Legal

Privacy Policy

Our policy explaining how we collect, use, and protect your personal data.

Last updated: 30 September 2026

This English version is provided for convenience. In case of any discrepancy, the Turkish version prevails. Read the Turkish version

1. Data Controller

The details of the company acting as data controller under Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu, "KVKK") are set out below:

  • Name: Özer Güzel / Gelen Medya
  • Tax No: 4530769425
  • Address: Atatürk Mahallesi Ali Kemali Caddesi No:8 D:8 Merkez/Erzincan 24000
  • Email: bilgi@genu.tr

2. Data Collected

2.1 Data of Platform Users (Business Owners)

The following personal data is collected when registering with Genu and using the Platform:

  • Identity and contact: First name, last name and email address. Account login is done with email and password; password reset and verification codes are sent by email.
  • Business information: Business name, address, phone number, opening hours, Wi-Fi details, table and floor layout
  • Payment and billing information: Full name, email, billing address, city, country (payment card details are not stored by Genu; they are kept only in iyzico's secure infrastructure)
  • Technical data: IP address, browser type, session timestamps, access logs

2.2 Data of Staff Accounts

Data processed for staff authorised by the business owner on the garson.genu.tr, mutfak.genu.tr and kasa.genu.tr subdomains:

  • Identity: The staff member's name / nickname (entered by the business owner)
  • Role and authority: Waiter, kitchen, cashier or manager role
  • Authentication: PIN code (stored with a one-way hash algorithm, not kept in plain text)
  • Session and transaction records: Bills opened, order/payment transactions performed, kitchen station interactions (for work tracking and audit purposes)

In principle, staff data is legally managed by the business owner in its capacity as "data controller". Genu stores this data only in its capacity as data processor and makes it available for viewing only to the relevant business.

2.3 Data of End Users (Business Guests)

Data collected from guests who use the digital menu and ordering flow:

  • Interaction data: Which menu items were viewed, view counts (processed anonymously)
  • Order data: Selected products, table number, any notes and special requests, preparation and delivery times (does not contain identity information without menu login; the business may add a name and phone number to an order it takes by phone or on the premises)
  • Feedback: The name, phone number, ratings and comments of guests who fill in the feedback form. Filling in the form is entirely optional; however, a phone number is requested when the form is submitted so that the business can get back to you.

Guest feedback and order data is viewed only by the relevant business; Genu does not process this data for advertising or profiling purposes.

Disclosing your identity to the business is your choice. When you log in to the menu with WhatsApp, you are offered the option “Let the business recognise me”. This option comes unticked and is not a condition for logging in, placing an order or using any feature of the menu. If you do not turn it on, the business sees you only with a masked phone number and anonymous order statistics. If you turn it on, only the business you order from can see your name, phone number, birthday (day and month only) and the delivery addresses you used in orders placed with that business; it is not disclosed to other businesses on the Platform. You can withdraw the preference at any time from your menu account.

Customer information recorded by the business. For orders it takes by phone or on the premises, the business may record in Genu your name, one or more phone numbers and your delivery address (optionally with its location), your birthday and notes relating to the order. This record is visible only to that business's authorised staff, is not shared with other businesses and is not linked to your Genu menu account. The data controller for this data is the relevant business; Genu acts in its capacity as data processor. The record is deleted 2 years after the last order or the last update; no WhatsApp message is sent to these numbers through Genu's infrastructure.

Orders placed on behalf of someone else. When a delivery order is placed on behalf of someone else, the name and phone number of the person who will receive it are transmitted to the business only for the delivery of that order; no message is sent to this person and no account or customer record is created for them. The person entering the information declares that they have informed the recipient. Information kept on a saved address is deleted when the address is deleted or 1 year after its last use.

The information needed for the preparation and delivery of your order and for status notifications is transmitted to the relevant business independently of this preference; the legal basis for this is the performance of a contract.

3. Purposes of Processing

  • Creating the user account and authentication
  • Running business operations: menu publishing, table and bill management, kitchen display, cashier transactions
  • PIN-based secure login for staff role/authority management and work tracking
  • Providing subscription and payment services
  • Issuing invoices and fulfilling legal obligations
  • Technical support and customer service
  • Ensuring platform security and preventing fraud
  • Anonymous statistical analysis to improve service quality
  • Fulfilling legal and administrative obligations (tax, accounting, etc.)
  • Where the user has given explicit consent: product updates and campaign notifications

4. Legal Basis

The processing of your personal data is based on the following provisions of Article 5 of KVKK:

  • Establishment or performance of a contract: Account creation, service provision, billing
  • Legal obligation: Compliance with tax legislation, official notifications
  • Legitimate interest: Platform security, fraud prevention, technical infrastructure improvement
  • Explicit consent: Marketing communications, optional analytics cookies

5. Data Transfers

Your personal data is not shared with third parties except in the following cases:

  • Our service providers: Convex Inc. (USA — data centre: EU West, Ireland), iyzico Ödeme Hizmetleri A.Ş. (Türkiye), Vercel Inc. (hosting), Meta Platforms Ireland Ltd. (WhatsApp messaging), Google Ireland Ltd. (consent-based analytics and AI services), Resend Inc. (transactional email), Cloudflare Inc. (bot protection)
  • Legal requirement: In line with a court order or a request by a competent authority
  • AI client connected by the business itself: While the AI Client Connection (MCP), set up with the explicit approval of the business's authorised person from the panel, is open, business data and staff data are transmitted to the AI provider chosen by the business. The data controller for this transfer is the relevant business; details are given below in the Third-Party Services section.

For transfers of data abroad, the safeguards under Article 9 of KVKK are applied. Convex operates its SOC 2 certified infrastructure in data centres located within the territory of the European Union.

6. Third-Party Services

Resend (Transactional Email)

Login verification codes, password reset links and end-of-day reports you request are sent through the infrastructure of Resend Inc. For this purpose, only the recipient email address and the message content are transmitted.

WhatsApp (Meta) — Guest Login and Notifications

The messages and numbers of guests who choose to log in to the menu with WhatsApp are processed by Meta via the WhatsApp Business Platform. In this flow, WhatsApp generates a user identifier specific to our business (BSUID); this identifier cannot be used to identify the same person at other businesses. Guest login is entirely optional; the menu can also be used without logging in.

Messages you send to Genu’s WhatsApp line or to a line a business uses through Genu (text, photos, audio, documents, location) and the replies sent to you are stored in order to handle your support request and are seen only by the Genu support team. These conversations are automatically deleted after one year; data received from WhatsApp is not transferred to any third party other than Meta.

The Genu support team's access to a guest record is limited to support requests, responding to applications under KVKK, security and abuse investigations, and requests from competent authorities. Each access is logged together with its justification and is made only by authorised Genu employees; this view is not used for commercial purposes and is not transferred to businesses.

Cloudflare Turnstile (Bot Protection)

Cloudflare Turnstile is used on login and contact forms to block automated attacks. During this verification, the IP address and browser signals are transmitted to Cloudflare; no personal profile is created.

iyzico (Payment Processing)

Payment transactions are carried out by iyzico Ödeme Hizmetleri A.Ş. Your full card number and CVV are never transmitted to Genu servers; they are processed directly in iyzico's secure infrastructure. In order to renew the subscription and show you your saved card, the last four digits of the card, the card brand and the stored card token returned by iyzico are stored on Genu's side. iyzico is a PCI DSS certified payment institution. You can access iyzico's privacy policy here.

Google Analytics (Subject to Explicit Consent)

Google Analytics is used to understand how the site is used. Analytics storage is off by default: unless you give your explicit consent in the cookie banner, no analytics cookie is written. You can withdraw your consent at any time. Advertising and personalisation signals are off.

Vercel (Hosting and Cookieless Measurement)

The site and panels are hosted on Vercel infrastructure. Vercel's page usage measurement does not use cookies and does not store an identifier that identifies the visitor.

AI Services

Genu’s AI features run on Google’s Gemini models. Each feature sends only the data needed to do that job:

  • Menu import, translation, product information and image enhancement: The menu photo, PDF or text uploaded by the business; product and category names, descriptions, prices; the product photo to be enhanced.
  • Expense document reading: The image of the invoice, receipt or voucher uploaded by the business. The extracted information is not saved without the business's approval; personal data that may appear on the document (subscriber name, address, identity number) is not transferred to the expense record.
  • Genu Assistant and Genu Assistant · Merkez: The messages the user writes, together with the business context — venue details, menu, areas and tables, happy hour rules, number of open tables and the day's total sales figures, shift templates and the day's assignments (with staff roles and shift hours; staff names are not sent). The Merkez (headquarters) view sends organisation and branch names, branch menus and end-of-day totals per branch (collections, bills, discounts, cancellations, payments, channel, product and category totals, number of new and returning customers), staff sales totals, end-of-day alerts and end-of-day summaries; in these texts, too, staff appear under a pseudonymous label rather than by name.
  • Genu Pazarlama (Genu Marketing): Total sales figures for the last 90 days and their breakdowns (hour, day, product, category, channel, payment), counts of new and returning customers, number of feedback entries and average rating, menu, campaign rules, menu interaction counters and the operator's own marketing notes. Staff names are not sent.
  • End-of-day summary: The totals in the day's end-of-day report (revenue, collections, cancellation and discount totals, durations, best-selling products), the sales totals of staff who took orders and staff who did not turn up for their shift; staff appear under a pseudonymous label rather than by name.
  • Guest menu assistant: The business's published menu and the question the guest writes to the assistant. The guest's identity is not sent.

Staff names are not sent to the AI provider. Staff are passed to Genu’s AI services only under a pseudonymous label (e.g. “Garson-1” (Waiter-1), “Kasiyer-2” (Cashier-2)); their role, shift hours and sales totals may be sent. The mapping between the label and the real name is kept only on the Genu server processing that request, for the duration of the request, and is not transmitted to the provider; before the response is shown to you, the labels are converted back to real names on the Genu server. Names appearing in the user's message or in free-text fields (e.g. cancellation reason, note) in the form in which they are recorded in the business's staff list are also automatically scanned and labelled before sending. Names of persons not in the staff list are outside the scope of this scan; personal data of guests or third parties should therefore not be written in messages and free-text fields.

These features run only when the business uses or turns them on (in the case of the guest menu assistant, when a guest asks a question). Neither personal data of guests (name, phone, address, individual order and order-owner information, loyalty and current-account records, the business's customer book) nor any data received via WhatsApp is sent to the AI services; this limit is enforced on the server side and locked in by tests.

Genu uses Gemini on Google’s free usage tier. On this tier, Google may use the content sent and the responses generated to provide, develop and improve its own services; in this context, the content may be reviewed by Google’s human reviewers. For this reason, Genu limits the data it sends to the AI services to what is listed above; guest personal data, staff names and WhatsApp content are not sent. The transfer is made within the framework of the safeguards under Article 9 of KVKK.

AI Client Connected by the Business Itself

The business may connect an AI client of its own choice (e.g. ChatGPT, Claude) to Genu. This connection is optional and off by default and is set up only with the explicit approval of the business's authorised person from the panel. While the connection is open, the business's own business data and staff data (name, role, shift and working-hour records) are transmitted to the AI provider chosen by the business. Genu does not choose or supervise this provider and has no contract with it; the data controller for this transfer is the relevant business, and the provider's terms of use and privacy terms are between the business and the provider. Genu’s responsibility is limited to setting up the connection in line with the business's instruction, keeping its scope limited to the data categories listed in this policy, and disconnecting it immediately when the business wishes to disconnect. Neither personal data of guests (end users) nor any data originating from WhatsApp is included in this connection.

7. Data Security

The following technical and administrative measures are taken to protect your data:

  • All data transmission is protected by TLS encryption
  • The full card number and CVV are not stored in Genu's database; only the masked information returned by the payment provider and the stored card token are kept
  • Access authorisation is configured according to the principle of least privilege
  • Convex, used as infrastructure, holds SOC 2 Type II certification
  • Regular security scans and vulnerability assessments

In the event of a possible data breach, notification will be made to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within 72 hours pursuant to Article 12 of KVKK; affected users will be informed as soon as possible.

8. Retention Periods

  • Account data: For as long as the account is active and for 2 years from deletion of the account
  • Invoice, payment and accounting records: 10 years as required by law (Turkish Commercial Code (Türk Ticaret Kanunu) Art. 82)
  • Order and bill records: 10 years (Turkish Commercial Code Art. 82)
  • Staff shift, timekeeping and personnel records: 10 years from the end of the employment relationship (Law No. 5510, Art. 86)
  • Transaction and audit records (financial/administrative): 10 years
  • Access and operation logs: 1 year; after this period the email address is not kept in the log and the IP address is stored in truncated form
  • Feedback data: 2 years
  • Support requests and correspondence: 2 years from closure of the request
  • WhatsApp conversations: 1 year
  • Table reservations and waiting list: 1 year
  • Customer information recorded by the business: 2 years from the last order or the last update (kept for as long as a remote-order restriction remains in place)
  • Name and phone number of the recipient in an order placed on behalf of someone else: When the address is deleted or 1 year from the last use
  • Incoming call record (Caller ID): 30 days
  • Login verification codes and login attempt counter: 30 days / 1 day
  • AI assistant chat history: 1 year
  • Desktop application diagnostic logs: 30 days
  • Commercial electronic message and sharing consent records: 3 years from the end of the consent's validity (Law No. 6563)
  • Analytics data: Kept as daily, identity-free counters, indefinitely

9. Your Rights

Under Article 11 of KVKK you have the following rights:

  • To learn whether your personal data is processed
  • If it has been processed, to request information about it
  • To learn the purpose of processing and whether it is used in accordance with that purpose
  • To know the third parties to whom it is transferred in Türkiye or abroad
  • To request its rectification if it is incomplete or inaccurate
  • To request its erasure or destruction under the conditions set out in Article 7 of KVKK
  • To request that the above actions be notified to the third parties to whom it has been transferred
  • To object to a result to your detriment arising from analysis exclusively by automated systems
  • To claim compensation for damage suffered due to unlawful processing

To exercise these rights, you can send an email to bilgi@genu.tr or make a written application via the KVKK Application Form. Applications are answered within 30 days.

10. Cookies

Detailed information about the use of cookies on the Platform is available on our Cookie Policy page.

11. Contact

For your questions about our privacy policy or your personal data applications:

  • Email: bilgi@genu.tr
  • Post: Atatürk Mahallesi Ali Kemali Caddesi No:8 D:8 Merkez/Erzincan 24000

Your right to lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) (kvkk.gov.tr) is also reserved.