Legal
Our policy explaining how we collect, use, and protect your personal data.
Last updated: 30 September 2026
Legal Pages
This English version is provided for convenience. In case of any discrepancy, the Turkish version prevails. Read the Turkish version
The details of the company acting as data controller under Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu, "KVKK") are set out below:
The following personal data is collected when registering with Genu and using the Platform:
Data processed for staff authorised by the business owner on the garson.genu.tr, mutfak.genu.tr and kasa.genu.tr subdomains:
In principle, staff data is legally managed by the business owner in its capacity as "data controller". Genu stores this data only in its capacity as data processor and makes it available for viewing only to the relevant business.
Data collected from guests who use the digital menu and ordering flow:
Guest feedback and order data is viewed only by the relevant business; Genu does not process this data for advertising or profiling purposes.
Disclosing your identity to the business is your choice. When you log in to the menu with WhatsApp, you are offered the option “Let the business recognise me”. This option comes unticked and is not a condition for logging in, placing an order or using any feature of the menu. If you do not turn it on, the business sees you only with a masked phone number and anonymous order statistics. If you turn it on, only the business you order from can see your name, phone number, birthday (day and month only) and the delivery addresses you used in orders placed with that business; it is not disclosed to other businesses on the Platform. You can withdraw the preference at any time from your menu account.
Customer information recorded by the business. For orders it takes by phone or on the premises, the business may record in Genu your name, one or more phone numbers and your delivery address (optionally with its location), your birthday and notes relating to the order. This record is visible only to that business's authorised staff, is not shared with other businesses and is not linked to your Genu menu account. The data controller for this data is the relevant business; Genu acts in its capacity as data processor. The record is deleted 2 years after the last order or the last update; no WhatsApp message is sent to these numbers through Genu's infrastructure.
Orders placed on behalf of someone else. When a delivery order is placed on behalf of someone else, the name and phone number of the person who will receive it are transmitted to the business only for the delivery of that order; no message is sent to this person and no account or customer record is created for them. The person entering the information declares that they have informed the recipient. Information kept on a saved address is deleted when the address is deleted or 1 year after its last use.
The information needed for the preparation and delivery of your order and for status notifications is transmitted to the relevant business independently of this preference; the legal basis for this is the performance of a contract.
The processing of your personal data is based on the following provisions of Article 5 of KVKK:
Your personal data is not shared with third parties except in the following cases:
For transfers of data abroad, the safeguards under Article 9 of KVKK are applied. Convex operates its SOC 2 certified infrastructure in data centres located within the territory of the European Union.
Login verification codes, password reset links and end-of-day reports you request are sent through the infrastructure of Resend Inc. For this purpose, only the recipient email address and the message content are transmitted.
The messages and numbers of guests who choose to log in to the menu with WhatsApp are processed by Meta via the WhatsApp Business Platform. In this flow, WhatsApp generates a user identifier specific to our business (BSUID); this identifier cannot be used to identify the same person at other businesses. Guest login is entirely optional; the menu can also be used without logging in.
Messages you send to Genu’s WhatsApp line or to a line a business uses through Genu (text, photos, audio, documents, location) and the replies sent to you are stored in order to handle your support request and are seen only by the Genu support team. These conversations are automatically deleted after one year; data received from WhatsApp is not transferred to any third party other than Meta.
The Genu support team's access to a guest record is limited to support requests, responding to applications under KVKK, security and abuse investigations, and requests from competent authorities. Each access is logged together with its justification and is made only by authorised Genu employees; this view is not used for commercial purposes and is not transferred to businesses.
Cloudflare Turnstile is used on login and contact forms to block automated attacks. During this verification, the IP address and browser signals are transmitted to Cloudflare; no personal profile is created.
Payment transactions are carried out by iyzico Ödeme Hizmetleri A.Ş. Your full card number and CVV are never transmitted to Genu servers; they are processed directly in iyzico's secure infrastructure. In order to renew the subscription and show you your saved card, the last four digits of the card, the card brand and the stored card token returned by iyzico are stored on Genu's side. iyzico is a PCI DSS certified payment institution. You can access iyzico's privacy policy here.
Google Analytics is used to understand how the site is used. Analytics storage is off by default: unless you give your explicit consent in the cookie banner, no analytics cookie is written. You can withdraw your consent at any time. Advertising and personalisation signals are off.
The site and panels are hosted on Vercel infrastructure. Vercel's page usage measurement does not use cookies and does not store an identifier that identifies the visitor.
Genu’s AI features run on Google’s Gemini models. Each feature sends only the data needed to do that job:
Staff names are not sent to the AI provider. Staff are passed to Genu’s AI services only under a pseudonymous label (e.g. “Garson-1” (Waiter-1), “Kasiyer-2” (Cashier-2)); their role, shift hours and sales totals may be sent. The mapping between the label and the real name is kept only on the Genu server processing that request, for the duration of the request, and is not transmitted to the provider; before the response is shown to you, the labels are converted back to real names on the Genu server. Names appearing in the user's message or in free-text fields (e.g. cancellation reason, note) in the form in which they are recorded in the business's staff list are also automatically scanned and labelled before sending. Names of persons not in the staff list are outside the scope of this scan; personal data of guests or third parties should therefore not be written in messages and free-text fields.
These features run only when the business uses or turns them on (in the case of the guest menu assistant, when a guest asks a question). Neither personal data of guests (name, phone, address, individual order and order-owner information, loyalty and current-account records, the business's customer book) nor any data received via WhatsApp is sent to the AI services; this limit is enforced on the server side and locked in by tests.
Genu uses Gemini on Google’s free usage tier. On this tier, Google may use the content sent and the responses generated to provide, develop and improve its own services; in this context, the content may be reviewed by Google’s human reviewers. For this reason, Genu limits the data it sends to the AI services to what is listed above; guest personal data, staff names and WhatsApp content are not sent. The transfer is made within the framework of the safeguards under Article 9 of KVKK.
The business may connect an AI client of its own choice (e.g. ChatGPT, Claude) to Genu. This connection is optional and off by default and is set up only with the explicit approval of the business's authorised person from the panel. While the connection is open, the business's own business data and staff data (name, role, shift and working-hour records) are transmitted to the AI provider chosen by the business. Genu does not choose or supervise this provider and has no contract with it; the data controller for this transfer is the relevant business, and the provider's terms of use and privacy terms are between the business and the provider. Genu’s responsibility is limited to setting up the connection in line with the business's instruction, keeping its scope limited to the data categories listed in this policy, and disconnecting it immediately when the business wishes to disconnect. Neither personal data of guests (end users) nor any data originating from WhatsApp is included in this connection.
The following technical and administrative measures are taken to protect your data:
In the event of a possible data breach, notification will be made to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within 72 hours pursuant to Article 12 of KVKK; affected users will be informed as soon as possible.
Under Article 11 of KVKK you have the following rights:
To exercise these rights, you can send an email to bilgi@genu.tr or make a written application via the KVKK Application Form. Applications are answered within 30 days.
Detailed information about the use of cookies on the Platform is available on our Cookie Policy page.
For your questions about our privacy policy or your personal data applications:
Your right to lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) (kvkk.gov.tr) is also reserved.
Table of Contents
Other Legal Pages