Legal

Privacy Policy and KVKK Notice

Last updated:

This policy explains how Omni Zen ("Omni Zen", "we") processes your personal data when you use the website at https://omnizen.space and the Omni Zen mobile app. It also serves as the information notice required by Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK"), and includes the information required by the General Data Protection Regulation ("GDPR") for visitors in the European Union.

In short: you can read the site without an account. We use advertising and analytics cookies only if you allow them. We receive your email address only if you subscribe to the newsletter or request a guide.

1. Data controller

Omni Zen Email: [email protected]

Data When Purpose Legal basis (KVKK Art. 5 / GDPR Art. 6)
IP address, browser and device information, page visited, date and time (server logs) Every time you use the site or app Providing the Service, security, troubleshooting Legitimate interest
IP address (short-lived counter) When you search or submit the newsletter form Preventing abuse and automated attacks Legitimate interest
Email address, language preference, time of signup When you subscribe to the newsletter Sending the newsletter Explicit consent
Email address and any other information the form asks for; campaign details of the ad you came from (e.g. utm parameters) When you request a free guide or other content Sending what you requested; sending the newsletter if you agreed; measuring campaigns Entering into or performing a contract; explicit consent for marketing messages
Your cookie choice When you choose in the cookie notice Remembering your choice Legitimate interest / legal obligation
Online identifiers, page views and interaction data (analytics and marketing cookies) Only if you allow cookies Measuring visits, improving content, measuring ads Explicit consent
Messages you send us and your contact details When you contact us Answering your request Legitimate interest

We do not ask for special categories of personal data such as health data. Please don't share such information when you write to us.

We do not store the words you type into the search box in connection with a personal profile.

3. The mobile app

The Omni Zen app contains no advertising, analytics or tracking tools. The app loads content from our site, which creates the server logs described above. Posts you save, your listening position and your settings are stored only on your device and are not sent to us. We receive your email address only if you subscribe to the newsletter from within the app. External content such as YouTube or podcast players opens only when you choose to load it, and may then use its own cookies.

4. Cookies

We use non-essential cookies only with your permission. For details and how to change your choice, see the Cookie Policy.

5. Who we share data with

We do not sell your data. We share it only with service providers that work on our behalf to run the Service, and only as far as necessary:

  • Hosting, content delivery and database: Vercel Inc., Cloudflare Inc. and Neon (server logs and the technical operation of the Service);
  • Email and automation infrastructure: the automation and email-delivery services we use to send the newsletter and the content you request;
  • Analytics and advertising services (only if you allow them): tools such as Google Analytics and Meta (Facebook) Pixel;
  • Public authorities: only where the law requires it.

6. Transfers abroad

Some of these providers have servers outside Türkiye, in particular in the European Union and the United States, so your data may be transferred abroad. Transfers are made in accordance with Article 9 of the KVKK and related legislation and, under the GDPR, on the basis of appropriate safeguards such as standard contractual clauses.

7. How long we keep data

Data Period
IP address in abuse counters At most 1 day
Server logs The hosting provider's standard retention period
Newsletter subscription details Until you unsubscribe, and afterwards for as long as needed to evidence your request
Guide-request form details For as long as needed to fulfil the request, and for the applicable limitation periods
Your cookie choice 180 days
Your correspondence with us Up to 2 years after your request is resolved

When the period ends, data is deleted, destroyed or anonymised.

8. Your rights

Under Article 11 of the KVKK, you can contact the data controller to:

  • learn whether your personal data is processed, and request information if it is;
  • learn the purpose of processing and whether data is used in line with that purpose;
  • know the third parties, in Türkiye or abroad, to whom data is transferred;
  • request correction of incomplete or inaccurate data;
  • request deletion or destruction of data under the conditions in Article 7 of the KVKK;
  • request that corrections, deletions and destructions be notified to third parties to whom data was transferred;
  • object to a result against you arising from analysis of your data exclusively by automated systems;
  • claim compensation if you suffer damage because of unlawful processing.

If the GDPR applies to you, you also have the right to access your data, to request restriction of processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

How to make a request: send it to [email protected] with enough information for us to verify your identity. We respond free of charge within 30 days at the latest. If you are not satisfied with our answer, you can complain to the Turkish Personal Data Protection Board (kvkk.gov.tr) or to the data protection authority of your country.

To leave the newsletter, use the unsubscribe link in any email or write to us. You can withdraw your cookie consent at any time via "Cookie settings" at the bottom of every page.

9. Children

The Service is not directed at people under 18. If you are under 18, get your parent's or guardian's permission before subscribing to the newsletter or filling in a form. If we learn that we have processed a child's data unknowingly, we delete it.

10. Security

We take reasonable technical and organisational measures to protect your data, such as encrypted connections (HTTPS), access controls and abuse limits. Even so, no transmission over the internet is completely secure.

11. Changes

We may update this policy. The current version is always published on this page. We announce significant changes through the Service.

Stay Grounded

Weekly wellness notes, straight to your inbox.

One gentle email a week — mindful prompts, new posts, and community highlights.