Privacy Notice (KVKK)

Disclosure under Article 10 of Turkish Personal Data Protection Law No. 6698

Last updated: 28 July 2026

This notice explains how personal data is processed when you use the guest request system, hotel pages, reservation ledger and staff panel provided through the otelM platform. If the hotel you are staying at has its own privacy notice, that notice governs the relationship between you and the hotel; the explanations here describe how the platform works alongside it.

1. Data controller and data processor

The hotel where you use the service is the data controller for your personal data; it decides why and how the data is processed. otelM is a data processor acting on behalf of and on the instructions of the hotel: we build, host and secure the platform, but we do not use the data for our own purposes, share it with other hotels or sell it to third parties. Each hotel's data is isolated at the database level; staff of one hotel cannot see another hotel's records.

2. Personal data we process

The data processed on the platform differs by the surface it is collected on:

  • Request data (guest): room number, the service you select and its quantity, the urgency flag, the optional note you write (up to 500 characters), and the times a request is received, taken, completed or cancelled.
  • Room verification data: the guest surname and date of birth entered into the system by the hotel. These two items are used only for comparison when the room page is opened; they prevent requests being sent in the room's name if the QR link reaches someone else.
  • Reservation and offer records (entered by hotel staff): full name, phone, e-mail, stay dates, number of adults and children's ages, room type, amount and internal hotel notes.
  • Staff account data: full name, username, department and title, shift information, profile picture if any, and session records.
  • Technical data: the language preference cookie, the session cookie created when staff sign in, and short-lived server logs kept by our hosting providers for security purposes (including IP addresses).

The system never asks guests for an ID or passport number, address, location, payment card details or health data. The note field is free text; please do not write identity, contact or health information in it.

3. Purposes of processing

  • Delivering your request to the right department, having it taken on and fulfilled.
  • Sending an instant notification so hotel staff see the request in time.
  • Ensuring the room page is used only by the guest staying in that room, and preventing false requests and misuse.
  • Enabling the hotel to manage reservation, offer and stay records.
  • Measuring service quality and internal reporting (aggregate metrics such as average response time and number of overdue requests).
  • Maintaining system security, resolving faults and recording critical operations in the audit trail.

Your personal data is not used for advertising, marketing, profiling or automated decision-making.

4. Legal grounds for processing

The processing described above relies on the following grounds listed in Article 5 of the Law:

  • Directly related to the conclusion or performance of a contract (Art. 5/2-c): your requests within the accommodation relationship, and reservation and offer records.
  • Compliance with a legal obligation of the data controller (Art. 5/2-ç): record-keeping and retention obligations arising from legislation.
  • Legitimate interests of the data controller, provided this does not harm your fundamental rights and freedoms (Art. 5/2-f): service quality measurement, system security, prevention of misuse and the audit trail.
  • Your explicit consent: only for optional processing not covered by the grounds above. Where processing relies on consent, you may withdraw it at any time.

5. How data is collected

Data is collected electronically: by you through the page you open by scanning the QR code in your room, by hotel staff through the staff panel, and automatically by the system while a request is handled (timestamps, status changes). No data is collected on paper.

6. Transfers, including transfers abroad

To deliver the service, data is processed on the infrastructure of the following providers. They process it on our behalf and only to the extent the service requires:

  • Database and file storage: Supabase Inc. — where request, reservation and account records are held.
  • Application hosting and delivery network: Vercel Inc. — the infrastructure serving the pages.
  • Instant notification channels: the third-party messaging apps connected by the hotel (today, Telegram Messenger Inc.). The request content — room number, service, quantity and your note if you wrote one — is delivered to the hotel's staff group over this channel.
  • Text translation: DeepL SE — used only to translate the hotel's own content (service names, descriptions); guest requests and personal data are not sent to this service.
  • Competent public authorities: only where there is a request or obligation arising from legislation.

These providers' servers may be located abroad; transfers abroad are made on the grounds set out in Article 9 of the Law. Your data is never transferred or sold to any third party for advertising, marketing or data-trading purposes.

7. Retention periods

Data is kept for as long as the purpose requires. Anything past its period is deleted by an automated job that runs every night:

  • Your request note: automatically deleted 90 days after the request is completed or cancelled — the record itself remains, the note content does not.
  • Notification records: 180 days.
  • Audit trail (who changed what, and when): 365 days.
  • The room–guest link (surname and date of birth): cleared the moment check-out is recorded.
  • Remaining fields of a request record (room, service, time): kept for the period determined by the hotel for service quality reports.
  • Reservation and offer records: kept by the hotel, as data controller, for the duration of its financial and legal retention obligations.

8. Security measures

  • Each hotel's data is isolated at the database level (row level security); authorisation is enforced in the database itself, not only in the application.
  • Room links are generated with random tokens long enough to be unguessable; repeated failed verification attempts result in a temporary lock.
  • All traffic is carried over an encrypted connection (HTTPS).
  • Staff permissions are limited by department and title; critical operations are written to the audit trail.
  • Identity information is not written to system logs, and the number of fields collected is kept to what the purpose requires.

9. Cookies and local storage

No advertising, tracking or analytics cookies are used on this site, and no third-party measurement tool is embedded. Only the records needed for the service to work are kept:

  • Language preference cookie: remembers the language you chose for your next visit.
  • Session cookie: created only when staff sign in, and used to maintain the session; no session is opened on guest pages.
  • Theme (light/dark) preference: not a cookie — it is kept in your browser's local storage and never sent to the server.

10. Your rights under Article 11 of the Law

By applying to the data controller, you may exercise the following rights:

  • Learn whether your personal data is processed and, if so, request information about it.
  • Learn the purpose of processing and whether the data is used in line with that purpose.
  • Know the third parties, in Türkiye or abroad, to whom the data is transferred.
  • Request correction of data processed incompletely or inaccurately.
  • Request erasure or destruction of the data within the conditions set by the Law.
  • Request that correction, erasure and destruction be notified to third parties to whom the data was transferred.
  • Object to an outcome against you arising from analysis carried out exclusively by automated systems.
  • Claim compensation for damage suffered because of unlawful processing.

Please address your applications to the hotel where you are staying, as data controller — through reception or the application channels the hotel has published. Under the Communiqué on the Procedures and Principles of Application to the Data Controller, your application is concluded within 30 days at the latest and is free of charge as a rule. Requests reaching otelM are forwarded to the relevant hotel.

11. Changes to this notice

This notice may be updated as the platform's capabilities grow. The current version is always published on this page; the date at the top shows when it was last updated.

This notice is general information about how the platform works and does not replace legal advice. The privacy notice of the hotel where you are staying, and any explicit consent statements it collects, remain reserved.