Back to home

Privacy Policy and KVKK Disclosure

Last updated: 10 August 2026

At Restomia we process your restaurant's and your guests' data in line with Turkish Personal Data Protection Law no. 6698 (KVKK). This document explains which data we process and why, who we share it with, and what your rights are.

1. Data controller

Restomia is the data controller for the personal data covered by this document. Our contact details are at the end of this page.

2. Data we process

Account data (name, email, phone, restaurant name), business data (stock, sales, invoices, menu, staff records), supplier data (company name, contact number, product and price information), order and payment records, and the technical records needed to run the service (session information, error logs).

3. Purposes of processing

We process data to provide and maintain the service, produce your stock and cost figures, deliver your supplier orders, run invoicing and payments, support you, and meet our legal obligations. We do not sell your data to third parties for advertising.

4. Legal basis

Our processing relies on the establishment and performance of a contract, compliance with legal obligations and legitimate interest under article 5 of KVKK. Where explicit consent is required we obtain it separately, and you may withdraw it at any time.

5. Sharing and service providers

Your data is shared only to the extent needed to run the service, and only with providers of the following kinds: hosting and database infrastructure, email delivery, WhatsApp messaging infrastructure, the payment institution, and the AI provider used to read invoice data. For supplier orders, only the information required to deliver the order is shared with that supplier.

6. Payment data

Card details never reach Restomia's servers and are never stored by us. Payments complete on the licensed payment institution's own page; only the result and amount of the transaction are reported back to us.

7. Retention

We keep your data for as long as your account is open. When you close it, the related data is deleted except for records we are legally required to retain — financial records in particular.

8. Security

Every restaurant's data is isolated at the database level with row-level access rules; no account can reach another restaurant's data. Connections are encrypted and privileged operations are additionally verified server-side.

9. Cookies

We only use cookies that are strictly necessary: the session cookie that keeps you signed in, your language preference, and the anonymous guest identifier used when rating dishes on the QR menu. We use no advertising or profiling cookies.

10. Your rights under KVKK

Under article 11 of KVKK you have the right to learn whether your personal data is processed, request information about it, learn the purpose of processing, know the third parties it is transferred to at home or abroad, request correction if it is incomplete or inaccurate, request erasure or destruction, and claim compensation for damages. You can send requests through the contact channels below and we respond within 30 days at the latest.

Contact us

For any question, request or application regarding these documents, you can reach us through the channels below.