Data Protection Notice (KVKK)
Last updated: 2026-08-26
This notice is provided under Article 10 of Turkish Law no. 6698 on the Protection of Personal Data (KVKK). It explains who processes your personal data, for what purposes, on what legal basis, and what rights you have. This is not a consent form — it is given to you for information and does not depend on your approval. Where your explicit consent is required, it is stated below and is always requested separately. NOTE: The Turkish text is the authoritative version; this English translation is provided for convenience only and prevails in no case of conflict.
1. Who the data controller is
QuickEvent is a multi-tenant event management platform, and the distinction of roles matters: when you register for an event, the ORGANISING ORGANISATION decides what is collected and why. That organisation is the data controller; QuickEvent acts as data processor on its instructions. Event-specific questions should be addressed to the organiser first.
For your platform account data (profile, sign-in records, security logs and marketing preferences), the platform operator is the data controller.
Data controller contact: The operator’s registered name, address and tax number are not configured in this deployment. Please use the e-mail address below to request them.
For requests: support@quickevent.org
2. What personal data is processed
Identity and contact data: name, surname, e-mail address, phone number, date and place of birth, nationality, gender, marital status, identity/passport number.
Professional data: organisation, position, title, rank, security clearance level where applicable, biography and profile photograph.
Event participation data: registration form answers, flight and transfer details, accommodation records, session attendance, check-in records, survey and feedback answers, messages sent through the platform and files you upload.
Transaction security data: IP address, browser and device information, sign-in times, audit records, error logs, mobile notification device identifier.
Marketing and segmentation data (optional): profession, industry, organisation size, the type and number of events you run, how you heard about the platform, and your marketing preference. Every one of these can be left blank and the whole step can be skipped without losing access to anything.
3. Purposes of processing
Taking your registration, assessing your application and running the approval process.
Planning event logistics: accommodation, airport and local transfers, catering and dietary arrangements, session and programme management, badges and check-in.
Communicating with you about the event: information e-mails, reminders, programme changes and mobile notifications.
Creating and securing your platform account, preventing unauthorised access and monitoring transaction security.
Improving the service and understanding which kinds of organisation benefit from the platform. Sending you product news and event tips only where you have given explicit consent.
Meeting legal obligations, responding to requests from competent authorities, and establishing or defending legal claims.
4. Legal bases
Article 5/2(c) — directly related to the conclusion or performance of a contract: taking and processing your registration and providing event services.
Article 5/2(ç) — compliance with a legal obligation of the data controller.
Article 5/2(f) — legitimate interests of the data controller, provided this does not harm your fundamental rights and freedoms: platform and account security, abuse prevention, audit logging and service improvement.
Article 5/2(e) — processing necessary for the establishment, exercise or protection of a right.
Explicit consent (Article 5/1): marketing messages, use of your image in event photography and video, sharing your contact details with other participants, and publishing your biography rely solely on your explicit consent. Withholding consent does not affect your participation, and you may withdraw it at any time.
5. Special categories of personal data
You may be asked for your dietary preference and food allergies. This may qualify as health data under Article 6 of the Law and is processed SOLELY ON YOUR EXPLICIT CONSENT and solely to make catering arrangements. You are not required to complete these fields; leaving them blank does not invalidate your registration.
This data is visible only to the staff responsible for the arrangement and is erased or anonymised once the purpose ends after the event.
Security clearance level, passport and identity numbers are processed only where the accreditation process of the specific event requires it and on the instruction of the organising body.
6. How data is collected
Your data is collected by automated and partly automated means in electronic form: directly from you when you complete the registration form, create an account, use the mobile application, send messages or upload files; and from the organisation that invites you or registers you on your behalf (for example through your delegation coordinator).
Check-in records are created by scanning a QR code or barcode, or by an operator marking attendance manually.
7. Recipients
The organising body and the administrators it authorises, for assessing your registration and running the event.
Accommodation and transport providers (hotels and transfer providers), limited to the information needed for the booking or transfer.
IT service providers, for hosting and file storage, e-mail delivery, mobile notifications, bot protection and payment infrastructure.
Competent public authorities, within the scope of statutory information requests.
Your contact details and biography are shown to other participants ONLY where you have given explicit consent. Without consent these fields are closed to other participants.
8. International transfers
The platform’s hosting infrastructure and some service providers are located outside Türkiye. Your personal data may therefore be processed on servers of providers established in the European Union and the United States: application and database hosting and file storage (Microsoft Azure, West Europe region), e-mail delivery (Microsoft Azure Communication Services), mobile notifications (Google Firebase Cloud Messaging), bot protection (Cloudflare) and payment infrastructure (Stripe).
These transfers are carried out under Article 9 of the Law. As the Turkish Personal Data Protection Board has to date issued no adequacy decision for any country, transfers rely on appropriate safeguards (the standard contract published by the Board) or on the exceptions set out in the Law.
You have the right to request a copy of the safeguards applied to international transfers, using the procedure below.
9. Retention periods
Your registration and related logistics records are kept after the event and after the related obligations are complete, for the limitation periods set out in applicable legislation, and are then erased, destroyed or anonymised.
Security event records are kept for 730 days, audit records for 365 days, system health records for 90 days, sent-email records for 180 days, notifications for 90 days and screenshots attached to feedback for 90 days.
Your platform account remains open until you delete it. On deletion your profile data is erased or anonymised; records the organising body must retain under its own obligations remain subject to that body’s retention policy.
10. Your rights under Article 11 of the Law
By applying to the data controller you may exercise the following rights:
(a) to learn whether your personal data is processed;
(b) to request information if it has been processed;
(c) to learn the purpose of processing and whether the data is used in line with that purpose;
(ç) to know the third parties in Türkiye or abroad to whom the data is transferred;
(d) to request correction where the data is incomplete or inaccurate;
(e) to request erasure or destruction under the conditions of Article 7 of the Law;
(f) to request that operations under (d) and (e) be notified to the third parties the data was transferred to;
(g) to object to a result against you produced solely by automated analysis of the data;
(ğ) to claim compensation for damage arising from unlawful processing.
11. How to exercise your rights
You may submit your request, together with information establishing your identity, in writing to the data controller’s address, to its registered electronic mail (KEP) address, using a secure electronic signature or mobile signature, or from the e-mail address you have previously notified to us and which is registered in our systems.
Electronic application address: support@quickevent.org
Your request will be concluded as soon as possible and in any case within THIRTY DAYS. Where the process incurs a cost, a fee from the tariff set by the Board may be charged.
If your request is refused, you find our response insufficient, or no response is given in time, you may lodge a complaint with the Personal Data Protection Board within thirty days of learning the response and in any case within sixty days of your application.
12. When you enter someone else’s details
The registration form may ask for details of third parties such as accompanying persons, family members or emergency contacts. It is your responsibility to inform that person and, where necessary, obtain their consent before sharing their details.
Their data is used only to arrange event logistics and to make contact in an emergency, and they hold all of the rights listed under Article 11.
13. Security measures
Sensitive personal data fields are stored encrypted with AES-256-GCM, and the encryption keys are configured so they can be rotated.
Access is limited by role-based authorisation and administrator actions are written to an audit log. Session management, multi-factor authentication infrastructure, rate limiting and bot protection are applied.
Separation of data between organisations (tenant isolation) is enforced at application level; an administrator of one organisation cannot reach another organisation’s participant data.
14. Changes to this notice
This notice is updated as our processing activities change. The date of the current version appears at the top. You will be informed separately of material changes.