LEGAL
Privacy Policy
Last updated 30 July 2026
Who we are
Cotesty is a product operated by Codeativ ("we", "us", "our"). Codeativ is the data controller for the personal data described here. For any question about this policy, or to exercise a right below, write to [email protected].
What we collect, and what we do not
We collect the least the service can work with:
- The URL you submit when you request a report or join the waitlist.
- The page you submitted it from, so we know which entry point you used.
- Your email address, only if you choose to enter it. The waitlist email field is optional; leave it blank and we never receive it.
- Ordinary request metadata that your browser sends to any site it loads: your IP address, user-agent and the time of the request. Our hosting provider processes this to deliver the page and keep the service secure.
We do not ask for your name, we set no cookies, and we run no analytics, advertising, fingerprinting or session-replay. See the Cookie Policy.
Why we process it, and on what basis
- To produce the report you asked for and to run the waitlist before launch. Basis: steps taken at your request and performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5/2-c).
- To keep the service secure and prevent abuse. Basis: our legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5/2-f).
- To email you about your report or waitlist place, where you gave your address. Basis: your consent, which you may withdraw at any time.
Who else processes it
We keep the chain of processors short:
- Cloudflare, Inc. hosts the site and runs the serverless function and storage behind the waitlist, as our processor.
- Our report API at api.cotesty.com receives a submitted URL when you request a report, so the report can be produced.
We do not sell personal data and we do not share it with advertisers.
International transfers
Our processors operate globally, so your data may be processed on servers outside your country, including outside Türkiye and the EEA. Where that happens we rely on the safeguards the provider offers, such as standard contractual clauses.
How long we keep it
Waitlist entries are kept until the service opens or until you ask to be removed, whichever comes first, then deleted. A URL submitted for a report is kept only as long as needed to produce and deliver that report. Security and server logs are kept briefly and then rotated out.
Your rights
Under the GDPR you may request access, correction, erasure, restriction, objection and portability, and you may complain to your supervisory authority. Under the Turkish KVKK (Art. 11) you have equivalent rights, including to learn whether your data is processed and to request its correction or deletion. To exercise any of these, email [email protected]. See also our data-processing and KVKK notice.
Changes
If we change this policy we update the date at the top of this page, and make material changes clear on the site.