Legal preparation text • Not a live notice
Privacy Policy
Preparation framework for data minimisation, suppliers, security, retention, and visitor control on the ATUGIS website.
Last content review: 17 July 2026
1. Scope and related notices
This policy is limited to the ATUGIS website, Academy content, contact form, consent preferences, and their security. Personal data processed after a customer service relationship begins—such as employee, device, support-ticket, or contract records—will require separate notices and contractual controls.
The Privacy Notice explains the required elements of specific processing; the Cookie Policy describes device storage and optional technologies; and the Data Subject Request page explains how rights may be exercised.
2. Minimisation and purpose limitation
The form is limited to fields needed for an initial assessment. A telephone number and business name are optional. Passwords, remote-access codes, identity documents, health or biometric information, and payment details are not requested through the website.
Data collected for one purpose will not be repurposed without assessing transparency and legal-basis requirements. Analytics consent is not a condition for submitting an enquiry.
3. Supplier and data-flow governance
Each hosting, security, email, or measurement provider must be recorded in [TEDARİKÇİ VE VERİ AKIŞI ENVANTERİ] with its purpose, role, data, subprocessors, location, retention, and deletion controls. A new provider will not receive production data before contractual and technical checks are complete.
A temporary preview never sends a real email. Production email may be enabled only after the Microsoft 365 mailbox is verified and Exchange Online Application RBAC limits the application to that contact mailbox.
4. Security and incident handling
The planned controls combine least privilege, environment-held secrets, input validation, bot protection, trusted origin/host checks, rate limiting, dependency review, and log minimisation.
A suspected incident will be assessed through an internal process recording scope, affected data, timeline, containment, and notification duties. Named owners and communication routes will be completed with the official company information.
5. Retention and lifecycle
Data will not be kept indefinitely. [SAKLAMA VE İMHA PLANI] will assign separate periods and deletion triggers to contact requests, security events, error records, consent evidence, and legal-defence needs.
Residual backup copies will be access-restricted and overwritten or securely deleted through the normal backup lifecycle. A deletion request will be assessed against any overriding legal retention duty.
6. Visitor control and changes
Visitors can reopen Cookie Preferences from the persistent footer control, accept or reject optional analytics, and withdraw a previous choice. Theme storage can also be cleared from the device.
A material operational or legal update will carry a new review date and change summary. A new purpose that falls outside an earlier choice will require fresh information and, where necessary, a new affirmative choice.