Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Randevos LTD (“Randevos”, “we”, “us”, “our”) collects, uses, discloses, retains, and protects personal data, and the rights available to data subjects. Randevos is a business-to-business (B2B) service: our direct customers are the businesses that hold accounts. We process the personal data of those businesses and their staff as a controller, and — on each business’s documented instructions — the personal data of that business’s own end customers as a processor. This Policy is issued in compliance with the Turkish Personal Data Protection Law No. 6698 (“KVKK”), the UK General Data Protection Regulation and the EU General Data Protection Regulation (together, “GDPR”), and other applicable data-protection laws.

1. Data controller and contact

The data controller is Randevos LTD, a company registered in England and Wales under company number 17300468, with its registered office at Monomark House, 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.

In respect of the account, billing, and staff data of the businesses that use the platform, Randevos LTD acts as the data controller. In respect of the end-customer contacts, messages, appointments, and related records that a business manages through the platform, Randevos LTD acts as a data processor and the business is the controller; that business is responsible for the lawfulness of its own processing.

For any request or question concerning personal data, or to reach our data-protection contact, write to [email protected] or call +90 551 511 5000, or write to us at the registered office above.

2. Scope

This Policy applies to our websites, web application, mobile applications, and related services (the “Service”), and to personal data we process in connection with them.

End customers of a business do not hold accounts and interact only through loginless surfaces (for example booking pages, messaging, public menus, and public forms). Where an end customer’s data is processed, the relevant business is the controller and its own privacy notice governs that relationship; we act only as that business’s processor.

3. Categories of data we process

Account and identity data: business name, contact name, email address, telephone number, password (stored only as a salted cryptographic hash), two-factor-authentication settings, role and permissions, chosen plan, and billing country.

Operational data you enter: services, staff, working hours, appointments, customer contacts, notes, inventory, and financial record-keeping entries.

Communications data: conversations exchanged through channels you connect (for example WhatsApp, Instagram, and Facebook Messenger) and messages sent through the Service, processed to answer enquiries and manage bookings on your behalf.

Voice-call data: where a business enables the automated voice assistant and forwards its telephone line, we process the caller’s telephone number, the time and duration of the call, the text transcript of the conversation, a short automatically generated summary, and related technical call metadata. We do not store an audio recording of the call. For the one-time setup of call transfer, an automated verification call may be placed to the number designated by the business, during which only a verification code is read out; no conversation content is processed on that call.

Public social-media interaction data: where a business enables automatic replies to public comments, we process public comments made on that business’s social-media posts, the commenter’s public username and channel identifier, the automated public reply, and any single direct-message reply sent to the commenter in response to their comment.

Lodging guest-identity data (accommodation businesses only): where a business operates lodging accommodation, such as a hotel, motel, guesthouse, or bungalow, and uses the property-management features, we process, on that business’s behalf, the guest-identity information that the law requires the business to record for each stay: full name, identity-document type (national identity number, passport, or identity card), document number, date of birth, nationality, and the arrival and departure dates. The identifying fields (name, document number, and date of birth) are encrypted at rest. We never store an image, photocopy, scan, or photograph of an identity document; only these structured fields are recorded, and each record is immutable, so corrections are made by replacing it.

Transaction and billing data: your subscription and top-up purchases and related invoices. Full payment-card details are entered directly with our third-party payment processor and are not stored on our systems; we retain only limited transaction metadata (such as the last four digits, card brand, and status) as returned to us.

Technical and usage data: log records, device and browser information, IP address, approximate location (country level) used to set your default language and currency and to secure the Service, and product-usage metrics.

4. Purposes and legal bases

To create and administer your account and provide the Service you have requested — performance of a contract.

To process payments, prevent fraud, secure the platform, prevent abuse, and enforce spending limits and technical limits — our legitimate interests and, where applicable, performance of a contract.

To comply with legal, tax, accounting, and regulatory obligations, and to respond to lawful requests from authorities — compliance with a legal obligation.

To send service and security notices essential to the Service — performance of a contract or legitimate interests; and to send optional product news — only where you have given consent, which you may withdraw at any time.

For KVKK-specific processing, we rely on the corresponding lawful grounds in Article 5 of the KVKK, including the necessity of processing for the performance of a contract, compliance with a legal obligation, and our legitimate interests balanced against your rights.

For the lodging guest-identity data described above, the lawful basis is compliance with a legal obligation to which the accommodation business is subject: the statutory duty of lodging providers to record and report guest-identity information to the competent authorities. Under the KVKK this corresponds to processing that is expressly provided for by law and that is necessary for compliance with a legal obligation (Article 5(2)(a) and 5(2)(ç)); it is not based on consent, and a guest cannot withdraw a record that the law requires the business to keep. The accommodation business is the data controller and the party legally obliged to make that report; we act only as its processor, capturing the information and making an audited export available to the business, and the business submits the report to the authorities. We are not the reporting party.

5. Automated processing and AI

To understand enquiries and draft replies and booking proposals, message content is processed using a third-party artificial-intelligence service provider engaged by us as a sub-processor. We apply strict input controls, a pre-filter, and hard per-business spending limits to prevent abuse and unexpected cost.

Where a business enables it, inbound and outbound telephone calls may be answered or placed by an automated voice assistant. During such a call, speech is converted to text and processed by our automated systems and the artificial-intelligence sub-processor described above in the same manner as written messages. We do not store an audio recording of the call: only a text transcript and a short automatically generated summary are retained, for the purposes of handling the enquiry, keeping a record of the interaction, and improving service quality. This processing is carried out in accordance with the KVKK, the GDPR, and the other data-protection laws set out in this Policy. Each such call begins with a spoken notice informing the caller that they are speaking with an automated assistant and that no audio recording is kept, only a written transcript.

Where a business enables automatic replies to public comments, the text of a public comment on that business’s posts is processed in the same manner to draft a public reply and, where appropriate, a single direct-message reply to the commenter. The first automated message identifies itself as coming from an automated assistant. This assistant only replies to the comment; it takes no other action.

The AI only proposes; our booking engine validates and executes actions under its own rules. The Service does not make decisions producing legal or similarly significant effects about a data subject without human involvement, and we do not use your business data or your end customers’ data to train third parties’ foundation models.

The automated assistants cannot access lodging guest-identity data: they cannot read, write, or export it, and no assistant is able to handle an identity-document number, issue refunds, grant discounts, override prices, or read another guest’s data.

6. Disclosure and sub-processors

We do not sell personal data. We disclose personal data only to the following categories of recipients, under written contracts that require appropriate technical and organisational safeguards and processing solely on our instructions: cloud infrastructure and managed-database providers; content-delivery and edge-security providers; our payment processor; artificial-intelligence service providers; telephony and voice-infrastructure providers; speech-recognition and speech-synthesis providers; the providers of the messaging channels you connect; and email- and SMS-delivery providers. Authentication and session management are performed on our own infrastructure.

A current list of our sub-processors, including their identities and locations, is available to account holders on request at [email protected]. We may also disclose personal data where required by law, to establish, exercise, or defend legal claims, to protect the rights, safety, and security of users or the public, or in connection with a merger, acquisition, or sale of assets (subject to this Policy).

7. International transfers

Our core infrastructure hosts data within the European Union. Where a sub-processor processes personal data outside the country in which you are established (for example outside Türkiye, the United Kingdom, or the EU/EEA), we rely on appropriate safeguards recognised under applicable law — such as Standard Contractual Clauses, an adequacy decision, or, for transfers subject to the KVKK, an explicit consent, a commitment letter, or another lawful transfer mechanism.

Voice calls are processed in real time: during a call, speech audio is streamed to, and transcript text is processed by, the telephony, speech-recognition, speech-synthesis, and artificial-intelligence sub-processors described in this Policy, which may be located outside Türkiye, the United Kingdom, or the EU/EEA. Such transfers take place only under the safeguards described above; for transfers subject to the KVKK, we rely on the transfer instruments recognised under Article 9 of the KVKK — including the standard contract, notified to the competent authority where required — or another lawful transfer mechanism.

We do not disclose lodging guest-identity data to the artificial-intelligence, telephony, or speech sub-processors, and we do not transmit it abroad for any statutory reporting; where a report is required, the accommodation business submits it directly to the competent domestic authorities.

8. Retention

We retain account and operational data for as long as your account is active and for a limited period afterwards to satisfy legal, tax, accounting, and dispute-resolution obligations, after which we delete or irreversibly anonymise it. Security and audit records are retained in tamper-evident form for as long as necessary to investigate incidents and meet those obligations. Where a business instructs us to delete end-customer data, we do so subject to those retention requirements.

Call transcripts and summaries, and public-comment interaction records, are retained on the same basis as other communications data: for as long as the relevant business account is active and for the limited period described above, or until the business that is the controller instructs deletion, subject to mandatory retention requirements.

Lodging guest-identity data is retained for the period required by the law that obliges the business to record it, and is then deleted. Where a guest requests erasure of identity data that is no longer subject to a statutory retention duty, that request is honoured.

9. Security

We implement technical and organisational measures appropriate to the risk, including database-level tenant isolation with row-level security, encryption of secrets in a protected vault, encryption of data in transit, least-privilege access, hard spending caps, rate limiting, and a tamper-evident audit log of security-relevant actions. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

If a personal-data breach occurs that is likely to result in a risk to data subjects, we will notify the competent supervisory authority and, where required, affected controllers and data subjects, within the timeframes required by applicable law.

10. Your rights

Subject to applicable law, you have the right to be informed about, access, rectify, erase, restrict, and object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. Under the KVKK you also have the right to learn whether your data is processed, to request information about the processing, to learn its purpose and whether it is used accordingly, to know the third parties to whom it is transferred, to have inaccurate data corrected, to request erasure or destruction, to have such actions notified to third parties, to object to results arising solely from automated analysis, and to claim compensation for damages caused by unlawful processing.

To exercise these rights, contact [email protected]. We may need to verify your identity. You also have the right to lodge a complaint with a supervisory authority — in Türkiye, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu); in the United Kingdom, the Information Commissioner’s Office; or your local EU/EEA authority. End customers should contact the business they interacted with, which is the controller of their data; we will support that business as its processor.

11. Children

The Service is intended solely for businesses and their authorised adult staff and is not directed to children. We do not knowingly collect personal data directly from children through the Service. Where a business processes an end customer’s data, that business is responsible for any age-related consent required under applicable law.

12. Marketing and electronic messages

We send you service and security communications as part of providing the Service. We send optional promotional communications only with your consent, and every such message includes a means to opt out.

Where you use the Service to send messages or run campaigns to your own end customers, you are the sender and the controller. You are solely responsible for obtaining every consent and completing every registration required by applicable law — including, in Türkiye, prior consent and registration with the Message Management System (İYS) for commercial electronic messages under the applicable regulations — and for honouring opt-outs. We provide tools; we are not responsible for the lawfulness of the messages you choose to send.

The same applies to outbound automated calls. Outbound calls (for example appointment reminders, confirmations, or rescheduling calls) are placed only for call types you have expressly enabled. You are the caller of record and are solely responsible for any consent or registration required for such calls under applicable telemarketing and electronic-communication rules — including, in Türkiye, prior consent and İYS registration where a call is promotional in nature.

13. Cookies

We use strictly necessary cookies and similar technologies to operate the Service, keep your session secure, and remember your preferences, together with security technologies that protect the Service against abuse. Details are set out in our Cookie Policy.

14. Deleting data obtained via Meta platforms

Where a business connects a messaging channel operated by Meta (WhatsApp, Instagram, or Facebook), we receive and store limited data about the end customers who message that business or, where comment auto-reply is enabled, comment publicly on that business’s posts — principally the conversation and its messages, the public comment and any automated reply, and the customer’s channel identifier and display name. In line with our KVKK and GDPR obligations set out above, you may request deletion of the data we hold about you that was obtained through those platforms.

You can request deletion in three ways: (i) from your Facebook or Instagram account settings, remove our application — Meta then sends us a data-deletion request and we delete the conversation data associated with your channel identifier; (ii) email [email protected] asking us to delete your data, identifying the channel and account you used; or (iii) if you hold a business account, delete your account and its data from the in-application account settings (Danger Zone). Full instructions are published at /data-deletion. When a request is completed we provide a confirmation code and a status page at /data-deletion/status confirming the outcome; we retain only a non-identifying record of the request as required to evidence compliance.

15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here, revise the date above, and, for material changes, provide notice in-product or by email. Your continued use of the Service after the effective date constitutes acknowledgement of the updated Policy.

16. Contact

Questions or requests concerning this Policy or your personal data: [email protected] · +90 551 511 5000 · Randevos LTD, company no. 17300468, Monomark House, 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.

Randevos

Welcome back

Log in to your Randevos dashboard.

Forgot password?

New to Randevos?

By continuing you agree to our Terms and Privacy Policy.

Privacy Policy · Randevos