Privacy Policy
Last updated: 2026-08-05
1. Data Controller
This Privacy Policy explains our practices concerning personal data processed within the scope of the event and community management and ticketing services offered through the Gathin platform (web: gathin.com).
Pursuant to Law No. 6698 on the Protection of Personal Data (the "KVKK"), the data controller is Loopcode Bilişim Yazılım Mühendislik Eğitim ve Danışmanlık A.Ş. ("Loopcode" or the "Company"), which operates the Gathin platform and acts in the capacity of merchant of record for paid tickets.
The identity and contact details of the data controller are as follows:
- Trade name: Loopcode Bilişim Yazılım Mühendislik Eğitim ve Danışmanlık A.Ş.
- Registered address: Yavuz Sultan Selim Mah. Dr. Sadık Ahmet Cad. No:24 İç Kapı No:1, Fatih/İstanbul, Türkiye
- MERSIS No: 0609 0927 8100 0001
- Trade Registry No / Office: 189875-5 (Istanbul Trade Registry Office)
- Tax Office and Tax Identification No (VKN): Fatih Tax Office, VKN: 6090927810
- KVKK / legal contact e-mail: info@loopcode.co
- Telephone: 0 (530) 468 28 68
In this Policy, "User" means the natural person using Gathin; "Organiser" means the User staging the event; "Buyer" means the User purchasing the ticket; and "Event" and "Ticket" mean the service managed and sold through the platform and the related right of attendance. The Organiser is the party staging the event; it is not the seller of the ticket. For paid tickets, the party that sells the ticket in its own name, issues the document to the Buyer and collects the price is Loopcode.
2. Personal Data Processed
Depending on the nature of the service and the User's interaction with the platform, Loopcode processes the following categories of personal data.
2.1. Account and Registration Data
First name, last name, e-mail address and password. The password is stored in irreversibly hashed form; it is not kept in plain text.
2.2. Profile Data
Biography, first name, last name, telephone number, avatar (profile image), social media links, country and username information provided by the User at their option.
2.3. Data Collected at the Payment Step
During the purchase of a paid ticket, the following are collected from the Buyer: first and last name, e-mail address, mobile telephone number, identity number for paid tickets, billing address and, if any, tax number. This data is necessary in order to issue valid documentation and to fulfil fiscal legislation obligations.
Card details (card number, expiry date, security code) are transmitted to iyzico via Loopcode's payment infrastructure for the purpose of executing the payment transaction; they are not recorded or stored by Loopcode. Transmission takes place over an encrypted connection (TLS), and payment is carried out through the iyzico infrastructure with 3D Secure verification. Loopcode has access to data such as the transaction reference and status information relating to the payment result.
Amounts are collected by default in Turkish Lira (TL/TRY); they may also be collected in US Dollars (USD) and Euros (EUR). VAT is applied at the rate in force (the general rate is 20%); certain events may be subject to a different or zero rate under the legislation. Whether the price is displayed inclusive or exclusive of VAT may be determined by the Organiser.
2.4. User-Generated Content (UGC)
Photographs uploaded to community photo galleries, likes and the tagging of other users in photographs; forum messages, Organiser announcements, form responses, event and community descriptions and content shared on user profiles. Such content may contain personal data about other users (for example, visual data or identity information by way of tagging). Where content uploaded or shared by the User contains personal data belonging to third parties, the User is responsible for informing those persons and obtaining the necessary consents.
2.5. Communication and Marketing Data
The contact details required in order to send transactional messages (ticket/RSVP confirmation, the reminder sent 24 hours before an event, saved event reminders), together with records relating to the User's communication and notification preferences. Communication preferences are managed within the platform. Marketing messages are not currently sent by telephone/SMS; when commercial electronic messages begin to be sent, these will be carried out subject to the User's explicit consent and through the Message Management System (İYS).
2.6. Usage and Transaction Records (Logs)
Technical records generated automatically during use of the platform: IP address, date-time stamp, device and browser information, session information, and records of pages clicked and transactions performed.
2.7. Cookie Data
Data collected through cookies for the operation of the platform and for optional analytical purposes. For details, see section 9 of this Policy and the Cookie Policy.
2.8. Visitor and Session Analytics Data
Separately from Google Analytics, the Platform operates its own first-party visitor and session analytics. In this scope, session information, pages visited (URL), device and platform type, browser information and online status and time data are processed, including for visitors who are not logged in. This analytics is carried out on the basis of legitimate interest (Article 5/2-f of the KVKK), independently of the cookie consent banner. Organisers are provided only with aggregate traffic statistics relating to their own Event and community pages (number of unique visitors/sessions, device distribution and timeline); the analytics transferred to Organisers does not include raw IP addresses or browser identifiers (user-agent), and no individual visitor identity is shared.
3. Purposes of Processing Personal Data
Personal data is processed for the following purposes:
- Creating the User account, authentication and account management (including sign-in with Google OAuth),
- Providing event and community management services and carrying out RSVP and attendance transactions,
- Executing the sale transaction for paid tickets, collecting the price, issuing documentation to the Buyer and managing the transfer of the price to the Organiser,
- Sending transactional messages relating to ticket, RSVP and event reminders,
- Carrying out commercial electronic messaging and marketing communication subject to explicit consent,
- Operating user content features such as community photo galleries, forums, forms and announcements,
- Ensuring the security of the platform and preventing misuse and fraud,
- Measuring and improving service quality; operating first-party visitor and session analytics, providing Organisers with aggregate traffic statistics relating to their own pages, and carrying out optional (Google Analytics) analytical activities,
- Fulfilling fiscal, commercial and legal obligations and meeting obligations to provide information and documents to authorised institutions and organisations,
- Assessing requests and complaints and carrying out support processes.
4. Legal Grounds for Processing
Personal data is processed on the basis of the following legal grounds set out in Articles 5 and 6 of the KVKK.
Without requiring explicit consent, pursuant to Article 5/2 of the KVKK:
- Expressly provided for by law (Art. 5/2-a): identity number, billing address and documentation data collected within the scope of fiscal legislation and retention obligations,
- Establishment or performance of a contract (Art. 5/2-c): account creation, ticket sales, RSVP and attendance transactions and the sending of transactional messages,
- Compliance with a legal obligation (Art. 5/2-ç): issuing documentation, keeping fiscal records and providing information to authorised institutions,
- Where data processing is mandatory for the establishment, exercise or protection of a right (Art. 5/2-e),
- Legitimate interests of the data controller (Art. 5/2-f): ensuring platform security, preventing misuse, operating first-party visitor and session analytics and improving the service.
On the basis of explicit consent, pursuant to Article 5/1 of the KVKK:
- Sending commercial electronic messages, using analytical cookies for marketing purposes and processing optionally provided profile data for these purposes.
Pursuant to Article 6 of the KVKK:
- Where photographs and similar content uploaded within the scope of user content contain special categories of personal data, such data is processed on the basis of the explicit consent of the data subject.
In processing based on explicit consent, the User may withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of that consent up to the moment of withdrawal.
5. Transfer of Personal Data
Personal data may be shared with the following parties, limited to the achievement of the purposes stated above and to the relevant legal grounds:
- iyzico: for the purpose of executing the payment transaction, 3D Secure verification and processing card data,
- Organiser: for the purpose of sharing attendee list, RSVP, ticket and form submission information within the scope of the relevant event and community management. If you attend an Event (RSVP), purchase a ticket or submit a form belonging to a community, you will be made a member of that community if you are not already a member. Where an Event is organised collaboratively by more than one community, since those communities are joint organisers of the event, your attendance at the event constitutes interaction with all of those communities; membership and the associated data transfer arise for all of those communities on the legal grounds of performance of the contract and legitimate interest. Each Organiser bears separate responsibility in its own processes in respect of the data transferred to it,
- Google Analytics: for the purpose of optional analytical measurement,
- Google Maps: for the purposes of location and map display services,
- Hosting provider: for the purposes of storing data and operating the platform (DigitalOcean, LLC),
- E-mail/SMS delivery provider: for the purpose of transmitting transactional messages and messages subject to explicit consent (Mailgun (e-mail only; no SMS is sent)),
- Video meeting/room provider: for the purpose of running online events (Memeet — memeet.lodos.io; a service provided within Lodos),
- Authorised public institutions and organisations: for the purpose of fulfilling obligations arising from the legislation to provide information and documents.
Location of the servers hosting personal data: Germany (DigitalOcean Frankfurt data centre).
The infrastructure of some of the providers listed above may be located abroad. In that case, transfer abroad is carried out within the framework of the conditions provided for in Article 9 of the KVKK, on condition that an adequacy decision exists or, in the absence of an adequacy decision, that the appropriate safeguards set out in the Law (such as standard contracts or undertakings) are provided, or that the exceptional circumstances provided for in the Law or explicit consent exist.
6. Retention Periods
Personal data is retained for as long as is necessary for the purpose for which it is processed and for the minimum periods prescribed by the relevant legislation. Where the purpose ceases to exist and the statutory retention periods expire, the data is deleted, destroyed or anonymised.
- Fiscal and commercial records (invoices, documents and accounting records): legally 10 years pursuant to the relevant legislation,
- Account and profile data: for as long as the account is active,
- Transaction and traffic records (logs): for the periods prescribed by the relevant legislation,
- Where the account is deleted, the retention period for data other than that required in respect of legal obligations and potential disputes: within 30 days at the latest, subject to data required for legal obligations and potential disputes and to the mandatory retention periods prescribed by the legislation.
7. Data Security
Loopcode takes technical and administrative measures pursuant to Article 12 of the KVKK in order to prevent the unlawful processing of and unlawful access to personal data and to ensure the safekeeping of the data. In this scope, measures such as the use of 3D Secure at the payment step, encrypted communication during transmission (TLS), storage of passwords in irreversibly hashed form, restriction of access rights, operation of authorisation and logging mechanisms, and the establishment of confidentiality and data security undertakings with suppliers are applied. Card details are not stored by Loopcode; payment is carried out through the iyzico infrastructure using encrypted communication (TLS) and 3D Secure verification.
8. Rights of the Data Subject
Pursuant to Article 11 of the KVKK, the User has the following rights in relation to themselves by applying to the data controller:
- To learn whether their personal data is processed,
- To request information if their personal data has been processed,
- To learn the purpose of processing and whether the data is used in accordance with that purpose,
- To know the third parties to whom the data is transferred domestically or abroad,
- To request rectification where the data has been processed incompletely or inaccurately,
- To request the erasure or destruction of the data within the framework of the conditions provided for in Article 7 of the KVKK,
- To request that rectification, erasure and destruction operations be notified to the third parties to whom the data has been transferred,
- To object to a result arising against the person themselves through the analysis of processed data exclusively by automated systems,
- To claim compensation for damage suffered as a result of the unlawful processing of the data.
How requests relating to these rights are to be submitted is explained in section 12 of this Policy and in the KVKK Privacy Notice.
9. Cookies
On the marketing site, a cookie consent banner is presented which governs whether Google Analytics is activated; cookie use may be accepted or rejected through this banner. The User's cookie preference is stored in the consent cookie named "lodos-togather-consent". While strictly necessary cookies are used for the core functions of the platform, analytical cookies are activated only subject to the User's approval. The Platform's first-party visitor and session analytics, however, is independent of this cookie consent and is based on legitimate interest (see Section 2.8). Detailed information about the types, purposes and management of cookies is set out in the Cookie Policy.
10. Children's Privacy
Gathin is not directed at persons under the age of 16, and personal data is not knowingly collected from such persons. Any person using the platform declares that they have completed the age of 16. If it is determined that personal data belonging to a person under the age of 16 is being processed, such data is deleted without delay. Anyone who identifies such a situation may contact Loopcode through the contact channels in section 12 of this Policy.
11. Changes
Loopcode may update this Privacy Policy in line with changes in legislation, updates to services or developments in business processes. The current text is published on gathin.com together with its effective date. For material changes requiring the User's explicit consent, consent is obtained separately. The update date shown at the beginning of the text indicates the date of the most recent change.
12. Contact and Applications
The User may submit requests relating to their rights under Article 11 of the KVKK and questions about this Policy to Loopcode through the following channels:
- KVKK / legal contact e-mail: info@loopcode.co
- Support e-mail: info@loopcode.co
- Registered address: Yavuz Sultan Selim Mah. Dr. Sadık Ahmet Cad. No:24 İç Kapı No:1, Fatih/İstanbul, Türkiye
- Telephone: 0 (530) 468 28 68
Applications are assessed and concluded in accordance with the procedures and periods provided for in the Communiqué on the Procedures and Principles of Application to the Data Controller. The channel for submitting misuse or content complaints: info@loopcode.co. For detailed information regarding the processing of personal data, the KVKK Privacy Notice may be consulted.