Rmos Live Mobile App Privacy Policy
Last updated: 2026-09-12
This policy explains how personal data is processed in the Rmos Live mobile application (the "App"), developed by Reşat Mendi Otelcilik Sistemleri Bilgisayar Sanayi Turizm ve Ticaret Anonim Şirketi ("RMOS", the "Company"). The App is intended for staff of businesses that use the RMOS hotel management system; it is not a public consumer app.
Data controller
The data controller is Reşat Mendi Otelcilik Sistemleri Bilgisayar Sanayi Turizm ve Ticaret Anonim Şirketi.
- Address: Akdeniz Üniversitesi Akdeniz Tekno Kenti K:2 No:3 Konyaaltı / Antalya, Türkiye
- Phone: +90 242 227 87 31
- E-mail: [email protected]
- Registered e-mail (KEP): [email protected]
- Mersis No: 0-7340-1010-1400012
Data we process
The App processes only what it needs to function:
- Authentication data: username and password (sent to the server at sign-in only, never stored on the device), session and refresh tokens.
- User profile: your first name, last name, user code and permissions as defined in the hotel management system.
- App preferences: selected property/database, language and appearance.
- Business data: the room, reservation, revenue, inventory and accounting reports you view. This data belongs to the business you work for; RMOS hosts it on its behalf.
Accounts are created by your employer; the App offers no public sign-up.
Data we do not collect
The App collects no location, contacts, calendar, photos, camera, microphone, health data or advertising identifier (IDFA/AAID). It contains no advertising network, tracking or third-party analytics, and requests no device sensor access.
Purposes and legal basis
Data is processed to authenticate you, show the reports you are authorised to see, carry out actions such as purchase approvals, debug faults and maintain security.
The legal basis is Article 5/2-c (necessary for the performance of a contract) and Article 5/2-f (legitimate interest) of Turkish Law No. 6698 (KVKK); for users in the EEA the equivalent grounds under GDPR Art. 6(1)(b) and 6(1)(f) apply.
Where data is stored
Authentication tokens are kept encrypted in the operating system's secure storage (iOS Keychain / Android Keystore) and are deleted when you sign out. The App keeps no persistent copy of business reports on the device.
Server-side data is hosted on RMOS's servers and/or those of its cloud provider. All traffic is encrypted with HTTPS (TLS).
Disclosure
Your personal data is never sold or shared for marketing. It is disclosed only to the business you work for, to the infrastructure providers that host the service, and to public authorities where required by law, within the framework of KVKK Art. 8-9.
Retention
User accounts are retained while your relationship with the business continues. When an account is closed, the user record and session tokens are deleted; records that legislation requires us to keep are retained for the statutory period. See the Account Deletion page for details.
Children's privacy
The App is a business tool, is not directed at anyone under 18, and does not knowingly collect data from children.
Your rights
Under KVKK Art. 11 you may learn whether your personal data is processed, request information and correction or erasure, object to processing, and claim compensation for damages.
Send requests, with information that verifies your identity, to [email protected] or to the registered e-mail address [email protected]. Requests are answered within 30 days at the latest.
Changes
When this policy is updated, the effective date changes and the current text is published on this page. Material changes are announced in the App.
Contact
Privacy questions: [email protected]. Technical support: [email protected].