Privacy Policy
Scope and data minimisation
Seat Circle arranges small social coffee tables in İzmir. We aim to collect only data needed for applications, matching, reservations, payment, safety and support; limit fields to those purposes; and erase, anonymise or redact content as described below when it is no longer needed.
Controller
The controller is Denizcom Ltd. (Company Number: 16999432), 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: [email protected].
Data we process
We may process name, email and phone; your declaration that you are 18 or over; preferences and compatibility answers; account, application, table, reservation, membership and attendance records; Stripe transaction references; legal acceptance and consent evidence; website usage; and support, complaint and feedback content. Complaints may contain harassment, health or other sensitive allegations; access is limited to reviewing the report, protecting safety and assessing legal duties. Seat Circle does not see or store card details; Stripe processes them.
Purposes and lawful bases
We process data to establish and perform the service contract, suggest tables, conduct manual application review, handle payment/refunds, send service notices, investigate complaints and safety incidents, prevent fraud, meet legal duties and measure service quality. Bases may include contract, legal obligation, establishing/exercising/defending rights, legitimate interests and consent where required. You may withdraw consent-based processing at any time.
Limits of matching
The algorithm assesses similarity and balance signals from answers and eligibility; it cannot conclusively measure personality, safety or real-life compatibility. It does not guarantee a person, outcome, table or experience. The team reviews table suggestions before publication. You may ask for an explanation, correct inaccurate inputs and object through support. We do not aim to make legally or similarly significant adverse decisions based solely on automated analysis.
WhatsApp: operational, not marketing
Under the current Operational WhatsApp Policy, we use phone and messages only for application/table/reservation/payment notices and user-initiated support. It is not advertising or commercial-marketing consent. Turn the preference off in your profile or ask us to stop in a message. Opting out does not prevent essential in-account notices or a reply to support you requested.
Providers and international transfers
As needed, data may be shared with hosting/CDN and security providers, Sentry for error/performance monitoring, Stripe for payment, WhatsApp infrastructure for operations, and Google Analytics 4 or Meta Pixel only where consent is granted and the relevant ID is configured. Some providers are abroad. We use transfer mechanisms and safeguards required by KVKK Article 9 and other applicable law. Data may be disclosed to authorities upon a lawful request; we do not sell it.
Technical redaction and retention
Current technical settings redact WhatsApp message body, phone, provider payload/error and terminal table-assignment delivery payload after 90 days; WhatsApp AI summary/decision content after 30 days; and payment-webhook payload/error content after 365 days. Privacy/WhatsApp consent request-id correlation is held for 365 days while the consent event itself remains as evidence. Operational WhatsApp/privacy-cleanup task descriptions are redacted after 30 days, and city-request email/normalised email 365 days after the most recent request. This is content/payload redaction, not deletion of every record. Account, onboarding, reservation, complaint, feedback, legal acceptance and financial records remain for their purpose or applicable statutory limitation; no single enforced numeric deletion schedule currently covers them.
Under-18 users
The service is for adults aged 18 and over. We do not independently verify age with identity documents or payment cards. If we learn that a user is under 18, we stop participation and take reasonable steps to erase or restrict data that we are not legally required to keep.
Rights, complaints and security
Contact [email protected] to request access, correction, erasure/destruction, restriction, objection and, where applicable, portability. The KVKK Disclosure explains Turkish rights. To the extent UK GDPR applies, its rights and the route to complain to the UK Information Commissioner's Office remain available; this statement does not assert that UK GDPR applies to every processing activity. We use reasonable technical and organisational security, but no system is risk-free.
Language and changes
If Turkish and English differ, the Turkish text prevails without reducing mandatory consumer or data-protection rights in Türkiye. For material changes we update the version/effective date and request fresh acceptance where required.
