Protection of Personal Data
Privacy Notice · In force from 22 August 2026
This notice is issued under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and concerns personal data processed through meetfestivalleri.com and in the course of Meet Datça Festival activities.
1. Who is the data controller?
Datça Ahi Women's Enterprise Production and Management Cooperative
- 0534 835 66 84
- [email protected]
- https://www.meetfestivalleri.com
The festival is co-organised with Karya Sağlıklı Yaşam ve Aktif Yaşlanma Derneği. Personal data collected on this site is held solely by the cooperative named above; application records and uploaded documents are not shared with the association.
2. What data do we process, why, and for how long?
The table below covers every category of personal data processed on the site and during festival activities. A category not listed here is not processed.
Representatives of applicant cooperatives and producers
- Data processed
- Organisation name, representative's name, phone, e-mail, product category, application message; where the application proceeds: tax office and number, national ID number for sole traders, and the image of the bank transfer receipt
- Purpose
- Assessing the application, contacting the applicant, forming the participation contract, collecting and invoicing the participation fee, and keeping records required by tax legislation
- Legal basis
- Art. 5/2-c (necessary for a contract), 5/2-ç (legal obligation — tax and cooperative legislation), 5/2-e (establishment and protection of a right)
- Retention
- Financial records and receipts: 10 years (statutory retention); rejected or lapsed applications: 1 year after the festival
Participants who open a showcase page
- Data processed
- Contact details the participant enters for publication on their showcase (WhatsApp/phone number, Instagram handle, website) and product images
- Purpose
- Presenting the participant on the festival site and enabling direct contact with visitors
- Legal basis
- Art. 5/1 (explicit consent — the participant enters the details for publication)
- Retention
- Until removed by the participant or until the festival archive is revised
Visitors who submit a photograph via “Share Your Moment”
- Data processed
- The uploaded photograph (including the images of people in it) and, optionally, the sender's name
- Purpose
- Publication in the festival archive gallery and in festival promotion
- Legal basis
- Art. 5/1 (explicit consent — no submission is accepted unless the publication consent box is ticked)
- Retention
- Until consent is withdrawn; unapproved uploads are deleted within 6 months of the festival at the latest
People photographed or filmed at the festival venue
- Data processed
- Photographs and video footage recorded at the festival venue
- Purpose
- Documenting the festival, press releases, the outcome report and social media promotion
- Legal basis
- For general crowd footage, Art. 5/2-f (legitimate interest — documenting a cultural event); for portraits where an individual is identifiable and prominent, explicit consent
- Retention
- For the lifetime of the festival archive; on objection the relevant image is removed from publication
Notification subscribers
- Data processed
- The push subscription endpoint and encryption keys generated by the browser — no name, e-mail or phone number is collected
- Purpose
- Delivering programme changes and festival announcements to the device
- Legal basis
- Art. 5/1 (explicit consent — notification permission is granted in the browser)
- Retention
- Until the subscription is cancelled or the endpoint becomes invalid
All site visitors
- Data processed
- IP address — held only in the server's volatile memory for at most 10 minutes to rate-limit form submissions; never written to the database or logged
- Purpose
- Preventing abuse of form and upload endpoints
- Legal basis
- Art. 5/2-f (legitimate interest — system security)
- Retention
- At most 10 minutes, in memory only; lost on server restart
3. How is the data collected?
Personal data is collected electronically, by partly automated means, when you complete a form on the site yourself (stand pre-application, receipt upload, showcase editing, moment sharing), when you grant notification permission in your browser, and when photographs or video are recorded at the festival venue.
4. Site measurement and surveys
Traffic and engagement measurement is carried out without processing personal data: no third-party analytics tool, including Google Analytics, is used. Only aggregate counters by day · page · country and day · event are stored; no IP address, cookie, session identifier or device fingerprint is recorded. Survey answers are likewise counted only as option totals with no individual response record — this data cannot be linked to any person.
For what is stored in your browser, see the Cookie Policy, itemised.
5. Transfer of personal data
As a rule your personal data is not transferred to third parties; it is never sold or shared for marketing purposes. The following limited cases are the exceptions:
- •To authorised public authorities, where prescribed by law and limited to the scope of the request (Art. 8/2-a).
- •To the cooperative's accountant and the tax office, for invoicing the participation fee and meeting statutory record-keeping obligations.
- •To the hosting provider, within the scope of technical hosting. The server and database are located in Türkiye; personal data is not transferred abroad.
- •Photographs published with consent are transferred to the festival's social media platforms (Instagram, Facebook, YouTube, X) when shared there. These platforms are established abroad and apply their own policies — publication consent therefore covers sharing on these channels as well.
6. Security measures we take
- •All site traffic is encrypted end to end (HTTPS).
- •Application records are accessible only through a password-protected admin panel, by a limited number of authorised people.
- •National ID numbers are never requested at the pre-application stage — they are collected only at the contract and invoicing stage, and only as far as necessary (data minimisation).
- •Uploaded photographs are re-encoded in the browser, so EXIF data carrying location and device information never reaches the server. Video upload is kept disabled because we cannot yet perform the same cleaning.
- •Receipt upload links are protected by unguessable per-person keys and open only for the relevant application.
- •The database is backed up regularly; backups are kept in a directory accessible only to the server administrator and those older than seven days are deleted automatically.
7. Your rights under Article 11
By applying to the data controller you may exercise the following rights:
- •To learn whether your personal data is being processed
- •To request information if it has been processed
- •To learn the purpose of processing and whether the data is used accordingly
- •To know the third parties to whom the data has been transferred, at home or abroad
- •To request rectification of incomplete or inaccurate data
- •To request erasure or destruction under the conditions in Article 7
- •To request that such actions be notified to third parties to whom the data was transferred
- •To object to an adverse outcome arising solely from automated analysis
- •To claim compensation for damage arising from unlawful processing
8. How to exercise your rights
You may submit these requests in writing, or by registered electronic mail, secure electronic signature, mobile signature, or from an e-mail address you have previously notified to the cooperative and which is registered in our records, in line with the Communiqué on the Procedures and Principles of Application to the Data Controller.
Your application must state your name, signature (for written applications), national ID or passport number, address for service, telephone and e-mail if any, and the subject of your request. It will be concluded as soon as possible and within thirty days at the latest, free of charge; where the process incurs an additional cost, the fee set out in the Board's tariff may be charged.
If your application is rejected, the response is found insufficient, or no reply is given in time, you may lodge a complaint with the Personal Data Protection Board within thirty days of learning of the response and in any case within sixty days of the application date.
Where to send your application
- [email protected]
- 0534 835 66 84
If you want a photograph removed from publication, including the address of the page it appears on speeds up the process — your request is reviewed and concluded regardless.
