Data Protection
Data Protection and Privacy Policy
MICE101 Data Protection and Privacy Policy (KVKK/GDPR 2026)
1. Introduction and Data Controller Identity
At MICE101 Event Management Co., as we build "The Experience Architecture of the Future," we regard the data of our stakeholders as our most valuable trust. In the 2026 "Great Evolution" phase, we view data privacy not merely as a legal obligation, but as a guarantee of our corporate reputation.
Our Istanbul-based office acts as the "Data Controller" in full compliance with both Turkey's Law No. 6698 on the Protection of Personal Data (KVKK) and European Union GDPR standards.
2. Categories of Data Processed and Their Purposes
To ensure the operational excellence of our events, we process the following data:
Identity and Contact Information: For registration processes, transportation, and accommodation coordination.
Special Category Data: Within the scope of our Sustainability and ISO 31030 Travel Security protocols; dietary preferences (allergen, faith-based diets), health data (emergency medical intervention plans), and passport information (for international delegations).
Digital and AI Data: Digital footprint data for AI-powered smart matchmaking and attendee interaction analytics.
3. Legal Basis for Data Processing
Your data is processed based on your explicit consent, the establishment or performance of a contract (Logitech bootcamp, ISG gift kit operations, etc.), legal obligations of the data controller, and our legitimate interests.
4. Data Transfers and Third Parties
MICE101 shares limited data with solution partners that are an integral part of operations (hotels, airlines, visa services, and Event-Tech platforms).
Global Transfers: In our international operations (Colombia, Iraq, Egypt, etc.), your data is transmitted to relevant destination partners within the framework of secure transfer protocols (Standard Contractual Clauses – SCC).
Cybersecurity: Your data is protected by TLS 1.3 encryption and SIEM-based 24/7 monitoring systems.
5. Artificial Intelligence (AI) and Automated Decision-Making
In line with our agency's technology-driven identity, AI tools used in events are employed to personalize the attendee experience. Algorithmic transparency is fundamental in this process; AI models do not use personal data for training purposes and operate on a human-in-the-loop principle.
6. Data Retention and Disposal Policy
MICE101, within its "Demonstrable Compliance" model, retains data only for as long as the processing purpose requires. After an event is completed and applicable statutory limitation periods (generally 10 years) have expired, data is irreversibly deleted or anonymized during periodic disposal cycles each January and July.
7. Data Subject Rights
Pursuant to KVKK Article 11 and the GDPR, you have the following rights:
To learn whether your data is being processed and to request a copy.
To request the correction of incomplete or inaccurate data.
To request the deletion of your data under the "Right to be Forgotten."
To exercise the right to data portability.
8. Contact and Notification
You may direct any questions, requests, or suspected breaches related to data privacy to compliance@mice101.org. Data breaches will be reported to the relevant authorities and to you within a maximum of 72 hours of detection.
This policy, managed by MICE101's Compliance Unit, is the foundational document of our brand's "Digital Trust Architect" position.