Service provider
DOĞA PET GROOMING · PatiPilot
Zeynep Doğa Bayraktar Zuğurlu
CUMHURİYET MAH. ÇAĞLAYAN SK. KOZA PARK KOZA PARK C BLOK NO: 10 C/B ÇERKEZKÖY/ TEKİRDAĞ
Scope in the United Kingdom
This notice applies where PatiPilot’s processing for its own purposes falls within the UK GDPR, including where offering services to people in the UK or monitoring their behaviour there brings that processing within scope. The UK GDPR and Data Protection Act 2018 apply as amended, including applicable changes under the Data (Use and Access) Act 2025. Choosing English does not by itself determine the applicable law. This notice supplements our general Privacy notice and is separate from the Türkiye KVKK notice.
Controller and the salon’s role
The PatiPilot provider identified above, at the address in Türkiye, is controller for its own account, enquiry, support, security and business-transaction records. A salon determines the purposes of its pet-owner, customer, staff and appointment records; PatiPilot acts as processor when providing the service on that salon’s behalf. If you are a salon customer, you can contact your salon first about your records. Requests received by us are assessed with the relevant salon. This notice does not replace the separate data processing agreement required with the salon.
What information, and from where?
Accounts and forms provide names, business contact details, salon name, selected country/city, account permissions and messages. Correspondence provides support information; devices and infrastructure can generate IP/connection, security and error records. An authorised person at your business may supply your team-account details. Sales enquiries may also involve business contact details from public business websites, social profiles or directories; you can ask for the source of your record. Source/campaign information may accompany an enquiry you submit. With permission, limited visit analytics and optional notification endpoints are processed. Records processed for salons may include customer contacts, pet/grooming details, appointments, photos and work records. Do not upload human health information, card details or unnecessary identity documents.
Accounts and enquiries: contract or legitimate interests
Article 6(1)(b) of the UK GDPR supports account and enquiry processing necessary to perform a service contract with you, or take pre-contractual steps at your request. If you contact us as an employee of a business rather than a contracting party, managing that business relationship and answering your request are assessed under the legitimate-interest basis in Article 6(1)(f). Without required account and contact details, we may be unable to open the account or fulfil your request. Optional marketing permission is not a condition of service.
Security, source information and legal records
Protecting accounts and forms against abuse, investigating service errors, understanding the source of an enquiry and dealing with legal claims are assessed as necessary and proportionate legitimate interests under Article 6(1)(f); that basis cannot be used where your rights override those interests. Limited source information accompanying an enquiry is separate from optional visit analytics. Article 6(1)(c) is used for applicable legal obligations only when the relevant legal conditions are met. A Turkish obligation does not automatically constitute an EU or UK Article 6(1)(c) obligation; necessary retention and protection of legal rights require a separate assessment.
Optional processing and withdrawing consent
Optional analytics and product emails use separate choices; processing that requires consent relies on Article 6(1)(a). Change Cookie preferences to withdraw analytics permission, or contact support to withdraw product-email permission. Withdrawal does not affect the lawfulness of earlier processing based on consent. Browser-notification permission can be disabled in device settings and is not advertising permission. Acknowledging a privacy notice does not give marketing consent or authorise international transfers.
Who can receive information?
Authorised PatiPilot personnel and hosting, database, authentication, email, security, notification and backup providers can receive information as needed for the service. Infrastructure includes Vercel, Supabase, Resend, Hostinger and Cloudflare services. Backups may involve separate storage; browser notifications pass through the device’s browser/operating-system provider. Disclosures to competent authorities or professional advisers are limited to the relevant legal need. We do not sell personal data. The relevant salon determines access and purposes for its salon records.
Processing outside the UK
PatiPilot is operated from Türkiye; cloud services and support access can involve processing outside the UK. Where a restricted transfer occurs, the UK GDPR transfer rules also apply. Depending on the transfer, UK adequacy regulations or appropriate safeguards such as the IDTA or UK Addendum to EU standard clauses, together with the required transfer assessment, may be relevant; EU clauses alone do not cover every UK transfer. Contact support for recipients, countries, safeguards for a particular transfer, or a copy of an available safeguard document. This notice is not a statement that a transfer agreement has been signed or that Türkiye has adequacy status.
How long do we retain information?
Account records are assessed for the duration needed to provide the active service and complete necessary account-closure steps; enquiry and support records for resolving the request and relevant dispute needs; security records for investigating incidents and preventing abuse. Business records can have separate statutory and legal-claim retention periods. Personal data no longer needed is subject to deletion or anonymisation processes. Salon-data retention follows the salon’s instructions and applicable contract/law. Backups have a separate lifecycle; closing an account does not erase every backup and legal record simultaneously. You can ask for the period or criteria applied to your record.
Your rights
Under the UK GDPR, where the conditions for each right are met, you can request access, correction, erasure, restriction and data portability. Portability applies to information you provided that is processed by automated means on consent or contract grounds. You may object to legitimate-interest processing for reasons relating to your situation. You may object to direct marketing at any time, including profiling related to that marketing; processing for that purpose must stop. Rights are not unlimited: if a request cannot be met in full, the reasons and available remedies must be explained.
Making a request and response times
Write to the support address below or the postal address above, identifying the relevant account/salon and what you want us to do. Do not send passwords or card details. If identity checks are necessary, only proportionate information is requested. Rights requests are normally handled without undue delay and within one calendar month. If complexity or the number of requests permits a two-month extension, reasons must be given within the first month. UK GDPR rules on calculating time, including permitted waits for identity verification or necessary clarification, apply to the particular request. Requests are normally free of charge; fees are limited to statutory exceptions.
Complaining to us and the ICO
If you are unhappy with our use of your information or how a request was handled, email support or write to our postal address. A subject such as ‘Data protection complaint’ helps but is not required. Receipt must be acknowledged within 30 days; investigation starts without delay, progress updates are provided and the outcome is explained without undue delay. That 30-day acknowledgement is different from the deadline for responding to a data-rights request. You can complain to the Information Commissioner’s Office (ICO) at any time; giving us an opportunity to resolve the issue first is recommended. Your rights to seek a judicial remedy remain available.
Automated decisions and updates
PatiPilot’s current account and enquiry service does not use solely automated decision-making about people that produces legal or similarly significant effects. Technical security and abuse checks may apply; contact support for a review if you encounter a problem. If processing purposes change, we provide relevant new information and any necessary choices.
Contact
Support, privacy and legal requests: support@patipilot.com.