KVKK Disclosure Statement

1. Identity of the Data Controller

Pursuant to Law No. 6698 on the Protection of Personal Data (“KVKK”), your personal data is processed by KALKAN DİJİTAL PLATFORM E-TİCARET LİMİTED ŞİRKETİ (“Atolira” or the “Company”) in its capacity as the data controller.

  • Trade Name: KALKAN DİJİTAL PLATFORM E-TİCARET LİMİTED ŞİRKETİ
  • Address: Yakuplu Mah. Hürriyet Bul. Skyport Sitesi Skyport Residence No: 1, Interior Door No: 151, Beylikdüzü 34520 İstanbul, Türkiye
  • Email: info@atolira.com
  • Telephone: 0543 270 73 86
  • Tax Number: 4931528768
  • MERSIS Number: 0123119987300001

2. Scope of the Information Notice

This notice covers visitors to the atolira.com website in its capacity as an Intermediary Service Provider, registered Users, those who create an Event/Workshop participation booking as a guest User without becoming a member, participants in Workshops/Events organized by the Service Provider (Partner), those who contact customer services, those who grant newsletter or commercial communication permissions, those who submit requests through Atolira’s support channels, and prospective Partners.

3. Categories of Personal Data That May Be Processed

  • Identity data: Name, surname, and other identity information required according to the nature of the transaction.
  • Contact data: Email address, telephone number, and communication and support correspondence.
  • Customer transaction data: Participation booking, order, reservation/session, Event information, number of participants, cancellation/refund/postponement requests, Workshop preferences, campaigns, and transaction history.
  • Financial data: Amount relating to the completion of the payment transaction, transaction/reference/order number, refund information, and invoicing data. Credit/debit card numbers, expiration dates, and CVC/CVV security codes are never recorded or stored by Atolira. Payment transactions are carried out directly with the relevant financial institution through the infrastructure of BDDK-licensed payment institutions and/or authorized virtual POS providers under the security of 3D Secure.
  • Transaction security data: IP address, session information, log records, device/browser information, security records, and fraud prevention records.
  • Legal transaction data: Requests, complaints, notices, disputes, official institution correspondence, and legal process records.
  • Marketing data: Commercial communication permission, newsletter subscription, campaign interaction, preferences, and permission records.
  • Visual and audio data: Photographs, videos, and audio recordings taken during Events. This data is processed based on the legal grounds applicable to the specific activity and, where legally required, the explicit consent obtained from the relevant person.
  • Request/complaint and support data: Content submitted through live support, contact forms, email, and the call center; booking cancellation, refund, and date change requests submitted through Atolira’s support channels; and the related correspondence records.

4. Special Categories of Personal Data

Atolira does not intend to process special categories of personal data for its ordinary booking and reservation intermediation activities. However, if health data needs to be declared for participation safety in a particular Workshop or Event—for example, food, botanical, sound/light sensitivities or physical disability conditions relating to gastronomy tastings, plant/soil Workshops, yoga/sports activities, theatre/roleplay activities, or similar areas—the data minimization principle shall be observed, only the necessary data shall be processed, and the appropriate current processing condition stipulated under Article 6 of the KVKK shall be relied upon. Where explicit consent is required, it shall be obtained separately from the KVKK Information Notice.

5. Methods of Collecting Personal Data

Personal data may be collected through the website and mobile-compatible interfaces, membership and guest checkout forms, booking and reservation modules, payment and refund processes, email, live support, contact forms, customer services, Partner and group Event applications, cookies and similar technologies, social media interactions, and other physical or electronic channels permitted by legislation, by fully or partially automated means or by non-automated means, provided that the data forms part of a data recording system.

6. Processing Purposes and Legal Grounds

Processing Purpose

Main Data Categories

Main Legal Basis

Membership, guest checkout, creation of a participation booking, and performance of the service

Identity, contact, customer transaction

KVKK Art. 5/2-c – establishment or performance of a contract

Payment, refund, invoicing, and accounting

Finance, customer transaction, identity

LPPD Art.5/2-a and ç – legal obligation / legal requirement

Customer support, request, and complaint management

Contact, customer transaction, legal transaction

KVKK Art. 5/2-c, e, and f

Information security, logging, and fraud prevention

Transaction security, customer transaction

KVKK Art. 5/2-ç, e, and f

Management of legal disputes and requests from official institutions

Legal transaction, identity, contact, customer transaction

KVKK Art. 5/2-a, ç, and e

Management of Partner/Event operations

Identity, contact, customer transaction

KVKK Art. 5/2-c and f

Newsletter, campaigns, advertising, and personalized marketing

Contact, marketing, cookie data

Explicit consent and/or other applicable legal conditions according to the relevant activity; commercial electronic communication permissions are managed separately

Statistics, analysis, and service development

Transaction security, usage/cookie data

Legitimate interest according to the nature of the data or, where necessary, explicit consent

Use of Event visual and audio recordings for promotional purposes

Visual/audio data

Legal ground separately determined according to the specific activity; separate explicit consent where necessary

7. Explicit Consent and Commercial Communications

The obligation to provide information and explicit consent processes under the KVKK are separate from each other. Reading the Information Notice or granting consent to marketing activities that are not necessary for the provision of the service shall not be made a condition of benefiting from the basic service. Commercial electronic communication permissions are obtained separately in accordance with the relevant legislation and may be withdrawn. A separate selection option is provided through the cookie preference panel to the extent required for marketing and analytics cookies.

8. Domestic Transfer of Personal Data

Your personal data may be transferred to the following third parties located within Türkiye in accordance with the personal data processing conditions specified in Article 8 of the KVKK and only to the extent required by the processing purpose, in line with the data minimization principle:

  • Service Providers (Partner/Instructor): To the relevant Event owner for the purpose of verifying the participation booking, providing admission to the Event venue/preparing participant lists, and issuing the service invoice;
  • Financial Institutions and Payment Providers: To BDDK-licensed payment institutions, virtual POS providers, and banks for the secure completion of payment and refund transactions;
  • Financial and Legal Advisers: To financial advisers, authorized integrators, and legal advisers for statutory accounting processes, issuing electronic documents/e-invoices, and fulfilling legal obligations;
  • Technical and Operational Service Providers: To information technology and call/support service providers for maintaining the website infrastructure, delivering emails, and carrying out customer support processes;
  • Public Institutions and Organizations: To authorized administrative and judicial authorities and legally authorized public institutions in accordance with statutory obligations and official requests.

9. Cross-Border Transfer of Personal Data

Your personal data may be transferred abroad if the data centers of cloud server, email delivery, analytics, customer communication, security, or similar technical service providers used by Atolira when providing its Platform infrastructure are located abroad. Such transfers shall be carried out in accordance with the current Article 9 of the KVKK, within the framework of an adequacy decision, appropriate safeguards, or incidental transfer circumstances regulated under the Law, and shall be limited solely to technical requirements and the requirements of the service.

10. Retention Periods and Disposal

Personal data shall be retained for the period required by the relevant processing purpose and for the minimum retention periods stipulated under the applicable legislation. When determining the retention period, the type of transaction, continuation of the contractual relationship, tax and commercial legislation, consumer transactions, limitation periods for disputes, information security requirements, and the data controller’s legal obligations shall be taken into account. When the processing purpose and legal ground cease to exist, the data shall be deleted, destroyed, or anonymized during the first periodic disposal period.

11. Data Security

  • Authorization and access controls, strong passwords, and account security practices
  • SSL/TLS and appropriate encryption methods
  • Logging, security monitoring, and detection of unusual transactions
  • Data security and confidentiality obligations with Service Providers
  • Avoiding unnecessary data collection and limiting access according to duties
  • Backup, incident response, and data breach procedures
  • Compliance with the current KVKK notification periods upon becoming aware of a personal data breach

12. Rights of the Data Subject Under the KVKK

Pursuant to Article 11 of the KVKK, data subjects have the right to learn whether their personal data has been processed; request information if it has been processed; learn the purpose of processing and whether it has been used in accordance with that purpose; know the third parties to whom it has been transferred domestically or abroad; request the correction of incomplete or incorrectly processed data; request its deletion or destruction where the relevant conditions have been met; request that these actions be communicated to third parties to whom the data has been transferred; object to an adverse outcome arising as a result of its analysis exclusively through automated systems; and request compensation for damages arising from unlawful processing.

13. Application Procedure to the Data Controller

Requests under the KVKK may be submitted in writing, by registered electronic mail (KEP), secure electronic signature, mobile signature, or through the email address previously provided by the relevant person to Atolira and registered in Atolira’s systems. Applications shall be concluded as soon as possible according to the nature of the request and within no more than 30 days.

  • Postal/In-Person Application Address: Yakuplu Mah. Hürriyet Bul. Skyport Sitesi Skyport Residence No: 1, Interior Door No: 151, Beylikdüzü 34520 İstanbul, Türkiye
  • Email: info@atolira.com

14. Data Relating to Children

For Workshops and Events intended for children, personal data relating to the child shall be processed only to the extent necessary for the performance of the service and safe participation. Parent/guardian information and consent may be requested depending on the child’s age and the nature of the Event. The direct collection of data from children for marketing purposes and unnecessary profiling activities shall be avoided.

15. Updates and Entry into Force of the Notice

Atolira may update this Information Notice due to changes in legislation, Board decisions, technical infrastructure, or data processing activities. The current notice shall enter into force on the date it is published on atolira.com.