Privacy Notice (KVKK)
1. Data Controller
This Privacy Notice has been prepared by Tolerance Seyahat Turizm ve Organizasyon Anonim Şirketi (the “Company”, “Lufer Tour”) in its capacity as data controller under Article 10 of Turkish Personal Data Protection Law No. 6698 (“KVKK”).
Data Controller / Seller: Tolerance Seyahat Turizm ve Organizasyon Anonim Şirketi (operating under the “Lufer Tour” brand)
Address: Orhan Veli Kanık Caddesi No: 53/1 Kavacık / Beykoz / İstanbul
Tax Office / No: Beykoz Vergi Dairesi / 8490698779
MERSIS No: 925051342600018
E-mail: [email protected]
Phone: +90 530 088 44 88
Website: lufertour.com
2. Categories of Personal Data Processed
Lufer Tour operates as a direct cruise operator (B2C) and may process the following categories of personal data of its visitors, customers, members and corporate partners:
- Identity data: Full name, national ID number (only when legally required for invoicing/manifest), date of birth.
- Contact data: E-mail, mobile phone, billing address.
- Customer transaction data: Reservation records, tour date/time, party size, child/infant counts, option preferences (e.g. breakfast, dinner), basket and order history.
- Financial data: Invoice details, payment authorisation numbers, refund records. Card numbers, CVV codes and expiry dates are never stored on the Company's servers; the entire payment flow is operated through the PCI-DSS certified payment institution Iyzico (Iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.).
- Transaction security data: Hashed account password, session data, IP address, logs.
- Marketing data: Cookie preferences, GA4/Meta Pixel session data (only with explicit consent), affiliate (UTM / partner referral) parameters.
- Request / complaint data: Messages submitted via the contact form, customer reviews, refund/cancellation requests.
The Company does not request or process special-category personal data. Please refrain from sharing such data via any channel.
3. Purposes of Processing
- Processing tour reservations, taking payment, issuing invoices and keeping legal records.
- Pre/post-tour communication and contact in case of tour change/cancellation.
- Responding to requests, questions and complaints; managing refunds.
- Creating and protecting member accounts, ensuring session security.
- Subject to your explicit consent, marketing campaigns, commercial electronic messages and analytics via GA4/Meta Pixel.
- Compliance with legal obligations (tax, commerce, tourism, maritime manifest etc.).
- Prevention and follow-up of legal disputes.
4. Transfer of Personal Data
Your personal data may be transferred for the purposes set out below in compliance with KVKK Articles 8 and 9:
- Iyzico: 3D Secure payments, refunds, optional card-on-file storage.
- Resend / Gmail SMTP: Delivery of reservation and system e-mails.
- Google Analytics 4 and Meta Pixel: Only if you grant explicit consent in the cookie banner, session and interest data may be transferred to Google Ireland Ltd. and Meta Platforms Ireland Ltd.
- Affiliate partners: Only anonymised conversion information (e.g. UTM parameter, order ID) is shared with the partner who referred you.
- Public authorities: Courts, prosecutors, tax administration, law enforcement, in line with applicable legislation.
- Legal/financial advisors and auditors: Under confidentiality undertakings, on a limited basis.
Your data is never sold, rented or shared with third parties for marketing purposes beyond those listed above.
5. Method and Legal Basis of Collection
Your personal data is collected via our website (lufertour.com), contact forms, call centre, e-mail, social media channels and cookies — by automatic or partly automatic means. Legal bases:
- Necessary for the performance of a contract (KVKK 5/2-c).
- Necessary for compliance with a legal obligation (KVKK 5/2-ç).
- Necessary for our legitimate interests (KVKK 5/2-f).
- Your explicit consent (especially for marketing cookies and commercial e-mails — KVKK 5/1).
6. Retention Periods
- Membership and reservation data: while membership is active + 10 years after termination (TCC art. 82).
- Invoices and tax records: 5 years (Turkish Tax Procedural Law).
- Marketing consents: until withdrawn; +3 years thereafter for evidentiary purposes.
- Server logs: 2 years (Law No. 5651).
- Contact form messages: 2 years.
7. Your Rights under KVKK Article 11
As a data subject you have the right to learn whether your data is being processed, request information, learn the purpose of processing and whether it is used for that purpose, know the third parties to whom data is transferred (domestic and abroad), request rectification of incomplete/inaccurate data, request deletion/destruction within the conditions of KVKK art. 7, object to outcomes produced by automated processing, and seek compensation for damages.
You may submit your applications, in line with the “Communiqué on the Procedures and Principles for Application to the Data Controller”, together with documents establishing your identity, to [email protected] or to our postal address above. Requests are answered free of charge within 30 days.
Last updated: 2026-04-28