Skip to content
/privacy · kvkk

Privacy Notice on the Protection of Personal Data

Last updated: July 30, 2026

1. Purpose, Scope and Legal Ground

1.1. This Privacy Notice has been drawn up in order to fulfil the disclosure obligation laid down in Article 10 of the Turkish Personal Data Protection Law No. 6698 (hereinafter the "KVKK") in respect of the personal data processed when the personal website published at the domain https://msgxr.dev (hereinafter the "Site") is visited and when the communication channels offered on the Site are used.

1.2. The third paragraph of Article 20 of the Constitution of the Republic of Türkiye (Added paragraph: 12/9/2010-5982/Art. 2) provides as follows:

"Everyone has the right to request the protection of his/her personal data. This right includes being informed of, having access to and requesting the correction and deletion of his/her personal data, and to be informed whether these are used in consistency with envisaged objectives. Personal data can be processed only in cases envisaged by law or by the person's explicit consent. The principles and procedures regarding the protection of personal data shall be laid down in law."

Article 22 of the Constitution, in turn, provides that everyone has the freedom of communication and that the confidentiality of communication is fundamental.

1.3. The Site has not confined itself to adopting these constitutional principles merely at the level of declaration; it has adopted the principle that no record on an individual basis is kept about a visitor who merely browses the Site, and has implemented at a technical level end-to-end encryption for messages sent by a visitor who selects the "security" contact type, and server-side encryption for the personal data stored. The scope of the technical signals processed in the communication channels for the purpose of preventing abuse, and the balancing test relating thereto, are explained channel by channel in Article 4 of this text; the details of the security measures are set out in Article 6.

1.4. The Site is a personal portfolio site that conducts no commercial sales, has no membership system and publishes no advertising. This text is based on the principle of explaining, channel by channel and as they are, the data actually processed by the Site; all systematic processing activities carried out within the knowledge and control of the data controller are listed in this text.

2. Definitions

For the purposes of this text:

a) Law / KVKK: the Turkish Personal Data Protection Law No. 6698,

b) Board and Authority: the Personal Data Protection Board and the Personal Data Protection Authority,

c) Personal data: any information relating to an identified or identifiable natural person (KVKK Art. 3/1-d),

ç) Data subject: the natural person whose personal data is processed (KVKK Art. 3/1-ç),

d) Data controller: the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system (KVKK Art. 3/1-ı),

e) Processing: any operation performed on data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by fully or partially automated means, or by non-automated means provided that it forms part of a data recording system (KVKK Art. 3/1-e),

f) IP hash: the shortened value obtained by passing the visitor's IP address through a keyed, irreversible cryptographic hash function (HMAC-SHA256),

g) End-to-end encryption (E2EE): the method based on the principle that the content is encrypted on the visitor's device and can be decrypted only with the private key held by the data controller, and that the server, by design, at no stage holds the key required to decrypt the content,

ğ) KV / D1: the key-value store and the relational database used in the infrastructure on which the Site runs,

These definitions apply throughout this text.

3. Identity of the Data Controller

3.1. Within the meaning of Article 3 of the KVKK, the data controller is Muhammed Sina Gün, a natural person resident in İstanbul who is the owner and operator of the Site.

3.2. The electronic mail address for any application to be addressed to the data controller: contact@msgxr.dev.

3.3. As the data controller remains below the thresholds determined by Board decisions in terms of the annual number of employees and the annual financial balance sheet total, and as its main field of activity is not the processing of special categories of personal data, it does not fall within the scope of the obligation to register with the Data Controllers' Registry (VERBİS) pursuant to the Board's exemption decisions.

4. Personal Data Processed, Processing Purposes and Legal Bases

The Site processes data on a channel basis. In no channel is more intended than is necessary for the operation of that channel (general principles under Article 4 of the KVKK: lawfulness and fairness, accuracy, specific, explicit and legitimate purposes, relevance and proportionality to the purpose, retention for the period necessary).

4.1. Contact Form

a) Data entered by the visitor personally: Name (max. 100 characters), e-mail address (max. 200 characters), subject (max. 150 characters), message (max. 3000 characters), company name if any (max. 120 characters) and the choice of contact type (individual / corporate / official / collaboration / security).

b) Security and verification data: Human verification (Turnstile) token, single-use form token and hidden honeypot field.

c) Device and browser environment data (compiled and transmitted on the client side): Time zone and time offset, language(s), platform, number of processor cores, approximate amount of memory, number of touch points, screen and viewport dimensions, screen orientation, graphics hardware (GPU) vendor and model information, connection type/speed/latency and data-saving preference, battery level and charging status, storage quota, number of plug-ins, automation (webdriver) indicator, "tracking" preference signals (DNT/GPC), cookie support, presence of a PDF viewer, theme/reduced-motion/HDR/colour gamut preferences, referring address (referrer) and the path visited; browser fingerprint hashes (canvas/WebGL/audio/device — hash values of 16-32 hexadecimal characters) and form-filling behaviour measurements (filling and typing duration; counts of keystrokes, pastes, deletions and mouse movements).

d) Data added on the server side: The visitor's IP address (stored encrypted pursuant to Article 4.1/ı) and the reverse DNS (PTR) record of that address, together with the keyed hash of the IP address, salted hash of the e-mail address, browser identity (user-agent, max. 400 characters); network and approximate location information (ASN, internet service provider, country, city, region and region code, postal code, continent, approximate latitude and longitude, EU member state indicator, time zone, connection port, HTTP protocol, TLS version and cipher suite, connection latency, bot score and JA4 signature where available); browser client hints (platform and version, mobile indicator, processor architecture and bit width, device model, browser version list); accepted languages; technical intelligence relating to the e-mail domain (detection of disposable addresses, detection of role accounts, existence of MX/SPF/DMARC records, mail provider); consistency signals derived from this data (time zone/language-country mismatch, automation, proxy, data centre and VPN suspicion indicators).

e) Purpose: Receiving, assessing and responding to the contact request; preventing unsolicited messages (spam), automation and abuse; verifying the authenticity and integrity of the request.

f) Legal basis: As regards the content of the communication, the fact that it is directly related to the establishment of the communication initiated at the data subject's request and to the formation of a possible contractual relationship (KVKK Art. 5/2-c); as regards security, verification and abuse-prevention data, the legitimate interest of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject (KVKK Art. 5/2-f). The following elements have been taken as a basis in the legitimate interest balancing test: the technical signals in subparagraphs (c) and (d) are compiled only at the moment the form is submitted and are not collected during mere browsing; they are used exclusively to produce a spam and automation score; the IP address and e-mail content are stored only in encrypted form and all records are automatically deleted after 90 days at the latest.

g) Special provision — security-type communication: The content of messages sent by selecting the "security" type is encrypted end-to-end on the visitor's device; only the encrypted package reaches the server and, as the decryption key is not held on the server, it is not possible for the server to decrypt this content in the ordinary course of operation. This assurance is at the design level and depends on the integrity of the encryption code delivered to the visitor's device. Drafts of such messages are not even saved to the browser's local storage.

ğ) Notification: The submission is delivered to the data controller's mailbox (Article 8.4) as a notification e-mail; this notification contains the name, e-mail and message content together with the city/region/country, time zone, service provider, device and browser summary and security signals (for end-to-end encrypted messages, a placeholder appears instead of the content). If delivery fails, the message is placed in a recovery queue where it is held in encrypted form for a maximum of 7 days.

h) Rate limits: Limits of 3 submissions per minute and 20 per hour from the same source; 3 submissions per 24 hours from the same e-mail address; and 2 submissions per hour for a message with identical content are applied.

ı) Processing of the IP address — specific notice: The visitor's raw IP address and, where available, the reverse DNS (PTR) record of that address are kept in the submission record encrypted with AES-256-GCM; the decryption key resides only in the data controller's server environment and the record is viewable in the panel only through authorised access. The purpose is to identify the source of spam and abuse, to correlate repeated submissions and to document the act in case of unlawful use (Article 5/2-f DPL). This data is not shared with third parties; it may be produced only upon a duly made request of the competent judicial and administrative authorities. The record is deleted automatically after 90 days and falls within the scope of an erasure request made under Article 10. About location: The location obtained from the network infrastructure is at country, city/region and postal-code level; the latitude-longitude value is not a street or door address but an approximate point rounded to the centre of the region, and the physical address of the data subject is not derived from the IP address.

4.2. Guestbook

a) Data processed: Name or pseudonym (max. 40 characters), message (max. 500 characters) and the country code obtained from the network infrastructure. No e-mail address is requested or processed.

b) Public disclosure: The name and message written in the guestbook are provided for publication publicly on the Site (in the form of name, country flag and message) after passing the data controller's approval; for this reason they are stored unencrypted. The record is submitted by the data subject personally for the purpose of publication and with this knowledge. The country information is not a declaration of the visitor but is obtained from the network infrastructure and, when the record is published, is displayed solely in the form of a flag icon; this display is announced by this Article.

c) Purpose: Enabling visitors to share their impressions of the Site publicly; applying prior approval (moderation) in order to prevent unlawful content.

ç) Legal basis: As regards the storage and moderation of records awaiting approval, the fulfilment of the data subject's publication request (KVKK Art. 5/2-c) together with the data controller's legitimate interest in preventing unlawful content (KVKK Art. 5/2-f); as regards records approved and published, the data subject's own act of making the data public for the purpose of publication (KVKK Art. 5/2-d). The display, in flag form, of the country information obtained from the network infrastructure is based on the legitimate interest of the data controller (KVKK Art. 5/2-f), subject to the disclosure made by this Article.

d) Retention and notification: Records awaiting approval are automatically deleted if they are not approved within 30 days. Approved records are retained for as long as they remain published, subject to a ceiling of 200 entries at most. When a new record arrives, a notification e-mail containing the name, country, time and message is sent to the data controller. A limit of 3 submissions per hour per source is applied together with human verification.

4.3. Curriculum Vitae (CV) Request

a) Data processed: The visitor's e-mail address; on the server side, the IP address and, where available, its reverse DNS (PTR) record (encrypted on the same basis as Article 4.1/ı), the keyed hash of the IP address and the browser identity (max. 200 characters). Although this channel is technically operational, it may not actually be used during periods when no request button is offered in the Site interface; no data is processed under this Article for as long as the channel is not actually used.

b) Purpose: Conveying the CV request to the data controller and preventing abuse. The request is delivered to the data controller's mailbox (Article 8.4) as a notification containing the visitor's e-mail address together with approximate location, service provider, device and e-mail domain intelligence; no automatic e-mail is sent to the visitor through the Site.

c) Legal basis: Fulfilment of the data subject's request (KVKK Art. 5/2-c) and legitimate interest as regards the prevention of abuse (KVKK Art. 5/2-f).

ç) Retention: The request record is automatically deleted after 90 days; the e-mail address and the IP address are kept encrypted in the record. A limit of 5 requests per hour per source is applied.

4.4. Artificial Intelligence Chat

a) Data processed: The free text written by the visitor in the chat window. It is possible for the visitor to include personal data in this text of their own volition; it is recommended that no personal data be written in the chat.

b) Principle of non-retention: Chat content is not recorded in the Site's data stores (KV/D1). Messages are processed, for the purpose of generating a response, by the artificial intelligence service of the infrastructure on which the Site runs (Cloudflare Workers AI, @cf/meta/llama-3.3-70b-instruct-fp8-fast model; if that model is unavailable, the @cf/meta/llama-3.1-8b-instruct-fp8 model); the data controller's configuration is limited to this processing. Cloudflare's own processing behaviour, in its capacity as sub-processor, is subject to Cloudflare's terms of service and data processing documentation.

c) Purpose and legal basis: Providing interactive information about the Site; the legitimate interest of the data controller (KVKK Art. 5/2-f).

ç) Limits: 20 messages per hour per source; a budget limit of 200 messages per hour and 1000 messages per day across all visitors is applied.

4.5. Counters

The visitor counter and the blog view counters keep only an aggregate number; the counter itself contains no trace, profile or record on an individual basis. A rate limit based on the IP hash is applied at the counter endpoints in order to prevent abuse; these limit keys are short-lived, are automatically deleted at the end of their term and are not used for the purpose of direct identification. The salted IP hash retains the character of pseudonymised personal data in the hands of the data controller and is processed exclusively for the purpose of rate limiting.

4.6. Security Logs and Preservation of Evidence

a) In order to protect the integrity of the Site, to detect attacks and, where necessary, to be able to present evidence to the competent authorities, the following records are kept:

  1. Honeypot endpoints: Requests made to addresses that have no real function on the Site and that exist solely for the purpose of detecting unauthorised access attempts are recorded for 180 days together with the requester's raw IP address, browser identity (max. 200 characters), country, request method and path. Such a record constitutes attacker telemetry relating to an unlawful access attempt.
  2. Security event stream: The event type, severity level, raw IP address (max. 64 characters), country, browser identity (max. 200 characters) and detail (max. 300 characters) are kept for 30 days. Requests exceeding the rate limit may also fall into this stream; this possibility is known to the data controller and the records are kept solely for security purposes and for a limited period.
  3. Brute-force counters: These are temporary counters based on the IP hash with a lifetime of 900 seconds.
  4. Content Security Policy (CSP) violation reports: The time, the directive violated, the blocked address, the document address, the source file and line number, and only the salted hash of the IP address are kept for 30 days.
  5. Administrator access logs: The audit log relating to the administration panel (operation, operator, IP, browser, detail) is kept for 180 days, protected against tampering by a cryptographic chain; the subjects of these records are not visitors but persons accessing the administration panel in an authorised capacity. Where the administrator account is accessed from a new device, only the IP hash is retained for 180 days and an alert is sent to the data controller.

b) Purpose: Ensuring network and information security, detecting and preventing attacks, preserving records for use as evidence in possible legal proceedings, and alerting the data controller.

c) Legal basis: The legitimate interest of the data controller (KVKK Art. 5/2-f) and the fulfilment of obligations relating to data security (KVKK Art. 12); the fulfilment of a legal obligation in the case of requests by the competent authorities (KVKK Art. 5/2-ç).

ç) Warning: The recording of the raw IP address in security events is a deliberate choice; since blocking the person attempting unlawful access and documenting the act are not possible by means of an IP hash, the raw address is kept. These records are not shared with third parties; they may be produced only upon a duly made request of the competent judicial and administrative authorities.

4.7. Incoming E-Mail and Backups

a) E-mails arriving at contact@msgxr.dev and at the other addresses of the domain are passed through a spam filter. The sender and subject information of the filtered messages is kept encrypted for 30 days; the panel mirror of clean messages (sender, subject, up to 10,000 characters of the body) is kept encrypted for 90 days. Clean messages are forwarded to the data controller's mailbox (Article 8.4).

b) On a daily basis, only a numerical summary (the counts and status distribution of the last 24 hours) is sent to the data controller. On a weekly basis, all contact and CV records are sent to the data controller's mailbox (Article 8.4) as a disaster backup; in this backup the fields containing personal data remain encrypted, while the pseudonymised metadata (approximate location, network, language, device summary, IP hash, assessment score) is in plain text.

c) Legal basis: The maintenance of communication (KVKK Art. 5/2-c) together with legitimate interest as regards protection against data loss and security (KVKK Art. 5/2-f).

4.8. Forum (Member Short-Message Feed)

a) Data processed: The e-mail address used for membership (never displayed on the Site; stored encrypted with AES-GCM, with only a keyed, irreversible hash used for sign-in matching), the display name chosen by the member (2–40 characters), post and reply texts (max. 500 characters), like records and the identifier bound to the session cookie. Depending on the member's choice, the e-mail address is obtained either through the single-use link sent to their e-mail or — where offered — from Google in verified form during "Sign in with Google" (Article 9.e). Rate-limit hashes operating under the principles of Article 4.6 are kept for sign-in link requests. An image optionally attached to a post (JPEG/PNG/GIF/WebP, max. 2 MB) is provided for publication; any metadata embedded in the file (EXIF — for example the capture location) is published together with the file, and removing it before uploading is at the member's discretion.

b) Public disclosure and publication model: The display name, post/reply texts and like counts are published publicly on the Site and are stored unencrypted for that purpose; the e-mail address is never published in any form. Publication is instant (there is no prior approval); the data controller may subsequently hide or delete unlawful content or lock the membership. The member may permanently delete their own post (together with its replies and likes) at any time.

c) Purpose: Enabling members to share public short messages on software, projects and matters relating to the Site; verifying the account through a single-use e-mail link (passwordless); preventing abuse.

ç) Legal basis: The establishment and maintenance of the membership and the sending of the sign-in link rest on the formation/performance of a contract (KVKK Art. 5/2-c); published content rests on the data subject's own act of making the data public for the purpose of publication (KVKK Art. 5/2-d); abuse prevention, rate limiting and moderation rest on the data controller's legitimate interest (KVKK Art. 5/2-f).

d) Retention and notification: The sign-in link record is valid for 15 minutes and is single-use; the session record expires automatically after 30 days. The membership record and published content are retained until the member deletes them or the rights under Article 11 are exercised. When a new post is published, a notification e-mail containing the display name, country, time and message is sent to the data controller. A limit of 3 sign-in requests per hour per source and 10 posts per hour per member is applied together with human verification.

5. Method of Collecting Personal Data

Personal data is collected entirely by automated means: from the information entered by the data subject personally through the forms and the chat interface on the Site, from the data technically transmitted by the browser and the network infrastructure (HTTP headers, client hints, connection metadata), and from the network/geographic information provided by the infrastructure on which the Site runs. Merely browsing the Site does not give rise to any record on an individual basis apart from the counter and security operations explained in Articles 4.5 and 4.6; no analytics script for advertising, tracking or profiling purposes is embedded in the Site.

6. Technical and Administrative Measures for the Protection of Data

6.1. Pursuant to Article 12 of the KVKK, the data controller applies the following measures with a view to ensuring an appropriate level of security in order to prevent the unlawful processing of, and unlawful access to, the data and to ensure its preservation:

a) Server-side encryption: The personal data fields in the contact, CV request and e-mail records are stored encrypted with the AES-GCM algorithm using a 256-bit key in the production configuration where the encryption key is defined; an encryption secret of insufficient length is rejected in the production environment. The data controller ensures at the operational level that this key remains defined and valid in the production environment.

b) End-to-end encryption: Security-type communication messages are sealed on the visitor's device with ECDH P-256 key exchange, HKDF-SHA256 and AES-256-GCM; the private key never reaches the server under any circumstances and is wrapped in password-protected form with PBKDF2-SHA256 using 310,000 iterations.

c) Protection of the IP address: In contact form and CV request records the raw IP address is kept encrypted (AES-256-GCM) and its keyed hash is also stored; separate salts and IPv6 /64 normalisation are used in the rate-limiting keys. In the security telemetry (Article 4.6) and the administrator audit log the raw IP is kept unencrypted; the rationale for that choice is explained in Article 4.6/ç. Only hashes are used in rate-limiting, brute-force and CSP records.

d) Access control: The administration panel sits behind a Zero Trust access layer (Cloudflare Access); the access token (RS256-signed JWT) is independently re-verified within the server; in addition, constant-time key comparison, an IP-based lockout after 10 failed attempts within 15 minutes and request context checks are applied.

e) Audit log: Every administrator operation, export and deletion request is bound to an audit log whose integrity can be verified by means of a SHA-256-based hash chain.

f) Abuse prevention: Sliding-window rate limits on all write endpoints; human verification; single-use, time-bound signed form tokens; honeypot fields and honeypot endpoints; brute-force detection; an amplification ceiling of 12 messages per hour for e-mail sending.

g) Browser security headers: A Content Security Policy, HSTS, framing prohibition (X-Frame-Options: DENY), MIME-sniffing protection, Referrer-Policy, origin isolation headers and a comprehensive Permissions-Policy are applied.

6.2. The data controller applies and updates these measures with due care; nevertheless, given the nature of information systems, it cannot be undertaken that any system is absolutely secure. Should a data breach occur despite these measures, the obligation to notify the Board and the data subjects pursuant to Article 12/5 of the KVKK is reserved.

7. Retention Periods

7.1. Pursuant to Articles 4/2-d and 7 of the KVKK, personal data is retained for the period necessary for the purpose for which it is processed and is automatically deleted at the end of that period. The maximum periods on a channel basis are as follows:

RecordMaximum period
Contact form records (including the IP address, encrypted)90 days
Contact analytics (pseudonymised rows containing no personal data)90 days
Duplicate submission prevention record24 hours
Single-use form tokens45 minutes (contact) / 120 minutes (chat)
Guestbook — awaiting approval30 days
Guestbook — approvedFor as long as it remains published (max. 200 entries)
Forum — sign-in link record15 minutes (single-use)
Forum — session record30 days
Forum — membership (encrypted e-mail + display name)Until the membership is deleted (requests under Article 11 reserved)
Forum — posts, replies and likesFor as long as they remain published; the member may delete their own post at any time
Forum — post imagesFor as long as the post remains published; permanently deleted together with the post
CV request records (including the IP address, encrypted)90 days
Chat contentNot stored
CSP violation reports30 days
Honeypot endpoint records180 days
Security event logs30 days
Brute-force counters900 seconds
Administrator audit log180 days
Administrator device recognition record (IP hash only)180 days
Filtered e-mail metadata (encrypted)30 days
Incoming e-mail panel mirror (encrypted)90 days
Undeliverable notification queue (encrypted)7 days

7.2. Rows older than 90 days in the database are regularly deleted by a scheduled task.

7.3. Where the data subject makes a duly submitted deletion request, deletion is carried out within the framework of Articles 7 and 11 of the KVKK without waiting for the maximum period to expire; provided that records whose retention is mandatory for the fulfilment of a legal obligation or for the establishment, exercise or protection of a right (in particular the security and evidence records in Article 4.6) are excepted for the duration of that necessity.

8. Transfer of Personal Data and Transfer Abroad

8.1. Personal data is not sold or rented to any third party for commercial purposes and is not shared for marketing purposes.

8.2. The Site runs on a global cloud infrastructure (Cloudflare Workers) operated by Cloudflare, Inc. (United States of America). As a natural consequence of this architecture, the requests made to the Site and the data processing activities listed in this text may take place on Cloudflare's servers distributed worldwide — including the point of presence closest to the visitor. Such processing constitutes a transfer of personal data abroad within the meaning of Article 9 of the KVKK (as amended by Law No. 7499), and this Article has been drawn up in order to fulfil the disclosure obligation relating to that transfer.

8.3. The transfer abroad is carried out on the basis that Cloudflare acts as a data processor processing the data on behalf of the data controller and in accordance with its instructions, and within the framework of the contractual safeguards under the Data Processing Addendum applicable to Cloudflare services together with the principles concerning the appropriate safeguards provided for in Article 9 of the KVKK. Where the standard contract mechanism announced by the Board is used, the data controller observes the obligation to notify the Authority within five business days following the signing of the contract. The technical measures taken to minimise the risk of the transfer are listed in Article 6; in particular, the encryption of the stored personal data fields with AES-GCM, the end-to-end encryption of security-type messages and the use of an irreversible hash instead of the raw IP in visitor records are essential.

8.4. The notification e-mails for the contact form, the guestbook, the forum and the CV request; the forwarding of clean messages arriving at contact@msgxr.dev; and the weekly backup e-mails referred to in Article 4.7 reach a mailbox hosted with a third-party electronic mail service provider of the data controller (Google LLC — Gmail service, United States of America). Accordingly, that provider is also among the recipients to which personal data is transferred abroad; although the personal data fields in the weekly backup remain encrypted, the pseudonymised metadata categories (approximate location, network, language, device summary, IP hash, assessment score) reach this mailbox in plain text. This transfer is likewise carried out subject to the Article 9 KVKK regime explained in Article 8.3 and to the data processing terms of the relevant service provider.

8.5. Where the competent judicial and administrative authorities make requests that comply with the legislation and are duly served, the relevant records may be provided to those authorities pursuant to Article 5/2-ç of the KVKK.

9. Third-Party Services

9.1. Services that visitor data touches:

a) Cloudflare Turnstile (human verification): A verification component is loaded on the contact form, guestbook and forum pages; the visitor's IP address and browser signals are transmitted to Cloudflare for verification purposes. The server transmits the verification token, together with the visitor's IP, to Cloudflare's verification service.

b) Cloudflare DNS-over-HTTPS: Only the domain of the visitor's e-mail address (not the address itself) is transmitted, for the purpose of querying MX/SPF/DMARC records.

c) Cloudflare Workers AI: Chat messages are processed for response generation (Article 4.4).

d) Cloudflare KV, D1, Email Routing/Sending and Access: These constitute the Site's storage, database, e-mail delivery and authentication infrastructure. Forum sign-in link e-mails are delivered to the member's own address through Cloudflare's e-mail sending service.

e) The data controller's e-mail service provider (Google LLC — Gmail): This is the service hosting the mailbox to which the notification, forwarding and backup e-mails are delivered (Article 8.4).

9.2. External sources to which visitor data is not sent: the GitHub repository/activity data displayed on the Site (api.github.com), the GitHub contribution graph (github-contributions-api.jogruber.de), and Spotify and WakaTime data; all of these consist solely of fetching data belonging to the data controller's own accounts, and no data belonging to the visitor is transmitted in these requests.

9.3. Google Fonts is not used on the Site; fonts are loaded from the Site's own server. The browser's network connections are limited by the Content Security Policy to the Site's own origin and to Cloudflare verification/measurement endpoints. The measurement endpoint permitted by the policy belongs to Cloudflare's measurement service, which operates without cookies; no script belonging to this service is embedded in the Site code.

9.4. The Site may contain links to sites belonging to third parties. The privacy practices of those sites are the responsibility of their own operators; this text has effect only for msgxr.dev.

10. Statement Regarding Children

The Site does not host content aimed at children and its target audience is not children. The data controller does not knowingly and willingly collect personal data belonging to children. Should a parent or guardian notify that personal data belonging to a child is being processed, that data is deleted without delay upon an application made in accordance with the procedure in Article 12.

11. Rights of the Data Subject (KVKK Art. 11)

Everyone has the right to apply to the data controller and, in relation to themselves:

a) to learn whether personal data is being processed,

b) to request information if personal data has been processed,

c) to learn the purpose of the processing of personal data and whether it is used in accordance with its purpose,

ç) to know the third parties to whom personal data is transferred domestically or abroad,

d) to request the correction of personal data if it has been processed incompletely or inaccurately,

e) to request the erasure or destruction of personal data within the framework of the conditions provided for in Article 7 of the KVKK,

f) to request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom personal data has been transferred,

g) to object to the occurrence of a result to the detriment of the person by means of the analysis of the processed data exclusively through automated systems,

ğ) to claim compensation for the damage suffered as a result of the unlawful processing of personal data.

Automated security measures are operated on the Site — such as the filtering of unsolicited messages and the application of rate limits — which, upon the detection of abuse, may temporarily restrict access or transmission without human intervention. Apart from these security measures, there is no exclusively automated decision mechanism producing legal consequences to the detriment of the data subject; as regards filtered messages, the final assessment is made by the data controller. A data subject who considers that their message has been unjustly filtered or their access unjustly restricted may request a manual review via the address contact@msgxr.dev or the contact form on the Site; the request is assessed by the data controller independently of the automated system.

12. Application Procedure

12.1. Pursuant to Article 13 of the KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller, the data subject shall submit their requests to the data controller by electronic mail to contact@msgxr.dev. Pursuant to the second paragraph of Article 5 of the Communiqué, the application must contain: (a) name, surname and, if the application is in writing, a signature; (b) for citizens of the Republic of Türkiye, the Turkish identity number, and for foreigners, their nationality together with passport number or identity number if any; (c) the residential or business address for notification purposes; (ç) the electronic mail address, telephone and fax number for notification, if any; and (d) the subject matter of the request; information and documents relating to the subject matter shall be annexed to the application.

12.2. In order to prevent the disclosure of data to the wrong person, reasonable confirmation that the applicant is the data subject is required (in particular that the application is sent from the e-mail address on record). Applications where identity cannot be verified are concluded by requesting additional verification.

12.3. Applications are concluded free of charge as soon as possible and in any event within thirty days, depending on the nature of the request; where the operation additionally entails a cost, the fee in the tariff determined by the Board may be requested. The request is either accepted or rejected with the grounds stated, and the response is notified to the data subject in writing or electronically.

12.4. Deletion requests are fulfilled by means of an actual deletion process carried out on the records through e-mail matching; whether the process has been fully completed is reported by the system and every deletion operation is bound to the audit log.

12.5. Where the application is rejected, the response given is found insufficient or no response is given within the time limit, the data subject has the right to lodge a complaint with the Personal Data Protection Board within thirty days from the date on which they become aware of the response and in any event within sixty days from the date of the application (KVKK Art. 14). The data subject's rights to compensation under the general provisions are reserved.

13. Amendments

13.1. The data controller reserves the right to update this text at any time on account of changes in the legislation, Board decisions or changes in the operation of the Site.

13.2. The current text takes effect upon publication on the Site; the "Last updated" date at the beginning of the text indicates the version in force. Visitors are advised to review the text at regular intervals.

14. Entry into Force

This Privacy Notice was published on the Site on July 26, 2026 and entered into force on the same date. The invalidity of any provision of the text does not affect the validity of the other provisions. This text is subject to the law of the Republic of Türkiye.

Data Controller: Muhammed Sina Gün — İstanbul

Applications: contact@msgxr.dev