Reservation Information Text
PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA FOR RESERVATIONS AND ACCOMMODATION
At NG PHASELIS TURİZM A.Ş. ("the Company", "we"), we act as the "Data Controller" under the Turkish Personal Data Protection Law No. 6698 ("the Law"). This notice explains how we process your personal data when you make a reservation request and stay at our facility.
1. DATA CONTROLLER
| Trade Name | NG PHASELIS TURİZM A.Ş. |
| Brand / Facility | NG Phaselis Bay |
| Address | Göynük Mah. 3160. Sok. No: 31 Kemer / ANTALYA, Türkiye |
| Trade Registry No. | 145138 |
| MERSIS No. | 0631211031400002 |
| Tax Office / No. | Çinili Tax Office — 631 211 03 14 |
| KEP Address (Registered Electronic Mail) | [email protected] |
| Phone | +90 242 824 07 07 |
| [email protected] | |
| Website | www.ngphaselisbay.com |
2. PERSONAL DATA WE PROCESS
|
Personal Data Categories |
Data Types |
|
Identity |
Full name, nationality, place and date of birth, gender, Turkish ID number, passport or ID card number and issue details, signature; the full names of the guests with you and how they are related to you, vehicle plate number |
|
Contact |
Address, mobile phone number, email address |
|
Finance |
Payment information, invoice information, collection and balance records |
|
Customer transaction |
Reservation records, check-in and check-out dates, room and package details, stay history, à la carte and spa reservations, extra spending, loyalty program membership |
|
Physical premises security |
Security camera images, room key card access records, vehicle plate and parking records |
|
Transaction security |
Wi-Fi and internet access log records, IP address |
|
Special category (health) |
If you tell us: food allergies, dietary limits, disability and accessibility needs; first aid records from the facility's medical room |
|
Request / complaint |
Satisfaction surveys, feedback, complaints |
|
Other |
Travel and transport details (transfer, flight, CIP terminal), details of the group or tour you are part of |
3. PURPOSES AND LEGAL REASONS FOR PROCESSING
|
Personal Data Categories |
Purpose |
Legal Reason |
|
Identity, Contact, Customer transaction |
Creating the reservation, making and carrying out the accommodation contract, room allocation, check-in and check-out |
Processing the personal data of the parties to a contract is necessary, as long as it is directly related to making or carrying out that contract |
|
Identity, Contact, Customer transaction, Transaction security, vehicle plate |
Reporting guests' identity details to the general law enforcement forces (Law No. 1774 on Notification of Identity) |
The law clearly says so, and it is necessary for the data controller to meet a legal duty |
|
Identity, Contact, Finance |
Issuing invoices, accounting, tax and accommodation tax duties |
It is necessary for the data controller to meet a legal duty |
|
Identity, Contact |
Accommodation statistics reports to the Ministry of Culture and Tourism |
The law clearly says so, and it is necessary for the data controller to meet a legal duty |
|
Transaction security |
Keeping Wi-Fi access traffic records (Law No. 5651) |
The law clearly says so, and it is necessary for the data controller to meet a legal duty |
|
Identity, Contact, Finance |
Carrying out payment, collection and refund processes |
Processing the personal data of the parties to a contract is necessary, as long as it is directly related to making or carrying out that contract; and it is necessary for the data controller to meet a legal duty |
|
Physical premises security |
Keeping the facility, guests and employees safe, and monitoring with security cameras |
Processing is necessary for the legitimate interests of the data controller, as long as it does not harm the fundamental rights and freedoms of the data subject; and it is necessary for the data controller to meet a legal duty |
|
Special category (health) |
Meeting the food allergy, dietary and accessibility needs that you tell us about |
Your explicit consent, if you give it; and when a person cannot give consent because of a real impossibility, or their consent is not legally valid, and processing is necessary to protect the life or physical safety of that person or someone else |
|
Request / complaint |
Receiving and settling requests, suggestions and complaints |
Processing the personal data of the parties to a contract is necessary, as long as it is directly related to making or carrying out that contract; and processing is necessary for the legitimate interests of the data controller, as long as it does not harm the fundamental rights and freedoms of the data subject |
|
Request / complaint |
Measuring guest satisfaction and improving service quality |
Processing is necessary for the legitimate interests of the data controller, as long as it does not harm the fundamental rights and freedoms of the data subject |
|
Request / complaint, Transaction security |
Sending commercial electronic messages and campaign announcements |
Your explicit consent, if you give it |
|
Customer transaction |
Managing loyalty program membership |
Your explicit consent, if you give it |
|
Physical premises security |
Recording behavior that breaks the facility rules, and carrying out legal processes |
Processing is necessary to establish, use or protect a legal right; and processing is necessary for the legitimate interests of the data controller, as long as it does not harm the fundamental rights and freedoms of the data subject |
Showing your ID or passport when you enter the facility is required by Law No. 1774. We process this data without relying on explicit consent.
We carry out processing that is based on explicit consent only if you give your consent. You can withdraw your consent at any time.
4. CHILDREN'S DATA
Our facility has a kids' club and activities for children. We process your child's data (full name, age, allergy and health information, activity record, parent contact details) only with the consent of a parent or legal guardian, and only as much as we need to offer the activity safely.
5. HOW WE COLLECT YOUR DATA
We collect your data by automatic and partly automatic means. The sources are: reservation and online check-in forms, documents you fill in when you arrive, our call center, email and website, travel agencies and online booking platforms, security cameras, our Wi-Fi network and our hotel management system (PMS).
6. SHARING YOUR DATA
We may share your data with the groups of recipients below. We do this under the conditions in Articles 8 and 9 of the Law, and only as much as the service needs.
- Recipient: Public bodies and organizations that are authorized by law — General Directorate of Security and Gendarmerie (identity notification), Ministry of Culture and Tourism, Revenue Administration, Information and Communication Technologies Authority (BTK), courts and enforcement offices. If an authorized body asks for your personal data, we share it with the authorized public bodies, consumer arbitration committees, courts, public prosecutors, law enforcement, the relevant ministries and other judicial or administrative authorities. We do this to meet our legal reporting, declaration and audit duties, to handle official and court correspondence, to manage legal disputes, and to use our legal rights, such as the right to bring a case, reply and defend ourselves. Our legal reasons: it is necessary for us, as the data controller, to meet our legal duties, and it is necessary to establish, use or protect a legal right.
- Recipient: Travel agencies, tour operators and online booking platforms — only if they are the source of your reservation, and only to carry out that reservation. We share data so that services can be provided, such as accommodation, transfer, ticketing, invoicing, surveys, marketing messages and loyalty program management, and so that we can use independent audit services. Our legal reason: processing the personal data of the parties to a contract is necessary, as long as it is directly related to making or carrying out that contract.
- Recipient: Suppliers and data processors — hotel management system (PMS), reservation infrastructure, call center, cloud and hosting, e-invoice integrator, payment institutions and banks, transfer and security service providers. We share data so that services can be provided, such as accommodation, transfer, ticketing, invoicing, surveys, marketing messages and loyalty program management, and so that we can use independent audit services. Our legal reasons: processing is necessary to establish, use or protect a legal right, and processing is necessary for our legitimate interests, as long as it does not harm the fundamental rights and freedoms of the data subject.
- Recipient: Legal and financial advisers and independent auditors — we share data only as much as the process needs, to meet legal duties. Our legal reasons: the law clearly says so, and it is necessary for us, as the data controller, to meet our legal duties.
Transfer abroad. We work with agencies, global booking platforms and cloud service providers based outside Türkiye. To carry out the Company's business activities, we may transfer your data, to a limited extent, to our suppliers abroad. We do this under the conditions in Article 9 of the Law, to get support in areas such as servers, maintenance, technical support, storage, archiving, hosting and IT services. Our legal reason: processing is necessary for our legitimate interests, as long as it does not harm the fundamental rights and freedoms of the data subject.
7. RELATED NOTICES
8. YOUR RIGHTS AND HOW TO APPLY
Under Article 11 of the Law, you have the right to:
- find out whether your personal data is processed;
- ask for information if it has been processed;
- find out why it is processed and whether it is used for that purpose;
- know the third parties it is shared with, in Türkiye or abroad;
- ask for correction if it is incomplete or wrong;
- ask for deletion or destruction when the conditions are met;
- ask us to tell the third parties about corrections and deletions;
- object if an analysis made only by automated systems gives a result against you;
- ask for compensation if you suffer a loss because of unlawful processing.
Please fill in the Data Subject Application Form and send your request in one of these ways:
- In writing: Göynük Mah. 3160. Sok. No: 31 Kemer / ANTALYA, Türkiye (in person or through a notary)
- From your KEP address: [email protected]
- With a secure electronic signature or mobile signature: [email protected]
- From the email address registered in our system: [email protected]
We answer your request free of charge, as soon as possible and within thirty days at the latest, depending on the type of request. If our answer contains personal data, we send it after we verify your identity. We send it to your KEP address, to your email address registered in our system, or by registered mail with return receipt.
NG PHASELIS TURİZM A.Ş. (NG Phaselis Bay)
Göynük Mah. 3160. Sok. No: 31 Kemer / ANTALYA, Türkiye · +90 242 824 07 07 · [email protected]