Privacy Policy
Effective date: 4 October 2026 · Last updated: 4 October 2026
This Privacy Policy explains how personal data is collected, used, shared and retained, and what rights you have, when you use the takvim.in website, its related mobile and embeddable (widget) services and all connected features (together, the “Service”). By using the Service you acknowledge that you have read this policy. If you do not agree with it, please do not use the Service.
1. Data controller
The data controller under Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and, where applicable, the GDPR is AEGONTECH LLC, 8 The Green, Suite B, Dover, DE 19901-3618, United States, the operator of takvim.in. For any privacy or data protection request, write to support@takvim.in or use our contact page.
2. Data we collect
We collect only what we need to provide the Service. You can browse events, venues and blog posts without an account.
2.1. Data you give us
| Category | Examples | When |
|---|---|---|
| Account and identity | Email address, password (stored only in one-way hashed form), username, display name | When you sign up |
| Profile | Bio, profile picture, website, language preference, account type (individual/publisher) | When you fill in your profile |
| Interaction data | Categories, venues, organisations and tags you follow; events you mark as attending | As you use the Service |
| Publisher content | Event, venue and organisation details, images, descriptions and ticket links you add | When you publish as a publisher |
| Publisher application | Application text, organisation name and your relationship to it | When you apply to become a publisher |
| Reports | The text of a complaint about an event | When you report content |
| Correspondence | Name, email address and the content of your message | When you use the contact form |
| Newsletter preference | Email address, the moment you consented, the source of the consent and the version of the text shown, and the date you unsubscribed | When you subscribe to the newsletter |
2.2. Data collected automatically
- Technical and security data: to prevent abuse and excessive requests, an irreversibly hashed value of your IP address, the request time and rate-limit counters. Your raw IP address is not stored in records such as contact form messages.
- Device and log data: browser type, operating system, requested page, error logs and IP address kept in our hosting provider’s server logs for a short time for security and debugging.
- Session data: the authentication information needed to keep you signed in (see “Cookies”).
2.3. Data from third parties
Event, venue and organiser information is compiled from organisers, from public programmes of official bodies and cultural centres, and from publishers. This information concerns organisations and events and is not intended to contain personal data of individuals. If you see data about yourself on an event page, you can ask us to remove it.
2.4. Data we do not collect
We do not ask for or collect your payment card details, ID or passport number, or health, religion, ethnicity or biometric data (special categories of personal data under KVKK art. 6 / GDPR art. 9). Please do not enter such data in profile fields, content or the contact form.
3. Why we process data
- To create, authenticate and manage your account;
- To deliver event, venue and blog content, and to provide recommendations and a personal calendar based on what you follow and your location;
- To run publishing, moderation and the publishing workflow for publishers;
- To answer contact and support requests and review reports;
- To send the newsletter and commercial electronic messages if you consent;
- To keep the Service secure and to prevent fraud, spam, automated abuse and unlawful content;
- To improve the Service and fix errors;
- To comply with legal obligations and to establish, exercise and defend legal claims.
We do not sell your data, do not use it to build advertising profiles and do not share it with third parties for advertising. We do not make decisions that produce legal effects about you based solely on automated processing.
4. Legal bases
| Legal basis (KVKK art. 5/2; GDPR art. 6) | Scope |
|---|---|
| Performance of a contract | Creating an account, signing in, follow/attend features, publisher services |
| Legal obligation | Responding to requests from competent authorities; keeping records required by law |
| Establishment, exercise or defence of a legal claim | Retaining evidence for disputes and claims |
| Legitimate interests | Security, preventing abuse, improving the Service — provided your fundamental rights and freedoms are not harmed |
| Explicit consent | The newsletter and commercial electronic messages, using your location, and any non-essential cookies (if we use them). You can withdraw consent at any time; this does not affect processing carried out before withdrawal. |
5. Cookies and similar technologies
We use only the cookies and browser storage that are strictly necessary for the Service:
- Session cookies: keep you signed in.
- Preference cookies/storage: remember your theme (light/dark) and language.
- On-device storage (localStorage): keeps your recent searches, unfinished event drafts and follow preferences on your device; this data is not sent to our servers and can be cleared from your browser settings.
We do not use advertising, cross-site tracking or behavioural profiling cookies. We therefore do not engage in tracking that a “Do Not Track” signal would apply to. You can block essential cookies in your browser settings, but features such as signing in may then stop working.
6. Location
For features such as “near me”, your browser asks for permission to share your approximate or precise location. If you decline, the rest of the Service keeps working. If you allow it, the location is used to rank nearby events and is not permanently stored against your account. You can withdraw permission at any time in your browser or device settings.
7. Newsletter and commercial electronic messages
The newsletter is entirely optional and is sent only with your explicit consent; the time, source and text version of your consent are stored as proof (Turkish Law No. 6563 on the Regulation of Electronic Commerce and its regulation). You can unsubscribe with one click from the link in every newsletter; the date is recorded and no further commercial messages are sent. Account, security and service messages (such as a password reset) are not commercial messages and may be sent even if you have unsubscribed.
8. Who we share data with
We share your data only in the following cases and only as far as necessary:
| Recipient / service | Purpose | Data shared |
|---|---|---|
| Vercel Inc. | Hosting and delivery of the website | Request logs, IP address, technical data |
| Supabase | Database, authentication and file storage infrastructure | Account, profile, interaction and content data |
| Google (Maps Platform, Geocoding/Places) | Showing maps, address search and placing venues on the map | Browser requests (IP address, map usage), the address/venue text searched |
| Email delivery service (SMTP provider) | Verification, password reset, replies to contact messages and newsletter emails | Email address, name, message content |
| Competent authorities | Legal obligation; a court, prosecutor or regulator request | Data required by the request |
| Corporate transactions | In a merger, acquisition or sale of assets, under the same level of protection | Relevant data |
These service providers process data only on our behalf and on our instructions, to the extent the service requires. Event, venue and organisation details you enter as a publisher, and your profile name, are by nature published publicly.
9. International transfers
The controller is established in the United States, and some of the providers above operate outside Türkiye (notably in the US and Europe), so your personal data may be transferred abroad. Transfers are made in line with KVKK art. 9 and the Regulation on Procedures and Principles on the Transfer of Personal Data Abroad and, for users in the EEA/UK, with Chapter V of the GDPR, using appropriate safeguards such as an adequacy decision, standard contractual clauses, binding corporate rules or — where the law provides — your explicit consent. You can contact us for details of the safeguards used.
10. Retention
| Data | Retention |
|---|---|
| Account and profile data | While your account is open; deleted or anonymised within a reasonable time after you request deletion (copies in backups are deleted within 90 days at the latest) |
| Follow and attendance records | Deleted together with your account |
| Content you published | Until you delete it or your account closes; archived/cached copies of publicly published content may remain visible for a short time |
| Contact form messages | Up to 2 years for the reply process and possible disputes |
| Newsletter consent record | For the duration of the subscription and up to 3 years after unsubscribing, as proof |
| Security and rate-limit records | Short-term (typically a few hours up to 30 days) |
| Server logs | The short period set by the hosting provider (typically 30 days or less) |
| Records required by law | The period required by the relevant legislation |
When the period ends, your data is deleted, destroyed or anonymised.
11. Security
We apply reasonable administrative and technical measures to protect your data: TLS encryption in transit, one-way hashing of passwords, row-level authorisation, role-based access, restricted administrative access and regular backups. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your account password confidential and for not reusing a password from another service.
12. Data breach notification
If we detect that your personal data has been unlawfully obtained by others, we will notify the Turkish Personal Data Protection Board within 72 hours of becoming aware, as required by KVKK art. 12/5, and affected individuals as soon as reasonably possible. Where the GDPR applies, we notify the competent supervisory authority and affected individuals as it requires.
13. Your rights
Under KVKK art. 11 (and, where applicable, the GDPR) you can ask the controller to:
- Confirm whether your personal data is processed and give you information about it;
- Explain the purposes of processing and whether data is used accordingly;
- Identify the third parties to whom data is transferred, in Türkiye or abroad;
- Correct data that is incomplete or inaccurate;
- Have data deleted or destroyed under KVKK art. 7, and have corrections and deletions notified to the third parties to whom the data was transferred;
- Object to a result against you produced by exclusively automated analysis of your data;
- Claim compensation for damage caused by unlawful processing;
- Where the GDPR applies: data portability, restriction and objection, and withdrawal of consent.
You can view and update your profile details on your account page. For other requests, including deletion of your account and data, send a written request that lets us verify your identity to support@takvim.in. We conclude requests free of charge within 30 days at the latest, depending on the nature of the request; if the action needs a separate cost, a fee under the tariff set by the Board may be charged. If you find our answer inadequate, you may complain to the Turkish Personal Data Protection Board within 30 days of learning our reply and in any case within 60 days of your request. If you live in the EU/EEA, you may also lodge a complaint with your local data protection authority.
14. Children
The Service is not an account service aimed at children. You must be at least 16 to create an account and at least 18 to hold a publisher account. If we learn that we have collected account data from a person under 16, we delete the account and related data immediately. If you believe a child under this age has given us data, please contact us. Viewing event and blog content without an account is open to everyone.
15. Third-party sites
The Service may link to third-party sites such as organiser sites, ticketing platforms and social networks. We are not responsible for their privacy practices; we recommend reading their policies before you follow a link.
16. Changes to this policy
We may update this policy to reflect legal, technical or operational changes. The current version is always published on this page and the “Last updated” date above changes. We will notify you of material changes by email to the address associated with your account or within the Service. Continuing to use the Service after a change means you accept the updated policy; for new processing that requires consent, we will ask for your consent separately.
17. Contact
AEGONTECH LLC (takvim.in)
8 The Green, Suite B, Dover, DE 19901-3618, United States
Email: support@takvim.in
Web: takvim.in contact page