PRIVACY AND PERSONAL DATA PROTECTION POLICY
As the Social and Economic Perspective Association (“SEPDER”, the “Association” or “we”), we attach great importance to the privacy and security of personal data.
This Privacy and Personal Data Protection Policy (“Policy”) has been prepared to explain the scope in which personal data is processed in relation to individuals who visit the sepder.org website operated by SEPDER, create a user account through the website, apply to congresses, symposiums, conferences and other academic activities, submit papers, participate in events, act as reviewers, serve on academic or scientific committees, contact us through our communication channels, or otherwise use SEPDER’s digital services.
SEPDER processes personal data in accordance with applicable legislation, particularly Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”), and adopts the principles of processing personal data lawfully and fairly, for specific, explicit and legitimate purposes, in a manner that is relevant, limited and proportionate to the purposes for which it is processed, and retaining such data only for the period necessary.
1. Data Controller
Within the scope of Law No. 6698 on the Protection of Personal Data, the data controller is:
Social and Economic Perspective Association (SEPDER)
Address: Fatih, Istanbul, Türkiye
E-mail: info@sepder.org
Phone: +90 (554) 946 23 86
Website: sepder.org
SEPDER acts as the data controller determining the purposes and means of processing personal data.
For certain technical operations carried out through the website, service providers offering hosting, e-mail, information technology infrastructure, security, data storage and similar services may act as data processors within the framework of applicable legislation.
2. Scope of the Policy
This Policy covers personal data processing activities carried out during visits to sepder.org, creation of user accounts, login procedures, applications to congresses and symposiums, submission of abstracts or full-text papers, academic evaluation processes, submission of payment information and payment receipts, use of the contact form, communication with SEPDER via e-mail or telephone, participation in academic events and use of other services available on the website.
Websites, social media platforms or other digital services operated by third parties and linked from SEPDER’s website are subject to their own privacy policies. SEPDER is not responsible for the independent data processing activities of such third parties.
3. Categories of Personal Data That May Be Processed
Identity Information
Name, surname and, where necessary, other information used to identify an individual within application or event processes may be processed.
SEPDER does not request Turkish Republic identification numbers, passport numbers or similar official identity information through the website unless required by the nature of the service. Where such information becomes necessary due to an international event, invitation letter, travel process or a legal obligation, the relevant individual shall be separately informed.
Contact Information
E-mail address, telephone number and other contact information provided by the relevant individual for the purpose of communicating with SEPDER may be processed.
Such information may be used to provide information regarding applications, communicate reviewer evaluation results, announce programme or event changes, deliver participation certificates and respond to requests submitted by the relevant person.
Academic and Professional Information
Title, academic degree, institution of employment or education, department, country, field of expertise and other academic or professional information voluntarily provided during the application process may be processed.
Such data may particularly be used for the evaluation of congress and symposium applications, preparation of programmes, creation of academic records and management of scientific publication processes.
Congress, Symposium and Application Information
Information regarding the event applied for, type of participation, number of submissions, paper title, abstract, keywords, study file, presentation details, names of co-authors, explanations, application dates, evaluation results and other application-related information may be processed.
Where submitted paper files contain personal data, such data may also be processed within the scope of application evaluation and academic procedures.
Co-Author Information
Where an academic paper has multiple authors, the applicant may provide SEPDER with the names, surnames, institutions, academic titles and similar information of other authors.
The applicant is expected to ensure that third parties whose personal data is shared with SEPDER are duly informed where required and that the necessary legal conditions for such sharing are fulfilled.
User Account Information
Where a user account is created on the website, name, surname, e-mail address, telephone number, institution, title, country information, account creation and update information, and records relating to account security may be processed.
Appropriate technical methods should be used to securely store passwords created by users. SEPDER personnel are not expected to be able to view user passwords in plain text or request users to disclose their passwords.
Payment and Financial Transaction Information
Within the scope of congresses, symposiums or other paid activities, payment receipts, payment dates, amount paid, transaction description, application reference number and limited bank transaction information appearing on the receipt may be processed.
SEPDER does not request or store bank or credit card numbers, CVV/CVC security codes or card passwords through its current website.
Where payments are subsequently processed through a third-party payment service provider, such provider may independently act as a data controller or data processor in relation to its own activities, and users may also be subject to the relevant payment provider’s privacy terms.
Communication and Request Information
Where SEPDER is contacted through the contact form, e-mail, telephone or other channels, name and surname, e-mail address, telephone number, message subject, message content, requests, complaints, suggestions and correspondence records may be processed.
Transaction Security and Technical Data
For the purpose of ensuring website security, limited technical data such as IP address, date and time of access, session records, browser and device information, error logs, security logs, user session data and similar information may be processed.
Such information may particularly be used to prevent unauthorised access, detect attacks, resolve technical problems and ensure system security.
Cookie and Preference Information
The website may use strictly necessary cookies and, subject to user preference, cookies used for statistics, performance or similar purposes.
Cookie preferences, consents granted or withdrawn by users and related technical records may be retained where necessary.
Visual and Audio Recordings
Where congresses, conferences, symposiums, panels or similar events organised by SEPDER are photographed, video recorded, broadcast online or used in the event archive, participants’ image or voice recordings may be processed.
Where the processing of image or audio recordings constitutes personal data processing, the necessary information shall be provided depending on the nature of the processing, and explicit consent shall be obtained where required by applicable legislation.
4. Methods of Collecting Personal Data
Personal data may be collected electronically or, where necessary, physically through membership and application forms on SEPDER’s website, user accounts, congress or symposium applications, uploaded Word or PDF files, payment receipts, contact forms, e-mail correspondence, telephone calls, academic evaluation processes, event records and technical records generated during use of the website.
Personal data may be obtained directly from the relevant individual or, in the case of multi-author academic works, from the corresponding author, scientific or organising committees, collaborating academic institutions or other sources permitted under applicable law.
5. Purposes of Processing Personal Data
SEPDER may process personal data for the purposes of creating and managing user accounts, receiving congress and symposium applications, recording and monitoring applications, conducting academic evaluations of papers and studies, managing peer review procedures, communicating with participants, notifying acceptance or rejection results, preparing congress programmes, managing event organisation, managing online or in-person participation processes, verifying payment and registration information, issuing participation certificates, conducting academic publication and proceedings processes, responding to user requests, improving SEPDER activities, ensuring website security, preventing misuse and unauthorised access, fulfilling legal obligations and establishing, exercising or protecting legal rights.
Personal data is not used for purposes incompatible with the purposes for which it was collected.
Where a new personal data processing purpose arises, the relevant individual shall be duly informed and, where required by applicable legislation, separate explicit consent shall be obtained.
6. Legal Grounds for Processing Personal Data
SEPDER does not process personal data solely on the basis of explicit consent in every case.
Personal data may be processed based on one of the appropriate legal grounds regulated under Article 5 of the KVKK, including where processing is directly related to the establishment or performance of a contract, is necessary for the data controller to fulfil a legal obligation, is necessary for the establishment, exercise or protection of a right, or is necessary for SEPDER’s legitimate interests provided that the fundamental rights and freedoms of the relevant person are not harmed.
Where explicit consent is required as the applicable legal ground, it shall be obtained separately, for a specific matter, based on adequate information and through the individual’s freely given will.
Where processing is based on explicit consent, the relevant individual may withdraw such consent at any time with prospective effect.
7. Special Categories of Personal Data
SEPDER does not systematically seek to collect users’ health data, biometric data, genetic data, religious or philosophical beliefs, political opinions or similar special categories of personal data within standard membership and congress application processes conducted through the website.
Applicants are expected not to include special categories of personal data that are unnecessary for the application in academic studies or other documents submitted to SEPDER.
Where academic studies contain special category or sensitive personal data belonging to third parties, the submitting author or authors are responsible for ensuring that the study has been prepared in compliance with relevant ethical, legal and academic obligations.
Where SEPDER is exceptionally required to process special categories of personal data, such processing shall be carried out in compliance with the conditions set out in Article 6 of the KVKK and with appropriate technical and administrative security measures.
8. Academic Evaluation and Peer Review Process
Papers submitted to academic events organised by SEPDER may be shared with reviewers, scientific committees or evaluation boards for the purpose of scientific evaluation.
Where double-blind peer review is applied, reasonable technical and administrative measures shall be implemented to conceal the identities of authors and reviewers from one another.
However, where submitted files contain names, institutional information, file metadata or other information directly identifying the author, the anonymisation process may be affected. Authors are therefore expected to prepare their files in accordance with the specified academic requirements where blind review applies.
9. Disclosure of Personal Data in Academic Programmes and Publications
Where a paper is accepted, the author’s name and surname, academic title, affiliated institution, country, paper title, session details and similar academic information may be published in the congress or symposium programme.
Where abstracts or full-text papers submitted for publication are published in congress proceedings, abstract books, on the website or in other academic publications, the author’s name, institutional information and academic data associated with the work may become publicly available.
The nature and scope of such publication activities may also be separately explained in the application and publication terms of the relevant event.
10. Parties to Whom Personal Data May Be Transferred
Personal data may be shared, to the extent required by the purpose of processing and in accordance with applicable legislation, with SEPDER’s authorised employees and managers, congress and symposium organising committees, scientific committees, reviewers, collaborating universities and academic institutions, service providers contributing to event organisation, hosting and IT service providers, e-mail and data storage service providers, financial advisors and legal consultants, banks and payment institutions, and authorised public institutions and authorities.
Transfers shall be limited to personal data necessary for the relevant purpose, and it is essential that the receiving parties process the data with appropriate security measures.
SEPDER does not sell personal data to third parties for commercial purposes.
11. Transfer of Personal Data Abroad
Where congresses and symposiums organised by SEPDER are held abroad, cooperation is carried out with universities or academic organisations located abroad, or services such as servers, e-mail systems, cloud storage, video conferencing or similar technical services located abroad are used, personal data may be transferred outside Türkiye.
Such transfers shall only be carried out where one of the conditions specified under Article 9 of the KVKK and the relevant secondary legislation is satisfied.
Depending on the nature of the transfer, appropriate mechanisms such as an adequacy decision, appropriate safeguards, standard contractual clauses or other legal transfer mechanisms provided under applicable legislation shall be applied.
Where explicit consent is legally required, the relevant person’s explicit consent shall be obtained before personal data is transferred abroad.
12. Cookies and Similar Technologies
SEPDER’s website may use strictly necessary cookies to ensure the proper and secure operation of the website.
Cookies required for session management, security and the provision of services explicitly requested by the user may be used on the basis of legal grounds permitted under applicable legislation.
For cookies used for statistics, analytics, performance, functionality or similar non-essential purposes that involve the processing of personal data, user preference shall be obtained where required by law. Users shall have the opportunity to reject non-essential cookies or withdraw consent previously given.
The types, providers, purposes and retention periods of cookies used by SEPDER may be separately explained through a Cookie Policy or cookie preference panel.
13. Third-Party Services and Maps
SEPDER’s website may use maps, social media links, videos, online meeting systems or other third-party services.
When content belonging to such services is loaded, technical data such as IP address, device information or similar information may be transmitted to the relevant third-party provider.
Where non-essential third-party content leads to the processing of personal data, user preference or explicit consent shall be obtained where required under applicable legislation.
The independent data processing activities of third-party service providers are subject to their own privacy policies.
14. Retention of Personal Data
SEPDER retains personal data only for the period necessary for the purposes for which it is processed or for mandatory retention periods prescribed under applicable legislation.
Records relating to congress and symposium applications may, as a general rule, be retained for five years following the completion of the relevant academic event. At the end of this period, where there is no other legal reason requiring retention, the data shall be deleted, destroyed or anonymised.
Documents relating to payment and financial transactions may be retained for the periods required under applicable financial and legal legislation.
User account information may be retained for the duration of the account’s active use and for a reasonable period thereafter where necessary to fulfil legal obligations or manage potential disputes.
Works that have acquired the nature of academic publications, congress proceedings and published academic programmes are separately evaluated due to their scientific publication and archival nature. A request for deletion of personal data shall be assessed by taking into account the integrity of the published academic work, legal obligations and the rights of the relevant individual.
15. Data Security
SEPDER endeavours to implement technical and administrative measures proportionate to the nature and level of risk involved in the processing in order to prevent unlawful processing of personal data, prevent unauthorised access and ensure secure storage of personal data.
Such measures may include restricting access authorisations, protecting user accounts, secure password policies, monitoring unauthorised login attempts, carrying out software and system updates, regular backups, reviewing records, evaluating service providers from a data security perspective and regulating data processing obligations through contracts where necessary.
Nevertheless, data transmission over the internet cannot be guaranteed to be entirely risk-free. Users are also advised to use strong and unique passwords, not to share account information with others and to contact SEPDER if they detect any suspicious activity.
16. Personal Data Breaches
Where it is determined that personal data has been unlawfully obtained or accessed by unauthorised persons, SEPDER shall assess the nature of the incident and carry out the necessary security, notification and remedial actions within the framework of applicable legislation.
Depending on the nature of the breach, the Personal Data Protection Board and affected individuals may be notified in accordance with applicable legislation.
17. Rights of Data Subjects Under the KVKK
Under Article 11 of the KVKK, data subjects have the right to learn whether their personal data is processed, request information if their personal data has been processed, learn the purpose of such processing and whether the data is used in accordance with that purpose, learn the third parties to whom personal data has been transferred domestically or abroad, request correction where personal data has been processed incompletely or inaccurately, request deletion or destruction of personal data where the conditions prescribed by law are met, request notification of correction, deletion or destruction operations to third parties to whom the data has been transferred, object to adverse consequences arising exclusively from automated processing systems, and request compensation for damages suffered as a result of unlawful processing of personal data.
18. Exercise of Rights and Application Procedure
You may contact SEPDER to obtain information regarding your personal data or exercise your rights under the KVKK.
Applications may be submitted to SEPDER via info@sepder.org.
Where identity verification is necessary, SEPDER may request additional information in order to verify that the applicant is in fact the relevant data subject. Such information shall be used solely for identity verification and for responding to the application.
Applications shall be concluded within the periods prescribed under applicable legislation, depending on the nature of the request.
SEPDER’s current and full notification address may also be published on the website in order to allow applications to be submitted by physical mail.
19. Withdrawal of Explicit Consent
Where a personal data processing activity is based on explicit consent, the relevant individual may withdraw such consent at any time.
Withdrawal of explicit consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal and, as a rule, takes effect prospectively.
Where a personal data processing activity is based on another valid legal ground under the KVKK rather than explicit consent, withdrawal of consent may not automatically result in the termination of that processing activity.
20. Closure of User Accounts
Users holding accounts on the website may request closure of their accounts or deletion of personal data associated with their accounts.
Following closure of an account, where it is necessary to retain records relating to applications, payments, academic publications or legal transactions due to legal requirements or for the establishment, exercise or protection of a right, such records may continue to be retained for the necessary period.
At the end of such period, personal data shall be deleted, destroyed or anonymised in accordance with applicable legislation.
21. Personal Data Relating to Children
SEPDER’s website and academic application systems are primarily intended for academics, researchers, experts, university students and adult participants.
Where an academic event or activity requires the processing of personal data relating to individuals under the age of eighteen, parent or legal representative information and necessary consent procedures shall be separately conducted depending on the age of the individual, the nature of the activity and applicable legislation.
22. Third-Party Data in Scientific Studies
Academic studies submitted to SEPDER may contain personal data relating to third parties obtained through surveys, interviews, case analyses, field research or other research methods.
Researchers are expected to conduct their studies in compliance with relevant ethics committee decisions, research ethics principles and applicable personal data protection legislation.
Directly identifying personal data that is not necessary for academic evaluation should be removed from study files submitted to SEPDER or appropriately anonymised.
23. Commercial Electronic Communications and Academic Announcements
E-mail addresses or telephone numbers provided within the scope of an application or user account shall primarily be used only for managing the relevant application and event process.
Where separate consent or permission is legally required to send promotional or informational communications regarding future congresses, symposiums, calls for papers or SEPDER activities, such permission shall not be presented as a mandatory condition of the application process.
Relevant persons may withdraw electronic communication permissions previously granted using methods compliant with applicable legislation.
24. Relationship of This Policy with Other Texts
This Privacy Policy explains the general framework of SEPDER’s personal data processing activities.
For a specific processing activity, a separately published KVKK Clarification Text, Cookie Policy, Explicit Consent Form, congress or symposium application terms or other information notices may apply together with this Policy.
This Privacy Policy does not in itself constitute a declaration of explicit consent. Where explicit consent is legally required, it shall be obtained separately.
25. Amendments to the Policy
SEPDER may update this Policy in accordance with changes in legislation, decisions of the Personal Data Protection Board, technical changes to the website, new services, new academic activities or changes in data processing procedures.
The current version of the Policy shall be published on sepder.org.
Where material changes are made, users may be informed through the website or via their registered contact information, depending on the nature of the change.
The “Last Updated” date at the beginning of this Policy indicates the most current version in effect.
26. Contact
For any questions regarding this Privacy Policy or the processing of your personal data, you may contact SEPDER.
Social and Economic Perspective Association (SEPDER)
Fatih, Istanbul, Türkiye
E-mail: info@sepder.org
Phone: +90 (554) 946 23 86
Website: sepder.org