PERSONAL DATA PROTECTION POLICY

PERSONAL DATA PROTECTION POLICY

1
İstanbul Ephesus Hotel
Ephesus Otelcilik ve Turizm Anonim Şirketi
PERSONAL DATA PROTECTION POLICY
&
GUIDE
DEFINITIONS / EXPLANATIONS
Istanbul
2
A. PURPOSE AND SCOPE
The purpose of this policy is to provide explanations regarding the personal data processing activities
lawfully carried out by Ephesus Otelcilik ve Turizm Anonim Şirketi ("Ephesus", "Ephesus Hotel" or briefly
the "COMPANY") in its capacity as data controller within the scope of the Turkish Law No. 6698 on the
Protection of Personal Data (KVKK). The purpose of these explanations is to inform the relevant persons
and thus ensure transparency in the matter of personal data.
Ephesus Hotel has the title of data controller under Law No. 6698, and in order to fulfill the obligations
required by this title, it carries out the necessary compliance work expressed in this Policy in line with the
provisions of the Constitution of the Republic of Turkey, the international agreements to which Turkey is a
party concerning human rights, and the provisions of all legislation on Data Protection Law, primarily Law
No. 6698. For this reason, the activities related to the protection of personal data of our employees,
candidate employees, interns, customers/potential customers, business partners/potential business
partners, suppliers/potential suppliers, intermediaries, third parties with whom we have a contractual
relationship, and all other related persons are managed by our Company in accordance with the principles
in this Policy.
In this context, our Company explains in detail in this Policy and in other KVKK policies prepared by
Ephesus Hotel and shared with the public: the personal data processing activities within the scope of
KVKK, the methods of collection and legal grounds, which groups of persons' personal data are
processed, which categories of personal data are processed regarding these groups of persons, in which
business processes and for which purposes these personal data are used, the technical and
administrative measures taken to ensure the security of personal data, to whom and for what purposes
personal data may be transferred, the retention periods of personal data, the rights of relevant persons
over personal data and how they can exercise these rights, and the sharing of personal data with
authorized institutions and organizations.
The protection of personal data and the observance of the fundamental rights and freedoms of natural
persons whose personal data are collected is the fundamental principle of our policies regarding personal
data processing. For this reason, we carry out all our activities in which personal data are processed by
observing the protection of privacy, confidentiality of communication, freedom of thought and belief, and
the right to use effective legal remedies.
For the protection of personal data, in accordance with the legislation and current technology, we take
all administrative and technical protection measures required by the nature of the relevant data.
Our policies are applied for all processing activities related to personal data within Ephesus Hotel and
have been addressed and prepared considering KVKK, other legislation regarding personal data, and
international standards in this field. Regular control and follow-up procedures regarding the matters within
the scope of the policies will be carried out according to the performance follow-up and monitoring criteria
to be established by the Company. The Company has also prepared the necessary disciplinary directives
and confidentiality agreements in this regard.
In accordance with Article 4, Paragraph 2 of Law No. 6698 on the Protection of Personal Data and
within the scope of the purposes specified in the "Purposes of Processing Personal Data" section of this
Policy, the Company adopts the following principles regarding the processing of personal data:
✓ Being in compliance with the law and the rules of integrity,
✓ Being accurate and up-to-date when necessary,
✓ Being processed for specific, explicit, and legitimate purposes,
3
✓ Being relevant, limited, and proportionate to the purposes for which they are processed,
✓ Being retained for the period stipulated in the relevant legislation or required for the purpose for which
they are processed.
B. DEFINITIONS AND CLASSIFICATIONS IN OUR POLICIES
1. Concept Definitions and Explanations
Concept Explanation
Explicit Consent Consent regarding a specific matter, based on information, and declared
with free will.
Anonymization Making personal data in such a way that they cannot be associated with
an identified or identifiable natural person in any way, even by matching
them with other data.
Employee/Personnel Employees, personnel, or interns.
Electronic Environment Environments in which personal data can be created, read, modified,
and written by electronic devices.
Non-Electronic Environment All written, printed, visual, and other environments outside electronic
environments.
Relevant Person Natural person whose personal data is processed.
Relevant User Persons who process personal data within the data controller
organization or in accordance with the authorization and instructions
received from the data controller, excluding the person or unit
responsible for the technical storage, protection, and backup of the data.
Destruction Deletion, destruction, or anonymization of personal data.
Recording Environment Any environment containing personal data processed by fully or partially
automatic means or by non-automatic means, provided that they are part
of any data recording system.
Registered Electronic Mail (KEP)
Address
A system that protects all kinds of commercial and legal correspondence
and document sharing in the form sent, definitively identifies the
recipient, ensures that the content does not change at all, and makes the
content legally valid, safe, and definitive evidence.
Personal Data Any information relating to an identified or identifiable natural person.
Processing of Personal Data Any operation performed on data such as obtaining, recording, storing,
preserving, modifying, rearranging, disclosing, transferring, taking over,
making available, classifying, or preventing the use of data by fully or
partially automatic means or by non-automatic means provided that they
are part of any data recording system.
Board Turkish Personal Data Protection Board
Authority Republic of Turkey Personal Data Protection Authority
KVKK, Law Turkish Law No. 6698 on the Protection of Personal Data
Customer A natural/legal person who has used/uses/purchases the products and
services offered by the Company, regardless of whether there is a
contractual relationship with Ephesus Hotel.
4
Concept Explanation
Special Category Personal Data Data relating to race, ethnic origin, political opinion, philosophical belief,
religion, sect or other beliefs, dress, association, foundation or union
membership, health, sexual life, criminal conviction and security
measures, as well as biometric and genetic data.
Periodic Destruction The process of deletion, destruction, or anonymization to be carried out
ex officio at recurring intervals specified in the personal data retention
and destruction policy in the event that all conditions for processing
personal data in the Law have ceased.
Policy(ies) Privacy Notice, Personal Data Protection Policy, Personal Data
Retention and Destruction Policy, Cookie Policy
Deletion Making personal data in such a way that they cannot be accessed and
reused in any way for the relevant users.
Company Ephesus Otelcilik ve Turizm Anonim Şirketi
Supplier A natural/legal person who provides/wishes to provide services in
accordance with the orders and instructions of the Company.
Ephesus Hotel Ephesus Otelcilik ve Turizm A.Ş.
Third Party Third party natural persons who are related to these persons in order to
ensure the commercial transaction security between the Company and
the parties mentioned in the Policies, or to protect the rights and provide
benefits of the persons mentioned (e.g., guarantor, companion, etc.).
Data Processor Natural and legal person who processes personal data on behalf of the
data controller based on the authority granted by the data controller.
Data Recording System Recording system, directory in which personal data are processed by
structuring according to certain criteria.
Data Controller Natural or legal person who determines the purposes and means of
processing personal data and is responsible for the establishment and
management of the data recording system: Ephesus Otelcilik ve Turizm
Anonim Şirketi
Destruction Making personal data in such a way that they cannot be accessed,
retrieved, or reused in any way by anyone.
Visitor Natural person who enters the physical premises owned by Ephesus
Hotel for various purposes.
2. Classification of Personal Data
2.1. Personal Data
The protection of personal data is only related to natural persons; information that does not contain
information about a natural person and belongs to legal entities is excluded from the protection of personal
data. Therefore, as a rule, this Policy is not applied to data belonging to legal entities.
2.2. Special Category Personal Data
Data relating to persons' race, ethnic origin, political opinion, philosophical belief, religion, sect or
other beliefs, dress, association, foundation or union memberships, health, sexual life, criminal conviction,
5
and security measures, as well as biometric and genetic data are special category personal data. They are
defined in Article 6 of Law No. 6698.
2.3. Categories of Personal Data
Personal data in the categories indicated below are processed by our Company within the periods
specified in the Ephesus Hotel KVKK Retention and Destruction Policy, limited to one or several of the
personal data processing conditions specified in Article 5 of the Law, based on the legitimate and lawful
personal data processing purposes by informing the relevant persons in accordance with Article 10 of
KVKK No. 6698, in compliance with the general principles specified in the Law, especially the principles
regarding the processing of personal data specified in Article 4, and all obligations regulated by the Law.
Data Category Explanation
Family Members and Relatives
Information
Information about family members and relatives of the personal data subject
in order to protect the legal and other interests of the Company and the data
subject.
Visual and Audio Records Photographs and camera recordings that clearly belong to an identified or
identifiable natural person (except for records within the scope of Physical
Space Security Information).
Finance Personal data processed for information, documents, and records showing
all financial results created according to the type of legal relationship our
Company has established with the personal data subject; processed in
partially or fully automated manner or as part of a data recording system in a
non-automated manner; clearly belonging to an identified or identifiable
natural person; as well as data such as bank account number, IBAN, credit
card information, financial profile, asset data, income information, salary
data.
Physical Space Security
Information
Personal data relating to records and documents taken during entrance to a
physical space, during stay within the physical space (in common use areas
such as corridors); camera recordings and recordings taken in security
areas, etc.; within the data recording system and clearly belonging to an
identified or identifiable natural person.
Legal Transaction Personal data processed within the scope of determining and following our
legal rights and receivables, fulfilling our debts, and complying with our legal
obligations and Company policies (Information in correspondence with
judicial authorities, information in case files, Minutes, Permits, Licenses,
Signature Circulars, Attendance Sheets, Trade Registry Records,
Malfunction repair and Maintenance forms, etc.).
Contact Information Phone number, address, e-mail, social media username, fax number, KEP
address, etc.
Transaction Security
Information
Your personal data processed to ensure our technical, administrative, legal,
and commercial security while carrying out our commercial activities (for
example log records, IP address information, password and code
information, website login/logout information).
Identity Information Data containing information about the person's identity: name-surname, T.R.
ID number, parents' names, place of birth, date of birth, marital status, ID
card serial number and similar information; documents such as driver's
license, ID card, and passport; tax number, etc.; vehicle license plate,
nationality information.
6
Data Category Explanation
Gender Data Data determining the gender of the personal data subject (female, male).
Customer Transaction
Information
Information such as instructions and requests of the customer regarding the
use of our products and services; clearly belonging to an identified or
identifiable natural person and within the data recording system; as well as
information voluntarily conveyed to us by the relevant person as a result of
our commercial activities and the operations carried out by our business
units within this framework.
Criminal Conviction and
Security Measures
Information on criminal conviction, which is one of the special category
personal data, information on security measures, etc.
Health Information Information on disability status, blood group information, personal health
information, information on devices and prostheses used, etc.
Employee Transaction
Information
Data such as shoe size, body size, height, weight, etc., processed to ensure
that the uniforms and shoes of our employees and interns are suitable for
their sizes.
Personnel Information All kinds of personal data processed to obtain information that will be the
basis for the formation of personnel rights of natural persons in a working
relationship with our Company (payroll information, disciplinary investigation,
employment document records, resume information, performance
evaluation reports, military service information, etc.).
Insurance Information Data such as policy and insurance number processed within the scope of
social security or private insurance policy of our employees and interns.
Professional Experience Diploma information, courses attended, in-service training information,
certificates, expertise documents of suppliers, transcript information, etc., of
candidate employees, employees, and interns.
3. Personal Data Subjects ("Relevant Persons")
Personal Data Subject Explanation
Employees/Interns Natural persons who have signed an employment contract with our
Company and interns.
Candidate Employee Natural persons who have applied for a job at our Company by any means
or made their CV and related information available for our Company's review
(including intern candidates).
Person Receiving Product or
Service (Customers)
Natural persons who use or have used the products and services offered by
our Company.
Potential Product or Service
Recipient (Customer
Candidate)
Natural persons who have not yet established a contractual relationship with
our Company or have not yet used the products or services of our Company.
Shareholder/Partner Natural persons who are shareholders of our Company and natural persons
who are members of the company's board of directors.
Supplier Authority Natural persons in institutions with which our Company has any business
relationship, including shareholders and authorities of these institutions.
Supplier Employee Persons working in institutions with which our Company has any business
relationship.
7
Personal Data Subject Explanation
Third Parties Third party natural persons related in order to carry out our Company's
relationships with the parties mentioned above or to protect the rights of the
persons mentioned or our Company and to provide benefits (e.g., guarantor,
family members, and relatives) or other natural persons not within the scope
of this policy.
Visitors Natural persons who have entered the physical premises owned by our
Company for various purposes or visit our websites.
C. PERSONAL DATA PROCESSED BY EPHESUS HOTEL
Personal data processed by Ephesus Hotel are collected as specified in Article 5 of Law No. 6698 on
the Protection of Personal Data, as follows:
• Express provision in the laws (e.g., keeping personnel information records as required by law),
• Necessity of processing personal data of the parties to a contract, provided that it is directly related to
the establishment or performance of a contract (e.g., recording the contact and identity information of
persons making restaurant reservations),
• Being made public by the relevant person himself/herself (e.g., processing by the hotel's social media
accounts in case a guest accommodating at the hotel posts a photograph of the accommodation on
his/her own social media account – tagging and reposting),
• Necessity of data processing for the legitimate interests of the data controller, provided that it does
not harm the fundamental rights and freedoms of the relevant person (e.g., examination of security
camera and IT system records for hotel security or early intervention in extraordinary situations such
as flood, fire),
• Necessity of data processing for the establishment, exercise, or protection of a right (e.g., retention of
necessary information of an employee who has left the job throughout the statute of limitations for
litigation),
Based on these legal reasons, data are collected audibly, electronically, or in writing through
notifications and other communication channels from authorized persons, institutions, and organizations
as well as administrative and judicial authorities.
The categories of personal data that vary and differ depending on the type and nature of the
relationship between the Company and the relevant person, the communication channel used, and the
purpose of processing personal data, and that are processed in compliance with the principles in this
Policy are generally as follows:
- Identifying identity information of persons created by the Company,
- Person-specific data stored for identity verification purposes,
- Visual and audio data,
- Contact information and records,
- Information about natural persons in documents related to legal entities,
- Identifying and qualifying information produced by the Company about candidate employees,
employees, interns, and representatives,
- Health data of employees, candidate employees, interns, and Company representatives,
- Financial data regarding the activities carried out in the Company's transactions,
- Special category data of health and criminal conviction in employee personnel files,
8
- Special category personal data found in customer registration files and voluntarily shared by them
without our request.
These data are defined in detail on VERBIS through the Personal Data Inventory specially prepared
for the Company. Some of these are special category personal data and their processing is based on
stricter procedures.
Special category personal data are processed by us by taking the administrative and technical
measures prescribed by the Personal Data Protection Board, in cases where the explicit consent of the
relevant person exists, or in cases required by legislation. Certain special category personal data we
process about the relevant persons are as follows:
❖ Health information of employees, including medical history information, is processed as required by
our legal obligations, within the scope of the personnel file, and blood group information for the
purpose of providing emergency blood needs of our employees and their relatives.
❖ Health information of our customers (such as whether they have any food allergies, disability status,
etc.) is processed for the purpose of providing personalized service.
❖ Dress, attire, and body measurements information of our employees are processed for the purpose of
providing the clothing they will use while performing their duties suitable for their sizes.
D. PURPOSES OF PROCESSING PERSONAL DATA
1. Our General Data Processing Purposes
Personal data may be processed by the Company within the scope of the purposes exemplified
below, and may be stored for as long as required by these purposes and relevant legal periods;
✓ Carrying out accommodation and other services in our hotel in a complete and high-quality manner,
✓ Maintaining direct sales activities through the restaurants in our hotel in a complete manner,
✓ Maintaining meeting, seminar, wedding, and invitation events in our hotel in a complete manner,
✓ Carrying out business activities within the scope of legal and administrative obligations,
✓ Negotiation, creation, and performance of contracts,
✓ Providing support to the relevant person within the scope of requests and questions,
✓ Carrying out promotion and marketing activities,
✓ Receiving opinions of relevant persons through surveys and votes and ensuring customer
satisfaction,
✓ Carrying out candidate evaluation and recruitment processes,
✓ Conducting Company human resources management,
✓ Planning and execution of corporate sustainability activities,
✓ Conducting commercial activities for the purposes of carrying out business partnerships with the
Company,
✓ Performance of contracts made between the Company and third parties and fulfillment of other legal
obligations,
✓ Identity verification and record creation,
✓ Being able to perform and ensure the continuity of commercial activities,
✓ For the purpose of informing about the service processes received,
✓ Being able to make statistics related to transactions and creating related lists, bringing commercial
statistics and analyses together,
9
✓ Research and development of products, services, and personal choice opportunities,
✓ Performing functions such as software, enterprise resource planning, reporting, marketing,
✓ For the purpose of benefiting from promotions and campaigns,
✓ Due to security applications at the workplace,
✓ Being able to perform necessary quality, confidentiality, and standard audits,
✓ Performance of requirements determined by laws and regulations (tax legislation, legislation for the
protection of consumers, code of obligations legislation, commercial law legislation, and all relevant
legislation),
✓ Performance of obligations related to e-invoice, e-archive, and e-waybill,
✓ Fulfillment of the requests of public institutions and organizations as required or compelled by legal
regulations (information sharing, etc.)
✓ Performance of legal obligations specified in Law No. 6698,
✓ Sending electronic messages for the purpose of providing information about new products,
campaigns, and promotions, provided that prior consent is given,
✓ Performance of legal obligations regarding the employment of personnel,
✓ Opening salary accounts for personnel, providing rental vehicles when necessary, providing phones,
providing phone lines, providing meal cards, performing automatic individual retirement transactions,
✓ Various human resources applications,
✓ Emergency medical interventions,
✓ Follow-up and monitoring of sick leaves or follow-up of the health conditions necessary for the
personnel to perform their duties,
✓ Follow-up of salary garnishments placed on personnel's salary,
✓ Healthy provision and inspection of quality, information security, and confidentiality policies and
standards,
✓ Contacting the persons given by the personnel with their own consent in the presence of
emergencies,
✓ Calculation of personnel expenses,
✓ Determination and control of arrivals and departures,
✓ Preparation of reports and analyses to be made to the Company's senior management,
✓ Conducting performance evaluation and determining wage policies,
✓ Recording camera images due to confidentiality and security applications at the workplace.
These purposes are detailed on VERBIS through the Personal Data Inventory.
2. Our Top-Level Personal Data Processing Purposes
Top-level purposes regarding the processing of personal data according to the categorization
prepared by our Company are shared below:
➢ Planning and execution of our Company's human resources policies and processes,
➢ Performance of the necessary work by our relevant business units for the realization of commercial
activities carried out by our Company and execution of related business processes,
➢ Performance of the necessary work by our business units to enable the relevant persons to benefit
from the products and services offered by our Company and execution of related business processes,
➢ Planning and execution of the Company's commercial and business strategies,
10
➢ Ensuring the legal, technical, and commercial-business security of our Company and the relevant
persons in a business relationship with our Company,
➢ Planning and execution of our Company's commercial and business strategies.
3. Our Specific Data Processing Purposes
➢ Execution of Emergency Management Processes,
➢ Execution of Information Security Processes,
➢ Execution of Employee Candidate / Intern Selection and Placement Processes,
➢ Execution of Candidate Employee Application Processes,
➢ Execution of Employee Satisfaction and Engagement Processes,
➢ Fulfillment of Employment Contract and Legislative Obligations for Employees,
➢ Execution of Fringe Benefits and Benefits Processes for Employees,
➢ Execution of Audit / Ethics Activities,
➢ Ensuring that uniforms are provided in appropriate sizes for employees,
➢ Execution of Training Activities,
➢ Execution of Access Authorizations,
➢ Execution of Activities in Compliance with Legislation,
➢ Execution of Finance and Accounting Affairs,
➢ Execution of Loyalty to Company/Product/Services Processes,
➢ Ensuring Physical Space Security,
➢ Execution of Assignment Processes,
➢ Follow-up and Execution of Legal Affairs,
➢ Execution of Internal Audit/Investigation Activities,
➢ Execution of Communication Activities,
➢ Planning of Human Resources Processes,
➢ Execution / Audit of Business Activities,
➢ Execution of Occupational Health / Safety Activities,
➢ Execution of Business Continuity Activities,
➢ Receiving and Evaluating Recommendations for Improvement of Business Processes,
➢ Execution of Goods/Services Procurement Processes,
➢ Execution of Goods/Services Sales Processes,
➢ Execution of Goods/Services Production and Operation Processes,
➢ Execution of Lost and Found Processes,
➢ Execution of Customer Relationship Management Processes,
➢ Execution of Activities for Customer Satisfaction,
➢ Organization and Event Management,
➢ Execution of Marketing Analysis Activities,
➢ Execution of Performance Evaluation Processes,
➢ Execution of Advertising / Campaign / Promotion Processes,
➢ Execution of Risk Management Processes,
➢ Follow-up of insurance transactions,
11
➢ Execution of Contract Processes,
➢ Follow-up of Requests/Complaints,
➢ Ensuring the Security of Movable Goods and Resources,
➢ Execution of Wage Policy,
➢ Execution of Marketing Processes of Products/Services,
➢ Ensuring the Security of Data Controller Operations,
➢ Foreign Personnel Work and Residence Permit Transactions,
➢ Execution of Talent / Career Development Activities,
➢ Providing Information to Authorized Persons, Institutions, and Organizations,
➢ Execution of Management Activities,
➢ Creation and Follow-up of Visitor Records.
Data Processing Purposes Within the Scope of Our Commercial Activities
Reservations can be made to our company hotels through intermediary agencies and tour companies,
as well as service purchases can be made. Furthermore, although there is currently no online reservation
and sales service through our website, it is entirely at our Company's discretion to put this service into
effect.
Personal data of our customers and potential customers who access the services offered by our
Company through electronic environments are processed in accordance with Law No. 6698 and relevant
legislation. In cases where it is not authorized by law, your explicit consent is sought for your personal data
to be processed. In such cases, your personal data is not processed in any way if you do not give explicit
consent. As Ephesus Hotel, even in cases where the legislation grants us authority, we carry out data
processing activities in compliance with the legislation by fulfilling our duty to inform in accordance with the
law and the rules of integrity.
E. LEGAL OBLIGATIONS
Our legal obligations within the scope of the protection and processing of personal data as the data
controller are listed below:
1. Our Obligation to Inform
As the data controller, when collecting personal data, we have the obligation to inform the relevant
person about the following matters:
➢ For what purpose your personal data will be processed,
➢ Our identity, information about the identity of our representative if any,
➢ To whom and for what purpose the processed personal data may be transferred,
➢ Our method of collecting data and its legal reason and
➢ Your rights arising from KVKK No. 6698.
As Ephesus Hotel, we take care to ensure that this Policy is understandable and easily accessible.
2. Our Obligation to Ensure Data Security
As the data controller, we take the administrative and technical measures stipulated in the legislation
to ensure the security of the personal data in our possession. Obligations regarding data security and
measures taken are detailed in the Ephesus Hotel KVKK Retention and Destruction Policy.
12
F. COLLECTION AND TRANSFER OF PERSONAL DATA
1. Collection of Personal Data
The Company may obtain personal data directly from employees and customers, representatives,
business partners, the call center, the live help channel, branches, and other physical environments, as
well as collect personal data through websites, mobile applications, social media, and other public
channels or organizations and similar events, in order to meet the purposes exemplified in the "Purposes
of Processing Personal Data" section of this Policy, within the framework of the conditions stipulated in
Articles 5 and 6 of KVKK No. 6698.
2. Transfer of Personal Data
The Company performs data transfer to branches, representatives, business partners, and authorized
official institutions/organizations by taking administrative and technical measures, when necessary and in
a proportionate manner, within the framework of the purposes exemplified in the "Purposes of Processing
Personal Data" section of this Policy and in accordance with the provisions of Article 8 of Law No. 6698.
Data transfer is carried out very limitedly domestically, and is not carried out abroad in any way.
However, the matter of data transfer abroad by other data controllers who accept customers on behalf of
Ephesus Hotel within the scope of bilateral contracts made with intermediary persons and companies
operating in tourism agencies and similar areas is not related to our Company.
2.1. Domestic Transfer
As Ephesus Hotel, we act in accordance with the regulations stipulated in KVKK and the decisions
taken by the Personal Data Protection Board regarding the transfer of personal data. Without prejudice to
the reasons for compliance with the law in the legislation, personal data and special category data are not
transferred to third parties without the explicit consent of the Relevant Person. However, in cases where
the explicit consent of the relevant person is not sought, the transfer of personal data to authorized
persons and institutions is in question with the authority granted by Law No. 6698.
2.2. Transfer Abroad
Personal data cannot be transferred abroad without the explicit consent of the relevant person as a
rule. Within the scope of the amendments made by Article 34 of Law No. 7499 dated 2/3/2024 to Law No.
6698, the transfer of personal data abroad has been made possible in certain cases. However, as
Ephesus Hotel, we do not transfer abroad the personal data that reach us directly as the data controller,
independent of the activities of our business partners with whom we have a bilateral business relationship.
2.3. Third Parties to Whom Personal Data Are Transferred
Personal data processed by us can be transferred domestically to the following categories of
persons within the scope of the rules specified in this Policy and in accordance with Articles 8 and 9 of the
Law:
- 1) Our Shareholders
- 2) Our Business Partners
- 3) Natural persons or legal entities of private law
- 4) Authorized Public Institutions and Organizations
- 5) Suppliers
13
Recipient Description Data Transfer Purpose
Our Shareholders Shareholders of our Company can be
accessed from the web page of the Istanbul
Trade Registry Directorate.
Limited to the purposes of informing
or auditing our Company's
commercial activities.
Business Partner Our business partners for purposes such as
sales, promotion, and marketing of our
Company's products and services; banks
that are our business partners for
performing payment and collection
transactions.
Limited to ensuring the fulfillment of
the purposes of establishing the
business partnership.
Natural Persons or
Legal Entities of Private
Law
Institutions or organizations that have been
established in accordance with certain
conditions specified by law in accordance
with the provisions of the relevant legislation
and continue their activities within the
framework determined by the law (For
example; independent auditors, lawyers
from whom we receive legal services,
accountants, workplace doctor).
Limited to ensuring the fulfillment of
the purposes of establishing the
business partnership.
Authorized Public
Institutions and
Organizations
Public institutions and organizations
authorized to receive information and
documents from our Company in
accordance with the provisions of relevant
legislation (Courts, Public Prosecutor's
Offices, Police Directorates, Tax Offices,
İŞKUR, SGK, GİB, Competition Authority,
Ministries, etc.).
Limited to the purpose requested by
the relevant public institutions and
organizations within their legal
authority.
Suppliers Parties providing services to our Company
in accordance with our Company's data
processing purposes and instructions within
the scope of conducting our Company's
commercial activities.
Limited to the purpose of ensuring
the provision of services obtained
externally from suppliers and
necessary to perform our Company's
commercial activities.
2.4. Measures We Take to Ensure the Lawful Transfer of Personal Data
The administrative and technical measures we take to protect personal data are included in the
Ephesus Hotel Data Retention and Destruction Policy.
G. RETENTION PERIOD OF PERSONAL DATA AND MEASURES TAKEN
1. Retention Periods
Personal data are kept within the Company for the relevant legal retention periods or for the period
required for the realization of the activities related to these data and the purposes specified in this Policy.
Personal data whose purpose of use has ceased or whose legal retention period has expired are
destroyed by the Company in accordance with the Data Retention and Destruction Policy.
In cases where we process personal data for more than one purpose, in the event that all of the
processing purposes of the data have ceased or upon the request of the relevant person, provided that
there is no obstacle to the deletion of the data in the legislation, the data are deleted, destroyed, or stored
anonymously. Provisions of the legislation and decisions of the KVK Board are complied with regarding the
14
destruction, deletion, or anonymization.
2. Measures We Take Regarding the Retention of Personal Data
2.1. Technical Measures
We establish technical infrastructures and audit mechanisms for the deletion, destruction, and
anonymization of personal data, take the necessary measures for the safe storage of personal data, and
install security systems in accordance with technological developments regarding the storage areas of
personal data.
2.2. Administrative Measures
We raise awareness by informing our employees about technical and administrative risks related to
the retention of personal data, provide training, and include provisions regarding the necessary security
measures to be taken for the protection and safe storage of the transferred personal data in contracts
made with companies to which personal data are transferred in case of cooperation with third parties for
the retention of personal data.
H. DELETION, DESTRUCTION, OR ANONYMIZATION OF PERSONAL DATA
Personal data collected within the scope of our processing purposes are processed and stored within
the scope of our processing purposes and current legislation provisions.
Personal data are deleted, destroyed, or anonymized upon the complete termination of our
processing purposes or upon the request of the Relevant Person. The deletion, destruction, and
anonymization processes in question are carried out within the scope of the "Ephesus Hotel KVKK
Retention and Destruction Policy" without prejudice to the provisions of the relevant legislation.
When your personal data are deleted, destroyed, or anonymized, the security measures included in
this Policy are taken. Records of the operations performed for the deletion, destruction, or anonymization
of personal data are kept for at least 10 years, without prejudice to other laws and legislation provisions.
Unless otherwise specified by the KVK Board, Ephesus Hotel selects the appropriate one among the
methods of deleting, destroying, or anonymizing personal data. However, upon the request of the Relevant
Person, the appropriate method is selected by explaining the reason.
I. RIGHTS OF THE RELEVANT PERSON AGAINST OUR COMPANY
In our Company, the rights of natural persons whose personal data are processed are regulated in
parallel with Article 11 of KVKK No. 6698, and the relevant persons have the following rights in our
Company:
- To learn whether his/her personal data are processed,
- To request information if his/her personal data have been processed,
- To learn the purpose of processing personal data and whether they are used in accordance with the
purpose,
- To know the third parties to whom his/her personal data are transferred domestically,
- To request the correction of personal data in case they have been processed incompletely or
incorrectly,
- To request the deletion or destruction of data in case the reasons requiring the processing of
personal data have ceased,
15
- To request notification to third parties to whom personal data have been transferred of the operations
performed pursuant to the above,
- To request the compensation of damages in case damages arise due to the unlawful processing of
personal data.
Requests from relevant persons for the use of one of the above rights shall be fulfilled by the
Company within a maximum of 30 days.
These requests can be conveyed through the contact channels of our Company or through the
exclusive Data Subject Application Form we have separately prepared; in the specified methods. These
methods are:
- Submitting the Data Subject Application Form on our website with a wet signature and a copy of the
ID card to the address "Mesih Paşa, Aksaray Cad. No:24, 34130 Fatih/İstanbul",
- Personal application with a valid ID card to the commercial headquarters address of our Company at
"Mesih Paşa, Aksaray Cad. No:24, 34130 Fatih/İstanbul",
Your right requests regarding your personal data are evaluated and responded to within a maximum
of 30 days from the date they reach us. In case your application is evaluated negatively, the reasoned
rejection reasons are sent to the address you specified in the application by e-mail or by post.
Pursuant to the Communiqué on the Procedures and Principles of Application to the Data Controller, it
is mandatory for the relevant person's application to contain name, surname, signature if the application is
written, T.R. ID number, (passport number if the applicant is a foreigner), residential address or workplace
address for notification, e-mail address for notification if any, phone number, fax number, and information
regarding the subject of the request.
The relevant person must clearly and understandably state the subject requested in the application
containing explanations regarding the right he/she wishes to exercise to use the above-mentioned rights.
Information and documents related to the application must be attached to the application.
Although the subject of the request must be related to the person of the applicant, if acting on behalf
of someone else, the applicant must be specifically authorized in this matter and this authorization must be
documented (special power of attorney). In addition, the application must contain identity and address
information and identity-confirming documents must be attached to the application.
Requests made on behalf of someone else by unauthorized third parties will not be evaluated.
Our Right to Reject the Application:
Applications related to personal data may be rejected in the following cases, including but not limited
to:
- Processing of personal data for purposes such as research, planning, and statistics by anonymizing
them with official statistics,
- Processing of personal data for purposes such as art, history, literature, or scientific purposes or
within the scope of freedom of expression, provided that they do not violate the privacy of the
Relevant Person or personality rights or constitute a crime,
- Processing of personal data made public by the Relevant Person,
- Application not being based on a justified reason,
- Application containing a request contrary to the relevant legislation,
- Non-compliance with the application procedure.
16
J. SECURITY OF PERSONAL DATA
Ephesus Hotel attaches importance to protecting the confidentiality and security of personal data. In
this direction, the necessary technical and administrative security measures are taken to protect personal
data against unauthorized access, damage, loss, or disclosure. In accordance with Article 12 of the Law,
necessary systemic access controls, data access controls, secure transfer controls, business continuity
controls, and other necessary institutional controls are applied to prevent the unlawful processing of the
personal data being processed, to prevent unlawful access to data, and to ensure the preservation of data.
The administrative and technical measures taken by us are generally as follows:
✓ Network security and application security are ensured.
✓ Security measures within the scope of information technology systems procurement, development,
and maintenance are taken.
✓ Security of personal data stored in the cloud is ensured.
✓ Disciplinary regulations containing data security provisions for employees are in place.
✓ Training and awareness activities on data security are conducted for employees at regular intervals.
✓ Data Loss Prevention software (DLP) is used.
✓ In addition to the use of strong passwords and codes, passwords and codes are changed at regular
intervals.
✓ For remote connection security, the method with the highest encryption and security is used.
✓ It is regularly monitored whether there are security vulnerabilities, and appropriate security patches
are installed.
✓ Access logs are kept regularly.
✓ Corporate policies on access, information security, use, retention, and destruction have been
prepared and put into practice.
✓ Data masking measures are applied when necessary.
✓ Confidentiality undertakings are made.
✓ The authorizations of employees who have changed positions or left the job in this area are removed.
✓ Up-to-date anti-virus systems are used.
✓ Firewalls are used.
✓ The contracts signed contain data security provisions.
✓ Personal data security policies and procedures have been determined.
✓ Personal data security issues are reported quickly.
✓ Personal data security is monitored.
✓ Necessary security measures are taken for entries and exits to physical environments containing
personal data.
✓ The security of physical environments containing personal data against external risks (fire, flood, etc.)
is ensured.
✓ The security of environments containing personal data is ensured.
✓ Personal data are reduced as much as possible.
✓ Personal data are backed up and the security of backed-up personal data is also ensured.
✓ A user account management and authorization control system is implemented and monitored.
✓ In-house periodic and/or random audits are carried out and conducted.
17
✓ Log records are kept without user intervention.
✓ Existing risks and threats have been identified.
Despite all measures taken, as soon as a data breach is detected, it will be notified to the relevant
personal data subjects and the Republic of Turkey Personal Data Protection Authority and will be shared
with the public as soon as possible.
K. PRIVACY NOTICE AND EXPLICIT CONSENT DECLARATIONS
Ephesus Hotel has placed separate privacy notices for each data subject group in physical
environments and virtual environments in a way that relevant persons can access. The privacy notices
prepared by the Company are directed to:
➢ Employees/Employee Candidates (Including Interns)
➢ Business Partners/Suppliers/Dealers/Intermediaries (Including Potential Ones)
➢ Customers to accommodate and customers who will purchase our other products and services
(Including Potential Ones)
➢ Visitors
L. EPHESUS HOTEL KVKK COMMITTEE, COMMITTEE'S ROLE AND
RESPONSIBILITY
1. Ephesus Hotel KVKK Committee
As Ephesus Hotel, the KVKK Committee to be established within the Company will consist of 1
chairperson and sufficient members.
2. Committee's Role and Responsibility
2.1. Supervision
The General Management unit is responsible for the determination and operation of notification,
examination, and sanction mechanisms in case of non-compliance with this Policy, rules, and regulations,
and for the supervision of these.
2.2. Approval
This Policy has been approved by the KVK Committee of Ephesus Hotel, and the KVK Committee is
the authorized approval mechanism for the establishment, application, and updating of the Policy when
necessary. The KVK Committee is responsible for ensuring that the necessary measures are taken for the
compliance of the employees working in the activities they are responsible for, as well as the external
service companies, with the Policy, examining the matters in order to determine the issues contrary to the
Policy, and reporting them to the "Supervision" unit.
2.3. Update
The General Management is responsible for the preparation, development, execution, and updating of
this Policy. It evaluates this Policy in terms of currency and development needs when necessary.
2.4. Distribution
The internal distribution of the prepared document is the responsibility of the General Management
unit.
18
2.5. Information
Within the scope of this Policy, the publication of the prepared document on the intranet system is the
responsibility of the General Management unit.
M. PUBLICATION, RETENTION, ENTRY INTO FORCE, AND UPDATE OF THE
POLICY
1. Publication and Retention of the Policy
This Policy enters into force with the approval of the KVK Committee of Ephesus Hotel.
This Policy is kept in two different environments, including printed paper and electronic environment.
The current version of the documents is included on the Company's website.
2. Entry into Force of the Policy
This Policy is deemed to have entered into force after its publication on the Company's website. In the
event that it is decided to abolish this Policy, the old copies of the Policy are canceled by the General
Management and kept for 5 years.
3. Update of the Policy
This Policy is reviewed at least once a year without any notification and updated when necessary
within the framework of the principles determined in the Documentation Management Procedure. For this
reason, it is recommended to review this Policy at regular intervals.
First Publication Date: 3/11/2025
Updates: 28 April 2026
Last Update: 28 April 2026
Note: This is an English translation of the Turkish original. In case of interpretation questions or legal disputes, the
Turkish original version shall prevail.