Reservation - +90 242 212 01 02
info@serenityhotels.comPERSONAL DATA PROTECTION AND PRIVACY POLICY
Purpose and Scope of the Policy
Policy Overview
As Serenity Hotels, we attach great importance to the privacy of our guests, visitors, suppliers and business partners. This Privacy Policy explains our principles regarding the protection of the personal data of users visiting our website and all stakeholders benefiting from our services through electronic channels. Our aim is to provide a transparent, reliable and legally compliant approach to data processing by embracing a strong data security culture.
Within this scope, we undertake to comply with the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the European Union General Data Protection Regulation ("GDPR") in all processes relating to the collection, storage, processing, transfer, protection and deletion of personal data. This Policy also provides information regarding the purposes of processing personal data, legal grounds, data security measures and the rights of data subjects.
The personal data of individuals using the Serenity Hotels mobile application are also covered by this Policy, and all data processing activities carried out through the application are conducted in accordance with the provisions of the KVKK and GDPR.
KVKK and GDPR Framework
This Policy has been prepared based on the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the European Union General Data Protection Regulation ("GDPR"). Legal requirements applicable in the regions where Serenity Hotels operates or provides services are also taken into consideration.
Under the KVKK, the lawful processing, storage and disposal of personal data and the provision of information to data subjects constitute legal obligations. In addition to these obligations, the GDPR provides broader user rights, including transparency, data portability, consent management and rights relating to supervision and control.
Serenity Hotels conducts its data processing activities in accordance with the common principles of both regulations, including:
Lawfulness and fairness,
Processing for specified, explicit and legitimate purposes,
Necessity and proportionality,
Accuracy and keeping data up to date,
Storage limitation,
Secure storage and disposal.
Categories of Data Subjects Covered
The categories of individuals whose personal data may be processed under this Policy include:
Website Visitors: All users accessing www.serenityhotels.com.
Guests and Potential Guests: Individuals benefiting from accommodation services or participating in the reservation process.
Business Partners and Suppliers: Third-party institutions and individuals from whom we receive services, with whom we cooperate or maintain consultancy relationships.
Employees and Candidates: Personnel working within Serenity Hotels and candidates participating in recruitment processes.
Event and Organization Participants: Individuals attending meetings, seminars, weddings, events and similar activities held at the hotel.
Visitors: Individuals physically visiting our facilities, such as restaurant guests or meeting participants.
Loyalty Program Members and Digital Platform Users: Individuals using our applications or subscribed to our e-mail communications.
Data Controller Information and Contact Details
Definition of Data Controller
Pursuant to the Turkish Personal Data Protection Law No. 6698 ("KVKK"), a "data controller" is the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Under the European Union General Data Protection Regulation (GDPR), a controller is similarly defined as the person or organization that determines the purposes and means by which personal data is processed.
Accordingly, the organization responsible as the data controller for the processing of personal data obtained through our website or through all physical and digital channels is identified below:
Serenity Hotels Data Controller Information
Company Name: City Line İnşaat Emlak Turizm Ticaret Ve Sanayi Ltd. Şti.
Address: Konaklı Mah. Nergis Sok. No:1 Alanya
Telephone: +90 (242) 511 84 84
E-mail: info@serenityhotels.com
VERBIS Data Controller Information
Serenity Hotels has appointed a Data Protection Officer within the scope of the European Union General Data Protection Regulation (GDPR). You may contact us through the following channel regarding requests, suggestions or complaints within the scope of the GDPR:
KVKK Contact Address: kvkk@serenityhotels.com
Our guests, suppliers and visitors who qualify as data subjects may submit any applications and requests relating to data processing activities in writing through the communication channels provided above or by using the KVKK Application Form.
Personal Data Collected and Categories of Data
Serenity Hotels may collect the personal data specified below when you use our services or visit our website, in accordance with applicable legislation and subject to appropriate security measures:
Identity, Contact, Reservation, Payment, Health and Similar Data
The following categories of data may be collected directly from you through electronic forms, reservation transactions, membership registrations, call center interactions, e-mail correspondence, physical forms and service requests made within the hotel:
Identity Information: Name, surname, Turkish ID number, date of birth, gender, passport information and nationality.
Contact Information: E-mail address, mobile telephone number, landline number, postal address and country information.
Reservation and Accommodation Data: Room type, check-in and check-out dates, special requests, number of guests, information relating to children and accommodation history.
Payment and Billing Information: Credit card information (in encrypted form), billing address, bank account number and e-invoice/e-archive information.
Health Data: Information provided with the guest's consent concerning allergies, special diets, disabilities and medical requirements. Such special categories of personal data are processed only to the limited extent necessary to improve your accommodation experience and ensure your safety.
Loyalty Program and Service Preferences: Loyalty membership information, service preferences, feedback and social media interactions.
Data Collected Through Automated Systems
When you visit our website or use our digital applications, the following technical data may be collected automatically:
IP address, device type, operating system and browser type
Login and logout times and pages visited
Click history, preferred language and location data (depending on device settings)
Network and connection type information
Session ID and user behavior information
Such data is retained for a limited period for purposes such as improving the user experience, ensuring system security and preventing fraud, and may be analyzed in anonymized form.
Cookie Data
Our website uses cookie technologies to provide visitors with more effective services and to personalize their experience. The types of cookies used include:
Necessary Cookies: Technical cookies required for the basic functionality of the website.
Functional Cookies: Cookies that remember your preferences, such as language and region.
Performance and Analytics Cookies: Cookies used to measure website traffic and analyze performance, such as Google Analytics.
Marketing and Targeting Cookies: Cookies used to provide advertising based on your interests, subject to your explicit consent.
You can manage your cookie preferences through your browser settings or our Advertising and Cookie Policy page.
Methods and Legal Grounds for Collecting Personal Data
Serenity Hotels collects, processes and stores your personal data using the methods described below. These activities are based on applicable legal grounds such as explicit consent, establishment and performance of a contract, legitimate interests and compliance with legal obligations.
Directly from the User
Your personal data may be obtained directly from you through the following channels:
Reservations, contact requests or information requests submitted through our website
Telephone conversations with our call center
Direct applications made to our hotel, including registration forms and check-in procedures
Physical forms, surveys or satisfaction forms
Feedback provided during guest relations processes
Participation in loyalty programs, competitions or campaigns
Legal Grounds:
KVKK Art. 5/2-c: Processing is necessary for the establishment or performance of a contract
KVKK Art. 5/2-f: Legitimate interests of the data controller
GDPR Art. 6(1)(b): Processing necessary for the performance of a contract
Where explicit consent is obtained: KVKK Art. 5/1 and GDPR Art. 6(1)(a)
Digital Channels and Cookies
When you visit our website or use our digital platforms, data may be collected through:
Cookies and similar technologies on our website
Mobile applications and social media platforms
IP address, device information, session activity and visit duration
Third-party analytics tools such as Google Analytics
Legal Grounds:
KVKK Art. 5/2-f: Legitimate interest
KVKK Art. 5/1 and GDPR Art. 6(1)(a): Explicit consent for cookie use where required
GDPR Art. 6(1)(f): Website security and improvement of the user experience
Security Systems (CCTV, Access Control, etc.)
Closed-circuit television systems (CCTV) and entry/exit control systems are used at Serenity Hotels facilities for security purposes. Through these systems, visual data and entry/exit records may be processed.
Only visual data is collected through cameras located in common areas; audio recordings are not made.
Camera surveillance activities are conducted within legal limits and appropriate privacy notices are provided.
Legal Grounds:
KVKK Art. 5/2-f: Legitimate interests of the data controller
GDPR Art. 6(1)(f): Monitoring for security and crime prevention purposes
Age Restrictions / Personal Data of Children
Serenity Hotels processes personal data relating to individuals under the age of 18 only with the explicit consent of their parents or legal guardians. We do not directly request information from individuals under the age of 18 through our website. Information relating to minors is processed only to the extent necessary for the provision of accommodation services and in accordance with applicable legislation.
Purposes of Processing Personal Data
Serenity Hotels processes your personal data for the purposes set out below and within applicable legal limits. Your data is used only for the stated purposes and is shared with third parties only where there is an appropriate legal basis and, where necessary, with your explicit consent.
Provision of Services and Reservation Processes
Providing hotel services such as accommodation, transfers, restaurants, spa facilities and meeting rooms
Receiving and confirming reservation requests
Processing payments and issuing invoices
Meeting special requirements, including allergies, special diets and accessibility needs
Customer Experience and Satisfaction Management
Conducting guest satisfaction surveys
Evaluating complaints, suggestions and feedback
Operating loyalty programs and providing personalized services
Compliance with Legal Obligations
Carrying out identity verification and accommodation notification procedures
Complying with tax, accounting and other statutory reporting requirements
Responding to requests from authorized public institutions and authorities
Ensuring Security
Ensuring general security through CCTV systems within the premises
Maintaining entry/exit controls and log records
Retaining data as evidence in potential legal disputes
Marketing, Promotion and Communication Activities (Where Explicit Consent Has Been Obtained)
Sending promotional and informational communications by e-mail, SMS or telephone
Analyzing user behavior through consent-based cookies
Promoting campaigns, events and new services
Loyalty program members' reservation history, accommodation preferences, campaign interactions and frequency of service use may be analyzed to provide personalized offers. A segmentation system providing benefits according to membership level (e.g. Green, Silver, Gold and Ruby membership) may form part of these data processing activities. Location-based campaigns, travel-time preferences and loyalty card thresholds may also be processed within this scope. These activities are carried out only for individuals who have provided explicit consent.
Loyalty program data is not shared with third parties for marketing or advertising purposes. Such data is used solely for personalization services within Serenity Hotels.
Within the loyalty program:
Data such as membership type, enrollment date and transaction volume may be categorized for profiling purposes.
Members may progress to different membership levels (e.g. Green, Silver, Gold and Ruby) according to specified spending ranges.
Campaigns, discounts and promotional content may be offered according to each segment.
Users who do not wish to receive offers generated through such analyses may opt out by updating their communication preferences.
Improvement of Business Processes and Analytics
Internal audits, service quality monitoring and strategic planning activities
Analysis of website and digital platform usage data
Improving the user experience and implementing cybersecurity measures
Call Center Conversations and Recordings
Telephone conversations conducted with the Serenity Hotels call center are not recorded by the Serenity Hotels group.
Digital Assistant and WhatsApp Records
Serenity Hotels may retain the content of conversations conducted through WhatsApp and AI-based digital assistant solutions for purposes including guest satisfaction, transaction tracking and improving service quality. Within this scope:
WhatsApp conversations are used solely for following up relevant service requests and resolving complaints. Commercial communications are sent only where explicit consent has been obtained.
Conversations are stored for a limited period in secure digital environments accessible only to authorized departments.
Records are retained and anonymized upon expiry of the applicable retention period.
Records are stored only within Türkiye and are not transferred abroad.
Correspondence with digital assistants is not used for automated decision-making or profiling and is used only to support the service process.
Before a conversation begins, the data subject is informed through an appropriate privacy notice.
Personal data processed within these communication processes is processed on the basis of the legitimate interests of the data controller pursuant to KVKK Art. 5/2-f and GDPR Art. 6(1)(f).
Sharing and Transfer of Personal Data
Serenity Hotels shares and/or transfers your personal data domestically or internationally only for specified purposes and in accordance with applicable legislation with the persons, institutions or organizations described below.
Domestic Transfers
Your personal data may be shared with the following parties where appropriate for the relevant processing purpose and in accordance with applicable legislation:
Business partners and suppliers: For the provision of services including reservations, transfers, restaurants, SPA, cleaning, IT infrastructure support and customer relations.
Group companies: For ensuring service continuity and corporate operations.
Authorized public institutions and authorities: Where legally requested by law enforcement agencies, courts, tax authorities and other competent authorities.
Legal grounds:
KVKK Art. 8
Identity Notification Law No. 1774
Tax Procedure Law No. 213
International Data Transfers
Certain personal data may be transferred abroad in circumstances including:
Use of foreign-based cloud service providers, such as e-mail, backup and reservation systems
Analytics and advertising service providers, such as Google and Facebook
Loyalty and customer experience platforms for consent-based communication processes
Such transfers are carried out only in accordance with the conditions and safeguards required under applicable data protection legislation.
Legal grounds:
KVKK Art. 9
GDPR Arts. 45-49
Safeguards for International Data Transfers
The following safeguards may be implemented when transferring your data internationally:
Standard Contractual Clauses approved by the European Commission
Necessary technical and organizational data security measures
Encryption, access restrictions and logging mechanisms
Data processing agreements concluded with third parties
Transfer of Data to Group Companies and Affiliates
Your personal data may be shared with companies providing services under the Serenity Hotels brand or operating within the same corporate group, solely for the data processing purposes described above. The same data security policies apply within this scope, and all group companies are required to implement appropriate organizational and technical safeguards. A list of group companies and their corporate details may be provided upon request.
Fundamental Principles Relating to the Processing of Personal Data
Serenity Hotels complies with the principles set out in Article 4 of the KVKK and Article 5 of the GDPR when processing personal data. Data processing activities are conducted according to the following fundamental principles:
Lawfulness and Fairness
Data processing activities are carried out in accordance with applicable laws and principles of fairness. For example, e-mail addresses are used for marketing purposes only where the required consent has been obtained.
Accuracy and Keeping Data Up to Date
Processed data must be accurate and up to date. Guests may request updates where their contact or reservation information changes.
Specified, Explicit and Legitimate Purposes
Personal data is collected only for specified and legitimate purposes. For example, passport information is used only for purposes connected with accommodation notification requirements.
Adequacy, Relevance and Data Minimization
Personal data is collected only to the extent necessary and relevant for the applicable purpose. Unnecessary personal data is not processed.
Storage Limitation
Personal data is retained only for the period necessary for the relevant processing purpose. Data whose retention period has expired is deleted, destroyed or anonymized.
Secure Storage and Prevention of Unauthorized Access
All personal data is protected so that it can be accessed only by authorized persons. Access records are maintained and security measures are continuously reviewed and updated.
Special Categories of Personal Data
Under KVKK Art. 6 and GDPR Art. 9, special categories of personal data are subject to enhanced protection standards. Serenity Hotels processes such data only where permitted by law and/or where the necessary explicit consent has been obtained. This may include:
Health Information: Allergies, disabilities, special dietary requirements and medical support requirements
Biometric Data: Biometric data, where such data is processed for a legally permitted purpose
Religious Beliefs, Association Membership, etc.: Only where voluntarily disclosed by you and where required for the relevant service
Disability Information: For accessibility and accommodation arrangements
Processing Conditions:
Obtaining explicit consent where required
Processing expressly provided for by law
Processing health data by persons subject to confidentiality obligations where applicable
Implementation of additional security measures required by the competent authority
Serenity Hotels limits retention periods to those prescribed by legislation and those required by the purposes of processing. Data is retained in accordance with applicable legal obligations, commercial transaction requirements and service quality standards. Upon expiry of the applicable period, data is deleted, destroyed or anonymized in accordance with our data disposal policies.
Retention Periods for Personal Data
Criteria for Determining Retention Periods
Periods expressly specified in applicable legislation
Completion of services and termination of contractual relationships
Expiry of applicable statutory limitation periods
Withdrawal of the user's consent where processing is based on consent
Fulfilment of conditions for deletion following a data subject request
Handling of Data Upon Expiry of the Retention Period
When the retention period expires, data is:
Deleted: Made inaccessible and unavailable for further use.
Destroyed: Data stored in physical media is securely destroyed.
Anonymized: Data is rendered incapable of being associated with an identifiable individual and may thereafter be used for statistical purposes.
Records and Auditing
Data retention and disposal activities are documented in accordance with the Personal Data Retention and Disposal Policy and relevant procedures and, where necessary, documented through a Personal Data Disposal Form.
Rights of Data Subjects and Application Process
Natural persons whose personal data is processed have certain rights under the KVKK and GDPR. Serenity Hotels recognizes these rights and provides appropriate mechanisms for exercising them.
Your Rights Under the KVKK
To learn whether your personal data is being processed
To request information if your personal data has been processed
To learn the purpose of processing and whether the data is being used in accordance with that purpose
To know the third parties to whom personal data has been transferred domestically or internationally
To request correction of incomplete or inaccurate personal data
To request deletion or destruction of personal data in accordance with applicable legislation
To request notification of such actions to third parties to whom the data has been transferred
To object to an adverse result arising from analysis exclusively through automated systems
To claim compensation where you have suffered damage due to unlawful processing
Your Rights Under the GDPR
Right of access
Right to rectification
Right to erasure ("right to be forgotten")
Right to restriction of processing
Right to data portability
Right to object to processing
Rights relating to automated decision-making and profiling
Right to lodge a complaint with a competent data protection authority
Application Methods
You may submit requests concerning your rights:
Through the KVKK Application Form available on our website,
By sending a wet-signed application by post/courier, or
Via registered electronic mail (KEP) or an e-mail address previously registered in our systems to kvkk@serenityhotels.com.
Applications are finalized free of charge within the statutory period of no later than 30 days. However, where processing of the request incurs an additional cost, a fee determined by the competent authority may be charged.
Security and Protection of Personal Data
Serenity Hotels implements technical and organizational measures to ensure a high level of security for personal data. Data security is regarded not only as a legal obligation but also as a corporate responsibility and quality standard.
Technical Measures
Data encryption: Critical data flows and databases are protected using strong encryption technologies.
Secure access: Personal data may be accessed only by authorized personnel through appropriate authentication mechanisms.
Penetration testing and vulnerability assessments: Information systems are regularly tested to identify and remedy potential vulnerabilities.
CCTV systems: Camera systems used within the hotel are operated solely for security purposes, and appropriate privacy notices are provided.
Data Loss Prevention (DLP): Software solutions may be implemented to prevent unauthorized data transfers.
Organizational Measures
Authorization matrix: Access to personal data is restricted according to job descriptions and business requirements.
Training: Employees receive regular training on data protection and privacy awareness.
Confidentiality undertakings and agreements: Data security obligations are included in agreements with business partners, suppliers and employees.
Audits: Data protection practices are periodically reviewed through internal audit mechanisms.
Personal Data Breach Notification
Where Serenity Hotels identifies a personal data security breach, necessary notifications are made in accordance with Article 12 of the KVKK and Articles 33 and 34 of the GDPR.
Within this scope:
The nature of the breach, number of affected individuals and potential consequences are assessed.
Notifications to the competent authorities are made within the periods required by applicable legislation.
Affected data subjects are informed through our communication channels where required by applicable law and the nature of the breach.
Technical and organizational measures are reviewed and strengthened to prevent recurrence.
Measures taken and notifications made during this process are documented and periodically reviewed.
E-Invoice and E-Archive Data
Serenity Hotels operates in accordance with the Turkish Tax Procedure Law No. 213 (VUK) and applicable electronic invoicing legislation and issues e-invoices and e-archive invoices to guests where applicable.
Within this scope:
Your e-mail address may be used for sending invoices through secure infrastructure integrated with electronic invoicing systems.
E-invoice and e-archive records are retained for the periods required by applicable tax legislation and are accessible only to authorized personnel.
Such data is used solely for invoicing purposes and is not shared with third parties for marketing purposes.
Automated Decision-Making
Serenity Hotels does not make decisions producing legal or similarly significant effects on individuals solely on the basis of automated processing. Automated decision-making and profiling processes, where applicable, are supported by assessments involving human intervention. In accordance with Article 22 of the GDPR, where a decision is based solely on automated systems, the data subject will be appropriately informed and provided with applicable rights to object, request human intervention and seek review of the decision.
Legal Responsibilities and Administrative Sanctions
Serenity Hotels fulfils its obligations regarding the protection of personal data in accordance with the KVKK and applicable secondary legislation and implements appropriate technical and organizational measures for data security. Administrative sanctions may be imposed by the Turkish Personal Data Protection Board for violations of obligations under the KVKK. Serenity Hotels implements internal audit procedures, provides regular awareness training to employees and continuously reviews its data protection policies in order to prevent such violations.
Transfer of Personal Data (Domestic and International)
Serenity Hotels complies with applicable obligations under the KVKK and GDPR when transferring personal data to third parties.
Domestic Transfers
Personal data may be transferred to the following parties within the framework of KVKK Art. 8 and subject to appropriate security measures:
Group companies and affiliates,
Authorized business partners involved in reservation and operational processes,
Electronic communication service providers and marketing companies where the required consent exists,
Professional advisers such as accountants, legal advisers and audit firms,
Public institutions and authorities where required by law, including law enforcement authorities and courts.
International Transfers
Personal data may be transferred internationally in accordance with GDPR requirements and KVKK Art. 9 where an appropriate legal transfer mechanism exists.
Recipients may include:
Cloud computing and reservation infrastructure providers, including hosting and CRM providers,
E-mail marketing and survey providers,
International loyalty program partners and business partners,
Other third-party technology providers engaged to process personal data.
Safeguards Relating to Transfers
Security measures used during data transfers may include:
Data processing agreements and confidentiality undertakings,
European Commission-approved Standard Contractual Clauses (SCCs), where applicable,
Encryption and secure transfer protocols such as VPN, TLS and SSL,
Limiting transferred data to what is necessary for the relevant processing purpose.
Rights of Data Subjects (KVKK and GDPR)
Serenity Hotels recognizes the rights of personal data subjects under Article 11 of the KVKK and Articles 12-23 of the GDPR.
Rights Under the KVKK
As a data subject, you have the right to:
Learn whether your personal data is being processed,
Request information where your personal data has been processed,
Learn the purpose of processing and whether your personal data is used in accordance with that purpose,
Know the third parties to whom your personal data has been transferred domestically or internationally,
Request correction of incomplete or inaccurate personal data,
Request deletion or destruction pursuant to KVKK Art. 7,
Request notification of such actions to third parties to whom the data has been transferred,
Object to an adverse result arising from the analysis of personal data exclusively through automated systems,
Claim compensation where you suffer damage due to unlawful processing.
Rights Under the GDPR
For guests subject to European Union data protection legislation, GDPR rights include:
Right of Access: Obtain access to personal data processed about you,
Right to Rectification: Request correction of inaccurate or incomplete data,
Right to Erasure: Request deletion under the "right to be forgotten",
Restriction of Processing: Request restriction of processing under applicable conditions,
Data Portability: Receive personal data in a structured, commonly used format and transmit it to another controller where applicable,
Right to Object: Object to processing under applicable circumstances,
Automated Decision-Making: Exercise rights relating to decisions based on automated processing and profiling,
Withdrawal of Consent: Withdraw consent at any time where processing is based on consent,
Right to Lodge a Complaint: Submit a complaint to a competent data protection supervisory authority.
Serenity Hotels does not make decisions concerning guests that produce legal or similarly significant effects solely through automated processing. Human involvement and, where appropriate, manual review form part of relevant assessment and decision-making processes.
Application Method
To exercise your rights, you may complete the application form available on Serenity Hotels' official website or contact us following appropriate identity verification through the following channels:
E-mail: kvkk@serenityhotels.com
Address: Serenity Hotels, Konaklı Mah. Nergis Sok. No:1 Alanya / Antalya
Cookie Policy
Serenity Hotels uses cookies to improve the experience of visitors to our website, provide ease of use and offer personalized services. Cookies are used in accordance with the KVKK and GDPR.
What Is a Cookie?
Cookies are small text files stored on your device through your web browser that enable a website to recognize your device or browser. They may collect information about how you use our website and help us customize your experience.
Types of Cookies Used
Our website may use the following categories of cookies:
Necessary Cookies: Required for the website's basic functions, including session management, security and network management.
Functional Cookies: Help the website remember your preferences, such as language selection.
Performance and Analytics Cookies: Used to analyze visitor behavior and improve website performance.
Targeting/Advertising Cookies: Used to provide content and advertising relevant to your interests. These cookies may be placed by third parties.
Third-Party Cookies
Cookies may be used through third-party analytics and marketing providers such as Google Analytics and Meta/Facebook services. Such technologies may help us understand visitor behavior and optimize our marketing activities, subject to applicable consent requirements.
Managing Cookies
When visiting our website, you may specify your cookie preferences and subsequently modify them. You may also disable cookies through your browser settings. However, disabling necessary cookies may prevent certain parts of the website from functioning properly.
Explicit Consent and Legal Basis
Cookies requiring consent are processed only after the required consent has been obtained. You may withdraw your consent and update your cookie preferences at any time.
Privacy Notices and Explicit Consent Processes
Serenity Hotels embraces transparency in all activities relating to the protection of personal data. Informing data subjects and obtaining explicit consent where required are integral parts of our legal compliance processes.
Obligation to Provide Information
Pursuant to Article 10 of the KVKK and Articles 13 and 14 of the GDPR, data subjects are provided with privacy notices containing information including:
The identity of the data controller and, where applicable, its representative,
The purposes for which personal data will be processed,
The recipients and purposes of any data transfers,
The method and legal basis for collecting personal data,
Rights of the data subject under KVKK Art. 11 and the GDPR.
Such privacy notices are provided separately for guests, employees, suppliers, business partners and visitors, where appropriate, at the point of data collection and through the relevant channel.
Privacy Notices:
Please click here for the Guest Privacy Notice.
Please click here for the Employee Privacy Notice.
Please click here for the Supplier – Business Partner Privacy Notice.
CCTV Privacy Notices:
Please click here for the Guest CCTV Privacy Notice.
Please click here for the Employee CCTV Privacy Notice.
Please click here for the Supplier CCTV Privacy Notice.
Policies:
Please click here for the Personal Data Processing and Protection Policy.
Please click here for the Personal Data Retention and Disposal Policy.
Application Form:
Please click here for the KVKK Application Form.
Situations Requiring Explicit Consent
Where processing requires explicit consent under applicable legislation, a separate consent mechanism is used. This may include, depending on the relevant processing activity:
Marketing, promotional and campaign communications,
Profiling and personalized services,
Use of third-party advertising cookies,
Processing of special categories of personal data such as health, disability and allergy information where consent is the applicable legal basis,
International data transfers where consent is relied upon as the applicable transfer mechanism.
Withdrawal of Explicit Consent
A data subject may withdraw previously provided consent at any time. Following withdrawal, processing based solely on that consent will cease, without affecting the lawfulness of processing carried out before withdrawal or processing based on another valid legal basis. Withdrawal may be made through a data subject request or available consent-management tools.
Application and Complaint Process
Data subjects may submit requests concerning their rights under Article 11 of the KVKK and Articles 15-22 of the GDPR to Serenity Hotels.
Application Methods
Applications may be submitted through one of the following methods:
E-mail: Via registered electronic mail (KEP) or an e-mail address registered in our systems to kvkk@serenityhotels.com,
Post: By sending a signed application form using an appropriate postal method,
In Person: By applying personally at Serenity Hotels facilities, subject to appropriate identity verification.
Applications may be submitted using the "KVKK Application Form", which can be obtained from our website or hotel reception desks.
Response Period
Applications are processed free of charge within no later than 30 days. Where processing the request incurs additional costs, fees permitted under applicable legislation may be charged.
Right to Lodge a Complaint
Under the KVKK, where an application is rejected or is not answered within the applicable statutory period, the data subject may have the right to lodge a complaint with the Turkish Personal Data Protection Board subject to the conditions and time limits prescribed by law. Under the GDPR, the data subject may lodge a complaint with the competent supervisory authority.
Changes to the Privacy Policy
Serenity Hotels may update this Privacy Policy from time to time as a result of changes in legislation, updates to the scope of services or revisions to data processing activities.
Tracking Updates
The date on which this Policy was last updated is stated at the end of the document. The most recent version is always published at https://serenityhotels.com/tr/kvkk-politikasi.html. Previous versions may be provided upon request.
Notification Methods
Material changes to our Privacy Policy may be communicated to relevant individuals by e-mail, SMS, mobile application notifications or on-site notices. They may also be published on our website as a "Policy Update" notice. This allows data subjects to remain informed of significant changes that may affect their rights.
Third-Party Websites and Disclaimer
The Serenity Hotels website may contain links to third-party websites to enhance the user experience.
External Links
Such links are provided for informational purposes. The privacy practices of third-party websites are outside the control of Serenity Hotels. Users are encouraged to review the privacy policies and cookie settings of third-party websites before providing personal data.
Disclaimer
Serenity Hotels is not responsible for the content, data processing activities or security practices of third-party websites, to the extent permitted by applicable law. Users should exercise appropriate care before providing personal data on external websites.
Surveys and Marketing Communications
Under Turkish Law No. 6563 on the Regulation of Electronic Commerce, Serenity Hotels sends surveys and commercial electronic communications only in accordance with applicable consent and communication rules.
Communications may be used to measure service quality, improve the customer experience and provide promotional information. Personal data processed for these purposes may be shared with survey service providers only to the extent necessary for the stated purpose. Where only an e-mail address is shared for a survey process, it may be retained for no longer than two months and subsequently deleted.
Guests may opt out of such communications and update their communication preferences by contacting kvkk@serenityhotels.com or using other available opt-out mechanisms.
Automated Data Processing and Profiling
Serenity Hotels may process and analyze certain personal data through automated means in order to improve the user experience, enhance service quality and provide personalized offers, in accordance with the KVKK and GDPR.
Sources used in automated data processing may include:
Website and mobile application usage: Pages visited, clicks, session duration, device and browser information, language preferences and IP address.
Loyalty program data: Reservation history, frequency of stays, campaign interactions and spending amounts.
Security systems: Entry and exit records and relevant security records.
Survey results and digital interactions: Preferences, feedback and segmentation information.
Such data may be analyzed for purposes including:
Personalization of services, such as room preferences, dining preferences and SPA usage
Targeted campaigns and discount suggestions where legally permitted
Segmentation according to loyalty levels
Optimization of website and application interfaces
For profiling activities:
Segment-based advertising and marketing content requiring consent is provided only where the necessary consent has been obtained. Decisions producing legal or similarly significant effects are not made solely through automated processing.
Users may exercise applicable rights to obtain information about profiling, object to processing and request deletion of relevant data where the legal requirements are met.
Information Regarding the IYS System
Commercial Electronic Message Management System (İYS)
Serenity Hotels sends commercial electronic communications in accordance with Turkish Law No. 6563 on the Regulation of Electronic Commerce and applicable regulations.
Within this scope, commercial communications such as campaign announcements, surveys and promotions sent through the following channels may be recorded and managed through the İleti Yönetim Sistemi (İYS):
SMS
E-mail
Telephone calls
Other electronic communications
Through the İYS system, users may:
View their current communication permissions,
Withdraw permissions for individual communication channels,
Manage their commercial electronic communication preferences.
Official platform: https://iys.org.tr
Data Security:
Permission data and contact information are processed through appropriate systems and protected in accordance with applicable data protection legislation. Commercial electronic communications requiring consent are not sent without the required approval.
Digital Application Conversations and Message Retention
Serenity Hotels uses digital technologies to improve guest satisfaction. Correspondence conducted through mobile applications, WhatsApp groups and internal hotel written communication platforms may be recorded to improve service quality, track transaction history and resolve potential disputes.
Digital channels within this scope may include:
Mobile application messaging panels
WhatsApp group/private conversations
Hotel digital assistant modules
Loyalty application messaging systems
Recording and Retention Conditions:
Correspondence is retained only for as long as required for service delivery and for a maximum of one year in secure systems.
Messages are protected through access controls so that they can be accessed only by authorized departmental personnel.
Guests are provided with appropriate privacy information at the beginning of the relevant communication process, and consent is obtained where required.
Data Security:
Recorded messages are stored using appropriate security safeguards and auditable logging mechanisms.
Message content is used solely for purposes such as fulfilling guest requests, analyzing complaints and measuring service quality.
It is not used for unrelated marketing purposes and is shared with third parties only where a valid legal basis and operational necessity exist.
Where legitimate interest is relied upon, processing is carried out pursuant to KVKK Art. 5/2-f and GDPR Art. 6(1)(f), subject to the data subject's applicable right to object.
Right to Object to Profiling and Automated Decision-Making
Under GDPR Articles 21 and 22 and applicable KVKK provisions, data subjects have specific rights relating to profiling and decisions based solely on automated processing.
Right to Object to Profiling
A data subject has the right to object to the use of personal data for profiling connected with direct marketing. Where the objection concerns direct marketing, processing for such purposes will cease in accordance with applicable law.
Right to Object to Automated Decision-Making
Serenity Hotels does not use decision-making processes based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect individuals.
If such processing is introduced in the future, data subjects will be provided with applicable safeguards, which may include the right to request human intervention, express their point of view and contest the decision.
Policy Update and Revision Information
This Privacy Policy may be revised from time to time due to changes in legislation or updates to the scope of services. The date of the latest update and revision number are provided below:
Last Updated: 24.09.2026
Revision No: 00
Reservation - +90 242 212 01 02
info@serenityhotels.com