Privacy Policy and KVKK Information Notice
Last updated: 10 September 2026
This English translation is provided for convenience only. The Turkish version is the legally binding text.
1. Data controller and our role
Under the Kişisel Verilerin Korunması Kanunu No. 6698 (Turkish Personal Data Protection Law, "KVKK"), your personal data may be processed by Etkin.app as data controller within the scope described below.
Etkin.app is a multi-tenant platform; therefore our role changes depending on whose data it is. The distinction below is important because it determines against whom you exercise your rights:
Account holders — Etkin is the data controller
For users who open an account on the platform and for organization officers, Etkin determines and processes the data. Your requests regarding this data are submitted directly to us.
Attendees — the organization is the data controller
When you register for an event, the organization running the event decides which data will be collected and why it will be processed. Etkin processes this data only to provide the service, in its capacity as data processor. You need to submit your request primarily to the relevant organization; we will also help you by directing you.
Contact details:
- 📧 Email: info@etkin.app
- 🌐 Web: etkin.app
2. Personal data processed
Which data is processed depends on how you use the platform. As an attendee, only the fields in the registration form are processed; as an organization officer, account and billing data are processed as well.
Identity and account
- • First and last name
- • Age / year of birth, gender
- • Account and session information (sign-in method, passkey registration)
- • Your role within the organization
Contact and location
- • Email address
- • Phone number
- • City / district
- • Your communication permissions (consent/refusal record)
Education and profile
- • Student status
- • School / university (optional)
- • Additional fields the organization adds to its registration form
Technical and security
- • IP address, browser and device information
- • Device fingerprint and entry time during QR scanning
- • System, security and error logs
- • Cookie and analytics data
Other data depending on use
- • Event and attendance: your registration record, approval status, check-in time, seat/hall assignment, your survey responses, certificate records.
- • Sending records: the sending/delivery status of SMS, email, WhatsApp and push notifications sent to you.
- • Payment and billing: billing information and transaction records in paid plan or ticketed event transactions. Card details are not seen or stored by Etkin; they are held by the payment institution.
- • Support correspondence: the content of requests, complaints and in-app messages you send us.
Etkin does not envisage collecting special categories of personal data such as health data, biometric data, religion or political opinion. Organizations must not add such fields to their registration forms; if they do, the responsibility lies with the organization concerned.
3. Purposes of processing
Your personal data is processed for the following purposes:
- ✓Creating your account, authentication and ensuring session security
- ✓Carrying out event registration, approval and attendance processes
- ✓Verifying event entries through QR code generation and preventing duplicate entries
- ✓Sending information, reminders and announcements about the event (SMS, email, WhatsApp, push)
- ✓Conducting attendee satisfaction surveys and generating attendance certificates and making them verifiable
- ✓Planning seating, hall and transport arrangements
- ✓Carrying out subscription, payment, invoicing and accounting processes
- ✓Responding to support requests and carrying out communication
- ✓Ensuring the security of the service and preventing abuse and fraud
- ✓Statistical analysis, reporting and improvement of the service
- ✓Fulfilling legal obligations and responding to requests from competent authorities
4. Legal grounds
Your data is processed based on the conditions listed in Articles 5 and 8 of the KVKK. The legal grounds we rely on, by purpose, are as follows:
| Processing | Legal ground (KVKK Art. 5) |
|---|---|
| Account opening, subscription and event registration | Necessary for the conclusion and performance of a contract (Art. 5/2-c) |
| Invoices, accounting and statutory records | Compliance with a legal obligation (Art. 5/2-ç) |
| Security logs, prevention of abuse | Legitimate interest (Art. 5/2-f) |
| Commercial electronic messages (announcements/marketing) | Explicit consent and approval under Law No. 6563 |
| Analytics cookies | Explicit consent (your choice in the cookie notice) |
| Transfer of data to the AI assistant you connect (MCP) | Explicit consent (the authorization you grant on the consent screen during connection) — Art. 5/1 and Art. 9 |
| Establishment, exercise or protection of a right | Art. 5/2-e |
For processing based on explicit consent, you may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out up to that point.
5. Transfers and service providers
Your data is not sold and is not shared with third parties for marketing purposes. It is shared only with the following parties that are necessary for providing the service, to the extent necessary:
- • The organization running the event: the organization that owns the event you registered for accesses your registration and attendance data through its own panel.
- • Hosting: data is hosted on servers under Etkin’s own control; it is not opened to third-party event platforms.
- • Payment: PayTR (payment and refund transactions, fraud prevention). Card details are held only by the payment institution.
- • Message sending: SMS providers, email (SMTP) providers and Meta infrastructure for WhatsApp business messaging. If the organization has connected its own provider account, sending is done directly through that account.
- • Measurement: PostHog and Cloudflare Web Analytics — only if you have given cookie consent (Cloudflare measurement is cookieless).
- • Infrastructure and security: Cloudflare (CDN, bot and attack filtering).
- • The AI assistant you connect: only if you connect an assistant to your account of your own accord. For details, see 5.1.
- • Competent authorities: where required by legislation, to the extent requested.
Where a transfer abroad is required (for example, global infrastructure services), the transfer is made in accordance with the conditions in Article 9 of the KVKK and with standard contract/undertaking mechanisms. Data processing agreements (DPAs) are concluded with our service providers; the list of sub-processors is shared on request.
5.1 The AI assistant you connect (MCP)
Etkin can be connected to an AI assistant (for example Claude) through the open standard called Model Context Protocol (MCP). This connection is off by default and works only if you set it up: no data leaves through this interface unless you explicitly authorize an assistant.
How the connection is set up
Authorization is done with OAuth 2.1 and PKCE; your password is not given to the assistant. In the middle of the flow you land on Etkin’s own consent screen: you see which application is requesting which permissions and can approve or reject. No connection is established without approval; there is no silent or automatic approval.
Which data can go to the assistant
Limited to the scope of the organization your account is authorized for, the assistant can call only the following tools and sees only their output:
- • Event information: a predefined list of fields such as name, date, location, status, capacity and number of registrations. This list is a closed allowlist; no field that is not on the list leaves.
- • Numerical summaries: registration, attendance and notification counts and status distributions — not the attendee list.
- • Survey summaries: number of responses, completion rate, distributions of closed-ended questions and average scores.
- • Financial summaries: the event’s expected revenue, amount collected, refunds, expenses and payout status — as total amounts. Buyer identity, card details and the payment provider’s raw response do not leave through this interface.
- • Creating draft events: the only object the assistant can create without your approval is a draft. A draft is not published, no notification is sent to anyone and it can be deleted from the panel; pricing is done from the panel.
Operations the assistant can start — only with your approval
The assistant connection does not only read data. The following two operations produce an irreversible external effect and you are therefore asked separately on each call: the tool states in numbers how many people will receive what, and does nothing without your explicit approval. On clients that cannot open an approval window, the operation is rejected.
- • Publishing an event: when an event is published, an announcement email may be sent to people who follow your organization and have a verified email address. The approval text states the estimated number of recipients. You can revert the event’s status, but an email that has been sent cannot be recalled.
- • Scheduling a reminder email: a reminder email to attendees registered for the event is queued. Only the email channel is used — SMS and WhatsApp cannot be sent through this interface. Sending starts 15 minutes later at the earliest and can be cancelled from the panel until then; a single call has at most 100 recipients, and if the cap is exceeded the job is not created at all (the list is not silently truncated).
The recipient addresses of these sends are not shown to the assistant; Etkin does the sending, and the assistant only sees how many people it will go to. Sent emails are also recorded in the notification ledger and can be viewed from the panel. The assistant cannot update, delete or cancel events.
A record of this connection is kept
Every tool call made by the assistant is written to your account’s audit log and can be viewed from the panel. Its purpose is security: only this record can show whether an operation was carried out without your knowledge. The following is recorded:
- • Which tool was called, its result (successful / rejected), how long it took and — if applicable — which event it was called for.
- • The name and version of the connecting client, the protocol version and the IP address of the connection.
- • The texts you write to the assistant are not recorded. For example, the description you write to generate a draft, or the subject and body of a reminder email, do not go into the log; only the fact that those fields were filled in is kept.
These records are subject to the same retention period as other audit records (see section 6) and are covered by your deletion request.
Data that does not go to the assistant
- • Attendees’ name, email and phone details do not leave through this interface; the assistant cannot receive the attendee list.
- • IBAN, bank and account holder details, as well as the organization’s contact person data and internal analysis notes, do not leave.
- • Free-text answers in surveys are not returned in any form — not as examples, summaries or word frequencies either.
- • If the number of responses to a question is below five, that question’s distribution is also hidden; only how many people answered is reported. This threshold is applied because with few responses the distribution itself could point to a single person.
- • The assistant can see only the data of the organization you are authorized for; when data of another organization is requested, the request is rejected.
Recipient and transfer abroad
Tool output is sent to the provider operating the assistant you connect (for example Anthropic) and is subject to that provider’s own privacy policy and terms. These providers are generally located outside Türkiye; therefore, if you set up the connection, a transfer abroad takes place. The transfer is based on your explicit consent under Article 9 of the KVKK: the legal ground is not legitimate interest, but the authorization you grant on the consent screen during connection. You give your approval knowing that the country to which the data is transferred may not offer the same level of protection as Türkiye.
Revoking the authorization
For this transfer based on explicit consent, you may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out up to that point. You can remove the authorization with one click in the “Connected apps” section of the Settings > AI assistant screen; when you disconnect, the assistant’s access ends immediately and your approval is required again for it to reconnect. You can also do the same from the integration settings of the assistant application you use. If you wish, you can also write to info@etkin.app; your request will be concluded within 30 days at the latest.
6. Retention periods
Data is retained for the period necessary for the purpose of processing and for the periods required by legislation; when the period expires, it is automatically deleted or anonymized.
| Data | Retention period |
|---|---|
| Account data | As long as the account is open; upon a deletion request, deleted except for statutory retention obligations |
| Event registration data | 2 years from the event date |
| Survey responses | 1 year from the event date |
| SMS and WhatsApp sending records | 365 days |
| Email sending records | 180 days |
| Other notification records | 90 days |
| User action (activity) records | 180 days |
| System and security logs | 90 days |
| Performance and session monitoring records | 30 days |
| Invoice and accounting records | 10 years as required by tax legislation |
| Cookie data | The periods in the Cookie Policy (at most 365 days) |
Certificates remain accessible in the attendee portal in order to preserve their verifiability; upon a deletion request, the certificate record is also deleted and the verification link becomes invalid.
7. Your rights and applications
Under Article 11 of the KVKK, you have the following rights:
You can do it yourself: when signed in, you can download a copy of your data and create a deletion request from the Account → My data page.
Applications: you can send your requests to info@etkin.app. Applications are concluded within 30 days at the latest. For data you provided as an attendee of an event, the addressee of your application is the organization running the event; we forward your request to the relevant organization without delay.
8. Cookies
Strictly necessary cookies are used for maintaining the session and for security, and preference cookies for your language and theme preference. The measurement tool PostHog is loaded only when you give consent in the cookie notice; if you reject, it is not started and existing measurement cookies are cleared. Cloudflare Web Analytics does not use cookies. Google Analytics 4 was removed on 5 August 2026 and re-added on 25 August 2026; it is loaded only when you give cookie consent, measurement data is processed by Google and may be transferred abroad.
Cookie preferences: you can accept or reject analytics cookies from the cookie notice shown at the bottom of the page; your preference is kept for 365 days. For cookie names, purposes and retention periods, see the Cookie Policy page.
9. Data security
The main measures taken for the security of your personal data:
- • Encryption of all traffic with SSL/TLS
- • Encrypted storage of organization secrets (SMTP, SMS API keys) in the database
- • Isolation of each organization’s data with row-level access control
- • Role-based authorization and the principle of least privilege
- • A phishing-resistant sign-in option with passkeys (WebAuthn)
- • Regular backups, restore drills and security updates
- • Vulnerability monitoring, audit trail and incident logs
For details, see our Security & Compliance page. If you notice a security vulnerability, we kindly ask you to report it to info@etkin.app.
10. Children’s data
Etkin.app is not a service directed at children. When attendees under the age of eighteen register for events, obtaining the necessary parent/guardian consent is the responsibility of the organization running the event. If we learn that data belonging to a child has been processed without parental consent, we delete the data concerned.
11. Automated decision-making and artificial intelligence
No decision made exclusively by automated systems that produces legal effects concerning you or significantly affects you is applied. Registration approval, attendance and certificate decisions are made by the relevant organization.
AI-assisted features such as event draft suggestions work on the event text entered by the organization officer; attendee lists and personal data are not used for this purpose. The generated draft is always approved by the user before it is published.
If you connect an AI assistant to your account of your own accord, which data that assistant can access and what is not transferred is explained under the heading 5.1 The AI assistant you connect (MCP). The assistant does not make decisions on your behalf; it only calls the tools you have authorized. The event drafts it creates are not published unless you publish them. Publishing an event and scheduling reminder emails to attendees can be started through the assistant, but each time you must approve separately and explicitly; without approval these operations are not carried out.
12. GDPR compliance
Additional rights apply to users within the scope of the European Union General Data Protection Regulation (GDPR):
- • Right of access to your data
- • Right to erasure ("right to be forgotten")
- • Right to request restriction of processing
- • Right to data portability (machine-readable export)
- • Right to object to processing
- • Right to object to automated decision-making processes
- • Right to lodge a complaint with the competent supervisory authority
A separate Data Processing Agreement (DPA) is offered to corporate customers; to request it: info@etkin.app.
13. Changes
This policy may be updated according to developments in the service and the legislation. The current version is always published on this page and the date at the top of the page is updated. In the case of changes that materially affect your rights, you are also informed by email or in-app notification.
14. Contact
You can write to us to exercise your rights under the KVKK or with any questions about this policy:
Your applications are answered within 30 days at the latest. If you prefer, you can also use the contact form.
This privacy policy was last updated on 10 September 2026. Changes to the policy will be published on this page.