Legal Documents
Privacy Policy
Last updated: April 2026 · Otelyon Technology
This Privacy Policy explains how personal data collected during the use of services provided by Otelyon Technology is processed and protected. It has been prepared in accordance with the Turkish Personal Data Protection Law No. 6698 (KVKK).
1. Data Controller
Otelyon Technology acts as the data controller under Law No. 6698 (KVKK). Personal data belonging to employees of customer hotels using our services is processed within the framework of the agreement signed between the customer hotel and Otelyon Technology.
2. Personal Data Collected
During use of the Otelyon product suite, personal data in the following categories may be processed:
- Identity Information: First name, last name, username
- Contact Information: Email address, phone number
- Employment Information: Department, title, shift schedule, attendance records
- System Usage Data: Login/logout times, actions performed, IP address
- Photos: Profile photo (optional) and task photos attached to job records
- Guest Request Data: Service requests submitted via QR (room number, request content)
- Contact Form Data: Name, email, phone, and hotel information shared during demo requests
3. Purposes of Processing Personal Data
Collected personal data is processed for the following purposes:
- Providing and managing Otelyon services
- Creating user accounts and identity verification (2FA)
- Operating task, notification, and messaging services
- Human resources processes (attendance tracking, leave management, timesheets)
- Maintaining system security and audit logs
- Technical support and troubleshooting activities
- Demo requests and commercial communications
4. Legal Basis
Personal data is processed under the following legal bases within the scope of Article 5 of the KVKK:
- Necessity for the establishment or performance of a contract (KVKK Art. 5/2-c)
- Fulfillment of the data controller's legal obligation (KVKK Art. 5/2-ç)
- Necessity of processing for legitimate interests (KVKK Art. 5/2-f)
- Explicit consent (KVKK Art. 5/1) — where the above bases do not apply
5. Data Retention Period
Personal data is retained for as long as the purpose of processing requires and in accordance with legal obligations. Upon termination of the service agreement, data is retained for the retention period stipulated in applicable legislation, and then deleted or anonymized.
6. Sharing Data with Third Parties
Otelyon Technology shares personal data with third parties only under the following conditions:
- Service Providers: Infrastructure services required for system operation (Firebase FCM — push notifications, İletimerkezi — SMS delivery). These providers may only process data within the scope of the service.
- Legal Obligation: In accordance with legal requirements upon request by authorized public institutions and organizations
- Explicit Consent: Provided that written consent has been obtained from the data subject
Personal data is not sold or rented to third parties for marketing purposes.
7. Data Security
Technical and administrative measures taken to ensure the security of personal data:
- Encrypted data transmission via HTTPS / TLS
- SHA-256 password hashing
- Two-factor authentication (2FA / OTP)
- Role-based access control (RBAC) and multi-tenant isolation
- Account lockout mechanism (5 failed attempts → 15-minute wait)
- Audit logging of all critical operations
- Database access restrictions and SQL injection protection
8. Your Rights Under the KVKK
Pursuant to Article 11 of Law No. 6698 (KVKK), you may exercise the following rights:
- To learn whether your personal data is being processed
- To request information if your personal data has been processed
- To learn the purpose of processing your personal data and whether it is being used in accordance with that purpose
- To know the third parties to whom your personal data has been transferred, domestically or abroad
- To request correction of your personal data if it is incomplete or inaccurate
- To request deletion or destruction of your personal data within the framework of the conditions set out in Article 7 of the KVKK
- To object to a result that is to your detriment arising solely from the automated analysis of your personal data
- To demand compensation for damages in the event that your personal data is processed unlawfully
To exercise your rights, you may submit a written request to iletisim@otelyon.com. Requests are finalized within 30 days at the latest.
9. Cookies
The Otelyon website and applications use essential session cookies for session management. No third-party advertising or tracking cookies are used. You can manage cookies through your browser settings; however, disabling essential cookies may cause some features to stop working.
10. Policy Changes
Otelyon Technology may update this privacy policy from time to time. Significant changes will be announced on the website and/or notified to the registered email address. The current policy is always published on this page.
11. Contact
For questions about our privacy policy or the processing of your personal data: