Data Protection (KVKK & GDPR)
Last updated: May 21, 2026
At Neavents Technology Inc., we place great importance on protecting your personal data under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the European Union General Data Protection Regulation (GDPR). This page provides detailed information about our data protection practices.
1. Data Controller
Neavents Technology Inc.
Address: Istanbul, Turkey
Email: info@neavents.com
Your personal data is processed by the data controller identified above, for the purposes and within the legal frameworks described below.
2. Personal Data Processed
Identity Data
• First name, last name
• Venue name and title
Contact Data
• Email address
• Phone number
• Address information
Transaction Security Data
• IP address
• Session information
• Browser and device information
Financial Data
• Payment history
• Subscription information
• Invoice details
Usage Data
• Menu view statistics
• QR code scan data
• Platform usage patterns
3. Legal Basis
Your personal data is processed based on the following legal grounds:
• Performance of a contract (KVKK Art.5/2-c, GDPR Art.6/1-b): Establishing and fulfilling the service agreement
• Legitimate interest (KVKK Art.5/2-f, GDPR Art.6/1-f): Improving service quality, security measures
• Legal obligation (KVKK Art.5/2-ç, GDPR Art.6/1-c): Tax legislation, legal reporting
• Explicit consent (KVKK Art.5/1, GDPR Art.6/1-a): Marketing communications (only with your permission)
4. Data Retention Periods
Your personal data is retained for the duration required by the processing purpose:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of active account + 30 days |
| Payment records | 10 years (tax legislation) |
| Usage statistics | 2 years |
| Session data | 30 days |
| Support requests | 3 years |
Data that has exceeded its retention period is automatically deleted or anonymized.
5. Data Transfers
Your personal data may be transferred to third parties in the following cases:
• Payment service provider: Payment processing, under Standard Contractual Clauses (SCC)
• Infrastructure providers: Cloud server services, GDPR-compliant data centers
• Legal authorities: In case of court order or legal obligation
Your data is transferred to countries that provide adequate protection or where appropriate safeguards are in place.
6. Your Rights (KVKK Article 11 / GDPR Articles 15-22)
As a data subject, you have the following rights:
• Right to information: Learn whether your data is being processed
• Right of access: Request access to your processed data
• Right to rectification: Request correction of incomplete or inaccurate data
• Right to erasure: Request deletion of your data under certain conditions
• Right to restriction: Request limitation of data processing
• Right to data portability: Receive your data in a structured format
• Right to object: Object to processing based on legitimate interest
• Right against automated decision-making: Object to decisions based solely on automated processing
To exercise these rights, contact info@neavents.com. Your request will be responded to within 30 days.
7. Data Security Measures
We implement the following technical and administrative measures to ensure the security of your personal data:
Technical Measures
• TLS 1.3 encrypted data transmission
• AES-256 encrypted data storage
• Web Application Firewall (WAF)
• Regular penetration testing
• Automatic security updates
Administrative Measures
• Employee confidentiality agreements
• Access control and authorization matrix
• Data processing inventory
• Regular training programs
• Data breach response plan
8. Data Breach Notification
In case of a personal data breach:
• The KVKK Board is notified within 72 hours
• Affected individuals are informed as soon as possible
• The scope, impact, and measures taken are reported
• Necessary corrective measures are implemented immediately
9. Applications and Complaints
Application to the Data Controller
Email: info@neavents.com
You may submit your application in writing with identity verification or through other methods determined by the Personal Data Protection Authority.
Right to Complain
If you do not receive a response within 30 days or are not satisfied with the response:
• Turkey: Personal Data Protection Authority (kvkk.gov.tr)
• EU/EEA: You may apply to the competent Data Protection Authority in your country