← Ana sayfa

Aydınlatma Metni

Privacy notice

GİZLİLİK POLİTİKASI VE KVKK / GDPR AYDINLATMA METNİ

Veri Sorumlusu: MacroSmart Danışmanlık ve Yönetim Hizmetleri Limited Şirketi (“Şirket”, “biz” veya “QRMenuPort”)

Gizliliğinize önem veriyoruz. Bu metin, platformumuzu kullanan restoran/işletmeler (“Müşteriler”) ile QR kod üzerinden menü görüntüleyen son tüketicilerden (“Ziyaretçiler”) hangi kişisel verileri nasıl topladığımızı, kullandığımızı ve paylaştığımızı açıklar. 6698 sayılı KVKK ve AB GDPR ile uyumlu olacak şekilde hazırlanmıştır.

1. HANGİ VERİLERİ NEDEN TOPLUYORUZ (HUKUKİ SEBEP)

A. Müşteriler (Restoran / işletme sahipleri ve personel):

Kimlik ve iletişim: Ad, e-posta, telefon. Amaç ve hukuki sebep: hesap oluşturma, destek ve sözleşmenin ifası (GDPR md. 6(1)(b)).

Finansal veriler: Fatura bilgileri ve vergi kimliği. Kart bilgileri lisanslı ödeme kuruluşları (ör. iyzico) tarafından işlenir; sunucularımızda saklanmaz. Amaç: ödeme ve vergi/muhasebe yükümlülükleri (GDPR md. 6(1)(c)).

Teknik ve kullanım verileri: IP, giriş bilgileri, denetim kayıtları. Amaç: güvenlik ve dolandırıcılığın önlenmesi — meşru menfaat (GDPR md. 6(1)(f)).

B. Ziyaretçiler (menüyü görüntüleyen son tüketiciler):

Dijital iz verileri: Cihaz tipi, işletim sistemi, IP. Amaç: menünün doğru yüklenmesi, performans ölçümü ve siber güvenlik yükümlülükleri (meşru menfaat ve hukuki yükümlülük).

Not: Standart menü görüntülemede ziyaretçiden ad veya iletişim istenmez; restoran etkileşimli sipariş modülü açmadıkça bu veriler toplanmaz.

2. VERİ PAYLAŞIMI VE YURT DIŞI AKTARIM

Kişisel verilerinizi satmayız. Hizmet için bulut barındırma, ödeme kuruluşları ve kanunen yetkili kurumlarla paylaşım yapılabilir. AEA veya Türkiye dışına aktarımda uygun güvenceler (ör. SCC) sağlanır.

3. KVKK VE GDPR KAPSAMINDA HAKLARINIZ

Bulunduğunuz yere göre aşağıdaki haklara sahip olabilirsiniz:

Erişim ve düzeltme: Verilerinizin bir kopyasını talep etme veya yanlış verilerin düzeltilmesini isteme.

Silme (“unutulma hakkı”): Artık gerekli olmayan verilerinizin silinmesini talep etme.

Veri taşınabilirliği (GDPR): Verilerinizi yapılandırılmış, makinece okunabilir biçimde alma.

İtiraz ve işlemenin kısıtlanması: Meşru menfaate dayalı işlemeye itiraz veya kısıtlama talep etme.

Haklarınızı kullanmak için: macrosmart@hs01.kep.tr — 30 gün içinde yanıtlanır.

Son güncelleme: 09.09.2026


English

PRIVACY POLICY & GDPR NOTICE

Data Controller: MacroSmart Danışmanlık ve Yönetim Hizmetleri Limited Şirketi ("Company", "we", "us", or "QRMenuPort")

We take your privacy seriously. This Privacy Policy explains how we collect, use, and share personal data from restaurants/businesses using our platform ("Customers") and end-consumers viewing menus via QR codes ("Visitors"). This notice is designed to comply with the Turkish Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).

1. WHAT DATA WE COLLECT AND WHY (LEGAL BASIS)

A. For Customers (Restaurant/Business Owners & Staff):

Identity & Contact Data: Name, email address, phone number. Purpose & Legal Basis: To create your account, provide customer support, and fulfill our contractual obligations (GDPR Art. 6(1)(b)).

Financial Data: Billing information and tax ID. Credit card details are processed directly by our licensed payment gateways (e.g., Iyzico/Stripe) and are not stored on our servers. Purpose & Legal Basis: Payment processing and compliance with tax/accounting laws (GDPR Art. 6(1)(c)).

Technical & Usage Data: IP address, login credentials, and audit logs. Purpose & Legal Basis: Ensuring platform security and preventing fraud based on our legitimate interests (GDPR Art. 6(1)(f)).

B. For Visitors (End-Consumers viewing the menu):

Digital Trace Data: Device type, operating system, and IP address. Purpose & Legal Basis: To ensure the menu loads correctly on your device, measure system performance, and comply with cybersecurity laws (Legitimate Interests & Legal Obligation — GDPR Art. 6(1)(f) & (c)).

Note: Standard menu viewing does not require Visitors to provide their name or contact info unless an interactive ordering module is explicitly enabled by the restaurant.

2. DATA SHARING AND INTERNATIONAL TRANSFERS

We do not sell your personal data. We only share data with trusted third parties to provide our services, such as cloud hosting providers, payment processors, and authorized public institutions when required by law. If data is transferred outside the European Economic Area (EEA) or Turkey, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs).

3. YOUR RIGHTS UNDER GDPR AND KVKK

Depending on your location, you have the following rights regarding your personal data:

Right to Access & Rectification: Request a copy of your data or ask us to correct inaccurate data.

Right to Erasure ("Right to be Forgotten"): Request deletion of your data when it is no longer necessary.

Right to Data Portability (GDPR): Receive your data in a structured, machine-readable format.

Right to Object & Restrict Processing: Object to our processing based on legitimate interests or ask us to restrict it.

To exercise your rights, please contact us at: macrosmart@hs01.kep.tr. We will respond within 30 days.

Last updated: 09.09.2026