Rutba

Personal Data Protection — Privacy Notice

Prepared under Article 10 of Turkish Law no. 6698 on the Protection of Personal Data and the related Communiqué on the duty to inform. This QR menu performs no operation that requires identifying you. Only the data actually processed is described below.

Data controller

Ticari unvan adres Tax No: vergi no
Rutba Turizm Gıda San. ve Tic. Ltd. Şti. (Demo) Karaçayır Mah. Örnek Cad. No: 1, Merkez / Bolu +90 374 000 00 00 Tax No: 1234567890
Rutba Otelcilik A.Ş. (Demo) Sazakçayır Mah. Kartalkaya Yolu No: 7, Bolu +90 374 111 11 11 Tax No: 9876543210

Personal data processed, purposes and legal grounds

IP address

The IP address of every request to the QR menu address is processed. The purpose is security only: limiting excessive requests from one source, stopping invalid QR code attempts, and preventing repeated scans of the same code by the same visitor from inflating the scan counter. Legal ground: Article 5/2(f) of the Law, the legitimate interest of the data controller.

Browser information (user agent)

The string your browser identifies itself with is processed. For the scan limit it is turned into a one-way digest together with the IP address and is not kept there in plain form. It is also read to tell link-preview bots apart from real visitors. It is additionally kept in plain form, with the IP address, in the session record. The legal ground is the same as for the IP address.

Language preference cookie

When you choose to view the menu in Turkish, English or Arabic, your choice is stored for one year in a cookie named rutba_lang. It is written only when you change the language yourself. It is a functional cookie and requires no explicit consent.

Session and form security cookies

Two cookies are strictly necessary for the page to work: the session cookie (rutba-session) and the form security cookie (XSRF-TOKEN). Both expire after roughly two hours. The session record holds your IP address and browser information. As strictly necessary cookies they require no explicit consent.

Scan counters

For each table or room we keep how many times its QR code has been scanned and when it was last scanned. This number is not linked to any person; it is an aggregate counter and not personal data. Its purpose is to notice a QR code that has been covered over or has fallen off.

Panel accounts (venue staff)

For venue staff only: the name, e-mail address and a one-way digest of the password of accounts that sign in to the panel are processed. The purpose is authorisation and account security; the legal grounds are Articles 5/2(c) and 5/2(f) of the Law. No account is created for guests.

Retention periods

Rate-limit counters are deleted after one minute, the scan limit after thirty minutes, and the session record after roughly two hours. IP address and browser information are never kept longer than 90 days. None of this data is reported, exported or used for profiling.

Data that is not collected

This menu neither asks for nor collects your name, telephone number, e-mail address, room number, orders, payment or card details; there is no such field on the page. No location data is taken. No analytics or advertising cookies are used, and there are no third-party trackers, pixels, ad networks or social media plugins. If room service ordering is added later, this notice will be updated before any such data collection begins.

No explicit consent is requested

None of the processing above relies on explicit consent; all of it rests on legitimate interest and performance of a contract (Article 5/2 of the Law). Marketing permission is never requested and no data is processed for marketing. The only cookies that require consent are non-essential ones, and there are none on this page. That is why no cookie banner or consent box is shown.

Transfers

Personal data is not transferred abroad. It is held on the server of the venue’s hosting provider in Türkiye. It is not shared with third parties unless there is a lawful request.

Your rights under Article 11 of the Law

By applying to the data controller you may exercise the following rights:

Applications

Under the Communiqué on the procedures for applying to the data controller, you may submit your application in writing to the data controller address above. Your application will be concluded within thirty days at the latest.

This notice describes the data the system actually processes, and it is updated before any change to that processing takes effect.