SWISSOTEL THE BOSPHORUS, ISTANBUL, ANADOLU JAPAN TURİZM A.Ş. DISCLOSURE TEXT ON THE PROCESSING OF PERSONAL DATA
This Disclosure Text has been prepared in order to set out the details regarding the processing, in accordance with Law No. 6698 on the Protection of Personal Data (the “Law”), of the personal data you have shared with Anadolu Japan Turizm A.Ş. (Swissotel The Bosphorus, Istanbul), acting as data controller.
INFORMATION REGARDING THE LAW ON THE PROTECTION OF PERSONAL DATA
Our operating group company AccorResort and our workplace Anadolu Japan Turizm A.Ş. (Swissotel The Bosphorus, Istanbul) take the highest possible level of security measures in order to ensure that your personal data are collected, stored and shared in accordance with the law and to protect your privacy.
Our aim is to inform you, in the most transparent manner and in line with your satisfaction, pursuant to Article 10 of Law No. 6698 on the “Protection of Personal Data”, about the ways in which your personal data are obtained, the purposes of processing, the persons with whom they are shared, the legal grounds, and your rights.
Pursuant to Law No. 6698 on the Protection of Personal Data (“Law No. 6698”), your personal data will be collected and may be processed, within the scope described below, by Swissotel Hotels & Resorts (“Swissotel”) as the data controller.
The Personal Information we collect may include:
Personal data may be collected in various situations, including the following:
ç) For What Purposes Personal Data Will Be Processed
Swissotel may collect personal data in the categories listed above from parties such as potential customers, guests, job applicants, employees, business partners, travel agencies, tour operators and suppliers.
Your personal data collected are processed for the following purposes, within the personal data processing conditions and purposes set out in Articles 5 and 6 of Law No. 6698:
Your personal data collected, limited to the realisation of the purposes stated above, may be transferred, within the scope of the personal data processing conditions and purposes set out in Articles 8 and 9 of Law No. 6698, to the following:
ç) Method and Legal Basis of Personal Data Collection
Your personal data are collected:
particularly through other channels that may be established/arise, your personal data are collected by Swissotel within the framework of applicable legislation, for the purposes stated above, provided that this is directly related to the establishment or performance of a contract, is mandatory for the fulfilment of our legal obligation, and within the scope of the other exceptions set out in Article 5 of the Law.
As personal data owners, if you submit your requests regarding your rights using the methods set out below, Swissotel will conclude the request as soon as possible and within thirty days at the latest, depending on the nature of the request.
No fee will be charged for a response of up to ten pages. A processing fee of 1 Turkish Lira will be charged for each page over ten pages. If the response to the application is to be provided on a recording medium such as a CD or flash drive, the fee that may be requested by our company will not exceed the cost of the recording medium.
In this context, personal data owners have the right to:
You may submit your request regarding the exercise of your rights above, in Turkish and in writing, or by using a registered electronic mail (KEP) address, secure electronic signature, mobile signature, or the e-mail address previously notified to Swissotel and registered in our system, in accordance with Article 13(1) of Law No. 6698 and the Communiqué on the Procedures and Principles of Application to the Data Controller dated 10.03.2018 and numbered 30356.
Swissotel reserves the right to verify your identity before responding.
Your application must contain:
and any relevant information and documents concerning the subject must also be attached to the application.
You may send your written applications, together with the required documents, by registered mail with return receipt to our Company, as data controller, at the following address: Vişnezade Mah. Acısu Sok. No:19 Beşiktaş, Maçka, Istanbul.
You may submit your applications by e-mail to kvkk.istanbul@swissotel.com. You may submit your applications via KEP to our KEP address anadolujapan@hs03.kep.tr.
Depending on the nature of your request, the information and documents must be provided to us completely and accurately. If the requested information and documents are not provided properly, Swissotel may experience difficulties in conducting the investigations to be carried out in response to your request in a complete and qualified manner. In this case, Swissotel declares that it reserves its legal rights. For this reason, your application must be sent in a manner that includes complete information and the requested documents, depending on the nature of your request.
Your request will be evaluated by Swissotel The Bosphorus, Istanbul and concluded, as prescribed under the Law, within 30 (thirty) days at the latest. Although, as a general rule, no fee is charged for requests, Swissotel The Bosphorus, Istanbul reserves the right to charge a fee based on the tariff of fees determined by the Personal Data Protection Board.
CCTV / SECURITY CAMERA DISCLOSURE TEXT Pursuant to Law No. 6698 on the Protection of Personal Data
This CCTV / Security Camera Disclosure Text has been prepared by Anadolu Japan Turizm A.Ş. (the “Company”), as the data controller, pursuant to Law No. 6698 on the Protection of Personal Data (“KVKK”) and the relevant legislation.
The data controller’s information is as follows:
Anadolu Japan Turizm A.Ş. Address: Vişnezade Mah. Acısu Sok. No: 19 34357 Beşiktaş – Istanbul
E-mail: istanbul@swissotel.com Website: www.swissotel.com.tr/istanbul
This Disclosure Text has been prepared in order to inform data subjects about the personal data processing activities carried out through camera systems at the Company’s workplaces, offices, operation areas, entry-exit points, common-use areas, and other physical areas equipped with a security camera system.
This Disclosure Text applies to employees, job candidates, interns, visitors, representatives of suppliers/business partners, service provider personnel, customers, guests, and other natural persons present in the areas where camera recording is carried out.
The security cameras used by the Company are used solely for specific, explicit and legitimate purposes. The camera systems are not used for the continuous monitoring of employees, the general measurement of work efficiency, performance evaluation, ensuring discipline, or the general and continuous monitoring of employee attendance.
The following categories of personal data may be processed through the security camera systems:
Visual records: camera footage, the physical appearance of the person, the person’s movements as reflected in the camera recording, and the date, time and location information reflected in the camera recording.
Physical premises security information: entry-exit to the workplace, presence in certain areas, footage relating to security incidents, and incident information reflected in the security camera recordings.
Identity information: to the limited extent required, name, surname, title/position or visitor information that may need to be processed in connection with the camera recording, where the identity of the person appearing in the footage must be determined for the purposes of incident investigation, legal proceedings, an official authority’s request, or an internal security review.
The Company does not make audio recordings through the security cameras. The camera systems are used solely for the purpose of image recording. Even where a device with an audio-recording feature is used, this feature is not activated and no audio data are processed.
The security camera systems are used solely for the following purposes:
The camera systems are not used by the Company for the following purposes:
Camera recordings are not used for purposes other than the legitimate and limited purposes set out above; if processing for a different purpose becomes necessary, a new legal basis compliant with KVKK and, where necessary, a further information process will be applied.
Security cameras may be used by the Company, connected to, limited to and proportionate for the processing purpose, in the following areas:
Camera positions, viewing angles and recording scope are determined so as to be appropriate, necessary and proportionate to the monitoring purpose. Cameras are positioned so as to cover only the areas necessary for security and occupational health/safety purposes.
Security cameras are not used by the Company in the following areas:
The use of cameras in these areas may only be considered in very exceptional, legally mandatory, explicitly justified circumstances that have passed a proportionality test. In current practice, no camera recording is carried out in these areas.
Your personal data are processed through the camera systems based on the following legal grounds:
Within the scope of this legal ground, camera recordings may be processed for the purposes of occupational health and safety, workplace security, ensuring the security of employees and third parties, the employer’s duty of care, the obligation to provide a safe working environment, responding to official authority requests, and fulfilling obligations arising from legislation.
Within the scope of this legal ground, the relevant camera recordings may be processed in situations requiring the preservation of evidence, such as a security incident, work accident, damage, theft, assault, a concrete incident that may be subject to a disciplinary process, legal dispute, complaint, request, lawsuit, enforcement proceeding, or administrative/judicial application.
Within the scope of this legal ground, camera recordings may be processed for purposes such as ensuring the security of the physical premises, protecting the Company’s assets, preventing unauthorised entries, ensuring operational security, and protecting the security of employees, visitors and third parties.
As a rule, explicit consent is not relied upon for personal data processing activities carried out through the camera systems. The processing activity is carried out on the basis of the statutory processing conditions set out above. However, if it becomes necessary to use the camera system outside its current purpose and scope, the applicable legal ground will be separately assessed.
The data processing activities carried out through the camera systems are conducted in compliance with the relevant legislation, primarily KVKK.
In this context, the Company uses the camera systems taking into account:
its obligations under Article 417 of Turkish Code of Obligations No. 6098 to protect employees’ personal rights, to maintain an order in the workplace consistent with the principles of good faith, and to ensure occupational health and safety;
its obligations under Article 4 of the Occupational Health and Safety Law No. 6331 to monitor and audit compliance with occupational health and safety measures taken in the workplace and to ensure that non-compliances are remedied;
its obligations under Articles 4, 5, 10 and 12 of KVKK No. 6698 to process personal data in compliance with the law, to inform data subjects, and to ensure the security of personal data.
When processing personal data through the camera systems, the Company acts in accordance with the following basic principles set out in Article 4 of KVKK:
Within this framework, the camera systems are used in the areas necessary to achieve the purpose and to the extent necessary. The scope of monitoring, camera angle, recording period, access authorisations and retention period of the recordings are determined by taking the principle of proportionality into account.
The Company acts in accordance with the principle of data minimisation with respect to the use of the camera systems. The areas subject to camera recording are limited to the areas where there is a concrete need in terms of security or occupational health and safety.
The following matters are taken into account when determining the position, viewing angle, recording scope and recording period of the camera systems:
The Company avoids disproportionate camera use covering all areas of the workplace, monitoring activities of an intensity that would harm data subjects’ expectation of privacy, and camera positioning that cannot be justified on security grounds.
As a rule, camera recordings are kept accessible only to a limited number of authorised persons within the Company. Camera recordings are not shared with unauthorised third parties.
Your personal data may be transferred, in accordance with Article 8 of KVKK and the relevant legislation, only to the extent necessary and limited to the relevant purpose, to the following persons, institutions and organisations:
Transfers are made only on the basis of the relevant legal ground and to the extent required by the purpose. Camera recordings may not be transferred to third parties without authorisation, for purposes other than intended, or without authority.
As a rule, camera recordings are not transferred abroad.
Should the transfer of camera recordings abroad become an issue due to the technical infrastructure used, cloud service, centralised security system, group company access, maintenance/support service or a similar reason, such transfer will be separately assessed pursuant to Article 9 of KVKK and the relevant secondary legislation, and no transfer abroad will be made without the necessary legal mechanisms being put in place.
Camera recordings are retained for the period necessary for the purpose for which they are processed.
As a rule, camera recordings are retained by the Company for a period of 30 (thirty) days, at the end of which they are automatically deleted, destroyed, or disposed of by being overwritten with new recordings.
In the event of a concrete security incident, work accident, complaint, official authority request, legal dispute, disciplinary process, judicial/administrative investigation, or a situation necessary for the establishment, exercise or protection of a right, only the camera recordings connected with the relevant incident are separated and may be retained until the relevant process is concluded and the periods arising from legislation have expired.
It is essential that recordings are not retained for longer than necessary. The principles of data minimisation, proportionality and purpose limitation are taken into account when determining the retention period.
A systemic automatic deletion, overwriting or destruction mechanism is applied to the camera recordings.
Recordings whose retention period has expired are deleted, destroyed or anonymised in accordance with the Company’s Personal Data Retention and Destruction Policy and related internal procedures. Recordings separated on an incident basis are destroyed following the completion of the relevant legal, administrative or operational process.
Access to camera recordings is restricted on a need-to-know and duty basis. Not every employee has authority to access camera recordings.
Camera recordings may only be accessed by the following authorised persons or units:
Access authorisations are determined in writing, unnecessary access is prevented, and authorisations are periodically reviewed.
The Company takes the necessary technical and administrative measures to prevent camera recordings from being processed unlawfully, accessed unlawfully, or unlawfully disclosed.
Measures that may be applied in this context include the following:
Warning signs are placed in areas subject to camera recording so that data subjects can easily notice that camera recording is taking place.
The warning signs contain at least the following information:
The detailed Disclosure Text can be accessed through the Company’s website, a QR code, or the relevant physical/electronic application channels.
Your personal data are obtained by automatic means through the CCTV / security camera systems used by the Company.
The camera systems record, in electronic form, the images of persons present in the areas subject to recording. The records obtained through the camera systems may be stored in the Company’s technical infrastructure, recording devices, servers, or authorised secure systems.
Pursuant to Article 11 of KVKK, data subjects have the following rights regarding their personal data:
You may submit your applications and requests regarding your personal data to the Company through the following methods:
You may send your application, signed with a mobile signature or secure electronic signature, to anadolujapan@hs03.kep.tr.
You may send it, using your registered electronic mail address, secure electronic signature or mobile signature, to the Company’s registered electronic mail address: kvkk.istanbul@swissotel.com
You may apply, through the e-mail address registered in the Company’s systems, to istanbul@swissotel.com.
Your application must include your name, surname, signature (if the application is in writing), Turkish Republic identity number, and for foreign nationals your passport number or identity number if any, your residential or business address for notification purposes, your e-mail address and telephone number for notification purposes if any, and the subject of your request.
As a rule, the application must relate to the applicant. If an application is made on behalf of another person, the applicant must attach to the application a document showing that they are specifically authorised to do so.
Applications made by unauthorised third parties on behalf of another person will not be taken into consideration.
The Company concludes data subject applications, pursuant to KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller, as soon as possible and within thirty days at the latest.
Where the application requires an additional cost, a fee may be charged according to the tariff determined by the Personal Data Protection Board.
If your application is rejected, the response given is found insufficient, or no response is given within the time limit, you have the right to lodge a complaint with the Personal Data Protection Board within the procedures and time limits set out in KVKK.
The Company may update this Disclosure Text in the event of a change in the scope of the camera systems, the purposes of use, the retention periods, the transfer processes, or the relevant legislation.
Swissôtel The Bosphorus ☆☆☆☆☆
Visnezade Mah. Acisu Sok. N. 19, 34357 Macka Besiktas
Istanbul
Tel: +90 212 326 11 00
Email:
istanbul@swissotel.com