Last updated: October 5, 2026

This User Security Policy explains the security approach used for recepemreercetin.com (the “Site”), the precautions expected from users, and the process for reporting suspected vulnerabilities or security incidents.

Reasonable technical and organisational measures can reduce risk, but no website, network, device, provider or transmission method can be guaranteed completely secure.

1. Security approach

The Site may use layered controls such as:

  • HTTPS/TLS for data in transit;
  • hosting and server security controls;
  • content-delivery, firewall and web-application security services such as Cloudflare;
  • administrative access controls and least-privilege practices where technically available;
  • software, theme, plugin and dependency maintenance;
  • logging and monitoring for suspicious activity;
  • anti-spam, rate-limiting, bot-management or abuse-prevention controls;
  • backup and recovery procedures;
  • separation of user-facing and administrative functionality where appropriate.

Specific controls may change as infrastructure and risk change. Publication of this policy does not disclose confidential security architecture, credentials or defensive configurations.

2. Account security

Where account functionality is enabled, you should:

  • use a strong, unique password;
  • not reuse a password from another service;
  • protect the email account associated with your Site account;
  • keep your device and browser updated;
  • avoid sharing credentials or authentication codes;
  • log out of shared or public devices;
  • report suspected unauthorised access promptly.

If additional authentication controls are offered, using them may further reduce risk.

3. Phishing and suspicious communications

Be cautious of messages claiming to be from me that ask for passwords, one-time authentication codes, private keys, recovery codes, payment-card data, or similar credentials.

I will not ask you to send your Site password by email.

If a message appears suspicious, verify the sender and the request independently before opening attachments, following links or providing information.

4. Downloads and third-party links

The Site may provide free digital resources or links to third-party websites and platforms. Use the normal security precautions appropriate for your device before opening a downloaded file or external link.

Third-party websites and services operate under their own security, privacy and availability practices. A link from the Site is not a guarantee of another service’s security.

5. Prohibited security activity

You must not use the Site to:

  • attempt unauthorised access to accounts, servers, databases, storage, APIs or administrative systems;
  • bypass authentication, authorisation, rate limits, anti-bot controls or other security measures;
  • conduct vulnerability scanning, penetration testing or automated probing without prior written authorisation;
  • exploit a suspected vulnerability beyond the minimum necessary to describe an issue that was encountered lawfully;
  • access, copy, alter, download or retain another person’s data without authorisation;
  • upload or distribute malware, malicious scripts, destructive payloads or credential-stealing content;
  • conduct credential stuffing, password attacks, denial-of-service activity or similar abuse;
  • interfere with Site availability, integrity, logging, monitoring or normal operation.

Nothing in this policy creates a bug-bounty programme, security-testing licence or safe harbour for unauthorised access.

6. Reporting a suspected vulnerability

If you believe you have identified a vulnerability through lawful use of the Site, send a concise report to [email protected].

A useful report should include, where safe and lawful:

  • the affected URL or feature;
  • a clear description of the issue;
  • reproducible steps that do not expose unrelated users’ data;
  • the potential impact;
  • screenshots or technical evidence that can be shared lawfully;
  • your contact information if you want a response.

Do not publicly disclose a vulnerability before there has been a reasonable opportunity to investigate and address it. Do not demand payment, threaten disclosure, or retain personal data as leverage.

A good-faith report will be reviewed on its facts. Receipt of a report does not retroactively authorise testing that was otherwise unlawful or prohibited.

7. Personal-data incidents

A security event that affects personal data is assessed to determine:

  • what happened and whether the incident is ongoing;
  • what systems, records and people may be affected;
  • the sensitivity and volume of the information involved;
  • the likelihood and severity of harm;
  • what containment, recovery, preservation and notification steps are required.

Material incidents should be documented even where notification is not legally required.

8. UK-specific breach handling

Where the UK GDPR applies, a reportable personal-data breach must be notified to the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours after becoming aware of it. If a breach is likely to result in a high risk to affected individuals, those individuals must also be informed without undue delay, subject to applicable exceptions.

The Site’s incident process should preserve the information needed to document the nature of the breach, its effects, the risk assessment and the remedial steps taken.

9. U.S.-specific security and breach obligations

The United States does not use one single general breach-notification rule for every website. Applicable obligations may arise under federal sector-specific law or the law of one or more U.S. states, depending on the information involved, the affected residents and the circumstances.

Where a U.S. state privacy or breach-notification law applies, the relevant requirements concerning reasonable security, investigation, notice content, timing, regulator notification, consumer notification or other remedies will be assessed under that law.

If an applicable U.S. state privacy law requires risk assessments, cybersecurity audits or other governance measures because a statutory threshold or processing trigger is met, those requirements must be evaluated before the relevant activity is undertaken or by the applicable compliance deadline.

10. Data minimisation and access

Security includes reducing unnecessary exposure. Site features should collect only information reasonably needed for their function, and access to stored data should be limited to the operator and providers that need it for an authorised purpose.

User personal data submitted through ordinary Site functions is not intentionally sent to external AI services for routine prompt processing, model training or profiling as part of ordinary Site operation.

11. User responsibility for submitted information

You are responsible for ensuring that information you submit is lawful and appropriate to share. Do not submit another person’s confidential, sensitive or restricted information unless you have authority to do so and an appropriate channel is being used.

Never submit passwords, private keys, authentication secrets, recovery codes or payment-card security codes through an ordinary Site form.

12. Security complaints and rights

Security concerns that also involve personal data may be treated as privacy complaints or rights requests where appropriate. Depending on applicable law, you may have a right to receive information about a breach or complain to a regulator.

Privacy and rights requests can be sent to [email protected]. See the Privacy Notice and Data Subject Rights Request Form for additional information.

13. No security guarantee

Reasonable safeguards reduce risk but cannot eliminate every threat. To the maximum extent permitted by law, the Site does not guarantee that it will always be uninterrupted, error-free, immune from attack or free of harmful third-party activity.

Nothing in this policy excludes responsibility that cannot lawfully be excluded, including mandatory rights or remedies available under applicable consumer, privacy or security law.

14. Contact

Security concerns can be reported to:

Recep Emre Erçetin
Email: [email protected]