Privacy Notice
Published · August 2, 2026
DATA CONTROLLER
Seller: —
Address: —
Telephone: +90 533 370 8161
E-mail: online@galadoosuites.com
Tax office / number: —
MERSIS: —
Website: https://galadoosuites.com
WHAT WE PROCESS
For the booking: name, surname, e-mail, telephone, country, stay dates, number of guests and any note you leave.
For legal compliance: the identification presented on arrival (Turkish Law no. 1774 on Identity Notification).
For payment: the outcome, amount and date of the payment. We never see or store your card number — card details are entered only on iyzico's own secure page.
For correspondence: the name, e-mail and message you send us.
Technical: IP address and browser information, for security and abuse prevention only.
WHY
To create and perform the booking (performance of a contract), to meet statutory retention and notification duties (legal obligation), and to answer your questions and improve the service (legitimate interest). We do not send marketing e-mail.
WHO WE SHARE IT WITH
With the payment institution (iyzico) in order to take the payment; with the provider we use to send e-mail; and with public authorities only where the law requires it. We share data with no one else and we do not sell it.
HOW LONG WE KEEP IT
Booking and payment records are kept for 10 years under tax and commercial law. Identity notification records are kept for the period the relevant legislation requires. Correspondence is deleted after 2 years. Images of identity documents are deleted when the statutory period ends and, until then, are held outside the web root in a location only authorised staff can reach, with every access logged.
YOUR RIGHTS
Under article 11 of the Turkish Data Protection Law you may ask whether your data is processed, request information about it, ask for it to be corrected or erased, learn who it has been transferred to, and object to processing.
Apply through the data request form at https://galadoosuites.com. Before we act on a request we ask you to confirm your identity through a link sent to your e-mail address — otherwise anyone could request, or erase, your data in your name. Requests are answered within 30 days at the latest.
SECURITY
Passwords are stored irreversibly, session data is encrypted, identity documents are held outside the web root, and every access to them is recorded.