Select Language ×
Türkçe English Deutsch Français Pусский Español Italiano Português Azərbaycan العربية

General Restaurant KVKK

REZTORAN | Personal Data Protection and Processing Policy

PERSONAL DATA PROTECTION AND PROCESSING POLICY

The Reztoran platform, mobile application, website, RezManager, reservation, order, loyalty, customer intelligence, and business processes upper policy

Data Controller Reztoran Electronic Communication Software Trade Inc.
Document Type Corporate Upper Policy
Version / Date 2.0 / 10.07.2026
Contact info@reztoran.com │ Suadiye Mah. Kazım Özalp Sk. C Block No: 60 Inner Door No: 2 Kadıköy / Istanbul
Important: This document applies to the personal data processing activities in effect. Before a new product, integration, artificial intelligence tool, foreign service provider, or data category is activated, the data processing inventory, legal reason, clarification, and transfer mechanism will also be updated.

Version 2.0 | Last Update: 10.07.2026

REZTORAN | Personal Data Protection and Processing Policy

1. Purpose and Scope

This Policy establishes the basic rules regarding the processing of personal data conducted by Reztoran Electronic Communication Software Trade Inc. in accordance with the Law No. 6698 on the Protection of Personal Data ("Law" or "KVKK"), relevant secondary legislation, and decisions of the Personal Data Protection Board.

The policy covers the Reztoran mobile application, the website with the domain www.reztoran.com, restaurant management panel/RezManager, API and channel integrations, reservation, waiting list, order, delivery or take-away, prepayment, loyalty, campaigns, customer support, social features, customer intelligence, analytics, security, human resources, supplier, and physical visitor processes.

This Policy is of a general nature. The obligation to inform under Article 10 of the Law is fulfilled through separate clarification texts prepared specifically for the relevant person and processing activity. In cases where explicit consent is required, the clarification and consent processes are carried out separately; consent or approval is not sought for the fact that clarification has been made.

2. Legal Basis

• Law No. 6698 on the Protection of Personal Data and especially Articles 4, 5, 6, 7, 8, 9, 10, 11, 12, and 13;

• Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform;

• Communiqué on the Procedures and Principles for Applications to the Data Controller;

• Regulation on the Deletion, Destruction, or Anonymization of Personal Data;

• Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad and current standard contracts;

• The Personal Data Protection Board's Decision No. 2026/347 dated 18.02.2026 and related current decisions and guidelines;

• Electronic commercial communication, consumer, electronic commerce, tax, accounting, business, social security, and other applicable legislation.

3. Definitions

Term Description
Explicit consent Consent expressed freely based on information regarding a specific subject.
Data subject Real person whose personal data is processed.
Personal data Any information relating to an identified or identifiable natural person.
Special categories of personal data Data limitedly specified in Article 6 of the Law; race, ethnic origin, political opinion, philosophical belief, religion/sect or other beliefs, appearance and clothing, membership in associations/foundations/unions, health, sexual life, criminal conviction and security measures, and biometric and genetic data.
Data processing Any operation performed on personal data, such as collection, recording, storage, alteration, disclosure, transfer, classification, analysis, deletion, and similar.
Data controller The person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
Data processor The person who processes personal data on behalf of the data controller based on the authority granted by them.
Profiling The automated processing of personal data to evaluate or predict preferences, behaviors, visit frequency, spending, interests, security, or similar characteristics of a natural person.
Anonymization The process of making personal data no longer attributable to a specific or identifiable person, even if it is matched with other data.
Platform Reztoran mobile application, website, RezManager, APIs, widgets, and connected digital services.

4. Reztoran's Data Protection Roles

Reztoran's data protection role is determined by who actually determines the purposes and means of the relevant processing activity rather than the naming in the contract.

Activity Reztoran's Main Role Description
Membership, account, authentication, platform security Data controller The purposes and means related to the operation of membership and platform security are determined by Reztoran.
Reztoran loyalty network, internal advantages and level management Data controller Points, discounts, rewards, levels, abuse controls, and network rules are determined by Reztoran.
Service analytics, customer intelligence, and product development belonging to Reztoran Data controller Scope, data merging, analysis, and usage purposes of outputs are determined by Reztoran.
Personalized marketing and advertising Data controller Conducted within the framework of separate explicit consent and commercial communication preferences.
Technical hosting of customer records managed solely by a restaurant Data processor may be Reztoran does not use the data for its own purposes, and the main decisions regarding processing means are determined by the restaurant to the extent specified.
Transmission of reservation or order to the relevant restaurant and provision of restaurant service Parties may be separate data controllers Reztoran platform services; the restaurant may determine separate purposes regarding its own reservations, services, customer relations, financial and legal obligations.
Processes of banks, payment institutions, and independent channel providers Independent data controllers The legal obligations and service processes of these parties are evaluated separately.

The roles of data controller/data processor in contracts made with restaurants and other business partners, instructions, sub-processors, security, breach notification, data subject applications, data return, and destruction obligations are also regulated.

5. Basic Principles in the Processing of Personal Data

1. Actions are taken in accordance with the law and principles of honesty.

2. Data is ensured to be accurate and, when necessary, up to date.

3. Processing purposes are defined as specific, clear, and legitimate.

4. Data is kept limited and proportionate to the purpose for which it is processed.

5. Data is not kept longer than the period required by the relevant legislation or necessary for the purpose of processing.

6. Unnecessary data is not collected; new features are developed with data protection design and default privacy principles.

7. If the same purpose can be achieved with less data, methods that process less data are preferred.

8. Explicit consent is not made a condition of the contract or service; it is easily revocable.

9. Anonymized or aggregated data is prioritized over personal data.

6. Data Subject Groups

• Members, potential members, individuals creating reservations/orders, and guests included in the reservation;

• Restaurant customers, loyalty program participants, event and experience participants;

• Restaurant owners, managers, employees, call center, and authorized users;

• Couriers, delivery personnel, and employees of delivery service providers;

• Employees and authorized representatives of suppliers, business partners, dealers, channels, integrations, and consulting firms;

• Employees, interns, job candidates, former employees, and their relatives/references when necessary;

• Visitors to the website and mobile application as well as physical location visitors;

• Relevant persons in legal disputes or application processes.

7. Categories of Personal Data Processed

Data Category Main Data Examples
Identity Name, surname, username, date of birth if necessary, T.C. identity or tax identification information only if required by legislation/billing, profile photo.
Contact Phone, email, delivery or billing address, communication preferences, verification information.
Membership and account Membership date, account status, preferences and settings, linked accounts, authentication and session information.
Reservation Restaurant, date-time, number of people, table/area preference, channel, changes, cancellations, waiting list, no-show, prepayment, special requests, guest and staff notes.
Order and delivery Products, options, amount, discount, delivery/take-away preference, address and instructions, preparation/delivery status, courier, cancellation/refund, group or multiple cart information.
Finance and transaction security Payment amount, date, transaction number, token, masked part of the card, bank/payment institution, prepayment, refund, failed transaction, chargeback, and risk records. Full card data must not be stored by Reztoran.
Loyalty Points, discounts, rewards, advantages, levels, earning/usage activity, participating restaurant, and abuse records.
Customer relations Requests, complaints, support correspondence, call or message content, evaluation, solution, and satisfaction information.
Social and user content Profile content, friends/connections, shared lists, group cart, messages, comments, and content made visible by the user.
Location Approximate or exact device location depending on the user's request for the feature; delivery address and location accuracy.
Technical and usage IP, device/operating system, application version, browser, device and advertising identifiers used as necessary, cookie/SDK/beacon data, logs, error and performance records.
Analysis and inference Visit frequency, preference, segment, spending range, loyalty, recovery, recommendation, no-show or abuse indicators; subject to relevant security and legal conditions as long as the personal data quality continues.
Personal and work Employment contract, salary, bank, social security, education, performance, leave, travel, occupational health and safety, access, and corporate system records.
Legal process and compliance Contract, warning, application, lawsuit/enforcement, audit, official authority requests, permission, and rejection records.
Physical security Visitor records and camera footage in necessary areas.
Special categories of data Allergy, health, or accessibility information reported by the user within the scope of necessary service requests; employee health/criminal conviction data and other data specified in Article 6 of the Law only to the extent necessary and lawful.

8. Methods and Sources of Obtaining Personal Data

• Mobile application, website, RezManager, and other Reztoran interfaces;

• Restaurant website and application, reservation widget, restaurant staff, phone, and call center;

• To the extent used, Google, Michelin/Mozrest, WhatsApp, and similar reservation or communication channels;

• POS, ERP, payment, delivery, loyalty, and similar integrations;

• Limited transaction results communicated to Reztoran by banks and licensed payment institutions;

• Cookies, SDKs, system logs, and permitted device features;

• Email, messaging, social media, support channels, forms, and contracts;

• Physical documents, job applications, visitor records, and camera systems;

• Authorized public institutions, judicial authorities, and third parties that can legally share data.

A user providing contact or reservation information of a third party to Reztoran is responsible for ensuring that they are authorized to share this information and for ensuring that the relevant person is informed accordingly. Reztoran will additionally inform the relevant person during the first contact when appropriate.

9. Purposes of Processing and Legal Reasons

Process / Purpose Main Data Legal Reason
Establishment, verification, and management of membership and account Identity, contact, account, security Law Article 5/2(c): necessary for the establishment or performance of the contract; necessary security operations under Article 5/2(f).
Reservation, waiting list, changes, cancellations, reminders, and communication with the restaurant Contact, reservation, special request, transaction Article 5/2(c); in financial/legal obligations Article 5/2(a) and (c); in disputes Article 5/2(e).
Order, delivery/take-away, preparation, courier, return, and group cart Order, address, location, payment, user content Article 5/2(c); in legal obligations Article 5/2(a)/(c); in protecting rights Article 5/2(e).
Management of prepayment and payment results Finance, transaction, and security Article 5/2(c), Article 5/2(a)/(c), Article 5/2(e), and for security Article 5/2(f).
Management of loyalty points, discounts, levels, and rewards Loyalty and transaction Article 5/2(c); in preventing abuse Article 5/2(f).
Customer support, complaint, dispute, and application management Contact, customer transaction, legal process Article 5/2(e), Article 5/2(c), and according to the relevant service Article 5/2(c).
Platform security, access control, prevention of fraud and abuse Technical, security, transaction, risk Article 5/2(f); when a right needs to be protected Article 5/2(e).
Service quality, capacity, anonymous/aggregated statistics, product development Technical, usage, transaction Provided that it does not harm fundamental rights Article 5/2(f); where possible, anonymous or aggregated data.
Personalized campaigns, behavioral profiling, and targeted advertising Contact, behavior, transaction, inference Separate explicit consent under Article 5/1 of the Law; for commercial electronic communications, also approval in accordance with relevant legislation.
Social features, user-to-user communication and sharing Profile, connection, message, content To provide the requested function Article 5/2(c); for additional processes such as guide synchronization or marketing analysis, separate legal evaluation/explicit consent.
Showing nearby restaurants and delivery location Location, address For the service requested by the user Article 5/2(c); for background/continuous or marketing purposes, separate explicit consent. Device permission alone is not a legal reason under KVKK.
Human resources, payroll, social security, occupational health and safety Identity, personal, finance, health Article 5/2(a), (c), (e), (f); for special categories of data, the appropriate conditions in Article 6/2 of the Law.
Supplier and business partner relationships Identity, contact, finance, legal process Article 5/2(c), (e), (f).
Physical security and visitor management Identity, visit, footage Article 5/2(f); when necessary Article 5/2(c)/(e).

10. Special Categories of Personal Data

Special categories of personal data are processed only if one of the processing conditions specified in Article 6 of the Law is present, the processing is necessary and proportionate, and sufficient measures determined by the Board are taken.

• Health, allergy, disability, accessibility, or belief-related information is not requested if not necessary in reservation or order notes.

• In a necessary service request, this information is kept as structured, limited, and short-term as possible; it is not used in general marketing or customer segmentation.

• Access to special categories of data is restricted to those who need to know for their duties; accesses are recorded, and additional security is applied during transfers.

• Employee health and criminal conviction data are limited to the scope necessary for employment, occupational health and safety, social security, or the establishment/use/protection of a right.

• In cases where explicit consent is required, consent is obtained in a specific, separate, informed, and revocable manner.

11. Customer Intelligence, Profiling, and Artificial Intelligence

Reztoran may generate analyses from processing and usage data for the security of the service, capacity management, restaurant performance, user experience, and the provision of suggestions requested by the user. Personalized campaigns, behavioral profiling, or targeted advertising in third-party environments for marketing purposes are subject to separate explicit consent.

• Records across different channels may be matched to the extent necessary and proportionate to ensure correct recognition of the same person and to prevent duplicate records.

• Behavioral and spending information between restaurants is not disclosed to another restaurant on a person basis without clear notification to the relevant person and without a suitable legal reason.

• No-show, fraud, or abuse indicators are not used as definitive judgments; human assessment and the possibility of appeal are provided in decisions that may lead to significant negative outcomes.

• In cases where data is transferred to artificial intelligence providers, data minimization, pseudonymization where possible, prohibition of model training, retention periods, sub-processors, and guarantees for international transfers are determined by contract.

• User messages or operational data sent to generative artificial intelligence are not used for general model training without legal reason and user notification.

12. Domestic Transfer of Personal Data

Personal data may be transferred to the following recipient groups in accordance with the conditions specified in Article 8 of the Law and limited to the purpose:

• Restaurants where reservations are made, orders are placed, or loyalty benefits are used, and only their authorized employees;

• Banks, licensed payment institutions, billing, and financial service providers;

• Couriers, delivery, and logistics providers;

• Reservation, order, POS, ERP, CRM, loyalty, call center, and channel integration providers;

• Cloud, hosting, security, verification, email, SMS, push, support, analytics, and error tracking service providers;

• Advertising, media, research, and campaign providers within the scope of explicit consent and commercial communication preferences;

• Lawyers, financial advisors, independent auditors, insurance, and consulting service providers;

• Authorized public institutions, regulatory authorities, law enforcement, and judicial authorities;

• Parties under confidentiality and data protection obligations during company mergers, investments, restructuring, or asset transfers; data transfer is limited to necessity and proportionality.

13. Transfer of Personal Data Abroad

Personal data may be transferred abroad in cases where cloud, hosting, email, notification, security, analytics, customer support, communication, artificial intelligence, or similar technology services are provided abroad or access is provided to sub-processors abroad.

Regular transfers abroad are carried out using one of the adequacy decisions or appropriate safeguard methods specified in Article 9 of the Law. In the case of using standard contracts, notification to the Authority is made within five business days from the completion of the signatures of the contract. Occasional transfers are not used as an alternative to regular and continuous transfers.

• For each service provider, country, role, data category, purpose, sub-processor, transfer mechanism, and security measures are recorded in the international transfer inventory.

• Regular transfers are not made without adequacy or appropriate safeguards.

• Relying on explicit consent for international transfer is limited to exceptional and occasional conditions; general consent is not obtained as a mandatory condition of the service.

• The relevant person is informed about the transfer and is provided access to current recipient groups.

14. Retention, Deletion, Destruction, and Anonymization

Personal data is retained for the period specified in the relevant legislation or necessary for the purpose of processing. The periods are determined in the personal data processing inventory and retention and destruction policy, considering data category, processing purpose, contract and statute of limitations, financial legislation, security needs, proof of explicit consent/rejection, and the reasonable expectations of the relevant person.

Record Group Retention Approach
Membership and account During active membership; limited records necessary for legal obligations, security, disputes, and proof after account closure for the relevant period.
Reservation and order For the necessary period for service provision, customer support, financial records, and protection of rights; operational notes are kept separate from financial records and for a shorter period.
Finance and accounting For the mandatory periods in tax, trade, and financial legislation.
Marketing explicit consent and commercial communication Active use until consent/approval is revoked; records of revocation and rejection are kept for the necessary period for legal proof.
Technical and security logs Limited period proportional to security, incident investigation, and service continuity risk.
Message and user content For the period required by the function; considering user deletion preferences, complaint/dispute, and backup cycles.
Employee and candidate Employment relationship and legislative periods; for candidates not hired, if there is explicit consent for re-evaluation, the determined limited period.
Camera and visitor Short period proportional to physical security needs; if there is an incident or legal dispute, the relevant records are stored separately.

When the conditions for processing cease, the data is deleted, destroyed, or anonymized in the first periodic destruction. The periodic destruction interval cannot exceed six months. Data in backups is also included in the destruction plan through access restriction and completion of the backup cycle.

15. Technical and Administrative Security Measures

• Data processing inventory, data flow map, and role/authority matrix are maintained; data protection impact assessments are conducted for new products.

• In multi-tenant systems, data isolation is applied based on restaurant, brand, branch, and user.

• Least privilege, separation of duties, strong authentication, privileged account management, and periodic access reviews are implemented.

• Encryption during transfer and in appropriate storage areas; management of keys, passwords, APIs, and confidential information is applied.

• Critical operations and administrative accesses are logged; log integrity and unauthorized access control are ensured.

• Production data is not directly transferred to test environments; anonymization or masking is performed if necessary.

• Vulnerability management, secure software development, code review, patching, penetration testing, and incident monitoring processes are conducted.

• Suppliers and sub-processors are evaluated periodically based on risk before contracts.

• Employees receive regular privacy and data security training; privacy commitments are obtained.

• Additional access, masking, and transfer measures are applied for special categories of data, payment results, messages, and reservation notes.

• Deletion and anonymization processes are recorded; the risk of re-identification of anonymous data is tested.

16. Personal Data Breach Management

In the event of unlawful acquisition, access, disclosure, alteration, loss, or impairment of the availability of personal data, the incident is immediately reported to the information security and data protection officers. The breach is evaluated in terms of scope, affected persons, data categories, risk, measures taken, and notification obligations.

Notification to the Authority is made without delay and in principle within 72 hours from the learning of the breach, in accordance with the Board's decisions. Relevant persons are notified in a manner suitable for mitigating the negative consequences of the breach and without delay. Data processors notify Reztoran within the short period specified in the contract as soon as they learn of the breach.

17. Rights of the Relevant Person and Application

Relevant persons have the right to learn whether their personal data is processed, to request information, to learn the purpose of processing and its appropriate use, to know domestic/international recipients, to rectify, delete/destroy, request notification of these processes to recipients, to object to the result of exclusively automated analysis, and to request compensation for damages due to unlawful processing, in accordance with Article 11 of the Law.

Applications can be submitted in writing to the address Suadiye Mah. Kazım Özalp Sk. C Block No: 60 Inner Door No: 2 Kadıköy / Istanbul, via KEP/secure electronic signature/mobile signature methods, or sent to the email address info@reztoran.com from an email address previously notified to Reztoran and registered in the system, or through the application provided for the purpose of the application. Applications are concluded within a maximum of 30 days. Additional information may be requested based on the nature of the request for identity verification.

18. Organization, Supervision, and Responsibility

• Management ensures sufficient resources and assignment of responsibilities.

• The legal/KVKK function coordinates legislation, clarification, contracts, applications from relevant persons, and breach processes.

• Information security and technology units carry out technical measures, access controls, logs, and incident response.

• Product teams conduct privacy design checks before launching new processing activities.

• Human resources, sales, marketing, customer services, and operations units only process data that is authorized and limited to the purpose.

• The policy, data processing inventory, and VERBIS records are updated regularly and in significant changes.

19. Entry into Force and Update

This Policy enters into force on 10.07.2026. It will be updated in case of changes in legislation, products, data flow, suppliers, or organization. The current version will be published on Reztoran's appropriate digital channels. Substantial changes will be announced to relevant persons in an appropriate manner.

Appendix-1: Process-based Minimum KVKK Checklist

Control Minimum Requirement
New integration Role analysis, data flow, legal reason, clarification, contract, security, international transfer, and retention period must be completed before going live.
New analytics/AI model Purpose, data source, risk of discrimination/misalignment, human control, model training, data minimization, and impact assessment are conducted.
New marketing activity Explicit consent and commercial communication approval are separated; rejection/withdrawal is applied immediately; mandatory service notification is separated from marketing.
Restaurant data access Only the relevant restaurant/branch and authorized role; cross-restaurant visibility is closed unless specifically approved.
Foreign provider Transfer mechanism, standard contract type, 5 business days notification, sub-processor, and data location are recorded.
Special categories of data Necessity test, separate area, additional access and security, short retention, not using in marketing.
Account closure Closing active profile, separating mandatory records, initiating backup and sub-processor destruction cycle.
WhatsApp store