Privacy Notice

1. Who We Are

For the purposes of Turkish Personal Data Protection Law No. 6698 (the “KVKK”), the data controller is [[FULL LEGAL NAME]], trading under the Solara Event brand (“Solara”, “we”, “us” or “our”). Where the EU General Data Protection Regulation (“EU GDPR”) or United Kingdom data protection law applies to a particular activity, Solara acts as the controller for that activity unless we tell you otherwise.

2. Scope of This Notice

This Notice explains how we collect and use personal data when you visit our website, submit an enquiry or quotation form, communicate with us by telephone, e-mail, WhatsApp or social media, request event-planning information, receive a proposal, or become a client. Separate notices may apply to employees, job applicants, suppliers, event staff, or guests appearing in event photography.

This Notice provides information; it is not consent. Where consent is legally required — for example, for optional cookies, certain marketing communications, or a particular use of photographs — we will request it separately and provide a genuine choice.

3. Personal Data We May Collect

4. How We Collect Personal Data

  • Directly from you through website forms, telephone calls, e-mail, WhatsApp, social media, meetings, proposals, contracts and payment records;
  • From a person authorised to organise an event or make an enquiry on behalf of a couple, family, company or group;
  • Automatically through website logs, cookies, Google Tag Manager-managed tags and similar technologies;
  • From venues, hotels, suppliers, photographers, payment or accounting providers where necessary to deliver or administer an agreed service;
  • From publicly available sources where relevant and lawful, such as a public business profile or a review you choose to publish.

5. Purposes and Legal Bases

We only process personal data for a defined purpose and with a lawful basis. The basis depends on the activity and the law that applies.

Under the KVKK, these activities may rely on explicit consent or the processing conditions in Articles 5 and 6, including necessity for a contract, compliance with a legal obligation, establishment or protection of a right, and legitimate interests that do not harm fundamental rights. Where EU or UK law applies, the corresponding bases may include consent, steps before or performance of a contract, legal obligation, and legitimate interests subject to the required balancing test.

6. When You Provide Data About Someone Else

If you give us personal data about a partner, guest, employee, speaker or another person, you must be authorised to do so and must provide any information required by law. Share only what is necessary. We may provide a separate notice directly to that person where required and reasonably possible.

7. Who We May Share Data With

Depending on the service requested, we may share limited personal data with:

  • Solara personnel and authorised event teams who need the information for their role;
  • Venues, hotels, caterers, decorators, entertainment providers, photographers, transport companies and other suppliers selected for the event;
  • Website hosting, cloud, e-mail, communications, form, CRM, analytics, security and technical-support providers;
  • Banks, payment providers, accountants, auditors, insurers and professional advisers;
  • Public authorities, courts, regulators or law-enforcement bodies where disclosure is required or legally justified;
  • A potential buyer, investor or successor in a legitimate corporate transaction, subject to appropriate confidentiality and legal safeguards.

We do not sell personal data. Suppliers receive only the information reasonably required for the relevant purpose and are expected to use it lawfully and securely.

8. International Processing and Transfers

Solara is based in Turkiye, so information submitted by an overseas visitor will be received and processed in Turkiye. Some technology providers or their support teams may also process data in the European Economic Area, the United Kingdom, the United States or other countries.

Where an onward transfer is subject to the KVKK, EU GDPR or UK data-protection transfer rules, Solara will use a lawful transfer mechanism and any required supplementary safeguards, such as an adequacy decision, approved standard contractual clauses or another permitted mechanism. The exact mechanism depends on the provider, destination and circumstances. Contact us if you would like available information about the relevant safeguard.

9. Retention

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, contractual, security and dispute requirements. The following are working retention periods and must be aligned with Solara’s final internal schedule:

At the end of the relevant period, data is deleted, destroyed or anonymised unless a lawful reason requires continued storage. Backup copies may remain until they are overwritten in the normal backup cycle and are protected from routine use.

10. Cookies and Similar Technologies

We use necessary technologies to operate and protect the site. Optional analytics or marketing technologies are handled through the cookie banner and preference centre. Please read the separate Cookie Policy for providers, purposes, typical durations and controls.

11. Automated Decisions

Solara does not currently make decisions about event enquiries or clients solely by automated means where the decision produces legal or similarly significant effects. If this changes, we will provide the information and safeguards required by applicable law before using such a process.

12. Your Rights

12.1 Rights under the KVKK

  • Learn whether your personal data is being processed and request information about the processing;
  • Learn the purpose of processing and whether the data is used consistently with that purpose;
  • Know the third parties in Turkiye or abroad to whom personal data has been transferred;
  • Request correction of incomplete or inaccurate data and notification of the correction to relevant recipients;
  • Request deletion or destruction where the legal conditions are met and notification to relevant recipients;
  • Object to a result arising against you through analysis exclusively by automated systems;
  • Request compensation if you suffer damage because personal data has been processed unlawfully.

12.2 Additional EU/EEA or UK rights, where applicable

  • Access, rectification and erasure;
  • Restriction of processing and data portability where the legal conditions are met;
  • Objection to processing based on legitimate interests and an absolute right to object to direct marketing;
  • Withdrawal of consent at any time, without affecting processing already carried out lawfully;
  • Rights relating to qualifying automated decision-making;
  • A complaint to the competent supervisory authority, including the ICO in the UK where UK law applies.

These rights are not absolute. We may refuse or limit a request where the law permits and will explain the reason when required.

13. How to Exercise Your Rights or Make a Privacy Complaint

Send your request or complaint to [email protected], by post to 2066 Sokak No: 12, Caglayan Mahallesi, Dudenpark Evleri, Block B, Apartment 26, Muratpasa 07235, Antalya, Turkiye, through the Privacy Rights Request Form, or through another legally permitted channel. Please write “Privacy Request” or “Data Protection Complaint” in the subject line where practical.

We may ask for information reasonably necessary to confirm identity or authority. Do not send a full identity-document copy unless we specifically request it and explain a secure method. Under the KVKK, applications are answered as soon as possible and no later than 30 days. Where EU or UK law applies, the relevant statutory response period applies, subject to any permitted extension.

Where the UK data-protection complaint procedure applies, we will provide a clear complaint channel, acknowledge receipt within 30 days, take appropriate steps without undue delay, keep you reasonably informed, and communicate the outcome without undue delay. This complaint process is separate from the deadline for responding to a formal rights request.

14. Security

We apply reasonable administrative, contractual and technical measures intended to protect personal data. No internet transmission or storage system is completely secure. Please avoid sending unnecessary identity, payment or sensitive details through ordinary e-mail or open message fields.

15. Children

The website is directed to adults arranging events and is not intended for children to submit enquiries independently. If event planning requires information about a child, it should be provided by or with the authority of a parent, guardian or other authorised adult and limited to what is necessary.

16. Changes and Contact

We may update this Notice when our services, providers or legal obligations change. The current version will show its effective date. Questions may be sent to [email protected] or raised by telephone on +90 532 373 51 11.