Controller identity — unresolved launch blocker
The final legal identity of the data controller, its official address and any required registration/contact details have not been supplied. Turkish counsel must determine whether the controller is Ahmed Mujahed personally, another MUJ legal/business entity, RookZ Doruk, or a defined allocation between parties. The website must not guess this.
Data categories and purposes
The current site processes identity/contact details, inquiry and viewing information, account/preferences, favorites and saved searches, uploaded profile/media information, consent/privacy-request records, administrator/audit records, first-party analytics if allowed, and technical abuse-prevention data. Purposes are responding to requested services, account features, property/viewing administration, security, auditability, recovery and optional site measurement.
Collection method and legal basis — counsel to finalize
Information is collected electronically from website forms, account activity, authenticated identity headers, uploads and technical requests. The exact KVKK Article 5/6 processing condition for each purpose must be mapped by Turkish counsel. Necessary service processing is not presented as optional marketing consent, and the site no longer makes a privacy-acknowledgement checkbox a condition of submitting a normal request.
Recipients and transfers
Technical recipients/services currently include the OpenAI/ChatGPT Sites hosting/authentication environment and Cloudflare infrastructure; browser-requested external resources can also involve OpenStreetMap, Wikimedia Commons or Unsplash. TurkiyeAPI can receive server-side location-query text. User-chosen links can transfer the user to Google Maps or Meta/WhatsApp/Instagram/Facebook/TikTok. The legal recipient categories, processor/controller roles and any Article 9 international-transfer safeguard must be confirmed before launch.
Data-subject rights
The final notice must preserve the rights available under KVKK Article 11, including learning whether data is processed, requesting information, learning purpose and use, knowing recipients, requesting correction, requesting deletion/destruction where conditions apply, requesting notification of correction/deletion to recipients where applicable, objecting to certain exclusively automated results, and seeking compensation for unlawful processing where the legal conditions are met.
Application handling
The Account privacy center starts a review request and the administrator can track requested, in-review, completed or rejected states with notes and an audit trail. Formal KVKK applications may require identity verification and the legally prescribed application information/method. The controller should answer a compliant application as soon as possible and no later than 30 days, subject to the applicable rules.
Retention and destruction
The 24-month date applied to new website inquiries and viewing requests is a provisional operational review point requested by the owner, not a legally approved destruction period. Counsel must approve the schedule for accounts, leads, viewings, favorites, saved searches, privacy requests, analytics, security/audit records and backups. Technical backup retention currently preserves selected recovery points for up to 12 months; deletion requests must be reconciled with lawful retention and protected backup expiry.
Required professional sign-off
Before public launch, Turkish counsel/KVKK expertise must approve controller identity, Article 5/6 legal bases, recipient groups, Article 9 international-transfer safeguards, retention/destruction periods, application route, VERBİS status and the final Turkish wording. English and Arabic should remain translations of the approved Turkish substance.
Official references
KVKK · Aydınlatma Tebliği · KVKK · Yurt Dışına Aktarım · KVKK · Silme / Yok Etme / Anonimleştirme
Technical/legal-content review: 10 August 2026 · Contact MUJ