Privacy NoticeData protection, cookies and your rights
Effective date: July 12, 2026
This notice explains the actual personal-data practices of hypnosreklam.com, operated under the HYPNOS REKLAM name.
It should be read together with any service-specific terms and updated when the implementation or providers change.
1. Who We Are and Scope
HYPNOS REKLAM acts as the controller for the personal data described in this notice when you use hypnosreklam.com. This notice explains the site's actual data practices in a general international context and provides information under the UK GDPR, the Data Protection Act 2018 and PECR where those laws apply.
The codebase does not contain a verified business address, company registration number, data protection officer or UK representative. Those details must not be inferred and should be added if legally required. Until then, privacy requests may be sent to destek@hypnosreklam.com or made by phone at 0534 683 47 19.
References to UK law do not imply that the business is established in the United Kingdom. The UK GDPR may apply, for example, where services are offered to people in the UK or their behaviour there is monitored; territorial scope must be assessed against the facts.
2. Personal Data We Collect
Depending on how you use the site, we collect or derive the following information:
- IP address and IP-derived country, region, city, postal code, approximate latitude/longitude and time zone, plus ISP, organisation and ASN
- User-agent, browser and rendering engine name/version, operating system, CPU architecture, device type, vendor and model
- Language(s), platform, screen dimensions, colour depth, pixel ratio, processor cores, memory, touch points, connection type/speed/latency, and GPU vendor/renderer
- Cookie support, Do Not Track signal, time zone, a random persistent visitor ID, and hashed fingerprints derived from canvas, WebGL, audio, fonts and other device characteristics
- Fraud and automation indicators such as webdriver/headless signals, sensor or pointer behaviour, spoofing indicators, risk score/category and correlations between a fingerprint and multiple IP addresses
- Page visited, page URL/title, referrer, visit/event time and session-level visit status
- Call or WhatsApp click type, destination URL, source page, visitor ID, IP, user-agent and approximate location
- Name, phone number and message entered in the contact form, together with visitor ID and IP
- If you continue to WhatsApp, the pre-filled name, phone and message that you choose to send through that service
3. How We Collect It
Data is collected directly from form fields and automatically through browser/device APIs, HTTP request headers, server logs, localStorage, sessionStorage, cookies and similar technologies, click listeners and an external IP-geolocation query.
The application may create a persistent visitor ID (hypnos_vid), a session measurement marker (hypnos_tracked), and an approximately 24-hour fraud-risk cookie (hypnos_tq). Closing the information notice stores hypnos_privacy_notice_v2; this is not a consent preference.
4. Purposes and Lawful Bases
We must have a lawful basis for each use. The appropriate UK GDPR basis depends on the context:
- Responding to enquiries and discussing a requested service: steps at your request before a contract, performance of a contract, and/or legitimate interests in customer communication
- Delivering and debugging the site, protecting systems and detecting abuse or advertising click fraud: legitimate interests in security and fraud prevention, balanced against your rights
- Keeping records needed for legal claims or regulatory duties: legal obligation and/or legitimate interests in establishing, exercising or defending legal claims
- Audience measurement, campaign attribution, GA4 and persistent or fingerprint-based tracking: consent where required by the UK GDPR and applicable electronic-communications rules; only genuinely limited and necessary measurement should rely on legitimate interests
- Measuring call and WhatsApp conversions: consent where the measurement uses non-essential storage/access or tracking; otherwise a documented and balanced legitimate interest where legally available
5. Cookies, Local Storage and Information Notice
The notice at the bottom of the page explains data use; it is not a consent panel and does not present Accept or Reject choices. Closing it only stores hypnos_privacy_notice_v2.
The visitor tracker, persistent visitor identification and fingerprint/fraud shield start automatically when the page loads. Google Analytics 4 also loads automatically when configured.
You can reopen the notice through “Data Use” in the footer. Closing the notice does not stop processing.
You can block or clear cookies and site storage through your browser. The Do Not Track value may be recorded as technical data, but the current application does not stop tracking in response to it. A separate consent mechanism may still be legally required for analytics or device access where the UK GDPR, PECR or other applicable law requires consent.
6. Recipients, Providers and International Transfers
Data may be available to authorised staff and hosting/network providers; ip-api.com for IP geolocation; Google Analytics 4/Google if configured; WhatsApp/Meta when you follow a WhatsApp link; and public authorities where disclosure is legally required.
The visitor and click endpoints may automatically send the IP address to ip-api.com to obtain approximate location and network information. If GA4 is configured, Google may receive page, device, event and fraud-classification data. The code requests GA's anonymize_ip setting, but that does not eliminate all personal-data processing or international transfer. If you proceed to WhatsApp, Meta processes the link interaction and any message you choose to send under its own terms.
The business has a Turkish connection and data is stored by the application's hosting environment. Depending on the provider configuration, data may be transferred to Türkiye, the United States or other countries. For restricted transfers from the UK, an adequacy regulation, the UK International Data Transfer Agreement/Addendum or another valid safeguard must be used where required. The actual hosting locations, provider contracts and transfer safeguards must be verified rather than assumed.
We do not sell personal data as a marketing list.
7. Retention
No automatic deletion schedule or verified fixed retention period for visit, click, fraud or contact records is evident in the code. Records appended to server files may remain until manually removed. A documented retention and deletion schedule should therefore be adopted.
We should keep each record only for as long as needed for the relevant enquiry, service, security investigation, reporting purpose or legal claim, then delete or anonymise it. The hypnos_tq cookie lasts about 24 hours, the session marker normally lasts for the browser session, and localStorage values may remain until the user or application removes them. Google and Meta apply their own configured or policy-based retention periods.
8. Security and Automated Assessment
Reasonable technical and organisational safeguards should be used, but no internet transmission or storage system can be guaranteed completely secure.
When the page loads, device and behaviour signals may be combined automatically into a safe, warning, suspicious or bot score. Similar fingerprints may be correlated across different IP addresses, and a fraud event and classification may be sent to GA4 for advertising-traffic filtering. The observed implementation does not by itself appear to make a decision producing legal or similarly significant effects on an individual. If that changes, meaningful information, a route to challenge the result and human review must be provided where required.
9. Your UK Data Protection Rights
Where the UK GDPR applies, and subject to its conditions and exceptions, you may have the right to:
- Access your personal data and receive information about its use
- Correct inaccurate or incomplete data
- Request erasure or restriction of processing
- Object to processing based on legitimate interests and object absolutely to direct marketing
- Receive data you provided in a portable format where the portability conditions apply
- Withdraw consent at any time, without affecting earlier lawful processing
- Not be subject to qualifying solely automated decisions with legal or similarly significant effects
10. Requests, Complaints and Contact
Send a request describing your identity and the right you wish to exercise to destek@hypnosreklam.com, or contact 0534 683 47 19. We may request proportionate proof of identity; please do not send unnecessary identity documents. Where UK law applies, we normally respond within one month, subject to permitted extensions.
You may complain to the UK Information Commissioner's Office (ICO) if the UK GDPR applies to the processing. The ICO can be contacted through ico.org.uk. You may also complain to the competent authority in your country of residence, work or the place of the alleged infringement. Contacting us first may allow the concern to be resolved more quickly, but it is not a condition of complaining to a regulator.
11. Changes to This Notice
We may update this notice when technologies, providers or legal requirements change. The current version and effective date should be shown on this page, and material changes should be communicated appropriately.