At Registpass we take the privacy and security of the personal data processed through our guest identity verification platform seriously. This Privacy Policy explains what role we play on the platform, on whose behalf we process data, the parties we share it with, and your rights as a data subject.
1. Our Roles: Data Controller vs Data Processor
Two distinct data processing activities take place on the Registpass platform, and IHATECH LTD ("Registpass", "we") acts in a different legal capacity in each:
a) For personal data belonging to hotel guests (identity, MRZ, passport, stay details, etc.) we act as a "Data Processor". The actual Data Controller of this data is the hotel that uses our service. The hotel collects and processes this data to meet its obligations under Turkish Law No. 1774 on Identity Notification, Law No. 6698 (KVKK) and EU/UK GDPR. Registpass provides the technical infrastructure solely on the hotel's instructions, within the service agreement and Data Processing Agreement (DPA) between us; we process the data on the hotel's behalf and do not use it for our own purposes.
For this reason, requests about your personal data as a hotel guest should first be directed to the hotel where you stayed. The hotel fulfils your request with the necessary support from Registpass.
b) For data belonging to our website, demo form, subscription account and hotel staff users, we act as a "Data Controller". This category covers hotel managers and employees who create accounts, visitors who request a demo, and website users.
Our contact details as Data Controller:
- Company: IHATECH LTD
- Registration: Registered in England and Wales under company number 16676486.
- Registered Address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
- ICO Registration: We are registered with the Information Commissioner's Office (ICO) under reference number ZC117625, in line with the UK Data Protection Act 2018.
- Contact: [email protected]
2. Personal Data We Process on the Hotel's Behalf (as Data Processor)
On the hotel's instructions we may process the following categories of guest data:
- Identity data: first name, last name, Turkish national ID number, passport number, date of birth, nationality, gender, MRZ data, document serial number.
- Document images: scans of ID cards or passports (encrypted end-to-end).
- Stay data: check-in/check-out dates, room number, reservation details, accompanying guest information.
- Transaction records: KBS notification status, notification date, the staff member who performed the action.
This data is processed solely for filing KBS notifications, synchronising with the hotel management system and DİA pre-accounting, keeping an audit trail, and carrying out the hotel's other explicit instructions. Registpass may not use this data for its own marketing, profiling or commercial purposes.
3. Data We Process Under Our Own Responsibility
- Account and usage data: username, password hashes, session logs, device info, IP address, access logs.
- Contact data: the hotel representative's name, email address and phone number.
- Billing data: subscription details, payment references (card details are processed by Stripe in a PCI-DSS compliant manner; we do not store card numbers).
- Support communications: messages and form content you send us.
4. Purposes of Processing
On the hotel's instructions (as Data Processor):
- Filing KBS notifications on the hotel's behalf as required by Law No. 1774.
- Two-way synchronisation with hotel management systems and the DİA pre-accounting platform.
- Supporting the hotel's statutory retention and audit obligations.
Under our own responsibility (as Data Controller):
- Delivering the service, performing the contract, billing and customer support.
- Measuring service quality, maintaining security, preventing fraud and abuse.
- Complying with legal obligations.
- Where you have given explicit consent, marketing and informational communications.
5. Legal Basis for Processing
For guest data (as Data Processor): the service agreement between us and the hotel, and the processing instructions under KVKK Art. 3/1(ğ) and GDPR Art. 28.
For our own activities (as Data Controller): necessity for the formation or performance of a contract, explicit statutory requirements, compliance with a legal obligation, our legitimate interests and, where required, your explicit consent.
6. Recipients of Your Data
Guest data we process on the hotel's behalf is shared, on the hotel's instructions, with the Turkish Ministry of Interior for KBS notifications, with systems such as DİA that the hotel integrates with, and with the infrastructure providers we use to deliver the service. This data is not shared with any third party without the hotel's written instruction.
For lawful requests from competent public authorities, the relevant hotel is notified in advance to the extent permitted by applicable law.
Data under our own responsibility may be shared with our cloud/infrastructure providers, our payment provider (Stripe), our email/SMS providers, our CRM tools and, where legally required, competent public authorities.
Any transfer abroad is subject to appropriate safeguards under KVKK Art. 9 and GDPR Chapter V (such as standard contractual clauses).
7. Retention Periods
Guest data is retained only for the term of the agreement between us and the hotel and on the hotel's written instructions. On termination, and subject to the minimum retention periods required by applicable law (e.g. statutory periods for KBS records), the data is deleted, destroyed, anonymised or returned to the hotel according to the hotel's choice.
Data under our own responsibility is retained for as long as the purpose of processing requires, and for 10 years for invoice records and for the periods required by applicable law for log records.
8. Security
Your data is protected through advanced hybrid encryption, role-based access control, audit logging and regular security testing. We implement appropriate technical and organisational measures against unauthorised access, loss or disclosure. Our staff are bound by confidentiality obligations.
If a data breach is detected, in our role as data processor we notify the relevant hotel without undue delay (in any event within 24 hours). The hotel, as Data Controller, is responsible for notifying the competent authority.
9. Cookies and Similar Technologies
Our website uses essential and optional cookies for session management, preferences and traffic analytics. You can update your cookie preferences at any time through your browser settings.
10. Your Rights as a Data Subject
Under KVKK Art. 11 and GDPR Arts. 15-22 you have the right to access, rectify, erase or anonymise your data, to object to processing and to data portability.
If you are a hotel guest and your rights concern the hotel where you stayed, you must first apply to that hotel. As the hotel's Data Processor, Registpass provides technical support in this process. If you believe you cannot reach the hotel, you may contact us and we will forward your request to the relevant hotel.
You can submit requests about our own processes directly to us:
- Data deletion requests via the form at /data-deletion-request.
- All other requests to [email protected].
- Requests are resolved within 30 days at the latest.
11. Changes to This Policy
We may update this Policy when necessary. Material changes will be communicated through our website and/or by email. The effective date is shown at the top of this page.
12. Contact and Right to Complain
For any questions about our privacy practices: [email protected]
You also have the right to lodge a complaint with the following supervisory authorities:
- Turkey: Personal Data Protection Authority (KVKK)
- United Kingdom: Information Commissioner's Office (ICO) — IHATECH LTD's ICO registration number is ZC117625; complaints.
This text is provided for informational purposes only and does not constitute legal advice.