Legal · Data protection

Privacy Policy

Trasst Global · Hotel Wi-Fi portal & related digital services · Effective / last updated: 16 September 2026

This Policy explains how personal data is collected and processed when guests use hotel Wi-Fi login pages and related services powered by Trasst technology. It is designed to align with Türkiye’s KVKK (Law No. 6698) and, where applicable, the EU/UK GDPR.

1. Who we are

Trasst Global (“Trasst”, “we”, “us”) provides technology that hotels and hospitality partners use to operate captive-portal Wi-Fi login, guest messaging, and related travel experience features (including product discovery on the portal).

Website: www.trasst.com
Privacy contact: [email protected]

The hotel where you are staying is typically the primary service provider of the Wi-Fi network. Trasst supplies the technical platform used to authenticate guests and deliver related communications.

2. Scope of this Policy

This Policy covers personal data processed in connection with:

  • Hotel Wi-Fi / hotspot captive-portal login pages operated with Trasst technology;
  • Transactional service messages confirming Wi-Fi access or first registration;
  • Optional marketing emails, only where you give explicit opt-in consent;
  • Optional WhatsApp / phone-based login flows configured by the hotel;
  • Limited product-interaction analytics on the portal (for example, product card views or booking clicks), used to improve the service;
  • The public Trasst website pages that link to this Policy (including /privacy).

It does not replace hotel-specific terms, PMS/reservation policies, or third-party product providers’ own privacy notices (for example eSIM or ticket vendors) that you may encounter after leaving the portal.

3. Controllers, processors and joint roles

3.1 Hotel (network operator)

The hotel (or hospitality group) that provides the Wi-Fi SSID generally determines the purposes of granting network access and may act as a data controller (or equivalent under KVKK) for guest connectivity records necessary to operate the network and comply with local rules.

3.2 Trasst (platform provider)

Trasst processes data to operate the identification / portal platform, deliver service messages, and—only with your opt-in—send marketing communications. Depending on the hotel contract and the processing activity, Trasst may act as a processor (on the hotel’s documented instructions) and/or as an independent controller for platform security, abuse prevention, service improvement analytics, and Trasst-originated marketing where consent is collected for Trasst.

3.3 Processors and tools

We use carefully selected service providers (for example email delivery platforms such as Mailjet, hosting, and network authentication components such as RADIUS-related systems) under contracts that require appropriate confidentiality and security measures.

4. Personal data we may process

Depending on the login method enabled for your hotel, we may process:

Category Examples
Identity / contact Email address; phone number (including country code); optionally room number if requested by the hotel flow
Authentication & network Portal session identifiers; interface / hotel identifiers; device-related technical identifiers used for Wi-Fi session management (as configured by the network)
Communications Transactional email / WhatsApp delivery status; marketing preference (opt-in / opt-out)
Usage / product analytics Aggregated or event-level portal interactions (for example product modal opens, booking clicks) tied to hotel/context identifiers
Technical logs Timestamps, error/diagnostic logs, approximate request metadata needed to secure and operate the service

We do not require government ID numbers or payment card data on the Wi-Fi login form described in this Policy.

5. Purposes and legal bases

Purpose Typical legal basis
Authenticate you and grant hotel Wi-Fi access Performance of a service request / contract-like steps at your request; legitimate interests in operating secure guest Wi-Fi; KVKK Art. 5 equivalents where applicable
Send transactional service messages (access / registration confirmation) Necessary for the requested service; legitimate interests in informing you about access status
Optional marketing emails (hotel offers, Istanbul experiences, Trasst updates) Consent — only if you actively tick the opt-in checkbox (never pre-ticked)
Security, fraud/abuse prevention, troubleshooting Legitimate interests; legal obligations where applicable
Service improvement and portal product analytics Legitimate interests in understanding feature usage in an operational hospitality context
Compliance with enforceable legal requests Legal obligation
Important: Connecting to Wi-Fi does not by itself constitute marketing consent. You can use Wi-Fi without ticking the marketing checkbox.

6. Marketing communications (opt-in only)

  • Marketing/promotional emails are sent only if you actively opt in on the login form.
  • The marketing checkbox is never pre-selected.
  • You may withdraw consent at any time via the unsubscribe link in marketing messages or by emailing [email protected].
  • Withdrawal does not affect the lawfulness of processing before withdrawal, and does not by itself disconnect your Wi-Fi session.
  • We do not buy or rent email lists for this captive-portal service, and we do not treat Wi-Fi login alone as marketing consent.

7. Sharing of personal data

We may share personal data only as needed for the purposes above:

  • With the hotel / hospitality partner operating the network you joined;
  • With processors such as email delivery providers (e.g. Mailjet), infrastructure/hosting providers, and authentication-related systems;
  • With professional advisers or authorities where required by law or to protect rights, safety, and security;
  • In a business transfer (merger, acquisition, restructuring), subject to appropriate safeguards.

We do not sell personal data.

8. International transfers

Some processors may process data in countries outside Türkiye and/or the EEA/UK. Where required, we rely on appropriate transfer mechanisms (such as contractual safeguards / standard contractual clauses or equivalent protections) and require recipients to protect the data appropriately.

9. Retention

We keep personal data only as long as needed for the purposes described, including:

  • Wi-Fi authentication / session-related records: for the operational period required by the hotel network and platform security, then deleted or anonymised according to retention schedules;
  • Transactional communication logs: for a limited period needed for delivery confirmation, support, and abuse prevention;
  • Marketing contact details & consent records: until you unsubscribe / withdraw consent, or the list is otherwise closed, plus a short period thereafter to evidence compliance;
  • Analytics events: retained in identifiable or hotel-linked form only as long as useful for reporting, then aggregated or deleted.

Where a longer retention is required by law (for example to respond to legal claims), we limit access and use accordingly.

10. Security measures

We apply technical and organisational measures appropriate to the risk, including access controls, encrypted transport (HTTPS) where configured, least-privilege administration, logging, and vendor due diligence. No method of transmission or storage is completely secure; we work continuously to reduce residual risk.

11. Your rights

Subject to applicable law (including KVKK and, where relevant, GDPR), you may have the right to:

  • Request access to your personal data;
  • Request rectification of inaccurate data;
  • Request deletion (“right to be forgotten”) in certain circumstances;
  • Request restriction of processing;
  • Object to processing based on legitimate interests;
  • Withdraw consent (for marketing) at any time;
  • Data portability, where technically applicable;
  • Lodge a complaint with a supervisory authority.

In Türkiye, the supervisory authority is the Personal Data Protection Authority (KVKK) (www.kvkk.gov.tr. EU/EEA guests may contact their local data protection authority; UK guests may contact the ICO.

To exercise rights relating to this portal, email [email protected] with enough detail for us to identify the hotel stay / login context. We may need to verify your identity before responding.

12. Cookies and similar technologies

The captive portal and website may use strictly necessary technical storage (for example language preference, session continuity, or security tokens). We do not use the Wi-Fi login page as an advertising tracking surface. If non-essential analytics cookies are introduced on marketing pages in the future, we will update this Policy and, where required, present a consent mechanism.

13. Children

The Wi-Fi login service is intended for hotel guests and is not directed at children. If you believe a child’s data was submitted inappropriately, contact us and we will take reasonable steps to delete it where required.

14. Changes to this Policy

We may update this Policy to reflect legal, technical, or operational changes. The “last updated” date at the top will change when we do. Material changes affecting marketing consent practices will be reflected on the login form and this page.

15. Contact

Privacy requests & questions:
[email protected]
Web: www.trasst.com