Privacy policy

Last updated: October 6, 2026

This policy explains how personal data is processed when you visit qrdip.com or contact us about the qrdip partner programme. For data processed inside a partner's restaurant panel, see theplatform privacy notice.

1. Controller

The controller is Utku Berberoğlu, a natural person (sole proprietor) established in the Republic of Türkiye ("we"). Contact: the contact form.

2. What we collect

  • Contact form: the details you choose to send - your message, how to reach you (e-mail or phone), and optionally your company, country, number of restaurants and the plan you are interested in. We also record the time of the request and, briefly, your IP address to protect the form against abuse (rate limiting).
  • Server logs: when you load a page, our web server records technical data (IP address, time, requested page, browser type) for security and troubleshooting.

No cookies, no analytics, no tracking. This website does not set cookies and does not use analytics, advertising or social-media tracking tools. Fonts are served from our own server.

3. Why we process it (legal bases)

  • To answer your request and prepare a partner offer - steps taken at your request before a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
  • To keep the website and the form secure and prevent abuse - our legitimate interest (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).

4. Who receives it

We do not sell or rent personal data. Data is processed by service providers acting on our behalf: our hosting provider (servers in the European Union) and our e-mail provider, which forwards contact requests to us. We may disclose data where required by law.

5. International transfers

We are based in Türkiye and our servers are in the European Union, so data may be processed in both. Where a transfer requires safeguards under GDPR or KVKK Art. 9, we rely on the mechanisms those laws provide.

6. How long we keep it

  • Contact requests: up to 24 months after our last exchange, unless they lead to an agreement (then for the duration of the agreement and statutory retention periods).
  • Server logs: a few weeks at most.

7. Your rights

Depending on where you live, you may request access to, correction or deletion of your data, restriction of processing, data portability, and object to processing based on legitimate interests (GDPR Art. 15-21; KVKK Art. 11). Send your request through the contact form. You may also complain to a supervisory authority - in Türkiye the Personal Data Protection Authority (kvkk.gov.tr), in the EU your national data protection authority.

8. Security

The website is served over HTTPS and access to stored requests is restricted. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Changes

We may update this policy; the current version is always published on this page with its date.

Related documents