Personal Data Protection — Privacy Notice
Prepared under Article 10 of Turkish Law no. 6698 on the Protection of Personal Data and the related Communiqué on the duty to inform. This QR menu performs no operation that requires identifying you. Only the data actually processed is described below.
Data controller
Ticari unvan adres Tax No: vergi no Rutba Turizm Gıda San. ve Tic. Ltd. Şti. (Demo) Karaçayır Mah. Örnek Cad. No: 1, Merkez / Bolu +90 374 000 00 00 Tax No: 1234567890 Rutba Otelcilik A.Ş. (Demo) Sazakçayır Mah. Kartalkaya Yolu No: 7, Bolu +90 374 111 11 11 Tax No: 9876543210Personal data processed, purposes and legal grounds
IP address
The IP address of every request to the QR menu address is processed. The purpose is security only: limiting excessive requests from one source, stopping invalid QR code attempts, and preventing repeated scans of the same code by the same visitor from inflating the scan counter. Legal ground: Article 5/2(f) of the Law, the legitimate interest of the data controller.
Browser information (user agent)
The string your browser identifies itself with is processed. For the scan limit it is turned into a one-way digest together with the IP address and is not kept there in plain form. It is also read to tell link-preview bots apart from real visitors. It is additionally kept in plain form, with the IP address, in the session record. The legal ground is the same as for the IP address.
Language preference cookie
When you choose to view the menu in Turkish, English or Arabic, your choice is stored for one year in a cookie named rutba_lang. It is written only when you change the language yourself. It is a functional cookie and requires no explicit consent.
Session and form security cookies
Two cookies are strictly necessary for the page to work: the session cookie (rutba-session) and the form security cookie (XSRF-TOKEN). Both expire after roughly two hours. The session record holds your IP address and browser information. As strictly necessary cookies they require no explicit consent.
Scan counters
For each table or room we keep how many times its QR code has been scanned and when it was last scanned. This number is not linked to any person; it is an aggregate counter and not personal data. Its purpose is to notice a QR code that has been covered over or has fallen off.
Panel accounts (venue staff)
For venue staff only: the name, e-mail address and a one-way digest of the password of accounts that sign in to the panel are processed. The purpose is authorisation and account security; the legal grounds are Articles 5/2(c) and 5/2(f) of the Law. No account is created for guests.
Retention periods
Rate-limit counters are deleted after one minute, the scan limit after thirty minutes, and the session record after roughly two hours. IP address and browser information are never kept longer than 90 days. None of this data is reported, exported or used for profiling.
Data that is not collected
This menu neither asks for nor collects your name, telephone number, e-mail address, room number, orders, payment or card details; there is no such field on the page. No location data is taken. No analytics or advertising cookies are used, and there are no third-party trackers, pixels, ad networks or social media plugins. If room service ordering is added later, this notice will be updated before any such data collection begins.
No explicit consent is requested
None of the processing above relies on explicit consent; all of it rests on legitimate interest and performance of a contract (Article 5/2 of the Law). Marketing permission is never requested and no data is processed for marketing. The only cookies that require consent are non-essential ones, and there are none on this page. That is why no cookie banner or consent box is shown.
Transfers
Personal data is not transferred abroad. It is held on the server of the venue’s hosting provider in Türkiye. It is not shared with third parties unless there is a lawful request.
Your rights under Article 11 of the Law
By applying to the data controller you may exercise the following rights:
- To learn whether your personal data is processed
- To request information if it has been processed
- To learn the purpose of processing and whether the data is used accordingly
- To know the third parties to whom it is transferred in Türkiye or abroad
- To request correction if it is incomplete or incorrect
- To request erasure or destruction within the conditions of the Law
- To claim compensation if you suffer loss because of unlawful processing
Applications
Under the Communiqué on the procedures for applying to the data controller, you may submit your application in writing to the data controller address above. Your application will be concluded within thirty days at the latest.
This notice describes the data the system actually processes, and it is updated before any change to that processing takes effect.