One cookie,
and it is your language.
There is no tracking cookie on this site. This page explains which cookie is written, why, how long it lasts and how to delete it.
Last updated: 27 August 2026
Quotations in this text are taken from the Constitution of the Republic of Türkiye — Law No. 2709, adopted 18/10/1982, Official Gazette: 9/11/1982 – 17863 (Repeated), as amended. The English wording is an unofficial translation; the Turkish original prevails.
What a cookie is, and how many are here
A cookie is a small piece of text a site leaves in your browser and can read back on later visits. Cookies can be used to recognise you, or merely to remember a preference.
This site sets exactly one cookie of its own, and it exists to remember the language you chose. Nothing here measures your visit, shows you advertising, or follows you across sites.
Everyone has the right to demand respect for their private and family life. The privacy of private and family life shall not be violated.
Cookies in use
The list below covers the whole site. It is kept by measurement rather than assumption — and the method was corrected on 28 August 2026: inspecting HTTP responses is not enough, because some cookies are written by a script running in the browser rather than by a server header. The list is now measured in a real browser, after the page has fully loaded.
- NHH_LOCALE
- Functional · 1 year · Written only when you pick a language in the language switcher, and carries nothing but the value "tr", "fr" or "en". It holds no identifying information.
- Cloudflare security cookies
- Strictly necessary · short-lived · Written by the bot protection. The cf_clearance cookie was measured in a real browser being written ON THE HOME PAGE — with no form filled in and nobody signed in; the verification component on the contact form may additionally write __cf_bm. They serve security and are not used for advertising.
- CF_Authorization
- Strictly necessary · administrators only · Written AFTER authentication succeeds for the /admin area. It does not appear for a visitor who never signs in — but CF_AppSession, below, does.
- CF_AppSession
- Strictly necessary · 24 hours · Written by Cloudflare Access on a request to /admin and used against session forgery (CSRF). It is created even without signing in — including when the address is reached by accident — which is why it is listed here.
Cookies we do not use
None of the following exist on this site. That is an architectural decision rather than an omission: no external advertising, measurement or social-media service is called.
For completeness, some technical requests do leave our domain, all of them to our infrastructure provider: the bot-verification component on the contact page (challenges.cloudflare.com) and the browser reporting network errors to the provider's collector. In addition, the provider's bot-detection script tries to load its own measurement component (static.cloudflareinsights.com); the site's content security policy BLOCKS that request, so no data reaches that address. None of them exists for tracking or advertising.
- Analytics and measurement cookies: visitor counters, session recording, heatmaps
- Advertising and retargeting cookies
- Social media sharing and tracking pixels
- Third-party content delivery network, font or map service cookies
- Scripts that fingerprint you for identification or marketing — security bot detection is excluded, see the note above
Browser storage that is not a cookie
Besides the cookie, the site keeps one more marker: so that the logo animation does not replay on every page, a flag named "nhh-logo-intro" is written to the browser's session storage.
This marker is never sent to the server, contains no personal data, and is erased when you close the tab. If reduced-motion is enabled on your device, the animation never plays at all.
Why there is no cookie banner
A consent banner is required for tracking and advertising cookies. As no such cookie exists here — and the remaining ones are either strictly necessary for the service or written by your own action, when you change the language — a banner asking for consent on every page would give you no real choice; it would only add another click.
If that changes, that is, if any measurement or advertising cookie is introduced, your explicit consent will be requested BEFORE those cookies are written and this page will be updated.
Managing and deleting cookies
You can delete or block cookies from your browser settings at any time. The path is similar in every browser: Settings → Privacy and security → Cookies and site data.
If you delete the language cookie, the site decides again from your browser's language preference; nothing else is lost. If you block Cloudflare's security cookies, the check on the contact form may not complete and your message may fail to send.
Updates to this text
If the cookies used on the site change, this list is updated and the date above is changed. If you find the list incomplete, tell us: every cookie you see in your browser should have an entry here.
A question about cookies?
Ask us in detail what any cookie does. If you spot a cookie that is not on this list, please tell us.
Write to Us →
