The protection of your personal data is extremely important to us. This policy explains how we collect and protect your data.
As Getivent ("Company", "we", "our"), we acknowledge our sensitivity and responsibility regarding the privacy of your personal data. This Privacy Policy explains how your personal data is collected, used, stored, and protected while you use the Getivent platform.
This policy has been prepared within the framework of compliance with the Republic of Turkey Law No. 6698 (KVKK) and the European Union General Data Protection Regulation (GDPR) standards. Getivent is integrating its data processing processes with EU standards (EU Data Privacy Standards) in preparation for its Netherlands-based operations.
We collect the following personal data through our platform:
First name, last name, date of birth, national ID number
Email address, phone number, address information
Invoice address and IBAN information. Important Note: Your credit card numbers and CVC codes are not stored on our servers. All payment transactions are carried out encrypted via secure payment infrastructures with PCI-DSS certification (e.g. Stripe, Iyzico).
IP address, browser information, device information, cookie data, and strictly necessary access logs, including ticket QR code scan events and ticket view events. These log entries capture the IP address and device information of the device used at the time of the scan or view, and are retained exclusively for platform security and fraud prevention purposes (see Section 3 and Section 6).
Purchase history, event attendance information, platform usage data
We use your personal data for the following purposes:
Providing and managing platform services
Technical support and customer services
Getivent processes ticket access logs (including QR code scan events and ticket view events) on the basis of its Legitimate Interest under Article 6(1)(f) GDPR, strictly for: fraud prevention and detection of duplicated ticket use; unauthorized access monitoring; preventing ticket duplication; and chargeback dispute resolution. This processing does not override the fundamental rights of data subjects, as logs are time-limited (90 days) and stored exclusively within the EU.
Service quality improvement and analysis
Information and marketing activities
Storage as required by legal regulations
We share your personal data with third parties only in the following cases and to a limited extent:
Licensed payment institutions for secure payment transactions
Cloud storage, analytics, and infrastructure services
As required by court order or legal regulation
Event organizers and content providers (limited data)
We never sell your data. All data sharing takes place within the scope of security protocols and data processing agreements.
We take the following technical and administrative measures for the security of your data:
Data transfer with 256-bit SSL certificate
Our production databases and application servers are hosted on secure infrastructure strictly within the European Union (primary region: Frankfurt, Germany, on Hetzner), ensuring full GDPR data residency compliance.
Regular security audits
Authorization-based data access
Automatic data backup system
24/7 security monitoring system
We retain personal data only for as long as is necessary for the purpose for which it was collected, in compliance with applicable legal obligations.
90 days from log entry date: Automatic and permanent deletion
Active account duration + 2 years: Secure deletion upon verified request or statutory expiry
7 years (EU fiscal regulations): Secure deletion upon expiry
Until consent is withdrawn: Immediate deletion upon opt-out
Ticket access logs, including all IP addresses and device information captured during QR code scan events and ticket view events, are automatically and permanently deleted after exactly 90 days from the date of each log entry. This deletion is enforced at the database level.
Under the General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK), you have the following rights regarding your personal data:
The right to learn which of your data is being processed
The right to request correction of erroneous data
The right to request deletion of your data
The right to object to data processing
The right to transfer your data to other platforms
The right to apply to the Personal Data Protection Board
To exercise your rights, contact us at our privacy address with a copy of a valid identity document. We will respond within 30 days in accordance with Art. 12 GDPR and Art. 13 KVKK. For complaints in the Netherlands, you may also contact the Autoriteit Persoonsgegevens (AP) at autoriteitpersoonsgegevens.nl.
Our platform uses cookies to provide better service:
Cookies required for platform functionality
Cookies used to analyze site usage
Cookies used for personalized advertisements
You can manage cookies and change your preferences from your browser settings.
You can contact us for questions about our privacy policy:
Getivent (Operation Center) Antalya, Turkey
+90 540 006 0077
Monday - Friday: 09:00 - 18:00
Saturday: 10:00 - 16:00
Sunday: Closed
Response Time: Within 48 business hours
This privacy policy may be updated due to legal regulations or platform changes. Important changes will be notified by email.