Swissôtel The Bosphorus - Luxury hotel - PRIVACY NOTICE ON PROCESSING OF PERSONAL DATA ISSUED BY SWİSSOTEL THE BOSPHORUS, İSTANBUL, ANADOLU JAPAN TURİZM A.Ş.

PRIVACY NOTICE ON PROCESSING OF PERSONAL DATA ISSUED BY SWİSSOTEL THE BOSPHORUS, İSTANBUL, ANADOLU JAPAN TURİZM A.Ş.


SWISSOTEL THE BOSPHORUS, ISTANBUL, ANADOLU JAPAN TURİZM A.Ş. DISCLOSURE TEXT ON THE PROCESSING OF PERSONAL DATA

This Disclosure Text has been prepared in order to set out the details regarding the processing, in accordance with Law No. 6698 on the Protection of Personal Data (the “Law”), of the personal data you have shared with Anadolu Japan Turizm A.Ş. (Swissotel The Bosphorus, Istanbul), acting as data controller.

INFORMATION REGARDING THE LAW ON THE PROTECTION OF PERSONAL DATA

Our operating group company AccorResort and our workplace Anadolu Japan Turizm A.Ş. (Swissotel The Bosphorus, Istanbul) take the highest possible level of security measures in order to ensure that your personal data are collected, stored and shared in accordance with the law and to protect your privacy.

Our aim is to inform you, in the most transparent manner and in line with your satisfaction, pursuant to Article 10 of Law No. 6698 on the “Protection of Personal Data”, about the ways in which your personal data are obtained, the purposes of processing, the persons with whom they are shared, the legal grounds, and your rights.

  1. a) Data Controller

Pursuant to Law No. 6698 on the Protection of Personal Data (“Law No. 6698”), your personal data will be collected and may be processed, within the scope described below, by Swissotel Hotels & Resorts (“Swissotel”) as the data controller.

  1. b) Which Personal Data Will Be Collected

The Personal Information we collect may include:

  • Identity Information (name, surname, gender, title, place and date of birth, nationality; passport, visa or other government-issued identification information);
  • Contact Information (home and business address, telephone number and e-mail address, and other contact information about you that we may obtain through third parties we work with, such as travel agencies or similar suppliers);
  • Your Preferences and Areas of Interest (hotels you have stayed at, your check-in and check-out dates, products and services purchased, special requests, information and observations regarding your service preferences, room type, preferred floor, type of newspaper/magazine, sports and cultural interests, facilities, holiday preferences, requested services, ages of children, or guest accommodation services including other aspects of the services used);
  • Telephone numbers dialed, faxes received/sent, or telephone messages received when guests connect to the telephone services we provide during their stay;
  • Credit card and debit card numbers;
  • Swissotel Loyalty Card information, online user account information, profile or password information, and other frequent-flyer or travel-partner programme information;
  • If you are an employee, dealer or other type of business partner of a corporate account, your employer information or other related information (e.g. travel agency or meeting and event organiser);
  • Profile picture;
  • Social media account ID or user ID;
  • If, in connection with the services, you provide us or our service providers with Personal Information relating to other persons (e.g. making a reservation on behalf of someone else), you thereby represent that you are authorised to do so and that you consent to that information being used in accordance with this disclosure.
  1. c) Through Which Processes Your Personal Data Will Be Collected

Personal data may be collected in various situations, including the following:

  • Hotel activities:
  • Room reservation
  • Check-in at the hotel and payment
  • Eating/drinking at the hotel bar or restaurant during a stay
  • Requests, complaints and/or disputes.
  • Participation in marketing programmes or events:
  • Enrolling in loyalty programmes
  • Participating in customer surveys (e.g. the Guest Satisfaction Survey)
  • Subscribing to newsletters in order to receive offers and promotions by e-mail.
  • Transmission of information from third parties:
  • Tour operators, travel agencies, reservation systems and others
  • Internet activities:
  • Connecting to Swissotel websites (IP addresses, cookies)
  • Online forms (online reservations, surveys, Swissotel pages on social networks)

ç) For What Purposes Personal Data Will Be Processed

Swissotel may collect personal data in the categories listed above from parties such as potential customers, guests, job applicants, employees, business partners, travel agencies, tour operators and suppliers.

Your personal data collected are processed for the following purposes, within the personal data processing conditions and purposes set out in Articles 5 and 6 of Law No. 6698:

  • To enable Swissotel products and services to be offered to you, to fulfil our obligations towards you, to prepare records and documents, and to comply with the information retention, reporting, notification, tax and other obligations required by local and international legislation;
  • To manage your hotel stay: monitoring your use of services (telephone, bar, pay-TV, etc.), managing access to rooms, internal administration of lists relating to guests who engage in inappropriate conduct during their stay at the hotel (aggressive or antisocial behaviour, non-compliance with the hotel agreement, non-compliance with security regulations, theft, damage and vandalism, or payment-related incidents);
  • To determine the availability of Swissotel services;
  • To offer you personalised advertising, campaigns, advantages and other benefits in connection with sales and marketing activities aimed at improving the quality of services and products;
  • To communicate with you for the purposes of IT requirements, systemic structure, the necessity of the IT support services received, and the transfer of information necessary in relation to these services and products;
  • To arrange Swissotel room reservations;
  • To carry out traffic measurement for sales and marketing activities, cross-checking of data collected during your reservation or stay in order to offer personalised offers, statistical analyses, segmentation/profiling and CRM activities;
  • To measure and increase customer satisfaction, manage complaints, obtain your views and suggestions regarding new services and products, receive your problem/error notifications, take into account the right to object, and inform you about Swiss Circle and other products and services and about your complaints and requests;
  • To use dedicated telephone services in order to contact persons staying at the Swiss Hotel in the event of serious incidents affecting the hotel concerned (natural disasters, terrorist attacks, etc.);
  • To take your orders, carry out your payment transactions, arrange product delivery through logistics cooperation with third parties, recommend products and services that may be of interest to you, carry out online behavioural advertising and marketing, customer portfolio management, measurement and improvement of service quality, communication, optimisation, audit, risk management and control, promotion, analysis, determination of interests, scoring, profiling, marketing, sales, advertising and communication;
  • For comparative product and/or service offers, modelling, existing or new product studies and/or developments, and to be used in any products and services to be offered to you within the scope of the laws and relevant legislation governing the matters set out in the Swissotel main agreement to which your disclosure of personal data to Swissotel is subject;
  • To comply with information retention, reporting and notification obligations prescribed by official authorities, to fulfil contractual requirements, and to perform Swissotel’s legal obligations relating to the benefit from these services;
  • To manage, for the purpose of determining and implementing Swissotel’s commercial and business strategies, the finance operations, communication, market research and social responsibility activities carried out by Swissotel, procurement operations (request, offer, evaluation, order, budgeting, contract), internal system and application management operations, and legal operations;
  • To examine, evaluate and respond to requests received from official authorities or from you.
  1. c) To Whom and For What Purposes the Processed Personal Data May Be Transferred

Your personal data collected, limited to the realisation of the purposes stated above, may be transferred, within the scope of the personal data processing conditions and purposes set out in Articles 8 and 9 of Law No. 6698, to the following:

  • Subsidiaries, affiliated companies, joint ventures, business partners and shareholders, including hotels or resorts operating under FRHI (Fairmont, Raffles) Hotels & Resorts, to which Swissotel’s group companies are affiliated;
  • Domestic and foreign hotels or resorts, for the purpose of forwarding your requests and demands to the hotels at which you have made a reservation domestically or abroad through the Swissotel website, call centre or other channels, together with your identity, contact and other necessary information;
  • Relevant institutions and organisations within the scope of the Tourism Incentive Law, the Law on Travel Agencies and the Association of Travel Agencies, and the Regulation on the Certification and Qualifications of Tourism Facilities;
  • Persons or organisations permitted under the Tax Procedure Law, Social Security Institution legislation, the Court of Accounts, the Law on the Prevention of Laundering of Proceeds of Crime, the Law on the Prevention of Money Laundering, the Turkish Commercial Code, the Code of Obligations and other legislative provisions;
  • Legally authorised public institutions and organisations, administrative authorities and judicial authorities;
  • Companies and affiliates abroad;
  • Real or legal persons from whom we receive services or with whom we cooperate for product/service comparison, analysis, evaluation, advertising and the realisation of the purposes stated above, programme-partner institutions and organisations, institutions with which we have agreements for sending communications to our customers, and cargo companies that deliver orders to you.

ç) Method and Legal Basis of Personal Data Collection

Your personal data are collected:

  • Through online services such as our website and affiliated websites: when you make a reservation or otherwise purchase products and services from us, when you contact us through online messaging services, when you inform us of your special requests or preferences, or when you subscribe to a newsletter, survey, contest or promotional offer.
  • Through any physical environment and customer service channel in which verbal and written information is shared: for example, when you visit one of our facilities, when you make a request in order to benefit from our services, when you inform us of your preferences, or when you make a reservation by telephone or contact customer services, we may collect Personal Information from you offline.
  • Through other sources such as our business partners, suppliers and travel agencies: we may obtain your Personal Information from other sources such as joint marketing partners and third parties. These may include information obtained from your travel agency, airline, credit card and other partners.
  • Through our social media accounts.

particularly through other channels that may be established/arise, your personal data are collected by Swissotel within the framework of applicable legislation, for the purposes stated above, provided that this is directly related to the establishment or performance of a contract, is mandatory for the fulfilment of our legal obligation, and within the scope of the other exceptions set out in Article 5 of the Law.

  1. d) Rights of the Personal Data Owner Set Out in Article 11 of Law No. 6698

As personal data owners, if you submit your requests regarding your rights using the methods set out below, Swissotel will conclude the request as soon as possible and within thirty days at the latest, depending on the nature of the request.

No fee will be charged for a response of up to ten pages. A processing fee of 1 Turkish Lira will be charged for each page over ten pages. If the response to the application is to be provided on a recording medium such as a CD or flash drive, the fee that may be requested by our company will not exceed the cost of the recording medium.

In this context, personal data owners have the right to:

  • Learn whether their personal data are being processed;
  • Request information as to whether their personal data have been processed;
  • Learn the purpose of processing of personal data and whether they are used in accordance with their purpose;
  • Know the third parties to whom personal data are transferred, domestically or abroad;
  • Request the correction of personal data if they have been processed incompletely or incorrectly, and request that this action be notified to third parties to whom personal data have been transferred;
  • Request the deletion or destruction of personal data in the event that the reasons requiring their processing no longer exist, even though they have been processed in accordance with Law No. 6698 and other relevant legal provisions, and request that this action be notified to third parties to whom personal data have been transferred;
  • Object to a result that is to their detriment arising from the analysis of the processed data exclusively through automated systems;
  • Request compensation for damages in the event that they suffer damage due to the unlawful processing of personal data.

You may submit your request regarding the exercise of your rights above, in Turkish and in writing, or by using a registered electronic mail (KEP) address, secure electronic signature, mobile signature, or the e-mail address previously notified to Swissotel and registered in our system, in accordance with Article 13(1) of Law No. 6698 and the Communiqué on the Procedures and Principles of Application to the Data Controller dated 10.03.2018 and numbered 30356.

Swissotel reserves the right to verify your identity before responding.

Your application must contain:

  • Your name, surname and, if the application is in writing, your signature;
  • Your Turkish Republic identity number if you are a Turkish citizen, or your nationality, passport number or identity number, if any, if you are a foreign national;
  • Your residential or business address for notification purposes;
  • Your e-mail address, telephone and fax number for notification purposes, if any;
  • The subject of your request,

and any relevant information and documents concerning the subject must also be attached to the application.

You may send your written applications, together with the required documents, by registered mail with return receipt to our Company, as data controller, at the following address: Vişnezade Mah. Acısu Sok. No:19 Beşiktaş, Maçka, Istanbul.

You may submit your applications by e-mail to kvkk.istanbul@swissotel.com. You may submit your applications via KEP to our KEP address anadolujapan@hs03.kep.tr.

Depending on the nature of your request, the information and documents must be provided to us completely and accurately. If the requested information and documents are not provided properly, Swissotel may experience difficulties in conducting the investigations to be carried out in response to your request in a complete and qualified manner. In this case, Swissotel declares that it reserves its legal rights. For this reason, your application must be sent in a manner that includes complete information and the requested documents, depending on the nature of your request.

Your request will be evaluated by Swissotel The Bosphorus, Istanbul and concluded, as prescribed under the Law, within 30 (thirty) days at the latest. Although, as a general rule, no fee is charged for requests, Swissotel The Bosphorus, Istanbul reserves the right to charge a fee based on the tariff of fees determined by the Personal Data Protection Board.

 

CCTV / SECURITY CAMERA DISCLOSURE TEXT Pursuant to Law No. 6698 on the Protection of Personal Data

  1. Data Controller

This CCTV / Security Camera Disclosure Text has been prepared by Anadolu Japan Turizm A.Ş. (the “Company”), as the data controller, pursuant to Law No. 6698 on the Protection of Personal Data (“KVKK”) and the relevant legislation.

The data controller’s information is as follows:

Anadolu Japan Turizm A.Ş. Address: Vişnezade Mah. Acısu Sok. No: 19 34357 Beşiktaş – Istanbul

E-mail: istanbul@swissotel.com Website: www.swissotel.com.tr/istanbul

This Disclosure Text has been prepared in order to inform data subjects about the personal data processing activities carried out through camera systems at the Company’s workplaces, offices, operation areas, entry-exit points, common-use areas, and other physical areas equipped with a security camera system.

  1. Scope of the Disclosure Text

This Disclosure Text applies to employees, job candidates, interns, visitors, representatives of suppliers/business partners, service provider personnel, customers, guests, and other natural persons present in the areas where camera recording is carried out.

The security cameras used by the Company are used solely for specific, explicit and legitimate purposes. The camera systems are not used for the continuous monitoring of employees, the general measurement of work efficiency, performance evaluation, ensuring discipline, or the general and continuous monitoring of employee attendance.

  1. Categories of Personal Data Processed

The following categories of personal data may be processed through the security camera systems:

Visual records: camera footage, the physical appearance of the person, the person’s movements as reflected in the camera recording, and the date, time and location information reflected in the camera recording.

Physical premises security information: entry-exit to the workplace, presence in certain areas, footage relating to security incidents, and incident information reflected in the security camera recordings.

Identity information: to the limited extent required, name, surname, title/position or visitor information that may need to be processed in connection with the camera recording, where the identity of the person appearing in the footage must be determined for the purposes of incident investigation, legal proceedings, an official authority’s request, or an internal security review.

The Company does not make audio recordings through the security cameras. The camera systems are used solely for the purpose of image recording. Even where a device with an audio-recording feature is used, this feature is not activated and no audio data are processed.

  1. Purposes of Use of the Camera Systems

The security camera systems are used solely for the following purposes:

  • Ensuring the security of the workplace and physical premises.
  • Protecting the life and property security of employees, visitors, customers and third parties.
  • Ensuring the security of the Company’s buildings, facilities, equipment, documents, information systems, operation areas and other assets.
  • Preventing, detecting and, where necessary, investigating unauthorised entries, security breaches, theft, damage, sabotage, attacks or similar unlawful acts.
  • Fulfilling occupational health and safety obligations, helping to prevent work accidents, and investigating incidents that occur.
  • Ensuring a safe working environment in areas involving operational security risks.
  • Retaining, to the extent limited to the relevant process, records that may constitute evidence in the event of a legal dispute, audit, official authority request, or judicial or administrative proceeding, and sharing them with the competent authorities.
  • Fulfilling the data controller’s legal obligations.
  • Using the relevant records where necessary for the establishment, exercise or protection of a right.
  • Protecting the Company’s legitimate interests within the scope of physical security and operational security, provided that this does not harm the fundamental rights and freedoms of data subjects.
  1. Purposes for Which the Camera Systems Are Not Used

The camera systems are not used by the Company for the following purposes:

  • Monitoring employees’ general performance.
  • Evaluating, through continuous surveillance, whether employees are working efficiently.
  • Exerting continuous pressure or discipline on employees.
  • Measuring employees’ attendance at work through general and continuous camera tracking.
  • Continuously and intensively monitoring individuals in a manner that would interfere with the privacy of their private life.
  • Recording footage in areas with a high expectation of privacy.

Camera recordings are not used for purposes other than the legitimate and limited purposes set out above; if processing for a different purpose becomes necessary, a new legal basis compliant with KVKK and, where necessary, a further information process will be applied.

  1. Areas Where Cameras Are Located

Security cameras may be used by the Company, connected to, limited to and proportionate for the processing purpose, in the following areas:

  • Building and facility entry-exit points.
  • Reception, greeting and waiting areas.
  • Corridors and common passage areas.
  • Car park, garden, external surroundings and the area around the building.
  • Warehouse, archive, technical areas and areas with operational security risk.
  • Areas where safes, deposit boxes, valuables, critical equipment or sensitive operational assets are located.
  • Entry-exit points of areas that need to be protected in terms of information systems, servers, technical infrastructure or operational security.
  • Production, operation, maintenance, technical service or similar working areas with occupational health and safety risk.

Camera positions, viewing angles and recording scope are determined so as to be appropriate, necessary and proportionate to the monitoring purpose. Cameras are positioned so as to cover only the areas necessary for security and occupational health/safety purposes.

  1. Areas Where Cameras Are Not Used

Security cameras are not used by the Company in the following areas:

  • Changing rooms.
  • Prayer rooms.
  • Rest areas.
  • Nursing/breastfeeding rooms.
  • Health/examination rooms.

The use of cameras in these areas may only be considered in very exceptional, legally mandatory, explicitly justified circumstances that have passed a proportionality test. In current practice, no camera recording is carried out in these areas.

  1. Legal Grounds

Your personal data are processed through the camera systems based on the following legal grounds:

  • KVKK Art. 5/2(ç): it being mandatory for the data controller to fulfil its legal obligation.

Within the scope of this legal ground, camera recordings may be processed for the purposes of occupational health and safety, workplace security, ensuring the security of employees and third parties, the employer’s duty of care, the obligation to provide a safe working environment, responding to official authority requests, and fulfilling obligations arising from legislation.

  • KVKK Art. 5/2(e): data processing being mandatory for the establishment, exercise or protection of a right.

Within the scope of this legal ground, the relevant camera recordings may be processed in situations requiring the preservation of evidence, such as a security incident, work accident, damage, theft, assault, a concrete incident that may be subject to a disciplinary process, legal dispute, complaint, request, lawsuit, enforcement proceeding, or administrative/judicial application.

  • KVKK Art. 5/2(f): it being mandatory to process data for the data controller’s legitimate interests, provided that this does not harm the fundamental rights and freedoms of the data subject.

Within the scope of this legal ground, camera recordings may be processed for purposes such as ensuring the security of the physical premises, protecting the Company’s assets, preventing unauthorised entries, ensuring operational security, and protecting the security of employees, visitors and third parties.

As a rule, explicit consent is not relied upon for personal data processing activities carried out through the camera systems. The processing activity is carried out on the basis of the statutory processing conditions set out above. However, if it becomes necessary to use the camera system outside its current purpose and scope, the applicable legal ground will be separately assessed.

  1. Relevant Legislation and Employer Obligations

The data processing activities carried out through the camera systems are conducted in compliance with the relevant legislation, primarily KVKK.

In this context, the Company uses the camera systems taking into account:

its obligations under Article 417 of Turkish Code of Obligations No. 6098 to protect employees’ personal rights, to maintain an order in the workplace consistent with the principles of good faith, and to ensure occupational health and safety;

its obligations under Article 4 of the Occupational Health and Safety Law No. 6331 to monitor and audit compliance with occupational health and safety measures taken in the workplace and to ensure that non-compliances are remedied;

its obligations under Articles 4, 5, 10 and 12 of KVKK No. 6698 to process personal data in compliance with the law, to inform data subjects, and to ensure the security of personal data.

  1. Basic Principles Observed in the Processing of Personal Data

When processing personal data through the camera systems, the Company acts in accordance with the following basic principles set out in Article 4 of KVKK:

  • Compliance with the law and the rule of good faith.
  • Being accurate and, where necessary, up to date.
  • Being processed for specified, explicit and legitimate purposes.
  • Being relevant to, limited to and proportionate for the purposes for which they are processed.
  • Being retained for the period prescribed by relevant legislation or required for the purpose for which they are processed.

Within this framework, the camera systems are used in the areas necessary to achieve the purpose and to the extent necessary. The scope of monitoring, camera angle, recording period, access authorisations and retention period of the recordings are determined by taking the principle of proportionality into account.

  1. Proportionality and Data Minimisation

The Company acts in accordance with the principle of data minimisation with respect to the use of the camera systems. The areas subject to camera recording are limited to the areas where there is a concrete need in terms of security or occupational health and safety.

The following matters are taken into account when determining the position, viewing angle, recording scope and recording period of the camera systems:

  • Whether the use of the camera is suitable for the specified purpose.
  • Whether the same purpose could be achieved through a less intrusive method.
  • Whether the use of the camera is necessary.
  • Whether the effect on data subjects’ private life and expectation of privacy is proportionate.
  • Whether the scope of monitoring is broader than necessary.
  • Whether face-focused, zoomed-in, or continuous and intensive surveillance-type recording is necessary.

The Company avoids disproportionate camera use covering all areas of the workplace, monitoring activities of an intensity that would harm data subjects’ expectation of privacy, and camera positioning that cannot be justified on security grounds.

  1. Transfer of Personal Data

As a rule, camera recordings are kept accessible only to a limited number of authorised persons within the Company. Camera recordings are not shared with unauthorised third parties.

Your personal data may be transferred, in accordance with Article 8 of KVKK and the relevant legislation, only to the extent necessary and limited to the relevant purpose, to the following persons, institutions and organisations:

  • Competent public institutions and organisations.
  • Courts, public prosecutors’ offices, law enforcement units and other judicial/administrative authorities.
  • Official authorities empowered under the relevant legislation to request information or documents.
  • Legal advisors, lawyers and, where necessary, advisors supporting the conduct of judicial/administrative proceedings.
  • Security service providers, technical service providers, camera system maintenance and support service providers, and information technology service providers.

Transfers are made only on the basis of the relevant legal ground and to the extent required by the purpose. Camera recordings may not be transferred to third parties without authorisation, for purposes other than intended, or without authority.

  1. Transfer Abroad

As a rule, camera recordings are not transferred abroad.

Should the transfer of camera recordings abroad become an issue due to the technical infrastructure used, cloud service, centralised security system, group company access, maintenance/support service or a similar reason, such transfer will be separately assessed pursuant to Article 9 of KVKK and the relevant secondary legislation, and no transfer abroad will be made without the necessary legal mechanisms being put in place.

  1. Retention Period

Camera recordings are retained for the period necessary for the purpose for which they are processed.

As a rule, camera recordings are retained by the Company for a period of 30 (thirty) days, at the end of which they are automatically deleted, destroyed, or disposed of by being overwritten with new recordings.

In the event of a concrete security incident, work accident, complaint, official authority request, legal dispute, disciplinary process, judicial/administrative investigation, or a situation necessary for the establishment, exercise or protection of a right, only the camera recordings connected with the relevant incident are separated and may be retained until the relevant process is concluded and the periods arising from legislation have expired.

It is essential that recordings are not retained for longer than necessary. The principles of data minimisation, proportionality and purpose limitation are taken into account when determining the retention period.

  1. Destruction and Automatic Deletion Mechanism

A systemic automatic deletion, overwriting or destruction mechanism is applied to the camera recordings.

Recordings whose retention period has expired are deleted, destroyed or anonymised in accordance with the Company’s Personal Data Retention and Destruction Policy and related internal procedures. Recordings separated on an incident basis are destroyed following the completion of the relevant legal, administrative or operational process.

  1. Access to Camera Recordings

Access to camera recordings is restricted on a need-to-know and duty basis. Not every employee has authority to access camera recordings.

Camera recordings may only be accessed by the following authorised persons or units:

  • Authorised personnel responsible for security.
  • Persons authorised within the scope of administrative affairs or facility management.
  • Authorised persons responsible for information technology or technical infrastructure support.
  • The legal, compliance, human resources or occupational health and safety units, only where there is a concrete incident, request, investigation or legal process, and limited to their duties.
  • Senior management or authorised managers, only where there is a concrete security matter, legal process or operational necessity.

Access authorisations are determined in writing, unnecessary access is prevented, and authorisations are periodically reviewed.

  1. Technical and Administrative Measures

The Company takes the necessary technical and administrative measures to prevent camera recordings from being processed unlawfully, accessed unlawfully, or unlawfully disclosed.

Measures that may be applied in this context include the following:

  • Restricting access authorisations to camera recordings.
  • Creating an authorisation matrix.
  • Determining authorised users and periodically reviewing authorisations.
  • Providing access to recording systems through strong passwords and user authorisation.
  • Applying physical and electronic security measures to prevent unauthorised access.
  • Ensuring the physical security of the devices, servers or recording media on which camera recordings are stored.
  • Preventing camera recordings from being shared with unauthorised persons.
  • Subjecting incident-based record extraction, copying or sharing processes to authorisation.
  • Recording, to the extent possible, access, viewing, export or sharing processes relating to the recordings.
  • Subjecting the access of technical service or security service providers to contractual and technical restrictions.
  • Automatically deleting or overwriting camera recordings at the end of the retention period.
  • Informing employees and relevant authorised persons about the protection of personal data.
  • Establishing internal procedures relating to the camera systems.
  • Operating the necessary internal notification and response processes in the event of unlawful processing, unauthorised access, or risk of a data breach relating to camera recordings.
  1. Camera Warning Signs and Layered Notice

Warning signs are placed in areas subject to camera recording so that data subjects can easily notice that camera recording is taking place.

The warning signs contain at least the following information:

  • That the areas are monitored by a camera system.
  • The title of the data controller.
  • The main purpose of the use of the camera.
  • The method of accessing the detailed disclosure text.
  • The communication or application channel.

The detailed Disclosure Text can be accessed through the Company’s website, a QR code, or the relevant physical/electronic application channels.

  1. Method of Obtaining Personal Data

Your personal data are obtained by automatic means through the CCTV / security camera systems used by the Company.

The camera systems record, in electronic form, the images of persons present in the areas subject to recording. The records obtained through the camera systems may be stored in the Company’s technical infrastructure, recording devices, servers, or authorised secure systems.

  1. Rights of Data Subjects

Pursuant to Article 11 of KVKK, data subjects have the following rights regarding their personal data:

  • Learn whether their personal data are processed.
  • Request information as to whether their personal data have been processed.
  • Learn the purpose of processing of personal data and whether they are used in accordance with their purpose.
  • Know the third parties to whom personal data are transferred, domestically or abroad.
  • Request the correction of personal data if they have been processed incompletely or incorrectly.
  • Request the deletion or destruction of personal data within the framework of KVKK and the relevant legislation.
  • Request that correction, deletion or destruction operations be notified to third parties to whom personal data have been transferred.
  • Object to a result that is to their detriment arising from the analysis of the processed data exclusively through automated systems.
  • Request compensation for damages in the event that they suffer damage due to the unlawful processing of personal data.
  1. Methods of Application

You may submit your applications and requests regarding your personal data to the Company through the following methods:

  • You may submit your wet-signed application, together with documents verifying your identity, to the address Vişnezade Mah. Acısu Sok. No: 19 34357 Beşiktaş – Istanbul, by mail or in person.
  • You may apply to the Company in person with a valid identity document.

You may send your application, signed with a mobile signature or secure electronic signature, to anadolujapan@hs03.kep.tr.

You may send it, using your registered electronic mail address, secure electronic signature or mobile signature, to the Company’s registered electronic mail address: kvkk.istanbul@swissotel.com

You may apply, through the e-mail address registered in the Company’s systems, to istanbul@swissotel.com.

Your application must include your name, surname, signature (if the application is in writing), Turkish Republic identity number, and for foreign nationals your passport number or identity number if any, your residential or business address for notification purposes, your e-mail address and telephone number for notification purposes if any, and the subject of your request.

As a rule, the application must relate to the applicant. If an application is made on behalf of another person, the applicant must attach to the application a document showing that they are specifically authorised to do so.

Applications made by unauthorised third parties on behalf of another person will not be taken into consideration.

  1. Conclusion of Applications

The Company concludes data subject applications, pursuant to KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller, as soon as possible and within thirty days at the latest.

Where the application requires an additional cost, a fee may be charged according to the tariff determined by the Personal Data Protection Board.

If your application is rejected, the response given is found insufficient, or no response is given within the time limit, you have the right to lodge a complaint with the Personal Data Protection Board within the procedures and time limits set out in KVKK.

  1. Update

The Company may update this Disclosure Text in the event of a change in the scope of the camera systems, the purposes of use, the retention periods, the transfer processes, or the relevant legislation.

Accessaddress

Swissôtel The Bosphorus ☆☆☆☆☆
Visnezade Mah. Acisu Sok. N. 19, 34357 Macka Besiktas
Istanbul
Tel: +90 212 326 11 00
Email: istanbul@swissotel.com

google_map
Book a room
Book a room
close