Hotel and Website Confidentiality Agreement During your visit to this website and your use of the service through this Site, how the information that we receive regarding you and the services you request will be used and protected are subject to this ‘’Confidentiality Agreement’’. You hereby accept the conditions stipulated in this ‘’Confidentiality Agreement’’ when you visit this website and request to use the services we provide through this Site.
I. Purpose of personal data protection and processing policy
Until today, data and information of our customers or potential customers are kept confidential and have never been shared with third parties by virtue of the sensitivity of our business as HOTEL. Personal data protection is our essential policy. Even before any legal regulation, our company and subsidiaries had attached a great importance to the confidentiality of personal data, adopted as a working principle and gave working instructions to the employees in compliance with this principle. As ‘HOTEL’’, we undertake to adhere to all responsibilities of Privacy Act. The principle of our companies to protect personal data also
covers our subsidiaries.
II. Scope and change of personal data protection and implementation policy
This Policy prepared by our Company has been regulated in accordance with “Law on Protection of Personal Data” no. 6698 (“KVKK”). The Law has entered into force with all of its provisions as of today. The data received with your consent or pursuant to the other regulations as per to the Law shall be used to make our service more quality and to improve our services and quality policy. Again, some of the data we obtain are removed from the scope of personal data and anonymized. These data are used for statistical purposes and not subject to the enforcement of Law and our Policy. “Personal Data Protection and Implementation Policy of HOTEL aims and regulates the protection of the data which are automatically obtained from our customers, potential customers, employees and the customers and employees of the companies in cooperation with us for solution partnership and the other parties. Our company reserves the right to change our Policy and Regulation – provided to comply with the Law and protect the personal data in a better way.
III. General principles on processing of the personal data
a) Being in compliance with the law and good faith: “HOTEL” questions the source of the data it collects or sent by other companies and attaches importance to handling these in compliance with the law and good faith. Within this framework, it warns and notifies the third parties (agencies and other intermediary firms) that sell the services provided by “HOTEL” to protect the personal data.
b) Being accurate and up to date, if necessary: “HOTEL” attaches importance to the accuracy of all of the data kept within the organization, to the fact that they don’t include any misinformation and that personal data are updated only if the changes are notified.
c) Being processed for specified, explicit, and legitimate purposes: “HOTEL” processes the data limited to the services and purposes for which consent of the persons are taken during the services. It shall not process, use and make use of the data out of business purposes.
d) Being relevant, limited and proportionate to the purposes for which data are processed: “HOTEL” uses the data only for processing purposes and to the extent what the service requires.
e) Being stored only for the time designated by relevant legislation or necessitated by the purpose for which data are collected: “HOTEL” keeps the contractual data as long as it’s required by the commercial and taxation law as well as the periods of conflicts of law. Nevertheless, it shall delete or anonymize the data in case the reasons necessitating their processing cease to exist. It’s crucial to state that whether “HOTEL” collects or processes the data by one’s will or in compliance with the law, the abovementioned provisions shall apply anyhow.
You shall have the following rights pursuant to Article 11 of Law on Protection of Personal Data. A separate application shall be prepared by “HOTEL” for you to facilitate your related rights. The persons whose personal data have been processed may apply to our official announced on our website by “HOTEL” and shall be entitled to;
a) Learn whether or not your personal data have been processed,
b) Request information as to processing if your data have been processed,
c) Learn the purpose of processing of the personal data and whether data are used in accordance with their purpose,
ç) Know the third parties in the country or abroad to whom personal data have been transferred,
d) Request rectification in case personal data are processed incompletely or inaccurately,
e) Request deletion or destruction of personal data within the framework of the conditions set forth under article 7,
f) Request notification of the operations made as per clauses (d) and (e) to third parties to whom personal data have been transferred,
g) Object to occurrence of any result that is to your detriment by means of analysis of personal data exclusively through automated systems,
h) Request compensation for the damages in case the person incurs damages due to unlawful processing of personal data. As “HOTEL”, we respect to these rights.
Maximum Savings Policy/Scrimping Policy
Pursuant to our policy called as maximum savings policy or scrimping policy, the data received by “HOTEL” are processed into the system as required. Thus, which data we will collect shall be determined according to the purpose. Unnecessary data shall not be collected. Other data submitted to our company are transferred to the information system of the company in the same way. Redundant information is not stored in the system, they are deleted or anonymized. These data may be used for statistical purposes. Health data among the special quality data are only kept in the system to provide better service to the customers and to protect their health.
Deletion of personal Data
When the retention period necessitated by the Law expires, judicial procedures are completed or other requirements no longer exists, these data shall be deleted, removed or anonymized automatically, by the company or upon the request of the relevant person.
Accuracy and Currency of Data
The data within the body of “HOTEL” are processed as declared by the relevant persons as a rule. “HOTEL” is not obliged to check up on the accuracy of the data declared by the customers or the persons in touch with “HOTEL” and it’s also contrary to the Laws and our working principles. The declared data are regarded as correct and accurate. The principle of accuracy and currency of personal data has also been adopted by “HOTEL”. The personal data processed upon the request of the relevant person or from official documents that are submitted to our company are updated. Necessary precautions are taken for this purpose.
Confidentiality and data security
Personal data are confidential and “HOTEL” obeys the rule of confidentiality. Only authorized persons shall access the personal data. All necessary technical and administrative measures are taken to protect the personal data collected by “HOTEL” and to prevent the damage on our customers and potential customers. Within this framework, it shall be ensured that the software complies with the standards, third parties are selected with caution and data protection policy is observed within the company.
IV. Purpose of data processing
Collection and processing of personal data by “HOTEL” shall be executed in line with the purposes stipulated in the letter of clarification. The data are collected and processed to draw up contracts and provide better services to the customers.
V. Data of customer, potential customer and business and solution partners Collection and processing of data for contractual relationship
In case of a contractual relationship with our customers and potential customers, the collected personal data may be used without the approval of the customers. However, this use shall be for the purpose of the contract. The data shall be used for better execution of the contract and as required by the services and updated, if necessary, by contacting the customers. Nevertheless, the data provided to us by our potential customers shall be processed to easier and more quality services later. These data shall be deleted upon requests in case of lack of any contractual relationship.
Data of Business and Solution Partners
“HOTEL” adopts as a principle to act in compliance with the laws when exchanging the data both with business and solution partners. The data are shared with the business and solution partners with the understanding of data confidentiality and as required by the services and it’s definitely ensured that these parties take measures regarding the data security.
Data processing for advertisement purposes
Electronic messages for advertisement purposes can only be sent to the persons with prior consent in compliance with the Law on the Regulation of E-Commerce and the Law on Commercial Communication and Commercial Electronic Messages. An explicit consent of the person is required to send advertisements. “HOTEL” obeys the details of ‘’the consent’’ specified in the same legislation. The consent to be obtained should cover all commercial electronic messages that are sent to the electronic communication addresses of the recipients to promote and market the goods and services of the company, to promote the business or to increase the recognition level of the company with contents including greetings and wishes. This consent may be obtained via any electronic communication channel or at physical medium in written. The important thing is to obtain the declaration of the recipient that he/she accepts to receive commercial electronic messages and to have his/her full name and electronic communication address.
Data processing due to legal obligations of the company or being stipulated explicitly in the Law
Personal data may be processed without prior consent when it’s stipulated explicitly in the relevant legislation or to fulfill a legal obligation specified in the legislation. Type and scope of the data processes are required for data processing activity that is permitted by the Laws and they should comply with the relevant legal provisions.
Data processing of the company
Personal data may be processed pursuant to the legal purposes and the services of the company. However, the data shall not be used for services contrary to the laws under any circumstances. Processing of special quality data
Pursuant to the Law, race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothes, membership of association, foundation or union, health, sexual choice, juridical sentence and data regarding safety measures and biometric and genetic data are among the special quality data. “HOTEL” also takes adequate measures determined by the Board for the processing of special quality data. “HOTEL” may process the special quality data only for the corresponding purposes to provide better services.
Data processed with automatic systems
“HOTEL” acts in compliance with the Law for data processed with automatic systems. The information obtained from these data without the explicit consent of the persons shall not be used against the person. However, “HOTEL” may take decisions regarding the persons that it will perform process by using the data within the system.
VI. Data of our employees Processing of the data for business relations
Personal data of the employees may be processed without obtaining consent to the extent of requirements of health insurance and business relations. However, “HOTEL” hereby undertakes the protection and confidentiality of the data of the employees.
Processing as per Legal Obligations
“HOTEL” may also processes the personal data of the employees without obtaining a separate consent to fulfill a legal obligation stipulated in the legislation or in case it’s explicitly specified in the legislation. This case is limited to the obligations arising from the Law.
Processing in Favor of the Employees
“HOTEL” may process the personal data without obtaining the consent for the procedures in favor of company employees like private health insurances. For the disputes arising from the business relations, “HOTEL” may also process the data of the employees.
Processing of special quality data
Pursuant to the Law, race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothes, membership of association, foundation or union, health, sexual choice, juridical sentence and data regarding safety measures and biometric and genetic data are among the special quality data. Besides the consent of the relevant person, “HOTEL” also takes adequate measures determined by the Board for the processing of special quality data. Special quality data may be processed limited to and related to the cases permitted by the Law without the consent of the person. The quality data obtained from the employees shall only be used for the corresponding purpose to allow them to benefit from the insurance and health services.
Data processed with automatic systems
The data processed regarding the employees with automatic systems may be used for in-house promotions and performance assessments. The employees reserve the right to appeal to the results against them and they should perform this process in compliance with the internal procedures. Appeals of the employees shall be evaluated again within the company.
Telecommunication and internet
The computers, telephone, e-mail and other applications allocated to the employees within the company shall only be used for business purposes. The employee cannot use any of these means allocated to himself/herself by the company for private purposes or communication. The company may control and monitor the data on these means. The employee undertakes not to keep any data or information apart from the business purposes on the computer, telephones or other means allocated to himself/herself as of his/her employment date.
VIII. Rights of the relevant person
“HOTEL” hereby agrees that the relevant person must provide his/her consent before processing the data within the scope of the Law and he/she reserves the right to determine the destiny of the data after the data is processed. Regarding the personal data, the relevant persons holds the right to do the following by applying to our official announced on the web page by “HOTEL”;
a) To be informed whether his/her personal data are processed or not,
b) To request information if the personal data are processed,
c) To learn the purpose of processing the personal data and whether the data are used for the corresponding purposes,
ç) To get information on the third parties to whom the personal data are transferred in the country and abroad,
d) In case the personal data are processed incompletely or inaccurately, to request the correction,
e) To request that personal data are deleted or removed within the framework of the conditions stipulated in article 7,
f) To request that the processes performed as per clause (d) and (e) are notified to the third parties to whom the personal data are transferred,
g) To appeal to the negative results against himself/herself arising from the analysis of the data processed exclusively through the automatic systems,
ğ) In case the personal data are damaged due to the processing of the data contrary to the Law, to request that the damages are indemnified. Nevertheless, the persons don’t reserve any right on the anonymized data within the company. “HOTEL” may share the personal data as required by a juridical function or governmental authority as per the business and contractual relationship. In order to use your rights as set out above, you must submit your written request with your necessary information identifying your identity and your statement of your right to use Written signed by registered mail or to with our secure electronic signature to our registered e-mail address.
Your application containing your personal data ownership and explanations of the rights you will use to use your rights above and which you request to use; you are required to be specifically authorized in this matter and to certify your competence, to include the identity and address information of the application, and to certify your identity to the applicant if the subject you request is clear and understandable, that you are concerned with the person you are requesting or you are acting on behalf of someone else. In this context, the applications will be concluded within the shortest possible time period and maximum 30 days.
IX. Confidentiality Principle
The data of the employees and other persons within “HOTEL” are confidential. Nobody can use, copy, reproduce, transfer these data for other purposes apart from the business purposes.
X. Process security
All necessary technical and administrative measures are taken to protect the personal data received by “HOTEL” and to prevent the retention of them by unauthorized persons and to prevent the damage on our customers and potential customers. Within this framework, it’s ensured that the software complies with the standards, third parties are selected with care and data protection policy is followed within the company. “HOTEL” carries out the internal and external inspections for protection of the personal data.