Last Updated: June 2026
As Picsolv Anonim Şirketi ("Picsolv" or the "Company"), in our capacity as "Data Controller" under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the European General Data Protection Regulation ("GDPR"), we wish to inform you about the processing of your personal data.
1. Data Controller
Data Controller: Picsolv Anonim Şirketi ("Picsolv")
Address: Istanbul, Türkiye
Contact and Requests: hello@picsolv.com
Where Picsolv is subject to the registration obligation with the Data Controllers' Registry (VERBİS) under the KVKK and its secondary legislation, it completes and keeps that registration up to date. Your personal data may be processed by Picsolv within the scope set out below.
Roles of the parties: For event photos taken at events and uploaded by the organiser, the data controller is the relevant event organiser; Picsolv processes these photos as a data processor on the organiser's behalf. For the selfie you provide directly through the Picsolv mobile app and the facial biometric template derived from it, however, Picsolv is the data controller.
2. Purposes of Processing Personal Data
Your collected personal data is processed for the following purposes:
- Provision of photo matching, face recognition and image processing services offered through the Picsolv platform,
- Carrying out membership procedures and ensuring the security of your account (e.g. via on-device liveness verification),
- Improving service quality, detecting and resolving system errors,
- Preparing aggregate/statistical reports for event organisers (participant density, estimated demographic distributions, etc.); such demographic figures are statistical estimates that carry a margin of error,
- Fulfilling legal obligations and notifying competent authorities.
3. Personal Data Processed and Collection Methods
Your personal data is collected by automated means in electronic form through the Picsolv mobile application, website, API integrations and cookies.
Data categories processed:
- Identity Information: First name, last name.
- Contact Information: Email, phone.
- Special Category Personal Data (Biometric Data): The reference photo used for face recognition and the irreversible numerical face template (embedding) derived from it.
- Liveness Verification: The liveness challenge that confirms you are a real person is performed locally on your device using Google ML Kit; this data is processed in real time on the device and is not uploaded to or stored on our servers.
- Audiovisual Records: Photos uploaded to the system or taken at events.
- Transaction Security: IP address, device information, log records.
Demographic / emotion estimates: The organiser may be shown estimates such as age range, gender and emotion for faces appearing in event photos. Aggregate/statistical reports (e.g. "~60% of attendees are female, average age 25–34") are anonymous data to the extent they cannot be linked to an individual. The per-face estimates shown when a photo/face is clicked are not anonymous: they are personal inferences derived from facial analysis, at the observational level already visible in the photo; they are not cross-matched with your identity to build profiles, and are shown only to the authorised organiser of the event. Age and gender are processed as ordinary personal data; emotion estimation is processed with additional caution. These inferences are processed under the explicit consent you give for face matching.
4. Legal Bases
Your personal data is processed on the following legal bases set out in KVKK Articles 5 and 6:
- Explicit Consent (KVKK Art. 6/2 · GDPR Art. 9/2-a): Your explicit consent is obtained for the processing of your biometric data (the face template used for face matching) and, where appropriate safeguards are exceptionally unavailable, for the international transfer of your personal data.
- Conclusion and Performance of Contract (KVKK Art. 5/2-c · GDPR Art. 6/1-b): Provision of the core service (showing photos, account management) as required by the membership agreement.
- Legal Obligation (KVKK Art. 5/2-ç · GDPR Art. 6/1-c): Retention of log records as required by Law No. 5651.
- Legitimate Interest (KVKK Art. 5/2-f · GDPR Art. 6/1-f): Analyses and security measures to improve service quality.
5. Transfer of Personal Data
Your personal data may be transferred to:
- Overseas Service Providers: Certain Amazon Web Services (AWS) cloud services (EU – Ireland/Germany; some components in the USA), used to create/store your facial biometric template, store photos, perform demographic/statistical analysis and, on request, image enhancement; and Google Cloud, used solely for non-biometric photo analysis (content/logo detection) and analytics report summaries — Google Cloud does not create or store your facial biometric template. Authentication (phone login) and push notifications are provided through Google Firebase, and web application hosting through Vercel.
- Business Partners: Event organisers (limited to your participation in the relevant event, plus aggregate/statistical reports or photos you have authorised); your facial biometric template is not shared with organisers.
- Public Authorities: Competent public institutions where required by law.
Basis for international transfer: Transfers are made primarily on the basis of appropriate safeguards under KVKK Art. 9 and GDPR Chapter V (an adequacy decision, Board-approved standard contracts / binding corporate rules, or GDPR Standard Contractual Clauses – SCCs). Where such safeguards are exceptionally unavailable, transfers rely on your explicit consent under KVKK Art. 9 and GDPR Art. 49. Transfers to the USA are minimised and supported by additional safeguards.
6. Data Subject Rights (KVKK Article 11 and the GDPR)
Under KVKK Art. 11 and the GDPR (Art. 15–22), you have the right to:
- Learn whether your personal data is processed and, if so, request information (access),
- Learn the purpose of processing and whether it is used accordingly,
- Know the third parties to whom your data is transferred at home or abroad,
- Request rectification of incomplete or incorrect data,
- Request erasure or destruction where the conditions are met (right to be forgotten),
- Request restriction of processing and, under the GDPR, data portability,
- Object to processing — in particular to object to decisions producing adverse effects based solely on automated processing (including face recognition),
- Withdraw your explicit consent and seek compensation for any damage.
Note: Data portability is principally a GDPR right (Art. 20).
7. How to Apply and Lodge a Complaint
To exercise your rights, send your requests to hello@picsolv.com. Requests are concluded free of charge as soon as possible and within thirty (30) days at the latest (a fee per the Board's tariff may apply where the action entails additional cost). If your request is refused or you are dissatisfied with the response, you may file a complaint with the Personal Data Protection Board within thirty (30) days of learning the response and in any case within sixty (60) days of the request. Users under the GDPR have the right to lodge a complaint with the competent supervisory authority.