Privacy Notice (KVKK)
NOTICE ON THE PROCESSING OF PERSONAL DATA OF MARISSTONE HOTELS GUESTS
Dear Guest,
Thank you for choosing Marisstone Hotels. We would like to inform you about how your personal data is processed.
This Privacy Notice has been prepared by Kartur İnşaat, Reklam, Turizm ve Taşımacılık Ltd. Şti. (MERSİS: 0499029508500012) (the “Company” or “Marisstone Hotel”) pursuant to the Turkish Personal Data Protection Law No. 6698 (the “Law”), to inform data subjects about the procedures and principles applicable to the processing of guests’ personal data.
In connection with the accommodation services you receive from Marisstone Hotels, we collect and process, in physical or electronic form: identity and contact information that you share with us, including any information in its attachments; financial information required to invoice the service; accommodation information; information you provide verbally during reservation discussions; visual and audio recordings made by security cameras at the entrance upon arrival and within the resort during your stay; information contained in correspondence with you and its attachments; and internet usage logs required by Law No. 5651 if you use the internet access provided by Marisstone Hotels during your stay.
Further information on the matters covered by this notice is available in the Personal Data Protection and Processing Policy of Kartur İnşaat, Reklam, Turizm ve Taşımacılık Ltd. Şti. (“Marisstone Hotels”) at http://www.marisstone.com, or through the detailed Privacy Notice option at our call centre on +90 284 767 72 22 or +90 284 767 72 23.
I. Data Controller
Kartur İnşaat, Reklam, Turizm ve Taşımacılık Ltd. Şti. (“Marisstone Hotels”), at Gökçetepe Köyü, Zeytindere Mevkii Küme Evler 201 - 22880 Keşan / Edirne, is the data controller under the Law.
II. Purposes for Which Your Personal Data Is Processed
Marisstone Hotels processes your personal data under Law No. 6698 for the following purposes:
- Managing service activation processes.
- Conducting emergency management processes.
- Ensuring the security of physical premises and the data controller’s operations.
- Conducting communication activities.
- Conducting sales processes for goods and services.
- Conducting guest satisfaction activities, including requests and complaints, and managing guest relations.
- Conducting advertising, campaign and promotional activities.
- Providing information to authorised persons, institutions and organisations.
- Conducting finance and accounting activities.
III. Personal Data That May Be Processed
Depending on the purpose of your visit and the services you use, the following information may be processed:
- Identity, contact and accommodation information, and any information on the registration card.
- Financial information required to invoice the service.
- Information contained in correspondence with our Company and information shared verbally during reservation discussions.
- Visual and audio data recorded by security cameras.
- Visual and audio data recorded by the Company’s advertising department, if you give explicit consent.
- Internal IP allocation logs kept as required by law if you connect to the Company’s guest network to use the internet.
IV. Recipients and Purposes of Personal Data Transfers
In accordance with the purposes above and the conditions specified by the Law, your personal data may be transferred:
- To our business partners and suppliers, limited to the provision of our products and services.
- To contracted travel agencies if accommodation services are obtained through an agency.
- In commercial, financial or legal disputes, and only where and to the extent required by law, to consultants, audit firms, lawyers, authorised public institutions and organisations, and judicial authorities.
V. Collection Methods and Legal Basis
Your personal data is collected by Marisstone Hotels or natural or legal persons processing data on its behalf, through physical documents, camera recordings and digital records, and by obtaining your explicit consent unless otherwise provided by law.
Marisstone Hotels processes your personal data on the basis of the Turkish Personal Data Protection Law No. 6698 and other applicable legislation.
VI. Your Rights Under the Law
Article 11 of the Law sets out your rights. By submitting a written application to Marisstone Hotels or the Company’s head office, you may:
- Learn whether your personal data is being processed.
- Request information if your personal data has been processed.
- Learn the purpose of processing and whether your data is used in accordance with that purpose.
- Learn the third parties to whom your data has been transferred in Türkiye or abroad.
- Request rectification if your personal data has been processed incompletely or inaccurately.
- Request deletion, destruction or anonymisation under the conditions specified in Article 7 of the Law.
- Request notification to recipients of the actions taken in response to your rectification or deletion requests.
- Object to an outcome against you arising exclusively from analysis by automated systems.
- Claim compensation if you suffer damage due to unlawful processing of your personal data.
To exercise these rights, complete the Data Subject Request Form, providing the information necessary to verify your identity and an explanation of the right you wish to exercise. You may deliver your application in person to Gökçetepe Köyü, Zeytindere Mevkii Küme Evler 201 - 22880 Keşan / Edirne, send it through a notary public, or email a signed copy to kvkk@marisstone.com. Requests will be resolved free of charge as soon as possible and within 30 days at the latest, depending on their nature. If the process incurs an additional cost, a fee may be charged according to the tariff determined by the Personal Data Protection Board. If an application is made on another person’s behalf, a power of attorney and other documents verifying your identity must be enclosed.
Personal Data Processing and Protection Policy
PERSONAL DATA PROCESSING AND PROTECTION POLICY
PART ONE
§ 1. INTRODUCTION
1.1. Introduction
As KAR TUR İNŞAAT REKLAM TURİZM VE TAŞIMACILIK LİMİTED ŞİRKETİ (the “Company” or “Marisstone Hotel”), we attach the utmost importance to the lawful processing and protection of personal data under Personal Data Protection Law No. 6698 (the “Law”) and exercise this care in all our planning and activities. With this awareness, we present this Personal Data Processing and Protection Policy (the “Policy”) both to fulfil our obligation to inform under Article 10 of the Law and to explain the administrative and technical measures we take to process and protect personal data.
1.2. Purpose of the Policy
The main purpose of this Policy is to explain the systems for processing and protecting personal data in accordance with the law and the purpose of the Law, and to inform the persons whose personal data our Company processes, particularly Company Stakeholders, Company Officers, Company Business Partners, Job Applicants, Visitors, Company Customers, Prospective Customers and Third Parties. The aim is to ensure full compliance with legislation in our personal data processing and protection activities and to protect all rights of data subjects arising from personal data legislation.
1.3. Scope of the Policy and Data Subjects
This Policy has been prepared for, and applies to, persons whose personal data our Company processes by fully or partly automated means, or by non-automated means forming part of a data filing system, particularly Company Stakeholders, Company Officers, Company Business Partners, Job Applicants, Visitors, Company Customers, Prospective Customers and Third Parties. This Policy does not apply to legal entities or data relating to legal entities.
Our Company informs these Data Subjects about the Law by publishing this Policy on its website. The Employee Personal Data Processing and Protection Policy applies to our employees. This Policy also does not apply where the data does not fall within the definition of “Personal Data” below or where our Company's processing activities are not carried out by the means specified above.
The data subjects covered by this Policy are as follows:
| Company Stakeholder | : | Natural persons who are stakeholders in the Company. |
|---|---|---|
| Individual Company Business Partner | : | Natural persons with whom the Company has any form of business relationship. |
| Stakeholder, Officer or Employee of a Company Business Partner | : | All natural persons, including employees, stakeholders and officers of natural persons and legal entities with whom the Company has any form of business relationship, such as business partners and suppliers. |
| Company Officer | : | Members of the Company's board of directors and other authorised natural persons. |
| Job Applicant | : | Natural persons who have applied for a job with the Company by any means or made their CV and related information available for the Company's review. |
| Company Customer | : | Natural persons who use or have used the Company's products and services, regardless of whether they have a contractual relationship with the Company. |
| Prospective Customer | : | Natural persons who have requested or expressed interest in using the Company's products and services, or who are considered likely to have such interest in accordance with commercial practice and good faith. |
| Visitor | : | All natural persons who enter the Company's physical premises for various purposes or visit its websites for any purpose. |
| Third Party | : | Other natural persons who fall outside the scope of the Personal Data Protection and Processing Policy prepared for Company Employees and outside any category of data subject in this Policy. |
1.4. Definitions
The terms used in this Policy have the following meanings:
| Company / Our Company | : | KAR TUR İNŞAAT REKLAM TURİZM VE TAŞIMACILIK LİMİTED ŞİRKETİ. |
|---|---|---|
| Personal Data | : | Any information relating to an identified or identifiable natural person. |
| Special Categories of Personal Data | : | Data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, religious denomination or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sex life, criminal convictions and security measures, and biometric and genetic data. |
| Processing of Personal Data | : | Any operation performed on personal data, such as obtaining, recording, storing, retaining, modifying, rearranging, disclosing, transferring, taking over, making available, classifying or preventing its use, by fully or partly automated means, or by non-automated means forming part of a data filing system. |
| Data Subject | : | Company Stakeholders, Company Business Partners, Company Officers, Job Applicants, Visitors, Company Customers, Prospective Customers, Third Parties and persons whose personal data is processed by the Company. |
| Data Filing System | : | A filing system in which personal data is processed according to specific criteria. |
| Data Controller | : | The natural person or legal entity that determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system. |
| Data Processor | : | A natural person or legal entity that processes personal data on behalf of the data controller, based on the authority granted by the controller. |
| Explicit Consent | : | Freely given, informed consent relating to a specific matter. |
| Anonymisation | : | Rendering data previously associated with a person incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data. |
| Law | : | Personal Data Protection Law No. 6698. |
| Personal Data Protection Board | : | The Personal Data Protection Board. |
1.5. Entry into Force of the Policy
This Policy, prepared by the Company and effective as of …………………., was updated on …/…/… and is published on the Company's website (www……………………….). It is also made available to Data Subjects upon request.
PART TWO
§ 2. PROCESSING AND TRANSFER OF PERSONAL DATA
2.1. General Principles for Processing Personal Data
The Company processes Personal Data in accordance with the procedures and principles stipulated in the Law and this Policy. When processing Personal Data, the Company acts in accordance with the following principles:
- Personal Data is processed lawfully and in accordance with the requirements of good faith.
- Personal Data is kept accurate and up to date. In this regard, due care is given to identifying the sources from which data is obtained, verifying its accuracy and assessing whether it needs updating.
- Personal Data is processed for specific, explicit and legitimate purposes . A legitimate purpose means that the Personal Data processed by the Company is related to, and necessary for, its business or the services it provides.
- Personal Data is relevant to achieving the purposes determined by the Company; processing data that is unrelated to or unnecessary for those purposes is avoided. Processing is limited to the data necessary to achieve the purpose. Accordingly, the Personal Data processed is relevant, limited and proportionate to the purposes for which it is processed.
- Where the relevant legislation stipulates a retention period, the Company complies with that period; otherwise, Personal Data is retained only for as long as necessary for the purpose for which it is processed. When there is no longer a valid reason for retaining Personal Data, it is deleted, destroyed or anonymised.
2.2. Conditions for Processing Personal Data
The Company does not process Personal Data without the data subject's explicit consent. Personal Data may be processed without explicit consent where one of the following conditions exists.
- The Company may process Data Subjects' Personal Data without explicit consent where expressly provided for by law. For example, Article 230 of the Tax Procedure Law does not require a person's explicit consent for their name to appear on an invoice.
- Personal Data may be processed without explicit consent where necessary to protect the life or physical integrity of a person who is unable to express consent due to practical impossibility, or whose consent is not legally valid, or that of another person. For example, where a person is unconscious or their consent is invalid due to mental illness, their Personal Data may be processed during medical intervention to protect life or physical integrity. Data such as blood group, previous illnesses and operations, and medications used may be processed through the relevant healthcare system.
- The Company may process Personal Data belonging to the parties to a contract where this is directly related to the establishment or performance of that contract. For example, a creditor's account number may be obtained to make a payment required under a contract.
- The Company may process Data Subjects' Personal Data where necessary to fulfil its legal obligations as data controller.
- The Company may process Personal Data made public by Data Subjects themselves, in other words disclosed to the public by any means, because the legal interest requiring protection no longer exists.
- The Company may process Data Subjects' Personal Data without explicit consent where processing is necessary to exercise or protect a legally legitimate right.
- The Company may process Data Subjects' Personal Data where necessary for its legitimate interests, provided that this does not harm the fundamental rights and freedoms protected under the Law and the Policy. The Company takes due care to comply with the fundamental principles of personal data protection and to maintain a balance between the interests of Data Subjects.
2.3. Conditions for Processing Special Categories of Personal Data
The Company does not process Special Categories of Personal Data without the data subject's explicit consent. However, Personal Data other than data relating to health and sex life may be processed without explicit consent where provided for by law. The Company processes Personal Data relating to health and sex life without explicit consent only for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing, where we are subject to a duty of confidentiality. The Company takes the necessary steps to implement the adequate measures determined by the Board for processing Special Categories of Personal Data.
2.4. Conditions for Transferring Personal Data
Our Company may transfer Data Subjects' Personal Data and Special Categories of Personal Data to third parties in accordance with the Law, by establishing the necessary confidentiality conditions and taking security measures for its processing purposes. Our Company complies with the statutory rules when transferring Personal Data. For legitimate and lawful processing purposes, transfers are based on and limited to one or more of the conditions in Article 5 of the Law listed below.
Personal Data may be transferred to third parties:
- Where the Data Subject has given explicit consent;
- Where a law expressly provides for the transfer of Personal Data; or where it is necessary to protect the life or physical integrity of the Data Subject or another person and
- the Data Subject is unable to express consent due to practical impossibility, or their consent is not legally valid;
- Where the transfer of Personal Data belonging to the parties to a contract is necessary and directly related to establishing or performing that contract;
- Where the transfer is necessary for our Company to fulfil a legal obligation;
- Where the Personal Data has been made public by the Data Subject;
- Where the transfer is necessary to establish, exercise or protect a right;
- Where the transfer is necessary for our Company's legitimate interests, provided that the Data Subject's fundamental rights and freedoms are not harmed.
2.4.1. Conditions for Transferring Personal Data Abroad
Our Company may transfer Data Subjects' Personal Data and Special Categories of Personal Data to third parties abroad by taking the necessary security measures for its processing purposes. Personal Data may be transferred to countries declared by the Personal Data Protection Board to provide adequate protection or, where adequate protection is lacking, to countries where the data controllers in Türkiye and the relevant foreign country provide a written undertaking of adequate protection and the Board has authorised the transfer.
2.5. Conditions for Transferring Special Categories of Personal Data
By exercising due care, taking the necessary security measures and implementing the adequate measures stipulated by the Personal Data Protection Board, the Company may transfer a Data Subject's Special Categories of Personal Data to third parties for legitimate and lawful processing purposes in the following circumstances:
- Where the Data Subject has given explicit consent; or
- Without the Data Subject's explicit consent where the following conditions apply:
- For Special Categories of Personal Data other than health and sex life data (race, ethnic origin, political opinions, philosophical beliefs, religion, religious denomination or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, criminal convictions and security measures, and biometric and genetic data), where provided for by law;
- For Special Categories of Personal Data relating to health and sex life, only by persons subject to a duty of confidentiality or authorised institutions and organisations, for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing.
2.5.1. Transfer of Special Categories of Personal Data Abroad
By exercising due care, taking the necessary security measures and implementing the adequate measures stipulated by the Personal Data Protection Board, the Company may transfer a Data Subject's Special Categories of Personal Data, for legitimate and lawful processing purposes, to foreign countries providing adequate protection or where a data controller undertakes to provide adequate protection, in the following circumstances:
- Where the Data Subject has given explicit consent; or
- Without the Data Subject's explicit consent where the following conditions apply:
- For Special Categories of Personal Data other than health and sex life data (race, ethnic origin, political opinions, philosophical beliefs, religion, religious denomination or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, criminal convictions and security measures, and biometric and genetic data), where provided for by law;
- For Special Categories of Personal Data relating to health and sex life, only by persons subject to a duty of confidentiality or authorised institutions and organisations, for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing.
PART THREE
§ 3. PURPOSES OF PROCESSING AND TRANSFERRING PERSONAL DATA AND RECIPIENTS
3.1. Purposes of Processing and Transferring Personal Data
Personal Data is processed lawfully and in accordance with the purpose of the Law, for the Company's following purposes:
- Planning and implementing human resources policies in the best possible way;
- Properly planning, conducting and managing business partnerships and strategies;
- Ensuring the legal, commercial and physical security of the Company and its business partners;
- Ensuring corporate operations and planning and carrying out management and communication activities;
- Enabling Data Subjects to benefit from products and services in the best possible way, and tailoring and recommending them according to their requests, needs and wishes;
- Ensuring the highest level of data security;
- Improving the services offered on the website and resolving website errors;
- Contacting Data Subjects who submit requests and complaints, and managing those requests and complaints;
- Event management;
- Managing relationships with business partners or suppliers;
- Conducting recruitment processes;
- Supporting the planning and implementation of benefits and entitlements for senior Company executives;
- Carrying out and monitoring financial reporting and risk management operations;
- Conducting and monitoring the Company's legal affairs;
- Carrying out activities to protect its reputation;
- Managing investor relations;
- Providing information required by legislation to authorised institutions;
- Creating and monitoring visitor records.
Processing is limited to these purposes and subject to the conditions specified in Articles 5 and 6 of the Law. If processing for these purposes does not meet any of the conditions stipulated in the Law, the Company obtains your explicit consent for the relevant processing activity.
3.2. Recipients of Personal Data
Personal Data may be shared with our business and solution partners, banks and third parties that perform technical, logistical and similar operations on our behalf, to ensure that the services provided to you are complete and without defects, and only to the extent appropriate to the nature of the service. These third parties are limited to persons who must have access to the relevant information to provide those services fully and properly.
Your Personal Data may also be transferred, limited to the relevant person or institution, where sharing with other third parties is necessary to provide the service fully and properly, to fulfil the Company's legal obligations, where expressly provided for by law, or where a judicial or administrative order has been issued in accordance with the law.
Some Personal Data may be shared with advertisers solely in an aggregated, anonymised form together with information about other users, to adapt advertisements to their target audience.
Anonymised data cannot be matched to you as visitors or customers, does not contain your identity information and does not make you identifiable. Your privacy is protected in anonymised data.
PART FOUR
§ 4. METHODS AND LEGAL GROUNDS FOR COLLECTING PERSONAL DATA; DELETION, DESTRUCTION, ANONYMISATION AND RETENTION PERIODS
4.1. Methods and Legal Grounds for Collecting Personal Data
For the purpose of checking compliance with Article 1, which sets out the purpose of the Law, and Article 2, which sets out its scope, Personal Data is collected verbally, in writing or electronically, through technical and other means, including stores, dealer/franchise channels, sales outlets, call centres, Company websites and mobile applications. It is collected to achieve the purposes in this Policy and to fulfil statutory responsibilities fully and correctly, on legal grounds arising from legislation, contracts, requests and demands, and is processed by the Company or processors appointed by the Company.
4.2. Deletion, Destruction or Anonymisation of Personal Data
Without prejudice to provisions in other laws on deletion, destruction or anonymisation, the Company deletes, destroys or anonymises Personal Data on its own initiative or at the data subject's request, in accordance with its Personal Data Retention and Disposal Policy, when the reasons requiring processing cease to exist, even if the data was processed in accordance with this Law and other laws.
4.3. Retention Periods for Personal Data
Where legislation stipulates a retention period, the Company retains Personal Data for that period. Where no period is specified, Personal Data is processed for as long as required by the relevant activity, the Company's practices and commercial custom, and is then deleted, destroyed or anonymised.
Where the processing purpose and the retention periods stipulated by legislation and the Company have ended, Personal Data may be retained solely as evidence in possible legal disputes or to assert a related right or establish a defence. Such periods are determined by reference to the limitation periods for asserting the right and examples of previous claims made against the Company on the same matters even after those limitation periods. In this case, retained Personal Data is not accessed for any other purpose and is accessed only when needed in the relevant legal dispute. Once these periods also expire, the Personal Data is deleted, destroyed or anonymised.
Detailed provisions concerning the Company's techniques for retaining, deleting, destroying and anonymising Personal Data are set out in the Company's Personal Data Retention and Disposal Policy.
PART FIVE
§ 5. MATTERS RELATING TO THE PROTECTION OF PERSONAL DATA
In accordance with Article 12 of the Law, the Company takes the necessary technical and administrative measures to ensure an appropriate level of security to prevent unlawful processing of and unlawful access to the Personal Data it processes, and to ensure its safekeeping. It carries out or commissions the necessary audits in this regard.
5.1. Ensuring the Security of Personal Data
5.1.1. Technical and Administrative Measures to Ensure Lawful Processing of Personal Data
The Company takes technical and administrative measures to ensure lawful processing of Personal Data, taking technological capabilities and implementation costs into account.
- Technical Measures to Ensure Lawful Processing of Personal Data
The principal technical measures taken by the Company to ensure lawful processing of Personal Data include, but are not limited to, the following:
- Personal Data processing activities within the Company are monitored through established technical systems.
- Technical measures are periodically reported to the relevant persons as part of the internal audit mechanism.
- Personnel with technical knowledge are employed.
- Administrative Measures to Ensure Lawful Processing of Personal Data
The principal administrative measures taken by the Company to ensure lawful processing of Personal Data include, but are not limited to, the following:
- Employees are informed and trained on personal data protection law and lawful processing of Personal Data.
- All Company activities are analysed in detail for each business unit, and the Personal Data processing activities associated with each unit's operations are identified.
- For each business unit and its specific activities, the requirements to be fulfilled to ensure that Personal Data processing complies with the processing conditions of the Law are determined.
- Awareness is raised and implementation rules are established in the relevant business units to meet the legal compliance requirements identified for each unit. Necessary administrative measures are implemented through internal policies and training to monitor these matters and ensure continuity of implementation.
- Contracts and documents governing the relationship between the Company and its employees include obligations not to process, disclose or use Personal Data except under the Company's instructions or statutory exceptions. Employee awareness is raised and audits are conducted to fulfil obligations arising from the Law.
5.1.2. Technical and Administrative Measures to Prevent Unlawful Access to Personal Data
The Company takes technical and administrative measures to prevent negligent or unauthorised disclosure, access or transfer, and all other forms of unlawful access to Personal Data, taking into account the nature of the data, technological capabilities and implementation costs.
- Technical Measures to Prevent Unlawful Access to Personal Data
The principal technical measures taken by the Company to prevent unlawful access to Personal Data include, but are not limited to, the following:
- Technical measures are taken in line with technological developments and are periodically updated and renewed.
- Technical access and authorisation solutions are implemented in accordance with the legal compliance requirements identified for each business unit.
- Access permissions are restricted and regularly reviewed.
- Technical measures are periodically reported to the relevant persons as part of the internal audit mechanism. Matters posing risks are reassessed and the necessary technological solutions are developed.
- Software and hardware incorporating antivirus systems and firewalls are installed.
- Personnel with technical knowledge are employed.
- Applications in which Personal Data is collected undergo regular security scans to identify vulnerabilities, and identified vulnerabilities are remedied.
- Administrative Measures to Prevent Unlawful Access to Personal Data
The principal administrative measures taken by the Company to prevent unlawful access to Personal Data include, but are not limited to, the following:
- Employees are trained on the technical measures required to prevent unlawful access to Personal Data.
- Internal access and authorisation processes for Personal Data are designed and implemented in accordance with each business unit's legal compliance requirements for processing.
- Employees are informed that they may not disclose Personal Data they learn to others in breach of the Law or use it for purposes other than processing, and that these obligations continue after leaving their role. The necessary undertakings are obtained from them accordingly.
- Contracts with persons to whom the Company lawfully transfers Personal Data include provisions requiring recipients to take the security measures necessary to protect Personal Data and to ensure compliance with those measures within their organisations.
5.1.3. Retention of Personal Data in Secure Environments
The Company takes the necessary technical and administrative measures to retain Personal Data in secure environments and prevent its destruction, loss or alteration for unlawful purposes, taking technological capabilities and implementation costs into account.
- Technical Measures for Retaining Personal Data in Secure Environments
The principal technical measures taken by the Company to retain Personal Data in secure environments include, but are not limited to, the following:
- Systems consistent with technological developments are used to retain Personal Data securely.
- Personnel with technical expertise are employed.
- Technical security systems are established for storage areas. Security tests and research are conducted to identify vulnerabilities in information systems, and existing or potential risks identified by these activities are remedied. Technical measures are periodically reported to the relevant persons as part of the internal audit mechanism.
- Backup programs are used lawfully to ensure secure retention of Personal Data.
- Access to environments holding Personal Data is restricted to authorised persons and to the purpose of retention. Access to storage areas containing Personal Data is logged, and inappropriate access or access attempts are reported to the relevant persons immediately.
- Administrative Measures for Retaining Personal Data in Secure Environments
The principal administrative measures taken by the Company to retain Personal Data securely are listed below:
- Employees are trained on ensuring secure retention of Personal Data.
- Legal and technical consultancy services are obtained to monitor developments in information security, privacy and personal data protection and to take the necessary action.
- Where external services are obtained for technical requirements relating to Personal Data retention, contracts with the companies to which data is lawfully transferred include provisions requiring recipients to take the necessary security measures to protect Personal Data and ensure compliance within their organisations.
5.1.4. Auditing Personal Data Protection Measures
In accordance with Article 12 of the Law, the Company carries out or commissions the necessary internal audits. Audit results are reported to the relevant department through the Company's internal procedures, and the activities necessary to improve measures are undertaken.
5.1.5. Measures in the Event of Unauthorised Disclosure of Personal Data
In accordance with Article 12 of the Law, the Company operates a system to notify the relevant Data Subject and the Personal Data Protection Board as soon as possible if processed Personal Data is obtained unlawfully by others. If the Board considers it necessary, the incident may be announced on the Board's website or by other means.
5.2. Safeguarding Data Subjects' Statutory Rights
The Company safeguards all statutory rights of Data Subjects through implementation of the Policy and the Law and takes all measures necessary to protect those rights. Detailed information on Data Subjects' rights is provided in Part Six of this Policy.
5.3. Protection of Special Categories of Personal Data
The Law attaches particular importance to certain Personal Data because unlawful processing may cause harm or discrimination. This includes data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, religious denomination or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sex life, criminal convictions and security measures, and biometric and genetic data. The Company exercises the utmost care in protecting lawfully processed Personal Data designated as “special categories” by the Law. Technical and administrative measures for protecting personal data are also applied with the utmost care to these categories, and the necessary internal audits are ensured.
PART SIX
§ 6. DATA SUBJECTS' RIGHTS, EXERCISE OF RIGHTS AND ASSESSMENT
6.1. Informing Data Subjects
The Company informs Data Subjects when Personal Data is obtained, in accordance with Article 10 of the Law. This includes the identity of the Company's representative, if any, the purposes of processing, the recipients and purposes of any transfers, the methods and legal grounds for collecting Personal Data, and the Data Subject's rights.
6.2. Data Subjects' Rights under the Personal Data Protection Law
Under Article 10 of the Law, the Company informs you of your rights, explains how to exercise them and establishes the necessary internal procedures and administrative and technical arrangements. Under Article 11, persons whose Personal Data is collected have the following rights:
- To learn whether their Personal Data is being processed;
- To request information if their Personal Data has been processed;
- To learn the purpose of processing and whether their Personal Data is used in accordance with that purpose;
- To know the third parties to whom Personal Data is transferred domestically or abroad;
- To request correction of incomplete or inaccurate Personal Data;
- To request deletion or destruction of Personal Data under the conditions in Article 7 of the Law;
- To request notification to third-party recipients of the actions taken under subparagraphs (d) and (e) of Article 11 of the Law;
- To object to a result that is detrimental to them arising from analysis of processed data exclusively through automated systems;
- To claim compensation for damage caused by unlawful processing of Personal Data.
The Company recognises these rights.
6.3. Exercise of Data Subjects' Rights
Data Subjects may submit requests concerning the rights listed in section 6.2 free of charge, with information and documents establishing their identity, by completing and signing the Application Form available at the ……………. link and submitting it through the methods below or other methods determined by the Personal Data Protection Board:
- After completing the form, delivering a copy bearing a handwritten signature in person or through a notary to [………………………………];
- After completing and signing the form with a “secure electronic signature” under Electronic Signature Law No. 5070, sending it by registered electronic mail to ……………...@..............kep.tr;
- Applying in person with proof of identity and information and documents relating to the request, and submitting the form using the email address previously notified to the Company and registered in its system.
For third parties to apply on behalf of a data subject, the applicant must hold a special power of attorney issued by the data subject through a notary.
6.4. Procedure and Time Limit for Responding to Applications
The Company resolves requests free of charge as soon as possible, and no later than thirty days, depending on their nature. If the procedure entails an additional cost, a fee may be charged according to the tariff set by the Personal Data Protection Board. The Company may accept a request or reject it with reasons, and communicates its response in writing or electronically. If a request is accepted, the Company takes the necessary action.
6.5. Data Subjects' Right to Complain to the Personal Data Protection Board
If an application is rejected, the response is inadequate or no response is provided within the time limit, the data subject may complain to the Personal Data Protection Board within thirty days of learning of the response and, in any event, within sixty days of the application date.
PART SEVEN
§ 7. COMPANY MANAGEMENT STRUCTURE UNDER THE PERSONAL DATA PROCESSING AND PROTECTION POLICY
A Personal Data Committee has been established by decision of senior management to administer this Policy and related policies. The Committee is authorised and responsible for taking the steps necessary to retain and process Data Subjects' data in accordance with the law, this Policy and related policies. Detailed provisions on the Committee's members and their duties appear in the Company's Personal Data Retention and Disposal Policy.
PART EIGHT
§ 8. UPDATES, COMPLIANCE AND AMENDMENTS
8.1. Updates and Compliance
The Company reserves the right to amend this Policy and related policies in response to changes in the Law, decisions of the Personal Data Protection Board, or developments in the sector or information technology.
Amendments to this Policy are incorporated into the text immediately, with explanations of the changes at the end of the Policy.
8.2. Amendments
| …../……/……….. | : | The Personal Data Processing and Protection Policy has been published. |
*There are no earlier amendments.*
Personal Data Retention and Disposal Policy
KAR TUR İNŞAAT REKLAM TURİZM VE TAŞIMACILIK LİMİTED ŞİRKETİ
PERSONAL DATA RETENTION AND DISPOSAL POLICY
PART 1: NATURE AND PURPOSE OF THE DISPOSAL POLICY
1.1. INTRODUCTION
This disposal policy has been prepared by KAR TUR İNŞAAT REKLAM TURİZM VE TAŞIMACILIK LİMİTED ŞİRKETİ (the “Company” or “Marisstone Hotel”) to establish the procedures and principles to be applied by KAR TUR for deleting, destroying or anonymising the personal data we hold as data controller, under Personal Data Protection Law No. 6698 and other applicable legislation.
Accordingly, the personal data of our employees, job applicants, customers and all natural persons whose data is held by KAR TUR for any reason is managed lawfully under the Personal Data Processing and Protection Policy and this Personal Data Retention and Disposal Policy.
All KAR TUR employees must apply this Policy to the extent relevant to their job descriptions.
1.2. DEFINITIONS
| Direct identifiers | : | Identifiers that, on their own, directly reveal, disclose and distinguish the person to whom they relate. |
|---|---|---|
| Indirect identifiers | : | Identifiers that, together with other identifiers, reveal, disclose and distinguish the person to whom they relate. |
| Data Controller | : | KAR TUR |
| Data Subject | : | The natural person whose personal data is processed. |
| Relevant Unit | : | Persons who process personal data within the KAR TUR organisation or under the authority and instructions of the data controller, excluding the person or unit responsible for technical storage, protection and backup of the data. |
| Disposal | : | The deletion, destruction or anonymisation of personal data. |
| Deletion | : | The process of rendering personal data inaccessible and unusable by the relevant unit in any way. |
| Destruction | : | The process of rendering personal data inaccessible, irretrievable and unusable by anyone in any way. |
| Anonymisation | : | Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even if matched with other data. |
| Law | : | Personal Data Protection Law No. 6698, published in the Official Gazette dated 7 April 2016, No. 29677. |
| Regulation | : | The Regulation on the Deletion, Destruction or Anonymisation of Personal Data, published in the Official Gazette dated 28 October 2017, No. 30224. |
| Board | : | The Personal Data Protection Board. |
| Recording Medium | : | Any medium containing personal data processed by fully or partly automated means, or by non-automated means forming part of a data filing system. |
| Personal Data Processing and Protection Policy | : | The policy establishing the procedures and principles for managing personal data held by KAR TUR. |
| Data Filing System | : | A filing system in which personal data is processed according to specific criteria. |
PART 2: ENVIRONMENTS AND SECURITY MEASURES
2.1. ENVIRONMENTS IN WHICH PERSONAL DATA IS RETAINED
Personal data held by KAR TUR is retained in a recording medium appropriate to the nature of the data and our legal obligations.
The recording media generally used for retaining personal data are listed below. Some data may be held in other media because of its special nature or our legal obligations. In all cases, KAR TUR acts as data controller and processes and protects personal data in accordance with the Law, the Personal Data Processing and Protection Policy and this Personal Data Retention and Disposal Policy.
| a) Printed media | : | Media in which data is retained by printing it on paper or microfilm. |
|---|---|---|
| b) Local digital media | : | Digital media within KAR TUR, such as servers, fixed or portable drives and optical discs. |
| c) Cloud environments | : | Environments using internet-based systems encrypted through cryptographic methods, which are used by KAR TUR but are not located within its organisation. |
2.2. ENSURING THE SECURITY OF ENVIRONMENTS
KAR TUR takes all necessary technical and administrative measures appropriate to the nature of the personal data and the environment in which it is held, to ensure secure retention and prevent unlawful processing and access.
These measures include, but are not limited to, the following administrative and technical measures, to the extent appropriate to the data and its storage environment.
2.2.1. Technical Measures
KAR TUR takes the following technical measures for all environments in which personal data is retained, as appropriate to the nature of the data and its storage environment:
- Only current, secure systems consistent with technological developments are used in environments holding personal data.
- Security systems are used for environments holding personal data.
- Security tests and research are conducted to identify vulnerabilities in information systems, and existing or potential risks identified through those activities are remedied.
- Access to environments holding personal data is restricted to authorised persons and limited to the purpose of retention; all access is recorded.
- KAR TUR employs sufficient technical personnel to secure the environments in which personal data is held.
2.2.2. Administrative Measures
KAR TUR takes the following administrative measures for all environments in which personal data is retained, as appropriate to the nature of the data and its storage environment:
- Activities are carried out to raise awareness and understanding of information security, personal data and privacy among all KAR TUR employees with access to personal data.
- Legal and technical consultancy services are obtained to monitor developments in information security, privacy and personal data protection and take the necessary action.
- Where personal data is transferred to third parties for technical or legal requirements, agreements are signed with those parties to protect personal data, and all due care is taken to ensure their compliance with those agreements.
2.2.3. Internal Audit
Under Article 12 of the Law, KAR TUR conducts internal audits concerning implementation of the Law, this Personal Data Retention and Disposal Policy and the Personal Data Processing and Protection Policy.
Any deficiencies or shortcomings in implementation identified by internal audits are remedied immediately.
If an audit or other means reveals that personal data for which KAR TUR is responsible has been obtained unlawfully by others, KAR TUR notifies the data subject and the Board as soon as possible.
PART 3: DISPOSAL OF PERSONAL DATA
3.1. REASONS FOR RETENTION AND DISPOSAL
3.1.1. Reasons for Retention
Personal data held by KAR TUR is retained for the purposes and reasons specified in the Law and our Personal Data Processing and Protection Policy (the relevant policy is available at the KAR TUR address).
3.1.2. Reasons for Disposal
Personal data held by KAR TUR is deleted, destroyed or anonymised under this Policy at the data subject's request or, on KAR TUR's own initiative, where the data subject has not given explicit consent and the grounds listed in Article 5(2) and Article 6(3) of the Law cease to exist.
The grounds listed in Article 5(2) and Article 6(3) of the Law are as follows:
- Processing is expressly provided for by law.
- Processing is necessary to protect the life or physical integrity of a person who is unable to express consent due to practical impossibility or whose consent is not legally valid, or that of another person.
- Processing the personal data of the parties to a contract is necessary and directly related to establishing or performing that contract.
- Processing is necessary for the data controller to fulfil a legal obligation.
- The data has been made public by the data subject.
- Processing is necessary to establish, exercise or protect a right.
- Processing is necessary for the legitimate interests of the data controller, provided that the data subject's fundamental rights and freedoms are not harmed.
3.2. DISPOSAL METHODS
When the reasons requiring processing cease to exist, KAR TUR deletes, destroys or anonymises personal data retained in accordance with the Law, other legislation and the Personal Data Processing and Protection Policy, at the data subject's request or on its own initiative during periodic disposal within the periods specified in this Policy. Where disposal is performed at the data subject's request, the reasons for choosing the appropriate method are explained.
The deletion, destruction and anonymisation techniques most commonly used by KAR TUR are listed below:
3.2.1.1. Deletion Methods
| Deletion Methods for Personal Data Held in Printed Media | Deletion Methods for Personal Data Held in Printed Media | Deletion Methods for Personal Data Held in Printed Media |
|---|---|---|
| Redaction | : | Personal data in printed media is deleted by redaction. Where possible, the personal data is cut out of the document; otherwise, permanent ink is used to make it invisible in a manner that is irreversible and cannot be read using technological solutions. |
| Deletion Methods for Personal Data Held in Cloud and Local Digital Environments | Deletion Methods for Personal Data Held in Cloud and Local Digital Environments | Deletion Methods for Personal Data Held in Cloud and Local Digital Environments |
| Secure deletion using software | : | Personal data held in cloud or local digital environments is deleted by a digital command so that it cannot be recovered. Data deleted in this way cannot be accessed again. |
3.2.1.2. Destruction Methods
| Destruction Methods for Personal Data Held in Printed Media | Destruction Methods for Personal Data Held in Printed Media | Destruction Methods for Personal Data Held in Printed Media |
|---|---|---|
| Physical destruction | : | Documents held in printed media are destroyed using document shredders so that they cannot be reassembled. |
| Destruction Methods for Personal Data Held in Local Digital Environments | Destruction Methods for Personal Data Held in Local Digital Environments | Destruction Methods for Personal Data Held in Local Digital Environments |
| Physical destruction | : | Optical and magnetic media containing personal data are physically destroyed by methods such as melting, burning or pulverising. Data is rendered inaccessible by melting, burning, pulverising or passing the media through a metal shredder. |
| Demagnetisation (degaussing) | : | Exposing magnetic media to a strong magnetic field to corrupt the data on it so that it becomes unreadable. |
| Overwriting | : | Random data consisting of zeros and ones is written over magnetic media and rewritable optical media at least seven times to prevent the old data from being read or recovered. |
| Destruction Methods for Personal Data Held in Cloud Environments | Destruction Methods for Personal Data Held in Cloud Environments | Destruction Methods for Personal Data Held in Cloud Environments |
| Secure deletion using software | : | Personal data held in the cloud is deleted by a digital command so that it cannot be recovered. When the cloud service relationship ends, all copies of the encryption keys needed to make the personal data usable are destroyed. Data deleted in this way cannot be accessed again. |
3.2.1.3. Anonymisation Methods
Anonymisation means rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
| Removing variables | : | Removing one or more direct identifiers within personal data that could identify the data subject in any way. This method may be used to anonymise personal data or to delete information within personal data that is not relevant to the processing purpose. |
|---|---|---|
| Local suppression | : | Deleting information that could distinguish exceptional records within a data table containing aggregated, anonymised personal data. |
| Generalisation | : | Combining personal data belonging to many people and removing distinguishing information to produce statistical data. |
| Top and bottom coding / Global coding | : | Defining ranges for a variable and assigning it to categories. If the variable does not contain a numerical value, similar data within it is categorised. Values falling within the same category are combined. |
| Microaggregation | : | All records in a dataset are first placed in a meaningful order and the dataset is then divided into a specified number of subsets. The mean value of the selected variable is calculated for each subset and replaces that variable's value in the subset. This alters indirect identifiers within the data, making it more difficult to link the data to the data subject. |
| Data swapping and perturbation | : | Direct or indirect identifiers within personal data are swapped with other values or altered to break their link to the data subject and remove their identifying characteristics. |
KAR TUR uses one or more of these anonymisation methods depending on the nature of the data. When applying these methods, KAR TUR may use the statistical methods K-Anonymity, L-Diversity and T-Closeness.
KAR TUR selects the most appropriate, suitable and proportionate disposal method after assessing the data subject's request, the Company's interests and the nature of the data concerned.
3.3. RETENTION AND DISPOSAL PERIODS
3.3.1. Retention Periods
| DATA SUBJECT | DATA CATEGORY | MAXIMUM RETENTION PERIOD |
|---|---|---|
| Employee | Personnel records | Retained throughout the employment contract and for 10 (ten) years from the beginning of the calendar year following its termination. |
| Employee | Data in the Workplace Personal Health File | Retained throughout the employment contract and for 15 (fifteen) years from its termination. |
| Business Partner / Solution Partner / Consultant | Identity, contact and financial information, audio recordings of telephone calls, and employee data relating to the conduct of the commercial relationship between the Business Partner / Solution Partner / Consultant and the Company. | Retained throughout the business/commercial relationship with the Company and for 10 years after it ends, under Article 146 of the Turkish Code of Obligations and Article 82 of the Turkish Commercial Code. |
| Visitor | The visitor's first and last name, Turkish identity number and vehicle registration plate collected on entry to the Company's physical premises, camera recordings and audio recordings of telephone calls. | Retained for 2 years. |
| Website Visitor | The website visitor's first and last name, email address and browsing activity information. | Retained for 2 years. |
| Job Applicant | Information in the job applicant's CV and job application form. | Retained until the CV becomes outdated, up to a maximum of 2 years. |
| Intern (student) | Information in the intern's internship file. | Retained throughout the internship and for 10 (ten) years from the beginning of the calendar year following its end. |
| Customer | The customer's first and last name, Turkish identity number, address, contact details, payment information and methods, browsing activity information, audio recordings of telephone calls, product/service preferences and transaction history. | Retained for 10 years from provision of each product/service purchased by the customer, under Article 146 of the Turkish Code of Obligations and Article 82 of the Turkish Commercial Code. |
| Customer | Camera footage | Retained for 2 years. |
| Prospective Customer | Identity, contact and financial information and audio recordings of telephone calls obtained during contract negotiations to establish a commercial relationship between the Prospective Customer and the Company. | Retained for 2 years. |
| Institutions/Companies Cooperating with the Company (Supplier, Contract Manufacturer, Dealer/Franchise) | Identity, contact and financial information, audio recordings of telephone calls and employee data relating to the conduct of the commercial relationship between the cooperating institution/company and the Company. | Retained throughout the cooperating institution/company's business/commercial relationship with the Company and for 10 years after it ends, under Article 146 of the Turkish Code of Obligations and Article 82 of the Turkish Commercial Code. |
* If legislation stipulates a longer period, including a longer limitation, forfeiture or retention period, the statutory period is treated as the maximum retention period.
3.3.2. Disposal Periods
KAR TUR deletes, destroys or anonymises personal data for which it is responsible at the first periodic disposal following the date on which the obligation to dispose of it arises under the Law, relevant legislation, the Personal Data Processing and Protection Policy and this Personal Data Retention and Disposal Policy.
Where a data subject applies to KAR TUR under Article 13 of the Law to request deletion or destruction of their personal data:
- If all conditions for processing have ceased to exist, KAR TUR deletes, destroys or anonymises the data concerned using an appropriate disposal method within 30 (thirty) days of receipt, explaining its reasons. For the request to be deemed received, it must have been made in accordance with the Personal Data Processing and Protection Policy. In all cases, KAR TUR informs the data subject of the action taken.
- If not all conditions for processing have ceased to exist, KAR TUR may reject the request with reasons under Article 13(3) of the Law and communicates the rejection within thirty days through the communication method requested by the data subject.
3.4. PERIODIC DISPOSAL
When all statutory conditions for processing personal data cease to exist, KAR TUR deletes, destroys or anonymises the data on its own initiative at the recurring intervals specified in this Personal Data Retention and Disposal Policy.
Periodic disposal begins on …./…../…….. and is repeated every 6 (six) months.
3.5. AUDITING THE LAWFULNESS OF DISPOSAL
KAR TUR conducts disposal, whether at a data subject's request or on its own initiative during periodic disposal, in accordance with the Law, other legislation, the Personal Data Processing and Protection Policy and this Personal Data Retention and Disposal Policy.
KAR TUR takes administrative and technical measures to ensure that disposal complies with these provisions.
3.5.1. Technical Measures
- KAR TUR maintains technical tools and equipment appropriate to each disposal method in this Policy.
- KAR TUR ensures the security of the location where disposal is carried out.
- KAR TUR keeps access records of the persons performing disposal.
- KAR TUR employs qualified, experienced personnel to perform disposal or obtains services from qualified third parties where necessary.
3.5.2. Administrative Measures
- KAR TUR carries out activities to raise awareness and understanding of information security, personal data and privacy among employees performing disposal.
- KAR TUR obtains legal and technical consultancy services to monitor developments in information security, privacy, personal data protection and secure disposal techniques and to take the necessary action.
- Where third parties perform disposal for technical or legal reasons, KAR TUR signs agreements with them to protect personal data and takes all due care to ensure their compliance with those agreements.
- KAR TUR regularly audits whether disposal complies with the law and the conditions and obligations in this Personal Data Retention and Disposal Policy and takes the necessary action.
- KAR TUR records all operations relating to the deletion, destruction and anonymisation of personal data and retains these records for at least three years, without prejudice to other legal obligations.
PART 4: PERSONAL DATA COMMITTEE
KAR TUR establishes a Personal Data Committee. The Committee is authorised and responsible for carrying out or arranging the procedures necessary to retain and process data subjects' data in accordance with the law, the Personal Data Processing and Protection Policy and the Personal Data Retention and Disposal Policy, and for overseeing these processes.
The Personal Data Committee consists of two people: an Information Technology Officer and a Human Resources Officer. Those selected for the Committee serve as one manager and two specialists. The duties of the Committee's manager and specialists are set out below:
| Title | Job Description | |
|---|---|---|
| Personal Data Committee Manager | : | Responsible for directing all planning, analysis, research and risk identification in projects carried out for compliance with the Law; managing processes required by the Law, the Personal Data Processing and Protection Policy and the Personal Data Retention and Disposal Policy; and deciding on requests from data subjects. |
| Personal Data Protection Specialist (Technical and Administrative) | : | Responsible for examining data subject requests and reporting them to the Personal Data Committee Manager for assessment; implementing the Manager's decisions on assessed requests; auditing retention and disposal processes and reporting those audits to the Manager; and carrying out retention and disposal processes. |
PART 5: UPDATES AND COMPLIANCE
KAR TUR may amend the Personal Data Processing and Protection Policy or this Personal Data Retention and Disposal Policy in response to changes in the Law, decisions of the Authority or developments in the sector or information technology.
Amendments to this Personal Data Retention and Disposal Policy are incorporated into the text immediately, with explanations of the changes at the end of the Policy.
5.1. AMENDMENT NOTES
| …../……/…… | : | The Personal Data Retention and Disposal Policy has been published. |
*There are no earlier amendments.*
Cookie Policy
COOKIE PRIVACY NOTICE
The marisstonehotels.com domain is used by KAR TUR İNŞAAT REKLAM TURİZM VE TAŞIMACILIK LİMİTED ŞİRKETİ. KAR TUR permits the use of cookies, pixels, GIFs and similar technologies (“cookies”) to improve your experience when you visit our website. Cookies are used in accordance with the Turkish Personal Data Protection Law No. 6698 (the “Data Protection Law”) and other applicable legislation.
This notice informs you about the processing of personal data obtained through the use of cookies when you use our website and accept the cookie conditions. It explains the types of cookies we use, their purposes and how you can control them.
ABOUT COOKIES
KAR TUR processes certain personal data in connection with the services provided on the website. This may include your full name, tax number, telephone number, address, email address, fax number, IP address, social media accounts, location information, information about purchases of products or services, pages viewed on our website, and data identifying your mobile device if you visit using a mobile device. We may also access and process any other information you expressly choose and agree in writing to provide, or that we obtain from third parties with your explicit approval.
KAR TUR may obtain some of this personal data through a technical communication file known as a cookie. Cookies are small text files sent by a website to a user’s browser to be stored in main memory. They make internet use easier by storing website status information and preferences. Cookies help obtain statistics on the number of users, the purposes and frequency of visits, and the time spent on a website. They also help dynamically generate advertising and content on pages tailored to users. A cookie is not designed to retrieve data from your main memory or email, or to retrieve other personal data. Most browsers are initially configured to accept cookies, but users can change their settings to reject cookies or receive a warning when a cookie is sent.
Your personal data is collected electronically through cookies during your visit to our website on the legal basis of our Company’s legitimate interests. The collected data may also be processed for the purposes specified in this notice within the processing conditions and purposes set out in Articles 5 and 6 of the Law.
RECIPIENTS AND PURPOSES OF PERSONAL DATA TRANSFERS
Under Articles 5 and 8 of the Turkish Personal Data Protection Law No. 6698 and/or where exceptions under applicable legislation exist, your personal data may be processed for the purposes above with your consent where consent is required, and otherwise without obtaining your consent. KAR TUR may share personal data covered by this notice with its suppliers, legally authorised public institutions and private persons, limited to achieving the purposes above and in accordance with legislation. Please note that recipients may store your personal data on servers anywhere in the world.
Which Cookies Are Used and for What Purposes?
General Information
KAR TUR uses cookies on https://www.marisstone.com/ for various purposes and processes your personal data through them. The main purposes are:
- Performing the essential functions needed for the website to operate. For example, allowing signed-in members to visit different pages without entering their password again.
- Analysing the website and improving its performance. For example, integrating the different servers on which it operates, identifying visitor numbers and adjusting performance accordingly, or helping visitors find what they need.
- Improving functionality and ease of use. For example, sharing content with third-party social media platforms through the website, or remembering a visitor’s username or search queries on a later visit.
- Carrying out personalisation, targeting and advertising activities. For example, showing advertising relevant to visitors’ interests based on the pages and products they have viewed.
- Measuring and improving advertising campaign effectiveness. For example, determining whether you clicked an advertisement and subsequently used a service on the website to which it directed you; showing advertisements relevant to your interests and limiting how many advertisements are displayed.
COOKIES USED ON OUR WEBSITE
The different types of cookies used on our website are described below. We use both first-party cookies, placed by the website you visit, and third-party cookies, placed by servers other than the website you visit.
The types of cookies used on the website are shown in the following table:
| Strictly necessary cookies | Anonymous cookies allow visitors to navigate https://......................... and use its features to access secure areas. Information collected by these cookies cannot be used for marketing. If these cookies are not permitted, various parts of https://......................... cannot be used. For example, authentication cookies activated when you sign in allow your session to continue as you move between pages. |
|---|---|
| Performance cookies | Anonymous cookies help improve the website. They collect information on how visitors use https://........................... to identify the most visited pages, whether the website works correctly, and any errors. WebAnalytics cookies are an example. Information collected through these cookies cannot be used for marketing or disclosed to third parties. |
| Functional cookies | Anonymous cookies allow KAR TUR to remember visitor characteristics and preferences. Based on this information, https://............................ can display tailored content and remember language choices or the font size selected when reading text. If these cookies are not permitted:
|
| Targeting or advertising cookies | These cookies are generally placed by the advertising networks of https://...................................... with KAR TUR’s knowledge. Their purposes include:
|
HOW CAN I CONTROL AND/OR STOP THE USE OF COOKIES?
You can block cookies using the links below, as appropriate for your browser or service:
- Adobe Analytics
- AOL
- Google AdWords
- Google Analytics
- Google Chrome
- Internet Explorer
- Mozilla Firefox
- Opera
- Safari
UPDATES AND CHANGES
KAR TUR may change this Privacy Policy at any time to keep its privacy and data protection principles up to date and consistent with applicable legislation. The amended Privacy Policy will be published on the website of https://................................... . You can always access the current version at https://..................................... . Continued use of KAR TUR’s services and/or applications after changes to this Privacy Policy will be considered acceptance of those changes. Amended provisions take effect on the date of publication on the website.
WHAT ARE YOUR RIGHTS AS A DATA SUBJECT?
Under Article 11 of the Turkish Personal Data Protection Law No. 6698, data subjects have the right to:
- Learn whether personal data is being processed.
- Request information if their personal data has been processed.
- Learn the purpose of processing and whether the data is used in accordance with that purpose.
- Learn the third parties to whom personal data is transferred in Türkiye or abroad.
- Request rectification of incomplete or inaccurate personal data and notification of that rectification to recipients.
- Request deletion or destruction when the reasons for processing no longer exist, even if the data was processed in compliance with Law No. 6698 and other applicable laws, and request notification of that action to recipients.
- Object to an outcome against them arising exclusively from analysis through automated systems.
- Claim compensation for damage caused by unlawful processing.
If you submit requests concerning these rights to us, your application will be assessed and resolved as soon as possible and within 30 days at the latest. Requests are generally handled free of charge, but KAR TUR reserves the right to charge a fee according to the tariff determined by the Personal Data Protection Board.
The data subject undertakes that the information covered by this Cookie Policy is complete, accurate and up to date, and that any changes will be updated promptly. KAR TUR will not be responsible if the data subject fails to provide current information.
The data subject acknowledges that a request resulting in KAR TUR being unable to use any of their personal data may prevent full use of the website’s functions and declares that they assume responsibility for any resulting consequences.
KAR TUR may discontinue cookies, change their types or functions, or add new cookies. We therefore reserve the right to amend this notice at any time. Changes take effect when published on the website or through any publicly accessible medium. The date of the latest update can be found at the beginning of the notice.
For more information on KAR TUR’s processing of your personal data, we recommend reading the KAR TUR Personal Data Protection and Processing Policy at ……………… .
Contact Details
Address:
Telephone:
Fax:
Website Contact Form Privacy Notice
The content of this section is being prepared.
It will be published here once the final text has been prepared by the legal adviser.
CCTV Privacy Notice
The content of this section is being prepared.
It will be published here once the final text has been prepared by the legal adviser.
Data Subject Request Form
This form has been prepared to enable data subjects to submit requests to the data controller under Articles 11 and 13 of the Turkish Personal Data Protection Law No. 6698 and the Communiqué on the Procedures and Principles for Applications to the Data Controller.
DATA SUBJECT REQUEST FORM
1. DATA CONTROLLER DETAILS
| Data Controller | Kartur İnşaat, Reklam, Turizm ve Taşımacılık Ltd. Şti. (Marisstone Hotels) |
|---|---|
| MERSİS No. | 0499029508500012 |
| Address | Gökçetepe Köyü, Zeytindere Mevkii Küme Evler 201, 22880 Keşan / Edirne |
| Privacy Email | kvkk@marisstone.com |
| Registered Electronic Mail (KEP) | karturinsaat@hs05.kep.tr |
| Telephone | +90 284 767 72 22 |
2. APPLICANT DETAILS
| Full Name | |
|---|---|
| Turkish Identity Number | |
| For Foreign Nationals: Nationality / Passport Number / Identity Number, if any | |
| Residential or Business Address for Correspondence | |
| Email Address | |
| Telephone | |
| Fax, if any | |
| Your Relationship with Marisstone Hotels, if any | □ Customer / Guest □ Visitor □ Supplier / Business Partner □ Other: ............................ |
3. YOUR REQUEST UNDER THE DATA PROTECTION LAW
Please tick the right or rights relevant to your request.
| Select | Request |
|---|---|
| □ | I wish to learn whether my personal data is being processed. |
| □ | If my personal data has been processed, I request information about that processing. |
| □ | I wish to learn the purpose of processing and whether my personal data is used in accordance with that purpose. |
| □ | I wish to learn the third parties to whom my personal data has been transferred in Türkiye or abroad. |
| □ | I request rectification if my personal data has been processed incompletely or inaccurately. |
| □ | I request deletion or destruction of my personal data under the conditions specified in Article 7 of the Law. |
| □ | I request that recipients of my personal data be notified of its rectification, deletion or destruction. |
| □ | I object to an outcome against me arising exclusively from analysis of my personal data through automated systems. |
| □ | I claim compensation for any damage I have suffered due to unlawful processing of my personal data. |
4. DETAILS OF YOUR REQUEST
Please explain your request and describe any relevant information and documents.
................................................................................................................................................
................................................................................................................................................
................................................................................................................................................
5. ENCLOSED DOCUMENTS
................................................................................................................................................
................................................................................................................................................
6. HOW YOU WOULD LIKE TO RECEIVE OUR RESPONSE
□ In writing at my correspondence address □ Electronically at my email address
7. APPLICATION METHODS
You may submit your request in writing to the data controller’s address; via registered electronic mail (KEP), secure electronic signature, mobile signature, or an email address you have previously notified to the data controller and that is registered in its systems; or through software or an application developed for this purpose.
- Postal or in-person applications: Gökçetepe Köyü, Zeytindere Mevkii Küme Evler 201, 22880 Keşan / Edirne
- KEP: karturinsaat@hs05.kep.tr
- Previously registered email: Send your request to kvkk@marisstone.com from the email address already registered in the Company’s systems.
If a representative submits the request, a copy of the power of attorney must be enclosed. Relevant information and supporting documents should also be attached.
8. APPLICANT’S DECLARATION
I declare that the information above is accurate and up to date, acknowledge that identity verification necessary to assess my application may be carried out, and request that the response be sent by the method I have selected.
| Date | .... / .... / ........ | Signature | |
|---|---|---|---|
| Full Name | |||
Customer WhatsApp Privacy Notice
The content of this section is being prepared.
It will be published here once the final text has been prepared by the legal adviser.
Social Media Communications Privacy Notice
The content of this section is being prepared.
It will be published here once the final text has been prepared by the legal adviser.


