Privacy Notice on the Processing of Personal Data (KVKK)
Last updated: 2026-08-05
This Privacy Notice has been prepared pursuant to Law No. 6698 on the Protection of Personal Data (the "KVKK" or the "Law") and its secondary legislation, for the purpose of informing you about your personal data processed within the scope of the event, community management and ticketing services ("Gathin" or the "Platform") offered at gathin.com under the "Gathin" brand.
The definitions used in this text are as follows: "Loopcode" or the "Company" means Loopcode Bilişim Yazılım Mühendislik Eğitim ve Danışmanlık A.Ş., which operates the Platform and holds the capacity of merchant of record for paid tickets; "User" means the natural person who registers with or uses the Platform; "Organiser" means the User who creates and stages an event on the Platform; "Event" means the activity announced or ticketed through the Platform; "Ticket" means the document granting the right to attend an Event; and "Buyer" means the person who purchases a Ticket.
You may obtain more detailed information about the processing of your personal data from the Privacy Policy, the Cookie Policy and the relevant agreements.
1. Identity of the Data Controller
Pursuant to the KVKK, your personal data is processed by Loopcode Bilişim Yazılım Mühendislik Eğitim ve Danışmanlık A.Ş. in the capacity of data controller, within the framework of the purposes and legal grounds set out below.
Information regarding the data controller is as follows:
- Title: Loopcode Bilişim Yazılım Mühendislik Eğitim ve Danışmanlık A.Ş.
- Registered Address: Yavuz Sultan Selim Mah. Dr. Sadık Ahmet Cad. No:24 İç Kapı No:1, Fatih/İstanbul, Türkiye
- MERSIS No: 0609 0927 8100 0001
- Trade Registry No / Office: 189875-5 (Istanbul Trade Registry Office)
- Tax Office / Tax Identification No (VKN): Fatih Tax Office, VKN: 6090927810
- KVKK / Legal Contact E-mail: info@loopcode.co
- Support E-mail: info@loopcode.co
- Telephone: 0 (530) 468 28 68
For paid tickets, Loopcode acts in the capacity of merchant of record for the ticket; it sells the ticket in its own name, issues the invoice to the Buyer and collects the price. The Organiser, on the other hand, is the party staging the Event and is not the seller of the ticket. For this reason, Loopcode is the data controller in respect of personal data relating to the sale transaction; and in respect of data processed by the Organiser within the scope of managing its own community and Event, the Organiser may additionally hold the capacity of data controller.
2. Categories of Personal Data Processed
Depending on your use of the Platform and the transactions you carry out, the following categories of personal data are processed.
2.1. Identity Data
First name, last name, username and the identity number requested under the legislation for paid ticket purchases.
2.2. Contact Data
E-mail address, mobile telephone number, billing address, country information and, where shared on the profile, social media account links.
2.3. Customer Transaction Data
Ticket and RSVP records, order and purchase information, Event attendance and registration history, communities of which you are a member, and requests, complaints and support records submitted through the Platform.
2.4. Financial Data
Invoice information, tax number provided optionally, payment amount and currency (TL/TRY, USD or EUR) and value added tax (VAT) information relating to the transaction. Your card details (card number, expiry date, security code) are transmitted to iyzico via Loopcode's payment infrastructure for the purpose of executing the payment and are not stored by Loopcode; the payment is carried out by iyzico using the 3D Secure security protocol.
2.5. Transaction Security Data
Account password (kept in encrypted/hashed form), login and session records, IP address, device and browser information, cookie records and data relating to authentication (OAuth) transactions carried out through Google. In addition, within the scope of the Platform's first-party visitor and session analytics, session information, pages visited, device and platform type and online status and time data are processed, including for visitors who are not logged in. This analytics is based on legitimate interest and is reflected to Organisers only as aggregate traffic statistics (not containing raw IP addresses or browser identifiers).
2.6. Marketing Data
Your communication and notification preferences; the approval/refusal records and Message Management System (İYS) permission statuses to be kept once commercial electronic messaging is activated; analytical and usage data collected through cookies. Communication preferences are managed within the platform and marketing messages are not currently sent by telephone/SMS.
2.7. Visual and Audio Data
Profile image (avatar), photographs uploaded to community photo galleries and images associated with tagging operations carried out in those photographs.
2.8. User Content Data
Within the scope of user-generated content, profile biography, forum messages, Organiser announcements, form responses, Event and community descriptions and other information shared on User profiles.
Gathin does not aim to collect special categories of personal data (Article 6 of the KVKK) and does not request such data from Users. However, where content shared by Users of their own volition in areas such as galleries, forums, forms or profiles contains special categories of personal data, such data is processed and hosted on the basis of explicit consent pursuant to Article 6 of the KVKK. You are advised not to share such data.
3. Purposes of Processing Personal Data
Your personal data is processed for the following purposes:
- Creating Platform membership, managing the account and providing authentication,
- Providing event and community management services and carrying out RSVP and attendance processes,
- Offering paid tickets for sale in the capacity of merchant of record and carrying out order, payment and collection processes,
- Issuing invoices and fiscal documents and fulfilling accounting and fiscal obligations,
- Sending transactional messages (ticket and RSVP confirmation, reminder messages before the Event, reminders relating to saved Events),
- Where your explicit consent exists, sending commercial electronic messages for promotional and marketing purposes and managing your preferences,
- Responding to User requests, suggestions and complaints and providing support services,
- Ensuring the security of the Platform and Users, preventing fraud and misuse, and keeping records,
- Developing services, carrying out usage analyses including first-party visitor and session analytics, providing Organisers with aggregate traffic statistics relating to their own pages, and improving Platform performance,
- Fulfilling obligations arising from the relevant legislation and responding to the requests of authorised institutions and organisations,
- Establishing, exercising and protecting rights in the event of disputes.
4. Legal Grounds for Processing Personal Data
Depending on the purpose of processing, your personal data is processed on the basis of the following legal grounds set out in Articles 5 and 6 of the KVKK.
4.1. Cases Not Requiring Explicit Consent (Article 5/2 of the KVKK)
- Expressly provided for by law (Art. 5/2-a): Processing of records that must be kept within the scope of tax, invoicing and electronic commerce legislation.
- Directly related to the establishment or performance of a contract (Art. 5/2-c): Establishing membership, executing the Ticket sale transaction, and carrying out RSVP and Event attendance processes.
- Compliance by the data controller with a legal obligation (Art. 5/2-ç): Issuing invoices, fulfilling fiscal and tax obligations and obligations under Law No. 6563.
- Mandatory for the establishment, exercise or protection of a right (Art. 5/2-e): Resolving disputes and carrying out processes relating to legal claims.
- Mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject (Art. 5/2-f): Operations aimed at ensuring Platform security, preventing misuse, operating first-party visitor and session analytics and improving service quality.
Your identity data, including the identity number requested for paid ticket purchases, is processed on the legal grounds of the legal obligation relating to the issuance of invoices and fiscal documents (Art. 5/2-ç) and the performance of the sales contract (Art. 5/2-c).
4.2. Cases Based on Explicit Consent (Articles 5/1 and 6 of the KVKK)
- Sending commercial electronic messages for promotional and marketing purposes, including commercial messages relating to communities you have not joined, is based on your explicit consent and your İYS approval.
- The processing of data through non-mandatory (marketing and analytical) cookies is based on your explicit consent.
- Where your user content contains special categories of personal data, the processing and hosting of such data is based on your explicit consent pursuant to Article 6 of the KVKK.
In processing activities based on explicit consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of the processing carried out up to the moment of withdrawal.
5. Parties to Whom Personal Data Is Transferred and Purposes of Transfer
Your personal data may be shared with the following parties, limited to the achievement of the purposes stated above and in accordance with the conditions provided for in Articles 8 and 9 of the KVKK.
5.1. Domestic Transfer
- Organisers: If you attend an Event (RSVP), purchase a Ticket, or complete and submit a form belonging to a community, your first name, last name, e-mail, telephone, form responses and attendance and membership information are transferred to the relevant Organiser (community administrator) for the purposes of staging the Event and managing attendees and community membership. If you carry out these transactions and are not already a member of the relevant community (the community staging the Event or the community to which the form belongs), you will be made a member of that community and a membership record will be created. Where an Event is staged jointly (collaboratively) by more than one community, membership and the associated data transfer cover all of the collaborating communities.
- iyzico: Shared with the payment infrastructure provider iyzico for the purposes of executing payment and collection transactions, 3D Secure verification and preventing fraud.
- Message Management System (İYS): Once commercial electronic messaging is activated, your approval and refusal records will be transferred to and held in İYS as required by the legislation (Loopcode is not currently registered with İYS and does not send commercial electronic messages).
- Financial advisors, audit and legal consultants: May be shared for the purposes of accounting, fulfilling fiscal obligations and conducting legal processes.
- Authorised public institutions and organisations and judicial authorities: May be shared within the scope of obligations arising from the relevant legislation and upon request.
- Service providers: Data may be shared with DigitalOcean, LLC for the provision of hosting services and with Mailgun (e-mail only; no SMS is sent) for the delivery of transactional/commercial messages. Location of the server and hosting infrastructure: Germany (DigitalOcean Frankfurt data centre).
5.2. Transfer Abroad
Your personal data may be transferred abroad as a result of the use of the following services. Transfers abroad are carried out within the framework of the conditions set out in Article 9 of the KVKK (the existence of an adequacy decision, the provision of appropriate safeguards, or the existence of the exceptional circumstances provided for).
- Google: Due to the use of Google Analytics (analytics), Google Maps (location and map services) and Google OAuth (authentication) services across the Platform, the relevant data may be shared with Google.
- Infrastructure providers located abroad: Where the hosting or message delivery infrastructure is located abroad, the relevant data may be shared with those providers.
6. Method of Collecting Personal Data and Legal Ground
Your personal data is collected electronically, by wholly or partly automated means, through membership and registration forms on the Platform, profile editing areas, Ticket and RSVP transactions, the fields completed at the payment step (first and last name, e-mail, mobile telephone, identity number for paid tickets, billing address, optional tax number and card details transmitted via iyzico), Organiser forms, community and forum interactions, support requests, cookies and authentication transactions carried out through Google.
The legal grounds for the data collected are the provisions of Articles 5 and 6 of the KVKK explained under the heading "4. Legal Grounds for Processing Personal Data" of this text.
7. Rights of the Data Subject
Pursuant to Article 11 of the KVKK, you may exercise the following rights by applying to the data controller:
- a) To learn whether your personal data is processed,
- b) To request information if your personal data has been processed,
- c) To learn the purpose of processing your personal data and whether it is used in accordance with that purpose,
- ç) To know the third parties to whom your personal data is transferred domestically or abroad,
- d) To request rectification where your personal data has been processed incompletely or inaccurately,
- e) To request the erasure or destruction of your personal data within the framework of the conditions provided for in Article 7 of the KVKK,
- f) To request that operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom your personal data has been transferred,
- g) To object to a result arising against you through the analysis of your processed data exclusively by automated systems,
- ğ) To claim compensation for damage suffered as a result of the unlawful processing of your personal data.
Following the deletion of your account, without prejudice to the rights stated above, your personal data may be retained for the purpose of fulfilling legal obligations for the periods provided for in the relevant legislation (within 30 days at the latest, subject to data required for legal obligations and potential disputes and to the mandatory retention periods prescribed by the legislation); at the end of those periods your data is deleted, destroyed or anonymised.
8. Application Procedure
You may submit your requests relating to the rights listed above to the Company by the following methods, in accordance with the procedure provided for in the Communiqué on the Procedures and Principles of Application to the Data Controller:
- By sending your wet-signed petition in person or through a notary to the address Yavuz Sultan Selim Mah. Dr. Sadık Ahmet Cad. No:24 İç Kapı No:1, Fatih/İstanbul, Türkiye,
- By sending it to info@loopcode.co from the e-mail address you have previously notified to the Company and which is registered in our system.
Your application must include your first name, last name, your signature if the application is in writing, your Turkish identity number (passport number for foreign nationals), your address for service, your electronic mail address for notification if any, your telephone number and the subject of your request. You must attach to your application information verifying your identity together with documents and explanations relating to your request.
The Company concludes your request as soon as possible depending on its nature and in any event within thirty days at the latest from the date the application reaches the Company. Responses to applications are free of charge as a rule; however, if the operation additionally entails a cost, the fee in the tariff determined by the Personal Data Protection Board may be charged.
Where your application is refused, where you find the response given insufficient, or where no response is given within the period, you have the right to lodge a complaint with the Personal Data Protection Board within thirty days from the date you learn of the response and in any event within sixty days from the date of application.
You may also submit notifications regarding misuse, unlawful content or the breach of your personal data via info@loopcode.co.