Legal
Privacy Policy
Courtesy translation. The German Datenschutzerklärung is the legally binding version.
1. Controller
The controller responsible for data processing on this website is:
Sinan Isoglu
c/o Kanzlei Novalex GmbH (opens in a new tab)
Rechtsanwalt Dr. Saban Sincar, LL.M.
Uerdinger Str. 64
40474 Düsseldorf
Germany
Email: sinan@isoglu.com
2. Principles
Protecting your personal data matters to me. I process your data solely on the basis of the applicable law (GDPR, German BDSG, DDG). This policy tells you the nature, scope and purpose of the processing and your rights. The site is deliberately data-minimal: without your consent, no cookies are set for analytics or marketing. Audience measurement is cookieless by default; an optional, consent-based tool is only loaded after you agree (see section 12).
3. Hosting and server log files
This website is hosted on Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA) via Cloudflare Pages. When the pages are accessed, Cloudflare processes technically necessary access data in server log files, including your IP address, the date and time of access, the resource requested, the referrer, and browser and operating-system information. This processing serves the secure, stable and efficient operation of the website and the prevention of attacks.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure operation). A data-processing agreement is in place with Cloudflare. As processing may also take place in the USA, it is safeguarded by the EU Standard Contractual Clauses.
4. Fonts
The fonts used are served locally from this server (self-hosting). No connection is made to third-party font services (such as Google Fonts) and your IP address is not transmitted to such providers.
5. Contact form
When you use the contact form, I process the data you provide: depending on your enquiry, in particular your first and last name, email address, your message and the context-specific fields (e.g. organisation, topic, format, location). Alongside it, and solely to prevent abuse and enforce rate limits, a salted, truncated technical hash derived from your connection (ip_hash) and a coarse description of your browser and operating system (e.g. “Chrome on Windows”) are stored. Your raw IP address and your full browser identifier are not saved. This information is used solely to handle and answer your enquiry.
The legal basis is your consent under Art. 6 (1) (a) GDPR (confirmed via a checkbox) and, insofar as your enquiry is aimed at a contract, Art. 6 (1) (b) GDPR. A double-opt-in procedure is used to confirm your enquiry: you receive an email with a confirmation link that expires after 24 hours and works exactly once, and only after you click it is your enquiry marked as confirmed. The data is stored in a database (Cloudflare D1) and kept for as long as necessary to process it, or until you request its deletion. An enquiry that is never confirmed is deleted automatically after 30 days. Statutory retention obligations remain unaffected.
6. Spam protection (Cloudflare Turnstile)
To protect the forms against automated abuse, I use Cloudflare Turnstile. Technical characteristics of your access (including your IP address and browser signals) are transmitted to Cloudflare and evaluated to distinguish humans from bots. Turnstile works without cookies and without cross-site personal tracking. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse and spam).
7. Email delivery (Brevo)
To send the confirmation and notification emails I use Brevo (Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany), with processing within the EU. Your first and last name, your email address and the content of the respective message are processed for this purpose. A data-processing agreement is in place with Brevo. The legal basis is Art. 6 (1) (a) or (f) GDPR.
8. Newsletter
If you subscribe to the newsletter, I process your first and last name and your email address to send you occasional pieces. As with the contact form, a salted, truncated technical hash derived from your connection (ip_hash) and a coarse client description (e.g. “Safari on macOS”) are stored with the subscription for abuse prevention and rate limiting; no raw IP address and no full browser identifier are saved. Subscription uses a double-opt-in procedure: you receive a confirmation email whose link expires after 24 hours and works exactly once, and you are only added to the list after you click it. A subscription that is never confirmed is deleted automatically after 30 days. The subscription is logged so that it can be proven. The legal basis is your consent under Art. 6 (1) (a) GDPR. You can unsubscribe at any time via the link at the end of every email; your consent is thereby deemed withdrawn.
9. Arcade leaderboard (easter egg)
This site hides a small arcade game. If you find it and choose to save your score, a three-character tag of your choice, the score, the wave reached and the duration of the run are stored in the site’s database and shown in a public high-score list. The tag is freely chosen and need not identify you; please do not use personal data as your tag. To prevent abuse, a salted, truncated technical hash derived from your connection is stored alongside the entry — the raw IP address is not saved. The legal basis is legitimate interest in operating and protecting this voluntary feature under Art. 6 (1) (f) GDPR; saving a score is entirely optional.
10. Journal: comments, topic suggestions and readership counts
Comments. If you comment on a journal piece, the name you enter, your comment, an optionally quoted passage and the time are stored and: after personal review and approval: published with the article. No email address is required. You can request deletion of your comment at any time.
Topic suggestions. If you suggest a topic, your first and last name, your email address, the topic and any note are stored separately from the contact database, solely so I can follow up on the suggestion. They do not go through the double-opt-in procedure described in section 5 and are not added to the contact database or the newsletter. If the suggestion becomes a piece, your name: never your email address: is credited in the article; by submitting, you agree to this attribution and can withdraw it at any time.
Readership counts. Each article shows how many distinct readers it has had — people, counted once per connection, together with each named AI system that has fetched it. It is not a headcount: several readers behind one office or mobile network count as one. Counting is privacy-minimal: a salted, truncated technical hash derived from your connection is stored per article per hour to avoid double-counting — the raw IP address is not saved and no reading profile is created. Abuse prevention for comments and suggestions uses the same hashing approach.
The legal basis for comments and suggestions is your consent through active submission under Art. 6 (1) (a) GDPR; for counting and abuse prevention, legitimate interest under Art. 6 (1) (f) GDPR.
11. Doctoral research study: expressing interest, invitation and consent
This website carries the expression of interest and the informed-consent flow for a doctoral research study (DBA, EM Normandie Business School) on cross-border company integrations. Participation is by personal invitation only; there is no public self-registration. All study data is stored strictly separated from the contact database and the newsletter, and is never used for marketing.
Expressing interest. If you express interest in taking part via the contact form (“Taking part in the study”), your first and last name, email address, message and the eligibility details you provide (organisation, your vantage point, number of cross-border integrations, sector, how one unfolded, interview language) are stored in a dedicated store: solely for eligibility screening and for arranging a short screening call. The same double-opt-in procedure as in section 5 applies; an unconfirmed expression of interest is deleted automatically after 30 days, and you can withdraw your interest at any time via the link in the email or by a simple message.
Invitation and consent. The consent declaration is signed through a personal invitation link. With the signature, the following are stored: your name, email address, the typed signature, the individual declarations (participation, data processing, pseudonymised quotation, recording choice), the form version, and a SHA-256 fingerprint of the exact text you were shown: which makes it provable which wording was signed. For abuse prevention, as with every form, a salted, truncated technical hash of the connection and a coarse browser description are stored.
Retention of consent records. Consent records are evidence of lawful processing (Art. 5 (2), Art. 7 (1) GDPR). They are therefore not subject to the automatic 30-day deletion. A withdrawal is recorded on the record with its time rather than executed by erasure: the research data itself is deleted on withdrawal; the fact that consent existed and was withdrawn remains demonstrable. Interview data (recordings, transcripts) is governed by the consent form you sign, which prevails over this policy as the more specific document and states the retention period (the doctoral period plus the publication window).
The legal basis is your consent under Art. 6 (1) (a) GDPR; for abuse prevention, legitimate interest under Art. 6 (1) (f) GDPR.
12. Analytics and consent
Cloudflare Web Analytics (cookieless)
To measure page views I use Cloudflare Web Analytics. This method works without cookies, without cross-device tracking and without profiling; only aggregate metrics are collected. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in data-minimal audience measurement).
Microsoft Clarity (only with your consent)
With your consent I additionally use Microsoft Clarity (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA) to better understand how the site is used: for example through session recordings and heatmaps. This sets cookies (e.g. _clck, _clsk) and transmits interaction data to Microsoft. Clarity is only loaded after you agree in the consent banner; without consent there is no transmission to Microsoft and no cookie is set. The legal basis is your consent under Art. 6 (1) (a) GDPR. As processing may take place in the USA, it is safeguarded by the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework. You can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer.
Google Tag Manager (only with your consent)
With your consent I use Google Tag Manager, container GTM-T458F953 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; where processing takes place outside the EEA, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Tag Manager is an administrative tool for managing measurement tags. It sets no cookies of its own, but loading it transmits your IP address, the address of the page you are on and information about your browser and device to Google. It is only loaded after you agree in the consent banner; without consent no request is made to Google and nothing is transmitted. Google Consent Mode is configured so that even after loading, storage for analytics and functionality is permitted only on the basis of your consent, and storage for advertising purposes remains switched off: this site runs no advertising tags. The legal basis is your consent under Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (the former TTDSG). As processing may take place in the USA, it is safeguarded by the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework, under which Google LLC is certified. You can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer.
On the same consent basis I use Google Analytics 4 (measurement ID G-9LFNJVYNPK, same provider as above) to measure page views and basic usage of this site in aggregate. Once you have consented, Google Analytics stores the cookies _ga and _ga_* on your device to distinguish visitors; without your consent the service is not loaded, no cookie is set and no request is made to Google. Consent Mode applies as described above, and withdrawal works the same way.
If a measurement tag is later added to this container, this policy will name it before it goes live and the consent version will be raised, so that your choice is asked again rather than an old consent being carried over to a processor you never agreed to.
What this site stores in your browser (localStorage)
Besides the Clarity cookies above: which are only ever set if you accept: this site stores a few entries in your browser’s localStorage. They stay on your device, are never transmitted to me or to a third party, and you can clear them at any time in your browser settings:
isoglu-consent: your choice in the consent banner, together with the time you made it and the version of this policy it applies to. The version is what lets me re-ask rather than silently carry an old consent over when the list of processors changes (Art. 7 (1) GDPR). Strictly necessary, so that the banner does not reappear on every visit.isoglu-read-<article>: one entry per journal article, holding the hour in which that article was last counted as read on this device, so the readership counter in section 10 does not count the same device twice within the same hour.isoglu-arcade-board,isoglu-arcade-mute,isoglu-arcade-music: the local high-score list and the sound settings of the arcade easter egg in section 9. Only entries you explicitly submit ever leave your device.
No cookie is set for any of these.
13. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing (Art. 21). Where processing is based on your consent, you can withdraw it at any time with effect for the future. To exercise your rights, a message to sinan@isoglu.com is sufficient.
14. Right to complain
You have the right to lodge a complaint with a data-protection supervisory authority if you believe that the processing of your data infringes the GDPR. You may address the authority of your habitual residence, of your place of work, or of the place of the alleged infringement. The authority competent for me as controller is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
15. Retention
I store personal data only for as long as necessary for the respective purposes or as required by statutory retention periods. The data is deleted thereafter. Specifically:
- A contact enquiry, a newsletter subscription or a study expression of interest that is never confirmed is deleted after 30 days, automatically and without you having to ask.
- Study consent records (section 11) are not auto-deleted: they are retained as evidence of lawful processing; a withdrawal is recorded on the record while the research data itself is deleted.
- A confirmation link expires after 24 hours and can be used exactly once; it is invalidated the moment it is used. The unsubscribe link is a separate token and keeps working afterwards.
- The moderation link attached to a comment notification stops working after 14 days.
- Confirmed records are deleted after 24 months, counted from the last interaction rather than from when you first wrote, so an ongoing exchange is never cut short by the clock. This covers contact enquiries, topic suggestions, leaderboard entries, diagnostic tool requests, per-issue delivery logs, and subscriptions after you unsubscribe. You can of course ask for deletion at any time, and an active newsletter subscription is not on this clock at all.
- Security and moderation traces are deleted after 90 days: sign-in codes and failed attempts for the study console, and any comment that was never approved.
Status of this privacy policy: 2026. It will be updated if the website or the services used change.