Privacy Policy

Last Updated: June 2026

1. Introduction and Scope

As Picsolv Anonim Şirketi ("Picsolv" or the "Company"), we attach great importance to the protection of personal data of our users ("User" or "Data Subject") who benefit from the services we provide through the www.picsolv.com website and mobile applications (the "Platform").

This Privacy Policy has been prepared to transparently explain the processes regarding the personal data collected, processed, stored and transferred by Picsolv within the scope of the Turkish Personal Data Protection Law No. 6698 ("KVKK"), the European General Data Protection Regulation ("GDPR") and other applicable legislation.

In particular, due to the AI-powered photo matching, face recognition and image enhancement services offered by Picsolv, detailed information on how your biometric data and visual data are processed is a key focus of this policy.

Roles of the parties: For event photos taken at events and uploaded by the organiser, the data controller is the relevant event organiser; Picsolv processes these photos as a data processor on the organiser's behalf. For the selfie you provide directly through the Picsolv mobile app and the facial biometric template derived from it, however, Picsolv is the data controller.

2. Your Personal Data We Process

Our Company processes your data in the categories set out below by the nature of our services:

2.1. Identity and Contact Information

  • First name, last name.
  • Email address, phone number.
  • Date of birth (where age verification is required).

2.2. Visual and Biometric Data (Special Category Personal Data)

For photo matching and analysis operations that form the basis of Picsolv services:

  • Facial Biometrics: Numerical data containing a mathematical map of your face (face template/embedding) obtained from the "selfie" or reference photos you upload. This data is used to find you in event photos.
  • Photographs: Photos taken at events or uploaded to the system, in which you or other persons appear.
  • Liveness Test Data: Instant facial movement data captured during the camera scanning performed to verify that you are a real person. In our mobile application, this liveness challenge is performed locally on your device using Google ML Kit; this liveness data is processed in real time on the device and is not uploaded to or stored on our servers.

2.3. Transaction and Security Information

  • User ID, password (in hashed form).
  • Log records, IP address, device information (Device ID), browser type.
  • Last login date/time information.

2.4. Event and Behavioural Analytics Data

  • Events you participate in, photos you add to favourites.
  • Photo download and sharing habits.
  • In-platform navigation (clicks, page views).

3. Purposes of Processing Personal Data

Your collected data is processed for the following purposes:

  1. Service Delivery: Scanning faces in event photos with your uploaded selfie using Artificial Intelligence (AI) algorithms running on certain Amazon Web Services (AWS) cloud services, and finding and matching photos that belong to you.
  2. Image Enhancement: Where you request it, enhancing low-resolution or degraded photos using a generative AI image enhancement service. This is an optional feature, provided only at your request.
  3. Security and Verification: Performing liveness checks to secure your account and prevent fake accounts.
  4. Analytics and Reporting: Preparing aggregate/statistical reports for event organisers on participant demographics (estimated age range, gender, etc.) and event interactions. Aggregate/statistical reports (e.g. "~60% of attendees are female, average age 25–34") are anonymous data to the extent they cannot be linked to an individual. The per-face age range, gender and emotion estimates shown when a photo/face is clicked are not anonymous: they are personal inferences derived from facial analysis, at the observational level already visible in the photo; they are not cross-matched with your identity to build profiles, and are shown only to the authorised organiser of the event. Age and gender are processed as ordinary personal data; emotion estimation is processed with additional caution. These inferences are processed under the explicit consent you give for face matching.
  5. Legal Obligations: Keeping log records in accordance with Law No. 5651 and related legislation.

4. Processing of Biometric Data and Use of AI

Picsolv uses advanced artificial intelligence and machine learning technologies to provide the photo matching service.

  • Face Recognition Technology: Your reference photo uploaded to the system is analysed through certain Amazon Web Services (AWS) cloud services and a numerical vector (template) of your face is created. This vector is compared with event photos in our database to find matches.
  • Storage: Instead of your original biometric data (raw face data), encrypted numerical codes derived from it that cannot be converted back into a face image by reverse engineering are stored.
  • Consent: The processing of your biometric data is carried out on the basis of your Explicit Consent in accordance with KVKK Article 6. The explicit consent you give when you start using the application is the legal basis for this processing.

5. Transfer of Personal Data and International Transfer

Picsolv works with technology partners whose servers and infrastructure providers are located abroad in order to provide services to global standards.

  • International Transfer: Your facial biometric template and your photos are stored and processed on Amazon Web Services (AWS - Ireland/Germany/USA) servers with high security standards. Event photos may additionally be processed by Google Cloud services solely for non-biometric features (such as content/logo detection and the generation of analytics reports); Google Cloud is not used to create or store your facial biometric template. These transfers are made primarily on the basis of appropriate safeguards under KVKK Art. 9 and GDPR Chapter V (an adequacy decision, Board-approved standard contracts / binding corporate rules, or GDPR Standard Contractual Clauses – SCCs); where such safeguards are exceptionally unavailable, they rely on your explicit consent. Transfers to the USA are minimized and supported by additional safeguards.
  • Business Partners: With event organisers, only data relating to that event and to which you have allowed access, plus aggregate/statistical reports, is shared; your facial biometric template is not shared with organisers.
  • Authorities: Sharing may be made with authorised public bodies where there is a court order or legal obligation.

6. Data Security

Our Company takes industry-standard measures for the security of your data:

  • All data transfers are carried out with SSL/TLS encryption.
  • Sensitive data (passwords, biometric templates) in databases is stored encrypted.
  • Access rights are restricted and regular security testing is carried out.

7. Data Retention and Deletion

  • Your personal data is retained for as long as your membership continues or for the statutory retention periods provided for in the relevant legislation.
  • When you delete your membership or withdraw your explicit consent, your biometric data and photos are permanently deleted from the system or anonymised, except for log records that must be retained by law.

7.1. Account deletion, removal from live systems and limited archive period

When you delete your account or your photos through the Platform:

  • Your data is immediately removed from live services, event galleries and systems where it is actively processed; it is not used for profiling, marketing, analytics or AI model training (“beyond use”).
  • For legitimate purposes such as potential legal disputes, security incident review and backup integrity, limited technical copies may be held in isolated storage (e.g. a separate S3 prefix or bucket) for up to 30 days, as disclosed in this policy and our privacy notice.
  • After that maximum 30-day period, those copies are automatically and irreversibly deleted via object lifecycle rules. No copies of your face data (biometric template) or photos are retained beyond this period, except for log records that must be kept under law.

8. Your Rights as Data Subject

Under KVKK Article 11 and the GDPR (Art. 15–22), you have the right:

  • To learn whether your data is being processed,
  • To request information if it has been processed,
  • To learn the purpose of processing and whether it is used for that purpose,
  • To know the third parties to whom it has been transferred domestically or abroad,
  • To request correction if processing is incomplete or incorrect,
  • To request deletion or destruction of data (right to be forgotten),
  • To request restriction of processing and, under the GDPR, data portability (GDPR Art. 20),
  • To object to processing — in particular to object to decisions producing adverse effects based solely on automated processing (including face recognition),
  • To withdraw your explicit consent at any time, and to seek compensation for any damage.

To exercise these rights (including the right to request deletion of your data), contact us at hello@picsolv.com.

8.1. How to Apply and Lodge a Complaint

Your requests are concluded free of charge as soon as possible and within thirty (30) days at the latest (a fee per the Board's tariff may apply where the action entails additional cost). If your request is refused or you are dissatisfied with the response, you may file a complaint with the Personal Data Protection Board within thirty (30) days of learning the response and in any case within sixty (60) days of the request. Users under the GDPR also have the right to lodge a complaint with the competent supervisory authority.

9. Contact Us

Data Controller: Picsolv Anonim Şirketi
Address: Istanbul, Türkiye
Email: hello@picsolv.com

Where Picsolv is subject to the registration obligation with the Data Controllers' Registry (VERBİS) under the KVKK and its secondary legislation, it completes and keeps that registration up to date.

For any request regarding your personal data, privacy or this policy, please email us at hello@picsolv.com.