This notice explains how personal data is handled in Genix Hotel and sets out the terms on which Genix Bilgisayar — Cansu Aydin ("Genix", "Processor") processes personal data on behalf of the customer ("you", "Controller"). It forms part of the Terms of Service and serves as the data processing agreement required by Article 28 GDPR. By ticking the consent box during sign-up you confirm that you have read it.
| Data | Controller | Our role |
|---|---|---|
| Your account: name, e-mail, phone, business name, subscription status | Genix | Controller — see the Privacy Policy |
| Guest and business records you enter: reservations, guests, payments, identity documents, notes | You | Processor — we act only on your documented instructions |
Your responsibility. When you enter your guests' personal data into Genix Hotel, you decide why and how it is processed. You must have a lawful basis for doing so, inform your guests as required, and honour their rights. Genix never uses your guests' data for its own purposes.
We process personal data only to provide the Service described in the Terms, for as long as your account exists. On termination we delete or return the data as described in section 8.
You give general authorisation for the following categories of sub-processor. We will inform you of intended changes and you may object on reasonable data-protection grounds.
| Purpose | Provider | Location |
|---|---|---|
| Hosting and storage | Genix-operated servers | Türkiye |
| Transactional e-mail | E-mail delivery provider | EU / EEA |
| Push notifications | Apple Push Notification service; browser web-push services | United States / EEA |
| Payments | App store providers (Apple, Google) and our web payment provider | Depends on provider |
| Guest messaging (only if you enable it) | WhatsApp Business Cloud API (Meta) | United States / EEA |
Our servers are located in Türkiye, which is not covered by a European Commission adequacy decision. Where personal data is transferred from the EEA or the UK, the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies, and supplementary measures including encryption in transit. A copy of the safeguards is available on request.
You may export or delete your data at any time from within the Service. When your account is closed, live data is deleted; copies held in encrypted backups are removed when those backups are rotated. We retain only what applicable law requires us to keep, such as invoices.
Individuals have the right to access, rectify, erase, restrict and object to the processing of their personal data, to data portability, and to withdraw consent at any time. Guests should address their requests to the hotel that holds their booking, as that hotel is the controller. If a request reaches us directly, we will forward it to the relevant hotel and assist as required.
Individuals in the EEA or the UK may lodge a complaint with their supervisory authority. California residents may exercise the rights described in the Privacy Policy. We do not sell or share personal information.
By ticking the box during registration, I confirm that I have read this Data Protection Notice, that I accept it as the data processing agreement between me and Genix, and that I consent to the processing of my own account data as described in the Privacy Policy. I understand that I may withdraw consent for optional processing, such as marketing e-mails, at any time.
Genix Bilgisayar — Cansu Aydin
Inonu Mah. Sefa Sok. No:7/A, 35750 Odemis / Izmir, Türkiye
✉️ info@genixsoft.com.tr · 📞 +90 532 174 73 88