This Privacy Notice has been prepared by QRestAI in its capacity as data controller, pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data ("KVKK") and the "Communiqué on the Procedures and Principles to be Followed in Fulfilling the Disclosure Obligation" (Official Gazette dated 10.03.2018, No. 30356). Processing activities that depend on explicit consent are addressed separately in the "Explicit Consent Statement" as required by Art. 10 together with Art. 5/1 and Art. 6/2 of the KVKK; this Privacy Notice does not substitute for obtaining explicit consent.
1. Identity of the Data Controller
The data controller within the meaning of Art. 3 of the KVKK (that is, the entity determining the purposes and means of processing personal data) is the following legal entity:
- Name: QRestAI
- E-mail: [email protected] / [email protected]
- Website: https://qrestai.com
Defined terms used in this Notice:
- Business User: A restaurant, café, hotel or similar business that registers with QRestAI and manages the Service, together with the natural-person users acting on its behalf.
- End User: A guest (data subject) who views the QR menu published by a Business User or places an order through it.
- Service: The QR-code-based menu management, ordering/POS, AI-assisted content generation and operational SaaS platform provided by QRestAI.
2. Categories of Personal Data Processed
2.1 Business Users
| Data Category | Examples |
|---|---|
| Identity | Full name, legal company name |
| Contact | E-mail address, phone number, business/branch address |
| Customer Transaction | Subscription plan, business/branch details, team membership and role |
| Finance | Billing details, payment information (card data is NOT stored by QRestAI; only the last-4-digits reference held by the payment provider) |
| Transaction Security | Hashed password (industry-standard one-way password hashing), session data, IP address, log records |
| Marketing | Communication preferences, ad click identifier and conversion details |
2.2 End Users (Guests / Diners)
| Data Category | Examples |
|---|---|
| Identity (optional) | Name, if entered during ordering |
| Contact (optional) | Phone number, if entered during ordering |
| Customer Transaction | Order content, table/spot information, feedback |
| Transaction Security / Analytics | Salted IP hash for traffic analytics: the raw IP address is NOT stored |
As a rule, QRestAI does not request special categories of personal data (Art. 6 of the KVKK) from End Users. Processing of such data may only occur if a Business User enters it into the menu/order fields under its own consent and responsibility.
3. Purposes of Processing
Your personal data is processed for the following purposes:
- Account creation, authentication and account management
- Provision, maintenance and improvement of the subscription plan and the Service
- Storage, publication and QR-based delivery of menu content
- Operation of ordering/POS processes
- Execution of payment transactions and invoicing
- Provision of AI-assisted content generation features (text/image/video) and tracking of credit consumption
- Conduct of information-security processes, error monitoring and fraud prevention
- Generation of aggregated/analytical reporting on Service usage
- Handling of requests and complaints, customer-relationship management and technical support
- Fulfilment of legal obligations, provision of information to authorized persons/institutions, and response to legal claims
4. Legal Grounds for Processing (Art. 5 of the KVKK)
Your personal data is processed without seeking explicit consent, based on the following legal grounds set out in Art. 5/2 of the KVKK:
| Legal Ground | Application |
|---|---|
| Art. 5/2-a: Expressly provided for by law | Tax/accounting and retention obligations (Tax Procedure Law, VUK) |
| Art. 5/2-c: Necessary for the formation or performance of a contract | Account creation, subscription, provision of the Service, ordering and payment processes |
| Art. 5/2-ç: Necessary for compliance with a legal obligation | Statutory record/document retention and notification obligations |
| Art. 5/2-e: Necessary for the establishment, exercise or protection of a right | Dispute and legal-claim processes, evidentiary purposes |
| Art. 5/2-f: Legitimate interest (provided it does not harm fundamental rights and freedoms) | Information security, fraud prevention, Service improvement and aggregated analytics |
Marketing communications and any other processing for which the legislation requires explicit consent (e.g. the exceptional explicit consent relied upon for scope-expanding international transfers) are based on explicit consent under Art. 5/1 of the KVKK and are carried out under the separate Explicit Consent Statement. Where special categories of personal data are involved, processing is carried out within the framework of Art. 6 of the KVKK.
5. Method of Collection
Your personal data is collected electronically, wholly or partly by automated means, via web and mobile interfaces, panel/administration screens, API calls, QR menu viewing and order flows during account creation and use of the Service. Payment information is obtained through the infrastructure of the relevant payment provider; card data is not stored on QRestAI's systems.
6. Transfer of Personal Data
6.1 Domestic Transfers (Art. 8 of the KVKK)
Limited to the purposes set out above and within the scope of Art. 8 of the KVKK, your personal data may be transferred to authorized public institutions and bodies (upon request and as required by legislation), to our business partners, and to the legal/financial-advisory and audit service providers we engage.
6.2 International Transfers (Art. 9 of the KVKK, Regime as Amended by Law No. 7499)
To provide the Service, QRestAI relies on data processors (sub-processors) some of which are located abroad. International transfers are carried out in accordance with Art. 9 of the KVKK as amended by Law No. 7499 (in force as of 1 June 2024) and the "Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad" (Official Gazette dated 10.07.2024, No. 32598; the transition period ended on 1 September 2024), within the following tiered regime:
- Adequacy decision (Art. 9/1): Where the Personal Data Protection Board has issued an adequacy decision regarding the destination country, sector or international organization.
- Appropriate safeguards (Art. 9/4): In the absence of an adequacy decision, where the parties provide one of the appropriate safeguards such as standard contractual clauses or binding corporate rules (provided that the data subject is able to exercise their rights and access effective legal remedies in the destination country).
- Exceptional (incidental) cases (Art. 9/6): Where the above cannot be provided, on an incidental basis; for example, the explicit consent of the data subject who has been informed of the possible risks, or where the transfer is necessary for the performance of a contract.
Recipient groups and international sub-processors:
| Recipient Group | Sub-processor | Purpose |
|---|---|---|
| Payment providers | Payment service providers (international and local) | Payment processing and fraud prevention (card data is held by the payment service provider) |
| Cloud storage / CDN | Cloud object storage & content delivery (CDN) provider | Storage and delivery of image/video assets |
| Event / analytics database | Cloud log & analytics infrastructure provider | Event and analytics records (90 days raw / 3 years aggregated) |
| Primary database | Encrypted databases (at rest) | Storage of transactional data |
| Cache | Cache infrastructure | Session and cache data |
| AI providers | Text / image / video generation providers | AI-assisted content generation |
| E-mail provider | E-mail delivery provider | Transactional/informational e-mails |
| Advertising measurement | Advertising measurement providers | Ad click identifier and conversion details (excluding name and e-mail) |
International transfers to these recipients are carried out in accordance with the tiered Art. 9 regime above: on the basis of standard contractual clauses/appropriate safeguards where no adequacy decision exists, or within the framework of the applicable exceptions.
7. Data Retention Periods
Your personal data is retained for the period required by the processing purpose, or for the longer of the minimum/maximum periods stipulated by legislation:
| Data Type | Retention Period | Basis |
|---|---|---|
| Account and profile data | While the account is open; deleted 90 days after the account is deleted | Contract |
| Menu content and images | For the duration of the subscription (user may delete); deleted 90 days after the account is deleted | Contract |
| Invoice and accounting records | For the statutory retention period; deleted at its end | Tax and commercial legislation |
| Payment and refund records | For the statutory retention period; deleted at its end | Legal obligation |
| Event/analytics records | 90 days raw / 3 years aggregated | System and legitimate interest |
| AI outputs | For the duration of the subscription (user may delete); deleted 90 days after the account is deleted | Contract |
| Deleted account data | Deleted 90 days after the account is deleted | Art. 7 of the KVKK |
Upon expiry of the retention period or where the reasons requiring processing no longer apply, your personal data is deleted pursuant to Art. 7 of the KVKK and the "Regulation on the Deletion, Destruction or Anonymization of Personal Data".
8. Rights of the Data Subject (Art. 11 of the KVKK)
Pursuant to Art. 11 of the KVKK, by applying to the data controller you have the right to:
- Learn whether your personal data is being processed,
- Request information if it has been processed,
- Learn the purpose of processing and whether the data is used in accordance with that purpose,
- Know the third parties to whom the data is transferred, domestically or abroad,
- Request the correction of incomplete or inaccurately processed data,
- Request the deletion or destruction of the data under the conditions set out in Art. 7 of the KVKK,
- Request that correction, deletion and destruction operations be notified to the third parties to whom the data was transferred,
- Object to a result that arises against you as a consequence of the analysis of your data exclusively by automated systems,
- Claim compensation for damage you suffer due to the unlawful processing of your personal data.
9. Application Method (Communiqué on Applications to the Data Controller)
Pursuant to Art. 13 of the KVKK and the "Communiqué on the Procedures and Principles for Applications to the Data Controller" (Official Gazette dated 10.03.2018, No. 30356), you may submit your requests under Art. 11 by the following methods:
- In writing (wet-ink signature): delivered via notary,
- Via secure electronic signature / mobile signature, or from an e-mail address registered in our system: [email protected].
Your application must include your full name and (for written applications) signature, your Turkish ID number for citizens of the Republic of Türkiye, your residential or business address for notification, your registered e-mail address/phone number (if any), and the subject of your request.
Your application will be concluded as soon as possible and, in any event, within thirty (30) days at the latest, depending on the nature of the request. Where the process entails an additional cost, a fee may be charged in accordance with the tariff set by the Board.
If your application is rejected, you find our response insufficient, or no response is provided within the period, you reserve the right to file a complaint with the Personal Data Protection Board within thirty (30) days from the date you learn of the response and, in any event, within sixty (60) days from the date of application.