This notice informs data subjects under Turkish Law No. 6698 about the processing of their personal data. The controller identity, processing inventory, retention periods and application procedure are set out in the relevant service records and notices.
Data controller
The verified trade name and official contact details of the entity providing Checkinger must be published in the identity area of this page. A hotel may separately be a controller or processor for its own purposes; roles must be defined in the applicable agreements.
Data categories and purposes
Depending on the service flow, identity and contact details, reservation details, stay dates, room information, transaction records, device/network security logs and support communications may be processed for reservation verification, self check-in, security, support, service improvement and legal obligations.
- Collect only data that is necessary and proportionate.
- Do not request sensitive data without a separate lawful basis.
- Provide updated information if the purpose changes.
Legal grounds
Each processing activity must be assigned an appropriate ground, such as performance of a contract, legal obligation, legitimate interest, explicit consent or another ground provided by law. Consent-dependent activities must remain separate from essential service functions and be withdrawable.
Collection methods
Data may be collected electronically through web forms, QR journeys, hotel or reservation-system integrations, support email, cookie preferences and technical logs. Hotels must provide any additional notices required for their own processing activities.
Recipients and transfers
Data may be shared with hosting, database, security, notification, support and technical infrastructure providers, authorised hotel users and legally authorised public bodies. International transfers must be assessed against the current Turkish rules and the providers actually used.
Retention and deletion
Data should be retained only for the period necessary for the relevant purpose and applicable legal limitation periods, then deleted, destroyed or anonymised. Exact periods must be set by category, contract and the final retention policy.
Security measures
Appropriate technical and organisational measures should include access controls, strong authentication, encryption in transit, audit logging, backups, incident response and supplier oversight.
Data-subject rights and applications
Data subjects may request information about processing, access, correction, deletion or destruction, recipient details, objection and other rights available under law. Requests should be received through the verified KVKK email or official application address shown in the identity block.