1. Core Principles
- Data minimisation: only what the service genuinely requires is collected.
- Purpose limitation: data is never repurposed beyond why it was collected.
- Transparency: what is processed, and why, is stated plainly on these pages.
- Privacy by default: analytics and marketing tools do not run before consent.
2. Technical Safeguards
- All traffic is encrypted with TLS 1.3; HSTS enforces HTTPS-only connections.
- A strict Content Security Policy with nonce-signed scripts limits XSS exposure.
- Admin passwords are stored irreversibly using PBKDF2-SHA256.
- Session cookies are marked HttpOnly, Secure and SameSite=Lax.
- Forms are protected with rate limiting and bot verification.
- Backups are encrypted and restorable only through authorised access.
3. Protecting Client Documents
Your CV, reference letters and similar documents are used solely for the duration of the engagement. They are never shared with third parties or used as teaching examples. If an anonymised excerpt is ever to be shared, your written consent is obtained first.
4. Children's Data
The services are intended for people aged 18 and over. Personal data is not knowingly collected from anyone under 18; if such data is identified it is deleted without delay.
5. Breach Notification
In the event of unlawful access to personal data, the Turkish Data Protection Authority and affected individuals are notified as soon as possible and in any case within 72 hours.
6. Contact
For any privacy question or request: aynur_turkseven@hotmail.com