Cookie Policy
& Cookie Inventory.
This page explains how Atabaş Group uses cookies and similar technologies on its website. In addition, it provides a structured cookie inventory prepared according to the website stack currently used by the site, including WordPress, Cloudflare, Wordfence, Google Site Kit and related services.
Some cookies appear only under specific conditions. For example, certain cookies are set only when a user logs in, when a security challenge is triggered, when analytics consent is granted, or when administrative functions are used.
Accordingly, the inventory below distinguishes between cookies that are generally expected on the public website and cookies that may appear only in restricted or conditional contexts.
Cookies support security, continuity and measurement.
Cookies are small text files that websites place on a visitor’s device. They help websites remember preferences, maintain secure sessions, improve performance and understand how users interact with pages.
Atabaş Group uses cookies only for legitimate website related purposes, including security, session continuity, consent management, traffic analysis and performance improvement. Where the law requires consent, non essential cookies activate only after the user has given a valid preference.
The website may use the following cookie categories.
Essential and Security Cookies
- Required for core website functionality
- Used for session continuity and preference storage
- Help protect the website against suspicious or abusive traffic
- Do not require opt in where they are strictly necessary
Analytics and Functional Cookies
- Help us understand how visitors interact with the website
- Support usability and performance improvements
- May remember certain user choices or interface settings
- Require consent where the applicable law requires consent
Public website cookies and condition based cookies.
The inventory below has been prepared according to the website stack currently associated with the site. Cookie names that contain dynamic values may appear with changing suffixes or identifiers. Durations may also vary depending on service configuration.
| Cookie Name | Provider | Category | Purpose | Typical Duration | Legal Basis |
|---|---|---|---|---|---|
| cookieyes-consent or equivalent consent cookie | Consent platform | Essential | Stores the user’s cookie consent preferences | 6 months to 1 year | Legal obligation and compliance documentation |
| wordpress_test_cookie | WordPress | Essential | Checks whether the browser accepts cookies | Session | Legitimate interest for website functionality |
| wordpress_logged_in_[hash] | WordPress | Essential | Maintains login session for authenticated users | Session or persistent for logged in users | Contract and legitimate interest |
| wordpress_sec_[hash] | WordPress | Essential | Provides secure authentication for logged in users | Session | Security and legitimate interest |
| wp-settings-[user_id] | WordPress | Functional | Saves user interface preferences in the admin area | 1 year | Legitimate interest |
| wp-settings-time-[user_id] | WordPress | Functional | Stores the time at which admin settings were set | 1 year | Legitimate interest |
| wp_lang | WordPress | Functional | Stores selected language in certain WordPress contexts | Session | Legitimate interest |
| __cf_bm | Cloudflare | Security | Helps Cloudflare identify and mitigate automated traffic | Usually 30 minutes | Legitimate interest for security |
| cf_clearance | Cloudflare | Security | Stores proof that a user has passed a security challenge | Variable | Legitimate interest for security |
| _cfuvid | Cloudflare | Security | Supports rate limiting and trusted traffic identification | Session | Legitimate interest for security |
| wfwaf-authcookie-[hash] | Wordfence | Security | Enables the Wordfence firewall to identify trusted logged in users | Session | Legitimate interest for security |
| wf_loginalerted_[hash] | Wordfence | Security | Helps avoid repeated login alert notifications | Persistent | Legitimate interest for security |
| wfCBLBypass | Wordfence | Security | Allows a visitor to bypass country or access related blocks after validation in limited cases | Variable | Legitimate interest for security |
| wordfence_verifiedHuman | Wordfence | Security | May be used to verify that a visitor passed a human verification step | Variable | Legitimate interest for security |
| _ga | Google Analytics via Site Kit | Analytics | Distinguishes users for analytics measurement | Typically 2 years | Consent where required |
| _ga_[container_id] | Google Analytics via Site Kit | Analytics | Maintains session and state in Google Analytics 4 | Typically up to 2 years | Consent where required |
| _gid | Google Analytics via Site Kit | Analytics | Distinguishes users on a shorter interval | 24 hours | Consent where required |
| _gat or related throttling cookie | Google Analytics via Site Kit | Analytics | Controls request rate in some analytics implementations | 1 minute | Consent where required |
| Yoast SEO frontend cookies | Yoast SEO | Not generally set | No standard frontend tracking cookie is generally set by Yoast SEO for ordinary visitors | Not applicable | Not applicable |
| Redis Object Cache frontend cookies | Redis | Not generally set | Redis object caching generally operates server side and does not usually place visitor cookies | Not applicable | Not applicable |
| Imagify frontend cookies | Imagify | Not generally set | Imagify generally optimizes images server side and does not usually place standard visitor cookies | Not applicable | Not applicable |
Cookies listed as “not generally set” are included for transparency because the related services are part of the site stack. However, these services do not usually place a standard frontend cookie for ordinary visitors.
Likewise, some WordPress and Wordfence cookies appear only for authenticated users or specific security events. Accordingly, their inclusion strengthens the legal completeness of this page.
Cookies are used for limited and legitimate website purposes.
Why the website uses cookies
- To keep the website secure and operational
- To maintain sessions and remember essential preferences
- To protect the website against abuse and malicious traffic
- To understand aggregate user interaction when analytics are enabled
What Atabaş Group does not use cookies for
- We do not knowingly use cookies to collect sensitive personal data
- We do not rely on non essential cookies without a lawful basis
- We do not state that every listed cookie is always active for every visitor
- We do not treat analytics cookies as essential where consent is legally required
GDPR and KVKK framework.
Atabaş Group processes cookie related data in accordance with the General Data Protection Regulation and the Turkish Personal Data Protection Law, KVKK. Essential and security cookies are used on the basis of legitimate interest and website functionality where appropriate. Analytics and similar non essential cookies are used only on the basis of consent where the law requires consent.
In addition, Atabaş Group applies the principles of proportionality, data minimization, purpose limitation and transparency when managing cookie related processing.
Users can manage cookies through browser settings and consent tools.
Visitors can review or change cookie preferences through the cookie banner or consent tool used on the website, where available. In addition, most browsers allow users to view, delete or block cookies. However, disabling essential cookies may affect the correct operation of parts of the website.
Key points explained clearly.
Does every visitor receive every cookie listed on this page?
No. Some cookies apply only in specific situations, such as login, security validation, analytics consent or administrative access. The inventory is intentionally broad so the page remains legally complete and transparent.
Why are WordPress admin cookies listed on a public cookie page?
They are listed because they are part of the same website environment and may appear when authorized users access restricted areas. Including them strengthens disclosure and reduces ambiguity.
Are Google Analytics cookies essential?
No. Analytics cookies are not treated as essential. Where applicable law requires consent, these cookies should activate only after the visitor gives a valid analytics preference.
Do Redis, Yoast SEO and Imagify set visitor cookies?
In standard implementations they usually do not set ordinary frontend visitor cookies. They are still referenced here because they are part of the website stack and transparency benefits from acknowledging them.
Can this inventory be updated later?
Yes. Cookie inventories should be reviewed whenever plugins, analytics settings, consent tools, CDN settings or security services change. This page is designed to be updated as the technical stack evolves.

