KVKK policy — personal data processing, protection, and disposal policy under Turkish data protection law.

POLICY ON THE PROCESSING, PROTECTION, AND DISPOSAL OF PERSONAL DATA UNDER THE KVKK & GDPR

A. INTRODUCTION

As MEANDER FERİBOT İŞLETMELERİ ANONİM ŞİRKETİ (“Company”), we attach importance to the lawful, fair, transparent and secure processing of personal data.

With respect to the personal data processing activities carried out by the Company, the legislation on the protection of personal data in force in Turkey — in particular Law No. 6698 on the Protection of Personal Data (the “KVKK”) — is complied with.

In addition, with respect to personal data processing activities connected with the Company's offering of goods or services to persons located within the European Union and the European Economic Area (the “EU/EEA”), the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, the General Data Protection Regulation (the “GDPR”), also apply to the extent applicable.

The reason this Policy has been prepared taking into account both the KVKK and the GDPR provisions is that, in addition to operating as a data controller established in Turkey, the Company offers ferry tickets, reservations and related travel services to persons located in the EU/EEA through the [meanderferibot.com] website.

For this reason, the Company's personal data processing activities may be subject to the KVKK and/or the GDPR, depending on the nature and geographic scope of the relevant processing activity. This Policy sets out the general principles regarding the management, in an integrated manner under both sets of legislation, of the personal data processing activities carried out within the Company.

For the purposes of the application of the GDPR, it is not the nationality of the data subject but the conditions set out in Article 3 of the GDPR regarding its territorial scope that are taken as the basis. In this scope, personal data processing activities connected with the Company's offering of ferry tickets, reservations, travel or related services to persons located within the EU/EEA may be assessed within the scope of the GDPR.

The Company aims to show the necessary sensitivity to the security of personal data and the privacy of data subjects in the digital processes it conducts, in ferry ticket sales and reservation transactions, in door visa applications, in travel and tourism services, and in payment and customer communication processes.

This Policy on the Processing, Protection, Retention and Destruction of Personal Data (the “Policy”): [New English-language ticket-sales website for the EU/EEA market: meanderferibot.com] has been prepared in order to explain the general principles regarding the personal data processing activities carried out through the other digital channels operated by the Company and within the scope of the services offered by the Company.

This Policy is assessed together with the KVKK Clarification Texts provided to data subjects, the Privacy Notice/Privacy Policy under the GDPR, the Cookie Policy and, where necessary, the explicit consent texts provided.

B. PURPOSE OF THE POLICY

The purpose of this Policy is:

  1. to ensure that personal data is processed in accordance with the KVKK, the GDPR and other applicable data protection legislation,
  2. to ensure lawfulness, fairness, transparency, purpose limitation and data minimization in data processing activities,
  3. to protect personal data against unauthorized access, loss, disclosure, alteration and similar risks,
  4. to ensure that personal data is retained only for the period necessary,
  5. to ensure that data is deleted, destroyed or anonymized in a lawful manner when the retention period or the data processing purpose ends,
  6. to ensure that data subjects can effectively exercise their rights arising from the KVKK and, to the extent applicable, the GDPR,
  7. to ensure the Company's accountability regarding its data processing activities and the creation of the necessary records.

C. ENTRY INTO FORCE OF THE POLICY

This Policy takes effect on the date it is approved and published by the Company.

The Clarification Texts, Privacy Notice and Cookie Policy addressed to data subjects are kept accessible through the relevant websites. This Policy, on the other hand, constitutes the basic framework of the Company's internal data protection and compliance processes.

The Company may update this Policy in line with changes that may occur in the legislation in force, in the decisions and guidelines of the Personal Data Protection Board, the European Data Protection Board (the “EDPB”), the European Union institutions or the competent data protection authorities, as well as changes that may occur in the Company's data processing activities.

Significant changes are announced to data subjects, to the extent appropriate, through the website or other appropriate communication channels.

The effective date and the last update date are indicated on the current version of the Policy.

D. SCOPE OF THE POLICY AND DATA SUBJECTS

This Policy covers the personal data processing activities carried out by the Company in the capacity of data controller.

The KVKK applies to the Company's personal data processing activities within the scope of the KVKK.

The GDPR, on the other hand, applies in particular to the personal data processing activities that the Company carries out in connection with its offering of goods or services to persons located in the EU/EEA and that fall within the scope of Article 3 of the GDPR.

The persons whose personal data may be processed within the scope of the Policy are principally the following:

  • passengers and customers who purchase ferry tickets,
  • persons who make reservations,
  • prospective customers,
  • persons who apply for a door visa,
  • persons located within the EU/EEA who benefit from the Company's services,
  • website visitors,
  • persons who make a contact request,
  • other passengers whose information is shared within the scope of a group or family reservation,
  • emergency contact persons,
  • the representatives and employees of suppliers and business partners,
  • the Company's employees and job candidates, with respect to the relevant data processing activity,
  • the representatives of authorized public institutions and organizations,
  • other natural persons whose data is processed within the scope of a legal or commercial relationship.

E. DATA SUBJECTS GROUPS

Visitor

A person who visits the Company's websites and whose IP address, device information, cookie information or similar online identifiers may be processed within the scope of this visit.

Person Making a Contact Request

A person who contacts the Company through the website, e-mail, telephone or other communication channels.

Passenger / Customer / Prospective Customer

A person who benefits from, or contacts the Company in order to benefit from, ferry ticket, reservation, travel, tourism or door visa services.

Data Subject Under the GDPR

The data subject whose personal data is processed in connection with a data processing activity falling within the territorial scope of the GDPR. This status does not depend on the person's nationality.

Third Party

A natural person whose data is provided to the Company by another person for reasons such as a group reservation, family reservation, emergency contact person, reference or the like.

These categories are not exhaustive, and the fact that a person does not fall within one of the above categories does not remove their status as a data subject.

1. DEFINITIONS

  1. Consent: Consent that relates to a specific matter, is based on information and is declared with free will. Under the GDPR, consent must additionally be based on a freely given, specific, informed and unambiguous indication of will. Where special category personal data is processed on the basis of consent, the “explicit consent” conditions under the GDPR apply.
  2. Data Subject: The identified or identifiable natural person whose personal data is processed.
  3. Personal Data: Any information relating to an identified or identifiable natural person.
  4. Processing: Any operation carried out on personal data, including the obtaining, recording, organizing, structuring, storing, altering, using, disclosing, transferring, making accessible, combining, restricting, erasing or destroying of personal data.
  5. Controller: The natural or legal person who determines the purposes and means of the processing of personal data. The controller within the scope of this Policy is: MEANDER FERİBOT İŞLETMELERİ ANONİM ŞİRKETİ.
  6. Processor: The natural or legal person who processes personal data on behalf of the controller.
  7. Recipient: The natural or legal person, public authority, institution or other body to which personal data is disclosed.
  8. Anonymization: The rendering of personal data in such a way that it can in no manner be associated with an identified or identifiable natural person, taking into account the methods that may reasonably be used. Genuinely anonymized information is not considered personal data under the GDPR.
  9. Pseudonymization: The processing of personal data in such a way that it can no longer be attributed to a specific person without the use of additional information. Pseudonymized data is not considered anonymous data and retains its status as personal data.
  10. Destruction: The lawful deletion, destruction or anonymization of personal data.
  11. Recording Medium: Any electronic or physical medium in which personal data is located.
  12. Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data processed.
  13. Special Categories of Personal Data: Personal data subject to special protection within the scope of Article 6 of the KVKK and Article 9 of the GDPR.
  14. Supervisory Authority: An independent data protection authority established in an EU/EEA member state pursuant to the GDPR.
  15. Personal Data Protection Board: The Personal Data Protection Board of the Republic of Turkey.
  16. EU Representative : The natural or legal person designated in writing, where applicable, under Article 27 of the GDPR to represent a controller not established in the EU within the Union with respect to transactions falling within the scope of the GDPR.

    The Company's EU Representative under Article 27 of the GDPR:

    Title: Mr. Tekin Isikligil
    Address: Camikebir Mahallesi Mahmut Esat Bozkurt Caddesi Turistik Site No:14/B, 09400, Kuşadası, Aydin, Türkiye
    Email: info @ meanderferibot . com

2. PROCESSING OF PERSONAL DATA AND LEGAL BASES

The processing of personal data does not, in every case, have to be based on the data subject's consent. The Company relies, for each personal data processing activity, on at least one valid legal ground for processing under the applicable legislation.

Personal data processing activities within the scope of the KVKK are carried out pursuant to Article 5 of the KVKK and the other relevant provisions.

Personal data processing activities within the scope of the GDPR, on the other hand, may in particular be based on one or more of the following legal grounds within the scope of Article 6 of the GDPR:

  1. Consent – Article 6(1)(a) of the GDPR: The data subject's valid consent to a specific processing activity.
  2. Conclusion or performance of a contract – Article 6(1)(b) of the GDPR: The purchase of a ferry ticket, the making of a reservation, the provision of travel services, or the carrying out of pre-contractual transactions at the request of the data subject.
  3. Legal obligation – Article 6(1)(c) of the GDPR: The fulfilment of obligations arising from the legislation to which the Company is subject.
  4. Protection of vital interests – Article 6(1)(d) of the GDPR: Exceptional situations where it is necessary to protect the vital interests of the data subject or of another person.
  5. Legitimate interest – Article 6(1)(f) of the GDPR: The realization of legitimate commercial interests such as information security, fraud prevention, protection of legal rights, improvement of operations and the like, provided that the fundamental rights and freedoms of the data subject do not override.

Where the legal ground of legitimate interest is relied upon, the Company carries out, in the necessary cases, a balancing assessment between the relevant interest and the rights and freedoms of the data subject.

In consent-based processing, the data subject may withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out prior to the withdrawal.

3. SPECIAL CATEGORY PERSONAL DATA

Within the scope of the KVKK, special category personal data is processed in accordance with the provisions of Article 6 of the KVKK.

Within the scope of the GDPR, on the other hand:

  • Racial or ethnic origin,
  • Political opinions,
  • Religious or philosophical beliefs,
  • Trade union membership,
  • Genetic data,
  • Biometric data processed for the purpose of uniquely identifying a natural person,
  • Health data,
  • Data concerning sex life or sexual orientation

constitute special category personal data within the scope of Article 9 of the GDPR.

Personal data relating to criminal convictions and offences, on the other hand, is subject not to Article 9 but to the provisions of Article 10 of the GDPR.

Within the scope of Meander's ordinary activities, the need to process special category personal data may arise in particular with respect to:

  • Disability information,
  • Mobility restrictions,
  • Wheelchair/accompaniment needs,
  • Pregnancy status,
  • Special health or travel support requirements.

Such data is processed on the basis of one of the conditions provided for in Article 6 of the KVKK and Article 9 of the GDPR, depending on the nature of the processing, and with the necessary security measures taken.

Where, within the scope of the GDPR, the processing of health data for travel support purposes is based on consent, explicit consent is obtained from the data subject.

In an emergency, where the data subject is physically or legally unable to give consent, the provisions of Article 9(2)(c) of the GDPR regarding the protection of the vital interests of the person or of another natural person may be applied, where the applicable conditions exist.

The Company collects special category personal data only to the extent necessary for the processing purpose and keeps access to such data limited.

4. DATA SECURITY

In order to ensure the security of personal data, the Company takes technical and organizational measures in accordance with the applicable data protection legislation, in particular Article 12 of the KVKK and Article 32 of the GDPR.

In determining the measures to be taken, the following are taken into account:

  • The nature of the processing,
  • Its scope,
  • Its context,
  • Its purpose,
  • Current technological possibilities,
  • The cost of implementation,
  • The likelihood and severity of the risks that may arise for the rights and freedoms of data subjects.

The following measures are relied upon, to the extent appropriate:

  • Restriction of access authorizations,
  • User and authorization management,
  • Secure authentication methods,
  • Appropriate security methods in data transmission and storage,
  • Backup and business continuity measures,
  • Logging and monitoring,
  • Protection against malware,
  • Management of security vulnerabilities,
  • Informing employees about data security,
  • Concluding appropriate data protection agreements with processors,
  • Encryption and pseudonymization in appropriate cases,
  • Periodic assessment and testing of security measures.

The Company also takes into account the principles of privacy by design and privacy by default within the scope of Article 25 of the GDPR.

Personal Data Breaches: In the event that a personal data breach within the scope of the GDPR gives rise to a risk to the rights and freedoms of natural persons, the Company informs the competent supervisory authority, in accordance with the applicable conditions, without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

In the event that the breach gives rise to a high risk for the data subjects, notification is also made to the data subjects without undue delay pursuant to Article 34 of the GDPR. In the case of data breaches within the scope of the KVKK, the KVKK and the relevant regulations and decisions of the Personal Data Protection Board apply.

5. COLLECTION OF PERSONAL DATA

The Company may collect personal data in electronic or physical environments, by direct or indirect methods.

The principal data collection channels are the following:

  • Website reservation and ticket sales screens,
  • Gate visa application forms,
  • Contact forms,
  • E-mail and telephone communication,
  • Customer service processes,
  • Payment service providers,
  • Travel or reservation systems,
  • Cookies and similar online technologies,
  • Persons making group or family reservations,
  • Authorized public institutions,
  • Port and border-crossing authorities,
  • Carrier companies and relevant service providers.

In cases where personal data is obtained not from the data subject but from another source and Article 14 of the GDPR is applicable, the necessary information is provided to the data subject within the period and conditions provided for in the legislation.

Transactions carried out through cookies and similar technologies are additionally managed within the scope of the Company's Cookie Policy and the relevant consent management mechanism.

6. CATEGORIES OF PERSONAL DATA PROCESSED BY THE COMPANY

The principal categories of personal data that may be processed by the Company are shown in Appendix 1.

In accordance with the principle of data minimization, the Company takes as its basis the processing only of personal data that is necessary and proportionate for the specific processing purpose.

In cases where payment card information is not stored directly by the Company and is processed by the payment service provider, this matter is clearly notified to the data subjects.

7. PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA

Pursuant to Article 4 of the KVKK and Article 5 of the GDPR, the Company processes personal data in accordance with the following fundamental principles:

  • Lawfulness, fairness and transparency,
  • Processing for specified, explicit and legitimate purposes,
  • Relevance to the purpose,
  • Data minimization,
  • Accuracy and, where necessary, currency,
  • Storage limitation,
  • Integrity and confidentiality,
  • Protection of personal data against unauthorized or unlawful processing.

With respect to processing to which the GDPR applies, the Company additionally aims, in accordance with the principle of accountability, to establish and maintain policies, records and procedures capable of demonstrating that it complies with the above principles.

To the extent applicable, data processing activities are recorded within the scope of Article 30 of the GDPR.

In data processing activities that may give rise to a high risk, it is assessed whether a Data Protection Impact Assessment (DPIA) needs to be carried out pursuant to Article 35 of the GDPR.

8. PURPOSES OF PROCESSING PERSONAL DATA AND GDPR LEGAL BASES

The Company processes personal data on the basis of a valid legal ground under the GDPR and only to the extent necessary for the relevant processing purpose. In this scope, personal data may be processed for the following purposes:

Carrying out ferry ticket sales, reservation and modification transactions:

Personal data is processed for the purpose of carrying out ticket sales and reservation transactions, issuing tickets and providing travel services, on the legal ground of being necessary for the conclusion or performance of a contract within the scope of Article 6(1)(b) of the GDPR.

Conducting door visa applications:

For the purpose of receiving door visa applications, processing the application documents and transmitting the necessary information and documents to the authorized authorities, personal data may be processed — depending on the nature of the transaction — on the legal grounds of performance of the contract within the scope of Article 6(1)(b) of the GDPR and/or compliance with a legal obligation within the scope of Article 6(1)(c) of the GDPR. Where special category personal data is processed within the scope of the application, an appropriate processing condition under Article 9 of the GDPR is additionally relied upon.

Sharing passenger information with carriers and authorized authorities:

The sharing of passenger information with ferry operators, port authorities, border authorities or other authorized institutions may be carried out under Article 6(1)(b) of the GDPR with respect to the performance of the travel service, and under Article 6(1)(c) of the GDPR where there is a notification or sharing obligation arising from the legislation.

Evaluating customer requests and complaints:

For the purpose of evaluating and responding to customer questions, requests and complaints, personal data may be processed under Article 6(1)(b) of the GDPR where the request is connected with the contractual relationship, and in other cases under Article 6(1)(f) of the GDPR within the scope of the Company's legitimate interest in managing customer relations and service quality.

Carrying out payment and refund transactions:

Personal data relating to payment, collection and refund transactions is processed on the legal ground of being necessary for the performance of the contract within the scope of Article 6(1)(b) of the GDPR. With respect to tax, accounting and similar legal record-keeping obligations, the legal ground of legal obligation within the scope of Article 6(1)(c) of the GDPR may also apply. Payment transactions may be carried out through separate payment service providers.

Ensuring information security and transaction security:

The personal data necessary for the purpose of preventing fraud, unauthorized access, misuse and security breaches may be processed under Article 6(1)(f) of the GDPR within the scope of the Company's legitimate interest in ensuring the security of its systems, services and users.

Fulfilling legal obligations:

For the purpose of fulfilling obligations arising from tax, accounting, consumer, transport, tourism, border-crossing and other applicable legislation, and meeting the lawful requests of authorized administrative or judicial authorities, personal data may be processed within the scope of Article 6(1)(c) of the GDPR.

Establishing, exercising and protecting legal rights:

The personal data necessary for the purpose of managing disputes and asserting, exercising or defending legal claims may be processed under Article 6(1)(f) of the GDPR within the scope of the Company's legitimate interest in protecting its legal rights. Where it is necessary to process special category personal data for this purpose, Article 9(2)(f) of the GDPR may apply.

Analytics and improvement of the user experience:

Personal data processing activities carried out through non-mandatory analytical and performance cookies are based on the user's consent within the scope of Article 6(1)(a) of the GDPR, to the extent required under the applicable electronic communications and cookie legislation.

Marketing and commercial communication activities:

Within the scope of electronic marketing, advertising and promotional activities that require consent, personal data may be processed on the basis of the data subject's consent within the scope of Article 6(1)(a) of the GDPR, in accordance with the applicable data protection and electronic communications legislation.

The data subject may object at any time, within the scope of Article 21 of the GDPR, to personal data processing activities carried out for direct marketing purposes.

9. TRANSFER OF PERSONAL DATA WITHIN TURKEY AND RECIPIENTS

Personal data may be shared, to the extent required by the data processing purpose, with the following categories of recipients:

  • Ferry/maritime transport companies,
  • Payment service providers,
  • Information technology, hosting, software and technical support providers,
  • Reservation and customer service providers,
  • Professional advisors,
  • Legal and accounting service providers,
  • Port operators and border-crossing authorities,
  • Institutions and organizations authorized with respect to visa applications,
  • Public institutions and judicial/administrative authorities authorized by law.

Domestic transfers within Turkey within the scope of the KVKK are carried out in accordance with Article 8 of the KVKK.

Contractual arrangements in accordance with the provisions of Article 28 of the GDPR are made, to the extent applicable, with third parties from whom services are received in the capacity of processor under the GDPR.

The Company aims to work only with processors that provide adequate technical and organizational safeguards.

10. INTERNATIONAL TRANSFER OF PERSONAL DATA

1. Transfers Abroad Under the KVKK

The transfer of personal data subject to the KVKK outside Turkey is carried out in accordance with Article 9 of the KVKK and the provisions of the Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad.

Depending on the applicable situation, the following may be used:

  • An adequacy decision,
  • Standard contracts,
  • Binding corporate rules,
  • Written undertakings containing appropriate safeguards and the necessary Board authorization,
  • The exceptional cases provided for in the law.

2. International Transfers Under the GDPR

In the event that personal data within the scope of the GDPR is transferred by the Company to a separate controller or processor located outside the EEA, the international data transfer provisions set out in Chapter V of the GDPR apply.

Depending on the applicable situation, the following may be used:

  • An adequacy decision of the European Commission pursuant to Article 45 of the GDPR,
  • Appropriate safeguards pursuant to Article 46 of the GDPR,
  • The Standard Contractual Clauses (“SCCs”) adopted by the European Commission,
  • Binding Corporate Rules,
  • Approved codes of conduct or certification mechanisms and binding undertakings,
  • The limited derogations set out in Article 49 of the GDPR.

In transfers based on appropriate safeguards, the legal order and actual practices in the country to which the transfer is made are assessed to the extent necessary, and it is examined whether additional technical, contractual or organizational measures are necessary.

More detailed information regarding the country to which personal data will be transferred, the category of recipient and the protection mechanisms used is provided to data subjects in the relevant Privacy Notice.

11. RETENTION, DELETION, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

The Company does not retain personal data indefinitely.

Personal data is retained for the periods determined taking into account:

  • The purpose of the relevant transaction,
  • The duration of the contractual relationship,
  • The retention obligations provided for in the relevant legislation,
  • Tax and accounting obligations,
  • Travel and transport legislation,
  • Possible dispute and limitation periods,
  • The protection of legal rights,
  • Information security needs.

When the processing purpose and the legal retention requirement cease to exist, personal data is deleted, destroyed or anonymized in accordance with the applicable legislation.

Within the scope of the GDPR, the “storage limitation” principle is applied to personal data pursuant to Article 5(1)(e) of the GDPR.

In the event that the data subject makes an erasure request within the scope of Article 17 of the GDPR, the request is evaluated.

However, the right to erasure is not absolute. Where personal data:

  • Must be retained due to a legal obligation,
  • Is necessary for the establishment, exercise or defence of legal claims,
  • Falls within one of the other exceptions provided for in Article 17(3) of the GDPR,

the relevant data may continue to be retained for the legally necessary period.

In a consent-based data processing activity, in the event of the withdrawal of consent, the data processing is terminated if there is no other legal ground for the same data processing activity.

The Company retains the necessary records regarding retention and destruction operations for the periods provided for in the legislation.

12. DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

The destruction method used by the Company is determined according to:

  • The nature of the personal data,
  • The medium in which it is stored,
  • The technological infrastructure,
  • The risk of recoverability, and
  • The technical characteristics of the relevant system.

The technical methods included within the scope of the Policy apply only with respect to the systems and technologies actually used by the Company.

1. Deletion or Destruction of Electronic Data

Personal data held in electronic systems is deleted or destroyed by methods appropriate to the structure of the relevant system and that reasonably eliminate the risk of recovery.

2. Destruction of Physical Data

Personal data in printed documents or in physical media may be destroyed by methods such as shredding, secure destruction services, and physical destruction that prevents the re-obtaining of the data.

3. Anonymization

As a result of anonymization, it must not be reasonably possible for a person to be directly or indirectly re-identified.

The methods that may be used include data aggregation, removal of identifying fields, generalization, masking under the necessary conditions, and statistical methods.

Pseudonymization alone, or the removal of some identity-identifying fields, is not considered anonymization if re-identification is still possible.

13. RIGHTS OF DATA SUBJECTS

1. Rights Under the KVKK

Pursuant to Article 11 of the KVKK, data subjects have the rights to:

  • Learn whether personal data is being processed,
  • Request information regarding this if their personal data has been processed,
  • Learn the purpose of the processing of personal data and whether the data is used in accordance with the purpose,
  • Know the third parties to whom personal data is transferred,
  • Request the rectification of personal data that is incompletely or inaccurately processed,
  • Request the deletion or destruction of personal data upon the fulfilment of the legal conditions,
  • Request that rectification, deletion or destruction operations be notified to the third parties to whom the data was transferred,
  • Object to a result that arises against the person as a result of analysis exclusively by automated systems,
  • Request the compensation of the damage in the event of suffering damage due to unlawful processing of personal data.

2. Rights Under the GDPR

With respect to data processing activities to which the GDPR applies, data subjects have, to the extent the conditions are met:

  • Right to be informed: They have the right to receive clear and transparent information about how their personal data is processed within the scope of Articles 13 and 14 of the GDPR.
  • Right of access: They may request information and a copy regarding their personal data and the processing activities within the scope of Article 15 of the GDPR.
  • Right to rectification: They may request the rectification of inaccurate or incomplete personal data within the scope of Article 16 of the GDPR.
  • Right to erasure: They may request the erasure of personal data upon the existence of the conditions within the scope of Article 17 of the GDPR.
  • Right to restriction of processing: They may request the restriction of the processing of personal data in certain cases within the scope of Article 18 of the GDPR.
  • Right to data portability: Upon the fulfilment of the conditions in Article 20 of the GDPR, the data subject has the right to receive the personal data provided by them in a structured, commonly used and machine-readable format and, to the extent appropriate, to transfer it to another controller.
  • Right to object: They may object, on grounds relating to their particular situation, to certain data processing activities based on legitimate interest within the scope of Article 21 of the GDPR.
  • In the event of an objection to the processing of personal data for direct marketing purposes, the personal data in question is no longer processed for this purpose.
  • Automated decision-making and profiling: Within the framework of the conditions provided for in Article 22 of the GDPR, they have the right not to be subject to decisions based solely on automated processing which produce legal effects concerning them or similarly significantly affect them.
  • Withdrawal of consent: If the processing is based on consent, the data subject may withdraw their consent at any time.
  • Lodging a complaint: The data subject may, pursuant to Article 77 of the GDPR, lodge a complaint with the competent supervisory authority in the member state, in particular of their habitual residence, place of work or the place where the alleged infringement occurred.

14. APPLICATION TO THE DATA CONTROLLER

Personal data subjects may exercise their rights through the following channels:

Postal Address: Camikebir Mahallesi Mahmut Esat Bozkurt Caddesi Turistik Site No:14/B, 09400, Kuşadası, Aydin, Türkiye

Email: info @ meanderferibot . com

KEP (Registered E-mail): [email protected]

GDPR EU Representative: Tekin Isikligil

For applications within the scope of the GDPR, a notarized notice or a notarized power of attorney is not a mandatory application requirement. Where there is reasonable doubt regarding the identity of the person making the application, the Company may request necessary and proportionate additional information for the verification of identity pursuant to Article 12(6) of the GDPR. No more personal data than necessary is collected for the purpose of identity verification.

Response time for GDPR applications

Requests within the scope of the GDPR are, as a rule, concluded within one month of receipt of the request. Where necessary due to the complexity of the request or the high number of requests, this period may be extended by a further two months. In such a case, the data subject is informed about the extension and its justification within the first one-month period. Requests are, as a rule, free of charge.

Where the request is manifestly unfounded or excessive, in particular where it is repetitive, a reasonable fee may be charged, or the fulfilment of the request may be refused, within the framework of the conditions of Article 12(5) of the GDPR.

Applications within the scope of the KVKK, on the other hand, are concluded in accordance with the KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller, as soon as possible depending on the nature of the request and at the latest within thirty days.

15. RIGHTS OF COMPLAINT AND LEGAL RECOURSE

  1. KVKK: In the event that an application within the scope of the KVKK is refused, the response given is found insufficient, or no response is given within the time limit, the data subject may lodge a complaint with the Personal Data Protection Board within the period and conditions specified in the KVKK.
  2. GDPR: Data subjects falling within the scope of the GDPR may lodge a complaint with a competent EU/EEA data protection authority pursuant to Article 77 of the GDPR. The data subject's rights to an effective judicial remedy within the scope of Articles 78 and 79 of the GDPR, and their right to claim compensation for the damage suffered upon the fulfilment of the conditions in Article 82 of the GDPR, are additionally reserved.

Controller

MEANDER FERİBOT İŞLETMELERİ ANONİM ŞİRKETİ

Address: Camikebir Mahallesi Mahmut Esat Bozkurt Caddesi Turistik Site No:14/B, 09400, Kuşadası, Aydin, Türkiye

MERSİS No: 0295 0107 4740 0010

APPENDIX-1: DATA TABLE

DATA TYPE
DATA DESCRIPTION
DATA DETAILS
Identity Information
Information serving to identify a natural person
Name, surname, Turkish ID number (TCKN), passport number, date of birth, place of birth, gender, nationality information, photograph, specimen signature
Contact Information
Information used to reach and communicate with the person
Telephone number, e-mail address, residential address, emergency contact person information
Financial Information
Information processed within the scope of reservation and payment transactions
Bank account information (IBAN), credit card information (only through the payment provider), invoice information
Travel and Visa Information
Data processed in ferry ticket, reservation and door visa transactions
Travel date, voyage and route information, ticket number, reservation records, information in the visa application form, visa documents (civil registration copy, photograph, hotel/transport reservation, etc.)
Transaction Security Information
Data processed in order to secure transactions carried out in digital systems
Username, password, log-in/log-out time, log records, IP address, access authorizations, internet browser information
Marketing Information
Promotional and marketing data collected with the user's explicit consent
Commercial electronic message consent, campaign participation information, survey responses, areas of interest
Cookie Data
Data collected in order to improve the on-site user experience and to carry out statistical measurement
Cookie records, browser type, device information, page navigation data, session duration, preferred language, click history
Health Information
Information processed in order to determine security and accompaniment needs during the transport service
Pregnancy status, disability information, allergy and special health requirements (e.g. wheelchair need)
Legal Transaction and Compliance Information
Data processed in order to fulfil legal obligations
Information and documents submitted to courts and administrative authorities, identity verification records, official correspondence

APPENDIX-2: KVKK APPLICATION FORM

A. Contact Information of the Applicant:

Name:
Surname:
TC Identity Number:
Phone Number:
Email:
Address:

B. The Applicant's relationship with our Company:

The department you are in contact with within our company:
Years worked (for former employees):
The company I work for and my position (for third-party company employees):
Subject:

Please specify your request under the KVK Law in detail:

REQUEST No
SUBJECT of REQUEST
LEGAL BASIS
YOUR SELECTION
1
I would like to learn whether your Company processes personal data about me.
KVKK Article 11/1 (a)
2
If your organization processes personal data about me, I request information about these data processing activities.
KVKK Article 11/1 (b)
3
If your Company processes personal data about me, I request information about these data processing activities
KVKK Article 11/1 (c)
4
If your Company processes personal data about me, I would like to learn the purpose of the processing and whether it is used in accordance with that purpose.
KVKK Article 11/1 (c)
5
I believe my personal data has been processed incompletely or inaccurately and I request its rectification.
KVKK Article 11/1 (d)
6
Although my personal data has been processed in accordance with the law and other relevant legal provisions, I believe the reasons requiring its processing have ceased to exist, and in this framework I request the deletion or destruction of my personal data.
KVKK Article 11/1 (e)
7
I request that the rectification of my personal data which I believe has been processed incompletely or inaccurately also be carried out at the third parties to whom it was transferred.
KVKK Article 11/1 (f)
8
Although my personal data has been processed in accordance with the law and other relevant legal provisions, I believe the reasons requiring its processing have ceased to exist, and in this framework I request that the deletion or destruction of my personal data also be notified to the third parties to whom it was transferred.
KVKK Article 11/1 (g)
9
I believe that my personal data processed by your Company is analyzed exclusively through automated systems and that, as a result of this analysis, a result has arisen against me. I object to this result.
KVKK Article 11/1 (h)
10
I have suffered damage due to the unlawful processing of my personal data. I request the compensation of this damage.
KVKK Article 11/1 (j)
11
Other, Please specify:

Please select the method by which you would like the response to your application to be notified to you:

Note: (If you choose the email method, we will be able to respond to you more quickly.)

(If delivered by proxy, a notarized power of attorney or authorization document is required.)

This application form has been prepared in order to determine your relationship with our Company and, by completely identifying the personal data (if any) processed by our Company, to enable an accurate and timely response to the relevant application.

In order to eliminate the legal risks that may arise from unlawful and unjust data sharing and, in particular, to ensure the security of your personal data, our Company reserves the right to request additional documents and information (a copy of an identity card or driving licence, etc.) for the determination of identity and authorization.

In the event that the information regarding the requests you submit within the scope of the form is not accurate and up to date, or that an unauthorized application is made, our Company does not accept liability for requests arising from such inaccurate information or unauthorized application.

In line with the requests I have stated above, I kindly request that my application to your Company be evaluated pursuant to Article 13 of the Law and that I be informed.

I declare and undertake that the documents and information I have provided to you in this application are accurate and up to date and belong to me.

I permit the information and documents I have provided in this application form to be processed by your Company, limited to the purposes of evaluating and responding to the application I have made pursuant to Article 13 of Law No. 6698 on the Protection of Personal Data, delivering the response of my application to me, and determining my identity and address.

Name and Surname of the Applicant (Personal Data Subject):

Date of Application:

Signature:

APPENDIX 2: DATA SUBJECT RIGHTS APPLICATION FORM UNDER THE GDPR

MEANDER FERİBOT İŞLETMELERİ ANONİM ŞİRKETİ

GENERAL EXPLANATIONS

This form has been prepared in order to facilitate your application to MEANDER FERİBOT İŞLETMELERİ ANONİM ŞİRKETİ (the “Company” or “Meander”) in order to exercise the rights you have under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, the General Data Protection Regulation (the “GDPR”).

The use of this form is not mandatory. You may also submit your requests under the GDPR to the Company by another method, in a manner that allows your identity and your request to be understood.

Where there is reasonable doubt regarding your identity, the Company may request necessary and proportionate additional information pursuant to Article 12(6) of the GDPR in order to conclude your request securely. No more personal data than necessary is requested for the purpose of identity verification.

Requests under the GDPR are, as a rule, concluded free of charge within one month of receipt of the request. Where the request is complex or the number of requests is high, this period may be extended by a further two months; the extension and its justification are notified to the data subject within the first one-month period.

APPLICANT INFORMATION

Name and Surname:
E-mail Address:
Telephone Number (optional):
Postal Address (if a response by post is requested):
Your Relationship with the Company:
If Applying on Behalf of Someone Else, Your Authority to Represent:

YOUR RELATIONSHIP WITH THE COMPANY

( ) Passenger / Customer

( ) Person Making a Reservation

( ) Prospective Customer

( ) Gate Visa Applicant

( ) Website Visitor

( ) Person Making a Contact Request

( ) Employee / Former Employee

( ) Job Candidate

( ) Supplier / Business Partner Representative or Employee

( ) Other:

C. Your Request:

SELECTION
No
RIGHT / SUBJECT OF REQUEST
LEGAL BASIS
EXPLANATION
( )
1
Right to be informed
GDPR Art. 13-14
I request information about how my personal data is processed.
( )
2
Right of access
GDPR Art. 15
I request information and a copy regarding the personal data processed about me and these processing activities.
( )
3
Right to rectification
GDPR Art. 16
I request the rectification of my incomplete or inaccurate personal data.
( )
4
Right to erasure
GDPR Art. 17
I request the erasure of my personal data upon the existence of the conditions provided for in the GDPR.
( )
5
Restriction of processing
GDPR Art. 18
I request the restriction of the processing of my personal data within the framework of the conditions provided for in the GDPR.
( )
6
Notification of rectification/erasure/restriction to recipients
GDPR Art. 19
To the extent applicable, I request that the rectification, erasure or restriction of processing be notified to the recipients to whom the data was disclosed.
( )
7
Right to data portability
GDPR Art. 20
To the extent the conditions are met, I request to receive the personal data provided by me in a structured, commonly used and machine-readable format and/or to have it transferred to another controller.
( )
8
Right to object
GDPR Art. 21
I object, on grounds relating to my particular situation, to personal data processing activities based on legitimate interest.
( )
9
Objection to direct marketing
GDPR Art. 21(2)-(3)
I object to the processing of my personal data for direct marketing purposes.
( )
10
Withdrawal of consent
GDPR Art. 7(3)
With respect to consent-based data processing activities, I withdraw the consent I previously gave.
( )
1
Automated decision-making / profiling
GDPR Art. 22
I believe I have been subject to a decision based solely on automated processing that produces legal effects concerning me or similarly significantly affects me, and I wish to exercise my relevant right.
( )
12
Other
GDPR
My other request:

D. Details of Your Request

Please state the scope of your request, the relevant transaction/reservation date, the ticket or reservation number, the e-mail address you used, the relevant website or other information that will facilitate locating the request, only to the extent necessary.

E. Method Which You Wish To Response Delivered To

( ) I would like it to be sent to my e-mail address.

( ) I would like it to be sent to my postal address.

F. Application Channels

Postal Address
Camikebir Mahallesi Mahmut Esat Bozkurt Caddesi Turistik Site No:14/B, Kusadasi / Aydin / Türkiye
E-mail:
info @ meanderferibot .com
KEP (Registered E-mail):
GDPR EU Representative:
Mr. Tekin Isikligil

G. Declaration

I declare that the information I have given in this application is accurate and up to date and that the application belongs to me. I acknowledge that I am aware that the personal data necessary for the evaluation of the application, the verification of identity, the conclusion of the request and the delivery of the response to me may be processed for the purpose of the relevant legal obligations and the fulfilment of the application.

Where the application is manifestly unfounded or excessive, in particular where it is repetitive, the Company may charge a reasonable fee or refuse to act on the request pursuant to Article 12(5) of the GDPR.

Name and Surname of the Applicant
Date of Application
Signature (for written applications)
If applying through a representative, the name and authority of the representative

Note: This form has been prepared for applications within the scope of the GDPR. Applications within the scope of the KVKK are conducted through a separate application procedure and form.