For users in Türkiye, the Turkish version of this document is the legally binding text.
1. Data Controller
Your personal data is processed by Benetti Tasarım İç Mimarlık-Mimarlık ve İnşaat Limited Şirketi ("HotelPilot") as data controller under the Turkish Personal Data Protection Law ("KVKK"). Contact: iletisim@hotelpilot.net.
2. Data We Collect
- Account data: name, email, phone, property/company name, user role.
- Usage data: sign-in logs, IP address, browser/device info, in-app activity logs.
- Billing & payment data: plan, invoice details, amount and date. We never see or store your card details — payments are processed by the PCI-DSS compliant payment provider iyzico.
- Guest/business data: reservation and guest records you enter to run your property. Here you are the controller and HotelPilot is the processor.
- Cookies: strictly necessary cookies, plus analytics cookies subject to your consent.
3. Purposes of Processing
- Providing the service and managing your account,
- Subscription, billing and payment operations,
- Support, security, error detection and abuse prevention,
- Compliance with legal obligations (KBS, e-Invoice, Law 5651),
- Product announcements where you have consented.
4. Payment Security & iyzico
Online payments are processed via iyzico, a licensed payment institution. Sensitive card data (number, expiry, CVV) is handled directly by iyzico; HotelPilot neither accesses nor stores it. All transfers are protected with 256-bit SSL/TLS and may use 3D Secure over licensed card schemes including Visa and MasterCard.
5. Cookies
Strictly necessary cookies (session, security, language) are required for the site to function. Analytics cookies run only with your explicit consent. You can manage or delete cookies from your browser settings at any time.
6. Data Sharing & Third Parties
Your data is shared only as needed for payments (iyzico), email delivery, cloud hosting (Google Cloud / Firebase) and any integrations you enable (channel manager, e-Invoice, KBS), under those providers' privacy commitments. Disclosure to public authorities occurs only where legally required.
7. HotelPilot KBS Browser Extension
We offer an optional Chrome extension that automates guest notifications to the Turkish police identity system (KBS). It runs on exactly two sites — hotelpilot.net and kbs.egm.gov.tr — and on no others. It contains no ads or analytics and shares no data with third parties.
- Guest identity data(name, national ID or passport number, date and place of birth, parents' names, nationality, room and stay dates) is read from your HotelPilot account and submitted directly from your browser to the KBS portal, in fulfilment of your legal obligation under Turkish Law No. 1774.
- Your KBS portal credentials are transmitted over HTTPS only when you pair the extension, only to your own extension instance, and are filled into the login form without being stored.
- The one-time EGMSEC code never leaves your browser and is never sent to our servers.
- The only data the extension stores in your browser is the pairing key and the pending notification queue. Both are removed when you uninstall it.
8. HotelPilot Mobile App
The iOS and Android app is the field companion to the same account you use on the web, and it processes the same data for the same purposes. Accounts cannot be created in the app — your property administrator provisions them.
- No advertising, no analytics. The app contains no third-party advertising or tracking components, and your device is never identified for advertising purposes.
- Stored on your device:your session key, in the operating system's secure store (iOS Keychain / Android Keystore), and your appearance preferences. Both are removed when you uninstall the app.
- Face ID / fingerprint is used solely to unlock the session key held on the device. Your biometric data never leaves the device and is never transmitted to us.
- Notifications are shown only with your permission. Reminders such as day-close and overdue check-out are scheduled by the device itself; their contents are not sent to a server.
- Camera, location, contacts and photos are not used.
9. Deleting Your Account
Account deletion is initiated by the administrator of the business account, from Settings → Account in the web panel. In the mobile app, Profile → Delete Account directs you to that step; because the action is account-wide and irreversible, it is deliberately carried out only in the web panel.
A 30-day grace period begins after the request, and you can cancel it from the same screen during that time. When it expires, the account and all associated data — bookings, guest records, payments, documents and uploaded files — are permanently deleted from our servers. Records we are legally required to retain (for example documents mandated by tax legislation) are kept only for that statutory period and remain inaccessible.
You can export your data as CSV/JSON before deleting. If you cannot access your account, send your request to iletisim@hotelpilot.net.
10. Retention
Data is kept for as long as necessary for its purpose and for statutory retention periods. On termination, your business data is delivered in digital format (CSV/JSON) on request and then permanently deleted.
11. Your Rights
Under Article 11 of the KVKK you may learn whether your data is processed, request information and correction or erasure, learn the third parties to whom it was transferred and object to processing. Contact iletisim@hotelpilot.net.
12. Security
Data is protected with 256-bit SSL/TLS encryption, role-based access and regular backups. No transmission over the internet is ever 100% secure.
13. Changes & Contact
We may update this policy; the current version is published here with its effective date. Questions: iletisim@hotelpilot.net.