WebTrustEngine R50
ENTR
LEGAL

Privacy

The actual data practice of a static site: no forms; measurement only with your consent; an aggregate server-log count that identifies no one.

Who is responsible

Data controller: WebTrustEngine (webtrustengine.com) — the operator of this website, which decides why and how any personal data here is processed.

This notice is published to meet the information obligation under Article 10 of the Turkish Personal Data Protection Law (KVKK). For requests under Article 11, no direct application address is published on this site at present — we are not hiding that; it is a known gap, recorded as such. When a channel is opened it will be named here, and requests will be answered within 30 days at the latest, as required by Article 13. The right people need most often — withdrawing your consent — needs no application at all: press “Measurement preference” in the footer of any page and choose “Necessary only”; measurement stops instantly and the _ga cookies are deleted (details: Cookie Policy).

What this page is

This text is general information; it is not legal advice and gives no compliance guarantee under any regulation. Its purpose is to state plainly what this website actually does — and does not do — with personal data.

What data we collect

This site is made of static files: there is no account, membership, comment, form or payment system. The site code asks for and stores no name, e-mail, phone number or other personal data from visitors.

The single exception is correspondence you initiate: once a verified channel is published, what you send and your address are used only to answer your request — the principle is written here even before the channel opens.

The second data category is measurement, and it exists only if you allow it: with your consent the site loads Google Analytics 4 (measurement ID G-3BK71Z6VVY), which records page views and may record qualifying common-extension link clicks as file_download events, plus scroll depth and video engagement, and writes the cookies _ga and _ga_3BK71Z6VVY. Before consent nothing of ours is loaded and no measurement cookie is written. Even then the site carries no heat-map, no session recorder, no A/B tool, no ad pixel and no fingerprinting technique. The source is open to inspection — the static page source contains no measurement tag at all; the consent logic lives in one readable file, assets/js/riza.js. If you decline measurement, "nothing is collected" is not a policy sentence here; it is a technically auditable state.

For contrast, list what a typical corporate site collects: analytics identifiers, ad cookies, form submissions, newsletter lists, session recordings. Four of those five do not exist here — no mechanism to collect ad cookies, form submissions, newsletter lists or session recordings was ever built. The fifth, an analytics identifier, exists only if you accept measurement, and one click takes it back. For those four items, 'we don't collect' is not a policy preference on this site but an architectural fact, verifiable by anyone in the source code.

Measurement and cookies

What runs: Google Analytics 4, measurement ID G-3BK71Z6VVY, and only after you press “Accept all”. Cookies written: _ga and _ga_3BK71Z6VVY, about two years each.

What is measured — the full list. With consent, GA4 Enhanced Measurement may emit file_download for a clicked link whose extension is on its default list, including common PDF, CSV and TXT targets. SVG, MD, WebP and PNG are not covered by default, and this site has no custom download tracking. The event records a qualifying click, not proof that a transfer completed.

The data is not anonymous. GA4 assigns your browser a client identifier, which makes the data pseudonymous: we never ask who you are, but the same browser is recognisable across visits. Ad personalisation and Google Signals are disabled in code.

Retention: event-level data is kept in Google Analytics for at most 14 months, after which Google deletes it; aggregate reports may persist longer.

Where the data goes: to Google. Google operates a global infrastructure, so the data may be processed outside Türkiye — a cross-border transfer under Article 9 of the Turkish data-protection law. Advertising features, Google Signals and ad personalisation are switched off in code.

Default and withdrawal: the default state is declined; before consent nothing of ours is loaded and no measurement cookie is written. Withdraw at any time from the “Measurement preference” button in the footer of any page (primary route) — the cookies are then deleted. Browser settings and Google’s opt-out add-on remain as secondary alternatives. Your consent is valid for 12 months and lapses whenever this text is republished in a new version; the box then asks again.

Your consent record: stored in your browser’s localStorage under the key wte-riza — not a cookie and never sent to the server. It holds the decision, its timestamp and the version of this text, and remains until you change it or clear browser data.

Legal bases are separate: measurement rests on explicit consent; the aggregate server-log count rests on legitimate interest (Article 5/2-f); correspondence you initiate rests on legitimate interest (answering your request); raw server logs rest on legal obligation and security. They are not merged under one basis.

Cookies we do not control. The hosting provider (GoDaddy / secureserver) appends its own traffic script, img1.wsimg.com/traffic-assets/js/tccl.min.js, to every page as it is served, and that script writes cookies such as _tccl_visitor, _tccl_visit and _scc_session regardless of your choice. It is not part of our package, our consent gate cannot block it, and it does not send anything to Google Analytics. Its removal has been requested on the owner’s side; until then it is declared here rather than hidden.

Complaints. If you believe your rights have been infringed you may complain to the Turkish Personal Data Protection Authority (KVKK Kurulu, kvkk.gov.tr); visitors in the European Economic Area may also address their national supervisory authority. Requests under Article 11 are answered within the statutory 30 days — see the note on the contact channel below.

Aggregate server-log counting

What it produces. Beyond consented measurement, the owner periodically reads the access records the server already keeps and turns them into an aggregate picture: page views and day-unique visitors per day, language distribution, the most-read pages, and where requests came from. Nothing else.

Why it needs no consent. It reads records the server writes anyway. Nothing is written to your device and nothing is read from it — no cookie, no local storage, no identifier — so it falls outside the scope of cookie/ePrivacy consent. Because an IP address is personal data, the processing rests on legitimate interest (Article 5/2-f): knowing whether the site is read at all, without following any individual.

Honesty clause. Even if you decline measurement or choose “Necessary only”, your request still appears in the server record and is therefore included in this aggregate count. That does not mean data goes to Google — it does not.

What is kept and what is not. The report contains no IP address. For day-unique counting, IP and user-agent are hashed with a random salt that is generated afresh on every run and never written to disk, so no row can be traced back to a person. Bot and crawler traffic is filtered out; asset requests are ignored. No per-person profile is built and there is no cross-site tracking.

Legal basis and retention. The counting rests on legitimate interest; keeping the raw logs themselves is the hosting provider’s legal obligation and their retention period governs.

Server logs

Like any web host, the server this site runs on may keep access logs (IP address, timestamp, requested page, browser string). Such logs are the hosting provider’s standard security and debugging practice; the site owner does not use them for marketing or profiling.

Log retention and format follow the hosting provider's own policy; the site owner does not export raw logs, share them with third parties, or turn them into per-visitor analysis. Looking at logs in exceptional cases — say, suspected abuse — serves understanding misuse of the system, never profiling a visitor.

Rather than hiding that logs exist, we draw their limit: the owner's access to them is whatever the hosting panel exposes, they are not shared with third parties, never fed into marketing systems, and rotate away on reasonable schedules. Should a legal obligation arise, action is taken only on a properly formed request from the competent authority and strictly within its scope.

Third parties

Pages contain no advertising, no social pixels and no external font or service calls. All CSS, JavaScript, images and documents are served from this domain. The single exception is measurement: if and only if you accept, your browser also requests googletagmanager.com and sends page-view events to Google Analytics. Until you accept, your browser sends requests nowhere else.

The choice also buys resilience: a page that calls no external domain cannot be broken by that domain's outage or policy change. For the visitor the practical consequence is simple: unless you have accepted measurement, every byte you see here comes from the domain in the address bar, and that claim is verifiable in your browser's network tab within seconds.

This choice protects performance and privacy at once: no external font servers (system fonts are used), no social widgets, and the only external script is the consent-gated measurement tag. Your browser's network tab is the live proof — open the page and, until you accept measurement, you will see only webtrustengine.com addresses in the request list.

Retention and deletion

Since the site stores no visitor data, there is nothing to delete on the site side. E-mail threads are kept until your request concludes and for a reasonable archive period; write to the same address to have them removed.

Correspondence that turns into a service relationship puts client files under a separate regime: working copies are kept for the duration of the engagement, move to archive order at delivery, and are destroyed on request — a regime stated in writing in the agreement. The website itself hosts none of those files in any form.

Your rights

Data-protection law where you live may grant you rights such as access, correction and erasure. No direct application address is published on this site at present; when a channel is opened it will be named here. Withdrawing consent needs no application — you can do it yourself from the “Measurement preference” button in the footer of any page, and it stops measurement immediately.

The honest description of the request flow: identity is verified only to be sure the request concerns your own correspondence, with the minimum data possible; the reply comes within a reasonable time and rests on the actual practice this page describes. If you did not accept measurement, the site keeps no record about you and most requests have a one-sentence answer — not an evasion but the consequence of the architecture. If you did accept, a pseudonymous record exists on the Google Analytics side; access and erasure requests cover that record too.

If identity verification is needed to answer a request, only the minimum required to validate it is asked; nothing more is requested or retained. Answers are given within 30 days at the latest, as required by Article 13 of the Turkish data-protection law, and reference the real practice on this page in plain language rather than legal jargon.

Children and international transfer

The site is not directed at children and asks for no age information or personal detail of any kind, so it does not knowingly process children’s data. If measurement is accepted, the visit is measured regardless of the visitor’s age (see “Children’s privacy”). On international transfer: if you allow measurement, page-view and related event data is transferred to Google and may be processed outside Türkiye (a cross-border transfer under Article 9); if you do not, no such transfer occurs. Apart from measurement no visitor data is collected, and your e-mail correspondence travels on the infrastructure of the e-mail provider you use.

Changes and questions

If practice changes, this page is updated and — per the site’s release discipline — the change enters the manifest/checksum records. Questions about this page — and requests under Article 11 of the Turkish data-protection law (access, correction, erasure, withdrawal of consent) — will follow the application channel once one is opened; the statutory 30-day period runs from the moment a request reaches us. The site deliberately publishes no direct address yet; when a verified channel is published, it will be named here as the point of application. If your question is “does the site process X?”, the answer is most likely already here: if you did not accept measurement, it does not; if you did, only the measurement data listed on this page is processed.

How this page relates to the engine

In WebTrustEngine's 10-domain model, 'Privacy / Cookie Readiness' is a domain of its own: the engine classifies visible tracking signals, cookie notices and third-party calls on the sites it reviews. This page is that same lens turned on this site — we do not exempt ourselves from the audit we describe.

The symmetry hands you a practical test: reading any vendor's privacy page, ask 'does their site do what it says?'. Alignment of word and behaviour is the cheapest and sturdiest measure of trust in this field.

Children's privacy

The site carries corporate content for a general audience; it contains no children's sections, gamification or data-collecting interactions. No personal data — age included — is requested from any visitor; the site does not separate visitors by age and does not knowingly process children's data. That said, if measurement is accepted, the visit is measured like any other whatever the visitor's age — pseudonymously, with no profile built. We cannot know that a child has visited; measurement can be switched off by any visitor from the “Measurement preference” button in the footer.