Fishing Equipment
Favorites
Spinning Rods Surf Casting Rods LRF Rods Jigging Rods Carp Rods Feeder Rods
Spinning Reels Surf Reels Baitcasting Reels Conventional Reels Electric Reels Carp Reels
Rods
Spinning Rods Surf Casting Rods LRF Rods Jigging Rods Carp Rods Feeder Rods
Reels
Spinning Reels Surf Reels Baitcasting Reels Conventional Reels Electric Reels Carp Reels
Home › Privacy policy

Privacy policy

This policy explains, in line with Article 13 of the General Data Protection Regulation (GDPR), which personal data is processed when the eu.avmal.com website is visited, for what purposes and on what legal basis.

Controller

The controller responsible for the processing of personal data on this website is:

Name or company name
AVMAL REKLAM PAZARLAMA VE TICARET
Legal form
A.S.
Email
[email protected]

Scope

The website has no user accounts, contact form or newsletter. No name, address or email address is requested during a visit. The sections below describe the data processed for technical reasons when the website is used, the purposes of the processing and how long the data is kept.

Hosting and access logs

With every request to the website, the web server and Cloudflare process the IP address, the date and time, the requested address (including any query parameters), the referring page and the browser user agent. These records are needed to operate the website, to find errors and to prevent attacks.

The website server is located in Türkiye. As the server is located outside the EU and EEA, hosting also involves a transfer to a third country. Web server access logs are deleted after 90 days.

Security records

Request counters are kept to tell apart access that sends many requests in a short time or shows signs of automated tools. The counters are linked to the IP address (for IPv6 addresses, the first 64 bits of the address). Each counter is deleted from the cache automatically a short time after its counting window ends, the longest window being 24 hours. Rate limits on search, filter and comparison features are also based on the IP address.

For requests that identify themselves as a search engine, a DNS lookup (reverse and forward) checks whether the IP address really belongs to that search engine. The result is kept in the cache linked to the IP address (for negative results on IPv6, the first 64 bits of the address). A positive result is deleted automatically after at most 24 hours and a negative result after at most 1 hour.

When a client exceeds a request limit, the application log records the IP address, the path of the requested page (without query parameters) and the name of the limit exceeded. If a search engine check fails with an error, the IP address and the host name returned by the DNS lookup are recorded, and if the verification lookups reach the per-minute ceiling, the IP address is recorded. For failed sign-in attempts to the administration panel, the email address entered and the IP address are also recorded. The application log is deleted after 14 days.

A client that sends many requests in a short time or repeatedly sends requests with scanning or attack patterns is shown a security check (Cloudflare Turnstile). Only in that case does the check page load the Cloudflare component from challenges.cloudflare.com. With this request the browser transmits the IP address and technical signals from the browser to Cloudflare. Our server also asks Cloudflare for the result of the check, together with the IP address. A browser that passes the check receives a pass cookie, and the request counters of that browser are then kept under the random identifier in the cookie instead of the IP address.

Cloudflare

The website uses Cloudflare, Inc. (United States) as content delivery and security provider. All requests to the website pass through Cloudflare. The IP address and request data may therefore be processed on Cloudflare servers outside the EU and EEA.

Cookies and browser storage

The website uses no analytics, advertising or tracking cookies. The cookies in use are required for the operation and security of the website or are set for the comparison feature when a visitor uses it.

Cookie Purpose Duration
avmal-session Session cookie, required for the website to work during a visit. 60 minutes
XSRF-TOKEN Protects form requests against forged requests sent from other websites. 60 minutes
avmal_pass Pass cookie for a browser that passed the security check. It holds a random identifier, an expiry time, a shortened hash of the browser user agent and a signature. It holds no IP address. It is set only after the check. 12 hours
product_compare_list Stores the products added to the comparison list. Set only when a product is added to the comparison. 30 days

The session record is kept on the server. Besides the session data it contains the address of the last page visited, the IP address and the browser user agent. After the session expires, the record is deleted by the server at regular intervals.

Cloudflare may set its own strictly necessary cookies for security checks and bot management (for example __cf_bm and cf_clearance).

The website's own scripts do not use the browser's local storage (localStorage, sessionStorage).

Search, comparison and product views

Text entered in the search box is kept in the cache for 30 minutes to build the address of the results page. Autocomplete results are kept in the cache together with the searched text for 5 minutes. These records are not linked to the visitor. Text typed for autocomplete is part of the requested address and therefore also appears, together with the IP address, in the access logs of the web server and Cloudflare.

When a comparison link is created, only the numbers of the selected products are kept on the server for 7 days.

Product page views are counted as totals per product, site, date and hour. No IP address, cookie or other visitor data is stored for this count. Visits from search engines and bots are not counted.

Third-party resources

Pages load the icon font (Font Awesome) from cdnjs.cloudflare.com. With this request the browser transmits the IP address to Cloudflare.

Contact by email

When the controller is contacted by email, the email address and the content of the message are processed only to answer the request. This data is deleted once the request has been dealt with, unless statutory retention obligations apply.

Legal bases

Access and security logs, the session and security cookies and the processing by Cloudflare are based on Art. 6(1)(f) GDPR. The legitimate interest is the secure and stable operation of the website. Storing the strictly necessary cookies in the browser is based on section 25(2) TDDDG. Emails are processed under Art. 6(1)(f) GDPR, requests to exercise data subject rights under Art. 6(1)(c) GDPR.

Loading the third-party resources (icon font and, where used, the content delivery network) is based on Art. 6(1)(f) GDPR. The legitimate interest is to display the pages completely with icons and images.

There is no obligation to provide personal data. Technical data such as the IP address has to be processed for the website to be delivered.

Recipients and transfers

Personal data is passed to the hosting provider, to Cloudflare and to the providers of the third-party resources named above, only for the purposes described in this policy. As Cloudflare is based in the United States, this includes a transfer to a third country. Public authorities receive data only where there is a legal obligation. Personal data is not sold and is not shared for advertising.

No profiling takes place and no automated decisions with legal or similarly significant effects are made.

Rights of data subjects

Under Articles 15 to 22 GDPR, data subjects have the following rights towards the controller:

  • Access to the personal data concerning them (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing based on Art. 6(1)(f), on grounds relating to their particular situation (Art. 21)
  • Not to be subject to a decision based solely on automated processing (Art. 22)

Requests can be sent to the controller at the email or postal address given above.

Data subjects also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of their habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR).

Fishing Equipment

Avmal compares 2,336 fishing rods and 1,495 fishing reels by their specifications, gathered from every brand in the range.

Rods

  • Fishing Rods
  • Spinning Rods
  • Surf Casting Rods
  • LRF Rods
  • Jigging Rods

Reels

  • Fishing Reels
  • Spinning Reels
  • Surf Reels
  • Conventional Reels
  • Baitcasting Reels
Legal notice Privacy policy

© 2026 avmal. All rights reserved.