Privacy Policy

Version: 2.0

Effective Date: 01/01/2026

Last Updated: 01/01/2026

1. INTRODUCTION

This Privacy Policy explains how Coast Guide TR ("we," "us," "our") collects, uses, stores, and protects your personal data when you use our website and services at https://www.coastguidetr.com.

Our Commitment

We are committed to protecting your privacy and personal data in accordance with:

  • EU General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
  • Turkish Personal Data Protection Law (KVKK) - Law No. 6698
  • Applicable international data protection standards

Data Controller

Coast Guide TR
Website: https://www.coastguidetr.com

Email: contact [at] coastguidetr [dot] com

Privacy Contact: privacy [at] coastguidetr [dot] com

For KVKK purposes, Coast Guide TR acts as the Data Controller (Veri Sorumlusu) for all personal data collected through this platform.

2. SCOPE OF THIS POLICY

This Privacy Policy applies to all visitors to https://www.coastguidetr.com, users of our platform features and services, subscribers to newsletters or communications, registered account holders (if applicable), and anyone whose personal data we process.

3. PERSONAL DATA WE COLLECT

We collect various types of personal data to provide and improve our services.

3.1 Information You Provide Directly

Contact Information: Name and surname, email address, phone number (if provided), mailing address (if provided), account credentials (username, password if registration enabled).

Maritime Information (Voluntary): Vessel name and type, sailing experience level, preferred sailing areas, marina preferences, saved locations and routes, comments and contributions.

Communication Data: Messages sent through contact forms, customer support inquiries, feedback and survey responses, newsletter preferences.

3.2 Information Collected Automatically

Technical Data: IP addresses (full IPv4 and IPv6 addresses), device identifiers and fingerprints, browser type, version, and language settings, operating system and device information, screen resolution and display settings, referrer URLs.

Usage Data: Pages visited and content viewed, date and time of access, session duration and frequency, search queries on our platform, click patterns and navigation paths, features used and interactions, download and upload activities.

Location Data: Country and region (derived from IP address), city-level location (approximate), time zone, language preferences.

Security & Log Data: Access timestamps, HTTP methods and status codes, user agent strings, request and response headers, failed login attempts, suspicious activity patterns, security event logs.

5. HOW WE USE YOUR PERSONAL DATA

We use your personal data for service delivery, security and fraud prevention, platform improvement, content enhancement, communication, legal compliance, and advertising.

5.1 Service Delivery

Display navigational information and maritime resources. Deliver weather data via Google Weather API. Provide interactive maps through Garmin Navionics. Enable saved locations and user preferences. Facilitate search functionality. Stream video content via YouTube.

5.2 Security & Fraud Prevention

Real-time threat detection: Identifying malicious traffic patterns. Intrusion prevention: Blocking unauthorized access attempts. DDoS protection: Mitigating distributed denial-of-service attacks. Fraud detection: Identifying suspicious behavior and fraudulent activities. Rate limiting: Preventing abuse and ensuring fair resource allocation.

6. DATA STORAGE & INFRASTRUCTURE

Information about how and where we store your data.

6.1 Hosting Provider

Amazon Web Services (AWS): Coast Guide TR is hosted on AWS cloud infrastructure, utilizing secure and reliable services designed for high availability and performance, enterprise-grade security, scalability and redundancy, disaster recovery capabilities.

AWS Compliance: GDPR-compliant Data Processing Agreement (DPA), ISO 27001, ISO 27017, ISO 27018 certifications, SOC 1, SOC 2, SOC 3 reports, regular security audits and compliance assessments.

6.2 Data Location

Primary Storage: European Economic Area (EEA) - Your data is primarily stored in AWS data centers located within the EEA (typically EU regions). This ensures compliance with GDPR data localization preferences.

Secondary/Backup Storage: Other AWS Regions - For operational purposes including disaster recovery, redundancy, and service optimization, select data may be stored in other AWS regions, including the United States. All such transfers are protected by appropriate safeguards.

7. DATA RETENTION

We retain personal data only as long as necessary for stated purposes and legal obligations.

7.1 Retention Periods

Data retention periods vary by type and legal requirements.

Data TypeRetention PeriodLegal Basis
IP Addresses (active security logs)12 monthsLegitimate interest (security monitoring)
IP Addresses (compliance records)Up to 10 yearsLegal obligation (Turkish Commercial Code)
Account data (active users)Duration of use + 3 yearsContract performance + statute of limitations
Account data (inactive)3 years after last activity, then deletedLegitimate interest
Strictly necessary cookiesSession to 12 monthsLegitimate interest
Analytics cookiesUp to 26 monthsConsent
Advertising cookiesUp to 24 monthsConsent
Google Analytics data26 months (default setting)Consent
Customer support records5 yearsLegal obligation + legitimate interest
Financial records10 yearsLegal obligation (tax, accounting laws)
Legal dispute recordsDuration of dispute + statute of limitationsLegal claims
Marketing consent recordsUntil consent withdrawn + 3 yearsCompliance documentation
Anonymized/aggregated dataIndefiniteNot personal data (GDPR does not apply)
Backup data30-90 days (rolling backups)Legitimate interest (disaster recovery)

9. THIRD-PARTY DATA SHARING & PROCESSORS

We share your data only with trusted service providers necessary for platform operation.

9.1 Amazon Web Services (AWS)

Role: Data Processor (hosting and infrastructure)

Services: Cloud hosting, data storage, backup and disaster recovery, CDN, security services.

Data shared: All platform data including personal information, IP addresses, logs.

Location: Primary EEA, backup in other AWS regions including US.

Protection: GDPR-compliant DPA, EU SCCs, ISO certifications.

9.2 Google LLC

Role: Data Processor (analytics, advertising, weather, video)

Services: Google AdSense, Analytics, Weather API, YouTube embedding.

Data shared: IP addresses (anonymized where possible), browsing behavior, device info.

Location: United States with global infrastructure.

Protection: GDPR-compliant terms, EU-U.S. Data Privacy Framework.

9.3 Garmin International / Navionics

Role: Data Processor (maritime charts and maps)

Services: Interactive maritime charts, real-time map rendering, chart updates.

Data shared: Map interactions, viewed areas, usage patterns, device info for optimization.

Location: United States (Garmin), Italy (Navionics), European data centers.

Protection: Data Processing Agreement, GDPR compliance measures.

Privacy Policy: https://www.garmin.com/en-GB/legal/marine-cartography-disclaimer/

10. ARTIFICIAL INTELLIGENCE & AUTOMATED PROCESSING

Coast Guide TR employs artificial intelligence and machine learning for security, fraud detection, platform optimization, content enhancement, and personalization.

10.1 How We Use AI

Security & Fraud Detection: Threat analysis, anomaly detection, automated blocking, fraud prevention, spam filtering, bot detection.

Platform Optimization: Usage analytics, performance tuning, feature recommendations, search improvement, A/B testing.

Content Enhancement: Translation, optimization, summarization, tagging, quality assurance.

10.2 Human Oversight

Critical content is human-verified: Maritime and navigational information authored by experienced sailors, editorial team reviews AI-enhanced content, safety-critical data verified by maritime professionals.

Human review available: You can request human review of automated decisions, contest AI-driven outcomes, appeal security-related blocks.

11. YOUR PRIVACY RIGHTS

You have comprehensive rights regarding your personal data under GDPR and KVKK.

11.1 Right of Access

You can request confirmation of data processing, obtain copies of your data, and receive information about our processing activities. Email privacy [at] coastguidetr [dot] com with 'Data Access Request'.

11.2 Right to Rectification

You can correct inaccurate data, complete incomplete data, and update outdated information. Email privacy [at] coastguidetr [dot] com with 'Data Correction Request'.

11.3 Right to Erasure

You can request deletion when data is no longer necessary, you withdraw consent, or object to processing. Email privacy [at] coastguidetr [dot] com with 'Data Deletion Request'. Some data may be retained for legal obligations.

11.4 Right to Restriction of Processing

You can restrict processing when you contest accuracy of data, processing is unlawful but you oppose erasure, we no longer need data but you need it for legal claims, or you object to processing.

11.5 Right to Data Portability

You can receive your data in machine-readable format and transmit it to another service. Email privacy [at] coastguidetr [dot] com with 'Data Portability Request'.

11.6 Right to Object

You can object to processing based on legitimate interests or direct marketing. Email privacy [at] coastguidetr [dot] com with 'Objection to Processing'. Note: Objecting to essential security processing may prevent platform use.

11.8 Right to Lodge a Complaint

You can complain to data protection authorities. Turkey - KVKK: https://www.kvkk.gov.tr EU - Your National DPA: https://edpb.europa.eu/about-edpb/board/members_en

12. CHILDREN'S PRIVACY

Coast Guide TR is not intended for children under 16 years (GDPR) or 18 years (KVKK). We do not knowingly collect personal data from minors. If we discover data from minors, we will promptly delete such information.

13. DATA BREACH NOTIFICATION

In the event of a data breach affecting personal data, we will notify relevant supervisory authorities within 72 hours (GDPR) and affected individuals without undue delay if the breach is likely to result in high risk to rights and freedoms.

14. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect changes in laws, new features, enhanced security measures, or business changes. Material changes will be notified 30 days in advance via email and prominent website notification.

15. INTERNATIONAL USERS & FUTURE OPERATIONS

Coast Guide TR currently operates primarily serving Turkish coastal sailors, hosted in European Economic Area, subject to Turkish and EU law. We plan to establish business entities in additional jurisdictions, including the United Kingdom, to better serve the international sailing community.

16. CONTACT INFORMATION

How to contact us regarding privacy matters.

16.1 General Privacy Inquiries

Email: privacy [at] coastguidetr [dot] com
Website: https://www.coastguidetr.com

Response time: Within 5 business days (acknowledgment), 30 days (full response)

16.2 Exercising Your Rights

Email privacy [at] coastguidetr [dot] com with appropriate subject line:
- 'Data Access Request' (Right of Access)

- 'Data Correction Request' (Rectification)

- 'Data Deletion Request' (Erasure)

- 'Restriction Request' (Restriction of Processing)

- 'Data Portability Request' (Portability)

- 'Objection to Processing' (Object)

- 'Withdraw Consent' (Consent Withdrawal)

Include: Full name, contact information, Turkish ID/passport number, clear description of request, proof of identity.

16.3 Security Issues

For security vulnerabilities or incidents:
Email: security [at] coastguidetr [dot] com

Subject: 'Security Vulnerability Report' or 'Security Incident'

We appreciate responsible disclosure and will work with security researchers to address issues promptly.

16.4 Supervisory Authorities

Turkey - KVKK:
Kişisel Verileri Koruma Kurumu

Website: https://www.kvkk.gov.tr

Address: Nasuh Akar Mah. Ziyabey Cad. 1407. Sok. No: 4, 06520 Balgat-Çankaya/Ankara, Turkey

European Union:
Find your National DPA: https://edpb.europa.eu/about-edpb/board/members_en

17. ACKNOWLEDGMENT & CONSENT

BY USING COAST GUIDE TR, YOU ACKNOWLEDGE AND CONSENT TO the collection, use, storage, and processing of your personal data as described in this Privacy Policy, use of cookies and similar technologies, IP address collection and storage for security and legal compliance, international data transfers with appropriate safeguards, data storage primarily in Europe with backup in other regions, sharing data with third-party processors, automated processing including AI/ML for security and improvement.

18. SPECIAL NOTICE ON IP ADDRESSES & SECURITY LOGGING

We collect and store IP addresses as a fundamental requirement for security, legal compliance, and platform integrity.

Purpose of IP Address Collection

Security & Protection: Detecting and preventing cyber attacks, identifying fraudulent activity, protecting against unauthorized access, investigating security incidents, rate limiting and abuse prevention.

Legal Compliance: Turkish Commercial Code record-keeping requirements, cybersecurity law obligations, law enforcement cooperation when legally required, regulatory compliance.

Legal Basis: Legitimate Interest (platform and user security), Legal Obligation (statutory retention requirements).

Retention: 12 months (active security monitoring), up to 10 years (compliance records - Turkish Commercial Code).

Your Rights and Limitations

Your Rights: You can request access to your IP address logs, deletion requests subject to security and legal exceptions, objection to IP logging may prevent platform use (security essential).

This processing cannot be disabled as it is: Essential for platform security, legally required for record-keeping, necessary to protect all users, foundation of our cybersecurity measures.

For more details, see Section 3.2 (Data Collection) and Section 5.2 (Security Use).

Email Security Notice

Email addresses in this document are displayed in [at] and [dot] format for bot and spam protection. Use @ and . characters when using the actual email addresses.

ACKNOWLEDGMENT & CONSENT

BY USING COAST GUIDE TR, YOU ACKNOWLEDGE AND CONSENT TO the collection, use, storage, and processing of your personal data as described in this Privacy Policy.

Coast Guide TR Privacy Policy
Version 2.0 | Effective Date: 01/01/2026

© 2026 Coast Guide TR. All rights reserved.

This Privacy Policy is provided in English and Turkish. Both versions are equally authoritative.

Privacy Policy - Coast Guide TR | Coast Guide TR