PRIVACY NOTICE UNDER THE GENERAL DATA PROTECTION REGULATION (GDPR)
MEANDER FERİBOT İŞLETMELERİ ANONİM ŞİRKETİ As the Company (the "Company" or "Meander"), we attach importance to the protection and privacy of your personal data.
This Privacy Notice has been prepared, within the scope of Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation (the "GDPR"), in order to inform you about the methods by which your personal data — obtained through the English-language website operated by the Company (the "Site") or through the Company's other communication and application channels — is collected, the purposes and legal grounds for which it is processed, with whom it may be shared, for how long it is retained, and your rights over your personal data.
The Company acts in the capacity of data controller with respect to the personal data processing activities within the scope of this Privacy Notice.
Data Controller: MEANDER FERİBOT İŞLETMELERİ ANONİM ŞİRKETİ
Address: Camikebir Mahallesi, Mahmut Esat Bozkurt Caddesi, Turistik Site No:14/B, 09400 Kusadasi/Aydin, Türkiye
Email: info @meanderferibot . com
The Company's representative within the European Union under Article 27 of the GDPR:
EU Representative: Tekin Isikligil
Address: Camikebir Mahallesi, Mahmut Esat Bozkurt Caddesi, Turistik Site No:14/B, 09400 Kusadasi/Aydin, Türkiye
Email: info @meanderferibot . com
1. DEFINITIONS
Consent: Refers to the declaration of will by which the data subject freely, in a specific, informed and unambiguous manner, indicates through a clear statement or an affirmative action that they accept the processing of personal data relating to them.
Personal Data: Any information relating to an identified or identifiable natural person,
Processing: Any operation carried out on personal data, including the obtaining, recording, organizing, storing, altering, using, disclosing, transferring, making accessible, restricting, erasing or destroying of personal data,
Controller: The natural or legal person who determines the purposes and means of the processing of personal data,
Processor: The natural or legal person who processes personal data on behalf of and in accordance with the instructions of the controller,
Special Categories of Personal Data: Refers to personal data subject to special protection under Article 9 of the GDPR; namely, health data, biometric and genetic data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and data concerning sex life or sexual orientation.
2. COLLECTION OF PERSONAL DATA
Your personal data may be collected by the Company, within the scope of your benefiting from the services and your use of the Site, by automatic or non-automatic methods, in physical or digital environments.
Your personal data may be obtained, in particular, through:
- Information provided by you during ferry ticket reservation, purchase, modification, cancellation or refund transactions,
- Information provided within the scope of an application, in the event of benefiting from a door visa or related travel services,
- Communication or reservation forms on the Site,
- Correspondence carried out with the Company via e-mail, telephone or other communication channels,
- Transaction information obtained through payment service providers within the scope of payment transactions,
- Passenger information provided by other persons making the reservation, in cases such as group or family reservations,
- IP address, device type, operating system, browser information, access time and system logs during the use of the Site,
- Cookies and similar technologies.
Detailed information about the use of cookies and similar technologies is provided within the scope of the Company's Cookie Policy.
In cases where personal data is obtained not directly from you but from another person or source, further information is provided, to the extent required under Article 14 of the GDPR.
3. PROCESSING OF PERSONAL DATA AND ITS PURPOSES
Your personal data is processed only for specified, explicit and legitimate purposes and on the basis of a valid legal ground within the scope of the GDPR.
In this scope, your personal data may be processed:
- For the purpose of carrying out ferry ticket reservation, purchase, modification, cancellation and refund transactions; issuing the ticket and providing the travel service, on the legal ground of being necessary for the conclusion or performance of a contract pursuant to Article 6(1)(b) of the GDPR,
- For the purpose of carrying out payment transactions, creating payment and invoice records and conducting financial transactions, on the legal grounds of performance of the contract within the scope of Article 6(1)(b) of the GDPR and, with respect to applicable legal obligations, compliance with a legal obligation within the scope of Article 6(1)(c) of the GDPR,
- For the purpose of communicating with passengers in relation to reservation, voyage changes, cancellation, refund or the services provided, on the legal ground of performance of the contract pursuant to Article 6(1)(b) of the GDPR,
- For the purpose of receiving and evaluating door visa or related travel applications and transmitting the necessary information and documents to the authorized institutions and organizations, on the legal grounds of — depending on the nature of the transaction — performance of the contract within the scope of Article 6(1)(b) of the GDPR and/or compliance with a legal obligation within the scope of Article 6(1)(c) of the GDPR,
- For the purpose of evaluating and responding to customer questions, requests and complaints, on the legal ground of — depending on the nature of the request — the conclusion or performance of the contract within the scope of Article 6(1)(b) of the GDPR, or the Company's legitimate interest in managing customer relations and service quality within the scope of Article 6(1)(f) of the GDPR,
- For the purpose of operating the Site and information systems securely, preventing unauthorized access, misuse and fraud, and ensuring information security, on the legal ground of the Company's legitimate interest in ensuring the security of its systems and services within the scope of Article 6(1)(f) of the GDPR,
- For the purpose of fulfilling legal obligations and meeting the lawful requests of authorized administrative or judicial authorities, on the legal ground of compliance with a legal obligation within the scope of Article 6(1)(c) of the GDPR,
- For the purpose of managing possible disputes and establishing, exercising or defending the Company's legal rights, on the legal ground of the Company's legitimate interest in protecting its legal rights within the scope of Article 6(1)(f) of the GDPR,
- For the purpose of using non-mandatory analytical, personalization or advertising cookies and conducting direct marketing activities for which consent is required, on the basis of your explicit consent within the scope of Article 6(1)(a) of the GDPR.
The personal data that may be processed in this scope may include identity information, contact information, reservation and travel information, payment and transaction information, technical and security data, cookie and online usage data, customer communication and request records, and — depending on the nature of the service — visa and travel document information.
In cases where credit or debit card information is processed directly by the payment service provider, this information is not stored by the Company.
In cases where it is necessary to process health information such as a passenger's disability status, special assistance or accessibility need, the said data is processed in accordance with the provisions of Article 9 of the GDPR. Where the processing is based on consent, the explicit consent of the data subject is obtained within the scope of Article 9(2)(a) of the GDPR.
In the event that the identity, contact, travel and payment information mandatorily requested for carrying out the ticket reservation and sale is not provided, it may not be possible to create the relevant reservation, issue the ticket or provide the service. Giving consent regarding marketing and non-mandatory cookies, on the other hand, is not a condition for purchasing a ticket or benefiting from the core services.
4. TRANSFER OF PERSONAL DATA
Your personal data may be shared, only to the extent required by the relevant processing purpose and in accordance with the provisions of the GDPR, with:
- Ferry and related transport service providers,
- Payment service providers,
- Reservation, hosting, software, information technology and technical support service providers,
- Customer service and operational service providers,
- The authorized Greek authorities and relevant public institutions, within the scope of conducting door visa or travel transactions,
- Port, border-crossing and other authorized public authorities,
- Legal, financial and other professional advisors,
- Administrative and judicial authorities authorized by law,
- Analytics or advertising service providers, where the necessary consent exists.
Data processing arrangements in accordance with the provisions of Article 28 of the GDPR are made, to the extent applicable, with service providers processing personal data on behalf of the Company.
Since the Company is established in Turkey, personal data transmitted to the Company through the Site may be processed and stored in Turkey.
In cases where the transfer of personal data to a separate controller or processor located outside the European Economic Area is subject to the international data transfer provisions of the GDPR, the Company ensures that the necessary protection mechanisms are in place pursuant to Chapter V of the GDPR. In this scope, where applicable, the Standard Contractual Clauses (SCCs) adopted by the European Commission or other appropriate safeguards provided for in the GDPR may be relied upon.
Information about the applied international data transfer safeguards, or a copy of the relevant safeguards, may be requested by contacting the Company.
5. RETENTION AND DESTRUCTION OF PERSONAL DATA
Your personal data is retained only for the period necessary for the purpose for which it is processed.
In determining the retention periods, the following are taken into account: the duration of the service and contractual relationship, retention obligations arising from applicable tax, accounting, commercial, transport and other legislation, limitation periods relating to legal disputes, information security requirements, and whether the relevant data processing purpose continues.
Ticket, reservation, payment and invoice records are retained for the applicable statutory retention periods; customer communication records for the period necessary for the conclusion of the relevant request and for possible legal disputes; and technical and security records for the period necessary and proportionate for the purpose of information security.
In consent-based data processing activities, personal data may be processed until the withdrawal of consent or the termination of the relevant processing purpose. In the event that there is another legal ground requiring the retention of the data after the withdrawal of consent, the relevant data is retained limited solely to the purpose and period required by that legal ground.
In the event that the retention period expires or the legal ground requiring the processing of personal data ceases to exist, personal data is securely deleted or anonymized.
6. YOUR RIGHTS
Under the GDPR, where the applicable conditions exist, you have the rights to:
- learn whether your personal data is being processed and request access to your personal data,
- request the rectification of your incomplete or inaccurate personal data,
- request the erasure of your personal data,
- request the restriction of the processing of your personal data,
- receive your personal data in a structured, commonly used and machine-readable format and exercise the right to data portability, within the framework of the conditions provided for in the GDPR,
- object, on grounds relating to your particular situation, to data processing carried out on the basis of legitimate interest within the scope of Article 6(1)(f) of the GDPR,
- object at any time to the processing of your personal data for direct marketing purposes,
- withdraw your consent at any time where data processing is based on consent,
- not be subject to decisions based solely on automated processing which produce legal or similarly significant effects concerning you, within the framework of the conditions provided for in Article 22 of the GDPR,
- lodge a complaint with a competent data protection supervisory authority.
The withdrawal of consent does not affect the lawfulness of the data processing activities carried out on the basis of consent prior to its withdrawal. In the ordinary ticket sales, reservation and customer service processes described within the scope of this Privacy Notice, no decision-making activity based solely on automated processing that produces legal or similarly significant effects concerning persons within the meaning of Article 22 of the GDPR is envisaged.
In order to exercise your rights, you can submit your requests to the Company through the following channels:
Email: info @meanderferibot . com
Post: Camikebir Mahallesi, Mahmut Esat Bozkurt Caddesi, Turistik Site No:14/B, 09400 Kusadasi/Aydin, Türkiye
EU Representative: Tekin Isikligil
Where there is reasonable doubt about the identity of the person making the request, the Company may request necessary and proportionate additional information in order to conclude the request securely.
Your requests are concluded, pursuant to Article 12 of the GDPR, free of charge, without undue delay and, as a rule, within one month following receipt of the request. Where the request is complex or the number of requests is high, this period may be extended by a further two months. In such a case, the extension of the period and its justification are notified to you within the first one-month period.
In addition, within the scope of Article 77 of the GDPR, you may lodge a complaint with the competent data protection supervisory authority, in particular in the EU/EEA country of your habitual residence, place of work, or the place where the infringement you consider to constitute unlawful processing of your personal data occurred.
7. FINAL PROVISIONS
This Privacy Notice has been prepared in order to provide information about the personal data processing activities carried out within the scope of the Site operated by Meander and the ferry ticket, reservation, travel and related services offered through the Site.
Detailed information regarding the use of cookies and similar technologies is explained within the scope of the Cookie Policy; and the Company's general practices regarding the protection of personal data are explained within the scope of the relevant Privacy and Data Protection Policy.
The Company may update this Privacy Notice in line with changes that may occur in its personal data processing activities, its services, the technologies used, or the applicable data protection legislation.
The current version of the Privacy Notice is published on the Site.
Last Updated: 03 September 2026