Privacy Policy

Effective date: [EFFECTIVE DATE]. Last updated: [DATE].

This Privacy Policy explains how [COMPANY NAME] ("we", "us", "our") collects, uses, and protects personal data when you or your event guests use the ShowUpShot service ("Service"). It is intended to satisfy the transparency obligations of the EU General Data Protection Regulation ("GDPR") and the Turkish Personal Data Protection Law No. 6698 ("KVKK").

1. Data controller and contact

Controller: [COMPANY NAME], [ADDRESS], [JURISDICTION].
Data protection contact: [DPO EMAIL].
KVKK VERBIS registration: [VERBIS NUMBER, if applicable].

2. What personal data we process

Account holders (event organisers): name, work email, company name, country, hashed password, IP address, session identifier, billing details processed by Stripe on our behalf.

Event guests: portrait photo uploaded to compose a branded image, optional name/title/company text added to the composite, IP address (hashed), event and download telemetry, browser and device metadata.

Website visitors: server logs (IP hashed, timestamps, requested URL, user agent), cookies described in our Cookie Policy.

3. Purposes and legal bases

PurposeGDPR basis (Art. 6)KVKK basis (Art. 5)
Providing the Service (account, authentication, event delivery)Contract (Art. 6(1)(b))Contract (Art. 5(2)(c))
Billing and fraud preventionContract, legal obligation, legitimate interestContract, legal obligation, legitimate interest
Guest photo composition and deliveryConsent from the guest (Art. 6(1)(a))Explicit consent (Art. 6)
Aggregated analytics and product improvementLegitimate interestLegitimate interest
Security, abuse detection, incident responseLegitimate interest, legal obligationLegitimate interest, legal obligation

4. Retention

5. Recipients and processors

We enter into written processing agreements with each processor that include the safeguards required by Article 28 GDPR and Article 12 KVKK.

6. International transfers

Some processors are located outside the EEA and Turkey. Where personal data is transferred internationally, we rely on Standard Contractual Clauses adopted by the European Commission and, for KVKK, on the applicable transfer mechanism (data subject consent, adequacy decision, or written undertaking approved by the KVK Board).

7. Your rights

Under GDPR you have the right to access, rectify, erase, restrict processing, port your data, and object to processing. Where processing is based on consent, you may withdraw consent at any time.

Under KVKK Article 11 you have the right to learn whether your data is processed, request information about processing, learn its purpose and whether it is used accordingly, know the third parties to whom it is disclosed, request correction of inaccurate data, request erasure or destruction, request that corrections and erasures be notified to third parties, object to processing that produces a result against you, and claim compensation for damages caused by unlawful processing.

To exercise these rights email [DPO EMAIL]. We respond within 30 days for GDPR requests and within 30 days for KVKK requests (up to 15 days extension where required).

8. Complaints

EU residents may lodge a complaint with the supervisory authority in their EU country of residence.

Turkey residents may apply to the Turkish Personal Data Protection Authority (KVK Board) if we do not respond within 30 days, respond negatively, or their response is unsatisfactory. The complaint must be lodged within 30 days of our response, or within 60 days if we did not respond.

9. Security

We apply appropriate technical and organisational measures including encryption in transit (TLS), encryption at rest for backups, access controls, password hashing, session isolation, audit logging, and vendor due diligence. No system is perfectly secure; we notify affected data subjects and authorities as required by law in the event of a personal data breach.

10. Children

The Service is not intended for children under the age of 16. If we learn that we have collected personal data from a child without appropriate consent we will delete it.

11. Changes

We may update this Privacy Policy. Material changes will be notified by email and by prominent notice on the Service at least 30 days before they take effect.

12. Contact

Data protection queries: [DPO EMAIL]. Postal: [COMPANY NAME], [ADDRESS].