KVKK / GDPR

Personal data protection notice

Last updated: 4 August 2026

This notice provides the information required by Article 10 of Turkish Law No. 6698 (KVKK) and Articles 13 and 14 of the GDPR where the GDPR applies. It is an information notice, not a consent form; consent-required processing is requested separately and is optional.

Privacy policy

1. Controller identity

The data controller is Hotel Atlas. Address: Istanbul, Türkiye (private office).

KVKK requests: kvkk@ostero.com. General privacy contact: privacy@ostero.com.

Hotel Atlas has not appointed a data protection officer.

This notice explains why and within what scope Hotel Atlas processes personal data. Where consent is required, the choice is presented separately, clearly, and optionally.

2. Personal data processed

Hotel Atlas processes first name, last name, email address, telephone number, user ID from the authentication account, organization membership, role, user preferences, IP address, browser and device information, session information, error and audit records, menu and operations records, integration records, camera video files, tray images, object-detection results, and weight events for the purposes in this notice. Hotel Atlas does not perform facial recognition or biometric identification.

The complete list does not mean that every item is collected from every user. A category is processed only when the relevant account, integration, camera, weight, or analytics feature is used and the data is needed for a stated purpose.

3. Purposes

Personal data is processed for account creation and authentication, organization and role management, delivery of the /operations workspace, menu and operations features, support, product security, prevention of unauthorized access and abuse, error detection, legal obligations, dispute handling, and product analytics and masked session replay after explicit consent.

A purpose explains the service or security activity for which data is used; a legal basis explains the KVKK condition that permits the processing. Consent is not a condition of using the account or core workspace.

4. Collection method and legal bases

Personal data is collected electronically through registration and invitation forms, sign-in, product use, support communications, integrations, camera and weight systems, essential storage technologies, and analytics technologies after explicit consent. Collection is fully or partly automated.

The legal bases are performance of a contract under KVKK Art. 5(2)(c), legitimate interests under KVKK Art. 5(2)(f), legal obligation under KVKK Art. 5(2)(a) and Art. 5(2)(ç), and explicit consent under KVKK Art. 5(1). Where GDPR applies, the corresponding bases are GDPR Art. 6(1)(b), 6(1)(f), 6(1)(c), and 6(1)(a).

Account, session, and workspace data is required to create an account or use the relevant workspace feature. Product analytics and masked session replay are optional; refusal does not affect service access.

Data may be collected directly from you or through an organization administrator, an integration you enable, or a camera or weight system. Where data is obtained from another person or system, the required notice is provided to the relevant person where practicable.

5. Transfers

Personal data is transferred to authentication and session providers, hosting, database and file-storage providers, AI and model-processing providers initiated by the user, product-analytics and masked-session-replay providers after explicit consent, email, SMS and messaging providers, integration and data-synchronization providers enabled by the user, and competent public authorities where legally required.

Some recipient categories may operate outside Türkiye or the European Economic Area. International transfers take place only to the extent necessary to provide the service and follow the KVKK rules for transfers abroad and GDPR Chapter V where applicable.

The purposes, recipient categories, and transfer safeguards are described in the Recipient categories and International transfers sections of the Privacy Policy. Contact privacy@ostero.com to request information or a copy of the safeguard.

6. Retention periods

Account and membership data is kept until account deletion or the end of the relevant membership. Where a legal dispute or legal obligation applies, the relevant record is retained until that obligation ends.

Operations and menu records are kept in the organization workspace while the service agreement is active and until the organization’s deletion, return, or anonymization instruction is applied after termination. Accounting and other statutory records are kept for the period required by applicable law.

Camera and processed-video files are kept for 30 days from creation. At the end of that period, files in the `motion` and `motion-annotated` storage buckets and their processing records are automatically deleted.

New analytics collection stops when consent is withdrawn. Previously collected data is deleted when the retention period configured with the relevant service provider ends or when a deletion request is completed.

When a retention period ends, records are deleted, destroyed, or anonymized. If a legal request or dispute requires retention, the record is protected only for the period required for that reason.

7. Rights under KVKK Art. 11

You may request to:

  • Learn whether your data is processed
  • Request information if processed
  • Learn the purpose and whether it is used accordingly
  • Know third parties in Türkiye or abroad
  • Request correction of incomplete/inaccurate data
  • Request deletion/destruction under KVKK Art. 7
  • Request notification of correction/deletion to third parties
  • Object to outcomes from exclusively automated analysis
  • Claim compensation for unlawful processing

8. GDPR rights

Where GDPR applies, you have the rights to access and obtain a copy of personal data, rectify inaccurate data, erase data, restrict processing, receive portable data in a structured and machine-readable format, object to processing based on legitimate interests, withdraw consent, and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

GDPR requests are completed within one month. This period may be extended by two months where necessary because of complexity or the number of requests; the extension and its reasons are communicated within the first month. You may also lodge a complaint with the supervisory authority in your habitual residence, place of work, or the place of the alleged infringement.

9. Hotel staff / kitchen imagery

An organization using cameras or waste metering is responsible for providing the required KVKK notice to its employees, guests, and other relevant people. Hotel Atlas does not perform facial recognition or biometric identification. Images are processed only for operations optimization and waste measurement and are retained for 30 days.

10. How to apply

You may submit a request in writing to Istanbul, Türkiye (private office) or by email to kvkk@ostero.com. The request must include your name, surname, signature, Turkish ID number for Turkish citizens or passport/identity number for foreign nationals, service address, email address if available, telephone number, and the subject of the request. Additional information may be requested to verify identity.

Identity verification is performed before the request is processed. Information may be removed or access may be limited where necessary to protect another person’s rights or confidential business information.

Account holders can start data export and account deletion from Settings › Privacy.

KVKK requests are completed within 30 days at the latest, depending on the nature of the request. If the request is rejected, the response is inadequate, or no response is provided on time, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board under KVKK.