Privacy and Security Policy

Virtual POS, online reservation and digital service channels · Universal Turizm ve Ticaret A.Ş. · Version 1.0 · Effective date: 21 August 2026 · Covered sites: booking.universaltravel.com.tr, universaltravel.com.tr, www.universaltravel-tr.com

Policy Summary

Universal processes personal data in a proportionate manner and solely for the provision of the service, the execution of payment and reservation processes, compliance with legal obligations and the maintenance of security. Full card numbers and CVV/CVC codes are not stored in Universal's systems.

Our Privacy Commitment

Universal Turizm ve Ticaret A.Ş. (“Universal” or the “Company”) respects the privacy of its customers, passengers, visitors and business partners. Personal data is processed lawfully and fairly, accurately and where necessary kept up to date, for specified, explicit and legitimate purposes, and in a manner that is relevant, limited and proportionate to those purposes.

Universal applies administrative and technical measures proportionate to the risk in order to prevent the unlawful processing of and access to personal data and to ensure that data is kept securely. Nevertheless, no method of transmission over the internet or of electronic storage can guarantee absolute security; for this reason security controls are reviewed and improved on a regular basis.

Scope and Data Controller

This Policy applies to transactions carried out through the websites operated by Universal, its online reservation and payment pages, payment links, contact forms, e-mail and other digital channels. For the purposes of Law No. 6698 on the Protection of Personal Data (“KVKK”), the data controller is Universal Turizm ve Ticaret A.Ş.

Data controller contact details: Ferah Sokak No: 29, Teşvikiye 34365 Şişli / Istanbul, Türkiye; +90 212 225 92 32; universal@universaltravel-tr.com; www.universaltravel-tr.com.

Personal Data That May Be Processed

Depending on the service requested, the nature of the reservation and the channel used, the following categories of data may be processed:

  • Identity and passenger information: first name, surname, date of birth, nationality, gender information, passport or identity information and travel document details.
  • Contact information: telephone number, e-mail address, address and preferred language of communication.
  • Reservation and travel information: tour, accommodation, flight and transfer details; date, itinerary, room type, accompanying person and group information; special requests and service history.
  • Financial and transaction information: invoicing details, transaction amount, currency, payment and refund status, bank transaction reference and transaction records such as the masked portion of the card only.
  • Communication and request records: e-mail correspondence, contact forms, complaints, feedback, amendment and cancellation requests.
  • Technical and online usage data: IP address, date-time records, browser and device information, error/security logs, referring page and cookie preferences.
  • Special categories of personal data: where necessary for the safe and appropriate provision of the service, limited information such as disability/accessibility needs, health condition, allergies and dietary restrictions.
  • Marketing preferences: where separate and valid permission is given, commercial electronic message consent, channel preferences and consent records.

Purposes and Legal Grounds of Processing

Personal data is processed for the purposes of creating and managing the reservation, establishing and performing the contract, executing payment and refund transactions, keeping invoicing and accounting records, planning travel services, providing customer support, resolving requests and complaints, preventing fraud and abuse, ensuring information security, managing legal disputes and fulfilling the requests of competent authorities.

Processing activities may rely on the legal grounds set out in the KVKK, namely that processing is expressly provided for by law, is directly related to the establishment or performance of a contract, is necessary for compliance with a legal obligation, is necessary for the establishment, exercise or protection of a right, or is necessary for legitimate interests provided that it does not harm fundamental rights and freedoms.

For activities requiring explicit consent, separate and freely given explicit consent is obtained. Special categories of personal data are processed only where one of the processing conditions set out in the KVKK exists and where the required additional measures are applied.

Methods of Collection

Data may be obtained from the data subject, from the person or organisation making the reservation, from the authorised travel agency, business partner, payment institution or bank, from service suppliers and from competent public authorities; through the website, reservation system, payment page, e-mail, telephone, contact form, contracts and similar physical or electronic channels.

A person making a reservation on behalf of another accepts that they are authorised to share the information provided and that they have informed the relevant person of the required notices. Only that part of sensitive information such as health, allergies or accessibility which is necessary for the safe provision of the service should be shared.

Transfer of Personal Data

Data necessary for the performance of the service may be transferred to the following groups of recipients, in observance of the principle of data minimisation and limited to the purpose:

  • Tourism and travel suppliers: hotels, airlines, transport and transfer companies, guides, restaurants, event venues, museums, ticketing and similar service providers.
  • Financial and payment parties: banks, card schemes, authorised payment service providers and parties providing financial audit/accounting services.
  • Technical service providers: suppliers providing hosting, software, e-mail, security, backup and IT support.
  • Competent authorities and professional advisers: public authorities, courts, enforcement offices, auditors, lawyers and financial advisers, as required by legislation or for the exercise of a legal right.
  • Parties to the reservation: the organisation making the reservation, the travel agency, the group organiser or persons authorised by the data subject.

Transfer of Data Abroad

Where the travel or event service is provided abroad, where a business partner located abroad is involved in the reservation, or where the technical service used has an international connection, the necessary personal data may be transferred abroad. Such transfers are carried out on the basis of whichever is applicable of the adequacy decision, appropriate safeguards or the exceptional cases exhaustively listed in law, as regulated by Article 9 of the KVKK. The scope of the transfer is limited to the minimum data required by the service.

Payment Security and Card Information

Online payments are processed through the Garanti BBVA Virtual POS and/or the secure infrastructure of the authorised bank or payment service provider with which Universal has a contract. Data transmitted to the payment page is sent over an encrypted connection with a valid SSL/TLS certificate.

  • Protection of card data: Card details entered during payment are transmitted securely to the relevant bank/payment infrastructure. The full card number and the CVV/CVC security code are not stored in Universal's systems.
  • Limited transaction records: For reconciliation, accounting, refunds and transaction tracking, only limited records such as the payment amount, currency, date, transaction result, bank reference and masked card information may be kept.
  • 3D Secure: Depending on the card, the bank and the suitability of the transaction, additional authentication may be applied by the cardholder's bank. The 3D Secure verification code is neither seen nor stored by Universal.
  • No request for confidential information: Universal employees never request card PINs, internet banking passwords, 3D Secure verification codes or CVV/CVC information via e-mail, telephone, messaging applications or social media.
  • User control: Before payment, the padlock icon in the browser, the correct domain name, the amount and the currency should be checked. In the event of a suspicious transaction, the issuing bank and Universal must be contacted immediately.

Website and Information Security

Universal applies controls proportionate to the nature of the data processed and the level of risk in order to support the security of personal data and online transactions. To the extent appropriate, these include the following measures:

  • Communication security: encryption of data traffic between the site and the user with SSL/TLS and monitoring of certificate validity.
  • Access management: definition of authorisations on a need-to-know and duty basis; control of user accounts, passwords and administrator access.
  • System security: update and patch management, protection against malware and unauthorised access, monitoring of security logs and unusual activity.
  • Data continuity: implementation of appropriate backup, restore and business continuity measures.
  • Supplier management: regulation of the security and confidentiality obligations of service providers processing personal data by contract, and performance of the necessary controls.
  • Corporate awareness: informing employees about confidentiality, social engineering, phishing and secure use of data; enforcement of confidentiality obligations.
  • Incident management: investigation of suspicious events, limitation of their impact and notification of the relevant persons and competent authorities where required by legislation.

The User's Security Responsibility

Users should keep their devices and browsers up to date, avoid making payments on shared or untrusted networks, use passwords that are hard to guess, check the domain name of any payment link sent to them and never share verification codes with anyone. Risks arising from security weaknesses in the user's own device, e-mail account or communication channel are outside Universal's control.

Cookies and Online Technologies

Cookies and similar technologies may be used on the websites for the purposes of operating the pages, remembering preferences, security, performance measurement and improving the user experience. Non-essential cookies are offered to the user's choice where required by applicable legislation. Cookie types, providers, retention periods and preference methods are explained in the separately published Cookie Policy and in the cookie management panel.

Retention and Destruction

Personal data is retained for the period required by the purpose of processing and for the retention, evidential and limitation periods prescribed by the relevant legislation. In determining the period, the reservation and contractual relationship, tax and commercial legislation, payment objection/chargeback periods, the needs of legal disputes and security requirements are taken into account. When the purpose of retention ceases to exist, data is deleted, destroyed or anonymised in accordance with the legislation and the Company's retention and destruction processes.

Rights of the Data Subject and Applications

Under Article 11 of the KVKK, the data subject has the right to learn whether their personal data is being processed, to request information if it has been processed, to learn the purpose of processing and whether the data is used in accordance with that purpose, to know the third parties to whom the data is transferred in Türkiye or abroad, to request the correction of incompletely or incorrectly processed data, to request its erasure or destruction where the conditions are met, to request that correction and erasure operations be notified to the third parties to whom the data has been transferred, to object to a result arising from analysis carried out exclusively by automated systems, and to claim compensation for damage arising from unlawful processing.

Applications relating to these rights may be submitted to Universal through the contact channels below, together with information sufficient to verify the applicant's identity and request. Applications are concluded as soon as possible according to their nature and at the latest within the period prescribed by legislation. Universal may request additional verification information in order to conclude the application securely.

By post / in person: Ferah Sokak No: 29, Teşvikiye 34365 Şişli / Istanbul, Türkiye · E-mail: universal@universaltravel-tr.com · Subject of application: “KVKK Data Subject Application”.

Information Relating to Children

Data relating to child passengers is processed to the extent required by the reservation and travel service, through the parent, guardian, legal representative or the person authorised to make the reservation. It is essential that information relating to children is not shared unnecessarily or disproportionately.

Third-Party Sites and Communication Channels

Universal's sites may contain links to third-party websites or services. The privacy and security practices of those sites are their own responsibility. Users are advised to review the relevant policies and terms before sending data to third-party pages. It should be taken into account that communication carried out via e-mail and messaging applications may carry additional risks by the very nature of the channel.

Relationship with Other Legal Texts

This Policy provides general information about website and virtual POS security. It does not replace the KVKK Information Notice, Explicit Consent Text, Cookie Policy, Distance Sales/Service Agreement, Payment and Cancellation-Refund Conditions or the delivery/service performance explanations that must be published for a specific transaction or data collection channel. Information notices and explicit consent texts are, by their legal nature, drawn up and presented separately.

Changes to the Policy

Universal may update this Policy owing to changes in legislation, the bank/payment infrastructure, the service model or security practices. The current text is published on the website together with its effective date and version information. Material changes may additionally be notified by an appropriate means of communication or announcement.

Contact

You may contact Universal for information about this Policy, personal data processing activities or a suspicious payment/security incident:

E-mail: universal@universaltravel-tr.com · Telephone: +90 212 225 92 32 · Address: Ferah Sokak No: 29, Teşvikiye 34365 Şişli / Istanbul, Türkiye.

Principal legal bases: Law No. 6698 on the Protection of Personal Data; Law No. 6502 on Consumer Protection; Law No. 6563 on the Regulation of Electronic Commerce; Law No. 5464 on Bank Cards and Credit Cards and the related secondary legislation.

Universal Travel Services · Ferah Sokak No:29, Teşvikiye 34365, Istanbul, Türkiye

universal@universaltravel-tr.com · +90 212 225 92 32