Website Visitor Privacy Notice and Cookie Statement
B.1. Purpose and scope
B.1.1. This notice sets out how Zerone Siber Güvenlik Limited Şirketi (Zerone) processes the personal data of visitors to its corporate and marketing website, and declares the cookies and similar technologies used on that site. It is issued under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (the Law) and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform (Official Gazette 10/3/2018, No. 30356). For visitors in the European Economic Area it also serves as the information notice required by Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and, as regards storage on and access to terminal equipment, by Article 5(3) of Directive 2002/58/EC as amended by Directive 2009/136/EC.
B.1.2. This notice covers website visitors only. Users of the Zero Door application console are informed through ../02-veri-koruma/20-aydinlatma-metni.md and ../02-veri-koruma/21-privacy-notice.md, and the console’s cookie and browser storage declaration is made in ../02-veri-koruma/23-cerez-politikasi.md. Findings recorded for the console shall not be extended to this website, and findings recorded here shall not be extended to the console; the two surfaces are separate software on separate domains with separate configurations.
B.1.3. This notice is built on the principle that each tool is declared individually. No cookie, pixel, embedded content, measurement script or browser storage item may be used on the site unless it has a row in the table at B.5.2. Bringing a tool into use is conditional upon the declaration elements listed in B.5.3 being completed in that table and an updated version of this notice being published.
B.2. Identity of the controller
Controller: Zerone Siber Güvenlik Limited Şirketi MERSIS number: 0998199408600001 · Trade registry number: 98809 (Adana Chamber of Commerce, chamber registry number: 95025) Tax office: Ziyapaşa Tax Office · Tax identification number: 9981994086 Address: Yenibaraj Mahallesi, Nursultan Nazarbayev Bulvarı No: 1, İç Kapı No: 3, Seyhan / Adana, Türkiye Telephone: +90 507 806 21 37 · E-mail: contact@zeronesecurity.com · Requests: privacy@zeronesecurity.com Contact person for data protection: Hüseyin Volkan Akyüz, Managing Director
B.3. Visitor data processed
B.3.1. The site does not ask visitors for identity documents. The following data are processed according to the nature of the visit and of the visitor’s own action.
| # | Category | Data processed | Method of collection |
|---|---|---|---|
| V1 | Server logs | IP address, browser identifier (User-Agent), date and time of the request, page requested, response code, referring address | Wholly automated, upon the request reaching the server |
| V2 | Contact form and demonstration request | Name and surname, business e-mail address, telephone number, company name and role, free-text content of the request | By the individual completing and submitting the form of their own volition |
| V3 | Newsletter subscription | E-mail address, subscription date, channel through which consent was obtained and the consent record | By the individual subscribing |
| V4 | Job application | Information disclosed by the candidate in the application form and curriculum vitae | By the candidate applying. Information for this category is given in ../02-veri-koruma/35-calisan-ve-aday-aydinlatma-metni.md |
| V5 | Data obtained through cookies and similar technologies | The data declared item by item in the table at B.5.2 | Through access to the visitor’s terminal equipment |
B.3.2. Zerone does not request special categories of personal data through the site. Content that an individual chooses to enter into a free-text field is not within Zerone’s control; individuals are expected not to enter information that has not been requested.
B.3.3. No processing is carried out on the site that produces legal effects concerning the visitor, or similarly significantly affects them, through automated decision-making or profiling.
B.4. Purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| V1 | Delivering the site, maintaining its availability, diagnosing faults | Law Art. 5(2)(f): legitimate interest in operating the site. GDPR Art. 6(1)(f) |
| V1 | Information security, detection and investigation of abuse and attacks | Law Art. 5(2)(f) together with Art. 5(2)(ç): compliance with the security obligation under Art. 12(1). GDPR Art. 6(1)(f) and, where applicable, Art. 6(1)(c) read with Art. 32 |
| V2 | Responding to the request, contacting the individual, arranging a demonstration or introductory meeting | Law Art. 5(2)(f): legitimate interest in responding to a business enquiry; and Art. 5(2)(c) where the requester is personally the prospective contracting party. GDPR Art. 6(1)(f), and Art. 6(1)(b) in that same case |
| V2 | Retaining the request and correspondence for evidential purposes | Law Art. 5(2)(f) and Art. 5(2)(e): establishment, exercise or defence of legal claims. GDPR Art. 6(1)(f) |
| V3 | Sending commercial electronic communications, newsletters and marketing content | Law Art. 5(1): explicit consent. Prior consent is additionally required by Article 6 of Law No. 6563 on the Regulation of Electronic Commerce. GDPR Art. 6(1)(a). See ../02-veri-koruma/22-acik-riza-metni-pazarlama.md and 63-ticari-elektronik-ileti-ve-iys.md |
| V3 | Retaining consent and objection records | Law Art. 5(2)(ç): retention obligation under Article 12 of the Regulation on Commercial Communication and Commercial Electronic Messages (Official Gazette 15/7/2015, No. 29417). GDPR Art. 6(1)(c) |
| V4 | Assessing the job application | ../02-veri-koruma/35-calisan-ve-aday-aydinlatma-metni.md, Section A.9 |
| V5 | Strictly necessary and functional items | Law Art. 5(2)(f); GDPR Art. 6(1)(f), with the storage exempt from consent under Art. 5(3) of Directive 2002/58/EC |
| V5 | Analytics, performance, marketing and targeting items | Law Art. 5(1): explicit consent, obtained before the item is brought into use and separately per category. GDPR Art. 6(1)(a) with Art. 5(3) of Directive 2002/58/EC |
B.4.1. Newsletter subscription and the contact form are separate acts. Submitting a contact form or a demonstration request does not constitute a subscription or consent to marketing messages. Subscription is taken through a separate, optional and unticked box. Under Article 6(1) of Law No. 6563, where an individual provides contact details for the purpose of being contacted, no separate consent is required for messages concerning changes to, use of and maintenance of the service supplied; that exception does not extend to promotional or campaign messages.
B.4.2. Merchant and tradesperson recipients. Under Article 6(2) of Law No. 6563, commercial electronic messages may be sent to merchants and tradespersons without prior consent. This is not an exemption from the Message Management System: their addresses are recorded in that system and, before each dispatch, it is checked whether the right to object has been exercised.
B.5. Cookies and similar technologies
B.5.1. Categories. Items that may be used on the site fall into four categories according to their function. The category determines the consent regime for the item.
| Category | Definition | Consent required |
|---|---|---|
| Strictly necessary | Items technically required to deliver the service the visitor has expressly requested: session, security, load balancing and the record of the consent choice | No |
| Functional | Items that remember a preference the visitor has expressed by their own express action, such as language or display | No, provided the item carries no identifier and is written on the visitor’s express action |
| Performance / analytics | Items serving the measurement of visit statistics, page views and usage behaviour | Yes, prior explicit consent |
| Marketing / targeting | Items serving advertising delivery, conversion measurement, profiling and cross-site tracking | Yes, prior explicit consent |
B.5.2. Declaration table. The following table is the complete list of items used on the site.
| Item | Setting party and domain | Technology | Category | Purpose | Lifetime or retention | Consent | Third-country transfer |
|---|---|---|---|---|---|---|---|
zd_cookie_consent | First party, zeronesecurity.com | Cookie | Strictly necessary | Recording the visitor’s cookie choice and the date on which it was made | 6 months | Not required | None |
| Server access log | First party, hosting layer | Not a cookie; server-side record | Strictly necessary | Security, abuse detection, fault diagnosis | 12 months | Not required | The hosting country declared at B.6.1 |
«işlevsel kalem adı» | «işlevsel kalem tarafı ve alan adı» | «çerez, yerel depolama veya oturum depolaması» | Functional | «işlevsel kalem amacı» | «işlevsel kalem ömrü» | Not required | «işlevsel kalem aktarım durumu» |
«analitik aracı kalem adı» | «analitik sağlayıcısı unvanı ve alan adı» | «çerez, piksel veya yerel depolama» | Performance / analytics | «analitik kalem amacı» | «analitik kalem ömrü» | Required, prior | «analitik sağlayıcısı aktarım ülkesi ve güvence» |
«pazarlama veya izleme pikseli adı» | «pazarlama sağlayıcısı unvanı ve alan adı» | «çerez veya piksel» | Marketing / targeting | «pazarlama kalemi amacı» | «pazarlama kalemi ömrü» | Required, prior | «pazarlama sağlayıcısı aktarım ülkesi ve güvence» |
«gömülü içerik veya video oynatıcı adı» | «gömülü içerik sağlayıcısı unvanı ve alan adı» | «çerez, yerel depolama veya betik» | «gömülü içerik kategorisi» | «gömülü içerik amacı» | «gömülü içerik ömrü» | «gömülü içerik rıza durumu» | «gömülü içerik aktarım ülkesi ve güvence» |
B.5.3. Elements that must be declared for every item entered in the table. Before a cookie, pixel, script, font, map, video player, chat component or similar item is brought into use on the site, all eight of the following elements shall be determined for that item and entered into the table at B.5.2:
- the name or identifier of the item;
- the name of the party that sets it and the domain on which it is set, and whether it is first party or third party;
- the technology: cookie, tracking pixel, local storage, session storage, embedded script or fingerprinting technique;
- which of the four categories at B.5.1 it falls into;
- its purpose, expressed in specific, explicit and legitimate terms; general or vague wording may not be used;
- its lifetime, or the retention period of the data obtained;
- whether consent is required and, if so, on which surface and how it will be obtained;
- where the item gives rise to a transfer abroad, the recipient, the country and the safeguard relied upon under Article 9 of the Law and Chapter V of the GDPR.
B.5.4. If any of the above elements cannot be determined, the item shall not be brought into use. A tool may run on the site only where a completed row-level declaration has been published in this notice. This rule applies equally where the tool is free of charge, where it forms part of a provider’s default configuration, and where it has been added only for trial purposes.
B.5.5. Consent banner. For as long as the table at B.5.2 contains an item categorised as performance, analytics, marketing or targeting, a consent management surface (a consent banner) shall be displayed on the site and all of the following conditions shall be satisfied:
- Priority. No item outside the strictly necessary category is written, and no third-party script is loaded, before consent is obtained. An analytics or marketing item that runs on page load does not become lawful through consent obtained afterwards.
- Granularity by category. Consent is given and withdrawn separately for each category. A single “accept all” box is not sufficient.
- Refusal as easy as acceptance. The first layer of the banner offers a “reject” option of equal prominence to “accept” and reachable in the same number of clicks.
- No pre-ticked boxes. No option outside the strictly necessary category is pre-selected. Silence, scrolling and dismissing the banner do not constitute consent.
- No conditioning of access. Access to site content is not made conditional upon acceptance of non-essential items.
- Withdrawal. Consent may be withdrawn at any time and as easily as it was given, through a persistent link available from every page. Withdrawal takes effect prospectively.
- Record. The category, date, version of the notice displayed and channel through which consent was obtained are recorded. The burden of proof lies with Zerone.
B.5.6. The consent surface is separate from this notice. Pursuant to principle decision No. 2026/347 of the Personal Data Protection Board dated 18/02/2026, explicit consent and the obligation to inform shall be discharged separately. Accordingly, the consent banner is not made conditional upon acceptance of this notice and no acceptance box is attached to this notice. The banner links to this notice; the only thing asked of the visitor is a choice as to the categories for which consent is required.
B.5.7. Browser controls. Independently of the consent banner, visitors may inspect, delete and block cookies and site data through their browser settings, on a per-domain basis or in full. In common browsers these controls are found under “Settings” within “Privacy and security” or “Cookies and site data”. In a private or incognito window, both cookies and browser storage are deleted when the window is closed. Blocking strictly necessary items may prevent parts of the site from working; that is a technical consequence of the relevant function rather than a restriction chosen by Zerone.
B.6. Transfers and third-country transfer assessment
B.6.1. Hosting. The corporate website is hosted by «tanıtım sitesi barındırma sağlayıcısının unvanı» in «tanıtım sitesi barındırma ülkesi». The hosting provider is a processor hosting the server logs and site content.
B.6.2. E-mail. Correspondence arising from the contact form, demonstration requests and the newsletter is handled through electronic mail infrastructure operated by «kurumsal e-posta sağlayıcısının unvanı» in «kurumsal e-posta sunucularının konumu».
B.6.3. Analytics and marketing providers. Where such a provider is used, its identity, the categories of data transferred and the transfer safeguard are declared row by row in the table at B.5.2. No transfer is made to a provider that does not appear in that table.
B.6.4. Third-country transfer regime. Where Zerone, established in Türkiye, has personal data processed on the systems of a provider located abroad, that constitutes a transfer abroad within the meaning of Article 9 of the Law. The Board has to date issued no adequacy decision in respect of any country; the fact that a recipient is located in a European Union Member State does not of itself render the transfer permissible. Accordingly, for each recipient located abroad under B.6.1 to B.6.3, the standard contract published by the Board under Article 9(4)(c) of the Law is executed and notified to the Authority within five business days of completion of signatures, in accordance with Article 14 of the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad. Depending on the capacities of the parties, either the controller-to-processor or the processor-to-processor standard contract is used. Where the GDPR applies to a transfer out of the European Economic Area, the standard contractual clauses of Commission Implementing Decision (EU) 2021/914 are used together with a transfer impact assessment.
B.6.5. Other disclosures. Beyond the recipients set out above, personal data are disclosed only to public authorities empowered by law, limited to the legal provision relied upon and the subject matter of the request, under Article 8(2)(a) of the Law. Zerone does not sell or rent visitor data and does not make it available to third parties for advertising purposes.
B.7. Retention periods
| Data | Period | Basis |
|---|---|---|
| V1 server logs | 12 months, then deleted | Proportionality under Law Art. 4(2)(d) and GDPR Art. 5(1)(e); the minimum period needed to investigate security events retrospectively |
| V2 contact form and demonstration request | «web formu saklama süresi». Where a request results in a contractual relationship, the data become subject to the retention regime of that relationship | Law Art. 4(2)(d); legitimate interest in evidencing the request and the correspondence |
| V3 newsletter subscription | For as long as the subscription lasts, until consent is withdrawn; on withdrawal the address is removed from the distribution list | Law Art. 5(1) and Art. 7(1); GDPR Art. 7(3) and Art. 17(1)(b) |
| V3 consent and objection records | Three years from the date on which the validity of the consent ends | Article 12 of the Regulation on Commercial Communication and Commercial Electronic Messages |
| V4 job application | One year from the date of application; two years where retained in the candidate pool with explicit consent | ../02-veri-koruma/35-calisan-ve-aday-aydinlatma-metni.md, Section A.9 |
| V5 cookies and similar technologies | The lifetime declared item by item in the table at B.5.2 | Law Art. 4(2)(d) |
B.7.1. Data whose period has expired are deleted, destroyed or anonymised within Zerone’s periodic destruction cycle. Zerone’s retention and destruction regime as a whole is set out in ../02-veri-koruma/30-saklama-ve-imha-politikasi.md.
B.8. Rights of data subjects and how to exercise them
B.8.1. Under Article 11 of the Law, data subjects have the right to learn whether their personal data are processed, to request information where they have been processed, to learn the purpose of the processing and whether the data are used in accordance with that purpose, to know the third parties to whom the data are transferred in Türkiye or abroad, to request rectification where the data are incomplete or inaccurate, to request erasure or destruction within the conditions of Article 7, to request that rectification, erasure and destruction be notified to third parties to whom the data have been transferred, to object to an adverse outcome arising from analysis by exclusively automated means, and to claim compensation for damage suffered as a result of unlawful processing.
B.8.2. Where the GDPR applies, data subjects additionally have the rights of access, rectification, erasure, restriction of processing, data portability and objection under Articles 15 to 21, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. They also have the right to lodge a complaint with a supervisory authority in the Member State of their habitual residence, place of work or place of the alleged infringement.
B.8.3. Requests may be submitted:
(a) in writing, by wet-signed letter delivered to or served at Yenibaraj Mahallesi, Nursultan Nazarbayev Bulvarı No: 1, İç Kapı No: 3, Seyhan / Adana;
(b) signed with a qualified electronic signature or mobile signature and sent to kvkk@zeronesecurity.com;
(c) from an e-mail address previously notified to Zerone and registered in Zerone’s systems, sent to kvkk@zeronesecurity.com.
Requests under the GDPR may also be addressed to privacy@zeronesecurity.com. The form at ../02-veri-koruma/33-ilgili-kisi-basvuru-formu.md may be used.
B.8.4. Under Article 5(2) of the Communiqué on the Procedures and Principles of Application to the Data Controller (Official Gazette 10/3/2018, No. 30356), an application must contain the applicant’s name and surname and, where the application is in writing, a signature; for Turkish citizens the Turkish identity number, and for foreign nationals their nationality, passport number or identity number if any; the address of residence or place of business for service; the e-mail address, telephone and fax number, if any, for notification; and the subject matter of the request. Supporting information and documents shall be annexed.
B.8.5. Requests are concluded free of charge as soon as possible and in any event within thirty days. Where the operation entails an additional cost, the tariff in Article 7 of that Communiqué applies: no charge is made for a written response of up to ten pages, and one Turkish Lira per page may be charged beyond ten pages; where the response is provided on a recording medium, the charge may not exceed the cost of that medium. Any charge collected is refunded where the application arises from an error on Zerone’s part. Requests falling under the GDPR are answered within one month, extendable by two further months where necessary having regard to the complexity and number of the requests, with the data subject informed of any extension within the first month.
B.8.6. Where a request is refused, the response is found inadequate or no response is given in time, the data subject may complain to the Personal Data Protection Board under Article 14 of the Law. That route is available only after the application to Zerone has been exhausted.
B.8.7. The right to refuse commercial electronic messages is independent of the rights under the Law and is exercised without reason, free of charge and by simple means. A refusal may be communicated through the channel on which the message was received or through the Message Management System, and dispatch is stopped within three business days of the refusal being received.
B.9. Updates
B.9.1. This notice is updated whenever the cookies, pixels, scripts or browser storage items used on the site change, whenever a new form or processing purpose is added, and whenever the recipients of transfers change. A new item is entered into the table at B.5.2 before it is brought into use, and an item that is removed is deleted from the table.
B.9.2. The version date is raised on each update and the current text is published at https://zeronesecurity.com/legal/. Where a material change is made, such as the addition of a new non-essential category, consent is obtained afresh before the change takes effect; a new category may not be operated in reliance on consent previously given.
Governing language. In the event of any discrepancy between the Turkish and the English text of this notice, the Turkish text prevails.