Privacy Policy
What data do we collect and why?
Your privacy is important to us. This Privacy Policy explains how information you share while using sukruyusufkaya.com is collected, used, protected, and what rights you have. The policy is prepared in accordance with the Turkish KVKK Law No. 6698 and EU General Data Protection Regulation (GDPR) principles.
1. Information We Collect
The website may collect two types of data: (a) Information you provide directly — name, email, phone, company name, and message content entered in contact forms, newsletter subscriptions, or training registrations. (b) Information collected automatically — IP address, browser type and version, operating system, pages visited, visit duration, referrer URL, cookie IDs, and device identifiers.
2. Purposes of Data Use
We use the collected information for: responding to contact requests, providing training and consulting services, managing invoices and contracts, sending newsletters (only with your explicit consent), analyzing and improving website performance, detecting and preventing security threats, and fulfilling legal obligations.
3. Data Security
Your data is protected with end-to-end SSL/TLS encryption. Databases (MongoDB Atlas) and hosting infrastructure (Vercel) are certified under industry-standard frameworks (ISO 27001, SOC 2). Two-factor authentication is enforced for sensitive operations. Passwords are stored as one-way bcrypt hashes; plain-text passwords are never stored.
4. Third-Party Service Providers
The website operates with the following service providers: Vercel (hosting, US), MongoDB Atlas (database, EU), Resend (email, EU), Google Analytics (analytics, US — IP anonymization enabled), Cloudinary (image CDN, EU). These providers access only the data necessary to deliver their services and are bound by KVKK/GDPR-compliant contracts.
5. Children's Privacy
The website is not directed to children under 18. We do not knowingly collect personal data from individuals under 18; if such data is detected, it is deleted immediately.
6. Automated Decision-Making
Your personal data is not subjected to fully automated processing that produces legal effects against you. If marketing profiling is performed, it requires your explicit consent which can be withdrawn at any time.
7. Third-Party Links
The website may contain links to external resources (LinkedIn, GitHub, YouTube, Medium, etc.). These sites have their own privacy policies, and Şükrü Yusuf KAYA is not responsible for the content or privacy practices of these sites.
8. Data Retention Period
Your personal data is retained for the period required by the purpose. Contact form messages are kept for 2 years, newsletter subscriptions until cancellation, and invoice/contract information for 10 years per legal requirements. After this period, data is automatically deleted or anonymized.
9. Policy Updates
This policy may be updated due to legal requirements or service changes. The current version is published on this page, and significant changes are notified via email.
10. Contact
For privacy-related questions, requests, or complaints: ee.sukruyusufkaya@gmail.com
Son güncelleme: 6/27/2026