Privacy

Privacy policy

This policy explains which personal data Hotel Atlas processes, for which purposes, on which legal bases, with whom the data may be shared, and how long the data is retained. It is written in direct language so you can understand why information is requested when you create an account or use the workspace. It is prepared with Turkish Law No. 6698 (KVKK) and the GDPR where the GDPR applies.

KVKK / GDPR notice

1. Controller

The data controller is Hotel Atlas.

Address: Istanbul, Türkiye (private office).

Privacy contact: privacy@ostero.com. KVKK requests: kvkk@ostero.com.

Hotel Atlas has not appointed a data protection officer.

This information notice is separate from consent. Hotel Atlas provides the notice whenever personal data is processed; optional analytics activities that require consent are controlled through a separate choice.

2. Scope

This policy covers the Hotel Atlas marketing site, account creation and sign-in, organization membership, the /operations workspace, support requests, integrations, camera features, and waste-analysis features.

When an organization enters information about employees, guests, suppliers, or other third parties into its Hotel Atlas workspace, that organization is the controller for its own processing purposes. Hotel Atlas processes that information only on the organization’s documented instructions and under the applicable service agreement.

This policy describes the Hotel Atlas account and platform services. An organization’s own notice for its employees or guests applies separately to processing for which that organization is the controller.

3. Categories of data

Hotel Atlas processes the following personal-data categories within the stated scope:

Data is obtained directly from you through registration and invitation forms, sign-in, product use, and support communications, and through organization administrators, integrations, camera and weight systems, and service providers. Hotel Atlas does not collect personal data from public sources for these purposes.

The presence of a category in this list does not mean that it is collected from every user or for every feature. A category is processed only when you use the relevant feature or the stated event occurs.

  • Identity and contact: first name, last name, email address, and telephone number.
  • Account and authorization: user ID from the authentication account, organization ID, membership, role, and user preferences.
  • Operations data: menus, dishes, ingredients, inventory, orders, prices, shift notes, reports, and workbooks.
  • Transaction-security data: IP address, browser type, device information, request time, session information, error records, and audit records.
  • Analytics data: analytics events and masked session replay only after explicit consent.
  • Integration data: PMS and other synchronization records, messaging-notification data, and email-report recipient information.
  • Image and waste-operations data: camera video files, tray images, object-detection results, and weight events. Hotel Atlas does not perform facial recognition or biometric identification.

4. Purposes and legal bases

Hotel Atlas processes personal data for the purposes below and relies on the corresponding legal bases. Hotel Atlas does not process special-category personal data or criminal-conviction data.

A legal basis explains why processing is permitted; a purpose explains the business activity for which the data is used. The same data may support different purposes under different legal bases. Hotel Atlas does not make optional analytics a condition of creating or using an account.

  • Account creation, authentication, organization membership, and workspace delivery: performance of a contract under KVKK Art. 5(2)(c) and GDPR Art. 6(1)(b).
  • Product security, unauthorized-access prevention, abuse prevention, error detection, and basic technical telemetry: legitimate interests under KVKK Art. 5(2)(f) and GDPR Art. 6(1)(f).
  • Menu, operations, analytics reporting, and support services: legitimate interests under KVKK Art. 5(2)(f) and GDPR Art. 6(1)(f); organization data is also processed under the applicable service agreement.
  • Product analytics and masked session replay: explicit consent under KVKK Art. 5(1) and GDPR Art. 6(1)(a). This choice is optional and does not affect access to the service.
  • Responding to competent authorities, handling disputes, and retaining accounting records: legal obligation under KVKK Art. 5(2)(a) and Art. 5(2)(ç), and GDPR Art. 6(1)(c).

5. Cookies and analytics

Essential storage: session-service information, active-organization information, and the theme preference. This storage is required for account sessions, organization selection, and the interface theme.

Analytics-storage key: `atlas_analytics_consent`. Hotel Atlas uses this key only to store your analytics choice.

Product analytics and session-replay services do not start before explicit consent. After consent, analytics events and masked session replay are enabled; form fields use the default masking setting. If you do not consent, these features remain disabled.

You can change your analytics choice from Settings › Privacy or the Cookie settings link in the footer.

6. Recipient categories and service providers

Hotel Atlas transfers personal data to the recipient categories below only for the stated purposes. This section describes recipient categories rather than the product’s technical architecture or software brands:

Service providers act on behalf of Hotel Atlas under written data-processing terms. A provider change does not by itself change these recipient categories or processing purposes; this policy is updated when a material purpose or recipient-category change occurs.

  • Authentication and session providers: account creation, sign-in, and session security.
  • Hosting, database, and file-storage providers: storage and delivery of account, organization, and operations data.
  • AI and model-processing providers: chat, image, text, and operations analysis initiated by the user.
  • Product-analytics and masked-session-replay providers: usage measurement and product improvement only after explicit consent.
  • Email, SMS, and messaging providers: invitations, support, reports, and notifications.
  • Integration and data-synchronization providers: PMS, inventory, pricing, and reporting data through connections enabled by the user.
  • Competent public authorities, courts, and legal advisers: legal obligations, disputes, and protection of rights.

7. Retention

Account and membership data: until account deletion or the relevant membership ends. Where a legal dispute or legal obligation applies, the relevant record is kept until that obligation ends.

Operations and menu records: in the organization workspace while the service agreement is active, and after termination until the organization’s deletion, return, or anonymization instruction is applied. Accounting and other statutory records are retained for the period required by applicable law.

Camera and processed-video files: 30 days from creation. At the end of that period, files in the `motion` and `motion-annotated` storage buckets and their processing records are automatically deleted.

Analytics data: new collection stops immediately when consent is withdrawn. Previously collected analytics data is deleted when the retention period configured with the relevant service provider ends or when a deletion request is completed.

When a retention period ends, data is deleted, destroyed, or anonymized. If a record must be kept for a legal request or dispute, it is protected only for the period required for that reason.

8. Your rights (KVKK + GDPR)

Under KVKK Art. 11, you may learn whether your personal data is processed, request information about the processing, learn the purposes and whether the data is used for those purposes, learn the recipients in Türkiye or abroad, request correction, request deletion or destruction, request notification of correction or deletion to recipients, object to a result against you from exclusively automated analysis, and claim compensation for unlawful processing.

Where the GDPR applies, you also have the rights under GDPR Arts. 15–22 to access, rectify, erase, restrict processing, port data, object, withdraw consent, and not be subject to a decision based solely on automated processing.

Use Settings › Privacy to export your data or start account deletion. You may also submit a request by email.

We may request additional information to verify your identity. Information may be removed or access may be limited where necessary to protect another person’s rights or confidential business information.

  • Privacy: privacy@ostero.com
  • KVKK: kvkk@ostero.com
  • KVKK requests are completed within 30 days at the latest, depending on the nature of the request.
  • GDPR requests are completed within one month of receipt. This period may be extended by two months where necessary because of complexity or the number of requests; the extension and its reasons are communicated within the first month.
  • If a KVKK request is rejected, the response is inadequate, or no response is provided on time, you may complain to the Turkish Personal Data Protection Board. Where GDPR applies, you may complain to the supervisory authority in your habitual residence, place of work, or the place of the alleged infringement.

9. International transfers

Some recipient categories may operate outside Türkiye or the European Economic Area. Such a transfer takes place only to the extent necessary to provide the service; the data categories, purposes, and recipient categories are described in this policy.

International transfers follow the KVKK rules for transfers abroad and GDPR Chapter V where applicable, using the relevant adequacy decision, appropriate safeguard, or applicable standard contractual terms. Contact privacy@ostero.com to request information or a copy of the transfer safeguard.

10. Automated decision-making and profiling

Hotel Atlas does not make a decision about you based solely on automated processing that produces legal effects or similarly significant effects. AI-generated menu, cost, waste, and operations suggestions are decision-support outputs; the user or organization representative makes the final decision.

11. Security

Hotel Atlas applies technical and administrative measures including HTTPS/TLS in transit, server-side access controls, organization and role checks, rate limits, audit logs, server-side secret storage, and automated deletion processes.

When a personal-data breach is detected, Hotel Atlas performs the risk assessment required by KVKK and GDPR and completes any required notifications within the applicable deadlines.

Security measures are reviewed according to the nature of the data and the processing risk. No internet service can guarantee zero risk, so please report suspected unauthorized access or misdirected communications promptly.

12. Contact and updates

This policy took effect on 4 August 2026. If the policy changes, the revised text will be published on this page. Material changes will be announced to account holders through an in-product notice or email. Contact privacy@ostero.com with questions.