1. Data Controller & Scope of Policy
This Privacy Policy outlines how kinaliada.tours (referred to herein as “the Monograph”, “we”, “our”, or “us”) collects, processes, stores, and protects information when visitors access and browse our digital publication.
We operate under the dual frameworks of the European Union General Data Protection Regulation (GDPR - Regulation EU 2016/679) and the Republic of Turkey Law on the Protection of Personal Data No. 6698 (KVKK - Kişisel Verilerin Korunması Kanunu). We are deeply committed to safeguarding visitor privacy and minimizing the collection of personally identifiable information.
The designated Data Controller responsible for personal data processed through this platform is the editorial office of Kınalıada Tours, reachable via editorial@kinaliada.tours.
2. Categories of Information Collected
We gather two general categories of information:
- Technical & Log Data: When you navigate our pages, our edge hosting infrastructure (Cloudflare Pages) automatically records standard server logs, including your internet protocol (IP) address, browser user-agent string, operating system version, referring uniform resource locator (URL), time stamps, and pages viewed. IP addresses are anonymized and processed solely for security diagnostics, preventing distributed denial-of-service (DDoS) attacks, and optimizing global cache delivery.
- Voluntary Communications: If you reach out to our editorial desk via email, we store your email address, full name, and message correspondence strictly for the purpose of answering your inquiry. We never sell, rent, or trade your contact details with commercial marketing brokers.
3. Cookies & Tracking Technologies
Cookies are compact data text files placed on your computer or mobile device by websites you visit. Our website uses minimal, privacy-centric cookies:
- Strictly Necessary Cookies: Essential for foundational website navigation, security token validation, and content delivery across Cloudflare's content delivery network.
- Aggregated Analytical Cookies: We may utilize lightweight, cookieless, or privacy-first web performance analytics to assess page readership, average visit duration, and popular search queries. These metrics are strictly aggregated and do not build behavioral advertising profiles across third-party domains.
4. Third-Party Affiliate Network Disclosures
This website participates in authorized affiliate marketing partnerships with licensed travel booking platforms, including GetYourGuide Deutschland GmbH and Viator Inc. (Tripadvisor Group).
When you click an outbound link to view tickets, ferry passes, or tour packages, a small tracking tag (such as partner_id=FY0PT2P or pid=P00271667) is appended to the destination URL. This tracking parameter informs the merchant that the visitor was referred by kinaliada.tours.
If you subsequently complete a booking on their secure servers, we may receive a modest commission at no extra charge to you. The third-party platform processes your personal payment information in accordance with their independent privacy policies; we never receive or store credit card numbers or billing details.
5. Your Legal Rights (GDPR & KVKK Law 6698)
Under the provisions of GDPR (Articles 15 through 22) and KVKK Article 11, data subjects possess fundamental rights regarding their personal information:
- Right of Access: The right to request confirmation of whether personal data concerning you is being processed and obtain a copy.
- Right to Rectification: The right to obtain correction of inaccurate or incomplete personal records without undue delay.
- Right to Erasure (“Right to be Forgotten”): The right to obtain deletion of personal information where processing is no longer necessary.
- Right to Restriction & Objection: The right to restrict or object to data processing on grounds relating to your particular situation.
- Right to Lodge a Complaint: The right to lodge a formal complaint with relevant data protection authorities (such as the Turkish Kişisel Verileri Koruma Kurumu - KVKK or your national EU Data Protection Authority).
6. International Cross-Border Data Transfers
Because our content delivery infrastructure utilizes globally distributed edge nodes operated by Cloudflare, technical routing data may be processed on servers located outside the Republic of Turkey or the European Economic Area (EEA).
All international data transfers comply with Chapter V of the GDPR and KVKK Article 9, relying upon European Commission Standard Contractual Clauses (SCCs) and binding corporate rules that guarantee an adequate level of protection equivalent to European and Turkish statutory standards.
7. Data Retention & Security Measures
Server access log files are retained for security auditing for a maximum period of 90 days, after which they are automatically purged. Inquiries submitted via email are retained for up to 12 months to maintain customer service records before secure deletion.
We implement industry-standard technical security protocols, including Transport Layer Security (TLS/HTTPS) encryption, strict HTTP Strict Transport Security (HSTS) response headers, and Cloudflare firewall protections to guard against unauthorized access, data alteration, or disclosure.
8. Protection of Children's Privacy
Our website is a general audience informational publication intended for adult travelers and cultural researchers. We do not knowingly solicit, collect, or store personal identifiable information from children under the age of 16 without verifiable parental consent in compliance with the Children's Online Privacy Protection Act (COPPA) and GDPR Article 8.
If a parent or legal guardian becomes aware that their minor child has transmitted personal information to our editorial office, please notify us immediately at editorial@kinaliada.tours for swift investigation and permanent expungement of the records.