Storage ledger · reviewed 04.10.2026
What This Site Stores
Not a policy. A list of every key this site writes to your device, with a button beside each one that deletes it.
-
0
cookies set by this site
see the hosting note below for Cloudflare’s
-
1
storage entry
local, and listed below
-
0
requests to other origins
fonts and styles are served from here
-
0
analytics or trackers
nothing counts you
The short version
This website sets no cookies of its own. It runs no analytics, no advertising tags, no session tracking, no social embeds and no third-party scripts. There is no consent banner because there is nothing on this site that requires consent.
We are a data protection practice. Publishing a cookie policy that describes cookies we do not set would be a compliance failure of exactly the kind we are retained to prevent, so this page describes only what the site actually does.
What the site is
gdpr.com.tr is a statically generated website. Every page is a pre-built file served from Cloudflare’s edge network. There is no application server, no database and no user account behind it. Nothing you do on this site is associated with an identifier we create.
Typefaces, stylesheets, scripts and images are served from this domain. The site makes no request to Google Fonts, to a content delivery network we do not control, or to any analytics or advertising service.
The ledger
| Key | Purpose | Store | Lifetime | Transmitted | Clear |
|---|---|---|---|---|---|
lex-lang-parallel On this device | Remembers that you asked the statute reader to show both languages of every paragraph at once on narrow screens, instead of one paragraph at a time.
| not a cookie | No expiry is set. It stays until you clear it here or clear site data in your browser. | never leaves your browser |
The “on this device” line under each key reads your own browser as this page loads. The reading happens in your browser and is reported to nobody — not to us, and not to anyone else.
And what is not here
- Cookies set by this site
- none — not first-party, not third-party, not on any page. Our hosting provider may set one strictly necessary security cookie when it challenges automated traffic; that is described below, and it is the only cookie you could ever meet here.
- Requests to another origin
- none — typefaces, stylesheets, scripts and the marble scan all come from gdpr.com.tr
- Analytics
- none — no page-view counter, no product analytics, no heatmap, no session replay
- Trackers, pixels, tag managers
- none
- Embeds (maps, video, chat, social, fonts)
- none — this is why the contact page carries an address and no map
- Identifiers created by the site
- none — nothing you do here is tied to an identifier we mint
- Typefaces
- two families — Instrument Sans and Martian Mono — subsetted and self-hosted, licensed under the SIL Open Font Licence
- Images
- no photographs and no generated imagery. The one figure on the site is a scan of a real marble sculpture, drawn in your browser from a file served by this domain — or, where it cannot be drawn, a still of the same scan; its source, licence and processing are declared on the provenance page
Why local storage is on this page at all
This is not a cookie, but we disclose it anyway. Article 5(3) of the ePrivacy Directive and the Board’s approach to terminal-equipment storage both look at storing or accessing information on a user’s device, not at the technical format used to do it. A policy that lists cookies and stays silent about localStorage is incomplete.
Clearing it
Every current browser lets you block or delete cookies and clear site storage. This site depends on neither, so blocking both leaves it entirely functional — you may simply have to tick the statute reader’s “both languages” box again. The button in the table above does the same job for this site alone, and touches nothing you have stored anywhere else.
Cookies our hosting provider may set
Cloudflare, Inc. provides hosting, TLS termination and network security for this domain. If Cloudflare’s bot management or challenge features are triggered by a request — typically automated traffic, not ordinary browsing — Cloudflare may set a strictly necessary security cookie such as __cf_bm or cf_clearance. These are used only to distinguish automated traffic from human visitors and to remember that a challenge was passed. They carry no advertising or analytics function and are not used to profile you. Cookies of this kind fall within the strictly necessary exemption and are not subject to consent.
Server logs
Delivering a web page requires processing your IP address and request metadata. Cloudflare processes this data as our hosting and security provider for the purposes of routing the request, terminating TLS, mitigating attacks and maintaining service availability. We do not build visitor profiles from it, do not join it to any other dataset, and do not use it for marketing. The lawful basis is our legitimate interest in operating and defending the site securely.
The Atlas is a separate site
atlas.gdpr.com.tr is published separately and hosted by GitHub Pages, a service of GitHub, Inc. When you follow a link to the Atlas, your request goes to GitHub’s infrastructure and is governed by GitHub’s own privacy and cookie practices, not by this page. The Atlas is a static publication and we do not run analytics on it either.
Links out
Where we link to third-party sites — the Authority, EUR-Lex, the Official Gazette, our sister firm at lexis.com.tr — those sites set their own cookies once you arrive. We have no control over them and no visibility into them.
The contact form
The contact form does not use cookies. When it is submitted, the information you type is transmitted to the endpoint that receives enquiries and used only to answer you. How that submission is handled is described in the Contact Form Privacy Notice, which is the document to read if you want to know what happens to your enquiry.
Changes
If we ever add a component that sets a cookie or stores anything further on your device — analytics, an embedded map, a video player, a chat widget — we will update this page before that component goes live, and we will implement consent where consent is required. If this page says the site sets no cookies, that is a statement about the site as deployed today.
Questions
Write to info@gdpr.com.tr. If you believe this page is inaccurate, we would genuinely like to know.
Why this page cannot go stale
The table is generated from src/data/storage-keys.json, which is where this build declares what it writes to a visitor’s device, and the declaration is checked: every time the site is built, the build reads its own source for each write to browser storage and each cookie, and stops if the list and the source disagree. The predecessor site published a cookie policy describing the hosting platform’s cookies; it became false the day the site left that platform, and nobody had to touch the policy for that to happen. Here the same drift stops the build.