Privacy Notice

Published · August 2, 2026

DATA CONTROLLER

Seller: —
Address: —
Telephone: +90 533 370 8161
E-mail: online@galadoosuites.com
Tax office / number: —
MERSIS: —
Website: https://galadoosuites.com

WHAT WE PROCESS

For the booking: name, surname, e-mail, telephone, country, stay dates, number of guests and any note you leave.
For legal compliance: the identification presented on arrival (Turkish Law no. 1774 on Identity Notification).
For payment: the outcome, amount and date of the payment. We never see or store your card number — card details are entered only on iyzico's own secure page.
For correspondence: the name, e-mail and message you send us.
Technical: IP address and browser information, for security and abuse prevention only.

WHY

To create and perform the booking (performance of a contract), to meet statutory retention and notification duties (legal obligation), and to answer your questions and improve the service (legitimate interest). We do not send marketing e-mail.

WHO WE SHARE IT WITH

With the payment institution (iyzico) in order to take the payment; with the provider we use to send e-mail; and with public authorities only where the law requires it. We share data with no one else and we do not sell it.

HOW LONG WE KEEP IT

Booking and payment records are kept for 10 years under tax and commercial law. Identity notification records are kept for the period the relevant legislation requires. Correspondence is deleted after 2 years. Images of identity documents are deleted when the statutory period ends and, until then, are held outside the web root in a location only authorised staff can reach, with every access logged.

YOUR RIGHTS

Under article 11 of the Turkish Data Protection Law you may ask whether your data is processed, request information about it, ask for it to be corrected or erased, learn who it has been transferred to, and object to processing.

Apply through the data request form at https://galadoosuites.com. Before we act on a request we ask you to confirm your identity through a link sent to your e-mail address — otherwise anyone could request, or erase, your data in your name. Requests are answered within 30 days at the latest.

SECURITY

Passwords are stored irreversibly, session data is encrypted, identity documents are held outside the web root, and every access to them is recorded.