Privacy Policy and Privacy Notice
Last updated: 22 September 2026
Photonza is a platform that collects event photos in a single feed and lets guests find their own photos. This is our privacy notice under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the related Communiqué; it also fulfils our transparency obligations under the GDPR. It exists to inform you and requires no approval.
1. Who is the data controller?
The Photonza platform is operated by Ali Mert Güleç. Email: info@alimertgulec.com.
Photonza is the data controller for all data relating to the operation of the platform: organizer and photographer accounts, guest participation records, the face recognition system and face signatures, automated content moderation, security and usage logs, and cookies.
For the photos, videos and notes uploaded to an event, the organizer who created the event (venue, event company, school, institution or photographer) is the data controller; the organizer decides who is invited, the event settings and content removal. Photonza is the processor that stores and displays this content on the organizer's behalf. You may send requests about event content to the organizer or directly to us; we forward them to the organizer where necessary.
2. What data do we process?
As a guest (you join without an account, email or phone number):
- Your display name and participation record (which event you joined and when). The display name is the only mandatory field.
- Photos, videos and notes you upload; your likes.
- Your face signature (biometric data): created only if you use the "Find Me" feature with your explicit consent. Details are in a separate text: the Biometric Data Notice and Explicit Consent.
- Agreement acceptance and consent records: which version of a text you accepted and when.
As an organizer or photographer:
- Business name, email address and an irreversible hash of your password.
- The events you create and their settings; credits you buy and payment records (card details are never held by us; Stripe processes them).
- Your IP address at registration (to prevent abuse).
For everyone (technical and security):
- Server and application logs: IP address, browser type, request time and the action performed (sign-in, upload, download, search). Used for rate limiting and attack prevention.
- Usage counts: per-event download, view and match counts, shown to the organizer as aggregate statistics.
- Measurement cookies (only with your consent): see the Cookie Notice.
3. How does face recognition work?
"Find Me" works with a selfie. Your selfie never leaves your device; a model running in your browser turns your face into a numeric signature and only those numbers are sent to the server. A face image cannot be reconstructed from the signature. Matching happens only within the photos of the event you joined.
Signatures of the same kind are also extracted for the faces in photos uploaded to the event; this happens on upload in events where the organizer keeps face recognition on. The organizer can turn face recognition off for the whole event; when off, no signature is generated.
Your own face signature is created only with explicit consent given via a separate checkbox; no signature is generated for you unless you use the feature. You can withdraw consent at any time with "Delete my face data" on the Profile page. Full details are in the Biometric Data Notice and Explicit Consent.
4. For what purposes and on which legal basis?
Data is collected and processed electronically (web application, server logs) by automated means on the following legal bases listed in Articles 5 and 6 of KVKK (Articles 6 and 9 of the GDPR):
- Performance of a contract (Art. 5/2(c)): joining an event, collecting and displaying photos, downloads; managing organizer and photographer accounts, credits and payments.
- Legal obligation (Art. 5/2(ç)): keeping payment records under tax law; keeping traffic logs under Law No. 5651; answering requests from competent authorities.
- Legitimate interest (Art. 5/2(f)): automated filtering of inappropriate content, preventing abuse and attacks, rate limiting, debugging, aggregate statistics for the organizer.
- Explicit consent (Art. 5/1 and Art. 6/2): creating and matching your face signature; measurement cookies.
5. Who receives your data?
Photos you upload can be seen by the other guests of the event, the photographer and the organizer. If the event is in "private" mode, guests see only their own photos. The organizer sees guests' display names and event statistics, never face signatures.
We do not sell your data or share it for advertising. The following infrastructure providers process data on our behalf, on our instructions and only to provide the service:
- Supabase (European Union): database, authentication, face signatures.
- Cloudflare R2 (European Union region): photo and video storage.
- Vercel (USA/EU): hosting of the web application and server-side processing.
- OpenAI (USA): moderation and categorisation of uploaded photos. Photos are sent through the API and, under OpenAI's API data policy, are not used to train models.
- Stripe (USA/EU): organizer payments. Card details are processed only by Stripe.
- Google Analytics and Microsoft Clarity (USA): aggregate usage measurement, only if you gave cookie consent.
Some of these providers are located outside Türkiye. Transfers abroad are carried out under Article 9 of KVKK with the safeguards required by the Personal Data Protection Board (including standard contracts and notification to the Board). Where legally required, data may be shared with competent public authorities.
6. How long do we keep data?
Data is deleted or anonymised automatically when the following periods end:
- Event content (photos, videos, notes, likes), face signatures and match results: 30 days after the event ends. This period lets guests download their photos; deletion is irreversible.
- Your face signature additionally: the moment you press "Delete my face data" or leave the event.
- Guest participation record and display name: together with the event. A guest account with no remaining events is deleted after 90 days.
- Organizer and photographer accounts: until the account is deleted. On a deletion request the account and its events are removed; payment records are anonymised and kept for the statutory period.
- Payment and invoice records: 10 years under tax law.
- Application activity logs and IP addresses: 12 months (the minimum under Law No. 5651).
- Rate-limiting records (IP): 24 hours.
- Administrator action logs: 24 months.
- Agreement acceptance and consent records: 3 years for evidentiary purposes; anonymised when the user is deleted.
- Measurement cookies: the periods in the Cookie Notice.
7. Security
Data is protected with TLS in transit and with the providers' disk encryption at rest. Database access is limited by row-level security rules: a guest reaches only the data of the event they joined. Photo URLs contain unguessable random keys. Passwords are stored as irreversible hashes. Administrator actions are logged.
If we detect a data breach, we notify the Personal Data Protection Board within 72 hours as required by KVKK and inform the affected people.
8. Your rights
Under Article 11 of KVKK you have the right to:
- Learn whether your personal data is processed and, if so, request information.
- Learn the purpose of processing and whether the data is used in line with it.
- Know the third parties to whom it is transferred, in Türkiye or abroad.
- Request correction if it is incomplete or inaccurate.
- Request deletion or destruction when the reasons for processing no longer exist.
- Request that corrections and deletions be notified to third parties the data was transferred to.
- Object to a result against you produced by analysis with automated systems.
- Claim compensation if you suffer damage due to unlawful processing.
- Withdraw explicit consent you have given, at any time.
If the GDPR applies to you, you also have the rights to data portability and restriction of processing, and you may lodge a complaint with the supervisory authority of your country.
What you can do from within the app: delete a photo you uploaded, delete your face signature, leave the event, change your cookie preference.
9. Requests
Under the Communiqué on the Procedures and Principles of Application to the Data Controller, you may send your request by email to info@alimertgulec.com. Your request must include:
- Full name; a signature for written requests.
- Turkish ID number for Turkish citizens; nationality and passport number (or ID number, if any) for foreign nationals.
- Residential or business address for notification; email address and phone number, if any.
- The subject of the request. If you are a guest, stating which event you joined and under which display name helps us match your request quickly.
We conclude requests free of charge as soon as possible and within 30 days at the latest. If the process incurs an additional cost, the fee set by the Board's tariff may be charged. If your request is refused, you find our answer insufficient or we do not answer in time, you may complain to the Personal Data Protection Board.
10. Children
The platform is not intended for people under 18; the face recognition feature is closed to minors. Children may appear in event photos; the organizer running the event is responsible for sharing that content and obtaining parental consent. If you want content showing your child removed, just write to us; we handle such requests with priority.
12. Changes and contact
When we update this notice we change the date on this page. We inform account holders of important changes separately.
Questions: info@alimertgulec.com