Privacy Policy
This Privacy Policy explains how [COMPANY NAME] ("we", "us", "our") collects, uses, and protects personal data when you or your event guests use the ShowUpShot service ("Service"). It is intended to satisfy the transparency obligations of the EU General Data Protection Regulation ("GDPR") and the Turkish Personal Data Protection Law No. 6698 ("KVKK").
1. Data controller and contact
Controller: [COMPANY NAME], [ADDRESS], [JURISDICTION].
Data protection contact: [DPO EMAIL].
KVKK VERBIS registration: [VERBIS NUMBER, if applicable].
2. What personal data we process
Account holders (event organisers): name, work email, company name, country, hashed password, IP address, session identifier, billing details processed by Stripe on our behalf.
Event guests: portrait photo uploaded to compose a branded image, optional name/title/company text added to the composite, IP address (hashed), event and download telemetry, browser and device metadata.
Website visitors: server logs (IP hashed, timestamps, requested URL, user agent), cookies described in our Cookie Policy.
3. Purposes and legal bases
| Purpose | GDPR basis (Art. 6) | KVKK basis (Art. 5) |
|---|---|---|
| Providing the Service (account, authentication, event delivery) | Contract (Art. 6(1)(b)) | Contract (Art. 5(2)(c)) |
| Billing and fraud prevention | Contract, legal obligation, legitimate interest | Contract, legal obligation, legitimate interest |
| Guest photo composition and delivery | Consent from the guest (Art. 6(1)(a)) | Explicit consent (Art. 6) |
| Aggregated analytics and product improvement | Legitimate interest | Legitimate interest |
| Security, abuse detection, incident response | Legitimate interest, legal obligation | Legitimate interest, legal obligation |
4. Retention
- Guest portrait uploads: deleted from our servers within 24 hours after upload.
- Event configurations and analytics: retained while your account is active, plus 12 months after account closure, then deleted.
- Billing records: retained for the period required by applicable tax and accounting law (typically 8-10 years).
- Server logs: 30 days for operational logs, 12 months for security-relevant logs.
5. Recipients and processors
- Stripe Payments (payment processing) - [STRIPE ENTITY]
- Postmark or Amazon SES (transactional email) - [MAIL PROVIDER ENTITY]
- [HOSTING PROVIDER] (infrastructure hosting the Service)
- Professional advisers (auditors, legal counsel) where necessary
We enter into written processing agreements with each processor that include the safeguards required by Article 28 GDPR and Article 12 KVKK.
6. International transfers
Some processors are located outside the EEA and Turkey. Where personal data is transferred internationally, we rely on Standard Contractual Clauses adopted by the European Commission and, for KVKK, on the applicable transfer mechanism (data subject consent, adequacy decision, or written undertaking approved by the KVK Board).
7. Your rights
Under GDPR you have the right to access, rectify, erase, restrict processing, port your data, and object to processing. Where processing is based on consent, you may withdraw consent at any time.
Under KVKK Article 11 you have the right to learn whether your data is processed, request information about processing, learn its purpose and whether it is used accordingly, know the third parties to whom it is disclosed, request correction of inaccurate data, request erasure or destruction, request that corrections and erasures be notified to third parties, object to processing that produces a result against you, and claim compensation for damages caused by unlawful processing.
To exercise these rights email [DPO EMAIL]. We respond within 30 days for GDPR requests and within 30 days for KVKK requests (up to 15 days extension where required).
8. Complaints
EU residents may lodge a complaint with the supervisory authority in their EU country of residence.
Turkey residents may apply to the Turkish Personal Data Protection Authority (KVK Board) if we do not respond within 30 days, respond negatively, or their response is unsatisfactory. The complaint must be lodged within 30 days of our response, or within 60 days if we did not respond.
9. Security
We apply appropriate technical and organisational measures including encryption in transit (TLS), encryption at rest for backups, access controls, password hashing, session isolation, audit logging, and vendor due diligence. No system is perfectly secure; we notify affected data subjects and authorities as required by law in the event of a personal data breach.
10. Children
The Service is not intended for children under the age of 16. If we learn that we have collected personal data from a child without appropriate consent we will delete it.
11. Changes
We may update this Privacy Policy. Material changes will be notified by email and by prominent notice on the Service at least 30 days before they take effect.
12. Contact
Data protection queries: [DPO EMAIL]. Postal: [COMPANY NAME], [ADDRESS].