Personal Data Processing Information Notice under Turkish Personal Data Protection Law No. 6698 (KVKK)
Last Updated: September 12, 2026
Your privacy and the security of your data are our priorities. We process your personal data carefully and confidentially and take appropriate administrative and technical measures to protect it against unauthorized access, use, disclosure, alteration, or loss.
We do not sell or rent your personal data, and we do not make it available to any party for purposes unrelated to the service you request.
We may share only the minimum data necessary with parties required to perform the requested service or fulfill a legal obligation, including airlines, hotels, consulates, visa platforms, and relevant governmental systems, subject to the conditions explained in this Information Notice.
1. Identity of the Data Controller
This Information Notice has been prepared pursuant to Article 10 of Turkish Personal Data Protection Law No. 6698 (KVKK) and the applicable principles and procedures.
2. Scope of This Information Notice
This Information Notice covers the processing of personal data belonging to customers, passengers, persons who contact us or request our services, and persons for whom bookings or applications are submitted by someone else.
It applies to all services provided by the Company, including travel and tourism services, airline and hotel bookings, transportation, insurance, travel packages, visa services, consultancy services, and other related services.
Where an agent or another person provides us with personal data relating to other passengers, that person represents that they are authorized to provide the data and have informed the relevant data subjects about this Information Notice and how their personal data will be processed.
Personal data relating to minors shall be obtained from or with the involvement of a parent or legal representative, according to the nature of the service and applicable law.
3. Categories of Personal Data We May Process
We request only the personal data necessary for the relevant service. Depending on the service, this may include:
Identity and Contact Data
Name, email address, telephone number, residential address, passport, national identity card, personal photograph or biometric photograph, and information contained in identification documents required for the relevant transaction.
Travel and Booking Data
Flight details, destination, dates, ticket, booking and accommodation information, requested services, and related correspondence.
Visa Application Data
Depending on the visa category and the requirements of the consulate or visa authority, this may include bank statements, occupation, income, employer information, commercial invitations, marital status, and family information.
Legal Transaction Data
A notarized power of attorney and other legal documents may be requested when the Company is asked to perform a service on behalf of another person.
Special Categories of Personal Data
Where required by a visa application or competent authority, we may request specific medical reports, proof of vaccination, or criminal record information.
We do not request fingerprints. A biometric photograph shall not be treated as special-category biometric data unless it is processed using technical methods for the purpose of uniquely identifying or authenticating an individual.
Transaction and Payment Data
Service value, invoices, bank transfers, payment or refund status, and payment method, without retaining bank card details.
Communication and Security Data
Correspondence, service request records, call recordings where the caller is informed before the conversation begins, office CCTV recordings, and technical access and security logs.
Website Usage Data
Technical and website usage data collected through cookies and measurement tools after obtaining consent where legally required.
4. Purposes of Processing Personal Data
We may process personal data, to the extent necessary, for the following purposes:
- Receiving, managing, and responding to service requests.
- Communicating with customers or passengers.
- Making airline, hotel, transportation, insurance, travel package, and other tourism-related bookings.
- Preparing, submitting, and following up visa applications before consulates, visa platforms, and competent authorities.
- Performing the technical, administrative, and financial tasks necessary to provide and complete our services.
- Issuing invoices, collecting payments, processing refunds, and maintaining accounting and tax records.
- Providing customer support, handling requests and complaints, improving service quality, and training employees.
- Protecting our offices, systems, and information and preventing fraud or misuse.
- Establishing, exercising, or protecting legal rights and providing evidence of transactions where necessary.
- Fulfilling legal obligations and responding to requests from competent authorities.
- Measuring website performance and improving the user experience after obtaining consent where required.
5. Methods of Collection and Legal Grounds
Personal data may be collected directly from the data subject, from a person or agent acting on their behalf, or from a service provider or competent authority, depending on the relevant transaction.
Data may be collected through:
- Our website.
- WhatsApp.
- Telephone communications.
- Email.
- Our office.
- Social media platforms.
- Service request forms.
- Booking systems.
- Correspondence and submitted documents.
- Agents or persons requesting services or making bookings on behalf of other passengers.
Personal data may be processed wholly or partly by automated means or by non-automated means where the data forms part of a data recording system.
Depending on the processing activity, personal data is processed on one or more of the legal grounds specified in Articles 5 and 6 of KVKK, including:
- Processing being necessary for the conclusion or performance of a contract.
- Processing being expressly provided for by law.
- Processing being necessary for the Company to comply with a legal obligation.
- Processing being necessary for the establishment, exercise, or protection of a legal right.
- Processing being necessary for the Company's legitimate interests, provided that the fundamental rights and freedoms of the data subject are not prejudiced.
- The data subject's specific, informed, and freely given explicit consent where no other legal ground applies or where consent is required by law.
Health data, criminal record information, and other special categories of personal data are processed only where necessary for the relevant transaction, based on one of the processing conditions specified in Article 6 of KVKK, and subject to the required additional safeguards.
Where processing is based on explicit consent, consent shall be obtained separately from this Information Notice. The data subject may withdraw consent at any time regarding future processing activities.
6. Sharing Personal Data with Third Parties
We share personal data only to the extent necessary to provide the requested service, fulfill the stated purpose, or comply with a legal obligation.
Depending on the relevant service, recipients may include:
- Airlines, hotels, transportation companies, insurance companies, tour operators, and other service providers.
- Consulates, embassies, visa application centers, visa platforms, governmental systems, and competent public authorities.
- Providers of booking systems, information technology and communication services, email, cloud storage, and customer relationship management services, including Google Drive according to its actual use.
- Banks, payment gateways, and collection service providers to the extent necessary to process or verify payment.
- Accountants, lawyers, consultants, judicial bodies, public authorities, and other legally authorized persons where necessary.
Where third parties act as service providers or data processors, we seek to require them to use personal data only for the specified purpose, maintain confidentiality, and implement appropriate security measures, according to the nature of the relationship and applicable law.
7. Transfer of Personal Data Outside Türkiye
The performance of certain services may require transferring the minimum necessary personal data outside Türkiye.
This may occur, for example, when booking or visa information is transmitted to an airline, hotel, consulate, visa platform, or service provider located outside Türkiye.
An international transfer may also occur through the use of cloud-based and technical services such as Google Drive, depending on the applicable hosting and technical support locations.
International transfers shall be carried out in accordance with Article 9 of KVKK, based on:
- A valid adequacy decision;
- An appropriate safeguard, together with completion of the required procedures, such as approved standard contractual clauses; or
- An exceptional transfer condition permitted by law where neither an adequacy decision nor an appropriate safeguard is available.
Transferred personal data shall only be used for the relevant service or legitimate operational purpose.
8. Retention and Deletion of Personal Data
We retain personal data only for as long as necessary for the purpose for which it was collected and for any period required by applicable law.
When the purpose of processing no longer exists and the applicable legal retention period has expired, personal data shall be deleted, destroyed, or anonymized in accordance with the law and the Company's periodic deletion procedures.
The following retention periods generally apply:
Passport Copies
Passport copies shall be deleted within six months after the service has been completed and all related invoices have been paid, unless an objection, dispute, investigation, or legal obligation requires longer retention.
Medical Documents, Criminal Records, and Sensitive Visa Documents
These documents shall be deleted when the operational need ends and no later than six months after completion of the service, unless a competent authority, legal obligation, or ongoing dispute requires longer retention.
Call Recordings
Call recordings shall be retained for no longer than six months unless they are required to handle a complaint, prove a transaction, or establish, exercise, or protect a legal right.
Office CCTV Recordings
CCTV recordings shall generally be retained for no longer than 30 days. A recording relating to a security incident or legal claim may be separated and retained until the legitimate need for it ends.
Invoices, Accounting Records, Commercial Records, and Transaction Records
These records shall be retained for the periods required by tax, commercial, and other applicable legislation, which may be up to ten years depending on the type of record.
A deletion request does not necessarily require the immediate deletion of every record. Where the Company is legally required to retain a record, its use shall be restricted to the relevant legal purpose, and it shall be deleted after the mandatory retention period expires.
9. Data Security and Bank Card Information
Depending on their nature, personal data may be stored on work computers and telephones, booking systems, email systems, social media platforms, and Google Drive.
The Company implements access controls and administrative and technical safeguards appropriate to the nature of the data and the relevant risks.
We never request or retain the full bank card number, CVV security code, or card PIN.
Payments are made through POS terminals, bank transfers to the Company's account, or secure payment links through which customers enter their card details directly into the bank's or payment provider's interface without the Company viewing them.
The Company does not make contactless payments on behalf of the cardholder and does not enter the cardholder's PIN.
10. Call Recordings and Office CCTV
Certain VoIP calls may be recorded for service quality, proof of requests and transactions, and protection of legal rights.
Where a call is recorded, the caller shall be informed through a clear audio message before the conversation begins.
CCTV cameras are used in the office to protect persons and property and maintain workplace security.
Cameras are not used in areas where they would violate personal privacy. A visible short-form notice and, where appropriate, a separate detailed CCTV Information Notice shall be provided.
11. Cookies and Measurement Tools
The website may use cookies that are necessary for its operation.
After obtaining legally required consent, it may also use tools such as Google Analytics, Meta Pixel, and TikTok Pixel to measure and improve website performance.
The cookies and tools used, their purposes, durations, and providers shall be described in a separate Cookie Policy.
Visitors may accept or reject non-essential cookies and may change their preferences at any time.
Non-essential cookies and measurement tools shall not be activated before the visitor gives consent where consent is legally required.
12. Your Rights under Article 11 of KVKK
Subject to the applicable legal conditions and limitations, you have the right to:
- Learn whether your personal data is being processed.
- Request information if your personal data has been processed.
- Learn the purpose of processing and whether your data is being used in accordance with that purpose.
- Learn the third parties to whom your personal data has been transferred within Türkiye or abroad.
- Request correction of incomplete or inaccurate personal data.
- Request deletion or destruction of personal data where the reasons for processing no longer exist, subject to mandatory legal retention periods.
- Request notification of correction, deletion, or destruction measures to third parties to whom the data has been transferred, subject to applicable legal conditions.
- Object to a result arising against you through the analysis of personal data exclusively by automated systems.
- Claim compensation for damage suffered as a result of unlawful processing of personal data.
13. How to Submit a KVKK Request
You may submit requests concerning your rights under KVKK through one of the following legally permitted methods:
- In writing to the Company's registered address: Merkez Mah. Reşitpaşa Cad. Altıntaş İş Merkezi No:55 Ofis No:36 Avcılar / İstanbul 34310 – Türkiye
- Through the Company's Registered Electronic Mail address (KEP): burakgroup@hs06.kep.tr
- Through the email address designated for KVKK requests: kvkk@buraktravel.com
- Using a secure electronic signature, mobile signature, or another method permitted by law.
Requests sent by email should preferably be submitted from an email address previously provided to and registered in the Company's systems or should include the information necessary to verify the applicant's identity.
The request should include the applicant's name and contact information, a clear explanation of the right being exercised, and any information or documents relevant to the request.
Please use the following subject line: Personal Data Protection Request – KVKK
The Company shall respond as soon as possible and no later than 30 days after receiving a complete request containing the necessary information.
Requests shall generally be processed free of charge. Where processing the request results in additional costs, the Company may charge the fee permitted under the applicable official tariff.
14. Updates to This Information Notice
The Company may update this Information Notice following changes to its services, personal data processing activities, systems, or legal requirements.
The updated version shall be published on buraktravel.com together with the date of the latest update.
Where a change requires explicit consent, consent shall be obtained separately before the relevant processing activity begins.