Publication policies
Privacy Policy
Clear information about your reading experience.
This policy explains how Metasharing handles information when you read our publication or write to us. Our articles are freely available without registration. The publication application does not build reader profiles or use analytics, advertising trackers, or cookies. Delivering a page and receiving an email can nevertheless involve personal information, as described below.
Who is responsible
KUTLU KURUMSAL İÇERİK HİZMETLERİ ANONİM ŞİRKETİ operates this publication and is responsible for the purposes and means of the personal information processing described here. Its registered address is Pazarbaşı Mah. Heybeliada Sok. No: 224, Kat: 4, Daire: 1, 34035, Bayrampaşa, İstanbul, Türkiye. Corporate identification details appear on our Contact page.
Gokce Kutlu, the publication owner, coordinates privacy correspondence. Write to contact@metasharing.org, addressed to Publication owner — privacy correspondence. This is also the contact route for requests about your information. You do not need an account or a particular form.
- European representative
- The publication uses the publisher's direct privacy contact. This role is not an appointment as a representative in the European Union. The publisher's policy requires a written mandate for a representative established in an appropriate Member State, and publication of that representative's contact details, whenever Article 27 of the General Data Protection Regulation requires it. The requirement must be assessed against the actual audience and processing before the activities requiring representation begin. Free access and the hosting location do not, by themselves, establish an exemption.
- Data protection officer
- The publication owner coordinates privacy administration as an internal contact. This operational responsibility is not a statutory data protection officer appointment. The publication application does not carry out large-scale monitoring or large-scale processing of sensitive personal information. The publisher's policy requires reassessment of officer designation before processing changes and whenever applicable law requires it. Any required officer must have appropriate expertise, independence, and duties that do not conflict with decisions about processing.
Information involved in reading the website
A browser sends technical information so that the website can return the requested page. This can include a network address, the requested page and query string, request time, browser information, and response status. Depending on the hosting configuration, the hosting infrastructure may record these details in access or error logs. Network addresses and related request details can be personal information even where we do not know a reader's name.
The publication application does not maintain a visitor database, combine reading activity into personal histories, or assign persistent reader identifiers. It does not request precise location, contacts, camera access, or microphone access. Technical information required to deliver a page is distinct from optional audience measurement; the application has no audience measurement integration.
Information you choose to email
If you email us, we receive your email address, the name displayed by your email application, the message, any attachments you include, and ordinary delivery information. We use relevant details to read and respond to the correspondence, consider an editorial correction, and maintain a proportionate record of the matter.
Writing to us is optional and is not a condition of reading. A reply requires a usable return address and enough context to understand the message. Please include only information relevant to the subject and avoid sending unrelated personal documents or information about other people. Sending an email does not subscribe you to marketing. We do not operate a mailing list.
Purposes and legal grounds
Where the General Data Protection Regulation applies, limited technical processing for page delivery and reliable operation relies on our legitimate interest in making the publication available. Handling ordinary editorial correspondence relies on our legitimate interest in maintaining an accurate publication and responding to messages addressed to us. These interests must be assessed against readers' rights, reasonable expectations, and the necessity of the information used.
Only necessary processing may rely on that balance. We do not use legitimate interests as a general permission to repurpose correspondence or track readers. If a binding legal obligation requires us to retain or disclose particular information, we process only what that obligation requires. The European Commission explains these distinctions in its guidance on legal grounds for processing.
Opening a page, following a link, or continuing to browse is not consent to additional processing. If a future activity requires consent, it must be separately explained before it begins, with a genuine choice and a way to withdraw that choice.
Advertising and external pages
The publication's sole intended revenue source is clearly identified sponsor advertisements. No sponsor advertisement is currently displayed, and no advertising content is loaded. The application does not use a reader profile, advertising identifier, conversion tag, or external advertising script. It does not send page views or email correspondence to sponsors.
External references and sponsor destinations are ordinary links. Their websites receive a request only when you choose to visit them; their own information practices then apply. Our publication does not control those websites. Citing a source or displaying a labelled advertisement does not make the other organisation an operator of this publication.
Recipients and processing locations
Relevant information may be accessible to people authorised to manage the publication and its correspondence, and to the hosting and email providers involved in those activities. Access should be limited to the task concerned. Where a provider processes information on our behalf, the applicable arrangement must define its instructions, confidentiality, and handling of that information. A public authority may receive information where a binding legal requirement applies.
- Hosting arrangements
- Website hosting is provided by ITENOS GmbH in Germany.
- Email arrangements
- Corporate email is hosted by ITENOS GmbH in Germany. The email infrastructure handles message delivery, mailbox storage, and associated delivery records.
- Network delivery
- Cloudflare forms part of the infrastructure through which website requests reach the hosting environment.
- Processing locations
- The publisher is established in Türkiye. Website hosting and corporate email are hosted in Germany. The network delivery provider operates an international network. Depending on routing and configuration, website request information can be processed outside the hosting country, including in the United States.
- International transfer arrangements
- For transfers subject to European transfer rules, the publisher's policy requires either an applicable adequacy decision covering the recipient and processing, or appropriate safeguards. Where required, those safeguards must include the European Commission's standard contractual clauses, an assessment of the destination and processing, and suitable supplementary measures. Arrangements with processors must address instructions, confidentiality, authorized subprocessors, deletion, and individual rights. A provider's public terms do not establish that a particular account has concluded the necessary arrangements. Readers may request details or copies of the applicable safeguards through the privacy contact above, subject to proportionate redaction of confidential information. A transfer that cannot meet the applicable requirements must not proceed.
The current network delivery configuration instructs compatible browsers to send reports of failed connections to a.nel.cloudflare.com. The browser reporting instruction remains valid for up to seven days unless refreshed; this is not the retention period of reports held by the provider. Diagnostic reporting is separate from advertising and audience tracking. The publication application does not set cookies or save identifiers in browser storage. See the Cookie Policy for the distinction between the application and the delivery infrastructure.
These requirements concern the actual recipient and processing arrangement. A provider's location or public documentation alone does not demonstrate that every transfer meets them. The network delivery provider's published data processing terms describe its contractual framework; account-specific arrangements must be established separately.
How long information is kept
The following schedule is the publisher's adopted retention policy for information under its control. The periods are maximum limits, not reasons to retain information that has already served its purpose. They are not verified descriptions of each infrastructure provider's current settings.
- Correspondence retention
- The publisher adopts a maximum retention period of 12 months after closure for ordinary editorial correspondence, company correspondence, and the minimum record needed to document a privacy request and its response. A matter closes when its final response or related editorial action is complete. Irrelevant or unsolicited messages have a maximum period of 30 days from receipt. Information no longer needed for the stated purpose must be deleted sooner. A longer period requires a documented legal obligation or specific legal claim, is limited to the relevant records, and must be reviewed at least every three months.
- Technical records and backups
- For records under its control, the publisher adopts maximum periods of 14 days from collection for routine access logs and 30 days from collection for diagnostic error logs. Unnecessary identifying details must be removed sooner. Backup copies of records covered by this policy must expire within 30 days after deletion from active systems. Such copies are restricted to recovery, and earlier deletions must be reapplied after restoration. Provider-managed logs and backups may have different contractual periods; these policy limits do not establish the actual retention settings of provider systems.
The relevant criteria are the time needed to address the original matter, complete any necessary follow-up, and meet an identified legal requirement. A particular record may need to be retained for a documented legal claim or statutory duty after routine handling ends. Such retention must be limited to the relevant material and purpose. It is not a reason to keep every email or technical record indefinitely.
When information is no longer needed, the policy requires deletion or irreversible anonymisation. A legal retention exception must identify its purpose and end condition. Provider deletion and backup arrangements must be matched to the relevant processing before their actual periods can be represented as confirmed. The European Commission explains the underlying storage limitation principle.
Your rights
Where applicable data protection law provides these rights, you may ask for access to your information, correction of inaccuracies, deletion, or restriction of processing. You may also have a right to receive qualifying information in a portable format. Portability applies under its legal conditions, including automated processing based on consent or a contract; it does not apply to every record.
You may object, for reasons relating to your situation, to processing based on legitimate interests. We must assess that objection and stop the processing unless the applicable law permits it to continue. If processing relies on consent, you may withdraw it without changing the lawfulness of processing that occurred before withdrawal. These rights and their conditions are explained in the General Data Protection Regulation.
Send requests to the privacy contact above. We respond without undue delay and, where the Regulation applies, within one month. If complexity or the number of requests justifies up to two additional months, we explain the extension and its reason within the first month. Requests are normally free. We explain any lawful limitation or refusal and the routes available to challenge it.
If identity verification is necessary, we request only proportionate information. We do not require readers to create an account. If we cannot associate a record with you, we explain that limitation rather than collecting unrelated information to build a profile. You may complain to a competent supervisory authority, including one in your habitual residence, workplace, or the place of an alleged infringement, and pursue available judicial remedies. Contacting us first is optional. See the European Commission's explanation of individual requests.
Browser settings and policy changes
The Cookie Policy explains the temporary theme control and ordinary browser caching. The publication application does not make automated decisions with legal or similarly significant effects and does not build reader profiles. The publication is written for a general readership and does not operate child accounts or solicit children's personal information.
Changes to information handling must be reflected here before the new activity begins. A material change of purpose may require an additional notice or other steps under applicable law; updating this page alone does not supply consent. The date above identifies this version of the policy.
