For users in Türkiye, the Turkish version of this document is the legally binding text.
1. Data Controller
Your personal data is processed by Benetti Tasarım İç Mimarlık-Mimarlık ve İnşaat Limited Şirketi ("HotelPilot") as data controller under the Turkish Personal Data Protection Law ("KVKK"). Contact: iletisim@hotelpilot.net.
2. Data We Collect
- Account data: name, email, phone, property/company name, user role.
- Usage data: sign-in logs, IP address, browser/device info, in-app activity logs.
- Billing & payment data: plan, invoice details, amount and date. We never see or store your card details — payments are processed by the PCI-DSS compliant payment provider iyzico.
- Guest/business data: reservation and guest records you enter to run your property. Here you are the controller and HotelPilot is the processor.
- Cookies: strictly necessary cookies, plus analytics cookies subject to your consent.
3. Purposes of Processing
- Providing the service and managing your account,
- Subscription, billing and payment operations,
- Support, security, error detection and abuse prevention,
- Compliance with legal obligations (KBS, e-Invoice, Law 5651),
- Product announcements where you have consented.
4. Payment Security & iyzico
Online payments are processed via iyzico, a licensed payment institution. Sensitive card data (number, expiry, CVV) is handled directly by iyzico; HotelPilot neither accesses nor stores it. All transfers are protected with 256-bit SSL/TLS and may use 3D Secure over licensed card schemes including Visa and MasterCard.
5. Cookies
Strictly necessary cookies (session, security, language) are required for the site to function. Analytics cookies run only with your explicit consent. You can manage or delete cookies from your browser settings at any time.
6. Data Sharing & Third Parties
Your data is shared only as needed for payments (iyzico), email delivery, cloud hosting (Google Cloud / Firebase) and any integrations you enable (channel manager, e-Invoice, KBS), under those providers' privacy commitments. Disclosure to public authorities occurs only where legally required.
7. Retention
Data is kept for as long as necessary for its purpose and for statutory retention periods. On termination, your business data is delivered in digital format (CSV/JSON) on request and then permanently deleted.
8. Your Rights
Under Article 11 of the KVKK you may learn whether your data is processed, request information and correction or erasure, learn the third parties to whom it was transferred and object to processing. Contact iletisim@hotelpilot.net.
9. Security
Data is protected with 256-bit SSL/TLS encryption, role-based access and regular backups. No transmission over the internet is ever 100% secure.
10. Changes & Contact
We may update this policy; the current version is published here with its effective date. Questions: iletisim@hotelpilot.net.