Last updated: 9 October 2026
1. Controller and scope
Attorney Bahadır Pars is the controller for contact and online/office consultation requests through this website. Address: Alsancak, Şair Eşref Boulevard 65, Apartment 13, 35220 Konak / İzmir Email: parsavukatlik@gmail.com Telephone: +90 (532) 557 30 95
This notice describes the actual website process under Turkish Personal Data Protection Law No. 6698. Acknowledging it is not blanket consent or marketing permission. Any subsequent legal engagement, document request, accounting or bank process may require separate information.
2. Categories of personal data
Forms collect only name/surname, telephone and email. Consultation requests additionally contain the online/office preference and requested date/time. The website has no subject, free-text message, legal summary, national ID or document field.
Technical processing may involve IP, browser/connection details, random form security values and short-lived abuse counters. Counters use a salted IP digest; hashing does not automatically make information anonymous or remove it from the Law. Hosting, email and identity providers may maintain their own technical records.
3. Collection methods
Individuals submit information electronically and it is forwarded to the office mailbox. Document uploads and fields outside the permitted schema are rejected. Form contents are not written as application records to the site database, file store or pending email queue. They are used temporarily while the forwarding request is processed.
4. Purposes and legal bases
Contact information is used to provide the requested response and assess a meeting request. Necessary processing directly related to establishing/performing the requested service may rely on Article 5(2)(c); necessary responses to general contact requests and service security may rely on Article 5(2)(f), subject to balancing fundamental rights. Legal obligations may fall under Article 5(2)(ç), and necessary establishment, exercise or protection of rights under Article 5(2)(e). Each ground applies only within its own scope and necessity.
Selecting a date/time does not reserve or confirm a meeting. The office separately communicates availability and fees. Attorney Bahadır Pars personally manages payment checks and final confirmation by email/telephone. No personal panel record is created for this process and no automated fee or final confirmation email is sent to the applicant. Information is not used for advertising, marketing, profiling or automated legal assessment.
5. Special category and third-party data
The website offers no field for health, criminal conviction/security measure, biometric or other special category data, legal documents or third-party case information. If the office subsequently requests documents, necessity, minimisation, professional confidentiality and applicable Article 6 conditions are evaluated separately. Reading this notice does not authorise unrestricted sensitive-data processing.
6. Bank transfer description and national ID number
The website does not request, validate or store national ID numbers. Instructions to include name/surname and Turkish national ID in a bank transfer description concern issuing a self-employment receipt in the separate bank/office process. Bank receipts, fiscal documents and identity information in that process remain subject to the Law; relevant purposes, duties, recipients and retention are explained separately where required. The site collects no bank receipt, card number, security code or banking password and creates no card-payment or payment-report record.
7. Recipients and purposes of disclosure
The recipient is Attorney Bahadır Pars at parsavukatlik@gmail.com. OpenAI Sites/Cloudflare provide hosting and request processing, Resend provides email transmission, and Gmail/Google provides the office mailbox. Name, telephone, email and meeting type/date/time are processed by relevant providers for delivery. The absence of site application records does not mean those providers or the mailbox never process or retain information.
Disclosure to competent authorities is limited to applicable duties or necessary protection of rights. Banks/accounting recipients of a subsequent engagement concern a separate process. Google Calendar, Outlook Calendar, WhatsApp and automated Zoom/Teams meeting links are not active in this form flow. Recipients, purposes and transfer conditions must be reassessed before activation.
8. Maps, cookies and external links
The embedded Google Map is displayed automatically on the contact page. Loading the map connects to Google, which may process IP, browser/device and usage information. No separate “Show map” action is required. Leaving the page does not erase records already received by Google. The necessary form-security cookie, device preference record and authorised administrative authentication are explained in the Cookie Policy. External links follow independent providers’ conditions.
9. International transfers
Names, telephone numbers and email addresses are personal data. Forwarding them through foreign hosting/email services still requires assessment under Article 9 even without site application records. An applicable processing condition and an adequacy decision, appropriate safeguard or other statutory transfer condition are needed. Where a Turkish standard contract is used, its scope and notification requirements must be met; a provider’s general terms or DPA are not automatically a Turkish standard contract.
The controller reports no signed transfer arrangement under Turkish data-protection legislation with the current providers. This notice does not certify completed transfer compliance. The controller is responsible for establishing an applicable transfer mechanism and provider arrangements. Regular service transfers are not based only on an acknowledgement box or an occasional-transfer exception.
10. Retention and disposal
New requests create no personal application, document, payment-report or email-queue record in the site database. There is no one-month site application archive. Failed transmissions are not saved to the site; the visitor receives an error and must retry.
Delivered emails remain in the office mailbox. Email delivery/technical records, hosting security logs and backups are separate processes with durations and access governed by the actual services. The site change does not guarantee instant erasure of every provider copy. Office-mailbox retention is assessed against purpose, whether an engagement was formed, legal duties and protection of rights; information is disposed of under applicable rules once its purpose and legal basis cease.
Abuse counters use short time windows; expired rows are removed during the next security check. They contain no submitted name, telephone or email. Statutory retention of legal files and fiscal records is separate from this web form. Previous test application and related notification records are removed on the controller’s instruction and old payment access is closed.
11. Confidentiality and security
The application uses HTTPS, server-side field/telephone validation, request-size limits, CSRF protection, short-lived abuse limits and authorised administrative access. The application does not log form content; this is not a guarantee about all infrastructure-provider logs. Success indicates acceptance by the email service, not proven inbox delivery. A failed transmission creates no hidden database or notification-queue fallback. No absolute security guarantee is made; incidents are assessed and notified where required under the Law and Board rules.
12. Your rights
Under Article 11, you may apply to the controller to:
- Learn whether your data is processed and request information if it is.
- Learn the purpose and whether data is used in accordance with it.
- Learn the domestic and international third-party recipients.
- Request correction of incomplete or inaccurate data.
- Request erasure or destruction when Article 7 conditions are met.
- Request that recipients be informed of correction, erasure or destruction.
- Object to a detrimental result arising solely from automated analysis.
- Claim compensation for damage from unlawful processing.
Exercising these rights does not require unrestricted disclosure of another person’s data or professional secrets. Specific legal reasons must be given for any complete or partial refusal.
13. Requests, responses and complaints
Submit your request in Turkish by signed written application to the office address above, or from the email address previously notified to the office and recorded in its system to the email above. The Communiqué’s methods using a secure electronic signature, mobile signature or the controller’s registered electronic mail (KEP) address, if available, remain applicable; no verified KEP address is announced on this page. “KVKK Request” in the subject assists identification but is not a condition of your rights. Requests from an unrecorded address may require an appropriate method or additional information to verify identity.
Include name and surname, signature for a written application, Turkish national ID number for Turkish citizens or nationality and passport/available ID number for foreign nationals; residential/business address for service, any notification email/telephone/fax and the subject of the request. Relevant documents may be attached. A representative must provide evidence of authority. Unrelated data or unnecessary identity images should not be requested. Personal information is not disclosed to an address belonging to somebody else.
Requests are concluded as soon as possible and within thirty days. Acceptance or the grounds for refusal are communicated in writing or electronically. A telephone status update does not replace the final response. Requests are normally free; additional costs may be charged only under the Board’s tariff. A fee is refunded if the request arose from the controller’s error.
If refused, inadequately answered or unanswered in time, Article 14 permits a complaint to the Board within thirty days of learning the response and, in all cases, sixty days from applying to the controller. Application to the controller must precede a Board complaint.
This notice is updated when purposes, providers or legislation change. Further notice is required before processing for a new purpose. An update is not itself explicit consent.
