Skip to content
STA Kongre
Language
TR EN
Institutional Principles & Policies

Personal Data Protection Notice

This notice provides general information on personal data that may be processed when interacting with STA Congress under Turkish Personal Data Protection Law No. 6698. Where a more specific notice is presented for a particular form or operation, that specific notice applies first.

Last updated08.10.2026
01

Data controller

Data controller: [The legal data controller must be configured in the administration panel.] Application/service address: [Application/service address must be configured.] Contact: [Contact email must be configured.] Data-subject request channel: [Contact email must be configured.] Registered e-mail (KEP): Not specified..

02

Categories of data

  • Identity and contact data: name, email and other contact details necessary for an application.
  • Academic/professional data: affiliation, title, academic identifiers such as ORCID, biography and expertise.
  • Submission/publication data: abstract/full paper, artwork information, contribution statements, review/editorial correspondence, decisions and revision records.
  • Audio-visual data: photographs, voice and video only to the extent required for disclosed purposes such as event recording or exhibition/profile presentation.
  • Transaction-security data: technical logs such as IP, date/time, session, security and error records.
  • Legal request records: records relating to rights requests, complaints, appeals and data-subject applications.
03

Purposes and legal bases

Data may be processed to receive submissions, verify identity/contact details, administer peer review/editorial processes, organise programmes and exhibitions, publish and archive the scholarly record, manage rights requests, secure information systems and comply with legal obligations. Each activity relies on an applicable condition under Articles 5 and, where relevant, 6 of Law No. 6698. Where explicit consent is required it is obtained separately from this notice and must be freely given; consent unrelated to the necessary service is not made mandatory.

04

Recipients and service providers

Personal data may be shared, to the extent necessary for the purpose, with authorised committees/editors/reviewers, technical service providers, online meeting/communication services, hosting/backup providers and legally competent public authorities. In peer review, identity disclosure is restricted in accordance with the double-blind model. Where data is transferred abroad, Article 9 of Law No. 6698 and current secondary legislation are applied. Current provider/recipient record: Overseas service providers actually used must be inventoried by the data controller and appropriate safeguards must be established.

05

Retention and deletion

Data is retained while the processing purpose and applicable legal/scholarly record obligations continue. Bibliographic data for published works, such as author name, affiliation, title, date, persistent link and publication history, may be retained long-term to preserve the scholarly record. Submission, review and operational records are deleted, destroyed or anonymised once their purpose and mandatory retention periods expire. Retention periods must remain consistent with the controller’s data inventory and actual systems.

06

Data-subject rights and requests

Data subjects may exercise their rights under Article 11 of Law No. 6698 by applying to the data controller. Requests must clearly state the right invoked and provide sufficient information for secure identity verification. Request channel: [Contact email must be configured.]; address: [Application/service address must be configured.]. Requests are handled according to the procedures and time limits in force.

07

Cookies and online tracking

Where non-essential analytics, performance or marketing cookies are used, an appropriate legal basis and, where required, prior opt-in explicit consent mechanism is applied. Details are set out in the Cookie Policy.

Implementation note

This text is an institutional operating policy of STA Congress. Applicable law, competent-authority decisions and stricter event-specific rules prevail where relevant. Policies must remain consistent with actual workflows and technical systems.