Last updated: October 5, 2026

This Privacy Policy describes the privacy principles I apply when operating recepemreercetin.com. It should be read together with the Privacy Notice, Cookie Policy, Contact Form Privacy Notice, User Security Policy, and the downloadable Data Processing and Protection Policy.

The Privacy Notice explains what happens to personal data in practical terms. This Privacy Policy explains the broader standards I aim to apply across Site operation.

1. Privacy principles

I aim to process personal data in a way that is:

  • lawful, fair and transparent;
  • purpose-limited, so information is used for defined and legitimate purposes;
  • data-minimised, so only information reasonably needed for the relevant purpose is collected;
  • accurate, with reasonable steps taken to correct material inaccuracies when identified;
  • retention-limited, so information is not kept indefinitely without a continuing reason;
  • secure, using measures proportionate to the nature of the information and foreseeable risks;
  • accountable, with processing, providers and legal bases reviewed when Site functionality changes.

2. Scope

This policy covers personal data handled through Site functions such as:

  • contact and enquiry forms;
  • newsletter subscriptions;
  • account functionality;
  • support communications;
  • blog comments where enabled;
  • free digital downloads delivered through WooCommerce or comparable systems;
  • analytics, performance measurement and Site improvement;
  • security, hosting, content delivery and technical logging;
  • cookie and consent-management functions.

The Site does not currently offer paid checkout as an active public sales channel. If paid sales, memberships or recurring subscriptions are introduced, the legal and consumer-information framework will be reviewed before launch.

3. Data collection should match the feature

I do not intend to collect personal data merely because it may be useful later. Each form or feature should request only information reasonably connected to its function.

Examples include:

  • a contact form may require a name, email address and message;
  • a support request may require technical details needed to investigate the problem;
  • a newsletter form normally requires an email address and may request a name;
  • an account may require identifiers and authentication-related information;
  • a free digital download may create an order or delivery record even where no payment is taken.

Optional fields should remain optional unless a genuine operational or legal reason requires them.

4. Transparency and consent are separate concepts

A privacy notice informs people about processing. It is not, by itself, consent.

Where processing is based on consent, the request for consent should be separate, specific and understandable. Consent should not be bundled into an acknowledgement of the Privacy Notice where the law requires a genuine choice.

For example, submitting a contact request may be necessary so I can respond to that request; that does not automatically mean the person has agreed to receive unrelated marketing communications.

Marketing consent, where required, should therefore be collected separately from ordinary contact or support communications.

5. U.S. state privacy framework

U.S. privacy requirements are not identical to the UK consent model. Where an applicable U.S. state privacy law covers the Site or a particular processing activity, I aim to apply the rights, disclosures and opt-out mechanisms required by that law rather than incorrectly treating UK PECR rules as a universal U.S. standard.

This includes, where legally required:

  • providing access, correction, deletion and portability rights;
  • providing an opt-out from sale, sharing, targeted advertising or qualifying profiling;
  • recognising a valid Global Privacy Control (GPC) or other legally recognised universal opt-out preference signal for the purposes required by the relevant state law;
  • obtaining consent before processing sensitive personal data where the applicable state law requires it;
  • allowing an appeal of certain denied rights requests where the law provides an appeal right;
  • avoiding unlawful discrimination against a person for exercising a privacy right; and
  • providing clear disclosures when personal data is used for targeted advertising or disclosed in a manner legally characterised as sale or sharing.

The Site does not sell personal data for money. Nevertheless, U.S. state statutes can define sale or sharing more broadly than an ordinary paid sale. Advertising, analytics or cross-service disclosures therefore need to be assessed by their actual data flow and purpose before they are enabled.

If the Site is not subject to a particular state statute because a statutory threshold, exemption or territorial condition is not met, this policy does not create a contractual promise that every right from that statute applies. I may nevertheless choose to honour a privacy request voluntarily where doing so is reasonable, lawful and technically feasible.

6. Data used for communications

Information submitted for an enquiry or support request is used primarily to understand and respond to that communication, maintain an appropriate record, protect against abuse and, where relevant, take steps connected with a requested professional relationship.

I do not intend to add a person to a marketing list merely because they sent a contact or support request.

7. Newsletter and direct marketing

Newsletter functionality may be provided using MailPoet and related email infrastructure.

Where consent is required, marketing communications are sent only after the required consent or other lawful basis has been established. Every marketing message should provide an appropriate way to unsubscribe or otherwise stop future marketing communications. For U.S. recipients, commercial email practices should also be reviewed against applicable federal and state marketing requirements, including the operational requirements that apply to commercial email.

An opt-out or suppression record may be retained so that the preference can continue to be honoured.

8. Analytics and measurement

Analytics may be used to understand aggregate Site performance, traffic patterns, content usefulness and technical issues.

For UK visitors, the legal treatment of analytics depends on the exact configuration. Following changes introduced through the Data (Use and Access) Act 2025, a narrow PECR statistical-purpose exception may be available where all statutory conditions are met. In particular, the use must be limited to qualifying statistical improvement purposes, users must receive clear information and a simple free means to object, and individual-level personal data must not be retained longer than necessary for aggregation.

If the configuration goes beyond the exception – for example by supporting advertising, cross-service tracking, profiling or individual-level retention beyond what the exception permits – prior consent is required where UK PECR applies.

9. Advertising and tracking

Advertising, remarketing, cross-service tracking or similar technologies may involve identifiers, device data, interaction data and information shared with third-party platforms.

Such technologies should not be activated for UK visitors before valid consent unless a specific legal exception clearly applies. In practice, advertising uses are treated separately from strictly necessary or qualifying statistical uses.

Other jurisdictions may provide additional opt-out rights even where consent is not the applicable mechanism.

10. Security and abuse prevention

Security processing may include IP addresses, logs, failed-login information, firewall events, suspicious request patterns and other technical indicators.

Such processing is intended to protect the Site, users and infrastructure against spam, credential attacks, malware, scraping abuse, denial-of-service activity and other security threats.

Infrastructure may include Cloudflare, Natro, Firebase and AWS services. Security providers may process technical data automatically as part of delivering their services.

11. Artificial intelligence and user data

User personal data submitted through Site functions is not intentionally routed to external AI services for ordinary prompt processing, model training or profiling.

If a future Site function intentionally uses an AI service with user data, that function must be reviewed before launch and the relevant privacy information must be updated.

This rule is separate from restrictions on third parties using Site content for AI training or dataset creation, which are addressed in the Content, Copyright and Intellectual Property Policy.

12. Third-party providers

Third-party providers are selected for a defined operational purpose. Where appropriate, I aim to review:

  • the role of the provider;
  • data categories involved;
  • processing location;
  • security and confidentiality terms;
  • retention and deletion controls;
  • contractual data-protection terms;
  • international-transfer mechanisms where required.

A provider’s own independent processing may also be governed by its own privacy notice.

13. International processing

Because the Site is operated from Türkiye and uses infrastructure in more than one region, personal data may cross borders.

Where a restricted transfer rule applies, the relevant transfer should be covered by a lawful transfer mechanism or exception. The mechanism can vary by recipient, service and jurisdiction.

The global Site privacy framework does not replace separate Turkish-language KVKK notices maintained for processing governed specifically by Turkish law.

14. Retention and deletion

Retention should be tied to a defined purpose rather than an unlimited period. Factors include:

  • whether the relationship or request remains active;
  • the sensitivity of the information;
  • security and fraud risks;
  • legal limitation periods;
  • accounting, regulatory or recordkeeping obligations;
  • whether an opt-out record is needed to continue respecting a privacy choice.

When data is no longer reasonably required, it should be deleted, anonymised or otherwise securely disposed of, subject to backup cycles and legal holds.

15. Rights handling

Rights requests are handled according to the law that applies to the requester and processing activity.

A request may be submitted to [email protected] or through the downloadable Data Subject Rights Request Form. Identity verification should be proportionate to the risk and should not require unnecessary personal data.

A request may be refused, limited or subject to another lawful outcome only where applicable law permits.

16. Privacy by design when the Site changes

Before a materially new Site feature is introduced, the privacy impact should be considered as part of implementation. Examples include:

  • paid checkout;
  • memberships or recurring subscriptions;
  • new advertising networks;
  • behavioural profiling;
  • new AI features involving user data;
  • new account or authentication systems;
  • collection of sensitive data;
  • new processors or major cross-border data flows.

Where the risk or law requires it, a formal assessment should be completed before launch.

17. Children’s data

The Site is not designed as a children’s service and is not directed to children under 13 in the United States. If a Site feature changes in a way that makes use by children likely, the privacy, parental-consent and age-assurance implications – including COPPA where applicable – must be reviewed before that feature is launched.

18. Policy review

This policy may be updated as the Site, providers, legal requirements or security practices change.

Questions about this policy can be sent to [email protected].