Website Visitor Privacy Notice
Last updated: 4 August 2026
1. Controllers
The controllers for the processing of personal data relating to website visitors are Attorney A and Attorney B, Attorneys at Law, practising from the same office under the title Independent Law Office.
Office address: Sample Office, Example Street, Istanbul. Email: contact@example.com. Data-protection requests: privacy@example.com. Independent Law Office is not a separate legal entity.
2. Scope
This notice explains the processing of technical data that may be generated automatically when the website is visited and the processing carried out to maintain the security and availability of the website.
The contact form and initial enquiries by telephone or email are covered by the separate “Privacy Notice for the Contact Form and Initial Enquiries”. Cookies are covered by the separate “Strictly Necessary Cookie Notice”. Once an engagement is established, additional client privacy information and contractual provisions may apply.
3. Personal Data Processed
- IP address and connection information.
- Date and time of access, page or file requested, request method and server response status.
- Browser type, operating system, device type, user-agent and language preference.
- Where transmitted, the referring URL, error logs, security events and misuse-detection records.
- Strictly necessary session and security identifiers.
The website does not identify visitors for profiling and does not process visitor data for analytics, behavioural tracking, advertising or marketing.
4. Purposes
- Providing and maintaining the operation, stability and availability of the website.
- Detecting and preventing unauthorised access, forged requests, malware, automated attacks and other security risks.
- Investigating and resolving technical faults and interruptions and monitoring systems for security purposes.
- Complying with legal obligations and, where necessary, establishing, exercising or protecting legal rights.
- Recording and evidencing information-security incidents.
5. Collection and Legal Bases
Technical data may be collected automatically and electronically when the website is accessed through the web server, hosting infrastructure, security components and strictly necessary technical cookies.
Under Turkish Personal Data Protection Law No. 6698, processing is based, as applicable, on compliance with legal obligations, the establishment, exercise or protection of rights and the legitimate interests of the controllers, provided that the fundamental rights and freedoms of the data subject are not prejudiced. No consent is requested merely for visiting the website unless a service requiring consent is introduced.
Where the General Data Protection Regulation applies, the relevant legal bases may include Articles 6(1)(c) and 6(1)(f) GDPR.
6. Recipients
Personal data may be disclosed only to the extent necessary to hosting, maintenance, software and information-security providers that are bound by confidentiality and data-protection duties. Such providers may not use the data for their own purposes.
Competent public authorities, courts, bar associations and other legally authorised recipients may receive data where required by law or necessary to protect legal rights.
7. International Transfers
Under the planned technical setup, website-visitor data are hosted in Türkiye and are not transferred abroad. Before any hosting, security, email, content-delivery or similar service involving processing outside Türkiye is introduced, an appropriate transfer mechanism under Article 9 of Law No. 6698 will be implemented and this notice will be updated to reflect the actual data flow.
Where the GDPR applies, the requirements of Chapter V GDPR will also be observed.
8. Retention
Server, error and security logs are generally retained for no longer than six months. Where the technical configuration applies a shorter period, the records are deleted or anonymised at the end of that period.
Where a security incident, legal dispute, request from a competent authority or protection of a legal right requires longer retention, only the necessary records are kept until the relevant purpose ends.
9. Cookies and Third-party Content
The website uses only strictly necessary cookies for core functions and security. It does not use analytics, advertising, behavioural tracking, social-media tracking or profiling cookies. Further information is provided in the “Strictly Necessary Cookie Notice”.
Before any third-party analytics, map, video, social-media, CAPTCHA, external-font or similar service is introduced, the data flow, international-transfer position and consent requirements will be reassessed. An effective preference and consent mechanism will be implemented where required.
10. Rights
Under Article 11 of Law No. 6698, data subjects may have the right to learn whether their personal data are processed, request information about processing, learn the purposes and whether the data are used accordingly, know the recipients, request correction of incomplete or inaccurate data, request deletion or destruction where the legal conditions are met, request notification of those actions to recipients, object to an adverse result produced exclusively by automated systems and request compensation for damage caused by unlawful processing.
Requests may be sent to privacy@example.com or through another legally recognised method, together with sufficient information to verify identity and describe the request. Unnecessary personal data should not be included.
Where the GDPR applies, additional rights may include access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests and the right to complain to a competent supervisory authority.
11. Automated Decision-making and Marketing
The website does not make solely automated decisions or create profiles that produce legal or similarly significant effects. Technical visitor information is not used for advertising or direct marketing.
12. Data Security
Appropriate technical and organisational measures are used to prevent unlawful processing or access and to protect personal data, including access controls, strong passwords and multi-factor authentication, current software, TLS/HTTPS, backups, security logging, data minimisation and service-provider controls.
Absolute security of internet transmission cannot be guaranteed. Identity documents, health information, criminal case files, banking or land-registry records and extensive litigation documents should therefore not be sent through the initial contact form.
13. Changes to this Notice
This notice will be updated if the technical infrastructure, service providers, processing activities or applicable law change. The current version and revision date will be published on this page.