Privacy Policy

1. Introduction

This Privacy Policy explains how QRestAI ("we" / "the company") collects, processes, stores, and protects personal data. This Policy is:

  • Turkey: compliant with the Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu, KVKK) and its related communiqués.
  • European Union: compliant with the GDPR (Regulation (EU) 2016/679) and the ePrivacy Directive 2002/58/EC (as amended by Directive 2009/136/EC).
  • Other Jurisdictions: compliant with applicable local data protection laws.

By creating an account or using the QRestAI Service, you accept this Policy.

2. Controller of the Data

2.1 Customers in Turkey

  • Data Controller: QRestAI

2.2 EU Customers

  • Data Controller: QRestAI
  • DPA (Data Processing Agreement): offered to customers as standard (upon request).

2.3 Data Processors: AI Providers

For its AI features (text generation, image generation, video generation), QRestAI uses the following third-party providers:

  • Artificial-intelligence service providers (LLM / image generation): subject to their own data processing terms

The Customer is responsible for reviewing the privacy policies of these providers regarding their data processing practices.

3. Data Collected

3.1 Data Collected Directly

3.1.1 Account Creation & Profile

  • Email address
  • Password (hashed with industry-standard one-way password hashing; never stored in plaintext)
  • Business name and type
  • Legal company name (UNVAN)
  • Tax Identification Number (VKN) / Tax ID
  • Region (Country, City)
  • Phone number
  • Address (registered business address)
  • Payment information (last 4 digits of the credit card, held by the payment service provider)

3.1.2 Operational Data

  • Menu content (category, product name, price, description, photographs)
  • Branch information (name, phone, location coordinates: latitude/longitude)
  • Team members & roles
  • Order data (where applicable, orders received via the QR menu, customer name, product, quantity)
  • Accounting & invoice records (for Turkey B2B customers only)

3.1.3 AI-Generated Data

  • Text outputs (menu descriptions, titles, SEO text): stored within QRestAI
  • Image outputs (AI-generated menu photographs): stored in QRestAI cloud storage
  • Video outputs: stored on a cloud content delivery network (CDN)

3.2 Data Collected Automatically

3.2.1 Web Analytics and Session Management

  • IP address
  • Cookie IDs (session tracking, preferences)
  • User-Agent & browser information
  • Duration and order of page visits
  • Referrer URLs
  • Geolocation (IP-based, city level)

3.2.2 Event Logging (event/analytics logs)

  • Login/logout events
  • API calls and their success/failure status
  • AI operation calls (start, end, error code)
  • Payment transaction events (success/failure)
  • Order events

3.2.3 System Logs

  • Application errors (stack traces)
  • Database query durations
  • API latency metrics

3.3 End User Data (Guests)

When an End User scans the QR menu or places an order, the following data may be collected:

  • IP address & geolocation (city level)
  • Browser information
  • The data point from which the QR code was scanned (location / table)
  • Menu viewing duration and interactions
  • If an order is placed: name, phone number, email, order contents
  • For a delivery order: province, district, neighbourhood or village; street, building, floor, flat and directions; the device location if the End User chooses to add it
  • If the End User uses "remember on this device", a copy of the delivery address is kept only in the browser of their own device; this copy is not sent to our servers and can be deleted by the End User

The Customer is responsible for providing a "privacy notice" for this data: a link to this Policy must be displayed to End Users on the QR menu or at the payment screen.

4. Purposes of Data Processing

4.1 Core Purposes (Service Delivery)

  • Account creation and management
  • Provision of the subscription plan
  • Storing and publishing menu content
  • Processing payments and issuing invoices (Turkey: e-Archive Invoice)
  • Provision of AI features (artificial-intelligence service provider calls)
  • Technical support and troubleshooting

4.2 Purposes Subject to Legal Obligation

  • Turkey: retention of accounting records for the statutory retention period under tax and commercial legislation, and e-Archive Invoice and e-Adisyon requirements
  • EU: GDPR Article 6(1)(b), performance of the contract
  • EU Consumers: GDPR Article 6(1)(c), compliance with legal obligations (accounting, tax)

4.3 Legitimate Interest Purposes

  • Securing the system and protecting against fraud
  • Service improvement (with aggregated and anonymised data)
  • Communication (important updates, account alerts)
  • Responding to legal claims

4.4 Marketing Purposes (Consent Required)

  • Product updates by email
  • Payment promotions
  • Invitations to new features
  • Advertising measurement: measuring whether our advertising spend produces results

The Customer may opt out of marketing communications at any time.

Advertising measurement is performed only where consent to the advertising cookie category was given while visiting our marketing site. Within that scope, the identifier of the advertisement clicked, together with the registration or subscription details (amount and currency where applicable), is reported to the relevant advertising platform as a conversion. The report is sent from our servers; name, email address and account content are not included in it.

4.5 AI Model Improvement (Consent Required, Opt-Out Available)

  • In accordance with its agreements with AI providers, QRestAI may use aggregated and anonymised output data (menu descriptions, image generation patterns) to improve models.
  • The Customer can opt out via Account Settings → "Decline participation in AI model improvement".
  • If the Customer opts out, no data is shared.

5. Legal Basis (GDPR & KVKK Compliance)

5.1 GDPR (EU Customers)

PurposeLegal BasisConsent
Performance of contractArt. 6(1)(b)Automatic
Legal obligations (tax, accounting)Art. 6(1)(c)Automatic
Legitimate interests (security, fraud, service improvement)Art. 6(1)(f)Automatic
Marketing (email and advertising measurement)Art. 6(1)(a) ConsentOpt-in
AI Model ImprovementArt. 6(1)(a) ConsentOpt-in (in Account Settings)
Personal Data Concerning Children (< 16 years, varies by EU country)Art. 8 ConsentParental Consent (where applicable)

5.2 KVKK (Turkey Customers)

PurposeLegal BasisExplicit Consent
Performance of contractKVKK Art. 5(2)(a)Not required
Legal obligations (tax, accounting, VUK)KVKK Art. 5(2)(c)Not required
Legitimate interests (service improvement, security)KVKK Art. 5(2)(d)Not required
Marketing: email and advertising measurementKVKK Art. 6(1) ConsentExplicit Consent (Opt-in)
Special Categories of Data (health, sexual orientation, etc., where applicable)KVKK Art. 6(1) ConsentExplicit Consent (Separate, Mandatory)

6. Data Sharing

6.1 Sharing Authorised by the Customer

  • Payment Providers: payment service providers (international and local)

    • Shared: email, company name, payment information (last 4 digits of the credit card)
    • Purpose: payment processing and fraud prevention
    • DPA: Yes (PCI-DSS compliant)
  • Accounting Representative (Turkey only):

    • Where one exists and the customer has notified us
    • Shared: company name, VKN, invoice data
    • Purpose: tax declaration

6.2 Legally Required Sharing

  • Court Order / Prosecutor's Order: upon a lawful request, subject to compliance with all agreements
  • Turkey: special requests from competent state authorities (e.g. the Ministry of the Interior)
  • EU: limited in accordance with GDPR Article 9 (cases of death, injury, etc.)
  • Financial Audit: independent auditor, tax inspectors (upon lawful request)

6.3 Service Providers (Data Processors)

ProviderDataPurposeLocationDPA
Cloud hosting infrastructure providerData within the scope of the ServiceApplication and database hostingEuropeYes
Cloud object storage & content delivery (CDN) providerMenu images, AI outputsStorage, CDNAbroad (including EU regions)Yes
Cloud log & analytics infrastructure provider (Events)Session, API, payment eventsAnalytics, system monitoringAbroadYes
Transactional email providerEmail (invoices, updates)Email deliveryAbroadYes
Application error-monitoring provider (only when configured)Application errors, stack tracesError monitoring (when configured)Abroad (including EU)Yes
Artificial-intelligence service providers (LLM / image generation)Menu descriptions, promptsAI processingAbroadYes
Advertising measurement providersAd click identifier, conversion type, amount and currencyMeasuring advertising performanceAbroadYes

All DPAs are covered by contract and are compliant with the GDPR Standard Contractual Clauses (SCC). Recipients are described by category in this Policy; the up-to-date named sub-processor list is available on request and/or via a dedicated sub-processor/DPA page.

6.4 Areas Where Data Is Not Shared

  • Usernames & passwords are not shared with any third party
  • Credit card numbers are not held by QRestAI (they are held by the payment service provider)
  • Menu content is not copied or sold without the customer's permission

7. Data Retention Periods

Personal data is kept for as long as the purpose of processing requires. When an account is deleted, data other than the records stated below to be subject to a statutory retention period is deleted 90 days later. The same periods apply to all Customers.

Data TypeRetention PeriodLegal Basis
Account information (email, name, password)While the account is open; deleted 90 days after the account is deletedContract
Menu content and imagesFor the duration of the subscription (the Customer may delete); deleted 90 days after the account is deletedContract
AI outputs (text, images, video)For the duration of the subscription (the Customer may delete); deleted 90 days after the account is deletedContract
Invoice and accounting recordsFor the statutory retention period; deleted at its endTax and commercial legislation
Payment and refund recordsFor the statutory retention period; deleted at its endLegal obligation
Event/analytics records90 days raw / 3 years aggregatedSystem requirements and legitimate interest
Deleted account dataDeleted 90 days after the account is deletedArt. 7 of the KVKK

7.1 End User (Guest) Data

End User data processed on the Customer's behalf is kept for as long as the service requires and for the applicable statutory retention periods:

  • Delivery address and location: Kept only for as long as necessary after the order is completed; afterwards the full address and location are deleted, and only province, district and neighbourhood level information remains for reporting.
  • Identity and contact details: Deleted once the End User has not interacted with the restaurant for a period of time. Information that does not identify anyone, such as order counts and amounts, remains.
  • Restaurants whose account is deleted: When a restaurant's account is deleted, End Users' identity, contact and address details are deleted 90 days later.
  • Deletion on request: At the End User's request, the Customer can delete saved delivery addresses and the End User record before these periods end.

8. Data Protection & Security

8.1 Technical Safeguards

  • Encryption: AES-256 (in transit: TLS 1.3)
  • Databases: encrypted databases (at rest)
  • Passwords: industry-standard one-way password hashing; never stored in plaintext
  • 2FA: TOTP (Time-based One-Time Password) offered to users (admin / Turkey applicable)

8.2 Operational Safeguards

  • Access control: Role-Based Access Control (RBAC)
  • Administration: platform admins and support staff only
  • Customer data: organisation-based tenant isolation
  • Backup: daily automatic encrypted (at-rest) database backups (retained for 7 days)
  • Antivirus & Intrusion Detection: web application firewall (WAF) and intrusion detection/prevention systems + infrastructure provider security controls

8.3 Operational Responsibility

  • Personal Data Breach Notification (to the supervisory authority): without undue delay and in any event within 72 hours of becoming aware of the breach. In Türkiye to the Personal Data Protection Board (KVKK Article 12), in the European Union to the competent supervisory authority (GDPR Article 33)
  • Personal Data Breach Notification (to the individual): where the breach is likely to result in a high risk to their rights and freedoms, within the shortest reasonable time (GDPR Article 34, KVKK Article 12)
  • Audit Logs: all administrative operations are recorded

9. User Rights (GDPR & KVKK)

9.1 Turkey (KVKK Articles 11-12)

Users have the following rights:

RightDescriptionResponse Time
Right of AccessTo learn what data about them is processed30 days
Right of RectificationTo correct inaccurate/incomplete data30 days
Right to Erasure (Right to be Forgotten)To request deletion of their data30 days
Restriction of ProcessingTo object to specific processing30 days
Right to PortabilityTo transfer their data to another provider30 days
Withdrawal of Explicit ConsentTo withdraw marketing consentImmediate (on request)
Objection to Automated DecisionsTo object to automated decision-making / profiling30 days

Request Method: [email protected] or Account Settings → "Data Subject Rights" (linked in the Panel)

9.2 EU (GDPR Articles 15-22)

RightDescriptionGDPR Article
Right of AccessTo obtain their own dataArt. 15
RectificationTo correct inaccurate dataArt. 16
Erasure (Right to be Forgotten)To request deletion of their dataArt. 17
Restriction of ProcessingTo stop processing for specific purposesArt. 18
PortabilityTo receive data in a structured, commonly used formatArt. 20
ObjectionTo object to processing based on legitimate interestsArt. 21
Protection Against ProfilingTo object to fully automated decision-makingArt. 22
Children's RightsParental consent for customers under 16Art. 8

Request Method: [email protected] or the in-app Portal (where available)

10. Protection of Children

10.1 Turkey

  • QRestAI does not permit persons under 18 to open an account
  • If data of a person under 18 is inadvertently collected, it is deleted immediately
  • Parental/guardian consent may be requested

10.2 EU (GDPR)

  • Aged 16 and over: may open an account with their own consent
  • Under 16: parental/guardian consent is mandatory (GDPR Article 8)
  • EU member states may set different ages (some at 13)
  • QRestAI does not support accounts for persons under 13

11. International Data Transfers

11.1 Turkey → Abroad

  • Service providers: cloud object storage & content delivery (CDN) provider, cloud log & analytics infrastructure provider, artificial-intelligence service providers (LLM / image generation), and transactional email provider
  • Legal Basis: KVKK Art. 9 (Conditions for Transfer Abroad)
  • Condition: the destination country being deemed "adequate" by the Turkish Personal Data Protection Board, OR standard contracts (DPA with SCC)

11.2 EU → Abroad

  • Standard Contractual Clauses (SCC): signed pursuant to GDPR Article 46(2)(c)
  • Transfer Risk Mitigation measures: GDPR compliance of cloud providers, an EU region option of the content delivery (CDN) provider is available
  • Processing outside the EU: carried out under contractual safeguards (SCCs) from the outset of engagement

The Customer is informed that data may also be processed outside Turkey and the EU.

12. Third-Party Services

12.1 Customer-Provided Providers

  • Photo CDN: customer-provided photo URLs (e.g. Unsplash, Cloudinary); the terms of those providers apply
  • Payment Connection: if the Customer connects its own payment system (where applicable), the terms of that system apply

12.2 Services Selected by QRestAI

All have GDPR/KVKK-compliant DPAs signed.

13. Changes to the Privacy Policy

13.1. QRestAI may update this Policy. Material changes are notified by email at least 30 days in advance.

13.2. Continuing to use the Service after the date of change constitutes acceptance of the new Policy.

13.3. Where renewed consent is required under GDPR Article 13(2)(c) (e.g. a new AI provider), customers will be asked explicitly.

14. Contact Us

14.1 General Enquiries

14.2 Data Subject Rights / Privacy Requests

  • DPO (Data Protection Officer): [email protected]
  • Request Types: access, erasure, objection, portability, etc.
  • Response Time: 30 days (GDPR/KVKK)

14.3 Data Breach Reporting / Security Issues

14.4 Complaints / Applications to Supervisory Authorities

Turkey:

EU Member States:

  • The Data Protection Authority of the relevant country
  • Right of direct application under GDPR Article 77 (without going to court)

15. Definitions

  • Data Controller: the person/entity that determines the purposes and means of processing data (QRestAI in this role)
  • Data Processor: the person/entity that processes data on the instructions of the controller (cloud infrastructure provider, artificial-intelligence service provider, etc.)
  • Personal Data: any information relating to an identified or identifiable natural person
  • Processing: any operation such as collection, recording, alteration, use, sharing, deletion, etc.
  • Consent: freely given, specific, informed, and explicit agreement
  • Legitimate Interests: the situation where processing serves the legitimate interests of the controller or third parties