Privacy & Data Protection Policy
ARİA RESORT OTELCİLİK TURİZM SAN. VE TİC. A.Ş.
CUSTOMER INFORMATION NOTICE ON THE PROTECTION AND PROCESSING OF PERSONAL DATA
1. Purpose
Aria Resort Otelcilik Turizm San. Ve Tic A.Ş. (“Company”) aims to process the personal data of its customers who are natural persons in accordance with the Turkish Personal Data Protection Law No. 6698 (“Personal Data Protection Law”) and other applicable legislation.
We inform you that, as the Company’s customer who is a natural person, the personal data you have provided or will provide to the Company and/or which the Company obtains externally by any means will be processed by the Company as the “Data Controller”:
- Within the purposes requiring their processing, in a manner related to, limited to and proportionate to those purposes;
- While maintaining the accuracy and currency of the personal data as provided by you or otherwise communicated to the Company;
- By recording, storing, retaining, reorganising and sharing them with institutions legally authorised to request them, transferring and assigning them to third parties in Türkiye or abroad under the conditions stipulated by the Personal Data Protection Law, classifying them, processing them in other ways specified in that Law and subjecting them to the other operations listed therein.
This Information Notice adopts the continuation and development of the Company’s activities in accordance with the principles laid down in the Personal Data Protection Law.
2. Collection of Personal Data of Customers Who Are Natural Persons and Collection Methods
The Company will process your personal data for the purposes stated in this Information Notice. Your separate permission will be obtained if there is any change to the purposes of processing your personal data.
The personal data of customers collected and used by the Company include, in particular, the following:
| Personal Data Category | Content of Personal Data |
|---|---|
| Identity Data | Documents such as driving licences, passports and copies of identity cards containing information including name and surname, Turkish identification number, tax identification number, nationality, mother’s and father’s names, place and date of birth and gender, together with signature/initial information. |
| Contact Data | Telephone number, fax, full address, country, city and email address, including corporate email addresses. |
| Financial Data | Card number, card type, expiry date, room number, card authorisation slip, payment information, data appearing on invoices and price. |
| Special Categories of Personal Data | Health data; blood group and religion entries on identity cards/driving licences. |
| Other Data | Data such as vehicle information, event information and membership number. |
| Professional Experience | Information such as the data subject’s occupation, professional group, company name and title. |
| Customer Transaction Data | Records of product and service use, instructions and requests necessary for the customer’s use of products and services, contract numbers, vehicle registration number, bank code, account number, number of days of stay, room number and request date. |
| Physical Premises Security Data | Vehicle photographs, photographs of individuals and camera recordings. |
| Transaction Security Data | Personal data processed to ensure technical, administrative, legal and commercial security in our business activities, including information linking a transaction to the relevant person and demonstrating their authority to perform it, such as password information. |
| Personnel Data | Photograph. |
| Marketing Data | Data displayed on the reservation screen during the reservation process. |
Your personal data are collected before, after and throughout the contractual relationship through all information, records and documents submitted to the Company by you, obtained from third parties or obtained from public institutions and bodies for reasons prescribed by law; through physical or electronic channels for reasons prescribed by law; and through cameras installed in Company buildings.
3. Purposes and Legal Grounds for Processing Personal Data
Your personal data may be processed by the Company for, but not limited to, the purposes set out below.
They are processed to fulfil legal obligations and requirements under, among other legislation, the Regulation on the Relations of Tourism Enterprises with the Ministry, Each Other and Customers and the Identity Notification Law.
To fulfil legal obligations under those regulations and laws and other applicable legislation, regulations and communiqués, in particular:
- Receiving customer reservation requests;
- Making reservations for the dates requested by the customer;
- Receiving reservation information;
- Sending reservation confirmations to the customer and retaining them;
- Checking the customer into the hotel and registering them in the system;
- Submitting customer identity notifications;
- Handling accommodation and check-out procedures;
- Making reservations through the mobile application;
- Handling group reservations;
- Making transfer reservations at the customer’s request;
- Making tour reservations at the customer’s request;
- Providing laundry services to the customer.
To enter into and perform a contract, in particular:
- Sending price quotations to the customer;
- Obtaining credit card information for payment;
- Verifying credit card information and authenticating identity for payment;
- Retaining reservation information;
- Informing hotel departments about VIP customers and customer preferences;
- Tracking information about the customer’s visitors;
- Tracking check-out procedures through the mobile application;
- Sending daily analyses to departments;
- Entering into contracts with travel agencies;
- Cross-checking customer names;
- Sending card authorisation information;
- Receiving customers’ special requests;
- Using aliases to protect customer privacy;
- Informing hotel departments of customer incidents and requests;
- Tracking the guest welcome process;
- Tracking newspaper preferences;
- Receiving requests for receptions, meetings, weddings and events;
- Providing price quotations;
- Notifying employees of customer incidents;
- Tracking customer feedback;
- Giving presentations at weekly leaders’ meetings;
- Evaluating customer comments;
- Making restaurant reservations at the customer’s request;
- Creating a customer card;
- Issuing electronic invoices to the customer;
- Checking and filing by the revenue auditor;
- Reconciling records with providers of transfer and sightseeing services and special airport passenger services;
- Making employee bonus payments;
- Tracking car park use;
- Verifying guests attending breakfast;
- Taking reservations for the hotel’s bar, restaurant and spa services;
- Retaining the customer’s bill;
- Tracking housekeeping preferences of arriving guests;
- Collecting information to create the customer’s spa membership and enable its benefits;
- Registering customer memberships;
- Tracking end-of-day closing procedures;
- Tracking lost and found items;
- Preparing incident reports;
- Informing the head office.
To establish, exercise and protect a right, where processing is necessary for the data controller’s legitimate interests, and to implement Company policies, in particular:
- Enrolling customers in a loyalty programme to earn points based on the frequency of their stays;
- Collecting customer preferences;
- Collecting customer information to maximise the benefits of spa therapy;
- Registering the customer’s membership and spa reservations in the system;
- Tracking the removal of damaged items or gifts from guests from the hotel;
- Tracking vehicles entering the car park;
- Monitoring the hotel with cameras.
Your personal data will be retained for the period prescribed by applicable legislation or for a reasonable period until the purpose of processing ceases to apply, and in any event for the statutory limitation periods.
4. Transfer of Personal Data to Third Parties
To fulfil legal obligations and contractual requirements under, among other legislation, the Identity Notification Law, your data may be transferred to the General Directorate of Security, Company hotels in Türkiye and abroad, and the Company’s relevant suppliers and business partners.
4.1. Transfer of Personal Data to Third Parties in Türkiye
To fulfil legal obligations under the Identity Notification Law and applicable legislation, regulations and communiqués, in particular:
- Submitting customer identity notifications.
To enter into and perform a contract, in particular:
- Sending price quotations to customers;
- Sending reservation confirmations to customers;
- Entering into contracts with travel agencies;
- Cross-checking customer names;
- Sending card authorisation information;
- Having the customer sign an event contract;
- Making restaurant reservations at the customer’s request;
- Retaining the customer’s bill.
Where processing is necessary for the data controller’s legitimate interests and to implement Company policies, in particular:
- Enabling customers to earn points and enjoy privileges at Company hotels in Türkiye;
- Providing better service by viewing customer information at Company hotels in Türkiye;
- Making transfer reservations at the customer’s request;
- Making tour reservations at the customer’s request;
- Reconciling records with providers of sightseeing, transfer and special airport passenger services;
- Tracking car park use;
- Tracking the removal of damaged items from the hotel.
4.2. Transfer of Personal Data to Third Parties Abroad
Your personal data may be transferred to group companies abroad for:
- Enabling customers to earn points and enjoy privileges at Company hotels abroad;
- Providing better service by viewing customer information at Company hotels in Türkiye;
- Reporting incidents;
- Transferring information about guests staying at the hotel each day.
5. Ensuring the Security and Confidentiality of Personal Data
In accordance with Article 12 of the Personal Data Protection Law, the Company takes all necessary technical and administrative measures to ensure an appropriate level of security, prevent unlawful processing of and unlawful access to personal data, and safeguard the data it processes.
5.1. Technical Measures to Ensure Lawful Processing and Prevent Unlawful Access to Personal Data
Without limiting applicable obligations, our hotel has taken the following measures:
(1) Informing individuals about the collection and use of their data, including through the global privacy notice;
(2) Using the data only for valid business purposes;
(3) Providing individuals, subject to applicable law, with opportunities to review, correct, update, suppress, restrict or delete their data;
(4) Requiring all service providers with whom data are shared to protect their security and confidentiality;
(5) Taking technical and organisational measures to prevent unauthorised persons within the organisation from unlawfully accessing, obtaining, using, disclosing, losing or altering personal data.
If you have further questions as a data subject or wish to request changes to your personal data, such as deletion or updating, you can email [email protected].
You can access the KVKK application form here: Personal Data Protection Application Form (Turkish)
5.2. Administrative Measures to Ensure Lawful Processing and Prevent Unlawful Access to Personal Data
- Training employees and raising awareness of the Personal Data Protection Law;
- Including provisions in contracts with recipients of personal data requiring those parties to fulfil data security obligations;
- Identifying the requirements for compliance with the Personal Data Protection Law and preparing internal policies for their implementation.
5.3. Measures in the Event of Unlawful Disclosure of Personal Data
If processed personal data are unlawfully obtained by others, the Company will notify the relevant data subject and the Personal Data Protection Board as soon as possible.
6. Deletion, Destruction and Anonymisation of Personal Data
Under Article 7 of the Personal Data Protection Law, although personal data may have been processed in accordance with applicable legislation, the Company will delete, destroy or anonymise them on its own initiative or at the data subject’s request when the reasons requiring their processing no longer exist.
The relevant procedures and principles will be followed in accordance with the Personal Data Protection Law and secondary legislation adopted on the basis of that Law.
6.1. Techniques for Deleting and Destroying Personal Data
Personal data collected in accordance with Company procedures will be securely destroyed/deleted by a specialist.
6.2. Techniques for Anonymising Personal Data
This refers to using encryption to render personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching them with other data.
7. Customer Rights
Under Article 11 of the Personal Data Protection Law, you may apply to the Company with the following requests concerning your personal data:
- To learn whether your personal data are processed;
- To request information if your personal data have been processed;
- To learn the purposes of processing and whether your data are used in accordance with those purposes;
- To learn the third parties to whom your data are transferred in Türkiye or abroad;
- To request correction of incomplete or inaccurate processing and notification of that correction to third parties to whom the data have been transferred;
- To request deletion, destruction or anonymisation when the reasons requiring processing cease to exist, and notification of those actions to third parties to whom the data have been transferred;
- To object to an outcome against you resulting from analysis of your personal data exclusively by automated systems;
- To request compensation for damage resulting from unlawful processing of your personal data.
The Company will handle your requests under the Personal Data Protection Law through the “Data Subject Application Form”. In accordance with Article 13 of that Law, your requests will be resolved free of charge according to their nature and within 30 (thirty) days at the latest. If a request is rejected, the reasons for rejection will be communicated to you in writing or electronically.
The Company may revise this Information Notice when necessary. You will be informed of any such revision.
Policy updated: 22 July 2025