Contents
This is a plain-language overview. The legal detail is in the separate notices listed below.
Who is responsible for your data
I am Utku Sakallıoğlu, a freelance sole trader (serbest çalışan) based in Ankara, Türkiye. I offer web design, brand identity, SEO/GEO, WordPress maintenance, repair and migration, and technical consulting. I am the data controller for the personal data described here, which means I decide why and how it is processed.
You can contact me about anything in this policy, including requests about your data, at [email protected]. I do not publish a postal address. If you need one to send a signed letter, ask me by email and I will send it to you.
Which text covers what
- This privacy policy is an overview for everyone who uses the site or works with me.
- The GDPR privacy notice gives the legal basis for each activity, your rights and how to make a request under the EU GDPR and the UK GDPR.
- The Cookie policy lists every cookie and browser-storage item on the site with its purpose and lifetime, and explains how to change your choices.
- The KVKK aydınlatma metni is my notice under the Turkish Personal Data Protection Law No. 6698 (KVKK). That law applies to all the personal data I process as a controller in Türkiye, whoever and wherever you are. The notice is written in Turkish for Turkish-speaking visitors. It is a separate, stand-alone text, and this policy does not replace it.
This policy is also available in Turkish as the Gizlilik politikası.
In short
- The website, its database with your form submissions, and my newsletter system run on servers in Türkiye. Cloudflare delivers and protects the site, so all traffic to it passes through Cloudflare’s global network.
- Analytics and advertising tools run only after you opt in through the cookie banner. Rejecting them is as easy as accepting them.
- Blog comments appear under your name only after I approve them. In this policy, “blog posts” means the posts in both the Blog and the Personal sections of the site. The comment form asks for your email address but never publishes it, and it sets no cookies.
- The AI-assisted analysis of quote requests is optional and needs its own consent. Without that consent, I review your request by hand.
- I review every AI result and make every decision myself. No decision about you is made by software alone.
- You can withdraw any consent at any time.
What I process and why
Visiting the website
Whenever your browser requests a page or file, Cloudflare and my hosting server process technical data about the request. This covers your IP address, the date and time, the address requested, the HTTP method and status code, the referring page, your browser and operating system (user agent), connection and encryption data, an approximate location derived from your IP address, and Cloudflare’s bot score and challenge result.
I use this data to deliver the site over an encrypted connection and cache it, to detect and block attacks, malicious bots and abuse, and to find faults and keep the site available. For this, Cloudflare may set two security cookies, cf_clearance and __cf_bm. They are strictly necessary, so they do not depend on your consent.
Preferences stored in your browser
The site remembers a few interface settings in your browser:
- the language you are viewing, in the pll_language cookie set by the site’s multilingual plugin
- your light or dark theme (site_theme), stored on your first visit with the default setting and updated when you use the theme toggle
- the currency you pick in the English pricing sections (site_currency), stored only when you choose one
- a short-lived timestamp that lets the language-switch transition play (site_lang_switch)
None of these contains your name, email address or any other identifier. Only the language cookie is sent to the server. The others stay on your device.
The site builder, Elementor Pro, also keeps counters in your browser for the rules that control its pop-ups, such as the info tips and panels. The counters record how many pages you have viewed, how many visits you have made, how often each pop-up was shown and whether you closed it. They are not sent anywhere, and they are stored only if you allow the “functional” category in the cookie banner.
Your cookie choices
When you accept, reject or save your choices in the cookie banner, I record your choice for each category (functional, analytics, marketing), the date and time, the banner version and a pseudonymous consent ID. I do not store your full IP address with this record. The choice is kept in a cookie in your browser and in a log on my server. It lets me respect your choice, avoid showing the banner on every visit and prove what you chose. You can change your choice at any time with the “Cookie settings” link in the footer.
Visit statistics
Cloudflare Web Analytics. If you consent to analytics, a small script from Cloudflare measures page views, visits, referring sites and page-load speed. It uses no cookies and no browser storage. It sends Cloudflare the page address without query parameters, the referring page and page-load timings. Your IP address and browser details reach Cloudflare with that request, and Cloudflare derives your country from the IP address. I see only aggregated figures.
Google Analytics 4. If you consent to analytics, Google Analytics 4 measures how the site is used: which pages and services attract interest, where visitors come from and how they move through the site. It sets two cookies: _ga, which holds a random ID, and a second cookie whose name starts with _ga_, which keeps track of your current session. Their lifetimes are in the Cookie policy. Google Analytics records page views, events, the referrer and campaign data, your device, browser, operating system, screen size and language, and timestamps. Google uses your IP address to estimate your approximate location (city, region and country) but does not log or store the address. I do not send your name, email address or form content to Google Analytics. Google processes this data on my behalf as a processor. Google explains its practices in How Google uses information from sites or apps that use our services.
Advertising measurement
If you consent to marketing, I use Google Ads conversion tracking and remarketing, and the Meta Pixel. These tools show which ads on Google, Facebook or Instagram lead to inquiries, and let me show ads to people who have visited the site. The Meta Pixel also helps optimize the delivery of my ads. The tools set advertising cookies such as _gcl_au, IDE, _fbp and _fbc. They send Google and Meta the IDs stored in these cookies (and in Meta’s own fr cookie, if your browser holds Meta cookies), click IDs from ads, the pages you view, events such as “quote form submitted” (never the form content), your IP address, browser details, the referrer and timestamps. Google also receives your consent choices. I do not send your email address or phone number to Google or Meta.
Until you consent, no Google or Meta tag loads at all. Google’s tags receive your choice through Google Consent Mode v2, which I run in basic mode.
For Google Ads, Google Ireland Limited processes the data as an independent controller under its own privacy policy. For visitors in the UK, this is Google LLC. I am responsible for collecting the data on this site and passing it to Google through the tag. What Google does with it afterwards is Google’s responsibility.
For the Meta Pixel, if you are in the EU or EEA, Meta Platforms Ireland Limited and I are joint controllers for collecting event data on this site and transmitting it to Meta. In essence, I give you this information and ask for your consent. Meta Ireland handles requests to access, correct, delete, restrict or port the data once Meta has received it. What Meta does with the data afterwards is its own responsibility. Whatever the arrangement says, you can exercise your rights against Meta Ireland or me. I deal with requests about the collection on this site and pass on anything that concerns Meta’s part. See Meta’s privacy policy and the Meta Controller Addendum. For visitors outside the EU and EEA, Meta Platforms, Inc. receives the data.
Contact form, email, messaging apps and social media
The contact form asks for your name, email address and message, and optionally your phone number. I cannot reply without the required fields. Your submission is stored in the site’s database on my hosting server in Türkiye and emailed to me through my own mail server in Türkiye.
You can also write to me directly by email or on WhatsApp, Signal, Telegram, LinkedIn, Instagram or X. If you do, I receive your name and email address or, on the other channels, your phone number or username and your profile name and photo, as well as your message, any files you send, and the date and time.
Writing to me on WhatsApp, Signal, Telegram, LinkedIn, Instagram or X is your choice. Delivering your message and storing it on the platform are governed by the platform’s own privacy terms, and the company that runs it is responsible for that processing as an independent controller. Because you send the message to the platform yourself, this is not a transfer by me. I use these messages only to reply to you and to consider your request. If we start working together, I move what is needed to the client file; otherwise I delete the copies in my account and on my devices 12 months after the last message. If you prefer not to use these platforms, write to me by email or use the forms on the site.
I use your messages to reply and to correspond with you. If you ask about a service for yourself, I also use them to take the steps you request before a contract. Bot protection, rate limiting and server-side checks protect the form against spam and abuse. These checks use technical data such as the time of submission and your IP address.
Quote requests
The quote form asks for your name, email address, company, the service you need, project details, budget range, timeline and current website address. Your phone number is optional. The form shows which of the other fields are required, and I cannot prepare a quote without them. You can attach up to five files of up to 10 MB each (JPG, PNG, WebP, PDF, TXT, MD, DOCX, ODT or RTF). Please do not include health data or other sensitive data, or personal data of other people that I do not need.
I use your request to assess the project, prepare the preliminary quote you asked for and correspond with you about it. I also record your choices on the two optional boxes described below, with the time, and the same kind of security data as for the contact form. Requests are stored as nonpublic records in the site’s database on my hosting server in Türkiye, and I receive a notification email through my own mail server in Türkiye. Uploads are checked on the server (file extension, real file type and file signature) and cannot be executed. Requests and attachments are deleted automatically 12 months after submission. If a contract follows, I move what the project needs to the client file.
The quote does not depend on any consent. For the quote itself, the form asks you only to confirm that you have read the notice. It also has two separate, optional boxes, both unticked by default. One is for the AI-assisted analysis described below. The other signs you up for my newsletter: you receive the same confirmation email as through the newsletter sign-up form, and you are subscribed only after you confirm.
AI-assisted preliminary analysis (optional)
If you check the AI box in the quote form, the site sends your project information (service needed, project details, budget range, timeline and website address) and your attachments to Google’s Gemini API. I use the paid tier, provided by Google Cloud EMEA Limited in Ireland. The name, email address and phone number you type into the form are left out. Your project details and attachments are sent as they are, so any personal data you write in the project details or include in attachments, including your own contact details, reaches Google. Gemini produces a draft analysis, with a summary, the likely scope and an effort estimate, that helps me prepare your preliminary quote. The draft is stored with your request and deleted with it.
I read every result and make every decision myself. No decision is based solely on automated processing, and none has a legal or similarly significant effect on you.
On the paid tier, Google does not use your content to improve its products. It keeps prompts and outputs in abuse-monitoring logs for 55 days, and authorized Google staff may review them. The content of your attachments that is used in the analysis can form part of these logged prompts. The uploaded files themselves are deleted straight after the analysis, and always within 48 hours. Google may store data temporarily or cache it in any country where it has facilities.
If you do not check the box, your request is not sent to Google or any other AI service, and I review it by hand. You can withdraw this consent at any time by email. Withdrawal stops future processing, but it cannot recall data already held in Google’s logs.
Newsletter
The newsletter brings articles, updates and news about my services. You can subscribe with your email address. Your name is optional. The newsletter runs on my own listmonk installation on my own server in Türkiye and is sent through my own mail server in Türkiye. After you sign up, I send you a confirmation email, and your subscription starts only when you click the link in it (double opt-in).
I store the following:
- your email address and, if you gave it, your name
- the date and time you signed up
- when you confirmed, and the IP address you confirmed from
- your list membership, subscription status and unsubscribe date
- which sign-up form and consent wording you used
I do not track whether you open my emails or click the links in them. I register your consent and any later refusal with the İleti Yönetim Sistemi (İYS) in Türkiye, as Turkish law on commercial electronic messages (Law No. 6563) requires.
Every newsletter contains an unsubscribe link, and you can also unsubscribe by writing to me. When you unsubscribe, I delete your subscriber profile or remove everything that links it to you. I keep your email address on a suppression list with the record of your consent and refusal, so that I do not write to you again and can show that I respected your choice. Sign-ups that are never confirmed are deleted after 30 days.
On blog posts you can also sign up in two ways: with the newsletter box at the end of every post, before the related posts and comments, or with the optional newsletter box in the comment form. The box at the end of a post asks only for your email address and is only for signing up; to submit it, you check its consent box, which is not checked in advance. The box in the comment form is separate from the required box confirming that you have read the notice, is optional and is not checked in advance, so you can comment without it. Both use the same wording: “I would like to read the latest tech news and hear about new guides and blog posts.”
When you sign up this way, I keep a consent record with your email address, your name and comment ID if you used the comment form, the date and time you submitted the form (UTC), the exact wording of the box, the language of the post, the source and the post. It does not include your IP address. The record is stored in the site’s database on my hosting server in Türkiye, separately from comments, so it stays even if your comment is not published or is deleted. My newsletter system is not set up yet, so I send nothing on the basis of these records today. When it is set up, I will import them into listmonk and send you a confirmation email. You are subscribed, your consent is registered with İYS and you receive newsletters only after you click the link in it. If you do not click it within 30 days, your record is deleted. The box at the end of a post is protected on the site itself by a hidden honeypot field and a signed timestamp, and it sets no cookies. You can withdraw your consent at any time, including before the newsletter system is set up, by writing to [email protected].
Blog comments
You can comment on blog posts and reply to other comments. The form asks for your name, your email address and your comment, and all three are required. Your email address is never published or shown to visitors. The form does not ask for a website, and you do not need an account. With each comment I store the date and time, the post, the comment you replied to (if any) and your IP address. I do not store your browser’s user agent. A required box asks you to confirm that you have read the notice on how I process your data; it is not a request for consent. The newsletter box is separate and optional (see “Newsletter”).
I keep your email address with your comment. I use it to contact you about your comment if needed, for example to ask a question before publishing it or to tell you why I did not publish it or removed it, and to check that a request about a comment comes from you. WordPress also uses it to recognize earlier comments from the same address, but I still approve every comment manually. I do not use it for marketing unless you check the newsletter box. It is deleted together with the comment.
I read every comment before it appears, and I publish only those I approve. A published comment shows your name, your comment and its date under the post, where anyone can read it, search engines can index it and others can copy it. Your email address and IP address are never published. I keep the IP address to prevent spam and abuse and to be able to deal with legal claims arising from a comment, and it is erased automatically 180 days after the comment date. Please do not include health data or other sensitive data, personal data of other people or your contact details in a comment.
Comments are stored in the site’s database on my hosting server in Türkiye, and I receive a notification email through my own mail server in Türkiye. The notification contains your name, email address and comment, but not your IP address. Spam protection runs on the site itself, with a hidden honeypot field and a minimum time for filling out the form, and no third-party spam or CAPTCHA service is involved. The comment form sets no cookies. Avatars are switched off on the whole site, so your email address is never sent to Gravatar.
To have a published comment deleted or corrected, write to [email protected]. To confirm that it is yours, I may ask you to write from the email address you used for the comment, or to reply to a verification message I send to that address. Once I delete a comment, I cannot control copies that search engines or other sites may hold.
Comments moved from the old site: comments written on the earlier version of the site between 2010 and 2021 were moved with the posts, with the name, comment text and date only; email and IP addresses were not moved. Publishing them is based on my legitimate interest in keeping the discussion under the posts complete. If you want a comment removed or your name hidden, write to [email protected].
Working with me
If you become a client, or you are a contact person at a client company, I process what the project needs:
- your name, job title, email address, phone number and address, and your company details
- the contract
- project briefs, and the content and files you give me
- temporary access details for your systems
- meeting notes and correspondence
- delivery and acceptance records
If you are a contact person, I may have received your details from your employer. I use this data to conclude and perform our contract, to communicate about the project, to deliver and support the work, and to keep the records I need to establish or defend legal claims.
Invoices are issued by Ruul (ruul.io), an invoicing platform for freelancers. Ruul collects the invoicing details it needs (name or trade name, address and tax details) from you itself, issues the invoice in its own name and processes the data under its own terms; I do not collect or keep them. You can also pay me directly by bank transfer in Turkish lira, euros or US dollars. The payer name, IBAN, amount, date and bank then appear on my bank statement. I use them only to match the payment to the work and keep no separate record. Your bank, my bank in Türkiye and any correspondent banks process the payment details.
When I work on your website, I may also handle data about your own customers or users on your behalf. Our contract governs that processing. This policy does not cover it.
Requests, legal obligations and claims
If you exercise your data protection rights, I process the details I need to verify your identity and answer you. I disclose data to courts and authorities when the law requires it. Where necessary, I also use data to establish, exercise or defend legal claims.
What the site does not use
- Fonts load from my own server, not from Google Fonts.
- The site embeds no videos and no social media plug-ins. My LinkedIn, Instagram and X profiles are plain links, so those networks receive data only if you follow a link, and then under their own policies.
- There are no user accounts. Blog comments need no account, and no avatars are shown, so the site sends no requests to Gravatar.
Legal bases in brief
Each activity rests on one of the grounds below. The GDPR privacy notice gives the exact basis for each activity under the GDPR and UK GDPR, and the KVKK aydınlatma metni gives it under Turkish law.
- Consent covers analytics and advertising tools, the pop-up counters (functional category), the AI-assisted analysis and the newsletter, including sign-ups on blog posts. You can withdraw consent at any time. Withdrawal does not affect processing that took place before it.
- Steps before a contract, and the contract itself cover quote requests, inquiries about a service for yourself, client projects, invoicing and payment.
- Legitimate interests cover website delivery and security, remembering your interface preferences, answering messages, publishing and moderating blog comments, keeping commenters’ email addresses to contact them about their comments, keeping commenters’ IP addresses for security and legal claims, dealing with contact persons at companies, recording your cookie choices, keeping proof of newsletter consents and refusals (under Turkish law, a legal obligation), and establishing or defending legal claims. Turkish law treats legal claims as a ground of its own.
- Legal obligations cover the Turkish rules on commercial email, lawful requests from authorities and answering data protection requests. Where the obligation comes from Turkish law, I rely under the GDPR and UK GDPR on my legitimate interest in complying with it instead, because a legal obligation there must come from EU, Member State or UK law.
Who receives your data
| Recipient | Role | Location | Purpose |
|---|---|---|---|
| Veridyen Bilişim Teknolojileri San. ve Tic. Ltd. Şti. | Processor; keeps hosting traffic data under its own legal duty (Law No. 5651) | İstanbul, Türkiye | Hosting the website, its database, uploaded files and server logs |
| Cloudflare, Inc. | Processor | USA; global network | Content delivery, encryption, attack and bot protection; Web Analytics (with consent) |
| Google LLC | Processor | USA and other countries | Google Analytics 4 (with consent) |
| Google Ireland Limited; Google LLC for UK visitors | Independent controller | Ireland; Google servers in the USA and elsewhere | Google Ads conversion tracking and remarketing (with consent) |
| Meta Platforms Ireland Limited (EU and EEA visitors); Meta Platforms, Inc. (other visitors) | EU/EEA: joint controller for collection and transmission, processor for matching and measurement. UK: processor. Elsewhere: processor or independent controller | Ireland; USA | Meta Pixel ad measurement and remarketing (with consent) |
| Google Cloud EMEA Limited | Processor | Ireland; other countries where Google has facilities | Gemini API for the optional AI analysis (with separate consent) |
| Ruul (Ruul Inc.; Ruul OÜ) | Independent controller | USA; Estonia | Issuing corporate invoices and collecting payment |
| Banks: my bank in Türkiye, the payer’s bank and correspondent banks | Independent controllers | Türkiye; abroad for transfers from outside Türkiye | Bank transfers |
| İleti Yönetim Sistemi A.Ş. (İYS) | Recipient required by law | Türkiye | Registering newsletter consents and refusals |
| The companies that run WhatsApp, Signal, Telegram, LinkedIn, Instagram and X | Independent controllers | Depends on the platform (for example the USA or Ireland) | The service you choose, if you message me there |
| Courts, authorities (including, if you complain to them, the KVKK Board, EEA supervisory authorities or the ICO) and lawyers, where engaged | Independent controllers | Türkiye; the EEA or UK for complaints | Lawful requests, complaints, legal claims and tax filings |
Published blog comments can be seen by anyone who visits the site and by search engines. I run my mail server and newsletter server myself in Türkiye, so they are not recipients. If we agree to use a file-sharing, meeting or collaboration tool for a project, its provider also receives what we share there.
Where your data is stored
The website, its database (including form submissions, attachments, blog comments, newsletter consent records from blog posts and the consent log) and my newsletter system run on servers in Türkiye, and the data they hold is stored there. That does not mean all processing happens in Türkiye. Cloudflare delivers and protects the site, so every page request, form submission and comment passes through Cloudflare’s global network and is handled at the Cloudflare data center nearest to you.
Some recipients are outside Türkiye: Cloudflare (USA and its global network), Google (USA, Ireland and other countries where Google has facilities), Meta (Ireland and the USA), Ruul (USA and Estonia), the payer’s and correspondent banks for transfers from abroad and the messaging and social media platforms you choose to message me on. Neither the European Commission nor the UK has issued an adequacy decision for Türkiye. The Turkish Personal Data Protection Board has not issued an adequacy decision for any country.
If you are in the EU, the EEA or the UK, the GDPR or UK GDPR applies to my processing of your data where it relates to offering you my services or to monitoring how you use the site. The GDPR privacy notice explains the transfer position for each recipient. It states, recipient by recipient, whether a transfer takes place, the safeguard relied on (mainly the provider’s standard contractual clauses, with the EU–US Data Privacy Framework as an additional basis where the provider is certified) and how to obtain a copy. It also says plainly where no recognized safeguard is yet in place, for example for my hosting provider in Türkiye. The KVKK aydınlatma metni sets out the position under Turkish law (KVKK Article 9).
How long I keep data
A record I delete may remain in a backup until the backup retention period ends.
| Data | How long |
|---|---|
| All cookies and browser-storage items, including analytics and advertising cookies | As listed in the Cookie policy |
| Server logs on my hosting account | Up to 30 days |
| Hosting traffic data that Veridyen keeps under its own legal duty as a hosting provider | The period Veridyen must apply under Law No. 5651 (the law provides for one to two years) |
| Your cookie consent choice in your browser | 6 months, after which the banner asks again |
| Consent log on my server | 3 years from recording |
| Google Analytics 4 user-level and event-level data | 14 months; aggregated reports are not subject to this limit |
| Data Google and Meta receive through their advertising tags | Kept under their own policies |
| Contact form messages, email, messaging app and social media inquiries | 12 months after the last message, unless a contract follows |
| Quote requests, attachments and AI drafts | Deleted automatically 12 months after submission, unless a contract follows |
| Prompts and outputs in Google’s Gemini abuse-monitoring logs | 55 days, including attachment content used in the prompt; the uploaded files themselves are deleted straight after the analysis |
| Newsletter subscriber profile | Until you unsubscribe |
| Newsletter consent and refusal records, including the suppression list entry | 3 years after your consent ends (Regulation on Commercial Communication and Commercial Electronic Messages, Art. 13) |
| Unconfirmed newsletter sign-ups | 30 days |
| Newsletter consent records from blog posts | Until they are imported into the newsletter system or you withdraw your consent. After import, deleted if you do not confirm within 30 days; if you confirm, kept as a newsletter consent record as above. If you withdraw, the record and your withdrawal are kept for 3 years after your consent ends (Regulation on Commercial Communication and Commercial Electronic Messages, Art. 13) |
| Published blog comments, including the email address stored with them | Until you ask me to delete them or I remove them; the email address is deleted with the comment |
| IP addresses stored with comments | Erased automatically 180 days after the comment date |
| Comments marked as spam or deleted, and comments left unapproved | Removed permanently after 30 days |
| Contracts, acceptance records and key correspondence | 10 years after the contract ends (Turkish Code of Obligations, Art. 146) |
| Other project files and working correspondence | 5 years after the project ends (Turkish Code of Obligations, Art. 147) |
| Access details for your systems | Deleted when our engagement ends |
| Data protection requests and my answers | 3 years after the request is closed, or longer while a complaint or dispute is pending |
| Data needed for legal proceedings | Until the proceedings end and the limitation periods expire |
How I protect your data
- Pages are delivered over an encrypted connection (HTTPS).
- Cloudflare filters attacks, malicious bots and DDoS traffic.
- The forms use bot protection, rate limiting, a security token (nonce) and server-side validation.
- The comment form is protected by a hidden honeypot field and a minimum fill-in time, and the newsletter box at the end of a post by a hidden honeypot field and a signed timestamp. I approve every comment before it is published.
- Uploaded files are checked on the server and cannot be executed, and quote requests are stored as nonpublic records.
- Only I have access to form records, newsletter consent records, unpublished comments and the email and IP addresses stored with comments, and to the systems that store them.
- For the AI analysis, only the project fields and your attachments are sent; the name, email address and phone number fields are left out, but any personal data you write in the project details or include in attachments is sent with them.
- Quote requests are deleted automatically after 12 months.
- I take backups. A record I delete may remain in a backup until the backup retention period ends.
- If a personal data breach occurs, I notify the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), any other competent supervisory authority and the people affected, as the law requires.
Your rights
Depending on the law that applies to you, you can ask me for access to your data, correction, deletion, restriction of processing, and a copy in a portable format. You can also object to processing and withdraw your consent. You can find out who has received your data, in Türkiye or abroad, and ask me to pass corrections and deletions on to them. Under Turkish law you can, in addition, object to an outcome against you that results solely from automated analysis, and claim compensation for damage caused by unlawful processing.
Right to object. Where I rely on legitimate interests, the GDPR lets you object at any time on grounds relating to your particular situation. You can stop direct marketing, including the newsletter, at any time without giving reasons.
To make a request, write to [email protected], preferably from the email address I already have for you. For an application under the KVKK by email, write from the address I already have for you, or sign it with a secure electronic or mobile signature. Requests are free of charge, except where the law allows a fee: under the GDPR for manifestly unfounded or excessive requests, and under the Turkish rules a cost-based fee for answers longer than ten pages or provided on a data medium. I answer within one month under the GDPR (extendable by two further months for complex requests) and within 30 days under the KVKK. I may ask for information to confirm your identity. For GDPR requests I ask only for what is proportionate. Applications under the KVKK must contain the details that Turkish rules require. To change your cookie choices, use the “Cookie settings” link in the footer. To leave the newsletter, use the unsubscribe link in any email or write to me. Until the newsletter system is set up, write to me to withdraw a sign-up made on a blog post.
You can also complain to a supervisory authority:
- in the EU or EEA, the authority in the country where you live or work, or where the alleged infringement took place
- in the UK, the Information Commissioner’s Office (ICO)
- in Türkiye, the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), after you have first applied to me: within 30 days of learning my answer, and in any case within 60 days of your application
The procedures, including the formal requirements for KVKK applications, are in the GDPR privacy notice and the KVKK aydınlatma metni.
Children
This site and my services are aimed at businesses and adults. I do not knowingly collect personal data from anyone under 18. If you are under 18, please do not comment on the blog or send me personal data. If you believe that someone under 18 has sent me personal data, please tell me at [email protected] and I will delete it.
Changes to this policy
I update this policy when my services, my tools or the legal requirements change. If I plan to use your data for a new purpose, I will tell you before I start. The date below shows the current version, and I keep earlier versions on file.
Last updated: October 3, 2026.