URLy
Startseite Wie es funktioniert Sicherheit Missbrauch melden Bedrohung FAQ Kontakt Rechtliches
EnglishEnglishTürkçeTürkçeGermanDeutsch✓FrenchFrançaisSpanishEspañolRussianРусскийArabicالعربية
Anmelden Registrieren
🏠 Startseite ℹ️ Wie es funktioniert 🛡️ Sicherheit 🚨 Missbrauch melden Bedrohung ❓ FAQ 💬 Kontakt 📜 Rechtliches
Anmelden Registrieren

📜 Legal Policies 26 Docs

Service & Usage
  • 📜 01. Terms of Service
  • 🚫 02. Acceptable Use Policy
  • ⚖️ 16. Content Moderation & Expression
Privacy & Data Protection
  • 🛡️ 03. Global Privacy Policy
  • 🍪 04. Cookie Policy
  • ⏱️ 06. Data Retention & Deletion Policy
  • 🇹🇷 10. KVKK Privacy Notice (Turkey)
  • 🇪🇺 11. GDPR (EEA & UK) Privacy Notice
  • 👤 13. Data Subject Request Procedure
  • 🌐 14. Subprocessors Disclosure
  • ✍️ 23. Explicit Consent Statement (TR)
  • ✍️ 24. Explicit Consent Statement (EN)
Security & Disclosure
  • 🔒 07. Security Policy
  • 🚸 12. Child Safety & CSAM Policy
  • 🎯 15. Vulnerability Disclosure Policy
  • 💻 18. Security Page Specification
  • 📑 19. RFC 9116 security.txt Standard
Legal Requests & Compliance
  • 🚨 05. Abuse Reporting Procedure
  • ©️ 08. Copyright & DMCA Takedown Policy
  • 🏛️ 09. Law Enforcement Guidelines
  • 📊 17. Transparency Report Framework
Official Submission Forms
  • 📝 20. Privacy & DSR Request Form Spec
  • ⚠️ 21. Abuse Report Form Spec
  • 🏷️ 22. Copyright & Trademark Form Spec
Master Archive & Directives
  • 📌 25. Policy Package Overview (README)
  • 📚 26. Consolidated Master Policy & Alignment
📚 Master Archive & Directives ✍️ Related Submission Channel →

26. Consolidated Master Policy & Alignment

🏢 Firma Life 📍 Selçuklu / Konya, Türkiye ⚖️ Konya Mahkemeleri 📑 26_master_legal_policy_en.txt

URly / urly.tr

COMPLETE FINAL LEGAL, PRIVACY, SECURITY & TRUST PACKAGE

Authoritative English base • Comprehensive version • Effective date placeholders intentionally retained

Legal entity: Firma Life • Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye

Support: support@urly.tr • Abuse/Security: abuse@urly.tr • Legal/Privacy/IP: legal@urly.tr

Primary infrastructure: Türkiye • Governing law: Republic of Türkiye • Jurisdiction: competent courts and enforcement offices of Konya, Türkiye

Document set

1. 01 Terms of Service

2. 02 Acceptable Use Policy

3. 03 Global Privacy Policy

4. 04 Cookie Policy

5. 05 Abuse Reporting

6. 06 Retention Deletion

7. 07 Security Policy

8. 08 Copyright Takedown

9. 09 Law Enforcement

10. 10 KVKK Aydinlatma

11. 11 GDPR EEA UK

12. 12 Child Safety

13. 13 Data Subject Request

14. 14 Subprocessors

15. 15 Vulnerability Disclosure

16. 16 Freedom Content Moderation

17. 17 Transparency Report

18. 18 Security Page

19. 19 security txt

20. 20 Privacy Request Form

21. 21 Abuse Report Form

22. 22 Copyright Trademark Form

1. 01 Terms of Service

These Terms govern access to and use of URLy, including its website, Short Links, link-management features, analytics, API and related services.

1. Acceptance and scope

By creating an account, creating or accessing a Short Link, using the API, or otherwise using the Service, you agree to these Terms and the policies incorporated into them.

2. Definitions

“Service” means URLy websites, applications, APIs, Short Links, link-management and related functionality. “Short Link” means a shortened URL generated or managed by URLy. “Destination URL” means the URL to which a Short Link directs. “User Content” means URLs, titles, descriptions, account information and other material submitted by a user.

3. Eligibility

You must be legally capable of entering into these Terms and must comply with applicable law. If acting for an organization, you represent that you have authority to bind it.

4. Accounts and credentials

You must provide accurate information and keep credentials, authentication codes and API keys confidential. You are responsible for activity performed through your account unless caused by URLy’s own breach or another circumstance for which applicable law imposes responsibility on URLy.

5. Creating and using Short Links

You may create Short Links only for lawful and legitimate purposes. You must have the right to submit the Destination URL and any associated content. You must not use URLy to conceal unlawful activity or evade enforcement by another service.

6. Link ownership and deletion

URLy may retain, restrict, expire or delete Short Links according to applicable product rules, security needs, legal obligations and retention policies. Anonymous Short Links may be subject to a 30-day inactivity expiry rule.

7. Prohibited use

The following are prohibited: phishing, credential theft, malware, ransomware, spyware, fraud, scams, illegal drug activity, unlawful gambling, weapons or explosives trafficking, terrorism or violent-extremism facilitation, child sexual exploitation, grooming, non-consensual sexual content, trafficking, stolen accounts or financial data, counterfeit or piracy operations, impersonation, doxxing, harassment, extortion, illegal marketplaces, security-control circumvention, malicious automation and spam.

8. Slug protection

URLy may protect brand names, aliases, variants, typosquats, confusable forms, system terms, sensitive terms and security-sensitive identifiers. Slug Protection decisions are ALLOW, REVIEW, RESERVED or BLOCK. RESERVED is an identifier-protection state and is distinct from content RESTRICT enforcement.

9. Destination safety and moderation

URLy may use automated and human review to assess suspicious destinations, domains, accounts and activity. Content/abuse decisions may be ALLOW, REVIEW, RESTRICT or BLOCK.

10. Security measures

URLy may rate-limit requests, log security events, restrict suspicious activity, suspend accounts and disable Short Links where reasonably necessary to protect users, third parties or the Service.

11. Suspension and termination

URLy may suspend or terminate accounts, API access or Short Links for policy violations, security risks, legal requirements, fraud, repeated abuse or other legitimate enforcement reasons. Where appropriate and legally permitted, users may request review.

12. Third-party destinations

URLy is not the creator or publisher of content hosted at third-party destinations and does not generally control that content. URLy may nevertheless restrict or disable Short Links where required by law or reasonably necessary under its policies.

13. Intellectual property

URLy software, branding, documentation and original Service materials belong to or are licensed by Firma Life. These Terms do not transfer ownership of URLy intellectual property.

14. User content

You retain rights you have in your submitted material, subject to the rights necessary for URLy to operate the Service. You grant URLy the limited rights necessary to host, process, redirect, secure, analyze and display your submitted information as part of the Service.

15. Privacy

Personal-data processing is described in the Global Privacy Policy, Cookie Policy, KVKK Privacy Notice and GDPR / EEA & UK Privacy Notice where applicable.

16. Service availability

URLy is provided on an as-available basis. We do not guarantee uninterrupted availability, permanent retention of every Short Link, error-free operation or detection of every harmful destination.

17. Disclaimer

To the maximum extent permitted by law, URLy disclaims warranties not expressly required by applicable law, including implied warranties concerning uninterrupted availability, fitness for a particular purpose or complete security.

18. Limitation of liability

To the maximum extent permitted by law, Firma Life is not liable for indirect, incidental, special, consequential or punitive losses arising from use of the Service. Nothing excludes liability that cannot lawfully be excluded.

19. Indemnification

To the extent permitted by law, you agree to defend and indemnify Firma Life against claims, losses and reasonable costs arising from your unlawful use of the Service, violation of these Terms or infringement of third-party rights.

20. Abuse, legal and IP reports

Reports may be submitted to abuse@urly.tr. Privacy, copyright, trademark and formal legal matters may be submitted to legal@urly.tr.

21. Changes

We may update these Terms as the Service, law or security requirements change. Material changes may be communicated through the Service or other appropriate means.

22. Severability and entire agreement

If a provision is unenforceable, the remainder remains effective to the extent permitted by law. These Terms and incorporated policies form the agreement governing use of the Service.

Legal entity and contact

URLy is operated by Firma Life. Registered address: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye. General support is available at support@urly.tr; abuse and security reports at abuse@urly.tr; legal, privacy, copyright and trademark matters at legal@urly.tr.

Governing law

Unless mandatory law provides otherwise, the laws of the Republic of Türkiye govern. The competent courts and enforcement offices of Konya, Türkiye have jurisdiction, subject to mandatory rights and jurisdictional rules that cannot lawfully be waived.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Accounts, verification and security

URLy may require email verification, security checks, CAPTCHA or other verification mechanisms where implemented. Users must promptly notify URLy of suspected unauthorized access. URLy may require password resets, API-key rotation or other protective measures following a suspected compromise. A user must not attempt to access another user’s account, session or API credentials.

API use

API access is subject to documented limits and may be suspended when traffic is abusive, anomalous, automated in a harmful manner or inconsistent with the stated purpose of an API application. API keys are confidential credentials and must not be embedded in publicly accessible client-side code when doing so would expose them.

Link analytics

Click and access analytics may be affected by browsers, privacy tools, caching, bots, security scanners, corporate proxies and other technical conditions. Analytics are therefore estimates and should not be interpreted as guaranteed unique-person measurements.

Passwords and protected links

Where URLy offers password-protected Short Links, the password is an additional access control and does not make an otherwise unlawful destination permissible. Users remain responsible for the Destination URL.

Expiration and limits

Short Links may be subject to expiration dates, click limits, account quotas, inactivity rules or other product constraints. URLy may change operational limits for security, capacity or abuse-prevention reasons.

Brand and reserved identifiers

A user may not claim a reserved slug merely because it is technically available. URLy may reserve identifiers to reduce impersonation, confusion, abuse or trademark-related risk.

Third-party services

A Short Link may redirect to a service that has its own terms, privacy practices, cookies and security risks. Users should evaluate destinations before entering credentials or personal information.

Notices and communications

URLy may send transactional communications concerning verification, security, account status, policy enforcement, legal requests and service operation. Users may not disable communications that are necessary for security or legal compliance.

User cooperation

Users must reasonably cooperate with investigations concerning abuse, security incidents, legal process or rights complaints. Failure to cooperate may result in temporary restriction where reasonably necessary.

Survival

Provisions concerning intellectual property, privacy, liability, indemnification, dispute resolution, legal compliance and records that by their nature should survive termination will survive termination.

2. 02 Acceptable Use Policy

This Policy establishes prohibited, restricted and reviewable uses of URLy. It is intended to protect users, third parties, URLy infrastructure and the integrity of Short Links.

1. General rule

You may not use URLy to facilitate unlawful conduct, deception, serious harm, security abuse or activity that materially threatens the Service.

2. Phishing and credential theft

Fake login pages designed to capture passwords, MFA codes, session tokens or recovery codes.

Credential harvesting, authentication bypass or account-takeover campaigns.

Brand or service impersonation intended to collect credentials.

3. Fraud and scams

Investment, payment, romance, employment, delivery, tax, refund or support scams.

Advance-fee fraud, fake invoices, deceptive fundraising or impersonation of financial institutions.

Fraudulent acquisition or sale of personal or financial information.

4. Malware and malicious code

Malware, ransomware, spyware, keyloggers and destructive payloads.

Malicious download pages and drive-by exploitation.

Infrastructure intended to distribute or control malware.

5. Cyber abuse

Unauthorized access, credential stuffing, exploit delivery or persistence.

Botnet command-and-control, malicious scanning or evasion of security controls.

Links designed to facilitate unauthorized intrusion or theft.

6. Spam and automation

Unsolicited bulk messaging and malicious campaigns.

Automated abuse of link creation, analytics or referral systems.

Activity intended to overload, degrade or circumvent Service controls.

7. Drugs and controlled substances

Illegal sale, trafficking or facilitation of controlled substances is prohibited. Legitimate educational, medical, scientific or recovery-related discussion may be reviewed in context.

8. Gambling and betting

Unlawful gambling, betting, casino operations or deceptive gambling schemes are prohibited. Legitimate informational content may be reviewed in context.

9. Weapons and explosives

Illegal sales or facilitation involving weapons, explosives or other prohibited weapons are not permitted. Lawful informational, journalistic or educational material may be considered in context.

10. Terrorism and violent extremism

Content or activity that materially facilitates terrorism, violent extremist recruitment, operational support, financing or violent wrongdoing is prohibited. Neutral reporting, research and historical discussion may be treated differently based on context.

11. Child safety

CSAM, grooming, sexual solicitation of minors, sexualized content involving minors, trafficking and exploitation are prohibited and may trigger immediate restriction and preservation.

12. Sexual exploitation

Non-consensual intimate material, sexual extortion, trafficking and exploitative sexual services are prohibited.

13. Stolen accounts and financial information

The sale or distribution of stolen accounts, credentials, payment-card data, authentication tokens or unlawfully obtained financial information is prohibited.

14. Counterfeit and piracy

Counterfeit goods, deliberate piracy operations and intentional infringement facilitation are prohibited.

15. Impersonation

Deceptive impersonation of brands, governments, law enforcement, financial institutions, employers, public officials or other entities is prohibited where intended to mislead or cause harm.

16. Privacy abuse

Doxxing, unlawful disclosure of personal data, stalking, targeted harassment and publication of sensitive information for malicious purposes are prohibited.

17. Harassment, threats and extortion

Threats, coercion, blackmail, extortion and targeted abusive campaigns are prohibited.

18. Illegal marketplaces

URLy may restrict Short Links that facilitate unlawful marketplaces or transactions.

19. Security-control circumvention

Attempting to evade slug protection, moderation, rate limits, account suspension, authentication or other security controls is prohibited.

20. Context and exceptions

Journalism, research, education, public-interest reporting and legitimate security work may be considered in context. Context does not authorize unlawful conduct.

21. Enforcement

Moderation may result in ALLOW, REVIEW, RESTRICT or BLOCK. Actions may include link restriction, account suspension, API restriction, deletion or other reasonable measures.

22. False reports and appeals

Knowingly false reports may result in enforcement. Users may request reconsideration where a review channel is available.

23. No guarantee

Detection systems are imperfect. A violation may evade detection and legitimate activity may be flagged for review.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

High-risk commercial combinations

Certain combinations of terms, domains, destinations and behaviors may be treated as higher risk than isolated words. For example, a general medical term may be permissible while a combination suggesting illicit sale, credential theft, malware delivery or fraudulent acquisition may trigger review or restriction.

Medical and recovery context

Medical, pharmaceutical, addiction-recovery, academic and public-health discussion is not automatically prohibited. Enforcement should distinguish legitimate informational context from unlawful sale, trafficking, counterfeit medicine or deceptive medical claims.

Financial abuse

URLy may restrict links that impersonate banks, payment providers, tax authorities, investment platforms, exchanges or financial professionals where the purpose is deception, credential collection or financial theft.

Government impersonation

Use of official names, logos or language is not automatically prohibited. The risk arises where a Short Link is designed to make users believe they are interacting with an official government or law-enforcement service when they are not.

Adult content

Adult content involving consenting adults may be subject to product, legal or hosting restrictions. Any sexual content involving minors, coercion, trafficking or non-consensual intimate material is prohibited.

Security research

Good-faith security research may be permitted when it does not facilitate real-world harm, unauthorized access or distribution of malicious payloads. Researchers should use the Vulnerability Disclosure Policy.

Copyright context

News reporting, criticism, quotation, education and other lawful uses may require contextual review. A complaint alone does not automatically establish infringement.

Domain reputation

A domain may receive elevated risk because of known abuse signals, suspicious infrastructure, repeated reports or security intelligence. Domain reputation is a risk signal, not by itself a legal finding.

Evasion and obfuscation

Attempts to evade filters through Unicode confusables, homographs, punctuation, spacing, encoding, transliteration or repeated account creation may be treated as aggravating factors.

Enforcement records

URLy may retain limited enforcement and abuse records as described in the retention policy so that repeated abuse can be identified and lawful investigations can be supported.

3. 03 Global Privacy Policy

This Policy explains what information URLy processes, why it is processed, how it is protected, when it may be shared and how users can exercise privacy rights.

1. Controller

URLy is operated by Firma Life. Registered address: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye.

2. Information collected

Account and authentication information.

User-submitted URLs, Short Link metadata and API information.

IP address and approximate IP-derived country/region/city.

Browser, browser language, operating system, device type, access time and available referrer information.

Click/access information and link analytics.

Support, abuse, security, moderation and legal-request records.

3. Approximate location

IP-based location is approximate and is not precise GPS location.

4. Local IP geolocation processing

URLy resolves approximate geolocation locally on-premise using encrypted edge headers and local databases. IP addresses are NOT transmitted to third-party IP geolocation API providers (ip-api.com has been decommissioned). Approximate location is limited to country/region/city and is never precise GPS tracking.

5. Purposes

Providing and maintaining the Service.

Account and Short Link management.

Analytics and operational measurement.

Security, fraud and abuse prevention.

Phishing, malware and suspicious-domain detection.

Customer support and legal/rights requests.

Compliance with applicable law and valid legal process.

Service reliability and improvement.

6. Legal bases

Depending on the jurisdiction, processing may rely on contract, legal obligation, legitimate interests, consent or another lawful basis.

7. Analytics and advertising

URLy does not currently use third-party advertising or third-party analytics platforms for user tracking. URLy’s own infrastructure may process technical and click/access information for service analytics, security and abuse prevention.

8. Cookies

See the Cookie Policy. Essential session, authentication, security and preference technologies may be used.

9. Sharing

Data may be shared with processors, service providers, authorities where legally required or authorized, and other parties where necessary to protect rights, safety or the Service. URLy does not sell personal data.

10. International transfers

Primary infrastructure is in Türkiye. Certain processors, including the current IP-geolocation provider, may process data outside Türkiye. Where law requires transfer safeguards, appropriate lawful mechanisms and safeguards will be used.

11. Retention

General retention targets are described in the Data Retention & Deletion Policy. Exact deletion dates may vary because of legal holds, security investigations, disputes, backups and other lawful exceptions.

12. Security

URLy supports TLS 1.2/1.3, disables legacy SSL/TLS, uses modern authenticated encryption cipher suites, supports forward secrecy and X25519MLKEM768, and has received an A rating in Qualys SSL Labs testing for the primary endpoint. No security system can guarantee absolute protection.

13. Rights

Depending on applicable law, users may have rights to access, correct, delete, restrict, object, obtain portability, withdraw consent and challenge certain automated decisions.

14. Children

URLy prohibits child sexual exploitation and related abuse. Reports should be sent to abuse@urly.tr.

15. Third-party destinations

Destination websites have their own privacy practices. URLy does not generally control their content or privacy practices.

16. Changes

This Policy may be updated when practices, law or the Service changes.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Account and authentication records

Account records may include email address, verification state, password hash, password-reset or email-change tokens, account status, language preference, API-related identifiers and security timestamps. Passwords should be stored as hashes rather than plaintext.

Support and communications

When users contact support, URLy may process the name, email address, subject, message, attachments or verification information necessary to answer the request.

API applications

API application records may include project name, purpose, domain, associated account, API key metadata and source IP. These records may be used for approval, security, abuse prevention and support.

Security and abuse logs

Security records may include event type, timestamps, IP address, account or Short Link identifiers, rule identifiers, risk scores and enforcement outcomes. Access to these records should be restricted.

Referrer information

Where HTTP referrer information is collected, it may contain information supplied by the browser. URLy should minimize unnecessary query-string or fragment data where technically feasible because referrer URLs can contain sensitive information.

IP handling

IP addresses are used for security, abuse prevention, rate limiting, operational analytics and approximate geolocation. An IP address can be personal data under applicable law.

Data minimization

URLy seeks to process information that is reasonably necessary for the purposes described in this Policy. Users should avoid submitting unnecessary sensitive personal data.

Legal requests

When legally compelled or authorized, URLy may disclose relevant records. It will not promise to produce information it does not possess.

Changes in providers

If URLy adds analytics, advertising, security, geolocation, hosting or other providers that materially affect personal-data processing, privacy disclosures should be reviewed and updated.

Data breach response

URLy may investigate suspected personal-data breaches, contain affected systems, preserve evidence and make notifications required by applicable law.

4. 04 Cookie Policy

This Policy describes cookies and similar technologies used by URLy.

1. Essential cookies

URLy may use session and authentication cookies, CSRF/security-related session state and language or preference cookies.

2. Persistent technologies

Some preferences may be stored beyond a single session where needed for functionality.

3. Third-party tracking

URLy does not currently use Google Analytics, third-party advertising pixels or comparable third-party cross-site advertising/tracking platforms for user tracking.

4. Server-side analytics

URLy may process access and click information through its own infrastructure. Server-side analytics is not itself a browser cookie.

5. Browser controls

Users can disable or delete cookies through browser settings. Essential functionality may stop working.

6. Do Not Track

Do Not Track is not standardized across all environments; URLy does not promise a particular technical response to every DNT signal.

7. Future changes

If non-essential third-party tracking or advertising is introduced, this Policy and any required consent mechanism will be updated.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Session lifecycle

Session cookies may expire when a session ends or after a security timeout. Authentication cookies may be invalidated after password changes, account suspension, logout or suspected compromise.

Security attributes

All production cookies issued by URLy (including PHPSESSID, app_lang, and urly_terms_agreed) strictly enforce the Secure attribute (transmitted exclusively over encrypted TLS/HTTPS connections) and SameSite=Lax protection. Sensitive session and authentication cookies additionally enforce HttpOnly to prevent unauthorized access via clientside scripts.

CSRF protection

Where state-changing requests require CSRF protection, URLy may use session-bound tokens or equivalent safeguards. CSRF tokens should not be treated as authentication credentials.

Language preference

A language preference cookie may be used to remember the selected interface language. This is a functionality preference rather than advertising tracking.

Cookie rejection

Blocking all cookies may prevent login, account management or other essential functions.

Third-party content

A third-party destination opened after a Short Link may set its own cookies. Those cookies are controlled by the destination operator, not URLy.

Consent

Where applicable law requires consent for a non-essential cookie, URLy should obtain and record consent before setting that technology.

Policy review

Cookie inventories should be reviewed when the frontend, authentication stack, analytics implementation or third-party integrations change.

5. 05 Abuse Reporting

This Policy describes reporting channels and the review process for harmful, unlawful or rights-infringing Short Links.

1. Channels

Security, phishing, malware, fraud and abuse: abuse@urly.tr. Legal, privacy, copyright and trademark: legal@urly.tr. General support: support@urly.tr.

2. Report information

Short Link URL.

Destination URL if safely available.

Description and category of suspected abuse.

Relevant dates and context.

Evidence that can be safely shared.

Reporter contact information and authority where relevant.

3. Phishing reports

Include the impersonated organization, suspected credential collection, affected domain and any relevant indicators.

4. Malware reports

Include the malicious URL, behavior observed, malware family if known and indicators of compromise without redistributing dangerous payloads.

5. Fraud reports

Describe the deceptive conduct, impersonated entity, financial harm or attempted harm and relevant Short Links.

6. Child safety

Send serious child-safety reports to abuse@urly.tr. Do not download, copy or redistribute illegal material solely to make a report.

7. Copyright and trademark

Formal rights complaints should identify the right, the disputed Short Link/material, the legal basis and the reporter’s authority.

8. Review process

URLy may use automated signals and human review. High-risk Short Links may be temporarily restricted while investigated.

9. Enforcement

Actions may include ALLOW, REVIEW, RESTRICT or BLOCK, and may include account or API restrictions.

10. False reports

Knowingly false, fraudulent or malicious reports may be rejected and may lead to enforcement.

11. Confidentiality

Reports are handled with reasonable confidentiality, subject to law, safety and investigation needs.

12. Response times

URLy may prioritize reports according to severity. No universal response or removal deadline is guaranteed.

13. Appeals

Affected users may request reconsideration where a review channel is available.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Severity triage

Reports may be prioritized based on imminent physical harm, child safety, active credential theft, malware distribution, financial fraud, scale, persistence and potential impact.

Evidence handling

Reporters should provide only evidence reasonably necessary to establish the issue. Sensitive personal information, passwords, authentication tokens and illegal material should not be unnecessarily included.

Reporter safety

URLy may avoid disclosing a reporter’s identity to the reported user where reasonably possible, subject to legal obligations and operational needs.

Temporary restrictions

A temporary restriction may be used while a report is investigated. Temporary restriction does not constitute a final legal finding.

Restoration

If review determines that a restriction was incorrect or no longer necessary, URLy may restore a Short Link or account subject to other applicable rules.

Repeat reporting

Multiple reports concerning the same URL may be consolidated. Repeated reports do not automatically establish a violation.

Malware handling

URLy personnel should not redistribute malicious files merely to investigate a report. Technical indicators can be used without unnecessarily propagating payloads.

Phishing response

Where appropriate, URLy may disable the Short Link, restrict related accounts, preserve relevant records and cooperate with affected providers or authorities.

Copyright response

Copyright complaints may be assessed separately from security or abuse reports and may require evidence of ownership or authorization.

Report status

URLy may provide limited status information but does not guarantee disclosure of internal detection methods or investigative details.

6. 06 Retention Deletion

This Policy establishes general retention targets for categories of information. These are not guarantees of exact automatic deletion dates.

1. Account information

While active and generally up to 12 months after deletion/closure.

2. Deleted account records

Generally up to 12 months after deletion, subject to legal, security and dispute exceptions.

3. Short Links and destination records

While active and generally up to 12 months after deactivation/deletion where applicable.

4. Click/access logs

Generally up to 12 months.

5. IP/device/browser/OS/language

Generally up to 12 months.

6. Security and abuse logs

Generally up to 24 months.

7. Fraud/phishing/malware enforcement records

Generally up to 24 months.

8. Abuse reports

Generally up to 24 months.

9. Legal requests and records

For the duration of the relevant legal matter and as long as reasonably necessary afterward.

10. Aggregated/de-identified data

May be retained longer where it no longer constitutes personal data under applicable law.

11. Anonymous Short Links

Current anonymous Short Links may expire after 30 days of inactivity under product rules.

12. Legal hold

Data may be preserved beyond ordinary retention when necessary for litigation, legal process, investigations, disputes or regulatory requirements.

13. Security incidents

Relevant records may be retained longer where necessary to investigate, remediate and document a security incident.

14. Backups

Backups may retain information beyond primary-system deletion schedules for a limited operational period and may not be individually erasable immediately.

15. Deletion requests

Requests may be submitted to legal@urly.tr. Deletion does not override information that must lawfully be retained.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Creator IP

The IP address associated with creation of a Short Link (urls.creator_ip) is retained strictly for security, abuse prevention, and legal compliance. In accordance with automated retention sweeps:
- For active Short Links, creator IP is retained for up to 12 months (365 days) from creation, after which it is automatically and irreversibly anonymized (set to NULL).
- For deleted or expired Short Links, creator IP is retained for an abuse dispute window of up to 90 days, after which it is automatically set to NULL.

IP geolocation cache

IP geolocation cache records (ip_geo_cache) are retained for a maximum of 12 months (365 days) or automatically cleared when orphaned, ensuring no indefinite retention of cached location mappings.

Support tickets

Support and communication records (support_tickets) are retained strictly according to operational necessity and applicable legal dispute periods:
- Unverified pending requests (status = pending_verification): Automatically purged after 14 days if email confirmation is not completed.
- IP addresses: IP addresses associated with support submissions are retained for up to 90 days for abuse prevention and fraud screening, then automatically anonymized (set to NULL).
- Resolved/closed records and inquiries: Retained for up to 3 years from creation to facilitate quality assurance, dispute resolution, consumer inquiries, and statutory limitation periods under applicable law, after which all ticket messages, user details, and responses are permanently deleted.

API applications

Developer API records (api_applications) are retained strictly in accordance with security lifecycle and operational needs:
- Active API credentials: Retained while the application is active and valid to enable programmatic link shortening and analytics services.
- Application IP addresses: IP addresses recorded at application submission are retained for 90 days for abuse prevention and developer verification, then automatically anonymized (set to NULL).
- Rejected applications: Retained for 90 days following review to allow for applicant inquiries and appeals, after which all project details and reasons are permanently deleted.
- Disabled/inactive credentials: Keys revoked, marked inactive, or unused for more than 12 months (365 days) are automatically purged.
- Orphaned applications: Applications linked to deleted user accounts are immediately deleted during automated account purge cycles.

Rate-limit records

Rate-limit records (rate_limits) are retained strictly for operational security and automated abuse mitigation (rate limiting and brute-force prevention). Expired rate-limit windows are automatically purged 1 day (24 hours) after expiration.

Referrer minimization

Where referrer information is stored (clicks_log.referer), URLy automatically sanitizes and minimizes incoming referrers at the point of ingestion. Query strings (?token=..., ?email=...) and fragments (#...) are strictly stripped to prevent accidental retention of sensitive parameters or personally identifiable information (PII). In addition, automated retention sweeps retroactively sanitize historical referrer records, and the outbound Referrer-Policy header is configured to protect visitors upon redirection.

Deletion versus anonymization

Information that is irreversibly aggregated or de-identified may no longer be treated as personal data, subject to applicable law and the quality of the de-identification.

Legal hold

A legal hold may suspend ordinary deletion for specific records. The hold should be limited to relevant information and removed when no longer necessary.

Backups

Backup retention should be documented separately so that deletion requests and incident-response obligations can be reconciled with backup architecture.

Review cadence

Retention schedules should be reviewed periodically against actual database cleanup jobs and application behavior.

7. 07 Security Policy

This Policy describes the principal security controls and verified transport-security characteristics of URLy.

1. TLS

URLy supports TLS 1.2 and TLS 1.3. Legacy SSL/TLS protocols are disabled.

2. Cryptography

The primary endpoint uses modern authenticated-encryption cipher suites and supports forward secrecy.

3. Post-quantum key exchange

X25519MLKEM768 support is present on the primary endpoint.

4. Certificate and protocol

The primary endpoint uses a trusted TLS certificate and supports HTTP/2.

5. External testing

Qualys SSL Labs has rated the primary endpoint A. The assessment tested common TLS issues including BEAST, POODLE variants, Heartbleed, CCS, ROBOT and related conditions, with the tested endpoint reported clean or mitigated.

6. Application controls

Input validation.

Authentication and session controls.

Authorization.

CSRF protections where applicable.

Rate limiting.

Abuse prevention.

Security logging and audit records.

Secure configuration and access controls.

7. Slug Protection

URLy uses normalization, case folding, separator handling, script/confusable analysis and rule matching to protect sensitive slugs. Decisions are ALLOW, REVIEW, RESERVED or BLOCK.

8. Destination Safety

Destination Safety is separate from slug protection and evaluates URLs/domains/activity for abuse and security risk.

9. Incident response

URLy may investigate, contain, remediate and document security incidents. Relevant information may be preserved where necessary.

10. Vulnerability management

Security issues may be prioritized by severity, exploitability, affected scope and user impact.

11. Administrative access

Access to operational systems should be limited according to role and operational necessity.

12. Limitations

URLy does not guarantee absolute security, uninterrupted availability or detection of every vulnerability or malicious destination.

13. Responsible disclosure

Security researchers should use the Vulnerability Disclosure Policy and abuse@urly.tr.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Trusted proxy boundaries

IP-address and geolocation extraction must trust forwarding and edge headers (including client IP and GeoIP metadata) only when requests originate from infrastructure controlled and trusted by URLy. Untrusted clients must not be able to spoof the effective client IP or geolocation through arbitrary headers.

Cookie and session security

Production sessions enforce Secure cookies when served over HTTPS, together with HttpOnly and SameSite=Lax. Active session identifiers are immediately regenerated (session_regenerate_id) upon successful authentication and activation to prevent session fixation attacks.

SSRF protection

All destination URL validation and redirection mechanisms enforce multi-tier SSRF (Server-Side Request Forgery) defenses against internal network reachability. Controls explicitly neutralize and block:
- Private, loopback, link-local, carrier-grade NAT, and reserved CIDR ranges across IPv4 and IPv6.
- DNS rebinding attacks and hostname-to-private-IP resolutions via recursive DNS validation.
- Obfuscated IP notations including decimal integers (e.g. 2130706433), hexadecimal (0x7f000001), octal, and IPv4-mapped IPv6 formats (::ffff:127.0.0.1).
- Localhost variations, single-word internal hostnames, internal TLDs (.local, .internal, .lan, .corp, etc.), and Cloud metadata endpoints (169.254.169.254, metadata.google.internal).
- Port restrictions limiting destinations strictly to standard web services (80, 443, 8080, 8443) to prevent internal port scanning.
- Self-referential redirect loops and dynamic re-verification prior to HTTP 302 dispatch.

Rate limiting

Rate limits and brute-force defenses are strictly enforced across public and sensitive operations:
- Authentication & login attempts enforce multi-tier rate limiting combining client IP, target account/email, and composite IP+account thresholds with cooldown delays to neutralize credential stuffing and brute-force attacks.
- Account creation, password recovery, verification resend, link creation, and API endpoints enforce granular per-IP and per-target velocity limits.

Secret management

Production credentials, SMTP passwords, database passwords, API keys and cron tokens must be stored securely and rotated if exposed.

Logging access

Security logs should be access-controlled and protected against unauthorized modification. Logs should not contain unnecessary secrets.

Dependency security

Third-party libraries and runtime components should be kept reasonably current and reviewed for material vulnerabilities.

Admin security

Administrative accounts should use strong authentication, least privilege and additional controls appropriate to their impact.

Incident evidence

Relevant logs should be preserved when an incident is under investigation, while avoiding unnecessary expansion of personal-data retention.

Security disclosure limitations

Publishing exact detection thresholds, blocklists or internal security architecture may increase evasion risk and is therefore not promised.

8. 08 Copyright Takedown

This procedure explains how URLy receives and reviews copyright and trademark complaints.

1. Scope

Complaints may concern a URLy Short Link, URLy-controlled metadata or other material within URLy’s control.

2. Destination-hosted content

URLy may control a Short Link but generally cannot directly remove content hosted by the third-party destination.

3. Copyright notice requirements

Identify the copyrighted work, disputed Short Link/material, basis of ownership or authorization, contact details and declarations required by applicable law.

4. Trademark complaint requirements

Identify the mark, ownership or registration basis where relevant, disputed Short Link/material and explanation of alleged infringement or confusion.

5. Review

URLy may request clarification, evidence or authorization. A complaint does not automatically establish infringement.

6. Temporary restriction

A Short Link may be temporarily restricted when reasonably necessary to prevent continuing harm while a serious complaint is reviewed.

7. Counter-notification

Where appropriate, an affected user may submit a counter-notification or reconsideration request with the information required by applicable law.

8. Fraudulent notices

Fraudulent, knowingly false or abusive notices may be rejected and may result in enforcement.

9. Repeat infringement

Repeated substantiated infringement may result in stronger enforcement, including account or Short Link restrictions.

10. Fair use and legal exceptions

URLy will consider applicable legal exceptions where relevant and where sufficient information is provided.

11. DMCA

URLy may process valid DMCA notices where applicable but does not represent that it qualifies for any particular DMCA safe harbor.

12. Government and emergency requests

Formal government requests should be sent to legal@urly.tr. Emergency requests involving serious imminent harm may be prioritized.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Required declaration

Where a statutory notice requires a declaration of good faith, accuracy or authority, the complainant should provide the applicable declaration.

Identification standard

The disputed material should be identified with enough precision for URLy to locate it without guessing.

Authorization

A representative should identify the rights holder or provide evidence of authority when reasonably requested.

Multiple works

Where multiple works or marks are involved, each should be identified clearly enough to support review.

Bad-faith notices

Knowingly false notices, harassment through the notice system or attempts to suppress lawful criticism may be rejected.

Destination limitations

If the alleged infringement is entirely hosted by a third-party site, URLy may provide the destination operator’s appropriate reporting route where known, but does not guarantee removal there.

Temporary measures

Temporary Short Link restrictions may be used where continued availability presents a credible legal or safety risk.

Counter-notice review

Counter-notices may be reviewed for completeness and may be handled according to applicable law and any relevant provider obligations.

Repeat infringement

A pattern of substantiated infringement may be considered in account enforcement.

No legal determination

URLy’s operational action is not necessarily a judicial determination that infringement occurred.

9. 09 Law Enforcement

This Policy explains how URLy handles government, law-enforcement and formal legal requests.

1. Contact

Send requests to legal@urly.tr.

2. Request contents

Requests should identify the authority, legal basis, jurisdiction, relevant account/Short Link, date range and specific records sought.

3. Data availability

URLy can only provide information it possesses and can lawfully disclose. Historical information may no longer exist due to retention or technical limitations.

4. Preservation

Where legally permitted and technically feasible, URLy may preserve specified records for a reasonable period pending appropriate legal process.

5. User notification

Where legally permitted and where notification would not create a safety or investigative risk, URLy may notify affected users.

6. Emergency requests

Requests involving imminent risk of death or serious physical harm may receive expedited review.

7. International requests

International authorities should use legally recognized procedures appropriate to the jurisdiction and nature of the request.

8. Private requests

Private parties should use applicable legal procedures. A private request does not automatically compel disclosure.

9. Authentication

URLy may verify the authenticity and authority of a request before responding.

10. Overbroad requests

URLy may request clarification or narrow an overbroad request where appropriate.

11. Legal challenge

Where appropriate, URLy may challenge, narrow or seek clarification of a legally defective request.

12. Confidentiality

URLy may keep requests confidential where required or appropriate.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Specificity

Specific requests reduce processing time and help avoid unnecessary disclosure of unrelated information.

Date ranges

Requests should specify relevant time periods because URLy may not retain historical data indefinitely.

Identifiers

Useful identifiers may include Short Link, account email, user ID, API application or relevant timestamp.

Content requests

Requests for third-party destination content should generally be directed to the destination operator unless URLy itself controls the requested material.

Preservation scope

Preservation should identify the records and time period to be preserved and should not require indefinite preservation without appropriate legal basis.

Emergency standard

Emergency requests should describe the imminent risk and why ordinary process cannot reasonably be followed.

Authentication

URLy may verify official email domains, signed requests, reference numbers or other authenticity indicators.

Disclosure minimization

Where disclosure is required, URLy should seek to provide information reasonably responsive to the request rather than unrelated records.

Notification exceptions

Notification may be withheld where prohibited by law, court order, emergency circumstances or reasonable investigative concerns.

Transparency

Aggregate legal-request statistics may be included in transparency reporting where lawful and safe.

10. 10 KVKK Aydinlatma

This English-base notice is intended for localization into Turkish and describes processing relevant to data subjects protected by Turkish data-protection law.

1. Veri Sorumlusu

Veri sorumlusu Firma Life’tır. Adres: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye.

2. Kişisel veri kategorileri

Hesap ve iletişim bilgileri.

Kimlik doğrulama ve güvenlik kayıtları.

IP adresi.

IP tabanlı yaklaşık ülke/bölge/şehir bilgisi.

Tarayıcı, işletim sistemi, cihaz türü ve dil bilgileri.

Kısa bağlantı ve hedef URL bilgileri.

Tıklama/erişim kayıtları.

Destek, abuse, güvenlik, moderasyon ve hukuki başvuru kayıtları.

3. İşleme amaçları

Hizmetin sunulması ve hesap yönetimi.

Kısa bağlantıların oluşturulması ve işletilmesi.

Güvenlik ve kötüye kullanımın önlenmesi.

Phishing, malware, fraud ve spam tespiti.

Destek ve başvuruların cevaplanması.

Hukuki yükümlülüklerin yerine getirilmesi.

Hizmet güvenilirliğinin ve performansının geliştirilmesi.

4. Hukuki sebepler

KVKK kapsamında uygulanabilir hukuki sebepler arasında sözleşmenin kurulması/ifası, hukuki yükümlülük, hakkın tesisi/kullanılması/korunması, veri sorumlusunun meşru menfaati ve gerektiğinde açık rıza bulunabilir.

5. Özel nitelikli veriler

URLy’nin amacı özel nitelikli kişisel veri toplamak değildir. Kullanıcılar gereksiz özel nitelikli verileri destek veya form alanlarına göndermemelidir.

6. Yurt dışı aktarım

Ana altyapı Türkiye’dedir. Ziyaretçi IP adresleri yerel (on-premise) altyapı ve şifreli edge ağ başlıkları üzerinden tamamen yerel olarak işlenmektedir; IP adresleri üçüncü taraf yurt dışı sorgulama servislerine aktarılmaz. KVKK Madde 9 kapsamındaki uluslararası aktarım riskleri yerel mimari ile bertaraf edilmiştir.

7. Saklama

Genel saklama hedefleri Data Retention & Deletion Policy’de açıklanmıştır.

8. Güvenlik

URLy makul teknik ve idari tedbirler uygular. TLS 1.2/1.3 ve doğrulanmış diğer güvenlik kontrolleri Security Policy’de açıklanmıştır.

9. İlgili kişi hakları

İlgili kişiler uygulanabilir KVKK hakları kapsamında başvurularını legal@urly.tr adresine iletebilir.

10. Başvuru usulü

URLy kimlik doğrulaması, başvurunun kapsamının netleştirilmesi ve hukuken gerekli bilgi/evrakların sunulmasını talep edebilir.

11. Çocuklar

Çocukların cinsel istismarı ve diğer ciddi çocuk güvenliği ihlalleri yasaktır.

12. Güncellemeler

Bu notice, işleme faaliyetleri veya mevzuat değiştikçe güncellenebilir.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Veri güvenliği

Kişisel verilerin hukuka aykırı işlenmesini, erişilmesini veya aktarılmasını önlemek için teknik ve idari tedbirler uygulanır.

IP ve güvenlik kayıtları

IP adresleri ve teknik kayıtlar güvenlik, kötüye kullanımın önlenmesi, rate limiting ve hukuki süreçler için işlenebilir.

Çerezler

Zorunlu oturum, güvenlik ve tercih çerezleri hizmetin çalışması için kullanılabilir. Zorunlu olmayan teknolojiler için uygulanabilir mevzuat kapsamında gerekli mekanizmalar kullanılmalıdır.

Veri aktarımı

Yurt içi ve yurt dışı hizmet sağlayıcılarına yapılan aktarımlar uygulanabilir KVKK hükümlerine göre değerlendirilir.

Başvuru kimlik doğrulaması

Başvurucunun verilerinin üçüncü kişilere açıklanmaması için makul kimlik doğrulaması istenebilir.

Başvuru kayıtları

KVKK başvurularının alındığını ve cevaplandığını göstermek amacıyla sınırlı başvuru kayıtları saklanabilir.

Reddetme/limitleme

Kanunen izin verilen durumlarda, başvuru diğer kişilerin hakları, güvenlik, hukuki yükümlülükler veya yasal saklama yükümlülükleri nedeniyle kısmen veya tamamen sınırlandırılabilir.

İletişim

Başvurular legal@urly.tr üzerinden alınır; uygulanabilir resmi başvuru yolları saklıdır.

11. 11 GDPR EEA UK

This Notice applies where GDPR, UK GDPR or equivalent EEA/UK privacy law applies.

1. Controller

Firma Life, Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye.

2. Categories

Account, authentication, IP, approximate location, technical/device, Short Link, click/access, support, abuse, security, moderation and legal-process data.

3. Purposes

Service delivery, security, fraud/abuse prevention, analytics, support, legal compliance and protection of rights.

4. Legal bases

Contract, legal obligation, legitimate interests, consent where required, and establishment/exercise/defense of legal claims where applicable.

5. Special categories

URLy does not intentionally seek special-category data. Users should not submit unnecessary sensitive information.

6. Automated processing

URLy may use automated risk signals for slug protection, destination safety, abuse detection and moderation. Automated signals can result in review or restriction; where applicable, users may request human reconsideration.

7. International transfers

Primary infrastructure is in Türkiye. The current IP-geolocation provider may process IP information outside the EEA/UK. Where a restricted transfer occurs, URLy will use a lawful transfer mechanism and appropriate safeguards required by applicable law.

8. Rights

Access.

Rectification.

Erasure.

Restriction.

Objection.

Portability where applicable.

Withdrawal of consent where applicable.

Rights relating to certain automated decisions.

9. Identity verification

Reasonable identity verification may be required before disclosure or changes affecting personal data.

10. Retention

See the Data Retention & Deletion Policy.

11. Complaints

You may complain to the competent supervisory authority in the EEA/UK jurisdiction applicable to you.

12. Representative / DPO

URLy does not claim an EEA/UK representative or DPO unless formally appointed. If appointment becomes required and is made, this Notice will be updated.

13. Breach notification

Where required by applicable law, URLy will follow applicable personal-data breach notification obligations.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Controller contact

For privacy matters, contact legal@urly.tr. The legal entity and address are stated in the Global Privacy Policy.

Legitimate interests

Relevant legitimate interests may include securing Short Links, preventing fraud, protecting accounts, enforcing policies, maintaining service integrity and responding to abuse.

Data minimization

URLy seeks to limit collection to information reasonably necessary for identified purposes.

Processor contracts

Where required, processors should be bound by GDPR-compliant data-processing terms and confidentiality/security obligations.

Transfer safeguards

Where a transfer requires safeguards, URLy should use an applicable adequacy decision, standard contractual mechanism or other lawful transfer basis, as appropriate.

Data-subject requests

Requests may be submitted to legal@urly.tr and may require identity verification.

Automated decisions

Risk scoring may assist moderation. Where a decision has legal or similarly significant effects and applicable law grants rights, URLy will provide the rights required by law.

Children

Where services are accessed by minors, applicable age and consent requirements will be considered. Illegal child-safety activity is prohibited regardless of age.

Retention exceptions

Legal obligations, claims, fraud prevention and security investigations may justify retention beyond ordinary targets where permitted by law.

Supervisory authority

Users may complain to the supervisory authority competent for their circumstances.

12. 12 Child Safety

This Policy establishes zero-tolerance rules for child sexual exploitation and serious abuse involving minors.

1. Prohibited material and conduct

CSAM and sexual exploitation of children.

Grooming or sexual solicitation of minors.

Sexualized content involving minors.

Child trafficking or exploitation.

AI-generated or manipulated material that sexualizes or exploits minors.

Child-targeted fraud, extortion or coercion.

Doxxing or malicious exposure of minors’ personal data.

Circumvention of age controls for unlawful purposes.

2. Immediate action

URLy may immediately restrict Short Links, accounts or related activity where there is a credible child-safety risk.

3. Preservation

Relevant information may be preserved when necessary for safety, investigation or lawful requests.

4. Reporting

Reports should be sent to abuse@urly.tr. Do not download, copy, create additional copies of or redistribute illegal material merely to report it.

5. Authorities

URLy may cooperate with competent authorities where legally required or appropriate.

6. Privacy

Child-safety reports are handled with reasonable confidentiality, subject to safety and legal requirements.

7. False reports

Knowingly false or malicious reports may be rejected and may result in enforcement.

8. Appeals

Enforcement may be reconsidered where appropriate, except where doing so would create unacceptable safety, legal or investigative risk.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Grooming indicators

Attempts to build sexual trust with minors, solicit sexual images, move a minor to private communication for sexual purposes or evade parental/safety controls may trigger immediate action.

Financial exploitation

Scams, coercion or extortion targeting minors are prohibited.

Personal information

Publishing a minor’s address, school, phone number, live location or other sensitive personal information for malicious purposes may be restricted.

Age evasion

Attempts to use URLy to bypass age gates for unlawful or exploitative purposes are prohibited.

Preservation

Where appropriate, URLy may preserve relevant account, Short Link and security records subject to applicable law.

Authority cooperation

Requests from competent child-protection or law-enforcement authorities may be handled under the Law Enforcement Guidelines.

Reporter guidance

Reporters should provide URLs and concise descriptions rather than copying or redistributing illegal imagery.

False allegations

Good-faith reports are welcome even where the reporter is uncertain; knowingly fabricated allegations may be treated differently.

Confidentiality

URLy may limit disclosure of report details to protect victims and investigations.

Policy updates

Child-safety practices may be updated as law, technology and safety standards evolve.

13. 13 Data Subject Request

This procedure explains how users can exercise privacy rights under applicable law.

1. Submission

Send a request to legal@urly.tr. State the relevant account/email if applicable, requested right and sufficient information to locate the record.

2. Rights

Access, correction, deletion, restriction, objection, portability, withdrawal of consent and applicable automated-decision rights.

3. Identity verification

Reasonable verification may be requested to prevent unauthorized disclosure.

4. Clarification

We may request clarification where a request is too broad or ambiguous.

5. Response timing

URLy will respond within applicable legal deadlines. Where law allows extensions, the requester may be informed.

6. Fees

Requests are generally handled without charge unless applicable law permits a reasonable fee for excessive or manifestly unfounded/repetitive requests.

7. Deletion limits

Information may remain where legally required, necessary for security, fraud prevention, disputes, legal claims or other lawful exceptions.

8. Third-party destinations

URLy cannot generally delete personal data held independently by a third-party destination website.

9. Appeals

Where applicable, users may request reconsideration of a refusal or limitation.

10. Request records

URLy may retain limited records of privacy requests for compliance, audit and security purposes.

11. Contact

legal@urly.tr.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Access scope

An access response may include categories, purposes, recipients, retention information and copies of personal data where legally required.

Correction

Users may identify inaccurate or incomplete personal information and request correction.

Deletion

Deletion may be limited where records must be retained by law or are necessary for legal claims, security or fraud prevention.

Restriction

Where applicable, processing may be restricted while accuracy, legality or objection is assessed.

Objection

An objection may be reviewed against the lawful basis and applicable exceptions.

Portability

Where portability applies, data may be provided in a structured, commonly used and machine-readable format.

Consent withdrawal

Withdrawing consent does not invalidate processing already lawfully performed before withdrawal.

Third-party data

URLy cannot generally correct or delete data held independently by a third-party destination.

Identity fraud prevention

Verification information itself should be minimized and protected.

Records of decisions

Limited records may be retained to demonstrate compliance with privacy obligations.

14. 14 Subprocessors

This disclosure explains third-party processing categories and the currently known geolocation integration.

1. Current infrastructure

URLy’s primary infrastructure is in Türkiye.

2. Analytics and advertising

URLy does not currently use third-party advertising or third-party analytics platforms for user tracking.

3. Local IP Geolocation Architecture

URLy uses a local on-premise IP geolocation mechanism and encrypted TLS edge transport headers. IP addresses are NOT transmitted to external third-party geolocation API providers (external APIs like ip-api.com have been completely decommissioned). Geolocation is performed entirely within URLy's local infrastructure, ensuring strict privacy, KVKK and GDPR compliance without cross-border data transfer risks.

4. Processor categories

Infrastructure and hosting.

Storage and backup.

Transactional email and support communications.

Security and abuse services.

Monitoring and technical services.

IP geolocation.

Other operational processors necessary to provide the Service.

5. Processor obligations

Where required, processors should be bound by appropriate confidentiality, security and data-processing obligations.

6. International transfers

Where processors process data outside Türkiye or the EEA/UK, applicable transfer requirements and safeguards should be addressed.

7. No sale

URLy does not sell personal data.

8. Changes

Processor categories and specific vendors may change. Material disclosures will be updated where required.

9. User rights

Data-subject requests may be submitted to legal@urly.tr.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Provider inventory

The published disclosure should be reviewed when a new provider gains access to personal data or an existing provider materially changes its processing.

Purpose limitation

Processors should receive only the data reasonably necessary for their contracted function.

Security

Providers handling personal data should be assessed according to the sensitivity and risk of the processing.

IP geolocation

URLy processes IP geolocation locally within its own environment. No visitor IP addresses are sent to third-party geolocation lookup services.

Email providers

Transactional email providers may process email addresses and message metadata necessary to deliver account and support communications.

Hosting and storage

Infrastructure providers may process system data as part of hosting, backup and maintenance.

Support providers

Where third-party support tools are introduced, their processing should be reflected in this disclosure.

International transfers

Transfer mechanisms should be reviewed whenever a provider processes data in a new country.

Change notification

Where required by law or contract, users may be informed of material processor changes.

No sale

Processing by a service provider for URLy’s purposes is not a sale of personal data.

15. 15 Vulnerability Disclosure

This Policy provides a responsible channel for security researchers to report vulnerabilities.

1. Contact

Report vulnerabilities to abuse@urly.tr.

2. Good-faith testing

Limit testing to what is necessary to demonstrate the issue.

3. Prohibited testing

Do not access, modify, delete or expose other users’ data.

Do not conduct destructive or denial-of-service testing.

Do not deploy malware or persistence.

Do not social-engineer staff or users.

Do not extort or threaten URLy.

Do not publish sensitive details before reasonable coordination.

4. Short Link testing

Redirect and URL handling tests must avoid harming third parties and must not be used to facilitate real-world abuse.

5. Proof of concept

Provide concise reproduction steps and evidence. Redact personal data and secrets.

6. Credentials and secrets

Do not send passwords, API keys or other live secrets in a report. If accidentally exposed, notify URLy immediately without redistributing them.

7. Handling

URLy may acknowledge, investigate, request clarification, remediate or close a report.

8. Severity

Severity may consider impact, exploitability, affected scope, user exposure and realistic abuse potential.

9. Duplicates

Duplicate reports may be linked to an existing investigation.

10. Third-party vulnerabilities

Issues caused solely by third-party systems may be redirected to the relevant provider.

11. Bug bounty

No monetary reward is promised unless expressly announced.

12. Safe-harbor intent

URLy intends to avoid unnecessary legal escalation for good-faith research following this Policy, to the extent permitted by law. This is not a legal waiver.

13. Coordinated disclosure

Researchers are encouraged to coordinate publication where sensitive details could create user risk.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Scope examples

Examples include authentication bypass, authorization flaws, SQL injection, XSS, SSRF, insecure direct object references, sensitive-data exposure, API-key disclosure and Short Link security flaws.

Out-of-scope examples

Purely informational issues without meaningful security impact, unsupported third-party systems and social-engineering attempts against personnel may be out of scope.

Privacy

Researchers must minimize access to personal data and promptly stop testing if real user data is encountered.

Rate-limit testing

Do not intentionally exhaust production resources. Use low-volume demonstrations or coordinate a safer test where possible.

SSRF testing

Do not probe internal services or metadata endpoints beyond what is necessary to establish the vulnerability.

Account takeover

Do not use another person’s credentials. If a vulnerability demonstrates takeover potential, stop before accessing unrelated data.

Disclosure timeline

URLy may coordinate a disclosure timeline based on severity and remediation status.

Recognition

URLy may acknowledge valid reports at its discretion but does not promise public credit.

Emergency vulnerabilities

Critical vulnerabilities may require immediate temporary restrictions or emergency maintenance.

Security.txt

The public security.txt file should point to the security page and abuse reporting address.

16. 16 Freedom Content Moderation

This Policy balances lawful expression with protection from serious abuse.

1. Principle

URLy supports lawful expression, journalism, research, criticism, public-interest information and legitimate discussion.

2. Restricted content

Serious abuse, unlawful exploitation, phishing, fraud, malware, child sexual exploitation, privacy abuse, trafficking and violent-wrongdoing facilitation may be restricted.

3. Political and public-interest content

Political speech, criticism of governments and public-interest journalism are not automatically prohibited.

4. Context

Intent, audience, context, likelihood of harm, repetition and surrounding material may be considered.

5. Automated systems

Automated signals may identify suspicious slugs, destinations, domains and behavior. Automated detection can produce false positives.

6. Human review

Human review may be used where appropriate, particularly for appeals, high-risk reports and ambiguous cases.

7. Decisions

Content moderation decisions are ALLOW, REVIEW, RESTRICT or BLOCK. Slug Protection uses a separate ALLOW, REVIEW, RESERVED or BLOCK taxonomy.

8. Proportionality

Where practical, URLy may choose the least restrictive effective action consistent with safety and law.

9. Appeals

Users may request reconsideration through support@urly.tr or the relevant policy channel.

10. Confidentiality of detection

URLy may withhold exact thresholds, detection rules and security signals when disclosure would facilitate evasion.

11. Repeat abuse

Repeated or coordinated abuse may result in stronger enforcement.

12. No guarantee

URLy cannot guarantee that every violation will be detected or that every legitimate link will avoid review.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Lawful controversial content

Controversial, offensive or unpopular opinions are not automatically prohibited merely because they are controversial.

Harm threshold

Moderation may focus on credible risk of unlawful conduct, serious harm, exploitation, fraud or abuse rather than viewpoint alone.

Contextual review

The same words may carry different meaning in news reporting, historical discussion, satire, quotation or direct operational instruction.

Impersonation

Parody and commentary may be distinguished from deceptive impersonation based on context and likely user confusion.

Adult content

Adult sexual material may be subject to applicable law and product restrictions, while content involving minors or non-consensual exploitation is prohibited.

Research and security

Legitimate research may be reviewed differently from operational exploitation or malware distribution.

Appeals

Appeals should identify why the decision is believed to be incorrect and provide relevant context.

Repeated evasion

Repeated attempts to evade a valid restriction may lead to stronger enforcement.

Transparency limits

URLy may explain the general policy basis without exposing proprietary detection thresholds.

Corrections

If a moderation decision is found to be erroneous, URLy may restore the affected Short Link or account where appropriate.

17. 17 Transparency Report

This Policy describes the framework URLy may use for periodic aggregate transparency reporting.

1. Purpose

Transparency reporting may describe aggregate abuse, moderation, legal and security activity without exposing individual users.

2. Potential metrics

Abuse reports received.

Phishing/malware/fraud reports.

Short Links restricted or blocked.

Accounts or API access restricted.

Appeals and outcomes.

Copyright/trademark notices.

Government and law-enforcement requests.

Emergency requests.

Child-safety actions.

Security incidents where disclosure is appropriate.

3. Aggregation

Data may be aggregated and small counts suppressed to reduce re-identification risk.

4. Methodology

Reports may explain definitions, counting periods, methodology, corrections and limitations.

5. Privacy

No individual user’s personal data should be published merely to increase transparency.

6. Security

Details that would enable abuse, expose vulnerabilities or undermine investigations may be omitted.

7. Legal restrictions

Publication may be delayed or limited where law, court orders, confidentiality or investigation needs require it.

8. Third-party reports

Reports may distinguish reports received from third parties from actions independently detected by URLy.

9. No promise

URLy is not required to publish a report at a particular frequency unless it expressly commits to one.

10. Corrections

Material errors may be corrected with an appropriate note.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Reporting periods

A report may cover a calendar year, quarter or other defined period.

Counting methodology

One report may count reports, URLs, accounts or actions differently; definitions should be stated clearly.

Duplicates

Multiple reports concerning one Short Link may be counted separately as reports but only once as an affected Short Link.

Automated versus human action

Where feasible, metrics may distinguish automated enforcement from human-reviewed actions.

Appeal outcomes

Appeal statistics may include upheld, reversed, modified or unresolved outcomes.

Legal requests

Requests may be counted by category, jurisdiction and type where lawful.

Child safety

Child-safety metrics should be aggregated carefully to avoid exposing victims or operational details.

Security incidents

Only incidents suitable for public disclosure should be reported; active vulnerabilities may be withheld.

Small-number suppression

Very small counts may be suppressed to reduce re-identification risk.

Corrections and archives

Material corrections should be dated, and prior reports may be archived for transparency.

18. 18 Security Page

This is suggested public-facing copy for https://urly.tr/security.

Security at URLy

Security is a core part of URLy’s infrastructure. We use encrypted transport, application controls, rate limiting, abuse prevention and security monitoring to protect the Service.

Transport security

URLy supports TLS 1.2 and TLS 1.3, disables legacy SSL/TLS, uses modern authenticated encryption cipher suites, supports forward secrecy and X25519MLKEM768, uses a trusted TLS certificate and supports HTTP/2.

Security testing

The primary urly.tr endpoint has received an A rating in Qualys SSL Labs testing, with common TLS vulnerabilities tested as clean or mitigated.

Link safety

URLy separates Global Slug Protection from Destination Safety. These systems help address phishing, malware, fraud, impersonation and other abusive activity.

Report a vulnerability

Send responsible vulnerability reports to abuse@urly.tr.

Related policies

See the Security Policy and Vulnerability Disclosure Policy for additional information.

Last reviewed

[INSERT DATE]

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Application security

URLy uses authentication, authorization, input validation, rate limiting, CSRF protections where applicable and security logging.

Abuse protection

The platform maintains separate slug-protection and destination-safety concepts.

Responsible disclosure

Researchers should report security issues to abuse@urly.tr and follow the Vulnerability Disclosure Policy.

Limitations

No security system is perfect and no guarantee is made that every malicious URL or vulnerability will be detected.

Public claims

The security page intentionally does not claim controls that are not verified for production.

19. 19 security txt

Recommended content for /.well-known/security.txt.

File content

Contact: mailto:abuse@urly.tr
Policy: https://urly.tr/security
Preferred-Languages: en,tr
Expires: [INSERT FUTURE UTC DATE]

Publication note

The Expires value must be a future UTC timestamp and should be renewed before expiration. The /security page should exist before publishing this file.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Required fields

Contact and Policy should point to live URLs/mailboxes. Expires should be a future UTC timestamp.

Language

Preferred-Languages may be updated as supported languages expand.

Maintenance

The file should be reviewed before its Expires date and kept reachable over HTTPS.

20. 20 Privacy Request Form

Suggested production copy for a privacy/data-subject request form.

Intro

Use this form to request access, correction, deletion, restriction, objection, portability or another privacy right available under applicable law.

Fields

Email address associated with the account, if applicable.

Request type.

Description of the request.

Relevant Short Link/account identifier, if applicable.

Additional information needed to locate the data.

Confirmation that the information provided is accurate.

Security notice

Do not submit passwords, authentication codes or unnecessary sensitive information.

Verification

We may request reasonable identity verification before disclosing or changing personal data.

Contact

Formal privacy requests may also be sent to legal@urly.tr.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Access request

Users may request a copy of personal data and relevant processing information where applicable.

Correction request

Users should identify the inaccurate field and the proposed correction.

Deletion request

Users should identify the account or data to be deleted; deletion may be limited by legal or security exceptions.

Objection/restriction

Users should explain the processing they object to or want restricted.

Portability

Where applicable, users may request portable data in a structured format.

Verification

URLy may request reasonable identity evidence and will seek to minimize collection of verification information.

No passwords

The form must not request the user’s password or authentication codes.

Response

Requests are handled according to applicable legal deadlines.

21. 21 Abuse Report Form

Suggested production copy for an abuse/security report form.

Intro

Use this form to report phishing, malware, fraud, scams, impersonation, illegal activity, child-safety concerns or other violations of URLy policies.

Fields

Short Link URL.

Destination URL, if safely available.

Suspected category.

Description.

Relevant dates/context.

Reporter contact information.

Safety notice

Do not download malware or illegal material to investigate a report. Do not upload or redistribute CSAM or other illegal material merely to support a report.

Priority

Serious security and child-safety reports should be sent to abuse@urly.tr.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Phishing

Include the impersonated organization and suspected credential-collection behavior.

Malware

Include the URL and observed behavior without uploading malicious payloads.

Fraud

Describe the deceptive scheme and affected service or organization.

Privacy abuse

Report doxxing, unlawful exposure of personal information or serious privacy violations.

Child safety

Use abuse@urly.tr for urgent child-safety reports and do not upload illegal material.

Weapons/drugs/gambling

Provide enough context to distinguish unlawful commercial facilitation from legitimate discussion.

False reports

Reports should be made in good faith.

Reporter safety

Do not expose your own unnecessary sensitive information in the form.

22. 22 Copyright Trademark Form

Suggested production copy for an intellectual-property complaint form.

Intro

Use this form to report alleged copyright or trademark infringement involving a URLy Short Link or URLy-controlled material.

Fields

Name and contact information.

Rights holder or authorized representative status.

Identification of copyrighted work or trademark.

Identification of Short Link/material.

Explanation of alleged infringement.

Supporting documentation where appropriate.

Required legal declarations/certifications.

Review

URLy may request additional information or temporarily restrict a Short Link while reviewing a serious complaint. A complaint does not automatically establish infringement.

Destination limitation

URLy may not control content hosted by a third-party destination.

Contact

Formal legal/IP matters may also be sent to legal@urly.tr.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Copyright fields

Identify the work, rights holder, disputed URL/Short Link and basis of the claim.

Trademark fields

Identify the mark, owner/registration where relevant and explanation of likely confusion or infringement.

Authorization

Representatives should identify their authority to act.

Evidence

Attach only evidence reasonably necessary to substantiate the complaint.

Counter-notice

Where applicable, affected users may request reconsideration or submit a legally sufficient counter-notice.

Destination limitation

Complaints about material hosted entirely by a third party may need to be sent to that host.

Bad-faith notices

Fraudulent or knowingly false complaints may be rejected.

Legal contact

Formal legal/IP matters should be sent to legal@urly.tr.

Implementation Alignment Appendix

A. Data inventory to policy mapping

Users table information maps to account, authentication and security disclosures. URLs table maps to Short Link, Destination URL, creator IP, title, click limits, expiration and status disclosures. Click logs map to IP, user agent, browser, OS, device, referrer, country/region/city, language and timestamp disclosures. IP geolocation cache maps to approximate location processing. Support tickets and API applications map to support/API processing disclosures.

B. Current technical privacy items requiring implementation alignment

The backend utilizes local on-premise IP geolocation and encrypted edge headers (ip-api.com has been removed). The ip_geo_cache table should have an explicit cleanup mechanism aligned with published retention. urls.creator_ip should have a defined retention path. Referrer storage should be reviewed for query-string and fragment minimization. Support-ticket and API-application retention should be explicitly implemented. These are implementation alignment items, not claims that they are already fixed.

C. Proxy and IP integrity

If HTTP_CF_CONNECTING_IP or X-Forwarded-For is used, only trusted proxy infrastructure should be allowed to supply the effective client IP. Otherwise clients may spoof headers and corrupt security logs, rate limits and abuse decisions.

D. Secret handling

Credentials present in the previously uploaded backend package should be treated as exposed. Database passwords, SMTP passwords, cron tokens and other production-like secrets should be rotated. If any secret was ever committed to public source control, history should be cleaned and credentials replaced.

E. Destination safety

SSRF protections should cover loopback, private, link-local and reserved IP ranges and should account for DNS rebinding and hostname-to-IP changes. Destination validation must not rely solely on a one-time hostname check.

F. Cookie verification

Production should verify Secure, HttpOnly and SameSite behavior for every authentication/session cookie. SSL Labs observations should not substitute for direct application verification.

G. Retention implementation

Published retention is a policy target. Production jobs should actually enforce cleanup for click logs, IP geolocation cache, creator IP, support/API records, rate-limit records and other personal-data stores as appropriate.

H. Slug protection architecture

Normalization should include Unicode NFKC, case folding, separator normalization, script detection, mixed-script detection, confusable skeleton, transliteration/ASCII comparison, exact/alias/variant matching, high-risk patterns, brand proximity and category scoring. Audit records should retain rule version and decision reason without exposing evasion-sensitive details publicly.

I. Moderation architecture

Content/abuse enforcement should remain separate from slug reservation. Automated risk scoring can feed REVIEW or enforcement, while human review and appeal should remain possible where appropriate.

J. Legal publication workflow

Publish the English authoritative version first. After legal approval, produce Turkish localization without changing substantive obligations accidentally. Effective dates and version numbers should be identical across language versions unless a language-specific legal notice requires otherwise.

K. Security.txt

Publish /.well-known/security.txt only after https://urly.tr/security exists. Renew the Expires timestamp before it expires.

L. Operational evidence

Keep versioned copies of published policies and record effective dates so that the policy applicable at the time of an incident or request can be established.

M. Legal review boundary

This package is a comprehensive drafting and operational-policy set, not a substitute for advice from qualified Turkish counsel or specialist privacy/IP counsel. The most important legal-review points are KVKK data transfers, GDPR/UK international transfers, copyright/takedown obligations, consumer law, electronic communications, jurisdiction and retention.

Final Go-Live Checklist

Replace all [INSERT EFFECTIVE DATE] placeholders.

Set a future UTC Expires value in security.txt.

Publish /security before publishing security.txt.

Confirm actual cookie flags in production.

Replace ip-api.com with local GeoIP if that is the chosen architecture, then update the privacy/subprocessor notices. [COMPLETED: Local GeoIP implemented; ip-api.com removed; privacy notices updated].

Implement ip_geo_cache cleanup.

Implement creator_ip retention/cleanup.

Review referrer minimization.

Define support/API record retention.

Verify trusted-proxy IP handling.

Rotate previously exposed production-like secrets.

Verify SSRF protections against DNS rebinding and private-IP resolution.

Version the policies and retain prior published versions.

Perform Turkish localization after English legal approval.

Obtain qualified legal review before relying on the policies as contractual/legal notices.

Legal Notice & Contacts:
This document is issued by Firma Life under Turkish law. For official inquiries or data subject rights, please contact the designated department above.

Destek: support@urly.tr • Kötüye Kullanım: abuse@urly.tr • Hukuk & KVKK: legal@urly.tr • Güvenlik (RFC 9116): security@urly.tr
URLy

URLy.tr ist ein moderner Linkverkürzungsdienst mit detaillierten Analysen und 500px hochauflösenden QR-Codes.

Created by FirmaLife Creative

Schnellzugriff

  • Startseite
  • Wie es funktioniert
  • FAQ
  • Kontakt
  • Übersicht

Rechtliches & Sicherheit

  • Nutzungsbedingungen
  • Datenschutz & Cookies
  • Datenschutz (DSGVO / KVKK)
  • GDPR / EEA Compliance
  • Cookie Policy
  • 📜 26 Yasal Belge Merkezi

Trust & Safety

Report suspicious links, phishing, malware, or brand abuse.
  • 🛡️ Security Policy
  • 🚨 Report Abuse
  • 📩 support@urly.tr
  • 📄 RFC 9116 security.txt
🔒 256-Bit TLS & Çok Katmanlı Güvenlik
© 2026 URLy.tr — Alle Rechte vorbehalten.
Ein Projekt von FirmaLife Creative Initiative.