Personal Data Retention and Destruction Policy

Last updated: 25 September 2026

This policy sets out the retention periods and destruction procedures for personal data processed on the Photonza platform, under Article 7 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the Regulation on the Deletion, Destruction or Anonymisation of Personal Data. It is for information only and requires no approval. Although Photonza is exempt from registration with VERBİS under the Board's exemption decisions and therefore not strictly obliged to have this policy, it applies and publishes it voluntarily so that the retention period of biometric data is explained with its reasons. Version 1.2.

1. Purpose and scope

This policy sets out in which storage media and for how long personal data processed in the operation of the Photonza platform is kept, by which method it is deleted, destroyed or anonymised when the retention period ends, and how often this is done. The data controller is Ali Mert Güleç, who operates the Photonza platform (Email: info@alimertgulec.com).

Scope: all personal data of guests, organizers (venues, event companies, schools, institutions), photographers, website visitors and people appearing in event photos that is processed by automated means. Photonza has no physical (paper) records containing personal data.

2. Definitions

Terms in this policy have the meaning given in the Regulation:

  • Deletion: making personal data inaccessible and unusable in any way for the relevant users (removing the database record and the storage object).
  • Destruction: making personal data inaccessible, irretrievable and unusable by anyone (deleted data also expiring from the providers' backups).
  • Anonymisation: making personal data impossible to associate with an identified or identifiable natural person, even when matched with other data (e.g. removing the link between a payment record and the user).
  • Periodic destruction: deletion, destruction or anonymisation, on the controller's own initiative and at recurring intervals set in this policy, of personal data whose retention period has ended.
  • Storage medium: any electronic medium in which personal data is held.

3. Storage media

Personal data is stored only in the following electronic media:

  • Database (Supabase; US company, servers in the European Union, Ireland): user and event records, participation records, post details, face signatures, consent records, application and administrator logs.
  • Authentication (Supabase Auth, same region): organizers' and photographers' email addresses and password hashes; guests' anonymous sessions.
  • Object storage (Cloudflare R2; US company): photo and video files and their thumbnails.
  • Face scanning (Cloudflare infrastructure): when face signatures are extracted from event photos, the photo is processed temporarily; neither the photo nor the signature is stored there, and the signature is written only to the database.
  • Application hosting (Vercel; US company, server-side processing in the European Union, Ireland): request logs (IP address, path, time) are kept briefly on the provider side; Photonza does not store them separately. Vercel Web Analytics keeps only aggregate page-view statistics; it uses no cookies and the visitor session is discarded after 24 hours.
  • Email mailbox (GoDaddy email hosting; US company): data subject requests, content removal notices, sales correspondence.
  • WhatsApp (Meta): sales correspondence, only if the person chooses to message us there.
  • Accounting: invoices and payment records via our accountant and the e-invoice system (Türkiye).

5. Retention and destruction periods

When the following periods end, data is deleted or anonymised by automated jobs or by administrator action:

  • Event content (photos, videos, notes, likes): 30 days from the end of the event. When the period ends the event is marked for deletion; an hourly clean-up job removes the files from storage and the records from the database.
  • Face signatures extracted from event photos and videos: together with the event (30 days from the end); at the same time if the photo or video is deleted earlier; within 30 days at the latest upon an objection and deletion request.
  • The face signature generated from a guest's selfie and match results: together with the event (30 days from the end); at the moment the guest presses "Delete my face data" or leaves the event; whichever comes first.
  • Guest participation record and display name: together with the event.
  • Anonymous guest account with no remaining events: deleted after 90 days.
  • Organizer and photographer accounts (business name, email, password hash): until the account is deleted; deleted within 30 days at the latest after a deletion request.
  • Payment and invoice records: 10 years; anonymised by removing the link to the user when the account is deleted.
  • Application activity logs (including IP address): 12 months.
  • Rate-limiting records (keyed to IP address): 24 hours.
  • Administrator action logs: 24 months.
  • Agreement acceptance and explicit consent records: 3 years; if the user was deleted earlier, the record is kept without a link to the user.
  • Expired invitation and sign-in tokens: between 15 minutes and 72 hours, depending on type.
  • Data subject requests, content removal notices and answers (email): 3 years from the date of the answer.
  • Sales correspondence and, for consumer sales, pre-contract information/contract confirmations: 3 years (Distance Contracts Regulation); 10 years where they support an invoice.
  • Strictly necessary records kept in your browser (session, language preference, event session, upload drafts, download progress): the periods stated for each in the Cookie Notice; you can delete them from your browser settings at any time.

6. Destruction methods

Because Photonza holds data only in electronic media, the following methods are used:

  • Deletion: deleting database records (including cascading deletion of related records) and removing files from storage.
  • Destruction: deleted data also leaving the backups when the providers' backup windows expire; object versioning is not used in storage.
  • Anonymisation: removing the link between a record and the user (payment records and consent records).

7. Periodic destruction

Under the Regulation, the periodic destruction interval is 6 months. Data whose retention period has ended is mostly deleted by automated jobs running every minute, hour or day; in addition, every 6 months:

  • The run logs of the automated deletion jobs are checked and any errors are fixed.
  • Expired request correspondence is deleted from the mailbox.
  • The providers' backup periods are checked.
  • This policy and the retention periods in the Privacy Policy are reviewed against the system.
  • Destruction operations are recorded; these records are kept for at least 3 years.

8. Technical and organisational measures

  • Row-level access rules in the database; a guest reaches only the data of the event they joined. Only the server-side service can access face signatures; organizers and other users cannot.
  • TLS encryption in transit, provider disk encryption at rest; passwords are stored as irreversible hashes.
  • Administrator actions are logged; service keys are kept only in the server environment.
  • Data minimisation: guests are not asked for an email address or phone number; the selfie image never leaves the device.
  • Only the data controller has access to personal data; if staff are employed, a confidentiality undertaking is obtained.

9. Responsibility and requests

The data controller, Ali Mert Güleç, is responsible for applying this policy, keeping the automated destruction jobs running and periodic destruction.

You may ask for your data to be deleted before the retention period ends, or send questions about this policy, to info@alimertgulec.com. The application procedure and your rights are described in the Privacy Policy and Privacy Notice (photonza.com/privacy).

10. Entry into force and changes

This policy first entered into force on 22 September 2026 and was updated on 25 September 2026. It is updated when legislation, infrastructure or the business model changes; the current version is published on this page.

Personal Data Retention and Destruction Policy | Photonza