudflare (1) | Processed transiently to deliver and protect each request. Any logs Cloudflare itself keeps are governed by the Cloudflare Customer DPA |
| Security cookies (1) | __cf_bm: 30 minutes of inactivity; cf_clearance: the period stated in the cookie policy |
| Interface preferences and pop-up counters in your browser (2) | As stated in the cookie policy; you can delete them at any time by clearing the site’s data in your browser |
| Consent cookie and consent log (3) | Cookie: 6 months, after which the banner asks again; log: 3 years from recording |
| Cloudflare Web Analytics (4) | Nothing is stored on your device. Cloudflare shows me only aggregated statistics; any retention on Cloudflare’s side is governed by the Cloudflare Customer DPA |
| Google Analytics 4 (5) | User-level and event-level data: 14 months, not extended by new activity. The limit applies to explorations and funnel reports; standard aggregated reports are not affected. _ga and _ga_<container-id> cookies: 14 months from your last visit |
| Google Ads (6) | _gcl_ cookies: 90 days; IDE: 13 months in the EEA and UK. Google keeps the data it receives under its own retention policy |
| Meta Pixel (7) | _fbp, _fbc and fr: 90 days. Meta keeps event data under its own policies |
| Contact form, email, messaging app and social media inquiries (8, 9) | 12 months after the last message, including database entries and mailbox copies, unless a contract follows; the data needed then moves to the client file |
| Quote requests, attachments and AI drafts (10, 11) | Deleted automatically 12 months after submission, including mailbox copies, unless a contract follows; the data needed then moves to the client file |
| Data sent to Google Gemini (11) | Abuse-monitoring logs: 55 days; uploaded files: deleted right after the analysis, at the latest after 48 hours |
| Newsletter subscriber profile (12) | Until you unsubscribe; then deleted or unlinked from you, while your email address stays on a suppression list with the refusal record |
| Newsletter consent and refusal records (12) | 3 years from the date your consent ends |
| Unconfirmed newsletter sign-ups (12) | 30 days |
| Newsletter consent records from blog posts (12) | Until they are imported into the newsletter system or you withdraw your consent. After import, deleted if you do not confirm within 30 days; if you confirm, kept as a newsletter consent record as above. If you withdraw, the record and your withdrawal are kept for 3 years from the date your consent ends (Turkish Regulation on Commercial Communication and Commercial Electronic Messages, Article 13(2)) |
| Published comments, including the email address stored with them (13) | Until you ask me to delete them or I remove them; the email address is deleted with the comment |
| IP addresses stored with comments (13) | Erased automatically 180 days after the comment date |
| Comments marked as spam or deleted, and comments left unapproved, including their email addresses (13) | Removed permanently after 30 days |
| Contracts, acceptance records and key correspondence (14) | 10 years after the contract ends (Turkish Code of Obligations, Article 146) |
| Other project files and working correspondence (14) | 5 years after the project ends (Turkish Code of Obligations, Article 147) |
| Access credentials to your systems (14) | Deleted when the engagement ends |
| Requests about your data (16) | 3 years after the request is closed, and longer while a complaint or dispute is pending |
| Data used for authority requests or legal claims (17) | For the duration of the proceedings and until the applicable limitation periods expire |
Your rights
Under the GDPR you have the right to:
- access your data and receive a copy (Article 15);
- have inaccurate or incomplete data rectified (Article 16);
- have your data erased (Article 17);
- restrict processing, for example while the accuracy of your data is being checked (Article 18);
- receive the data you gave me on the basis of consent or a contract in a structured, commonly used, machine-readable format, and have it sent to another controller (portability, Article 20);
- object to processing (Article 21, see below);
- withdraw your consent at any time (Article 7(3), see below).
To exercise a right, write to [email protected]. I answer within one month. If a request is complex or you send several, I may extend this by two further months; I will tell you so within the first month and explain why. Exercising your rights is free of charge. I verify your identity only as far as necessary, and I do not ask for a national ID number. If I correct or erase data, I inform the recipients who received it (Article 19).
For Meta Pixel data after its transmission to Meta, Meta Platforms Ireland Limited handles requests under Articles 15 to 20 GDPR. You can still contact me about it.
Your right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Article 6(1)(f)). I will then stop, unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
You can object to direct marketing at any time, without giving a reason. I will then stop using your data for that purpose. For the newsletter, use the unsubscribe link in any issue or write to me.
Withdrawing consent
- Optional cookies and similar technologies (functional, analytics, marketing): through the “Cookie settings” link in the footer of every page.
- Newsletter, including sign-ups through the newsletter box at the end of a blog post or in the comment form: through the unsubscribe link in every newsletter, or by email to [email protected]. Until the newsletter system is set up, by email.
- AI-assisted preliminary analysis: by email.
Withdrawal does not affect the lawfulness of processing before it. Data already sent to Google for an AI analysis stays in Google’s abuse-monitoring logs until the 55-day period ends.
Do you have to give me your data?
- No law obliges you to give me personal data. Ruul asks for the invoicing details it needs under its own terms.
- Contact form: your name, email address and message are needed so that I can answer; your phone number is optional.
- Quote form: the form marks the required fields, and without them I cannot prepare a quote; your phone number is optional.
- Newsletter: your email address is needed to send it; your name is optional, and the newsletter box at the end of a blog post does not ask for it.
- Blog comments: your name, email address and comment are required. Your name is published with the comment; your email address is not. The newsletter box in the comment form is optional.
- Clients: the data needed to conclude and perform our contract is a contractual requirement; without it I cannot work with you.
- Consent-based processing (optional cookies, the AI analysis and the newsletter) is entirely voluntary. Refusing it does not affect my services or your quote.
- The technical data in activity 1 is needed to deliver the website; without it the site cannot be shown to you.
Automated decision-making
I do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR; in the UK, Articles 22A to 22D UK GDPR). The optional AI analysis (activity 11) is a drafting aid: I review every result, can change or disregard it, take all the material into account and decide myself. If you do not consent to it, I review your request manually. Remarketing through Google and Meta (activities 6 and 7) uses information about your visits to select ads, and it runs only with your marketing consent.
Data I receive from others
Some data does not come from you directly (Article 14 GDPR):
- If you are an employee or contact person of a client or prospective client, I receive your name, job title, business contact details and project correspondence from your organization (activities 10, 14 and 15). I process this data on the basis of legitimate interests (Article 6(1)(f)), namely communicating with your organization about the quote or project.
- If you pay by direct bank transfer, the payer name, IBAN, amount, date and bank come from my bank statement (activity 15).
- Attachments to a quote request may contain data about other people; the source is the person who sent the request (activity 10).
- A blog comment or reply may mention other people; the source is the person who wrote it (activity 13). If a comment concerns you, you can ask me to remove it.
Complaints
You can raise any concern with me first at [email protected], with “Complaint” in the subject line. I acknowledge complaints within 30 days, take appropriate steps to respond and tell you the outcome without undue delay.
If you are in the EU or EEA, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Article 77 GDPR). The European Data Protection Board lists the authorities on its members page. You may also bring proceedings before the courts of the Member State where you habitually reside (Article 79 GDPR).
If you are in the UK, you can complain to the Information Commissioner’s Office (ico.org.uk/make-a-complaint, helpline 0303 123 1113).
Under Turkish law, after you have first applied to me, you can also complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu); the KVKK aydınlatma metni explains how.
Changes to this notice
I update this notice when my processing changes. Before I use your data for a new purpose, I will describe it here, and where the new purpose needs your consent, I will ask for it. If you are a client or a newsletter subscriber, or you have sent me a request, I will also tell you by email before the new processing starts. The date below shows the current version.
Last updated: October 3, 2026.