Not: Bu belgenin hukuken bağlayıcı sürümü Türkçe metindir.
Çerez Politikası & GDPR
Son güncelleme: 28 Haziran 2026
1. Çerez Nedir?
Çerez (cookie); bir web sitesini ziyaret ettiğinizde tarayıcınız tarafından cihazınıza kaydedilen küçük metin dosyalarıdır. Bu dosyalar; sitenin doğru çalışması, oturumun korunması ve dil/tema gibi tercihlerinizin hatırlanması için kullanılır.
2. Kullandığımız Çerezler
| Tür | İsim / Amaç | Süre | Yasal Dayanak |
| Zorunlu |
Oturum kimliği, JWT token (auth) |
Oturum süresince |
Sözleşmenin ifası — onay gerektirmez |
| Zorunlu |
Cloudflare DDoS koruma çerezi |
Oturum süresince |
Meşru menfaat (güvenlik) |
| Tercih |
Dil tercihi (locale: tr/en), tema (light/dark) |
1 yıl |
Kullanıcı deneyimi |
| Tercih |
Çerez bannerı onay durumu (cookie_consent) |
1 yıl |
KVKK/GDPR yükümlülüğü |
Şu anda analitik veya pazarlama çerezi kullanılmamaktadır. Google Analytics, Meta Pixel veya benzeri üçüncü taraf izleme aracı yüklenmez. Gelecekte eklenmesi durumunda çerez bannerı üzerinden ayrı onay alınır. Yazı tipleri Google Fonts üzerinden sunulur; bu bir izleme aracı değildir, ancak sayfalar yüklenirken IP adresiniz yazı tipi dosyalarının iletilmesi için Google'a aktarılır.
3. Çerezlerin Yönetimi
- Site açılırken görüntülenen çerez bannerı aracılığıyla opsiyonel çerezleri kabul edebilir veya reddedebilirsiniz.
- Tarayıcı ayarlarınızdan tüm çerezleri silebilir veya engelleyebilirsiniz: Chrome → Ayarlar → Gizlilik ve Güvenlik → Çerezler · Firefox → Tercihler → Gizlilik ve Güvenlik · Safari → Tercihler → Gizlilik.
- Zorunlu çerezleri devre dışı bırakırsanız oturum açma ve form doldurma gibi temel özellikler çalışmayabilir.
4. GDPR — AB Veri Koruma Tüzüğü
Avrupa Birliği veya Avrupa Ekonomik Alanı'nda ikamet eden kullanıcılarımız için 2016/679 sayılı Genel Veri Koruma Tüzüğü (GDPR) hükümleri uygulanır. Bu kapsamda aşağıdaki haklara sahipsiniz:
GDPR Kapsamında Haklarınız
- Madde 15 — Erişim hakkı: Kişisel verilerinizin işlenip işlenmediğini öğrenme ve kopyasını alma
- Madde 16 — Düzeltme hakkı: Yanlış veya eksik verilerin düzeltilmesini talep etme
- Madde 17 — Silinme hakkı (Unutulma hakkı): Verilerinizin silinmesini isteme
- Madde 18 — Kısıtlama hakkı: İşlemenin kısıtlanmasını talep etme
- Madde 20 — Veri taşınabilirliği: Verilerinizi yapılandırılmış, makine tarafından okunabilir formatta alma (JSON/XLSX)
- Madde 21 — İtiraz hakkı: Meşru menfaate dayanan işlemlere itiraz etme
- Madde 22 — Otomatik karar almaya itiraz: Profilleme dahil otomatik karar almaya itiraz etme
- Madde 77 — Şikâyet hakkı: İlgili denetim otoritesine (Türkiye'de KVKK Kurumu) şikâyette bulunma
İşleme Yasal Dayanakları (GDPR m.6)
- m.6/1-a (rıza): Bülten kaydı, opsiyonel çerezler
- m.6/1-b (sözleşme): Üyelik, abonelik, hizmet sunumu
- m.6/1-c (yasal yükümlülük): Vergi, fatura, denetim kayıtları
- m.6/1-f (meşru menfaat): Güvenlik, dolandırıcılık önleme, hizmet kalitesi
5. Uluslararası Veri Transferi
Sunucularımız Türkiye ve AB sınırları içinde konumlanmıştır. Bazı altyapı sağlayıcılarımız (Cloudflare, Anthropic) verileri ABD'de işleyebilir. Bu transferler için Standart Sözleşme Hükümleri (SCC) imzalanmıştır ve yeterlilik kararı bulunmayan ülkelere yapılan transferlerde ek güvenceler uygulanır.
6. Veri Saklama Süreleri
- Hesap verileri: Hesap aktif olduğu sürece + 30 gün
- Emisyon raporları: Raporlama dönemi sonundan itibaren 5 yıl (KVKK ve audit gereksinimi)
- Denetim logları: 2 yıl
- Onam kayıtları: Onamın geri çekilmesinden itibaren 3 yıl
- Ödeme/fatura kayıtları: Vergi mevzuatı gereği 10 yıl
7. Veri Sorumlusu Temsilcisi
AB Genel Veri Koruma Tüzüğü m.27 kapsamında AB temsilcisi atanması yükümlülüğü değerlendirilmektedir. Şu an için tüm taleplerinizi doğrudan veri sorumlusuna iletmeniz gerekmektedir.
8. İletişim ve Şikâyet
Veri Sorumlusu: U2 AI Studio Teknoloji Anonim Şirketi — Ahi Evran OSB Mah. Erkunt Cad. No: 3 İç Kapı No: 41 Sincan/Ankara, Türkiye
Çerez ve GDPR ile ilgili tüm sorularınız için: [email protected]
Türkiye'de denetim otoritesine başvuru: www.kvkk.gov.tr
AB'de denetim otoritesine başvuru: edpb.europa.eu
© 2026 U2 AI Studio Teknoloji A.Ş. Tüm hakları saklıdır.
Note: This English text is an informational translation
provided for convenience. The legally binding version of this document is
the Turkish text. In case of any discrepancy, the Turkish version prevails.
Cookie Policy & GDPR
Last updated: 28 June 2026
1. What Is a Cookie?
A cookie is a small text file stored on your device by your browser when you visit a website. These files are used to ensure the website functions properly, to maintain your session, and to remember your preferences such as language and theme.
2. Cookies We Use
| Type | Name / Purpose | Duration | Legal Basis |
| Strictly necessary |
Session ID, JWT token (auth) |
For the duration of the session |
Performance of a contract — no consent required |
| Strictly necessary |
Cloudflare DDoS protection cookie |
For the duration of the session |
Legitimate interest (security) |
| Preference |
Language preference (locale: tr/en), theme (light/dark) |
1 year |
User experience |
| Preference |
Cookie banner consent status (cookie_consent) |
1 year |
Obligation under the Turkish Personal Data Protection Law No. 6698 (KVKK) / GDPR |
At present, no analytics or marketing cookies are used. Google Analytics, Meta Pixel, or similar third-party tracking tools are not loaded. Should any be added in the future, separate consent will be obtained via the cookie banner. Fonts are served by Google Fonts; this is not a tracking tool, but when pages load your IP address is transmitted to Google to deliver the font files.
3. Managing Cookies
- You may accept or reject optional cookies via the cookie banner displayed when the site loads.
- You may delete or block all cookies through your browser settings: Chrome → Settings → Privacy and Security → Cookies · Firefox → Preferences → Privacy & Security · Safari → Preferences → Privacy.
- If you disable strictly necessary cookies, core features such as signing in and submitting forms may not work.
4. GDPR — EU General Data Protection Regulation
For users residing in the European Union or the European Economic Area, the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR) apply. In this context, you have the following rights:
Your Rights Under the GDPR
- Article 15 — Right of access: to learn whether your personal data is being processed and to obtain a copy of it
- Article 16 — Right to rectification: to request the correction of inaccurate or incomplete data
- Article 17 — Right to erasure (right to be forgotten): to request the deletion of your data
- Article 18 — Right to restriction of processing: to request that processing be restricted
- Article 20 — Right to data portability: to receive your data in a structured, machine-readable format (JSON/XLSX)
- Article 21 — Right to object: to object to processing based on legitimate interest
- Article 22 — Automated individual decision-making: to object to automated decision-making, including profiling
- Article 77 — Right to lodge a complaint: to lodge a complaint with the competent supervisory authority (in Türkiye, the Personal Data Protection Authority (KVKK))
Legal Bases for Processing (GDPR Art. 6)
- Art. 6(1)(a) (consent): newsletter subscription, optional cookies
- Art. 6(1)(b) (contract): membership, subscription, provision of services
- Art. 6(1)(c) (legal obligation): tax, invoicing, and audit records
- Art. 6(1)(f) (legitimate interest): security, fraud prevention, service quality
5. International Data Transfers
Our servers are located within Türkiye and the EU. Some of our infrastructure providers (Cloudflare, Anthropic) may process data in the United States. Standard Contractual Clauses (SCCs) have been executed for these transfers, and additional safeguards are applied to transfers to countries without an adequacy decision.
6. Data Retention Periods
- Account data: for as long as the account remains active + 30 days
- Emission reports: 5 years from the end of the reporting period (KVKK and audit requirement)
- Audit logs: 2 years
- Consent records: 3 years from the withdrawal of consent
- Payment/invoice records: 10 years as required by tax legislation
7. Data Controller Representative
The obligation to appoint an EU representative under Article 27 of the GDPR is currently under assessment. For the time being, please submit all requests directly to the data controller.
8. Contact and Complaints
Data Controller: U2 AI Studio Teknoloji Anonim Şirketi — Ahi Evran OSB Mah. Erkunt Cad. No: 3 İç Kapı No: 41 Sincan/Ankara, Türkiye
For all questions regarding cookies and the GDPR: [email protected]
Complaints to the supervisory authority in Türkiye: www.kvkk.gov.tr
Complaints to a supervisory authority in the EU: edpb.europa.eu
© 2026 U2 AI Studio Teknoloji A.Ş. All rights reserved.