الرئيسية الرحلات من نحن المدونة تواصل معنا تواصل معنا عبر واتساب

Personal Data Processing Information Notice under Turkish Personal Data Protection Law No. 6698 (KVKK)

Your privacy and the security of your data are our priorities. We process your personal data carefully and confidentially and take appropriate administrative and technical measures to protect it against unauthorized access, use, disclosure, alteration, or loss.

We do not sell or rent your personal data, and we do not make it available to any party for purposes unrelated to the service you request.

We may share only the minimum data necessary with parties required to perform the requested service or fulfill a legal obligation, including airlines, hotels, consulates, visa platforms, and relevant governmental systems, subject to the conditions explained in this Information Notice.

1. Identity of the Data Controller

This Information Notice has been prepared pursuant to Article 10 of Turkish Personal Data Protection Law No. 6698 (KVKK) and the applicable principles and procedures.

2. Scope of This Information Notice

This Information Notice covers the processing of personal data belonging to customers, passengers, persons who contact us or request our services, and persons for whom bookings or applications are submitted by someone else.

It applies to all services provided by the Company, including travel and tourism services, airline and hotel bookings, transportation, insurance, travel packages, visa services, consultancy services, and other related services.

Where an agent or another person provides us with personal data relating to other passengers, that person represents that they are authorized to provide the data and have informed the relevant data subjects about this Information Notice and how their personal data will be processed.

Personal data relating to minors shall be obtained from or with the involvement of a parent or legal representative, according to the nature of the service and applicable law.

3. Categories of Personal Data We May Process

We request only the personal data necessary for the relevant service. Depending on the service, this may include:

Identity and Contact Data

Name, email address, telephone number, residential address, passport, national identity card, personal photograph or biometric photograph, and information contained in identification documents required for the relevant transaction.

Travel and Booking Data

Flight details, destination, dates, ticket, booking and accommodation information, requested services, and related correspondence.

Visa Application Data

Depending on the visa category and the requirements of the consulate or visa authority, this may include bank statements, occupation, income, employer information, commercial invitations, marital status, and family information.

Legal Transaction Data

A notarized power of attorney and other legal documents may be requested when the Company is asked to perform a service on behalf of another person.

Special Categories of Personal Data

Where required by a visa application or competent authority, we may request specific medical reports, proof of vaccination, or criminal record information.

We do not request fingerprints. A biometric photograph shall not be treated as special-category biometric data unless it is processed using technical methods for the purpose of uniquely identifying or authenticating an individual.

Transaction and Payment Data

Service value, invoices, bank transfers, payment or refund status, and payment method, without retaining bank card details.

Communication and Security Data

Correspondence, service request records, call recordings where the caller is informed before the conversation begins, office CCTV recordings, and technical access and security logs.

Website Usage Data

Technical and website usage data collected through cookies and measurement tools after obtaining consent where legally required.

4. Purposes of Processing Personal Data

We may process personal data, to the extent necessary, for the following purposes:

5. Methods of Collection and Legal Grounds

Personal data may be collected directly from the data subject, from a person or agent acting on their behalf, or from a service provider or competent authority, depending on the relevant transaction.

Data may be collected through:

Personal data may be processed wholly or partly by automated means or by non-automated means where the data forms part of a data recording system.

Depending on the processing activity, personal data is processed on one or more of the legal grounds specified in Articles 5 and 6 of KVKK, including:

Health data, criminal record information, and other special categories of personal data are processed only where necessary for the relevant transaction, based on one of the processing conditions specified in Article 6 of KVKK, and subject to the required additional safeguards.

Where processing is based on explicit consent, consent shall be obtained separately from this Information Notice. The data subject may withdraw consent at any time regarding future processing activities.

6. Sharing Personal Data with Third Parties

We share personal data only to the extent necessary to provide the requested service, fulfill the stated purpose, or comply with a legal obligation.

Depending on the relevant service, recipients may include:

Where third parties act as service providers or data processors, we seek to require them to use personal data only for the specified purpose, maintain confidentiality, and implement appropriate security measures, according to the nature of the relationship and applicable law.

7. Transfer of Personal Data Outside Türkiye

The performance of certain services may require transferring the minimum necessary personal data outside Türkiye.

This may occur, for example, when booking or visa information is transmitted to an airline, hotel, consulate, visa platform, or service provider located outside Türkiye.

An international transfer may also occur through the use of cloud-based and technical services such as Google Drive, depending on the applicable hosting and technical support locations.

International transfers shall be carried out in accordance with Article 9 of KVKK, based on:

Transferred personal data shall only be used for the relevant service or legitimate operational purpose.

8. Retention and Deletion of Personal Data

We retain personal data only for as long as necessary for the purpose for which it was collected and for any period required by applicable law.

When the purpose of processing no longer exists and the applicable legal retention period has expired, personal data shall be deleted, destroyed, or anonymized in accordance with the law and the Company's periodic deletion procedures.

The following retention periods generally apply:

Passport Copies

Passport copies shall be deleted within six months after the service has been completed and all related invoices have been paid, unless an objection, dispute, investigation, or legal obligation requires longer retention.

Medical Documents, Criminal Records, and Sensitive Visa Documents

These documents shall be deleted when the operational need ends and no later than six months after completion of the service, unless a competent authority, legal obligation, or ongoing dispute requires longer retention.

Call Recordings

Call recordings shall be retained for no longer than six months unless they are required to handle a complaint, prove a transaction, or establish, exercise, or protect a legal right.

Office CCTV Recordings

CCTV recordings shall generally be retained for no longer than 30 days. A recording relating to a security incident or legal claim may be separated and retained until the legitimate need for it ends.

Invoices, Accounting Records, Commercial Records, and Transaction Records

These records shall be retained for the periods required by tax, commercial, and other applicable legislation, which may be up to ten years depending on the type of record.

A deletion request does not necessarily require the immediate deletion of every record. Where the Company is legally required to retain a record, its use shall be restricted to the relevant legal purpose, and it shall be deleted after the mandatory retention period expires.

9. Data Security and Bank Card Information

Depending on their nature, personal data may be stored on work computers and telephones, booking systems, email systems, social media platforms, and Google Drive.

The Company implements access controls and administrative and technical safeguards appropriate to the nature of the data and the relevant risks.

We never request or retain the full bank card number, CVV security code, or card PIN.

Payments are made through POS terminals, bank transfers to the Company's account, or secure payment links through which customers enter their card details directly into the bank's or payment provider's interface without the Company viewing them.

The Company does not make contactless payments on behalf of the cardholder and does not enter the cardholder's PIN.

10. Call Recordings and Office CCTV

Certain VoIP calls may be recorded for service quality, proof of requests and transactions, and protection of legal rights.

Where a call is recorded, the caller shall be informed through a clear audio message before the conversation begins.

CCTV cameras are used in the office to protect persons and property and maintain workplace security.

Cameras are not used in areas where they would violate personal privacy. A visible short-form notice and, where appropriate, a separate detailed CCTV Information Notice shall be provided.

11. Cookies and Measurement Tools

The website may use cookies that are necessary for its operation.

After obtaining legally required consent, it may also use tools such as Google Analytics, Meta Pixel, and TikTok Pixel to measure and improve website performance.

The cookies and tools used, their purposes, durations, and providers shall be described in a separate Cookie Policy.

Visitors may accept or reject non-essential cookies and may change their preferences at any time.

Non-essential cookies and measurement tools shall not be activated before the visitor gives consent where consent is legally required.

12. Your Rights under Article 11 of KVKK

Subject to the applicable legal conditions and limitations, you have the right to:

13. How to Submit a KVKK Request

You may submit requests concerning your rights under KVKK through one of the following legally permitted methods:

Requests sent by email should preferably be submitted from an email address previously provided to and registered in the Company's systems or should include the information necessary to verify the applicant's identity.

The request should include the applicant's name and contact information, a clear explanation of the right being exercised, and any information or documents relevant to the request.

Please use the following subject line: Personal Data Protection Request – KVKK

The Company shall respond as soon as possible and no later than 30 days after receiving a complete request containing the necessary information.

Requests shall generally be processed free of charge. Where processing the request results in additional costs, the Company may charge the fee permitted under the applicable official tariff.

14. Updates to This Information Notice

The Company may update this Information Notice following changes to its services, personal data processing activities, systems, or legal requirements.

The updated version shall be published on buraktravel.com together with the date of the latest update.

Where a change requires explicit consent, consent shall be obtained separately before the relevant processing activity begins.