Privacy and personal data

Privacy and KVKK Notice

This notice provides general information about personal data processed through the Ordiva web app, admin panel, booking pages, and support channels.

Effective date: September 6, 2026

1. Growth Assistant — OpenAI

This optional feature uses the OpenAI API after session-specific consent. Visit intervals, package usage, appointment trends, staff workload, available aggregate cost metrics and typed questions are shared. Known customer, staff and service names in the analysis are replaced with codes; stored contacts, private notes and individual wage rates are not sent. Free-text questions must not contain personal or sensitive data. API data is not used for model training by default. Requests use store:false, which does not guarantee zero retention: provider abuse-monitoring logs may be retained for up to 30 days by default, with possible exceptions. Processing may occur abroad. Ordiva keeps temporary conversation context in server memory; it expires after 20 minutes of inactivity. The assistant does not automatically send messages or change appointment or staff records. The business checks customer communication permissions separately.

2. Data controller

Ordiva is an appointment, customer, and business operations platform provided by Potensas Bilişim Teknolojileri Anonim Şirketi. Potensas Bilişim Teknolojileri Anonim Şirketi acts as data controller for Ordiva account, website, security, and platform operation data. When businesses add their own customer data to the Ordiva panel or collect it through a slug booking link, the relevant business is the data controller for those customer records; Ordiva processes such data for service delivery and technical operation.

3. Data categories processed

  • Account data: full name, email, phone, role, verification, and session information.
  • Business data: business name, address, working hours, services, staff, prices, and settings.
  • Appointment and customer data: customer name, contact details, gender, date of birth, appointment time, service, staff, payment method, and transaction history.
  • Support and communication data: support messages, notification preferences, email, and system records.
  • Technical data: IP address, device and browser information, security logs, error records, and cookie-like local storage data.

4. Purposes of processing

  • Creating user accounts, authenticating identity, and providing authorized access.
  • Operating business appointment, customer, staff, finance summary, package, and reminder workflows.
  • Providing online booking and appointment tracking for customers.
  • Running notification, support, security, abuse prevention, and service improvement processes.
  • Meeting legal obligations, managing disputes, and maintaining record security.
  • Technically hosting and processing customer data added by businesses according to the business instructions and platform purpose.

5. Legal bases

  • Processing necessary for entering into or performing a contract.
  • Compliance with legal obligations.
  • Processing necessary for establishing, exercising, or defending rights.
  • Legitimate interests in security, product improvement, and operational management.
  • Consent where required, especially for non-essential cookies and marketing communications.

6. Recipients

  • Cloud hosting, database, email, security, error monitoring, and support service providers.
  • Business account owners, authorized staff, and persons involved in appointment workflows.
  • Authorized public authorities, courts, and regulators where legally required.
  • For cross-border technical transfers, applicable safeguards and consent mechanisms under relevant law.

7. Notifications and marketing communications

Appointment confirmations, reminders, security, account, and support messages may be sent to operate the service. Campaign, announcement, or commercial electronic messages are subject to the recipient consent, opt-out rights, and communication preferences managed by the business.

8. Subprocessors and vendors

Ordiva may use vendors for technical services such as hosting, database, email delivery, security, error monitoring, maps, calendar, analytics, and AI-assisted insights. The current category list is published on the Subprocessors page and material changes are communicated where appropriate.

9. Retention

Personal data is kept for as long as necessary for the processing purpose and applicable limitation, accounting, security, and dispute management periods. After that period, data is deleted, destroyed, or anonymized.

10. Data subject rights

Rights under KVKK Article 11 and, where applicable, GDPR rights such as access, rectification, erasure, restriction, objection, and data portability may be exercised.

11. Security

Ordiva applies technical and administrative measures such as authorization, access control, secure configuration, encryption, logging, rate limiting, and environment variable management. Absolute security cannot be guaranteed for any internet service.

Cookie preferences

Ordiva uses necessary technologies to keep the site secure and useful. Analytics cookies work only with your permission.

Cookie policy