Privacy and KVKK
Privacy Notice on the Processing of Personal Data
This notice explains how personal data is processed through the ITS Istanbul 2026 website and visitor registration process. It also provides the relevant GDPR information where the GDPR applies.
Last updated:
1. What does this notice cover?
This notice covers use of the website, visitor registration, email verification, preparation of badges and QR codes, the public visitor profile required for event access, event entry records, service messages, security logs and, where permission is given, analytics.
2. What personal data do we process?
We process only data that is required for the processes below and is supplied directly by you or generated when you use the website.
- Identity and contact data: first name, last name, email address and telephone number.
- Attendance and professional data: country, spoken language, gender preference, organisation or company, job title and optional note.
- Verification and access data: verification status, profile address, the OTP hash and expiry stored while a registration is pending, and the hashed private edit-link secret. The raw OTP is never stored, remains valid for 20 minutes and its hash and expiry are cleared after successful verification.
- Event entry data: turnstile entry count and the time of the latest entry.
- Technical and security data: page or route used, request method, status code, timestamp and application error records. Infrastructure providers may also process connection information such as IP addresses for network security.
- Cookie and analytics choice stored locally in your browser.
3. Purposes and legal grounds
Data is processed only as necessary for each purpose under an applicable condition in Article 5 of Turkish Law No. 6698 and, where the GDPR applies, an appropriate legal basis under Article 6 GDPR. Permission-based analytics takes place only while your cookie choice is active.
- Receiving and verifying registration, enabling event access, and sending service messages necessary for the requested registration.
- Preparing badges and QR codes, running event operations, and recording turnstile entries for security and capacity management.
- Operating the system securely, preventing misuse, resolving errors and complying with legal obligations.
- Creating and keeping the public visitor profile available so that registration, the badge QR code and turnstile entry can work.
- Measuring website use with optional analytics cookies where you give separate permission.
4. Notice acknowledgement and public profile
The public registration form cannot be accepted unless you give the required confirmation that you have read and understood this privacy notice. No separate privacy-notice acknowledgement field, notice version or acknowledgement timestamp is stored; successful creation through the public registration form shows that this required validation passed. This confirmation is not consent.
A public profile is created at /p/{slug} for every verified visitor registration. Your first and last name, organisation, title, country, spoken language, gender, email address, telephone number and any note supplied on the form are published in this profile. It opens from the badge QR code and can be viewed, shared or copied by anyone with the link and by internet or social-media crawlers.
The public profile is a required part of the registration service used by the badge QR code and turnstile entry. Disabling the profile prevents event entry from working. You may send requests concerning the removal of your registration or profile to info@tuyafed.org.
5. Who receives the data?
Data may be shared, only as necessary for its purpose, with authorised TÜYAFED and event teams; hosting and database providers; Resend for email delivery; UserCheck, which receives only the email domain for temporary-email screening; the analytics service provider, Google, where permission is given; service providers responsible for event security and turnstile operations; and legally authorised public bodies.
Once registration is verified, the published profile information is disclosed to everyone who accesses the link. Some technology providers may operate outside Türkiye or your country. Any such transfer is carried out under the applicable transfer conditions and safeguards in Article 9 KVKK and, where applicable, the GDPR.
6. How long is data retained?
Personal data is retained only for as long as necessary for the purposes above, event operations, applicable legal obligations and potential legal claims; it is then erased, destroyed or anonymised. OTPs remain valid for 20 minutes. Application error logs older than 90 days are removed during the next logging cycle. The cookie and analytics choice may be retained until it is changed, expires or its purpose ends.
7. Your rights
Under Article 11 KVKK, you may ask whether your data is processed; request information; learn the purpose and whether data is used for that purpose; learn the recipients in Türkiye or abroad; request correction and, where the conditions apply, erasure or destruction; request notification of those measures to recipients; object to an outcome produced solely through automated systems; and claim compensation for damage caused by unlawful processing.
Where the GDPR applies, you may also have rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and complaint to a competent supervisory authority. You may send a request with information sufficient to verify your identity to info@tuyafed.org.
8. Security and updates to this notice
Access restrictions, hashed storage of verification and private-access secrets, security records and appropriate technical and organisational measures are used to protect data. This notice may be updated when the service or applicable law changes; the current version is published on this page with its effective date.
