Last updated: October 5, 2026

This Contact Form Privacy Notice explains how Recep Emre Erçetin (“I”, “me”, or “the site operator”) handles personal data submitted through contact, enquiry or support forms on recepemreercetin.com (the “Site”). It supplements the Site’s Privacy Notice and Privacy Policy.

Privacy contact: [email protected]

This notice is intended as a global baseline, with additional provisions for users whose data is subject to UK privacy law or an applicable U.S. state privacy law. Mandatory local law prevails where it applies.

1. Information collected through forms

Depending on the form and what you choose to provide, I may collect:

  • your name and surname;
  • your email address;
  • your telephone number where requested or voluntarily provided;
  • company, role, project or professional information relevant to your enquiry;
  • the content of your message;
  • files or attachments you choose to send;
  • communication history relating to the request;
  • technical and security information such as IP address, timestamps, browser or device data, request logs, anti-spam signals and abuse-prevention information.

Please do not send passwords, authentication codes, private keys, payment-card data, government identification numbers, health information, biometric information, precise geolocation, or other sensitive information through an ordinary contact form unless it is genuinely necessary and an appropriate secure channel has been agreed.

If sensitive information is submitted unexpectedly, I may limit its use to handling the immediate request, protecting the Site, complying with law, or deleting it when it is no longer needed.

2. Why form information is used

Form information may be used to:

  • receive, understand and respond to your enquiry;
  • communicate with you about the subject of your message;
  • provide requested support or information;
  • take steps you request before a possible professional engagement;
  • administer an existing professional or contractual relationship;
  • maintain a proportionate record of correspondence;
  • prevent spam, fraud, abuse, malicious activity and security incidents;
  • comply with legal obligations;
  • establish, exercise or defend legal claims.

Ordinary contact-form data is not collected for the purpose of selling personal data for money, and it is not intentionally sent to external AI services for routine prompt processing, model training or profiling as part of normal Site operation.

3. UK-specific legal bases

Where the UK GDPR applies, the legal basis depends on the reason for the communication and may include:

  • legitimate interests, including responding to genuine enquiries, maintaining proportionate correspondence records, protecting the Site and preventing abuse;
  • steps taken at your request before entering into a contract, where your enquiry concerns a possible engagement;
  • performance of a contract, where the communication concerns an existing engagement;
  • legal obligation, where processing is required by law;
  • consent, only where consent is genuinely required for a separate optional activity.

Submitting an ordinary contact or support request does not by itself constitute consent to unrelated direct marketing.

If marketing consent is requested, it must be presented separately and remain optional unless another lawful route is available under the law that applies.

4. U.S. point-of-collection information

For users in a U.S. state whose privacy law applies to the Site, this section is intended to supplement any legally required notice at or before the point of collection.

The categories of personal information collected through forms may include:

  • identifiers and contact information;
  • professional or business information you provide;
  • internet, device, log and security information;
  • correspondence and other content you submit;
  • records reasonably necessary to provide or document the requested service.

These categories are used for the purposes described in Section 2. Retention is based on the criteria in Section 8 rather than an indefinite default period.

I do not sell ordinary contact-form personal data for money. Ordinary contact-form data is not intended to be used for cross-context behavioural advertising or targeted advertising. If a future configuration changes that position, the relevant privacy notice and any legally required opt-out mechanism must be updated before or when that activity begins.

Where an applicable U.S. state privacy law gives you rights to know/access, correct, delete, obtain a portable copy, opt out of sale/sharing, targeted advertising or qualifying profiling, limit certain uses of sensitive personal information, use an authorised agent, or appeal a rights decision, those rights will be handled as required by the law that applies.

Where applicable law requires recognition of a valid Global Privacy Control (GPC) or another recognised universal opt-out signal, that signal must be honoured for the purposes covered by the applicable law.

5. Who may receive form information

Form data may be processed through Site infrastructure and providers that are necessary to transmit, protect, store or respond to your message. Depending on the configuration, these may include:

  • Natro for hosting or related infrastructure in Türkiye;
  • Cloudflare for content delivery, performance and security;
  • Firebase services configured in the European region where applicable;
  • Amazon Web Services (AWS) services that may involve processing in the United States;
  • email, anti-spam, security or communication providers enabled for the relevant form.

A provider may act as a processor/service provider for one function and as an independent controller for another. Information is disclosed only to the extent reasonably necessary for the relevant purpose, or where disclosure is required or permitted by law.

6. International processing

Because the Site is operated from Türkiye and uses infrastructure in more than one region, form information may be processed in Türkiye, the European Economic Area, the United States or other locations used by relevant providers.

Where the UK GDPR applies and a disclosure is a restricted transfer, an available lawful transfer route must be used. Depending on the recipient and circumstances, this may include UK adequacy regulations, the UK Extension to the EU-U.S. Data Privacy Framework for an eligible and certified U.S. recipient, the UK International Data Transfer Agreement, an applicable UK Addendum, or another lawful mechanism.

No transfer mechanism is assumed merely because a provider is well known or headquartered in a particular country.

7. Security

Reasonable technical and organisational measures are used to reduce the risk of unauthorised access, disclosure, alteration or loss. These may include HTTPS/TLS, access controls, security logging, firewall or anti-abuse measures, provider security controls and proportionate backup practices.

No internet transmission or storage system can be guaranteed completely secure. Do not use an ordinary form to send credentials or highly sensitive information unless specifically requested through an appropriate secure process.

8. Retention

Form submissions are kept only for as long as reasonably necessary for the enquiry and any related purpose. Relevant factors include:

  • whether the matter remains active;
  • whether a professional relationship results from the enquiry;
  • security, fraud-prevention or abuse-prevention needs;
  • applicable limitation periods and legal claims;
  • legal, regulatory or accounting obligations;
  • the need to preserve an opt-out, suppression or complaint record.

When the retention purpose ends, information may be deleted, anonymised or securely disposed of, subject to proportionate backup cycles and legal holds.

9. Privacy acknowledgement is not blanket consent

A link to this notice exists to provide information about how form data is handled. If a form asks you to acknowledge that you have seen the notice, that acknowledgement is not blanket consent for unrelated processing.

Any activity that genuinely requires consent, such as optional marketing where consent is required, must use a separate and specific consent mechanism.

10. Your rights and privacy complaints

Depending on the law that applies, you may have rights to access or know, correct, delete or erase, restrict or object, obtain portability, withdraw consent, opt out of certain U.S. state-law processing, use an authorised agent, or appeal a decision.

Requests may be sent to [email protected] or submitted using the Data Subject Rights Request Form. Use of the form is optional.

Where the UK GDPR applies, requests are handled within the applicable statutory period. A subject access request is normally answered without undue delay and within one month, subject to lawful extensions and the current rules on identity verification or clarification. If clarification is reasonably required, the statutory clock may pause as permitted by law.

Where the UK data-protection complaint procedure applies, privacy complaints should be acknowledged within the legally required period and responded to without undue delay. You may also have the right to complain to the UK Information Commissioner’s Office (ICO).

For U.S. state-law requests, response, verification, authorised-agent and appeal procedures vary by state and are handled under the law that applies.

11. Children

The Site and its contact forms are not designed or directed as services for children. I do not knowingly seek personal information from children in circumstances that require parental authorisation.

If you believe a child has submitted personal information inappropriately, contact [email protected] so the situation can be reviewed.

12. Contact

Recep Emre Erçetin
Email: [email protected]
Website: recepemreercetin.com