Privacy & Security Policy
Universal Travel Services privacy and security policy covering virtual POS, online reservations and digital service channels (KVKK).
- Company
- Universal Turizm ve Ticaret A.Ş.
- Version
- 1.0
- Effective date
- 21 Ağustos 2026
- Covered sites
- universaltravel.com.tr
- Payment / reservation channel
- booking.universaltravel.com.tr
This is a translation of the approved Turkish text for information purposes. In case of any discrepancy, the Turkish version is the binding legal version.
Policy Summary
Universal processes personal data proportionately and solely for the purposes of delivering its services, carrying out payment and reservation processes, fulfilling legal obligations and ensuring security. Full card numbers and CVV/CVC codes are not stored on Universal's systems.
Our Privacy Commitment
Universal Turizm ve Ticaret A.Ş. (“Universal” or the “Company”) respects the privacy of its customers, travellers, visitors and business partners. Personal data is processed lawfully and fairly, accurately and where necessary kept up to date, for specified, explicit and legitimate purposes, and in a manner that is relevant, limited and proportionate to those purposes.
Universal applies administrative and technical measures proportionate to the risk in order to prevent the unlawful processing of and access to personal data and to ensure its secure retention. Nevertheless, no method of internet transmission or electronic storage can guarantee absolute security; security controls are therefore reviewed and improved on a regular basis.
Scope and Data Controller
This Policy applies to transactions carried out through the websites operated by Universal, its online reservation and payment pages, payment links, contact forms, e-mail and other digital channels. For the purposes of Turkish Personal Data Protection Law No. 6698 (“KVKK”), the data controller is Universal Turizm ve Ticaret A.Ş..
Data controller contact details: Teşvikiye Mahallesi, Ferah Sokak, No: 29, 34365 Şişli, İstanbul, Türkiye; +90 212 225 92 32; universal@universaltravel-tr.com; universaltravel.com.tr.
Personal Data That May Be Processed
Depending on the service requested, the nature of the reservation and the channel used, the following categories of data may be processed:
- Identity and traveller information: first name, surname, date of birth, nationality, gender, passport or ID details and travel document details.
- Contact information: telephone number, e-mail address, address and preferred language of communication.
- Reservation and travel information: tour, accommodation, flight and transfer details; dates, itinerary, room type, accompanying persons and group information; special requests and service history.
- Financial and transaction information: invoicing details, transaction amount, currency, payment and refund status, bank transaction reference and transaction records such as the masked portion of the card only.
- Communication and request records: e-mail correspondence, contact forms, complaints, feedback, amendment and cancellation requests.
- Technical and online usage data: IP address, date-time logs, browser and device information, error/security logs, referring page and cookie preferences.
- Special categories of personal data: where necessary for the safe and appropriate delivery of the service; limited information such as disability/accessibility needs, health condition, allergies and dietary restrictions.
- Marketing preferences: where separate and valid consent is given, commercial electronic message consent, channel preferences and consent records.
Purposes and Legal Grounds of Processing
Personal data is processed for the purposes of creating and managing reservations, concluding and performing the contract, executing payment and refund transactions, keeping invoicing and accounting records, planning travel services, providing customer support, resolving requests and complaints, preventing fraud and misuse, ensuring information security, managing legal disputes and complying with requests from competent authorities.
Processing activities may rely on the legal grounds set out in the KVKK: express provision in law, direct relation to the conclusion or performance of a contract, compliance with a legal obligation, establishment, exercise or protection of a right, and legitimate interest provided that the fundamental rights of the data subject are not harmed. Where consent is required, explicit consent given separately and freely is obtained. Special categories of personal data are processed only where one of the processing conditions provided in the KVKK exists and with the necessary additional measures in place.
Methods of Collection
Data may be obtained from the data subject, from the person or organisation making the reservation, from the authorised travel agency, business partner, payment institution or bank, from service suppliers and from competent public authorities; through the website, reservation system, payment page, e-mail, telephone, contact form, contracts and similar physical or electronic channels.
A person making a reservation on behalf of another accepts that they are authorised to share the information provided and that they have informed the relevant person of the required notices. Only that part of sensitive information such as health, allergy or accessibility data which is necessary for the safe delivery of the service should be shared.
Transfer of Personal Data
Data necessary for the performance of the service may be transferred to the following groups of recipients, observing the principle of data minimisation and limited to the purpose:
- Tourism and travel suppliers: hotels, airlines, transport and transfer companies, guides, restaurants, event venues, museums, ticketing and similar service providers.
- Financial and payment parties: banks, card schemes, authorised payment service providers and parties providing financial audit/accounting services.
- Technical service providers: suppliers providing hosting, software, e-mail, security, backup and IT support.
- Competent authorities and professional advisers: public institutions, courts, enforcement offices, auditors, lawyers and financial advisers, as required by legislation or for the exercise of a legal right.
- Parties to the reservation: the organisation making the reservation, the travel agency, the group organiser or persons authorised by the data subject.
Transfer of Data Abroad
Where the travel or event service is delivered abroad, where a business partner located abroad is involved in the reservation, or where the technical service used has an international element, the necessary personal data may be transferred abroad. Such transfers are carried out on the basis of whichever of the adequacy decision, appropriate safeguards or the exceptional cases exhaustively listed in the law is applicable under Article 9 of the KVKK. The scope of the transfer is limited to the minimum data required by the service.
Payment Security and Card Data
Online payments are processed through the Garanti BBVA Virtual POS and/or the secure infrastructure of the authorised bank or payment service provider contracted by Universal. Data transmitted to the payment page is sent over an encrypted connection with a valid SSL/TLS certificate.
- Protection of card data: Card details entered during payment are transmitted securely to the relevant bank/payment infrastructure. The full card number and the CVV/CVC security code are not stored on Universal's systems.
- Limited transaction records: For reconciliation, accounting, refunds and transaction tracking, only limited records such as the payment amount, currency, date, transaction result, bank reference and masked card information may be retained.
- 3D Secure: Depending on the card, the bank and the transaction, additional authentication may be applied by the cardholder's bank. The 3D Secure verification code is neither seen nor stored by Universal.
- No request for confidential information: Universal employees never request card PINs, internet banking passwords, 3D Secure verification codes or CVV/CVC information by e-mail, telephone, messaging applications or social media.
- User control: Before paying, the padlock icon in the browser, the correct domain name, the amount and the currency should be checked. In the event of a suspicious transaction, the issuing bank and Universal must be contacted immediately.
Website and Information Security
Universal applies controls proportionate to the nature of the data processed and the level of risk in order to support the security of personal data and online transactions. To the extent applicable, these include the following measures:
- Communication security: encryption of data traffic between the site and the user with SSL/TLS and monitoring of certificate validity.
- Access management: defining authorisations on a need-to-know and duty basis; controlling user accounts, passwords and administrator access.
- System security: update and patch management, protection against malware and unauthorised access, monitoring of security logs and unusual activity.
- Data continuity: implementation of appropriate backup, restore and business continuity measures.
- Supplier management: regulating the security and confidentiality obligations of service providers processing personal data by contract and performing the necessary controls.
- Corporate awareness: informing employees about confidentiality, social engineering, phishing and safe data use; enforcing confidentiality obligations.
- Incident management: investigating suspicious incidents, limiting their impact and notifying data subjects and competent authorities where required by legislation.
The User's Security Responsibility
Users should keep their devices and browsers up to date, avoid making payments on public or untrusted networks, use passwords that are difficult to guess, check the domain name of any payment link sent to them and never share verification codes with anyone. Risks arising from security vulnerabilities in the user's own device, e-mail account or communication channel are beyond Universal's control.
Cookies and Online Technologies
Cookies and similar technologies may be used on the websites for the purposes of operating the pages, remembering preferences, security, performance measurement and improving the user experience. Non-essential cookies are offered to the user's choice where required by applicable legislation. Cookie types, providers, retention periods and preference methods are explained in the separately published Cookie Policy and in the cookie management panel.
Retention and Destruction
Personal data is retained for the period required by the purpose of processing and for the retention, evidentiary and limitation periods stipulated in the relevant legislation. In determining the period, the reservation and contractual relationship, tax and commercial legislation, payment objection/chargeback periods, the needs of legal disputes and security requirements are taken into account. When the purpose of retention ceases to exist, data is erased, destroyed or anonymised in accordance with the legislation and the Company's retention and destruction processes.
Rights of the Data Subject and Applications
Under Article 11 of the KVKK, the data subject has the right to learn whether their personal data is processed; to request information if it has been processed; to learn the purpose of processing and whether the data is used in accordance with that purpose; to know the third parties to whom the data is transferred domestically or abroad; to request correction of incomplete or inaccurately processed data; to request erasure or destruction where the conditions are met; to request that correction and erasure operations be notified to the third parties to whom the data was transferred; to object to any outcome arising from analysis carried out exclusively by automated systems; and to claim compensation for damage arising from unlawful processing.
Applications concerning these rights may be submitted to Universal through the contact channels below, together with information sufficient to verify the applicant's identity and request. Applications are concluded as soon as possible according to their nature and at the latest within the period stipulated by legislation. Universal may request additional verification information in order to conclude the application securely.
- Post / in person: Teşvikiye Mahallesi, Ferah Sokak, No: 29, 34365 Şişli, İstanbul, Türkiye
- E-mail: universal@universaltravel-tr.com
- Subject line: “KVKK Data Subject Application”
Children's Information
Data relating to child travellers is processed to the extent required by the reservation and travel service, through a parent, guardian, legal representative or the person authorised to make the reservation. As a matter of principle, children's information must not be shared unnecessarily or disproportionately.
Third-Party Sites and Communication Channels
Universal's sites may contain links to third-party websites or services. The privacy and security practices of those sites are their own responsibility. Users are advised to review the relevant policies and terms before submitting data to third-party pages. It should be borne in mind that communication via e-mail and messaging applications may carry additional risks inherent to the channel.
Relationship with Other Legal Texts
This Policy provides general information about website and virtual POS security. It does not replace the KVKK Privacy Notice, Explicit Consent Text, Cookie Policy, Distance Sales/Service Agreement, Payment and Cancellation-Refund Terms or delivery/service performance statements that must be published for a specific transaction or data collection channel. Privacy notices and explicit consent texts are, by their legal nature, drawn up and presented separately.
Changes to the Policy
Universal may update this Policy due to changes in legislation, banking/payment infrastructure, service model or security practices. The current text is published on the website with its effective date and version information. Material changes may additionally be notified by an appropriate communication or announcement method.
Contact
You may contact Universal for information about this Policy, personal data processing activities or a suspected payment/security incident:
- E-mail: universal@universaltravel-tr.com
- Telephone: +90 212 225 92 32
- Address: Teşvikiye Mahallesi, Ferah Sokak, No: 29, 34365 Şişli, İstanbul, Türkiye
Principal legal bases: Personal Data Protection Law No. 6698; Consumer Protection Law No. 6502; Law No. 6563 on the Regulation of Electronic Commerce; Bank Cards and Credit Cards Law No. 5464 and related secondary legislation.
