Data Processing Agreement
Last updated: 05.09.2026
This agreement sets out the terms of the controller–processor relationship established under Turkish Personal Data Protection Law no. 6698 (KVKK) between an organisation publishing events on the QuickEvent platform and the platform operator. It forms an integral annex to the Terms of Service. NOTE: The Turkish text is the authoritative version; this English translation is provided for convenience only and does not prevail in case of conflict.
1. Parties and allocation of roles
CONTROLLER: the organisation that creates and publishes an event on the platform (the “Organiser”). The Organiser decides what the registration form collects, who is approved to attend and how the event is run. Because those decisions determine the purposes and means of processing, the Organiser is the data controller for event data under the Law.
PROCESSOR: NCU GLOBAL TEKNOLOJİLER BİLİŞİM A.Ş. · Armada İş Merkezi, Beştepe Mahallesi Dumlupınar Bulvarı No: 6/1 İç Kapı No: 18, Yenimahalle/Ankara, Türkiye · Tax/MERSIS no: 0630145269300001 · E-mail: info@ncuglobaltech.com
The platform operator processes event data only on the Organiser’s instructions and within this agreement; it does not determine the purposes of processing.
BOUNDARY OF THE ROLE: the platform operator is itself the CONTROLLER for the account data of the Organiser’s administrators (identity and contact details, sign-in and security records, billing data, marketing preferences). That data is governed by the platform’s own privacy notice, not by this agreement. The same applies to a participant’s platform account outside any event (profile, sign-in records).
2. Subject matter, duration, nature and purpose
PURPOSE: running the Organiser’s event — collecting and assessing registrations, planning accommodation and transport logistics, managing the programme and sessions, access control and badging, participant communication and post-event evaluation.
NATURE: collection, recording, storage, alteration, reorganisation, transfer and erasure by wholly or partly automated means in electronic form.
DURATION: for as long as the Organiser’s subscription continues; on termination, clause 11 applies.
Data categories and categories of data subjects are listed in Annex B.
3. Obligations of the processor
a) Processes personal data only on the Organiser’s documented instructions. Instructions given through the platform interface and configuration settings count as documented instructions.
b) Informs the Organiser in writing before carrying out an instruction it considers to be in breach of applicable law.
c) Ensures personnel with access to personal data are bound by confidentiality and limits access to what the role requires.
d) Does not use the data for its own purposes, does not sell it to third parties and does not make it available within another organisation’s event.
e) Maintains records of processing activities and makes them available on request.
4. Security measures
The processor implements technical and organisational measures appropriate to the risk, as required by Article 12 of the Law. Measures include at a minimum: encryption in transit and at rest, application-layer AES-256-GCM encryption with key rotation for sensitive and directly identifying fields, role-based access control, per-organisation data separation in the multi-tenant architecture, audit logging of sessions and administrative actions, rate limiting and bot protection, and regular backups.
Measures may be updated in line with technological developments and risk assessment, provided the level of protection is NOT reduced.
5. Breach notification
The processor notifies the Organiser WITHOUT UNDUE DELAY and in any event within 24 HOURS of becoming aware of a personal data breach. This period is contractual and is set so the Organiser can meet its own notification deadline to the Board.
The notification describes the nature of the breach, the categories of data subjects and data affected, the likely consequences and the measures taken or proposed. Where the information cannot be provided at once, it is supplied in phases without undue delay.
The duty to notify the Board and the data subjects rests with the CONTROLLER; the processor provides reasonable assistance in preparing those notifications.
6. Sub-processors
By entering into this agreement the Organiser gives general authorisation for the sub-processors listed in Annex A.
The processor informs the Organiser AT LEAST 30 DAYS before adding a new sub-processor or replacing an existing one. The Organiser may object on reasonable grounds within that period; if the objection cannot be resolved, the Organiser may terminate without penalty.
The processor imposes obligations equivalent to those in this agreement on its sub-processors and remains liable to the Organiser for their acts as for its own.
7. Assistance with data subject requests
If a data subject approaches the processor directly, the processor does not answer the request; it forwards it to the Organiser without undue delay and informs the applicant.
The processor provides the technical means for the rights under Article 11 to be satisfied: export, rectification, erasure or anonymisation of data and notification to parties the data was transferred to.
So the thirty-day period under Article 13 can be met, the processor responds to the Organiser’s written request within five business days.
8. International transfers
As shown in Annex A, some sub-processors are established outside Türkiye and personal data is therefore transferred abroad.
The Personal Data Protection Board has to date issued NO adequacy decision for any country. Transfers are accordingly carried out on the basis of appropriate safeguards under Article 9 — the standard contract published by the Board — or the derogations set out in the Law.
Where a standard contract is signed, it is notified to the Board within five business days. The duty to notify falls on the party making the transfer on its own behalf.
The Organiser may request a copy of the safeguards applied to transfers abroad.
9. Audit and information
The processor provides the information necessary to demonstrate compliance with this agreement.
The Organiser may audit, or appoint an independent auditor, no more than once a year and on at least thirty days’ written notice. These limits do not apply where a breach has occurred.
Audits are conducted so as not to give access to other organisations’ data or to compromise the security of the platform.
10. Obligations of the controller
The Organiser is responsible for the lawfulness of the data it collects through its registration forms: that a legal basis exists (explicit consent or another ground in the Law), that the conditions of Article 6 are met where sensitive data is collected, and that the data is relevant, limited and proportionate to the purpose.
The Organiser discharges its own INFORMATION obligation under Article 10 towards its participants. The notice provided by the platform covers the platform’s own processing and does not discharge the Organiser’s obligation.
The Organiser completes its own VERBİS registration where it is subject to it.
The Organiser ensures its instructions to the platform comply with applicable law.
11. Termination — return and erasure
On termination of the subscription the Organiser has thirty days to export its data.
At the end of that period the processor returns or erases the data at the Organiser’s choice. If no choice is communicated, the data is ERASED.
Copies held in backups are destroyed as their retention window expires, within no more than ninety days. Records subject to a statutory retention obligation are excepted and are kept only within the scope of that obligation.
Erasure is confirmed in writing on request.
12. Liability
Under Article 12(2) of the Law, the controller and the processor are JOINTLY liable for compliance with data security obligations.
A party held liable for an administrative fine or damages caused by the other party’s breach of this agreement may recover from the party at fault.
13. Duration, amendment and governing law
This agreement takes effect when the Organiser creates its platform account and ends with the subscription. Clauses 11 and 12 survive termination.
Material changes are notified at least thirty days in advance. If the Organiser does not accept them it may terminate without penalty.
This agreement is governed by Turkish law. The courts and execution offices of Ankara have jurisdiction.
Annex A — Sub-processors
The following parties access personal data to the extent necessary to provide the service:
Microsoft Azure (App Service, PostgreSQL, Blob Storage) — Application and database hosting, storage of uploaded files. Server location: West Europe (Netherlands).
Microsoft Azure Communication Services — Delivery of transactional e-mail (recipient address, subject and body). Server location: European Union.
Google Firebase Cloud Messaging — Mobile push notification delivery (device token, notification title and body). Server location: United States.
Cloudflare Turnstile — Bot protection — verification token and client IP address. Server location: United States.
Stripe — Subscription and payment infrastructure — ORGANISATION-level billing data only; participant data is not transferred to Stripe. Server location: United States.
Changes to this list follow the notice procedure in clause 6.
Annex B — Data categories and categories of data subjects
CATEGORIES OF DATA SUBJECTS: participants registering for the event, speakers and moderators, delegation points of contact (POC), accompanying persons and administrators authorised by the Organiser.
IDENTITY AND CONTACT DATA: name, surname, e-mail address, phone number, date and place of birth, nationality, passport and identity document details.
PROFESSIONAL DATA: organisation, job title, rank, biography, profile photograph.
EVENT PARTICIPATION DATA: registration form answers, flight and transfer details, accommodation preferences, dietary and accessibility requests, programme and session selections, check-in records.
COMMUNICATION CONTENT: messages and files exchanged between participants, session questions and answers, feedback and evaluation responses.
TRANSACTION SECURITY DATA: sign-in records, IP address, device token, audit logs.
SENSITIVE DATA: a dietary preference may imply health or belief information and an accessibility request may constitute health data. Where the Organiser uses these fields it is responsible for meeting the conditions in Article 6 of the Law.