Last updated · August 2026
Data protection notice
Explains what personal data Poddy processes when you use our studios, why we process it and how long we retain it. The Turkish KVKK notice remains the controlling local disclosure.
Data we process
- Identity and contact: full name, email address and phone number.
- Booking: studio, date, time, duration, guest count and booking notes.
- Payment: amount, date and status. Card details are handled by the payment provider and do not reach Poddy.
- Access logs: when a studio door code is used.
- Recording files: audio and video created during your session.
- Security footage: video from entrances and shared areas; these cameras do not record audio.
- Identity documents: images of an identity card, driving licence or passport and a selfie submitted before the first booking.
Identity verification
Our studios are self-service and customers receive an unstaffed building-access code. We therefore verify identity before the first booking. This processing is based on your explicit consent; if you do not consent, document images are not collected.
- Images are encrypted in restricted storage and are never made publicly accessible.
- Only authorised review staff may access them, and every access is logged.
- We do not retain the complete document number; only its last four characters remain after verification.
- Images are deleted automatically no later than 90 days after verification. The fact and date of verification remain.
- Images are not used for marketing, profiling or automated decisions and are not shared for those purposes.
- You may request earlier deletion. Your verification will then become invalid and must be repeated for a future booking.
Why we process data
- To create bookings, take payment and provide studio access.
- To create, deliver and retain recording files during the delivery period.
- To protect studio equipment and investigate damage or rule violations.
- To verify identity before granting access to a self-service studio.
- To meet invoicing, tax and record-keeping obligations.
Retention
Identity-document images are retained for no more than 90 days and then deleted automatically.
Recording files are retained for up to 14 days after delivery and then deleted. Booking and payment records are retained for the periods required by applicable law. Security-footage retention and access are separately restricted.
Recipients
- Payment providers, to process payments.
- Cloud storage and email/SMS providers, to deliver files and notifications.
- Public authorities, only when legally required.
Your rights
Depending on applicable law, you may request access, correction or deletion, object to processing, or seek compensation. Send requests to [email protected].
Data controller
Poddy · [email protected]
