STAYA

Privacy Policy

Last updated: 14 August 2026

Privacy PolicyTerms of UseData DeletionWhatsApp numbers we operateTürkçe

Who is responsible for what. STAYA is a data processor. The data controller for guest data is the hotel using the service: the hotel collects guest information and decides on retention and deletion. STAYA processes that data only on the hotel's instructions and only in order to provide the service to the hotel.

1. What data we process

Data entered into the system by the hotel, or shared by the guest during a conversation:

DataWhy it is needed
Full nameTo address the guest by name
Mobile phone numberThe address the WhatsApp message is sent to
Room numberTo connect the request to the correct room
Check-in / check-out datesTo send messages at the right time
Message contentTo understand and answer the request
Request records (orders, reservations, work orders, feedback)So hotel staff can carry out the work
Language preferenceTo reply in the guest's own language

Data we do not process: identity or passport numbers, payment card details, invoice and folio amounts, nationality. When guest lists are imported from a hotel system, these fields are filtered out in the browser and never reach our servers.

2. Legal basis (KVKK Art. 5)

Processing is carried out under the Turkish Personal Data Protection Law No. 6698 (KVKK) on the following grounds:

3. Who the data is shared with

RecipientPurposeLocation
Meta Platforms (WhatsApp Business Cloud API)Message deliveryOutside Türkiye
OpenAIResponse generation and text analysisOutside Türkiye
Hetzner Online GmbHServer hostingGermany (Nuremberg)
SentryError monitoring (personal data scrubbed)Outside Türkiye

These transfers are technically required in order to provide the service. Data is never used for advertising, never sold and never marketed to third parties. It is not used to train models.

4. Retention

Guest data is retained for as long as the hotel's contract with STAYA remains in force. When the contract ends, the hotel's data is deleted within 30 days upon request. A hotel may request deletion of an individual guest's data at any time.

5. Guest rights (KVKK Art. 11)

A guest has the right to learn whether their data is being processed, to request information about it, and to request its correction or deletion. Because the hotel is the data controller, such requests should be addressed to the hotel first; once the hotel passes the request on to us, we carry it out technically. You may also write to us directly — see Data Deletion.

6. Security

7. Changes

When this policy is updated, the new version is published on this page and the date above changes.

8. Contact

iletisim@stayai.net