Personvernsammendrag

Personvernsammendrag

De tre bildene sendes først til fal.ai for å lage modellen med Rodin v2. Hvis tjenesten svikter eller ikke er tilgjengelig, sendes de samme bildene til Tripo som reserve.

De opprinnelige bildefilene slettes når behandlingen er fullført. Arkivkopier for kvalitetsforbedring slettes senest innen 30 dager.

En arkivkopi av den genererte 3D-modellen beholdes til den tilknyttede restauranten eller kontoen slettes.

IP-adressen brukes midlertidig for å begrense misbruk; en hash lagres kort i en delt teller og slettes jevnlig. Den brukes ikke til sporing på tvers av nettsteder.

Fullstendig juridisk tekst (engelsk)

Den fullstendige kildeteksten står nedenfor på engelsk. Den oversatte delen ovenfor er et informativt sammendrag, ikke en fullstendig juridisk oversettelse. Kontakt en kvalifisert lokal fagperson om juridiske krav i din jurisdiksjon.

Data controller

The party operating MenuPort acts as the data controller and can be reached at the address below.

This policy is prepared to meet the information obligations under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the EU General Data Protection Regulation (GDPR).

Two kinds of users, two kinds of data

MenuPort has two kinds of users, and the data processed about them is entirely separate: restaurant owners who manage a menu (they create an account) and guests who scan a QR code to view a menu (they do not).

Data processed about restaurant owners

This data is necessary to create the account, provide the service and keep it secure.

Data processed about guests who make reservations

This information is processed to send the request to the restaurant you selected and allow the restaurant to manage it. A restaurant may provide its own privacy-notice and reservation-terms links in the booking form.

Data processed about menu visitors

No account is created for guests viewing a menu, no cookies are used, no advertising identifier or device fingerprint is generated, and no cross-site tracking takes place. Only aggregate counts that help the restaurant improve its own menu are kept:

These counts cannot be linked to a person

The records belong to the restaurant's menu rather than to individuals and consist of totals such as “this product was viewed 40 times”. Because no visitor identifier is created, these counts cannot be associated with a specific person.

The browser's `sessionStorage` is used only to avoid counting the same event more than once in a single visit. The value stored there is a marker, never leaves the device and is cleared when the tab closes; it is not a persistent identifier.

For abuse rate-limiting on the analytics endpoint, a truncated SHA-256 hash derived from the IP address is temporarily stored in the database with a one-minute counter window. The raw IP address is not written to that counter document. Counters expire after about 16 minutes and a cleanup job runs every 15 minutes. Because the hash can associate requests from the same source during this short period, it is pseudonymous rather than anonymous data.

Purposes and legal bases

Recipients and international transfers

The service is delivered through infrastructure providers, and data is processed by the following parties:

About transfers abroad

Some of the providers above are established outside Türkiye and may access data from abroad for support, backup or processing. Your personal data may therefore be transferred abroad.

Such transfers are carried out under KVKK art. 9 and Chapter V of the GDPR, relying on the providers' standard contractual clauses and equivalent security commitments. Using the service includes this transfer; if you do not want it, you should not use the service.

Retention periods

You can delete your account from the Profile screen in the app. Deleting the account permanently removes your restaurants, menus, products, uploaded images, generated 3D models and associated training-archive files. Purchased 3D credits are tied to the deleted account and can no longer be used, transferred or restored; mandatory consumer rights are unaffected. Limited store transaction records may remain for the purposes above, including service security, refund/dispute handling and financial/legal obligations. Deleting a single restaurant also removes that restaurant's archive. Source-photo copies are otherwise automatically removed within 30 days; generated model archive files remain until deletion. Deleted data also disappears from backups once the retention windows above have passed.

Your rights

Under KVKK art. 11 and the GDPR you have the right to:

How to exercise your rights

You can edit your menu content and account details in the app and delete your account at any time. For anything else, write to the contact address below; requests are answered within the statutory time limits.

If you are not satisfied with the outcome, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board or your local supervisory authority.

Security

Data is encrypted in transit, authorisation rules isolate each tenant's data from others, and clients cannot write directly to server-side records. That said, no system can offer absolute security; in the event of a security incident, the notifications required by law will be made.

Children

MenuPort is a service for businesses and is not directed at people under 18. Data is not knowingly collected from children.

Changes

When this policy is updated the date above changes. For significant changes affecting its scope, a separate notice is given in the app.

Kontakt

Spørsmål om dette dokumentet: info@sorin.tech