Point HOTEL Management A.Ş. (Hereinafter referred to as “OTEL”), we process the personal data / special personal data of our guests as the data controller, within the scope of the Personal Data Protection Law No. 6698 (hereinafter referred to as “KVKK”).
This text has been prepared for the purpose of informing you about our data controller identity, the purposes of processing your personal data, to whom and for what purposes we transfer your personal data, the methods of processing your personal data, our legal reasons and your rights as a relevant person within the scope of the form, reservation transactions and contact information you have filled out in order to benefit from the services we will provide on the website https://www.nipponhotel.com.tr as the "Data Controller" in accordance with Article 10 of the KVKK.
1-) DATA CONTROLLER:
ADDRESS : Topçu Cd. No:6 Beyoğlu/İSTANBUL
PHONE NUMBER: 0212 313 33 00
E-MAIL : kvkk@nipponhotel.com.tr
KEP : pointhotel@hs01.kep.tr
MERSİS : 0730036964500036
2-) SCOPE OF THE INFORMATION TEXT:
This text; It includes the data of website visitors, guests who made reservations and visitors / guests who want to contact us to obtain information.
3-) PROCESSED PERSONAL DATA AND PURPOSES OF PROCESSING PERSONAL DATA:
The categories of personal data processed for guests are listed below, and each data category is processed for the purposes specified above.
Purposes of Processing Personal Data
Identity Information: Name - Surname, T.R. Identity Number and Passport Number. For the purpose of performing the HOTEL reservation service; creating a guest registration, verifying the information of our guests, establishing a contractual relationship between the parties, and fulfilling the obligations arising from the Law.
Contact Information:
Email Address and Phone Number. Ensuring continuous and uninterrupted communication between the guest and the HOTEL staff and optionally benefiting from advertising and marketing services.
Camera Footage: Cameras Inside the HOTEL. Ensuring the physical space security of the OTEL, protecting the legitimate interests of the employer, protecting the life and property of guests, staff or third parties and obtaining evidence that can be proven in possible disputes.
Health Information: Allergen Records and Food Intolerance Information. In order to protect the health of the guests, determining the foods suitable for their health and meeting their special nutritional demands during their stay at the HOTEL.
Payment Information: Credit Card Information and Bank Account Information Completing transactions regarding guest reservations, collecting the amount of accommodation fees and providing convenience to our guests in payment transactions.
Invoice Information: Issuing e-invoice/e-archive invoices, submitting legal declarations and carrying out accounting processes in accordance with tax laws.
License Plate Information: Vehicle. Creating and tracking guest records and controlling HOTEL entry and exit.
SPA Information Registering the guests who want to benefit from the SPA service, determining the SPA occupancy rate, ensuring the preservation of the guest's valuable belongings before using the SPA and protecting the safety of the guest's life and property.
4-) PARTIES TO WHICH PERSONAL DATA CAN BE TRANSFERRED:
Among the personal data subject to this information text, those transferred for the purpose of fulfilling legal obligations, execution of the contract between the parties and ensuring the legitimate interests of the employer and the places where they are transferred are listed below.
Your personal data; It can be transferred domestically or abroad for the purposes stated below, in accordance with the personal data transfer conditions in KVKK articles 8 and 9. Data transfer abroad; In line with the GDPR, it is transferred to the server and cloud service provider operating in countries where an Adequacy Decision has been issued by the European Commission, solely for the purpose of security and storage of data.
Personal Data Categories Parties
Identification Judicial and Law Enforcement Authority.
Contact Information Authorized Public Institutions, Travel Agencies, CRM Companies, Supplier Officials and Supplier Employees.
Camera Footage Judicial Authorities and Law Enforcement Authority.
Payment Information Banks, Financial Institutions, Financial Advisors, Overseas Cloud Systems, Service Providers and Servers.
Invoice Information Authorized Public Institutions and Financial Advisors
5-) PROTECTION OF PERSONAL DATA:
In accordance with KVKK article 12; As the data controller, we take all necessary technical and administrative measures to prevent the unlawful processing of your personal data that we have collected, to prevent unlawful access, to preserve personal data and to prevent it from falling into the hands of unauthorized persons. The main measures taken in this direction are as follows:
Administrative Measures Technical Measures
Personnel KVKK Awareness Training: Hotel personnel are given periodic training on the protection of personal data; Awareness is provided to personnel in accordance with current KVKK legislation and principles. Cyber Security Measures: OTEL information systems are protected by up-to-date firewalls, anti-virus software and intrusion detection systems.
Confidentiality Agreements with Supplier Companies: Confidentiality agreements are signed with companies from which outsourced services are provided to ensure the security of personal data.
Physical Security: Physical archives and server rooms where data is stored; It is protected against natural disasters such as fire, flood and earthquake; Entry and exit to these areas is limited to authorized personnel.
Authorization Matrix: Access to personal data within OTEL is limited only to authorized persons who need access to the relevant data. Encryption and Secure Communication: In reservation and payment transactions made through the OTEL website, SSL (Secure Sockets Layer) certificate and cryptographic encryption methods are used for the secure transfer of data.
Data Storage and Destruction Policy: The retention periods of each personal data processed by the staff and guests within the hotel are certain, and personal data whose retention period has expired is periodically deleted, destroyed or anonymized in line with our "Personal Data Storage and Destruction Policy". Access Logs: All accesses to databases and reservation systems are monitored by keeping log records in order to detect unauthorized transactions.
Data Recovery Studies: There are procedures regarding how long and by what methods the backed-up data will be uploaded to the system in case of a possible cyber attack or data loss. Backup: Our data is regularly backed up in secure environments in case of a possible cyber attack or data loss.
6-) PERSONAL DATA COLLECTION METHODS AND LEGAL REASONS:
Your personal data; It is collected through our website, call center, reception records, agencies and security cameras.
Personal Data Collection Methods Legal Reasons:
Personal data regarding the identity of the guests; In online reservations, it is processed digitally by guests entering their identity information on the website, and in case of application to the HOTEL, it is processed directly by physical methods when the reservation is made. According to KVKK Article 5/2 - (d), "It is mandatory for the data controller to fulfill its legal obligations." (*In accordance with the Identity Reporting Law No. 1174, guests' identity information must be submitted to law enforcement.)
Personal data regarding contact information of guests; The form, reservation process or contact form filled out on the website is processed through digital media, contact by phone or written e-mail. According to KVKK Article 5/2 – (f), "Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person."
Personal data regarding guests' payment information; It is processed digitally when entering bank information for reservations. In accordance with KVKK Article 5/1, the relevant person must have explicit consent.
Personal data regarding billing information of guests; Payments made through the website are processed digitally, while physical payments are processed through physical methods upon the guest's verbal declaration to the reception. According to KVKK Article 5/2 – (d), “It is mandatory for the data controller to fulfill its legal obligations.”
Personal data regarding guests' camera images; From the time the guest enters the HOTEL for accommodation until he leaves the HOTEL, it is processed through security cameras in the common areas of the HOTEL. According to KVKK Article 5/2 – (f), "Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person."
Personal data regarding guests' health information; It is processed by physical methods after the guest communicates the sensitivity regarding allergen or food intolerance to the HOTEL staff verbally or in writing. According to KVKK article 6/3- (a), "Explicit consent of the relevant person"
Personal data regarding guests' license plate information; It is processed when the vehicle is left in front of the HOTEL during the guest's visit to the HOTEL. According to KVKK Article 5/2 - (f), "Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person."
Personal data regarding guests' SPA information; It is processed when the personal data of the guest is entered in the physical environment into the SPA entry-exit schedule while the guest will benefit from the SPA service. According to KVKK Article 5/2 - (f), "Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person."
7-) STORAGE PERIOD OF PERSONAL DATA:
The retention periods of personal data written in this information text according to data categories are listed below and personal data will be destroyed at the end of the period.
Personal Data Parties
ID 1 year.
Contact 10 years.
Payment Information 1 year.
Billing Information 10 years.
Health Information 1 year.
Camera Footage 15 days.
License Plate Information 3 months.
SPA Information 1 year.
8-) RIGHTS OF THE RELATED PERSON:
The natural person whose personal data is processed is defined as the relevant person and has the following rights regarding him/her by applying to the workplace:
a) Learning whether personal data is processed or not,
b) Requesting information if personal data has been processed,
c) Learning the purpose of processing personal data and whether they are used for their intended purpose,
ç) Knowing the third parties to whom personal data is transferred domestically or abroad,
d) Requesting correction of personal data if they are incomplete or incorrectly processed,
e) Requesting the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7,
f) To request that the transactions carried out in accordance with paragraphs (d) and (e) be notified to third parties to whom personal data is transferred,
g) Objecting to the emergence of a result that is unfavorable to the person by analyzing the processed data exclusively through automatic systems,
g) Requesting compensation for the damage in case of damage due to illegal processing of personal data.
In accordance with Article 11 titled "Rights of the person concerned" of the Personal Data Protection Law No. 6698, you can submit your requests regarding your personal data to Kocatepe, Topçu Cd. You can send it in writing to No:2, 34437 Beyoğlu/İstanbul or to our e-mail address kvkk@nipponhotel.com.tr. Your requests will be responded to in writing or electronically, free of charge, as soon as possible and within thirty days at the latest, depending on the nature of the request. However, if the transaction requires an additional cost, the fee in the tariff determined by the Board may be charged.
This Information Text may be revised by the OTEL when deemed necessary.
Point HOTEL Management A.Ş. I have read this clarification text prepared by and obtained information.