Cookie Policy
GDPR COOKIE POLICY - AMAGICTOUR.COM
Welcome to amagictour.com. Your privacy is important to us, and we are committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR). Please read this Cookie Policy carefully before accessing or using our website. By continuing to browse or use the site, you agree to the terms outlined below regarding the use of cookies.
-
What are Cookies?
Cookies are small text files stored on your device when you visit a website. These files collect data such as browsing preferences and activity to improve your user experience. Cookies are essential for certain functionalities of the website and can also help us deliver targeted advertisements and analyze traffic patterns. -
Types of Cookies We Use
- Essential Cookies: Required for the basic functioning of the website, such as login functionality or maintaining session security.
- Performance Cookies: Used to understand website performance and improve its usability.
- Functionality Cookies: Enhance the experience by remembering your preferences, such as language selection.
- Advertising Cookies: Help deliver relevant ads to you and measure the effectiveness of advertising campaigns.
-
How We Use Cookies
We use cookies to:- Personalize content and improve the usability of our site.
- Provide secure access to restricted sections of the website.
- Analyze visitor behavior to improve functionality and features.
- Manage and monitor advertising campaigns.
-
Third-Party Cookies
Amagictour.com may also include cookies from third parties such as Google Analytics, which helps us understand user behavior and optimize the site. These third-party cookies are subject to the privacy policies of the respective providers. -
Your Control Over Cookies
You have the right to accept or reject cookies at any time. Most web browsers automatically accept cookies, but you can modify your browser settings to decline cookies if you prefer. However, doing so may limit the functionality of some sections of the site. For more details on managing cookies, refer to the help section of your web browser. -
Cookie Consent
Upon your first visit to amagictour.com, you will be prompted with a cookie banner. By clicking "Accept All Cookies," you consent to our use of all categories of cookies. If you wish to customize your preferences, you can do so via the "Cookie Settings" option on our website. -
Updates to the Cookie Policy
We reserve the right to update or modify this Cookie Policy at any time. Changes will take effect immediately upon posting on the site. We recommend reviewing this policy periodically to stay informed about how we use cookies.
For more details, please visit the Privacy Policy section on amagictour.com. If you have any questions regarding this policy, feel free to contact us through the information provided on our Contact page.
By using amagictour.com, you acknowledge that you have read, understood, and agreed to this Cookie Policy.
Information Security Policy
- To define risk acceptance criteria, identify risks, and develop and implement controls,
- To ensure the implementation of the information security risk assessment process for identifying risks related to the confidentiality, integrity, and availability of information and associated data within the scope of the Information Security Management System (ISMS), and to identify risk owners,
- To define a framework for evaluating the confidentiality, integrity, and availability impacts of information and associated data within the scope of the ISMS,
- To continuously monitor risks by reviewing technological expectations within the scope of provided services,
- To comply with national or sectoral regulations, legal and related legislative requirements, contractual obligations, and institutional responsibilities arising from commitments to internal and external stakeholders concerning Information Security,
- To reduce the impact of Information Security threats to ensure service continuity and contribute to maintaining it,
- To have the capability to respond promptly to potential Information Security incidents and minimize their impact,
- To maintain and improve the level of information security over time with a cost-effective control infrastructure,
- To enhance corporate reputation and protect against adverse impacts related to information security,
- To ensure the confidentiality, integrity, and accessibility of all information hosted and obtained within the primary activities and business processes of AMAGIC TOUR,
- To raise institutional awareness regarding information with varying levels of sensitivity within the scope of AMAGIC TOUR Information Security Management System practices, to identify and implement logical, physical, and administrative controls suggested for information with different sensitivity levels, and to define access and control rules for data on portable media as part of the Information Security Management System practices,
A Data Classification Guide has been created to achieve these purposes.
AMAGIC TOUR senior management is committed to ensuring the implementation, review, and continuous improvement of Information Security practices.
Introduction
As Amagic Tour Tourism and Trade Inc. (“Amagic Tour,” “Company,” or “We”), we place the utmost importance on ensuring the confidentiality of your personal data and processing it in compliance with the relevant legislation while providing our services to you, our valued customers. This disclosure text has been prepared in accordance with Article 10 of the Turkish Personal Data Protection Law No. 6698 (“Law”) to inform you about the following topics:
- How do we collect your personal data?
- What personal data do we process?
- For what purposes and on what legal grounds do we process your personal data?
- With whom and for what purposes do we share your personal data?
- What are your rights regarding your personal data, and how can you exercise them?
How Do We Collect Your Personal Data?
As Amagic Tour, we can interact with you through various channels, such as:
- During your visits to our agencies or branches,
- When you call our call center and leave your information,
- When you visit our website or make a reservation as a member,
- Through email communication with our customer services or other Amagic Tour staff.
Additionally, if your relationship with our company is established through an intermediary institution, we may obtain your personal data via these intermediary institutions.
What Personal Data Do We Process?
To provide our services, we may process the following categories of personal data:
- Identity and Contact Information: Name, surname, ID number, passport details, email address, phone number, and address.
- Visual and Audio Records: Your photos and call center recordings.
- Financial Information: Records or payment details regarding services you have received from us.
- Current and Past Transaction Information: Details of your current or past reservations, including hotel or tour package preferences and travel details.
- Requests and Complaints: Written or verbal records of any requests or complaints regarding Amagic Tour’s services.
- Insurance Information: Details related to your travel insurance policy.
- Occupation Information: Details about your profession.
- Other Information: Your marriage date and details about your children.
- Special Category Personal Data: Health information that may affect your travel needs or lead to reservation changes or cancellations.
For What Purposes Do We Process Your Personal Data?
As Amagic Tour, we process your personal data for the following purposes and on the legal grounds specified in the Law:
Providing Products and Services You Request:
- Based on the legal ground of “necessity for the performance of a contract” under Article 5/2(c) of the Law.
- Examples: Booking your tours, reserving hotels, purchasing flight tickets on your behalf, notifying relevant parties, and providing updates about your travel.
Improving Our Service Quality:
- Based on the legal ground of “legitimate interests” under Article 5/2(f) of the Law.
- Examples: Conducting development analyses and customer satisfaction surveys, or using publicly shared feedback on social media.
Responding to Requests and Complaints:
- Based on the legal grounds of “legitimate interests” under Article 5/2(f) and “fulfillment of legal obligations” under Article 5/2(ç) of the Law.
Creating Financial Records:
- Based on the legal ground of “necessity for the performance of a contract” under Article 5/2(c).
- Examples: Issuing invoices, creating financial records, and conducting financial audits.
Internal Company Activities:
- Based on the legal ground of “legitimate interests” under Article 5/2(f).
Compliance with Legal Obligations:
- Based on Article 5/2(ç) and 5/2(a) of the Law.
- Examples: Sharing data with authorized public institutions or regulatory authorities.
Marketing Communications and Special Offers:
- Based on your explicit consent as per Article 5/1 of the Law.
With Whom and For What Purposes Do We Share Your Personal Data?
We may share your personal data with:
- Business Partners: Such as hotels, transportation companies, insurance providers, or organizers of travel packages.
- Suppliers: Such as IT service providers or legal advisors.
- Financial Institutions: For payment processing purposes.
- Authorized Public Institutions or Private Parties: When legally required, such as during audits or investigations.
- Marketing Partners: For promotional and advertising purposes based on your explicit consent.
What Are Your Rights Regarding Your Personal Data, and How Can You Exercise Them?
Under Article 11 of the Law, you have the following rights:
- To learn if your personal data is processed,
- To request information if it has been processed,
- To learn the purpose of processing and whether it is used accordingly,
- To learn the third parties to whom your data has been transferred,
- To request correction of inaccurate or incomplete data,
- To request deletion or destruction of your personal data if the reasons for processing no longer exist,
- To object to any unfavorable results obtained through automated data processing,
- To demand compensation for damages arising from unlawful data processing.
To exercise these rights, you can contact us using the methods specified in the Amagic Tour Personal Data Owner Application Form available on our website www.amagictour.com.
We aim to respond to your requests as soon as possible and within 30 days at the latest. While your applications are generally free of charge, we reserve the right to charge a fee as per the tariff set by the Personal Data Protection Board if additional costs arise.