Çerez Politikası & GDPR
Son güncelleme: 31 Ağustos 2026
1. Çerez Nedir?
Çerez (cookie); bir web sitesini ziyaret ettiğinizde tarayıcınız tarafından cihazınıza kaydedilen küçük metin dosyalarıdır. Bu dosyalar; sitenin doğru çalışması, oturumun korunması ve dil/tema gibi tercihlerinizin hatırlanması için kullanılır.
2. Kullandığımız Çerezler
| Tür | İsim / Amaç | Süre | Yasal Dayanak |
|---|---|---|---|
| Zorunlu | Oturum jetonu (JWT) · çerez değil, tarayıcının sessionStorage alanında saklanır · yalnızca uygulamada (app.u2carbon.com) | Oturum süresince | Sözleşmenin ifası · onay gerektirmez |
| Zorunlu | Cloudflare DDoS koruma çerezi · altyapı sağlayıcısı tarafından yerleştirilir | Oturum süresince | Meşru menfaat (güvenlik) |
| Tercih | Dil tercihi (tr/en) · çerez değil, tarayıcınızın localStorage alanında saklanır | Siz silene kadar | Kullanıcı deneyimi |
Şu anda analitik veya pazarlama çerezi kullanılmamaktadır. Google Analytics, Meta Pixel veya benzeri profilleme amaçlı izleme aracı yüklenmez. Ziyaret istatistikleri Cloudflare Web Analytics ile toplanır; bu araç çerez yerleştirmez, tarayıcınızda hiçbir tanımlayıcı saklamaz ve sizi siteler ya da oturumlar arasında takip etmez. Gelecekte eklenmesi durumunda, çerez yerleştirilmeden önce ayrı bir onay mekanizması sunulur ve bu politika güncellenir. Yazı tipleri Google Fonts üzerinden sunulur; bu bir izleme aracı değildir, ancak sayfalar yüklenirken IP adresiniz yazı tipi dosyalarının iletilmesi için Google'a aktarılır.
3. Çerezlerin Yönetimi
- Opsiyonel (analitik/pazarlama) çerez kullanılmadığı için onay bandı gösterilmemektedir. Yukarıdaki çerezlerin tamamı zorunlu ya da tercih çerezi olup KVKK m.5/2 ve GDPR m.6/1-(b),(f) uyarınca açık rıza gerektirmez. İleride opsiyonel çerez eklenirse, yerleştirilmeden ÖNCE onayınız istenecek ve bu politika güncellenecektir.
- Tarayıcı ayarlarınızdan tüm çerezleri silebilir veya engelleyebilirsiniz: Chrome → Ayarlar → Gizlilik ve Güvenlik → Çerezler · Firefox → Tercihler → Gizlilik ve Güvenlik · Safari → Tercihler → Gizlilik.
- Zorunlu çerezleri devre dışı bırakırsanız oturum açma ve form doldurma gibi temel özellikler çalışmayabilir.
4. GDPR · AB Veri Koruma Tüzüğü
Avrupa Birliği veya Avrupa Ekonomik Alanı'nda ikamet eden kullanıcılarımız için 2016/679 sayılı Genel Veri Koruma Tüzüğü (GDPR) hükümleri uygulanır. Bu kapsamda aşağıdaki haklara sahipsiniz:
GDPR Kapsamında Haklarınız
- Madde 15 · Erişim hakkı: Kişisel verilerinizin işlenip işlenmediğini öğrenme ve kopyasını alma
- Madde 16 · Düzeltme hakkı: Yanlış veya eksik verilerin düzeltilmesini talep etme
- Madde 17 · Silinme hakkı (Unutulma hakkı): Verilerinizin silinmesini isteme
- Madde 18 · Kısıtlama hakkı: İşlemenin kısıtlanmasını talep etme
- Madde 20 · Veri taşınabilirliği: Verilerinizi yapılandırılmış, makine tarafından okunabilir formatta alma (JSON/XLSX)
- Madde 21 · İtiraz hakkı: Meşru menfaate dayanan işlemlere itiraz etme
- Madde 22 · Otomatik karar almaya itiraz: Profilleme dahil otomatik karar almaya itiraz etme
- Madde 77 · Şikâyet hakkı: İlgili denetim otoritesine (Türkiye'de KVKK Kurumu) şikâyette bulunma
İşleme Yasal Dayanakları (GDPR m.6)
- m.6/1-a (rıza): Bülten kaydı, opsiyonel çerezler
- m.6/1-b (sözleşme): Üyelik, abonelik, hizmet sunumu
- m.6/1-c (yasal yükümlülük): Vergi, fatura, denetim kayıtları
- m.6/1-f (meşru menfaat): Güvenlik, dolandırıcılık önleme, hizmet kalitesi
5. Uluslararası Veri Transferi
Sunucularımız Türkiye ve AB sınırları içinde konumlanmıştır. Bazı altyapı sağlayıcılarımız (Cloudflare, Anthropic) verileri ABD'de işleyebilir. Bu transferler, sağlayıcıların veri işleme sözleşmeleri (DPA) ve bunların ekinde yer alan Standart Sözleşme Hükümleri (SCC) çerçevesinde yürütülür; yeterlilik kararı bulunmayan ülkelere yapılan aktarımlarda ek güvenceler uygulanır.
6. Veri Saklama Süreleri
- Hesap verileri: hesap kapatıldıktan sonra 30 gün içinde silinir
- Emisyon verileri ve raporları: raporlama döneminin bitiminden itibaren 5 yıl
- Denetim kayıtları: değiştirilemez (append-only) tutulur ve SHA-256 karma zinciriyle mühürlenir; silinmesi kaydın bütünlük kanıtını yok edeceği için hesap sonlandıktan sonra da ilgili mevzuatın öngördüğü zamanaşımı süresince saklanır
- Onam kayıtları: onamın geri çekilmesinden itibaren 3 yıl
- Ödeme ve fatura kayıtları: vergi mevzuatı gereği 10 yıl
7. Veri Sorumlusu Temsilcisi
AB Genel Veri Koruma Tüzüğü m.27 kapsamında AB temsilcisi atanması yükümlülüğü değerlendirilmektedir. Şu an için tüm taleplerinizi doğrudan veri sorumlusuna iletmeniz gerekmektedir.
8. İletişim ve Şikâyet
Veri Sorumlusu: U2 AI Studio Teknoloji Anonim Şirketi · Ahi Evran OSB Mah. Erkunt Cad. No: 3 İç Kapı No: 41 Sincan/Ankara, Türkiye
Çerez ve GDPR ile ilgili tüm sorularınız için: [email protected]
Türkiye'de denetim otoritesine başvuru: www.kvkk.gov.tr
AB'de denetim otoritesine başvuru: edpb.europa.eu
Cookie Policy & GDPR
Last updated: 31 August 2026
1. What Is a Cookie?
A cookie is a small text file stored on your device by your browser when you visit a website. These files are used to ensure the website functions properly, to maintain your session, and to remember your preferences such as language and theme.
2. Cookies We Use
| Type | Name / Purpose | Duration | Legal Basis |
|---|---|---|---|
| Strictly necessary | Session token (JWT) · not a cookie; stored in the browser's sessionStorage · application only (app.u2carbon.com) | For the duration of the session | Performance of a contract · no consent required |
| Strictly necessary | Cloudflare DDoS protection cookie · set by the infrastructure provider | For the duration of the session | Legitimate interest (security) |
| Preference | Language preference (tr/en) · not a cookie; stored in your browser localStorage | Until you clear it | User experience |
At present, no analytics or marketing cookies are used. Google Analytics, Meta Pixel, or similar profiling trackers are not loaded. Visit statistics are collected with Cloudflare Web Analytics, which sets no cookies, stores no identifier in your browser and does not track you across sites or sessions. Should any be added in the future, a separate consent mechanism will be presented before any such cookie is placed, and this policy will be updated. Fonts are served by Google Fonts; this is not a tracking tool, but when pages load your IP address is transmitted to Google to deliver the font files.
3. Managing Cookies
- Because no optional (analytics or marketing) cookies are used, no consent banner is displayed. All cookies listed above are strictly necessary or preference cookies and require no explicit consent under KVKK art. 5/2 and GDPR art. 6(1)(b),(f). Should optional cookies be introduced, your consent will be obtained BEFORE they are placed and this policy will be updated.
- You may delete or block all cookies through your browser settings: Chrome → Settings → Privacy and Security → Cookies · Firefox → Preferences → Privacy & Security · Safari → Preferences → Privacy.
- If you disable strictly necessary cookies, core features such as signing in and submitting forms may not work.
4. GDPR · EU General Data Protection Regulation
For users residing in the European Union or the European Economic Area, the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR) apply. In this context, you have the following rights:
Your Rights Under the GDPR
- Article 15 · Right of access: to learn whether your personal data is being processed and to obtain a copy of it
- Article 16 · Right to rectification: to request the correction of inaccurate or incomplete data
- Article 17 · Right to erasure (right to be forgotten): to request the deletion of your data
- Article 18 · Right to restriction of processing: to request that processing be restricted
- Article 20 · Right to data portability: to receive your data in a structured, machine-readable format (JSON/XLSX)
- Article 21 · Right to object: to object to processing based on legitimate interest
- Article 22 · Automated individual decision-making: to object to automated decision-making, including profiling
- Article 77 · Right to lodge a complaint: to lodge a complaint with the competent supervisory authority (in Türkiye, the Personal Data Protection Authority (KVKK))
Legal Bases for Processing (GDPR Art. 6)
- Art. 6(1)(a) (consent): newsletter subscription, optional cookies
- Art. 6(1)(b) (contract): membership, subscription, provision of services
- Art. 6(1)(c) (legal obligation): tax, invoicing, and audit records
- Art. 6(1)(f) (legitimate interest): security, fraud prevention, service quality
5. International Data Transfers
Our servers are located within Türkiye and the EU. Some of our infrastructure providers (Cloudflare, Anthropic) may process data in the United States. These transfers are governed by the providers' data processing agreements (DPAs) and the Standard Contractual Clauses (SCCs) annexed to them; additional safeguards are applied to transfers to countries without an adequacy decision.
6. Data Retention Periods
- Account data: deleted within 30 days after the account is closed
- Emission data and reports: 5 years from the end of the reporting period
- Audit records: kept append-only and sealed with a SHA-256 hash chain; because deleting them would destroy the integrity proof, they are retained after the account ends for the limitation period required by applicable law
- Consent records: 3 years from withdrawal of consent
- Payment and invoice records: 10 years, as required by tax legislation
7. Data Controller Representative
The obligation to appoint an EU representative under Article 27 of the GDPR is currently under assessment. For the time being, please submit all requests directly to the data controller.
8. Contact and Complaints
Data Controller: U2 AI Studio Teknoloji Anonim Şirketi · Ahi Evran OSB Mah. Erkunt Cad. No: 3 İç Kapı No: 41 Sincan/Ankara, Türkiye
For all questions regarding cookies and the GDPR: [email protected]
Complaints to the supervisory authority in Türkiye: www.kvkk.gov.tr
Complaints to a supervisory authority in the EU: edpb.europa.eu