Legal Document · Personal Data

Privacy Policy

This Privacy Policy explains how Koray Çetintaş Advisory ("we", "us") collects, uses, stores, and protects personal data shared through koraycetintas.com. We collect only the minimum data required to deliver advisory, assessment, and contact services, and we treat that data with confidentiality, integrity, and respect for the individual.

Last updated April 13, 2026
Data controller Koray Çetintaş Advisory
01

Data controller

  • Data controller: Koray Çetintaş Advisory (Çetintaş Yazılım Danışmanlık).
  • Address: İstiklal Mah. Piyalepaşa Bulvarı 22/1 Ticari, Hanspace B Blok, Beyoğlu / İstanbul, Türkiye.
  • Contact: koray@cetintas.com.tr · +90 549 221 10 08.
02

What we collect

  • Contact details (full name, business email, phone number, company) you voluntarily submit through contact, appointment, or assessment forms.
  • Assessment lead information (responses, score, level) when you explicitly request a preliminary review or share your report by email.
  • Conversation data exchanged through the live chat widget, including the message body and approximate browser metadata.
  • Technical analytics: anonymised page views, referrer URL, device type, browser, operating system, and approximate location at country/region level.
  • Cookies required for site functionality (session, language, consent) and optional analytics cookies, only after explicit consent.
03

How we use the data

  • To respond to contact, appointment, and discovery call requests.
  • To prepare context-aware preliminary analysis discussions and to share your assessment report when you ask for it.
  • To improve site performance, content relevance, and service quality.
  • To meet legal obligations and maintain operational and audit records.
04

Legal basis for processing

  • Performance of a service or response to your explicit request (Art. 5/2(c) KVKK).
  • Legitimate interest in providing, improving, and securing our services (Art. 5/2(f) KVKK).
  • Compliance with legal obligations under Turkish and EU data protection rules.
  • Your explicit consent for non-essential analytics and marketing cookies.
05

Sharing and third-party processors

  • We do not sell or rent personal data.
  • Limited operational sub-processors may be used: hosting provider (server infrastructure), email delivery (SMTP), analytics (Google Analytics 4 with anonymised IP), and self-hosted live chat (Chatwoot).
  • Each sub-processor is bound by confidentiality and processes data only for the purpose of providing the underlying service.
  • No data is transferred to third parties for unrelated marketing.
06

Data retention

  • Contact and lead data: kept for as long as the engagement context remains relevant, and at most 24 months after last interaction unless a longer period is required by law.
  • Assessment responses: retained only for the duration needed to interpret the result with you; aggregated/anonymised data may be retained for service improvement.
  • Live chat conversations: retained for up to 12 months for support continuity.
  • Server access logs: retained for the technical minimum required for security and incident response.
07

Your rights

  • Request access to the personal data we hold about you.
  • Request correction of inaccurate or outdated data.
  • Request deletion of your data, where legally possible.
  • Object to or restrict certain types of processing.
  • Withdraw consent for analytics and marketing cookies at any time.
  • For any of these requests, contact koray@cetintas.com.tr. We respond within 30 days.
08

Security

  • TLS encryption is enforced across all pages and APIs.
  • Administrative access to data is restricted to a limited set of authorised users.
  • We follow industry-standard hardening for the WordPress core, PHP runtime, and reverse proxy layer.
  • Backups are encrypted and rotated, and access logs are monitored for anomalies.
09

Updates to this policy

  • We may update this Privacy Policy as our services evolve or as legal requirements change.
  • Material updates will be reflected by changing the "Last updated" date at the top of the page.
  • Continued use of the site after an update means you accept the revised version.
10

Related documents

Have questions?

For any request related to this document or to your personal data, please contact us. We respond to KVKK requests within 30 days.