Last Updated: September 7, 2026

Privacy Notice & Personal Data Protection Policy

Information on the processing, storage, transfer of your personal data and your rights pursuant to Law No. 6698 on Protection of Personal Data ("KVKK") and GDPR.

Data Controller Gezi Rota TR
Country Türkiye
Contact Email [email protected]
KVKK Registry (VERBİS) Not required to register
Website gezirota.tr

1. Data Controller & Legal Framework

Gezirota ("Data Controller" or "Platform") attaches utmost importance to the privacy and security of visitors' personal data while providing travel planning and guidance services on gezirota.tr. This Privacy Notice has been prepared in accordance with Article 10 of the Turkish Law No. 6698 on Protection of Personal Data ("KVKK") and applicable data protection regulations (including GDPR where relevant).

The Data Controller's registered trade name is Gezi Rota TR. It does not hold a Registered Electronic Mail (KEP) address, and given the nature and scale of its activities it is not required to register with VERBİS (the Turkish Data Controllers' Registry). For this reason, requests under KVKK are accepted only through the email channel (see Section 7).

2. Categories of Processed Personal Data

The following categories of personal data are processed when you visit and use our Platform:

  • Essential Technical Signals & Server Data: Visited page path, a randomly generated short session code that is not stored, timestamp, IP address, device/browser details, and up to 3 limited JavaScript error messages per page. These are processed without cookies for technical operation and security; the IP address is never stored in plain text on the server — it is encrypted with the ChaCha20-Poly1305 algorithm and kept only in an encrypted column.
  • Consent Preference Record: The consent version, timestamp, analytics, product analytics, and session recording choices selected in the cookie panel. Stored strictly in your browser's local storage under the key gzOnay; never sent to the server.
  • Analytics Data (Subject to Explicit Consent): Pseudonymized IP address, page views, referrer URLs, and device features collected via Google Analytics 4 only if you grant “Analytics” consent.
  • Product Analytics Data (Subject to Separate Explicit Consent): A persistent browser identifier (gzUrunKimligi), planning-funnel events, product interactions, and return-visit information processed via PostHog EU only if you grant “Product analytics” consent.
  • Session Recording Data (Subject to Separate Explicit Consent): Mouse clicks, scrolling, screen movement, window dimensions, page DOM interactions, form contents, and free text collected via Microsoft Clarity only if you grant separate consent. Once granted, the page is recorded unmasked by default; only 8 fields are additionally masked — the 6 fields of the "Share your route" form plus the AI planning box and the optional reply-email field in "Report an error". The message box itself in "Report an error" is not masked (see Section 8 for details).
  • Route submission: Submitting the "Share your route" form requires your explicit consent. When you submit your plan, we process your name/nickname, email address, tour name, short description, duration, an optional "why is it special" text, the full plan (including all days/stops/hotels), a list of provinces derived from the plan, your language, and your submitting IP address. Your email is used solely to inform you of the outcome (approval or a reasoned rejection) and is not shared with third parties. Your name, email, IP, and plan content are stored server-side in a single encrypted block; the IP address is additionally indexed separately via a non-reversible hash (HMAC) — the plain IP is never stored in any queryable column. A verification link is sent to your email. If your submission is rejected, your email address is deleted; this deletion happens automatically and irreversibly immediately after the rejection notice. Your name or nickname appears on the route page as the contributor if the route is published.
  • "Report an Error" Form (Requires Explicit Consent): Your message (up to 1500 characters), the page path you were on, an optional reply email, and optional attachments (up to 5 files, of limited types) are sent to /gezi/api/bildir. A diagnostic file is automatically attached, containing your browser/OS info, language, screen size, the address of the page you visited, your app settings (with likely API key/token/password fields automatically redacted), and your last 20 client-side errors. On the server, the message, email, and diagnostic data are stored in a single encrypted block; the key difference here is that the sender's IP address is reduced to a /24 network prefix (IPv4) or /48 (IPv6) before encryption — so even in the encrypted data, this flow never contains a full IP address, only a network range.
  • AI-Assisted Plan Generation (Requires Explicit Consent, Involves an International Transfer): The free text you enter (up to 500 characters) is sent through our server to Google's Gemini API. Your free text is not stored in Gezirota's own database; only the request timestamp, your IP, your browser info, and processing metadata (event name, number of plans generated, latency) are written to an anonymous analytics record.
  • Direct Requests to Third Parties (Independent of Consent, Core Functionality): Route calculation (OSRM), address/hotel search and reverse geocoding (Nominatim), map tiles, weather data (Open-Meteo), and library/font CDNs go directly from your browser to the relevant provider for the site's core functions; these requests carry your IP address and do not pass through the Gezirota server. These flows are independent of the optional categories in the cookie consent banner and cannot be disabled (see Section 4 for details).
  • Cloudflare Performance Measurement (Not Present in the Site's Own Code): The Cloudflare reverse proxy in front of gezirota.tr injects its own performance-measurement (RUM) script into the page; this request is not present in the site's source code and operates entirely independently of cookie consent (see Section 4 for details).

3. Purposes & Legal Grounds for Processing

Your personal data is processed under the following legal bases:

a) Legitimate Interest (Without Consent Requirement)

Technical signals processed to maintain basic website security, enable core functions, count cookieless anonymous visits, and log system errors rely on KVKK Art. 5/2(f) (Legitimate Interest) provided it does not harm your fundamental rights and freedoms. Your consent record (gzOnay) is kept only in your browser, so it does not constitute a "transfer" to the server; it is maintained there to prove your choice.

b) Processing Based on Your Explicit Consent

The following processing activities rely on your separate, independently revocable explicit consents under KVKK Art. 5/1 (and GDPR Art. 6(1)(a)): submitting the "Share your route" form (to review, publish, and contact you about your submission — the act of filling out and submitting the form is itself treated as an explicit request and consent), submitting the "Report an error" form (to review the issue you reported and, if you wish, respond to you), AI-assisted plan generation (to produce a trip plan based on your request — since you are the one requesting this service), aggregate usage measurement (Google Analytics 4), planning-funnel and return-visit measurement with a persistent identifier (PostHog EU), and usability analysis through unmasked recordings that include form contents and free text (Microsoft Clarity). Declining these does not restrict essential platform features (route calculation, address search, maps, weather). You can withdraw consent at any time; withdrawal has effect only going forward.

Note: The "explicit consent" characterization for the route submission and error report forms is a reasonable legal reading but is not conclusive; it should be confirmed by legal counsel prior to publication.

4. Data Transfer & International Data Transfers

Due to third-party analytics and functional services used by Gezirota, personal data transfers occur as follows:

  • Google Analytics 4: Upon analytics consent, usage data is transferred to Google LLC servers. IP anonymization is active. Advertising personalization features are disabled.
  • PostHog Cloud EU: Upon product analytics consent, the persistent browser identifier and product events are processed on PostHog Inc.'s servers located in Frankfurt/Germany (EU region). PostHog session recording is disabled in our integration.
  • Microsoft Clarity: Upon separate session recording consent, unmasked interaction data including form contents and free text is processed via Microsoft Corporation infrastructure; only the optional error-report email is masked.
  • AI-Powered Planning (Google Gemini): When you use “Plan with AI”, the free-text trip request you enter is transferred from the Gezirota server to Google Gemini API infrastructure abroad to generate the plan draft.
  • Map and Routing Services (OSRM, the Project OSRM community): When routes, distances and travel times are calculated, the latitude/longitude coordinates of stops in your plan are transferred to OSRM routing infrastructure abroad.
  • Address Search (Nominatim): Your search term or selected coordinate is transferred directly from your browser to the OpenStreetMap Foundation's Nominatim infrastructure for reverse geocoding.
  • Weather (Open-Meteo): The coordinates and dates of the stops in your plan are transferred directly from your browser to Open-Meteo infrastructure to obtain weather data.
  • CDN Providers (unpkg, jsdelivr, sheetjs, Google Fonts): Your IP address reaches these providers when font and code files are downloaded.
  • Purelymail (SMTP email provider, US-based): When you use the route submission form, your name, email, and tour name are transferred through this provider to send you verification and result emails.
International Transfer Notice: Transfers to Google Analytics 4, PostHog Cloud EU and Microsoft Clarity rely only on the corresponding explicit consents granted through the cookie consent panel; if consent is not given, no data is transferred. AI planning, map/routing/search/weather services, CDN file servers, and Purelymail transfers occur because the requested functionality (plan generation, route drawing, search, maps, email verification) cannot be delivered at that moment without them, making these transfers a necessary part of providing the service. International transfers are handled in accordance with KVKK Article 9.
Cloudflare RUM Exception: The performance-measurement (RUM) script sent to static.cloudflareinsights.com is not present in the site's own source code; the Cloudflare reverse proxy in front of gezirota.tr injects it into the page itself, and it operates entirely independently of visitor cookie consent. The Data Controller has decided to leave this measurement active, relying on KVKK Art. 5/2(f) legitimate interest in monitoring the infrastructure's security and performance; explicit consent cannot be obtained for this flow, and it is disclosed here in the interest of transparency. Visitors cannot disable this measurement through the site; it can only be blocked with browser-level tracker blockers.

5. Data Retention Periods

Data Category / Provider Storage Location Retention Period
Consent Record (gzOnay) Browser LocalStorage Until cleared or modified by user
Cookieless Analytics / Technical Event Records Server Records Anonymized analytics rows: 730 days (2 years); legacy rows from before migration 010 that may contain raw IP/UA: 90 days
Google Analytics 4 Data Google Servers The technical lifetime of the _ga cookie is up to 2 years; the account-level analytics data retention period has been set by the Data Controller in the provider panel to 2 months, confirmed on 2026-09-07
PostHog EU Data PostHog EU Servers (Frankfurt) The technical lifetime of the SDK cookie is 365 days; the localStorage identifier persists until consent is withdrawn or browser data is cleared; the account-level project data retention period has been set by the provider panel to 30 days, confirmed on 2026-09-07
Microsoft Clarity Data Microsoft Servers The account-level session recording and heatmap data retention period has been set in the provider panel to 30 days, confirmed on 2026-09-07
Route Submission Form Record (name/email/plan) Gezirota Server (encrypted) No automatic time limit exists in the code; if a submission is rejected, the email address is automatically and irreversibly deleted. Data Controller decision: records are targeted for deletion within 60 days; complete deletion currently depends on manual action by site administration.
Error Report Record (message/attachment/diagnostic file) Gezirota Server (encrypted) No automatic time limit exists in the code; only manual deletion is available. Data Controller decision: records are targeted for deletion within 30 days.

Data is deleted once the retention period ends; a verified backup is taken before the pruning of server-side analytics records.

6. Rights of the Data Subject

Pursuant to KVKK Article 11 (and applicable GDPR provisions), data subjects possess the following rights:

  1. To learn whether personal data is processed,
  2. To request information if personal data has been processed,
  3. To learn the purpose of processing and whether data is used in accordance with its purpose,
  4. To know third parties to whom personal data is transferred domestically or abroad,
  5. To request correction of incomplete or inaccurate data,
  6. To request deletion or destruction of personal data under statutory conditions,
  7. To request notification of correction, deletion, or destruction to third parties to whom data has been transferred,
  8. To object to an adverse outcome resulting exclusively from automated processing,
  9. To claim compensation for damage suffered due to unlawful processing.

7. Application Procedure & Contact

To exercise your statutory rights, you may submit your request via official channels:

  • By Email: Send your request along with identity verification details to [email protected]. As the Data Controller does not hold a KEP address and has no published physical correspondence address, email is the only application channel.

Requests will be concluded free of charge as quickly as possible and within 30 (thirty) days at the latest.

Go to Data Subject Application Form & Guide →

8. Managing Cookie Preferences

gezirota does not write cookies unless you give permission. Your choice is not stored as a cookie but as a record named gzOnay in your browser's localStorage; this is not a cookie and stays only in this browser. Once you grant permission, the third-party tools that load (Google Analytics 4, PostHog, Microsoft Clarity) may write their own cookies (see the Cookie Policy for details). You can separately modify or withdraw your consent for analytics, product analytics, or session recording at any time. Click the "Cookie Settings" link in the site footer or click the button below to reopen the preferences panel:

If Do Not Track (DNT) or Global Privacy Control (GPC) is enabled in your browser, optional cookie categories start disabled automatically.