1. Introduction
This Privacy Policy explains how QRestAI ("we" / "the company") collects, processes, stores, and protects personal data. This Policy is:
- Turkey: compliant with the Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu, KVKK) and its related communiqués.
- European Union: compliant with the GDPR (Regulation (EU) 2016/679) and the ePrivacy Directive 2002/58/EC (as amended by Directive 2009/136/EC).
- Other Jurisdictions: compliant with applicable local data protection laws.
By creating an account or using the QRestAI Service, you accept this Policy.
2. Controller of the Data
2.1 Customers in Turkey
- Data Controller: QRestAI
2.2 EU Customers
- Data Controller: QRestAI
- DPA (Data Processing Agreement): offered to customers as standard (upon request).
2.3 Data Processors: AI Providers
For its AI features (text generation, image generation, video generation), QRestAI uses the following third-party providers:
- Artificial-intelligence service providers (LLM / image generation): subject to their own data processing terms
The Customer is responsible for reviewing the privacy policies of these providers regarding their data processing practices.
3. Data Collected
3.1 Data Collected Directly
3.1.1 Account Creation & Profile
- Email address
- Password (hashed with industry-standard one-way password hashing; never stored in plaintext)
- Business name and type
- Legal company name (UNVAN)
- Tax Identification Number (VKN) / Tax ID
- Region (Country, City)
- Phone number
- Address (registered business address)
- Payment information (last 4 digits of the credit card, held by the payment service provider)
3.1.2 Operational Data
- Menu content (category, product name, price, description, photographs)
- Branch information (name, phone, location coordinates: latitude/longitude)
- Team members & roles
- Order data (where applicable, orders received via the QR menu, customer name, product, quantity)
- Accounting & invoice records (for Turkey B2B customers only)
3.1.3 AI-Generated Data
- Text outputs (menu descriptions, titles, SEO text): stored within QRestAI
- Image outputs (AI-generated menu photographs): stored in QRestAI cloud storage
- Video outputs: stored on a cloud content delivery network (CDN)
3.2 Data Collected Automatically
3.2.1 Web Analytics and Session Management
- IP address
- Cookie IDs (session tracking, preferences)
- User-Agent & browser information
- Duration and order of page visits
- Referrer URLs
- Geolocation (IP-based, city level)
3.2.2 Event Logging (event/analytics logs)
- Login/logout events
- API calls and their success/failure status
- AI operation calls (start, end, error code)
- Payment transaction events (success/failure)
- Order events
3.2.3 System Logs
- Application errors (stack traces)
- Database query durations
- API latency metrics
3.3 End User Data (Guests)
When an End User scans the QR menu or places an order, the following data may be collected:
- IP address & geolocation (city level)
- Browser information
- The data point from which the QR code was scanned (location / table)
- Menu viewing duration and interactions
- If an order is placed: name, phone number, email, order contents
- For a delivery order: province, district, neighbourhood or village; street, building, floor, flat and directions; the device location if the End User chooses to add it
- If the End User uses "remember on this device", a copy of the delivery address is kept only in the browser of their own device; this copy is not sent to our servers and can be deleted by the End User
The Customer is responsible for providing a "privacy notice" for this data: a link to this Policy must be displayed to End Users on the QR menu or at the payment screen.
4. Purposes of Data Processing
4.1 Core Purposes (Service Delivery)
- Account creation and management
- Provision of the subscription plan
- Storing and publishing menu content
- Processing payments and issuing invoices (Turkey: e-Archive Invoice)
- Provision of AI features (artificial-intelligence service provider calls)
- Technical support and troubleshooting
4.2 Purposes Subject to Legal Obligation
- Turkey: retention of accounting records for the statutory retention period under tax and commercial legislation, and e-Archive Invoice and e-Adisyon requirements
- EU: GDPR Article 6(1)(b), performance of the contract
- EU Consumers: GDPR Article 6(1)(c), compliance with legal obligations (accounting, tax)
4.3 Legitimate Interest Purposes
- Securing the system and protecting against fraud
- Service improvement (with aggregated and anonymised data)
- Communication (important updates, account alerts)
- Responding to legal claims
4.4 Marketing Purposes (Consent Required)
- Product updates by email
- Payment promotions
- Invitations to new features
- Advertising measurement: measuring whether our advertising spend produces results
The Customer may opt out of marketing communications at any time.
Advertising measurement is performed only where consent to the advertising cookie category was given while visiting our marketing site. Within that scope, the identifier of the advertisement clicked, together with the registration or subscription details (amount and currency where applicable), is reported to the relevant advertising platform as a conversion. The report is sent from our servers; name, email address and account content are not included in it.
4.5 AI Model Improvement (Consent Required, Opt-Out Available)
- In accordance with its agreements with AI providers, QRestAI may use aggregated and anonymised output data (menu descriptions, image generation patterns) to improve models.
- The Customer can opt out via Account Settings → "Decline participation in AI model improvement".
- If the Customer opts out, no data is shared.
5. Legal Basis (GDPR & KVKK Compliance)
5.1 GDPR (EU Customers)
| Purpose | Legal Basis | Consent |
|---|---|---|
| Performance of contract | Art. 6(1)(b) | Automatic |
| Legal obligations (tax, accounting) | Art. 6(1)(c) | Automatic |
| Legitimate interests (security, fraud, service improvement) | Art. 6(1)(f) | Automatic |
| Marketing (email and advertising measurement) | Art. 6(1)(a) Consent | Opt-in |
| AI Model Improvement | Art. 6(1)(a) Consent | Opt-in (in Account Settings) |
| Personal Data Concerning Children (< 16 years, varies by EU country) | Art. 8 Consent | Parental Consent (where applicable) |
5.2 KVKK (Turkey Customers)
| Purpose | Legal Basis | Explicit Consent |
|---|---|---|
| Performance of contract | KVKK Art. 5(2)(a) | Not required |
| Legal obligations (tax, accounting, VUK) | KVKK Art. 5(2)(c) | Not required |
| Legitimate interests (service improvement, security) | KVKK Art. 5(2)(d) | Not required |
| Marketing: email and advertising measurement | KVKK Art. 6(1) Consent | Explicit Consent (Opt-in) |
| Special Categories of Data (health, sexual orientation, etc., where applicable) | KVKK Art. 6(1) Consent | Explicit Consent (Separate, Mandatory) |
6. Data Sharing
6.1 Sharing Authorised by the Customer
-
Payment Providers: payment service providers (international and local)
- Shared: email, company name, payment information (last 4 digits of the credit card)
- Purpose: payment processing and fraud prevention
- DPA: Yes (PCI-DSS compliant)
-
Accounting Representative (Turkey only):
- Where one exists and the customer has notified us
- Shared: company name, VKN, invoice data
- Purpose: tax declaration
6.2 Legally Required Sharing
- Court Order / Prosecutor's Order: upon a lawful request, subject to compliance with all agreements
- Turkey: special requests from competent state authorities (e.g. the Ministry of the Interior)
- EU: limited in accordance with GDPR Article 9 (cases of death, injury, etc.)
- Financial Audit: independent auditor, tax inspectors (upon lawful request)
6.3 Service Providers (Data Processors)
| Provider | Data | Purpose | Location | DPA |
|---|---|---|---|---|
| Cloud hosting infrastructure provider | Data within the scope of the Service | Application and database hosting | Europe | Yes |
| Cloud object storage & content delivery (CDN) provider | Menu images, AI outputs | Storage, CDN | Abroad (including EU regions) | Yes |
| Cloud log & analytics infrastructure provider (Events) | Session, API, payment events | Analytics, system monitoring | Abroad | Yes |
| Transactional email provider | Email (invoices, updates) | Email delivery | Abroad | Yes |
| Application error-monitoring provider (only when configured) | Application errors, stack traces | Error monitoring (when configured) | Abroad (including EU) | Yes |
| Artificial-intelligence service providers (LLM / image generation) | Menu descriptions, prompts | AI processing | Abroad | Yes |
| Advertising measurement providers | Ad click identifier, conversion type, amount and currency | Measuring advertising performance | Abroad | Yes |
All DPAs are covered by contract and are compliant with the GDPR Standard Contractual Clauses (SCC). Recipients are described by category in this Policy; the up-to-date named sub-processor list is available on request and/or via a dedicated sub-processor/DPA page.
6.4 Areas Where Data Is Not Shared
- Usernames & passwords are not shared with any third party
- Credit card numbers are not held by QRestAI (they are held by the payment service provider)
- Menu content is not copied or sold without the customer's permission
7. Data Retention Periods
Personal data is kept for as long as the purpose of processing requires. When an account is deleted, data other than the records stated below to be subject to a statutory retention period is deleted 90 days later. The same periods apply to all Customers.
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Account information (email, name, password) | While the account is open; deleted 90 days after the account is deleted | Contract |
| Menu content and images | For the duration of the subscription (the Customer may delete); deleted 90 days after the account is deleted | Contract |
| AI outputs (text, images, video) | For the duration of the subscription (the Customer may delete); deleted 90 days after the account is deleted | Contract |
| Invoice and accounting records | For the statutory retention period; deleted at its end | Tax and commercial legislation |
| Payment and refund records | For the statutory retention period; deleted at its end | Legal obligation |
| Event/analytics records | 90 days raw / 3 years aggregated | System requirements and legitimate interest |
| Deleted account data | Deleted 90 days after the account is deleted | Art. 7 of the KVKK |
7.1 End User (Guest) Data
End User data processed on the Customer's behalf is kept for as long as the service requires and for the applicable statutory retention periods:
- Delivery address and location: Kept only for as long as necessary after the order is completed; afterwards the full address and location are deleted, and only province, district and neighbourhood level information remains for reporting.
- Identity and contact details: Deleted once the End User has not interacted with the restaurant for a period of time. Information that does not identify anyone, such as order counts and amounts, remains.
- Restaurants whose account is deleted: When a restaurant's account is deleted, End Users' identity, contact and address details are deleted 90 days later.
- Deletion on request: At the End User's request, the Customer can delete saved delivery addresses and the End User record before these periods end.
8. Data Protection & Security
8.1 Technical Safeguards
- Encryption: AES-256 (in transit: TLS 1.3)
- Databases: encrypted databases (at rest)
- Passwords: industry-standard one-way password hashing; never stored in plaintext
- 2FA: TOTP (Time-based One-Time Password) offered to users (admin / Turkey applicable)
8.2 Operational Safeguards
- Access control: Role-Based Access Control (RBAC)
- Administration: platform admins and support staff only
- Customer data: organisation-based tenant isolation
- Backup: daily automatic encrypted (at-rest) database backups (retained for 7 days)
- Antivirus & Intrusion Detection: web application firewall (WAF) and intrusion detection/prevention systems + infrastructure provider security controls
8.3 Operational Responsibility
- Personal Data Breach Notification (to the supervisory authority): without undue delay and in any event within 72 hours of becoming aware of the breach. In Türkiye to the Personal Data Protection Board (KVKK Article 12), in the European Union to the competent supervisory authority (GDPR Article 33)
- Personal Data Breach Notification (to the individual): where the breach is likely to result in a high risk to their rights and freedoms, within the shortest reasonable time (GDPR Article 34, KVKK Article 12)
- Audit Logs: all administrative operations are recorded
9. User Rights (GDPR & KVKK)
9.1 Turkey (KVKK Articles 11-12)
Users have the following rights:
| Right | Description | Response Time |
|---|---|---|
| Right of Access | To learn what data about them is processed | 30 days |
| Right of Rectification | To correct inaccurate/incomplete data | 30 days |
| Right to Erasure (Right to be Forgotten) | To request deletion of their data | 30 days |
| Restriction of Processing | To object to specific processing | 30 days |
| Right to Portability | To transfer their data to another provider | 30 days |
| Withdrawal of Explicit Consent | To withdraw marketing consent | Immediate (on request) |
| Objection to Automated Decisions | To object to automated decision-making / profiling | 30 days |
Request Method: [email protected] or Account Settings → "Data Subject Rights" (linked in the Panel)
9.2 EU (GDPR Articles 15-22)
| Right | Description | GDPR Article |
|---|---|---|
| Right of Access | To obtain their own data | Art. 15 |
| Rectification | To correct inaccurate data | Art. 16 |
| Erasure (Right to be Forgotten) | To request deletion of their data | Art. 17 |
| Restriction of Processing | To stop processing for specific purposes | Art. 18 |
| Portability | To receive data in a structured, commonly used format | Art. 20 |
| Objection | To object to processing based on legitimate interests | Art. 21 |
| Protection Against Profiling | To object to fully automated decision-making | Art. 22 |
| Children's Rights | Parental consent for customers under 16 | Art. 8 |
Request Method: [email protected] or the in-app Portal (where available)
10. Protection of Children
10.1 Turkey
- QRestAI does not permit persons under 18 to open an account
- If data of a person under 18 is inadvertently collected, it is deleted immediately
- Parental/guardian consent may be requested
10.2 EU (GDPR)
- Aged 16 and over: may open an account with their own consent
- Under 16: parental/guardian consent is mandatory (GDPR Article 8)
- EU member states may set different ages (some at 13)
- QRestAI does not support accounts for persons under 13
11. International Data Transfers
11.1 Turkey → Abroad
- Service providers: cloud object storage & content delivery (CDN) provider, cloud log & analytics infrastructure provider, artificial-intelligence service providers (LLM / image generation), and transactional email provider
- Legal Basis: KVKK Art. 9 (Conditions for Transfer Abroad)
- Condition: the destination country being deemed "adequate" by the Turkish Personal Data Protection Board, OR standard contracts (DPA with SCC)
11.2 EU → Abroad
- Standard Contractual Clauses (SCC): signed pursuant to GDPR Article 46(2)(c)
- Transfer Risk Mitigation measures: GDPR compliance of cloud providers, an EU region option of the content delivery (CDN) provider is available
- Processing outside the EU: carried out under contractual safeguards (SCCs) from the outset of engagement
The Customer is informed that data may also be processed outside Turkey and the EU.
12. Third-Party Services
12.1 Customer-Provided Providers
- Photo CDN: customer-provided photo URLs (e.g. Unsplash, Cloudinary); the terms of those providers apply
- Payment Connection: if the Customer connects its own payment system (where applicable), the terms of that system apply
12.2 Services Selected by QRestAI
All have GDPR/KVKK-compliant DPAs signed.
13. Changes to the Privacy Policy
13.1. QRestAI may update this Policy. Material changes are notified by email at least 30 days in advance.
13.2. Continuing to use the Service after the date of change constitutes acceptance of the new Policy.
13.3. Where renewed consent is required under GDPR Article 13(2)(c) (e.g. a new AI provider), customers will be asked explicitly.
14. Contact Us
14.1 General Enquiries
- Email: [email protected]
- Portal: Account Settings → "Support"
14.2 Data Subject Rights / Privacy Requests
- DPO (Data Protection Officer): [email protected]
- Request Types: access, erasure, objection, portability, etc.
- Response Time: 30 days (GDPR/KVKK)
14.3 Data Breach Reporting / Security Issues
- Email: [email protected]
14.4 Complaints / Applications to Supervisory Authorities
Turkey:
- Personal Data Protection Authority (KVKK)
- Web: https://www.kvkk.gov.tr/
- Complaint Form: https://www.kvkk.gov.tr/Icerik/3666/Sikayetim
EU Member States:
- The Data Protection Authority of the relevant country
- Right of direct application under GDPR Article 77 (without going to court)
15. Definitions
- Data Controller: the person/entity that determines the purposes and means of processing data (QRestAI in this role)
- Data Processor: the person/entity that processes data on the instructions of the controller (cloud infrastructure provider, artificial-intelligence service provider, etc.)
- Personal Data: any information relating to an identified or identifiable natural person
- Processing: any operation such as collection, recording, alteration, use, sharing, deletion, etc.
- Consent: freely given, specific, informed, and explicit agreement
- Legitimate Interests: the situation where processing serves the legitimate interests of the controller or third parties