Privacy Policy and Data Protection Notice
Last updated: 18 September 2026
This notice is issued by Diginetics Ltd ("Gustu") as data controller under Türkiye's Law No. 6698 on the Protection of Personal Data ("KVKK"). It covers two distinct groups: restaurant staff who visit gustu.ai and use the contact form, and guests who scan a QR code at a restaurant table and chat with the menu.
What we process, and from whom
Restaurant staff
- Name, email address, restaurant name and message content you submit in the contact form.
- Your email address and authentication details when you create an account.
- Subscription and invoicing details. Card data never reaches us; Stripe processes it.
- Navigation data across the site and dashboard, device and browser information, IP address.
Guests at the table
- The questions you ask the menu and the preferences you share (allergies, diet, budget).
- A session identifier, which branch and table the scan belongs to, a timestamp, and the language you wrote in.
- Menu items you viewed and feedback you gave.
As a guest you do not create an account and do not give us a name, phone number or email. Unless you type personal information into the conversation yourself, we do not collect data that directly identifies you. If you volunteer an allergy, it is used solely to answer you correctly within that session.
Purposes and legal bases
- Providing the service (answering questions, generating recommendations): performance of a contract.
- Responding to your enquiry (contact form): your consent and legitimate interest.
- Improving the product and measuring answer quality: legitimate interest.
- Reporting insight to the restaurant: legitimate interest. Reports are aggregated; an owner cannot identify individual guests.
- Meeting legal obligations (invoicing, record retention): legal obligation.
Use of AI
The menu conversation uses large language models. Your question is sent to a model provider together with the restaurant's menu data to produce an answer. Conversation content may also be sent to our evaluation infrastructure to measure answer quality. We work with our model providers under business terms that exclude the use of this data for general model training.
Who we share it with
We do not sell data. We use the following processors to run the service:
| Service | Purpose | Region |
|---|---|---|
| Vercel | Hosting, edge network and site analytics | ABD / AB |
| Supabase | Database, authentication and file storage | AB |
| OpenAI | Generating chat responses | ABD |
| Vercel AI Gateway | Routing AI model requests | ABD / AB |
| Pinecone | Semantic search over menu content | ABD / AB |
| Braintrust | Response quality evaluation (processes chat content) | ABD |
| PostHog | Product analytics | AB (eu.i.posthog.com) |
| Sentry | Error monitoring | ABD / AB |
| Resend | Transactional email delivery | ABD / AB |
| Stripe | Subscription and payment processing | ABD / AB |
| Workspace email, Maps/Places address autocomplete | ABD / AB |
Some of these processors are located outside Türkiye, so your data is transferred abroad under Article 9 of the KVKK. Transfers are made under data processing agreements with each provider.
In addition: when you chat at a restaurant's table, aggregate insights drawn from that conversation (most-asked questions, language mix, allergen requests) are made available to that restaurant.
Retention
- Contact form records: 2 years after the enquiry is closed.
- Insights extracted from guest conversations: 24 months.
- Account and subscription records: 10 years after the relationship ends.
- Server and error logs: 90 days.
- Analytics records: 12 months.
Your rights
Under Article 11 of the KVKK you may learn whether your personal data is processed, request information if it is, learn the purpose of processing, know the third parties it is transferred to, request correction if it is inaccurate, request erasure where the conditions are met, and object to the outcome of processing.
Send requests to legal@gustu.ai; the data request page explains how. We respond within 30 days at the latest.
Security
Data is encrypted in transit with TLS. Restaurant data is isolated at the database level with row-level access rules: staff at one restaurant cannot reach another restaurant's data. Dashboard access is role-based.
Changes
When we update this notice we change the date above, and we email registered customers about material changes. Questions to hello@gustu.ai.