Privacy Notice (KVKK)

This Privacy Notice has been prepared by QRestAI in its capacity as data controller, pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data ("KVKK") and the "Communiqué on the Procedures and Principles to be Followed in Fulfilling the Disclosure Obligation" (Official Gazette dated 10.03.2018, No. 30356). Processing activities that depend on explicit consent are addressed separately in the "Explicit Consent Statement" as required by Art. 10 together with Art. 5/1 and Art. 6/2 of the KVKK; this Privacy Notice does not substitute for obtaining explicit consent.

1. Identity of the Data Controller

The data controller within the meaning of Art. 3 of the KVKK (that is, the entity determining the purposes and means of processing personal data) is the following legal entity:

Defined terms used in this Notice:

  • Business User: A restaurant, café, hotel or similar business that registers with QRestAI and manages the Service, together with the natural-person users acting on its behalf.
  • End User: A guest (data subject) who views the QR menu published by a Business User or places an order through it.
  • Service: The QR-code-based menu management, ordering/POS, AI-assisted content generation and operational SaaS platform provided by QRestAI.

2. Categories of Personal Data Processed

2.1 Business Users

Data CategoryExamples
IdentityFull name, legal company name
ContactE-mail address, phone number, business/branch address
Customer TransactionSubscription plan, business/branch details, team membership and role
FinanceBilling details, payment information (card data is NOT stored by QRestAI; only the last-4-digits reference held by the payment provider)
Transaction SecurityHashed password (industry-standard one-way password hashing), session data, IP address, log records
MarketingCommunication preferences, ad click identifier and conversion details

2.2 End Users (Guests / Diners)

Data CategoryExamples
Identity (optional)Name, if entered during ordering
Contact (optional)Phone number, if entered during ordering
Customer TransactionOrder content, table/spot information, feedback
Transaction Security / AnalyticsSalted IP hash for traffic analytics: the raw IP address is NOT stored

As a rule, QRestAI does not request special categories of personal data (Art. 6 of the KVKK) from End Users. Processing of such data may only occur if a Business User enters it into the menu/order fields under its own consent and responsibility.

3. Purposes of Processing

Your personal data is processed for the following purposes:

  • Account creation, authentication and account management
  • Provision, maintenance and improvement of the subscription plan and the Service
  • Storage, publication and QR-based delivery of menu content
  • Operation of ordering/POS processes
  • Execution of payment transactions and invoicing
  • Provision of AI-assisted content generation features (text/image/video) and tracking of credit consumption
  • Conduct of information-security processes, error monitoring and fraud prevention
  • Generation of aggregated/analytical reporting on Service usage
  • Handling of requests and complaints, customer-relationship management and technical support
  • Fulfilment of legal obligations, provision of information to authorized persons/institutions, and response to legal claims

4. Legal Grounds for Processing (Art. 5 of the KVKK)

Your personal data is processed without seeking explicit consent, based on the following legal grounds set out in Art. 5/2 of the KVKK:

Legal GroundApplication
Art. 5/2-a: Expressly provided for by lawTax/accounting and retention obligations (Tax Procedure Law, VUK)
Art. 5/2-c: Necessary for the formation or performance of a contractAccount creation, subscription, provision of the Service, ordering and payment processes
Art. 5/2-ç: Necessary for compliance with a legal obligationStatutory record/document retention and notification obligations
Art. 5/2-e: Necessary for the establishment, exercise or protection of a rightDispute and legal-claim processes, evidentiary purposes
Art. 5/2-f: Legitimate interest (provided it does not harm fundamental rights and freedoms)Information security, fraud prevention, Service improvement and aggregated analytics

Marketing communications and any other processing for which the legislation requires explicit consent (e.g. the exceptional explicit consent relied upon for scope-expanding international transfers) are based on explicit consent under Art. 5/1 of the KVKK and are carried out under the separate Explicit Consent Statement. Where special categories of personal data are involved, processing is carried out within the framework of Art. 6 of the KVKK.

5. Method of Collection

Your personal data is collected electronically, wholly or partly by automated means, via web and mobile interfaces, panel/administration screens, API calls, QR menu viewing and order flows during account creation and use of the Service. Payment information is obtained through the infrastructure of the relevant payment provider; card data is not stored on QRestAI's systems.

6. Transfer of Personal Data

6.1 Domestic Transfers (Art. 8 of the KVKK)

Limited to the purposes set out above and within the scope of Art. 8 of the KVKK, your personal data may be transferred to authorized public institutions and bodies (upon request and as required by legislation), to our business partners, and to the legal/financial-advisory and audit service providers we engage.

6.2 International Transfers (Art. 9 of the KVKK, Regime as Amended by Law No. 7499)

To provide the Service, QRestAI relies on data processors (sub-processors) some of which are located abroad. International transfers are carried out in accordance with Art. 9 of the KVKK as amended by Law No. 7499 (in force as of 1 June 2024) and the "Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad" (Official Gazette dated 10.07.2024, No. 32598; the transition period ended on 1 September 2024), within the following tiered regime:

  1. Adequacy decision (Art. 9/1): Where the Personal Data Protection Board has issued an adequacy decision regarding the destination country, sector or international organization.
  2. Appropriate safeguards (Art. 9/4): In the absence of an adequacy decision, where the parties provide one of the appropriate safeguards such as standard contractual clauses or binding corporate rules (provided that the data subject is able to exercise their rights and access effective legal remedies in the destination country).
  3. Exceptional (incidental) cases (Art. 9/6): Where the above cannot be provided, on an incidental basis; for example, the explicit consent of the data subject who has been informed of the possible risks, or where the transfer is necessary for the performance of a contract.

Recipient groups and international sub-processors:

Recipient GroupSub-processorPurpose
Payment providersPayment service providers (international and local)Payment processing and fraud prevention (card data is held by the payment service provider)
Cloud storage / CDNCloud object storage & content delivery (CDN) providerStorage and delivery of image/video assets
Event / analytics databaseCloud log & analytics infrastructure providerEvent and analytics records (90 days raw / 3 years aggregated)
Primary databaseEncrypted databases (at rest)Storage of transactional data
CacheCache infrastructureSession and cache data
AI providersText / image / video generation providersAI-assisted content generation
E-mail providerE-mail delivery providerTransactional/informational e-mails
Advertising measurementAdvertising measurement providersAd click identifier and conversion details (excluding name and e-mail)

International transfers to these recipients are carried out in accordance with the tiered Art. 9 regime above: on the basis of standard contractual clauses/appropriate safeguards where no adequacy decision exists, or within the framework of the applicable exceptions.

7. Data Retention Periods

Your personal data is retained for the period required by the processing purpose, or for the longer of the minimum/maximum periods stipulated by legislation:

Data TypeRetention PeriodBasis
Account and profile dataWhile the account is open; deleted 90 days after the account is deletedContract
Menu content and imagesFor the duration of the subscription (user may delete); deleted 90 days after the account is deletedContract
Invoice and accounting recordsFor the statutory retention period; deleted at its endTax and commercial legislation
Payment and refund recordsFor the statutory retention period; deleted at its endLegal obligation
Event/analytics records90 days raw / 3 years aggregatedSystem and legitimate interest
AI outputsFor the duration of the subscription (user may delete); deleted 90 days after the account is deletedContract
Deleted account dataDeleted 90 days after the account is deletedArt. 7 of the KVKK

Upon expiry of the retention period or where the reasons requiring processing no longer apply, your personal data is deleted pursuant to Art. 7 of the KVKK and the "Regulation on the Deletion, Destruction or Anonymization of Personal Data".

8. Rights of the Data Subject (Art. 11 of the KVKK)

Pursuant to Art. 11 of the KVKK, by applying to the data controller you have the right to:

  • Learn whether your personal data is being processed,
  • Request information if it has been processed,
  • Learn the purpose of processing and whether the data is used in accordance with that purpose,
  • Know the third parties to whom the data is transferred, domestically or abroad,
  • Request the correction of incomplete or inaccurately processed data,
  • Request the deletion or destruction of the data under the conditions set out in Art. 7 of the KVKK,
  • Request that correction, deletion and destruction operations be notified to the third parties to whom the data was transferred,
  • Object to a result that arises against you as a consequence of the analysis of your data exclusively by automated systems,
  • Claim compensation for damage you suffer due to the unlawful processing of your personal data.

9. Application Method (Communiqué on Applications to the Data Controller)

Pursuant to Art. 13 of the KVKK and the "Communiqué on the Procedures and Principles for Applications to the Data Controller" (Official Gazette dated 10.03.2018, No. 30356), you may submit your requests under Art. 11 by the following methods:

  • In writing (wet-ink signature): delivered via notary,
  • Via secure electronic signature / mobile signature, or from an e-mail address registered in our system: [email protected].

Your application must include your full name and (for written applications) signature, your Turkish ID number for citizens of the Republic of Türkiye, your residential or business address for notification, your registered e-mail address/phone number (if any), and the subject of your request.

Your application will be concluded as soon as possible and, in any event, within thirty (30) days at the latest, depending on the nature of the request. Where the process entails an additional cost, a fee may be charged in accordance with the tariff set by the Board.

If your application is rejected, you find our response insufficient, or no response is provided within the period, you reserve the right to file a complaint with the Personal Data Protection Board within thirty (30) days from the date you learn of the response and, in any event, within sixty (60) days from the date of application.

Privacy Notice (KVKK) | QRestAI