KVKK
SKREEN Personal Data Protection Notice
Personal data protection notice under Turkish Law No. 6698 (KVKK) for Skreen website, apps, kiosks, and event services.
July 1, 2026
SKREEN Personal Data Protection Notice
1. Purpose and Scope
This Personal Data Protection Notice (“Notice”) has been prepared to inform data subjects about the processing of personal data through the Skreen-branded website, web application, mobile application, kiosks, photo and video booths, AI-powered image generation services, printing, digital delivery, gallery, payment, and related services, in accordance with Turkish Personal Data Protection Law No. 6698 (“KVKK”). This Notice applies to:
- Businesses, agencies, event teams, and organizational users who create an account on or use the Skreen platform
- Participants who create photographs, videos, or AI-generated content through Skreen devices or digital experiences
- Visitors to the Skreen website
- Individuals who submit support, communication, or information requests
2. Data Controller
The data controller under the KVKK is:
SWG PHOTOBOOTH YAZILIM SANAYİ VE TİCARET LİMİTED ŞİRKETİ
Address: Fulya Mah. Yeşilçimen Sk. Polat Tower Residence No: 12, Unit No: 430, Şişli / Istanbul, Türkiye
Email: info@skreen.tech
Brand: Skreen / Skreen Tech
Where Skreen is used as part of a customized experience on behalf of an event owner, brand, agency, venue operator, or organizer, that party may act as a separate data controller to the extent that it determines the purposes and means of processing participant data.
In such cases, Skreen may act as a data processor and process personal data in accordance with the instructions of the relevant organization. Skreen may also act as a data controller in relation to activities including payment processing, platform security, technical support, compliance with legal obligations, and the management of its own services.
3. Personal Data Processed
Depending on how the Skreen services are used, the following categories of personal data may be processed.
3.1. Identity and contact information
- First name and surname
- Email address
- Telephone number
- Company or organization name
- Authorized representative information
- Information provided through support and communication requests
3.2. Account and customer transaction information
- User account and organization details
- User roles and authorization information
- Membership, contract, and subscription information
- Order, service, invoice, and transaction records
- Preferred language, experience, and delivery settings
- Notice, permission, and consent records
3.3. Visual and audio data
- Photographs taken or uploaded by the user
- Video and audio recordings
- Images processed or generated using artificial intelligence
- Information relating to templates, filters, frames, and effects
- Content prepared for printing or digital delivery
Skreen does not use photographs or images for biometric identity verification or for the purpose of uniquely identifying individuals through biometric methods. However, photographs and videos that make an individual identified or identifiable constitute personal data.
3.4. Payment and financial transaction information
- Payment amount and date
- Transaction status
- Order and transaction number
- Payment terminal or device information
- Refund and payment dispute records
Payments may be processed through PAVO and the relevant banks or payment service providers. Skreen does not store full credit card or debit card numbers or card security codes.
3.5. Technical and usage data
- IP address
- Device, browser, and operating system information
- Application version
- Session and login records
- Transaction dates and usage activity
- Error, performance, and crash records
- Security and access logs
- Information collected through cookies and similar technologies
3.6. Marketing and preference data
- Commercial electronic communication preferences
- Campaign and announcement permissions
- Language, theme, and interface preferences
- Communication history
Marketing communications are only sent where the required permissions have been obtained.
4. Purposes of Processing Personal Data
Personal data may be processed for the following purposes:
- Creating user accounts and organizational workspaces
- Performing user authentication and authorization procedures
- Providing photography, video, AI transformation, printing, and digital delivery services
- Applying templates, filters, effects, or experiences selected by the user
- Creating event galleries and sharing pages
- Processing and verifying payments
- Reviewing refund, duplicate payment, and technical issue requests
- Managing contracts, subscriptions, invoices, and accounting processes
- Operating the platform and ensuring platform security
- Preventing misuse and unauthorized access
- Detecting errors and performance issues
- Providing technical support and customer services
- Improving service quality and user experience
- Conducting statistical and aggregated usage analyses
- Preventing fraud and unlawful use
- Fulfilling legal obligations
- Establishing, exercising, or protecting legal rights
- Responding to requests from authorized institutions and authorities
- Sending campaigns, product announcements, and commercial electronic communications where separate permission has been provided
Photographs, videos, or other user content will not be used in Skreen’s advertising or promotional activities unless the user has provided separate, specific permission.
5. Legal Grounds for Processing
Personal data may be processed on the basis of the legal grounds set out under Article 5 and, where applicable, Article 6 of the KVKK, including:
- Processing being directly necessary for the establishment or performance of a contract
- Processing being necessary for the data controller to fulfill its legal obligations
- Processing being necessary for the establishment, exercise, or protection of a legal right
- Processing being necessary for the legitimate interests of Skreen, provided that the fundamental rights and freedoms of the data subject are not harmed
- Processing being expressly required by law
- Personal data having been made public by the data subject and being processed in accordance with the purpose for which it was made public
- Explicit consent of the data subject where no other legal ground applies
Separate consent mechanisms may be used for marketing communications, optional features, and other processing activities requiring explicit consent. Reading or acknowledging this Notice does not, by itself, constitute explicit consent.
6. Methods of Collecting Personal Data
Personal data may be collected through:
- The Skreen website and web application
- Mobile applications
- Photo and video booths
- Kiosks and event devices
- Cameras, microphones, and printing systems
- User registration and login screens
- Payment terminals
- Event galleries and sharing pages
- Support forms and email correspondence
- Cookies, log records, and similar technologies
- Information provided by an event owner, venue, agency, brand, or organizer
Personal data may be collected through fully or partially automated means or through non-automated means, provided that the processing forms part of a data recording system.
7. Transfer of Personal Data
Personal data may be transferred, only to the extent necessary for the provision of services and the purposes described above, to the following categories of recipients:
- Event owners, agencies, brands, organizers, or venue operators managing the relevant Skreen experience
- PAVO, banks, and payment service providers
- Server, hosting, cloud storage, and infrastructure providers
- Artificial intelligence processing service providers
- Email, SMS, digital delivery, and gallery service providers
- Printing, printer, and device integration providers
- Software development, technical support, maintenance, security, and error monitoring providers
- Accounting, legal, audit, and consultancy service providers
- Authorized public institutions, courts, enforcement offices, and law enforcement authorities
Transfers are limited to the personal data necessary for the relevant service or legal obligation, in accordance with the principle of data minimization.
8. Artificial Intelligence Processing and International Data Transfers
Where a user selects an AI-powered photograph or content transformation, the photograph, selected template, and technical information necessary to generate the requested output may be transferred to artificial intelligence and cloud infrastructure providers, including fal.ai. The servers of these service providers may be located outside Türkiye. Therefore, use of AI-powered features may involve the transfer of personal data abroad. International data transfers are carried out in accordance with Article 9 of the KVKK, relying on an applicable transfer mechanism, including:
- The existence of an adequacy decision
- The use of standard contractual clauses or another appropriate safeguard
- Another valid international transfer condition provided under applicable law
Where explicit consent is legally required, a separate consent mechanism will be presented after informing the data subject about the destination country or recipient category, the purpose of the transfer, and the possible risks. Where the AI feature is optional, users may choose a standard photography or other non-AI experience instead.
9. Retention Periods
Personal data is retained only for as long as necessary for the purpose for which it was processed and for the statutory retention periods required under applicable legislation. Photographs, videos, and AI-generated outputs may not be stored at all, depending on the technical setup of the relevant event. Where storage is necessary, such content is retained for delivery, printing, technical support, and completion of the service for a maximum period of 30 days. At the end of this period, the content is deleted, destroyed, or anonymized in a manner that cannot be reversed. Where an event owner or organizer acts as an independent data controller and determines a different retention period, that period and the relevant processing purpose must be separately explained in the organization’s own privacy notice. Account, contract, payment, invoice, accounting, and legal transaction records may be retained throughout the contractual relationship and thereafter for the periods required under applicable legislation. Consent and commercial communication permission records may be retained by taking into account the withdrawal of consent and applicable limitation periods.
10. Personal Data Relating to Children
Skreen is not designed as a service directed specifically at children. Users under the age of 18 should use Skreen under the supervision and with the permission of their parent or legal guardian. Children under the age of 13 should not use the service independently. The adult uploading or creating content involving a child, together with the relevant event owner or organizer, is responsible for obtaining the necessary permissions for the processing of the child’s photograph, video, or other content. Parents or legal guardians who believe that their child’s personal data has been processed without the necessary permission may contact Skreen at info@skreen.tech to request deletion.
11. Personal Data Security
Skreen implements appropriate technical and organizational measures to:
- Prevent the unlawful processing of personal data
- Prevent unlawful access to personal data
- Prevent personal data from being lost, altered, or disclosed to unauthorized persons
- Ensure that personal data is stored securely
Data security, confidentiality, and processing only in accordance with instructions are addressed in relationships with relevant service providers. However, absolute security cannot be guaranteed for any internet transmission, electronic storage system, or digital infrastructure.
12. Rights of Data Subjects
Under Article 11 of the KVKK, data subjects have the right to:
- Learn whether their personal data is being processed
- Request information where their personal data has been processed
- Learn the purpose of the processing and whether the data is being used in accordance with that purpose
- Learn the third parties to whom personal data has been transferred in Türkiye or abroad
- Request the correction of incomplete or inaccurate personal data
- Request the deletion or destruction of personal data under the conditions specified in the KVKK
- Request that correction, deletion, or destruction procedures be communicated to third parties to whom the personal data has been transferred
- Object to an outcome against the person arising from the analysis of processed data exclusively through automated systems
- Claim compensation for damages arising from the unlawful processing of personal data
13. Applications to the Data Controller
Requests under the KVKK may be submitted:
By sending a signed application explaining the identity of the applicant and the relevant request to:
-
SWG PHOTOBOOTH YAZILIM SANAYİ VE TİCARET LİMİTED ŞİRKETİFulya Mah. Yeşilçimen Sk. Polat Tower ResidenceNo: 12, Unit No: 430, Şişli / Istanbul, Türkiye By sending an email from an email address previously provided to Skreen by the data subject and registered in Skreen’s systems to:
-
info@skreen.tech Applications should include:
-
First name and surname
-
Signature, where the application is made in writing
-
Information sufficient to verify the applicant’s identity
-
Address for notifications
-
Registered email address and telephone number, where applicable
-
Details of the request
-
Information and documents supporting the request
Skreen may request additional information or documentation to verify the applicant’s identity before responding to the application. Applications will be processed as soon as possible and no later than 30 days, depending on the nature of the request. Where processing the request requires an additional cost, fees may be charged in accordance with the tariff determined by the Turkish Personal Data Protection Board.
14. Changes to This Notice
This Notice may be updated in line with changes in legislation, decisions of the Turkish Personal Data Protection Board, changes in service providers, or changes to Skreen services. The current version will be published on the Skreen website or within the relevant application. Where material changes are made to the purposes of processing personal data, data subjects will also be informed through appropriate methods.
15. Contact
For questions concerning personal data protection, content deletion requests, and applications under the KVKK:
- Email: info@skreen.techAddress: Fulya Mah. Yeşilçimen Sk. Polat Tower Residence No: 12, Unit No: 430, Şişli / Istanbul, Türkiye

