Last updated: 05/08/2026
This page is for visitors covered by the EU General Data Protection Regulation (GDPR). It complements the Privacy Policy: what data is processed is set out there, while the rights the GDPR gives you and how to exercise them are set out here.
If you are resident in Türkiye, the Personal Data Protection Law No. 6698 (KVKK) grants you comparable rights, and the routes below apply to those requests too.
1. Data Controller
Azad Furkan ŞAKAR
Diyarbakır, Türkiye
[email protected]
The scale of processing does not require the appointment of a Data Protection Officer. All data protection correspondence can be sent to the address above.
2. Processing Activities and Legal Bases
| Activity | Data | Art. 6 basis |
|---|---|---|
| Sending the newsletter | Email address, language preference | 6(1)(a) — consent |
| Proof of consent | IP address, user agent, signup timestamp, signup page | 6(1)(c) — legal obligation |
| Server logs | IP address, request metadata | 6(1)(f) — legitimate interest (security) |
| Visit statistics | Cookie identifiers, page views | 6(1)(a) — consent |
Where processing rests on legitimate interest, that interest is keeping the site secure and detecting abuse. You may object to it.
3. Automated Decision-Making
No automated decision-making or profiling is carried out about you.
4. Where Data Is Stored
The site is hosted in Hetzner Online GmbH's data centre in Germany, so data is held within the EU.
The following providers act as processors and may transfer data outside the EU:
- Cloudflare, Inc. (USA) — DNS, security and content delivery, under the EU Standard Contractual Clauses and the EU–US Data Privacy Framework.
- Google Ireland Ltd. (Ireland) — visit statistics, only if you consented. Google's transfers to the US fall under the same framework.
- Gmail — newsletter delivery.
5. Retention
- Newsletter record: until you unsubscribe, then kept for 365 days so the address is not mailed again, then deleted.
- Server logs: 30 days
- Cookie consent: 12 months in your browser
6. Your Rights Under the GDPR
- Access (Art. 15) — Request a copy of the data held about you.
- Rectification (Art. 16) — Have inaccurate or incomplete data corrected.
- Erasure (Art. 17) — Have your data deleted.
- Restriction (Art. 18) — Have processing limited.
- Portability (Art. 20) — Receive your data in a structured, machine-readable format.
- Objection (Art. 21) — Object to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)) — Withdraw consent at any time. This does not affect the lawfulness of processing carried out before the withdrawal.
7. How to Exercise Your Rights
Send your request to [email protected]. Simply state which right you want to exercise. There is no charge.
Requests are answered within one month. Where a request is complex, that period may be extended by a further two months; you will be told within the first month if that happens.
Additional information may be requested to verify that the request really comes from you. For newsletter matters, writing from the subscribed email address is enough.
Faster routes
- Leaving the newsletter: the link at the bottom of every email — immediate, no request needed.
- Withdrawing cookie consent: the cookie settings link in the footer.
8. Right to Complain
If you are unhappy with how your request was handled, you have the right to lodge a complaint with the data protection authority of your EU member state. The list of authorities is on the European Data Protection Board website.
If you are resident in Türkiye, you may apply to the Personal Data Protection Authority (KVKK).
9. Breach Notification
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, the competent supervisory authority will be notified within 72 hours and affected individuals will be informed without undue delay.
10. Changes
This policy may be updated. The current version takes effect on the date it is published on this page.


