Last Updated: August 18, 2026
This Data Protection Notice has been prepared to inform individuals about personal data-processing activities carried out by Webrote under Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”).
The Notice covers basic information about personal data that may be processed when the webrote.com website is visited, a contact or project request is submitted, a comment is posted, communication takes place by email or users interact with other features of the website.
Identity of the Data Controller
For personal data-processing activities carried out through webrote.com under Türkiye’s Personal Data Protection Law No. 6698, the data controller is Webrote.
- Website: https://www.webrote.com/
- Email: info@webrote.com
What Personal Data May Be Processed?
Depending on the nature of your interaction with Webrote, the following categories of personal data may be processed:
- Identity information: First name and last name.
- Contact information: Email address, telephone number and other contact information you provide.
- Request and communication information: Enquiry subject, project subject, message content, project descriptions and other information you provide to Webrote.
- Comment information: Information provided in comment forms, display name, comment content and website information where provided.
- Transaction security and technical information: IP address, user-agent, device and browser information, access time, visited or requested URL, referring page, HTTP records and similar technical logs.
- Analytics and usage information: Technical and statistical information relating to visited pages, traffic sources, device and browser characteristics and general website usage and interactions.
Webrote does not intend to request sensitive personal data as part of its ordinary activities. Users are advised not to enter sensitive personal data or other sensitive information in contact, project or comment fields unless it is necessary for the request to be evaluated or the relevant content to be published.
Purposes and Legal Grounds for Processing Personal Data
Personal data may be processed for the following purposes and on the following legal grounds, depending on the nature of the relevant processing activity:
| Processing Activity | Purpose of Processing | Legal Ground |
|---|---|---|
| Contact and project requests | Receiving, evaluating and responding to requests and conducting proposal and project discussions | Where directly related to the establishment or performance of a contract, Article 5(2)(c) of the KVKK; where appropriate, legitimate interests under Article 5(2)(f) |
| Comments and user contributions | Receiving, publishing and moderating comments and preventing abuse | Legitimate interests under Article 5(2)(f) of the KVKK, provided that the fundamental rights and freedoms of the individual are not adversely affected |
| Technical and security records | Operating and securing the website, identifying errors and investigating or preventing attacks and abuse attempts | Legitimate interests under Article 5(2)(f) of the KVKK; where the relevant conditions apply, compliance with legal obligations under Article 5(2)(ç) |
| Analytics measurement | Analysing website traffic, traffic sources, usage patterns and content performance | Where explicit consent is required for analytics cookies and similar technologies, explicit consent under Article 5(1) of the KVKK |
| Legal processes | Complying with legal obligations, establishing, exercising or protecting legal rights and responding to requests from competent authorities | Applicable legal grounds under Articles 5(2)(ç) and 5(2)(e) of the KVKK |
Personal data is processed only in a manner that is relevant, limited and proportionate to the relevant processing purpose. Where a processing activity may rely on another legal ground provided by law rather than explicit consent, separate explicit consent is not sought solely for that activity.
Methods of Collecting Personal Data
Depending on your interaction with Webrote, personal data may be collected by wholly or partly automated means or by non-automated means where the data forms part of a data-recording system.
Personal data may be obtained through contact and project forms, comment areas, email communications, web-server and hosting records, security systems, cookies and similar technologies, and analytics and security services used during the operation of the website.
Cloudflare Turnstile is used to protect forms against spam, automated bot submissions and abuse. Google Analytics is used to analyse visitor traffic and general website usage patterns.
Detailed information about the use of cookies and similar technologies is available in the Cookie Policy.
Contact, Project Requests and Comments
When you use contact or project forms, personal data such as your first name, last name, email address, telephone number, enquiry or project subject and message content may be processed. This information may be used to evaluate your request, communicate with you and, where necessary, conduct proposal or project processes.
Where comments are enabled on Webrote content, information provided through comment forms, comment content and technical data associated with the comment may be processed. For approved comments, the display name provided by the user and the comment content may be visible to other visitors.
During form and comment submissions, technical records such as IP address, user-agent, device information and referring page may be recorded for security purposes, to prevent spam and abuse and, where necessary, to investigate the relevant transaction technically.
Transfer of Personal Data
Personal data may be transferred to third parties only to the extent required by the relevant processing activity and where the legal conditions provided by law are met.
| Recipient Group | Purpose of Transfer |
|---|---|
| Hosting and server infrastructure providers | Hosting and operating the website, maintaining technical security and carrying out necessary system operations |
| Email service providers | Delivering contact and project requests and conducting email communications |
| Cloudflare | Preventing spam, bot activity and abuse attempts and performing security verification |
| Google Analytics / Google | Analysing website traffic and usage performance |
| Competent public authorities and judicial or administrative bodies | Complying with legal obligations and responding to duly submitted legal requests |
| Legal or technical support providers | Providing support where necessary for a legal dispute, technical incident or security process |
Personal data is not shared for the purpose of creating commercial data lists or selling personal data to third parties as a standalone product.
International Transfers of Personal Data
Because Webrote uses technical services with international infrastructure, such as Google Analytics and Cloudflare, certain personal data may, depending on the technical structure and configuration of the relevant service, be processed through systems located outside Türkiye or transferred internationally.
Where personal data is transferred outside Türkiye, the transfer is intended to be carried out in accordance with the conditions for international transfers set out in Article 9 of Türkiye’s Personal Data Protection Law No. 6698 and other applicable legislation.
Depending on the nature of the international transfer, adequacy decisions, appropriate safeguards or other applicable transfer mechanisms provided under the law may be considered.
Retention and Security of Personal Data
Personal data is retained for as long as necessary for the purpose for which it is processed and with regard to retention obligations required by applicable law.
When determining retention periods, factors such as the purpose of processing, whether the communication or service relationship continues, legal obligations, potential disputes and security requirements may be taken into account.
Where the reasons requiring the processing of personal data cease to exist and there is no other legal reason requiring retention, the relevant data may be deleted, destroyed or anonymised in accordance with applicable law.
Webrote applies technical and administrative measures appropriate to the nature of the relevant risks and systems in order to prevent unlawful processing of or access to personal data and to maintain data securely.
Your Rights Under the KVKK
Under Article 11 of Türkiye’s Personal Data Protection Law No. 6698, you have the right to apply to the data controller in relation to your personal data; to learn whether your data is processed; to request information if it has been processed; to learn the purpose of processing and the third parties to whom it has been transferred; to request correction, deletion or destruction where the relevant conditions are met; to object to an adverse result arising from analysis carried out exclusively by automated systems; and to request compensation where you suffer damage as a result of unlawful processing.
The scope and exercise of these rights are assessed according to the nature of the request and the conditions set out in Türkiye’s Personal Data Protection Law No. 6698.
Applying to the Data Controller
You may submit requests under the KVKK to Webrote using a method permitted under the Communiqué on the Procedures and Principles of Application to the Data Controller.
Where an application is made by email, you may contact info@webrote.com using an email address that you have previously provided to Webrote and that is registered in our systems.
Your request must be clear and understandable and include the information required by applicable legislation for the application to be valid. Additional information may be requested to the extent necessary to verify the applicant’s identity or associate the request with the correct personal data.
Applications are concluded as soon as possible depending on the nature of the request and no later than thirty days. Other valid application methods provided by law and applicable legislation remain available.
This Notice and Explicit Consent
This Data Protection Notice is provided for information purposes and does not constitute an explicit-consent declaration or contractual acceptance.
Where a personal data-processing activity must rely on explicit consent, that consent is obtained separately from this Notice and in a manner that allows the individual to make a free choice.
Related Policies and Notices
Webrote’s practices relating to personal data, privacy and website use may be considered together with the following documents:
- Privacy Policy
Webrote’s approach to collecting, using, storing and protecting information. - Cookie Policy
Information relating to the use of cookies and similar technologies. - Electronic Communications Consent
Information relating to permissions and preferences for commercial electronic communications. - Terms of Use
Terms governing the use of the Webrote website and its content.
Changes to This Data Protection Notice
Webrote may update this Data Protection Notice in response to changes in personal data-processing activities, technologies used, third-party service providers or applicable legislation.
The current version of the Notice is published on this page. Where material changes are made that affect the scope of personal data-processing activities, the last updated date will also be revised.