Privacy and personal data notice
Version: 2026-10-11.2
Service provider and contact
- Seller / data controller
- Özge Güneş
- Address
- Atatürk Mah. Mercan Sok. No:29/8 Küçükçekmece İstanbul
- Contact
- info@isozai.com 0555 753 26 85
- Tax / registration / exemption information
- Not specified.
Data controller
Under Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”), the data controller is the Invellora operator whose name, address and contact details appear at the top of this page. This notice is provided under Article 10 of the KVKK and the related communiqué on the duty to inform.
Categories of data
Identity (name, surname), contact (email, phone, address), customer transaction (orders, plans, invitation content, RSVP replies), transaction security (session, IP and access logs), finance (payment status and amount; never card details), visual and audio records (photos, video, audio and music you upload) and legal transaction records (contract acceptance, requests and complaints) are processed.
Service and responsibilities
The operator identified above is the controller for account, order, payment and platform security records. The host determines the purpose of event content and guest information and must meet the obligations applicable to that processing. Invellora hosts that information under the host’s instructions. The operator must separately establish the parties’ data processing agreement.
Information and purposes
Name, email, account identifier, salted password hash and session records support account security. Event details, text and uploaded media are used to save and publish invitations. Buyer contact/address, plan, payment status and contract acceptance are processed to fulfil and document sales. Invellora does not store plaintext passwords, card numbers or CVV.
Guest information and visibility
Attendance, guest counts, meal choices, private notes, gift notices and assistant questions are shown in the relevant host’s private dashboard. RSVP notes are never published in the public guestbook. Guestbook names and notes appear to people who open the link only when the guest separately chooses publication and the host enables the public book. This choice is optional. Memory photos, videos and audio are collected with separate permission and made available to the host. Do not include health details, identity documents, banking information or sensitive information about children in notes.
Personal invitation links
A host may create a personal link for a guest with their name, a greeting and the number of seats saved. This is used only to greet the guest by name on the invitation, prefill the reply form and match the reply to that guest in the host’s private dashboard; anyone opening the link sees that name. The link code cannot be guessed but is not a password; the recipient can forward it. Entering guest names and informing guests is the host’s responsibility. The host can delete a link at any time; deleting the invitation deletes all of its links, and a deleted link opens the general invitation.
Collection methods and legal grounds
Data is collected electronically through sign-in, forms, uploads, payment verification and security records. Where applicable, processing relies on contract formation/performance, legal obligations, protection of rights and proportionate legitimate security interests. Consent is requested separately and voluntarily where required. Reading this notice or accepting sales terms is not consent.
Recipients and external services
The authorised operator and relevant host access necessary records. Cloudflare provides hosting, D1 databases and R2 media storage. Resend processes recipient addresses and messages for password recovery; Google Workspace may be configured as a mail fallback, and Google verifies identity when Google sign-in is used. PayTR or iyzico processes payment information for the enabled method. Invitation maps load automatically through Google Maps as you approach the map section; the venue query and connection data may be shared with Google. WhatsApp, SMS and email links open your selected application. Records may be disclosed to competent authorities where required by law. Data is not sold for advertising.
International transfers
Cloud, email and selected external services may involve processing outside Türkiye. The operator must establish the applicable transfer mechanism under Article 9 of the Turkish personal data protection law and complete required agreements and notifications with providers. This notice is not a transfer authorisation or evidence that those procedures have been completed.
Retention, deletion and security
Account and content records are retained as needed for the service. When publication expires, guest access closes. Customer media is retained for 90 days for download or renewal, then deleted by daily automated cleanup. Shared media remains while another invitation uses it. Accounts, text, replies and orders are not erased by this media cleanup. Daily backups last 30 days and weekly backups 90 days. Deletion requests are assessed with related media, recipients and backups; mandatory financial retention and legal claim periods depend on the record category. Unpublishing is not deletion. Session authorisation, encrypted transport, file type/size checks, access restrictions and payment verification are used. Absolute security or uninterrupted access is not guaranteed; mandatory consumer rights remain protected.
Your rights and requests
Under Article 11 of the Turkish personal data protection law, you may ask whether data is processed, request information about purposes and recipients, seek correction or erasure, request notification to recipients, object to adverse automated analysis and seek compensation where applicable. Contact the email or postal address above with your request; do not send unnecessary identity documents. Identity checks must be proportionate. Requests are addressed under legal procedures within 30 days. To withdraw a publication choice or request deletion of guest data, contact the host and operator with the invitation link.
How to apply and the right to complain
Under the communiqué on applications to data controllers, you may send requests in writing to the postal address above, by registered electronic mail (KEP), with a secure electronic or mobile signature, or from the email address registered with us to the email address above. Include your name, signature (for written requests), a postal or email address for the reply and the subject of your request. Requests are answered free of charge within 30 days; if the action involves an additional cost, the tariff set by the Board may apply. If your request is refused, the answer is insufficient or no answer is given in time, you may complain to the Personal Data Protection Board within 30 days of learning the answer and in any case within 60 days of your request.
Changes
This notice may be updated as the service or the law changes. The current version and its effective date are published on this page; significant changes may also be sent to the email address registered to your account.