Note: This page is an informational translation of our Turkish-language privacy notice, which is prepared under Turkish Law No. 6698 on the Protection of Personal Data ("the Law", known as KVKK). In the event of any discrepancy, the Turkish original governs.
Under Turkish Law No. 6698 on the Protection of Personal Data ("the Law"), SIR TURİZM SANAYİ İNŞAAT HALI KUYUMCULUK TİCARET LTD. ŞTİ. (hereinafter referred to as "KARMİR HOTEL") is defined as the data controller because it processes personal data relating to you. Under Article 10 of the Law, titled "Obligation to Inform", data controllers are required to inform the individuals whose personal data they process about certain matters.
This notice has been prepared by KARMİR HOTEL both to ensure compliance with legislation and to be transparent and accountable.
Under Law No. 6698 on the Protection of Personal Data:
as defined above.
Data Subject: By staying with us as a guest at our hotels, you, whose certain personal data we process, are defined by the Law as the data subject.
Data Controller: KARMİR HOTEL, which determines the purposes and means of processing your personal data and is responsible for establishing and managing the data recording system, is the data controller.
Your personal data is processed within the following processes, in the context of the transactions you carry out during your stay.
Data processed: Identity (name, surname, nationality, date of birth, national ID number), Contact (address, phone), Legal Transaction (signature, signature date, departure date), Customer Transaction (room number, arrival date, departure date, folio number, agency) data.
Based on Article 5/2(c) of the Law: provided it is directly related to the establishment or performance of a contract, where it is necessary to process personal data belonging to the parties of the contract (we collect certain personal data on the accommodation form in order to provide you, our valued guest, with accommodation services).
Based on Article 5/2(f) of the Law: provided it does not harm the fundamental rights and freedoms of the data subject, where data processing is necessary for the legitimate interests of the data controller (we retain your accommodation form information for a reasonable period in order to keep records of our services).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data is not transferred.
Methods of Collecting Personal Data
Your personal data is obtained through non-automated means, by your filling in the accommodation form.
Data processed: Identity (name, surname), Health Data (allergen food information), Customer Transaction (room number) data.
For your data other than health data: Based on Article 5/2(c) of the Law: provided it is directly related to the establishment or performance of a contract, where it is necessary to process personal data belonging to the parties of the contract (we collect certain personal data on the food allergy form in order to provide you, our valued guest, with a trouble-free stay).
For health data: Based on Article 6/3(d) of the Law: where data processing is necessary for the establishment, exercise or protection of a right (we collect this personal data in order to provide you, our valued guest, with a trouble-free stay).
For your data other than health data: Based on Article 5/2(e) of the Law: where data processing is necessary for the establishment, exercise or protection of a right (we retain this personal data so that we can protect our rights in the event of a possible dispute).
For health data: Based on Article 6/3(d) of the Law: where data processing is necessary for the establishment, exercise or protection of a right (we retain this personal data in order to provide you, our valued guest, with a trouble-free stay).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data is not transferred.
Methods of Collecting Personal Data
Your personal data is obtained through non-automated means, by our staff filling in the guest information card.
Data processed: Identity (name, surname), Legal Transaction (invoice date, invoice time, invoice type, invoice number), Financial (service amount information), Customer Transaction (service received) data.
Based on Article 5/2(ç) of the Law: where it is mandatory for the data controller to fulfil its legal obligation (collecting this data is a legal obligation of the data controller under Article 230 of Law No. 213 on Tax Procedure).
Based on Article 5/2(ç) of the Law, the data controller's legal obligation (collecting this data is a legal obligation of the data controller under Article 82 of Turkish Commercial Code No. 6102).
Based on Article 5/2(f) of the Law: provided it does not harm the fundamental rights and freedoms of the data subject, where data processing is necessary for the legitimate interests of the data controller (we have a legitimate interest, as data controller, in transferring this data to the accounting software in order to conduct finance and accounting operations).
Your transaction security data (the date and time of the transaction you carried out) is created and retained by us for the purpose of conducting information security processes, based on Article 5/2(e) of the Law, where data processing is necessary for the establishment, exercise or protection of a right (we need to create and retain your personal data to protect our rights in the event of a possible dispute).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data may, within the conditions of Article 8 of the Law, be transferred to the accounting software used, for the purpose of conducting finance and accounting operations.
Methods of Collecting Personal Data
Your personal data is obtained through semi-automated means, in the accounting software.
Data processed: Identity (name, surname), Contact (phone), Legal Transaction (vehicle plate number, entry date, date) data.
Based on Article 5/2(f) of the Law: provided it does not harm the fundamental rights and freedoms of the data subject, where data processing is necessary for the legitimate interests of the data controller (we have a legitimate interest, as data controller, in creating the vehicle registration form to ensure physical space security, and in retaining it for the purpose of conducting storage and archiving activities).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data is not transferred.
Methods of Collecting Personal Data
Your personal data is created by our staff through non-automated means, on paper.
Data processed: Identity (name, surname, nationality, passport number, ID type) data.
Based on Article 5/2(f) of the Law: provided it does not harm the fundamental rights and freedoms of the data subject, where data processing is necessary for the legitimate interests of the data controller (we have a legitimate interest, as data controller, in creating this data to conduct goods/services sales processes, in retaining it for storage and archiving activities, and in transferring it to the hotel management software used to conduct/audit business activities).
Your transaction security data (the date and time of the transaction you carried out) is created and retained by us for the purpose of conducting information security processes, based on Article 5/2(e) of the Law, where data processing is necessary for the establishment, exercise or protection of a right (we need to create and retain your personal data to protect our rights in the event of a possible dispute).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data may, within the conditions of Article 8 of the Law, be transferred to the hotel management software used, for the purpose of conducting/auditing business activities.
Methods of Collecting Personal Data
Your personal data is created through semi-automated means, via the hotel management software used.
Data processed: Identity (name, surname), Financial (contract price), Legal Transaction (sale date), Customer Transaction (agency name, check-in date, check-out date, room type, number of rooms, etc.) data.
Based on Article 5/2(f) of the Law: provided it does not harm the fundamental rights and freedoms of the data subject, where data processing is necessary for the legitimate interests of the data controller (we have a legitimate interest, as data controller, in creating this data to conduct goods/services sales processes, in retaining it for storage and archiving activities, and in transferring it to the hotel management software used to conduct/audit business activities).
Your transaction security data (the date and time of the transaction you carried out) is created and retained by us for the purpose of conducting information security processes, based on Article 5/2(e) of the Law, where data processing is necessary for the establishment, exercise or protection of a right (we need to create and retain your personal data to protect our rights in the event of a possible dispute).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data may, within the conditions of Article 8 of the Law, be transferred to the hotel management software used, for the purpose of conducting/auditing business activities.
Methods of Collecting Personal Data
Your personal data is obtained through automated means, via the reservation channel used.
Data processed: Identity (name, surname), Contact (email, phone), Financial (card number, CVV), Customer Transaction (check-in date, check-out date, number of adults, number of children) data.
Based on Article 5/2(c) of the Law: provided it is directly related to the establishment or performance of a contract, where it is necessary to process personal data belonging to the parties of the contract (this personal data is collected in order to establish the online reservation agreement).
Based on Article 5/2(e) of the Law: where data processing is necessary for the establishment, exercise or protection of a right (we retain this personal data so that we can protect our rights in the event of a possible dispute).
Your transaction security data (the date and time of the transaction you carried out) is created and retained by us for the purpose of conducting information security processes, based on Article 5/2(e) of the Law, where data processing is necessary for the establishment, exercise or protection of a right (we need to create and retain your personal data to protect our rights in the event of a possible dispute).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data is not transferred.
Methods of Collecting Personal Data
Your personal data is obtained through automated means, by your filling in the relevant form on our website's reservation page.
Data processed: Identity (name, surname, national ID number) data.
Based on Article 5/2(a) of the Law: expressly provided for by law (Article 3 of Law No. 1774 on Identity Notification expressly provides that identity information must be transferred to authorised persons, institutions and organisations for the purpose of providing information).
To Whom and For What Purposes Personal Data May Be Transferred
Your personal data may be transferred to relevant authorities, without an obligation to inform and without seeking your explicit consent, if requested under Article 28/1 of the Law. Additionally, in unforeseen circumstances, if requested under cases explicitly provided for by law, your personal data may be transferred to public institutions specified in law (such as ministries) within the purposes and limitations set out in law. Other than these legal obligations, which do not require an obligation to inform or your explicit consent, your personal data may, within the conditions of Article 8 of the Law, be transferred to the Gendarmerie General Command for the purpose of providing information to authorised persons, institutions and organisations.
Data subjects must first submit their requests regarding their personal data to the data controller. Under the Law, regarding your personal data, you may exercise the right to:
and use these rights.
You may submit your application:
you may submit your application through one of the above channels.
must be included, along with any relevant information and documents related to the subject of your application.
KARMİR HOTEL reserves the right to verify your identity. You can find further details on the procedure to be followed when applying, and more detailed information, in the Turkish Personal Data Protection Authority's "Communiqué on the Procedures and Principles of Application to the Data Controller".