Corporate & Legal

Official Document Record

KVKK

Privacy Notice (KVKK)

Last Updated: March 20, 2026

Blue Bosphorus Turizm ve Tanıtım Ltd. Şti. (Tax No: 6340030273; Şişli Tax Office; Address: Cumhuriyet Cad. Babil Sok. No:7/3 Şişli, Istanbul, Türkiye) operates the etourgood.com ecosystem (the "Travel OS") as the Data Controller. We are fully committed to protecting your personal and corporate data in strict compliance with the Turkish Law on the Protection of Personal Data No. 6698 (KVKK) and international privacy standards.

1. Data Controller

Blue Bosphorus Turizm ve Tanıtım Ltd. Şti. is strictly responsible for all data processing, storage, and security activities across the etourgood.com platform, including our specialized B2B Extranet modules for hotels and travel agencies, and our B2C booking interfaces.

2. Personal and Corporate Data Collected

To operate our comprehensive Travel OS, we collect and process the following data categories:

  • Identity & Profile: Name, surname, TR Identity Number (for local compliance), gender, email address, and phone number.

  • B2B & Verification Data: For agency and hotel partners, we collect official business titles, tax numbers, tax office details, IBAN/bank details, operating licenses (e.g., TURSAB, Tourism Ministry Certificates), and uploaded payment receipts for activation fees.

  • Travel & Compliance: Passport details (issuing country, passport number, expiry date) strictly for international travel bookings and legal border compliance.

  • Communication & Content: Logs from our real-time messaging system, customer support tickets, property reviews, and uploaded media/logos.

  • Financial Data: Payment and billing details (processed securely via trusted third-party gateways). etourgood does not store your full credit card information.

  • Technical & Security Data: IP addresses, device identifiers, strictly necessary security tokens (such as CSRF tokens to prevent cyber-attacks), and cookies (see our Cookie Policy).

3. Purpose of Processing

We process your data based on the legal grounds provided in Articles 5 and 6 of the KVKK:

  • Ecosystem Operations: To instantly match travelers with service providers (hotels, tours, transports) and finalize bookings.

  • B2B Onboarding & Extranet: To legally verify travel agencies and properties, process one-time setup fees, and grant secure access to our inventory management CRM.

  • Communication: To facilitate seamless, multilingual real-time chat between guests and partners.

  • Analytics & Growth: To generate anonymized data to improve platform performance and provide business insights to our partners.

  • Security & Law: To prevent fraud, ensure platform security, and fulfill our legal obligations under local and international tourism, tax, and consumer protection laws.

4. Data Sharing & Global Transfers

Your data is strictly guarded and shared only when essential:

  • Service Fulfillment: Relevant booking data (name, travel dates, special requests) is shared securely with the specific hotel, guide, or transport provider you booked with.

  • Trusted Partners: Limited data is shared with our secure payment processors, cloud hosting providers, and analytical partners under strict confidentiality agreements.

  • International Transfers: Due to the global nature of travel, data may be transferred to service providers located outside of Türkiye to confirm your international bookings, operating under KVKK-compliant transfer mechanisms and explicit consent where necessary.

5. Data Retention Policy

We retain your personal and corporate data only for as long as your account is active or as legally mandated.

  • Upon a valid account deletion request, standard personal data is securely erased or anonymized within 30 days.

  • However, financial transaction logs, tax records, and B2B verification documents may be retained for up to 10 years as mandated by Turkish commercial and tax laws. Anonymized data may be kept indefinitely for platform analytics.

6. Security Infrastructure

We treat your data like a fortress. Our security measures include:

  • Encryption & Protocols: Advanced AES-256 encryption, SSL/TLS layers, and strict Origin/CSRF validation mechanisms to block unauthorized requests.

  • Audits & Access: Regular security audits and strict internal role-based access control.

  • Breach Notification: In the unlikely event of a data breach, notifications will be issued to affected users and the Turkish Data Protection Authority within 72 hours, as required by KVKK.

7. Your Rights Under Article 11 of KVKK

As a data subject, you have the absolute right to:

  • Learn whether your data is being processed and request details about the processing.

  • Access, correct, update, or request the deletion/destruction of your data.

  • Restrict or object to data processing, particularly regarding automated profiling.

  • Withdraw your consent for marketing communications at any time.

  • Claim compensation for damages arising from unlawful data processing.

etourgood logo Travel Operating System
Document Auto-Generated • 2026

Conversation

Sign Out?

Are you sure you want to end your current session?