Privacy Policy

1. Data Protection at a Glance

General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to any data that can identify you personally.

Detailed information on the subject of data protection can be found in our privacy policy outlined below.

Data Collection on This Website

  • Who is responsible for data collection on this website?
    Data processing on this website is carried out by the website operator. The operator's contact details can be found in the "Information on the Controller" section of this privacy policy.

  • How do we collect your data?
    Data is collected in two ways:

    1. By you providing it directly, such as entering information into a contact form.

    2. Automatically, or with your consent, through IT systems when you visit the website. This includes technical data (e.g., browser type, operating system, or the time of the page view).

  • What do we use your data for?
    Some data ensures the website functions properly, while other data may be used to analyze user behavior.

  • What rights do you have regarding your data?
    You have the right to receive information about the origin, recipient, and purpose of your stored personal data at no cost. Additionally, you can request the correction or deletion of your data. If you have provided consent to data processing, you may revoke it at any time. You may also request restrictions on the processing of your data under certain conditions and lodge a complaint with the appropriate supervisory authority. For further questions, you can contact us at any time.

Analysis Tools and Tools from Third-Party Providers
Your browsing behavior may be statistically analyzed when you visit this website. This is primarily done using analysis programs. For detailed information on these programs, please refer to the following privacy policy.

2. Hosting

Squarespace
The content of this website is hosted by Squarespace Ireland Ltd, Le Pole House, Ship Street Great, Dublin 8, Ireland. Squarespace may transfer personal data to its parent company, Squarespace Inc., in the USA. Cookies necessary for the website's operation and security ("necessary cookies") are also stored.

  • Legal Basis:
    The use of Squarespace is based on Art. 6(1)(f) GDPR due to our legitimate interest in providing a reliable website. If consent is provided, processing is based on Art. 6(1)(a) GDPR.

  • Data Transfer to the USA:
    Data transfers are based on the EU Commission's standard contractual clauses and the EU-US Data Privacy Framework (DPF). Further details can be found here.

Order Processing Agreement
We have a data processing agreement (DPA) with Squarespace, ensuring compliance with GDPR guidelines.

3. General Notes and Mandatory Information

Data Protection
We treat your personal data confidentially and in accordance with statutory regulations. This privacy policy explains the data we collect, its purpose, and how it is processed. Please note that data transmission on the internet (e.g., via email) may have security vulnerabilities.

Controller Information
Responsible party:
Zafer Ertem
Vali Konaklari, Altinkale Mah, Selcuklu Cad. No 1
07190 Antalya, Türkiye
Email: pilot.barbossa((@))gmail.com

Storage Period
Personal data is stored until the purpose of processing is no longer valid. Exceptions include legal obligations or justified reasons for continued storage (e.g., tax retention periods).

Legal Basis for Data Processing

  • Consent: Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR.

  • Contractual Fulfillment: Art. 6(1)(b) GDPR.

  • Legal Obligations: Art. 6(1)(c) GDPR.

  • Legitimate Interests: Art. 6(1)(f) GDPR.

For details, please refer to specific sections of this privacy policy.

Data Transfers to Non-EU Countries
Some tools or services may involve data transfers to non-EU countries. These transfers are secured by the EU-US Data Privacy Framework or other standard safeguards, as detailed within this policy.

4. Data Collection on This Website

Cookies
Our website uses cookies, which are small data packets that do not harm your device. Cookies may be stored temporarily (session cookies) or permanently (persistent cookies).

  • Types of Cookies:

    • Session Cookies: Automatically deleted after your visit.

    • Persistent Cookies: Remain stored until deleted manually or automatically by your browser.

    • First-Party Cookies: Set by our website.

    • Third-Party Cookies: Set by external providers for integrating services like payment processing or social media plugins.

Legal Basis for Cookies:
Cookies essential for electronic communication or providing requested services are stored under Art. 6(1)(f) GDPR. Consent is required for non-essential cookies under Art. 6(1)(a) GDPR and Section 25(1) TTDSG. Consent can be revoked at any time.

You can configure your browser to notify you about cookies, restrict their usage, or block them altogether. However, disabling cookies may limit website functionality.

Server Log Files
Our website automatically collects and stores server log file data:

  • Browser type and version

  • Operating system

  • Referrer URL

  • Host name of the accessing device

  • Time of server request

  • IP address

This data is collected under Art. 6(1)(f) GDPR for legitimate interests in ensuring the website's technical functionality and optimizing services.

Contact Form
If you submit a query via our contact form, the information provided, including your contact details, will be stored for processing your inquiry and follow-up questions.

  • Legal Basis:

    • For contract-related queries: Art. 6(1)(b) GDPR.

    • For other queries: Art. 6(1)(f) GDPR or your consent under Art. 6(1)(a) GDPR.

You can revoke your consent at any time. Data will be retained until its purpose no longer applies, subject to mandatory statutory provisions.

Email, Telephone, or Fax Queries
If you contact us via email, telephone, or fax, your inquiry and related personal data will be stored for processing.

  • Legal Basis:

    • Contract-related inquiries: Art. 6(1)(b) GDPR.

    • Other inquiries: Art. 6(1)(f) GDPR or consent under Art. 6(1)(a) GDPR.

Data will be retained until deletion is requested, consent is revoked, or the purpose is fulfilled, subject to statutory retention periods.

5. Social Media

Facebook
Our website integrates elements of Facebook, provided by Meta Platforms Ireland Limited, Dublin, Ireland. Data may also be transferred to Meta's parent company in the USA.

  • Functionality:
    When activated, Facebook plugins establish a direct connection between your device and Facebook's servers. Your IP address and, if logged in, your user account, may be linked to your website activity.

  • Legal Basis:

    • Consent-based: Art. 6(1)(a) GDPR and Section 25 TTDSG.

    • Legitimate interest: Art. 6(1)(f) GDPR for social media visibility.

Further details: Facebook Privacy Policy.

6. Plugins and Tools

YouTube (Extended Data Protection Mode)
We embed YouTube videos using extended data protection mode provided by Google Ireland Limited. This mode restricts data collection until videos are played.

  • Legal Basis:

    • Consent-based: Art. 6(1)(a) GDPR and Section 25 TTDSG.

    • Legitimate interest: Art. 6(1)(f) GDPR for a user-friendly website experience.

For more details: YouTube Privacy Policy.

Google Maps
Google Maps is used for displaying interactive maps. When activated, your IP address and other usage data are transferred to Google servers in the USA.

  • Legal Basis:

    • Consent-based: Art. 6(1)(a) GDPR.

    • Legitimate interest: Art. 6(1)(f) GDPR for enhancing website usability.

Further details: Google Privacy Policy.

7. Plugins and Tools

Vimeo (Do-Not-Track Mode)
This website integrates videos from Vimeo, provided by Vimeo Inc., New York, USA. We use Vimeo with the "Do-Not-Track" setting enabled, ensuring no user tracking or cookies are implemented.

  • Data Collected:
    When you visit a page with a Vimeo video, a connection is established to Vimeo servers, which may collect your IP address and details of your website activity.

  • Legal Basis:

    • Consent-based: Art. 6(1)(a) GDPR.

    • Legitimate interest: Art. 6(1)(f) GDPR for providing engaging content.

For details: Vimeo Privacy Policy.

8. Newsletter

Newsletter Data
To subscribe to our newsletter, you must provide a valid email address and consent to receive emails. This data is used exclusively for sending the newsletter and will not be shared with third parties.

  • Legal Basis:

    • Consent-based: Art. 6(1)(a) GDPR.

You may revoke consent at any time by clicking the "unsubscribe" link in the newsletter. Data will be deleted from the mailing list upon unsubscription unless legally required otherwise.

9. Data Security

SSL/TLS Encryption
This website uses SSL/TLS encryption to protect the transmission of sensitive data. An encrypted connection is indicated by "https://" in the browser’s address bar and a lock symbol.

Objection to Unsolicited Advertising
We prohibit the use of our published contact details for unsolicited advertising. Legal action may be taken in the event of violations, such as spam emails.

10. Your Rights

Right to Access
You have the right to obtain information about your stored personal data, its origin, recipients, and purpose at any time free of charge.

Right to Rectification and Erasure
You may request the correction or deletion of your data unless it is required to fulfill legal obligations.

Right to Restriction of Processing
You can request restricted processing of your personal data under certain conditions, such as disputes about accuracy or pending legal claims.

Right to Data Portability
You are entitled to receive your personal data in a structured, commonly used format and have it transferred to another controller if technically feasible.

Right to Object to Processing
If data is processed on the basis of Art. 6(1)(e) or (f) GDPR, you may object at any time due to personal circumstances. This also applies to profiling. If data is used for direct marketing, you have the right to object at any time without providing reasons.

Right to Lodge a Complaint
If you believe your rights under GDPR are being violated, you may lodge a complaint with a supervisory authority in your habitual residence, place of work, or the location of the alleged infringement.

11. Data Retention Periods

Personal data is stored only as long as necessary for its intended purpose or as required by law. Data will be deleted once the purpose no longer applies unless there are overriding legal obligations (e.g., tax or commercial retention periods).

12. Google reCAPTCHA

We use Google reCAPTCHA to determine if input on this website is made by a human or automated process.

  • Data Collected:
    reCAPTCHA analyzes user behavior (e.g., mouse movements, IP address) to verify legitimacy. This analysis runs in the background.

  • Legal Basis:

    • Legitimate interest: Art. 6(1)(f) GDPR to protect the website against spam and abuse.

For details: Google Privacy Policy.

13. Google Drive

This website uses Google Drive for uploading and storing content provided by users. When accessing our Google Drive-integrated upload area, a connection is established with Google servers.

  • Legal Basis:

    • Legitimate interest: Art. 6(1)(f) GDPR to enable seamless content uploads.

    • Consent-based: Art. 6(1)(a) GDPR.

For details: Google Privacy Policy.

14. Your Rights Under GDPR (Expanded)

Right to Revocation of Consent
If you have given your consent for data processing, you can revoke this consent at any time. The legality of the data processing carried out until the revocation remains unaffected.

Right to Complain to a Supervisory Authority
If you believe your data protection rights have been violated, you have the right to file a complaint with a supervisory authority. This can be the authority in your habitual residence, your workplace, or where the alleged infringement occurred.

15. Third-Party Data Transfers

Transfer to Non-EU Countries
We may transfer personal data to third-party countries that do not offer the same level of data protection as the EU. These transfers occur only if they are necessary for contract fulfillment or based on your consent.

For transfers to the USA or other countries not covered under the EU-US Data Privacy Framework, additional safeguards, such as standard contractual clauses, are implemented.

16. Social Media Integrations

Facebook, Instagram, and X (formerly Twitter)
This website integrates social media plugins to enhance user engagement and visibility. When these plugins are active, a direct connection between your device and the provider’s servers (e.g., Facebook, Instagram, or X) is established. Personal data such as your IP address and user interactions may be collected and stored.

  • Legal Basis:

    • Consent-based: Art. 6(1)(a) GDPR.

    • Legitimate interest: Art. 6(1)(f) GDPR for increasing website visibility.

Further details can be found in their respective privacy policies:

17. Use of Analytics and Advertising Tools

Google Analytics
We use Google Analytics to track and analyze user behavior to improve website performance. Google Analytics collects data such as IP addresses, browser types, and session durations.

  • Legal Basis:

    • Consent-based: Art. 6(1)(a) GDPR for data collection via cookies.

Data is anonymized wherever possible, and IP addresses are truncated within the EU before transfer to Google servers in the USA.

For details: Google Analytics Privacy Policy.

Advertising Cookies
Our website may use cookies for targeted advertising. These cookies track user activity across websites to provide personalized ads.

  • Opt-Out Options:
    You can opt out of targeted advertising through browser settings or tools like Your Online Choices.

18. Updates to This Privacy Policy

We reserve the right to amend this privacy policy as needed to comply with legal updates or changes to our website’s features. The updated policy will apply immediately upon publication.

19. Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that significantly affects users.

  • Legal Basis:
    Should automated processes be required for specific functionalities, they will only occur based on explicit user consent or under Art. 6(1)(b) GDPR (contract fulfillment).

20. Data Breaches and Reporting

In the event of a data breach, we are committed to notifying affected individuals and the relevant supervisory authorities without undue delay.

  • Legal Obligation:
    As per Art. 33 GDPR, we will report any breaches involving personal data that pose risks to user rights and freedoms.

21. Children's Data

This website is not intended for children under the age of 16. We do not knowingly collect or process data from individuals in this age group without parental or guardian consent.

22. Detailed Cookie Management

Cookie Types and Purposes:

  • Essential Cookies: Required for website functionality (e.g., user logins).

  • Performance Cookies: Track website usage to improve user experience.

  • Targeting Cookies: Enable personalized marketing and advertising.

You can manage cookies via browser settings or specific cookie management tools integrated into the website (e.g., a cookie consent banner).

23. Additional Information on Hosting Provider (Squarespace)

Standard Contractual Clauses (SCCs):
All data transfers to Squarespace comply with SCCs to ensure GDPR-compliant processing.

For more details:

  • Squarespace GDPR Compliance

24. Third-Party Data Processing Agreements

Whenever third-party providers process user data, a legally binding Data Processing Agreement (DPA) is signed to ensure they act strictly under our instructions and in line with GDPR requirements.

Examples include:

  • Hosting services

  • Payment gateways

  • Marketing tools

25. Questions or Concerns

For any questions, concerns, or requests regarding this privacy policy or how we handle your personal data, you can contact us via the following:

Contact Information:
Zafer Ertem
Vali Konaklari, Altinkale Mah, Selcuklu Cad. No 1
07190 Antalya, Türkiye
Email: pilot.barbossa((@))gmail.com