Privacy Policy

Last updated: 18 August 2026
App: CTO Essentials 2026 (iOS: com.zevent.ctoessentials26, Android: com.zevent.ctoessentials2026)
Data controller: Z Event Kongre Organizasyon Turizm Hizm. Ve Tic. Ltd. Şti, Maslak Mah. Büyükdere Cad. U.S.O. Center No:245 Kat.15 34453 Sarıyer/İstanbul - info@zevent.com.tr

NOTE: Fields in square brackets must be filled in before publishing.

1. SCOPE

This policy explains which personal data is processed when you use the CTO Essentials 2026 mobile application (the "App"), why, and what your rights are. The App is an event guide giving congress participants the programme, speakers, abstracts, announcements, surveys, gallery and contact details. No account, e-mail address or password is required to use it.

2. DATA WE PROCESS
2.1 Badge verification (when enabled by the congress organiser)

On first launch the App may ask you to scan the QR/barcode on your badge or type the code in.

  • Sent to the server: the code printed on your badge.
  • Returned and stored on the device: participant ID, full name, title, participant category (e.g. physician / nurse / student).
  • Purpose: confirming you are registered for the congress; showing announcements and notifications targeted at your participant category; linking your device registration to your participant record.
  • The "Sign out" button on the Home screen deletes this data from the device and resets verification.
2.2 Device registration and push notifications
  • Installation ID: a random identifier (UUID) generated the first time the App opens. It is not your hardware ID, advertising ID or phone number, and it changes if you uninstall and reinstall the App.
  • Push token: issued by Google Firebase Cloud Messaging if you allow notifications.
  • Platform: iOS / Android.
  • Participant ID: only if badge verification was completed (see 2.1).
  • Purpose: delivering congress announcements as push notifications; de-duplicating survey and rating responses per device.

If you decline notification permission the App keeps working; sent notifications remain readable in the in-app inbox (bell icon).

2.3 Survey and rating responses

When you complete a survey or session rating, your selected answers and your installation ID are sent to the server. Responses contain no name; however, if you verified your badge they can be linked to your participant record via the installation ID. Published survey results are aggregate only; free-text answers are never published.

2.4 Camera

The camera is used only to read the QR/barcode on your badge, and only when you open the scanner. No image is recorded, stored or transmitted — only the decoded code is processed. If you decline camera permission you can type the code manually.

2.5 Server access logs

Each request the App makes to the server records your IP address, timestamp and requested resource in standard server access logs for a limited time. These are used for system security and abuse prevention (rate limiting).

2.6 Data that stays on your device only

The following is stored on your phone only, is never sent to any server, and disappears when you delete the App:

  • Sessions added to your agenda and your personal notes
  • Dark-mode and language preference
  • Read/unread state of notifications
  • Congress content and images cached for offline use
3. DATA WE DO NOT COLLECT

The App does not collect location, contacts, advertising ID, photo/media library or microphone data. It contains no analytics, behavioural tracking or advertising SDK. Your data is not used for advertising and is not sold to third parties.

4. THIRD-PARTY SERVICES
  1. Google Firebase Cloud Messaging
    Used for: Push notification delivery
    What is shared: Push token; subject to Google's privacy policy.
  2. Google Fonts
    Used for: Downloading the interface typeface
    What is shared: Your IP address reaches Google servers during the download.
  3. YouTube / Vimeo
    Used for: In-app playback of gallery videos
    What is shared: The embedded player runs under the provider's own cookie and privacy policy.
  4. Congress server (zevent.congrex.app)
    Used for: All content and the data above
    What is shared: Items in section 2; servers located in Z Event Kongre Organizasyon Turizm Hizm. Ve Tic. Ltd. Şti / Türkiye

Phone, e-mail and web links in the App open in the corresponding app on your device (dialer, mail, browser).

5. PURPOSES AND LEGAL BASIS

Data is processed under Turkish Law No. 6698 (KVKK) Art. 5 and, for users in the EU, GDPR Art. 6, on the following bases:

  1. Providing the congress service (participant verification, content, surveys): performance of a contract / legitimate interest
  2. Push notifications: your OS-level permission (consent), revocable at any time in phone settings
  3. Security and access logs: legitimate interest
6. RETENTION
  1. Device registration, participant verification and survey responses: at most 1 year after the congress ends, then deleted or anonymised.
  2. Server access logs: at most 1 year..
  3. On-device data: until you delete the App.
7. YOUR RIGHTS

Under KVKK Art. 11 and the GDPR you have the right to access, rectify and erase your data, to object to processing and to lodge a complaint. Send requests to info@zevent.com.tr; they are answered within 30 days at the latest.

8. CHILDREN

The App is intended for a professional congress and is not directed at persons under 16; we do not knowingly collect data from children.

9. SECURITY

All communication with the server is encrypted with TLS (HTTPS). Images are served via short-lived signed links. On-device data is kept inside the operating system's app sandbox.

10. CHANGES

When this policy is updated, the new version is published on the app store listing and at [URL], and the "Last updated" date is changed.

11. CONTACT

Z Event Kongre Organizasyon Turizm Hizm. Ve Tic. Ltd. Şti, Maslak Mah. Büyükdere Cad. U.S.O. Center No:245 Kat.15 34453 Sarıyer/İstanbul - info@zevent.com.tr - +90 212 323 51 00

Important Dates