For readers in Türkiye, the EU/EEA and other countries
Privacy Policy
Last updated: 16 September 2026
Our principle: collect little, store it encrypted, delete it on time
Talay Insight is a publication, not a data business. You do not need to give us any personal information to read the site. Personal data is processed only when you start a subscription to the brief, use the contact form or make a data protection request.
1. Controller
talayinsight.com ("Talay Insight") is operated by Lu Apps LLC, which acts as controller of the personal data described in this policy.
- Entity: Lu Apps LLC · Wyoming
- Address: 30 N Gould St, Ste R, Sheridan, WY 82801, USA
- Privacy requests: serhatg@luapps.app
2. What we process, why, and on what legal basis
| Process | Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Subscription to the brief | Email address, language and content preferences | Sending the brief and publication notices; managing your preferences | Consent (Art. 6(1)(a)) |
| Consent record | Date of consent, version of the text consented to, country code | Demonstrating that consent was obtained | Legal obligation (Art. 6(1)(c), read with Art. 7(1)) |
| Contact form | Name (optional), email address, content of the message | Replying to your enquiry | Legitimate interest (Art. 6(1)(f)) |
| Data protection requests | Identity and contact details, content of the request | Handling your request within the statutory deadline | Legal obligation (Art. 6(1)(c)) |
| Site security | IP address and browser information (short-lived, processed by our infrastructure provider) | Preventing attacks and abuse | Legitimate interest (Art. 6(1)(f)) |
We do not record your IP address in our database; it is processed briefly by our infrastructure provider for security purposes only. Visitor statistics are measured without cookies, as aggregate counts only; see section 5.
3. Service providers and international transfers
Your personal data is never sold, rented or shared for advertising. To provide the service, it is disclosed only to the following service providers, and only to the extent the service requires:
- Cloudflare, Inc. (United States): hosting, security and database infrastructure.
- Resend (United States): delivery of the brief and notification emails.
Transfers to these providers are made under appropriate safeguards: the European Commission's Standard Contractual Clauses for data from the EU and EEA, and, for data from Türkiye, the standard contracts published by the Turkish Personal Data Protection Board and notified to it. Information may be disclosed to public authorities with legal powers only in response to a lawful request and only within the scope of that request.
4. How long we keep it
| Data | Retention period |
|---|---|
| Subscriber email address and preferences | For the duration of the subscription; deleted within 30 days after you unsubscribe |
| Consent record | Duration of the subscription plus 3 years |
| Block on re-sending | Indefinitely, but only as an irreversible hash |
| Contact messages | 12 months |
| Data protection requests | 3 years |
5. How we protect it
- All connections are encrypted (HTTPS, HSTS).
- Email addresses are encrypted at the application layer in the database; the encryption key is not kept in the same place as the database.
- The administration panel is not open to the internet; it is accessible only to the authorised editorial desk, with strong authentication. Every access to data is written to an audit log.
- Forms pass through bot protection and rate limiting.
- We use no advertising, tracking or third-party analytics tools.
- Visitor statistics are cookieless and first-party: we store only aggregate counts (page, clicked link, hour, country, language, rough screen class, referring site's domain). Your IP address is not stored; to count unique visits within a day we derive an irreversible hash from your IP address and browser details using a key that changes every day, and delete that hash within 48 hours. Location is country-level only. Nothing is measured if your browser sends Global Privacy Control or Do Not Track.
6. Data breaches
If a security incident affects your personal data, we notify the competent supervisory authority within 72 hours, including the Turkish Personal Data Protection Board as required by Turkish law, and inform the people affected as soon as possible.
7. Your rights
Wherever you live, you may ask us:
- to confirm whether we process your personal data and to provide a copy of it (access);
- to correct data that is inaccurate or incomplete (rectification);
- to delete your data (erasure);
- to restrict processing in certain circumstances (restriction);
- to provide the data you gave us in a structured, machine-readable format (portability);
- to stop processing based on our legitimate interests (objection);
- to withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out before it.
We do not take decisions about you based solely on automated processing. If you are in the EU or EEA, these rights arise under the General Data Protection Regulation (GDPR), and you may also lodge a complaint with the data protection authority of the country where you live or work.
Readers in Türkiye also have the rights set out in Article 11 of Law No. 6698 on the Protection of Personal Data (KVKK); these are described in the Turkish-language KVKK notice.
8. How to make a request
Send your request to serhatg@luapps.app from the email address you subscribed with, or choose "Personal data request" as the subject in the contact form. You can access, download and delete your subscription data directly on the subscription management page. Requests are handled free of charge and within 30 days at the latest.
9. Children
Our service is not directed at people under the age of 16, and we do not knowingly collect data from them.
10. Changes
We notify subscribers by email of any material change to this policy at least 15 days before it takes effect. Previous versions are available on request.