EU/EEA privacy notice (GDPR)

Updated: · Version: 2026-09-25-v2

Türkçe sürüm ↗

Service provider

DOĞA PET GROOMING · PatiPilot
Zeynep Doğa Bayraktar Zuğurlu

CUMHURİYET MAH. ÇAĞLAYAN SK. KOZA PARK KOZA PARK C BLOK NO: 10 C/B ÇERKEZKÖY/ TEKİRDAĞ

Provider and contact details ↗

Scope in the EU and European Economic Area

This notice applies where PatiPilot’s processing for its own purposes falls within the EU General Data Protection Regulation (GDPR). Offering services to people in the EU/EEA or monitoring their behaviour there can bring a provider in Türkiye within scope when Article 3 is met. A service being free, or a person’s nationality, does not by itself decide applicability. This notice supplements our general Privacy notice; language or country selection does not remove your rights.

Controller and the salon’s role

The PatiPilot provider identified above, at the address in Türkiye, is controller for its own account, enquiry, support, security and business-transaction records. A salon determines the purposes of its pet-owner, customer, staff and appointment records; PatiPilot acts as processor when providing the service on that salon’s behalf. If you are a salon customer, you can contact your salon first about your records. Requests received by us are assessed with the relevant salon. This notice does not replace the separate data processing agreement required with the salon.

What information, and from where?

Accounts and forms provide names, business contact details, salon name, selected country/city, account permissions and messages. Correspondence provides support information; devices and infrastructure can generate IP/connection, security and error records. An authorised person at your business may supply your team-account details. Sales enquiries may also involve business contact details from public business websites, social profiles or directories; you can ask for the source of your record. Source/campaign information may accompany an enquiry you submit. With permission, limited visit analytics and optional notification endpoints are processed. Records processed for salons may include customer contacts, pet/grooming details, appointments, photos and work records. Do not upload human health information, card details or unnecessary identity documents.

Accounts and enquiries: contract or legitimate interests

Article 6(1)(b) of the GDPR supports account and enquiry processing necessary to perform a service contract with you, or take pre-contractual steps at your request. If you contact us as an employee of a business rather than a contracting party, managing that business relationship and answering your request are assessed under the legitimate-interest basis in Article 6(1)(f). Without required account and contact details, we may be unable to open the account or fulfil your request. Optional marketing permission is not a condition of service.

Security, source information and legal records

Protecting accounts and forms against abuse, investigating service errors, understanding the source of an enquiry and dealing with legal claims are assessed as necessary and proportionate legitimate interests under Article 6(1)(f); that basis cannot be used where your rights override those interests. Limited source information accompanying an enquiry is separate from optional visit analytics. Article 6(1)(c) is used for applicable legal obligations only when the relevant legal conditions are met. A Turkish obligation does not automatically constitute an EU or UK Article 6(1)(c) obligation; necessary retention and protection of legal rights require a separate assessment.

Optional processing and withdrawing consent

Optional analytics and product emails use separate choices; processing that requires consent relies on Article 6(1)(a). Change Cookie preferences to withdraw analytics permission, or contact support to withdraw product-email permission. Withdrawal does not affect the lawfulness of earlier processing based on consent. Browser-notification permission can be disabled in device settings and is not advertising permission. Acknowledging a privacy notice does not give marketing consent or authorise international transfers.

Who can receive information?

Authorised PatiPilot personnel and hosting, database, authentication, email, security, notification and backup providers can receive information as needed for the service. Infrastructure includes Vercel, Supabase, Resend, Hostinger and Cloudflare services. Backups may involve separate storage; browser notifications pass through the device’s browser/operating-system provider. Disclosures to competent authorities or professional advisers are limited to the relevant legal need. We do not sell personal data. The relevant salon determines access and purposes for its salon records.

Processing outside the EU/EEA

PatiPilot is operated from Türkiye; cloud services and support access can involve processing outside the EU/EEA. A transfer subject to GDPR Chapter V requires valid transfer conditions in addition to a lawful basis for processing. Depending on the transfer, an adequacy decision or appropriate safeguards such as EU standard contractual clauses, a transfer assessment and necessary supplementary measures may be relevant. An EU server location does not remove the need to assess access from Türkiye. Contact support for recipients, countries, safeguards for a particular transfer, or a copy of an available safeguard document. This notice is not a statement that a transfer agreement has been signed or that Türkiye has adequacy status.

How long do we retain information?

Account records are assessed for the duration needed to provide the active service and complete necessary account-closure steps; enquiry and support records for resolving the request and relevant dispute needs; security records for investigating incidents and preventing abuse. Business records can have separate statutory and legal-claim retention periods. Personal data no longer needed is subject to deletion or anonymisation processes. Salon-data retention follows the salon’s instructions and applicable contract/law. Backups have a separate lifecycle; closing an account does not erase every backup and legal record simultaneously. You can ask for the period or criteria applied to your record.

Your rights

Under the GDPR, where the conditions for each right are met, you can request access, correction, erasure, restriction and data portability. Portability applies to information you provided that is processed by automated means on consent or contract grounds. You may object to legitimate-interest processing for reasons relating to your situation. You may object to direct marketing at any time, including profiling related to that marketing; processing for that purpose must stop. Rights are not unlimited: if a request cannot be met in full, the reasons and available remedies must be explained.

Making a request and response times

Write to the support address below or the postal address above, identifying the relevant account/salon and what you want us to do. Do not send passwords or card details. If identity checks are necessary, only proportionate information is requested. Rights requests are normally handled without undue delay and within one calendar month. If complexity or the number of requests permits a two-month extension, reasons must be given within the first month. Legally permitted timing rules, such as those relating to identity verification, apply to the particular request. Requests are normally free of charge; fees are limited to statutory exceptions.

Complaints and the competent authority

You can raise a concern with support. You also have the right under GDPR Article 77 to complain to a competent supervisory authority, particularly in the Member State of your habitual residence, place of work or the alleged infringement. We do not require you to complain to PatiPilot first. The European Data Protection Board’s member-authority directory helps identify the relevant authority. Rights to an effective judicial remedy and compensation where its conditions are met remain available.

Automated decisions and updates

PatiPilot’s current account and enquiry service does not use solely automated decision-making about people that produces legal or similarly significant effects. Technical security and abuse checks may apply; contact support for a review if you encounter a problem. If processing purposes change, we provide relevant new information and any necessary choices.

Contact

Support, privacy and legal requests: support@patipilot.com.

Find an EU/EEA supervisory authority (EDPB) ↗