GDPR

Last updated: 31 August 2026

1. Data Controller

This Personal Data Protection and Privacy Notice has been prepared in accordance with Turkish Personal Data Protection Law No. 6698 (“KVKK”), its secondary legislation and, where applicable, the European Union General Data Protection Regulation (“GDPR”).

Your personal data may be processed by the following company acting as the data controller:

Company: CKT TAŞ.TUR.SEY.TİC.LTD.ŞTİ

Brand and platform: 724GetTransfer

Registered address: Müftü Mah. Atatürk Cad. Genç Apt. No: 481/21, Merkez/Rize, Türkiye

Email: [email protected]

WhatsApp written support: +90 850 441 18 87

2. Role of the Platform

724GetTransfer is an electronic intermediary and booking platform that connects passengers with independent transfer and transportation service suppliers. The actual transportation service is performed by the independent supplier and carrier that accepts the booking.

CKT TAŞ.TUR.SEY.TİC.LTD.ŞTİ may act as the data controller for personal data processed in connection with operating the platform, receiving booking requests, communicating with customers, administering payments and sharing the necessary information with the relevant supplier.

Actual carriers may act as independent data controllers for their own activities, including performing the transportation service, preparing passenger lists, maintaining legally required transport records and handling insurance or accident procedures. Each party is responsible for protecting personal data under its control in accordance with applicable law.

3. Personal Data We May Process

Depending on the requested service and the method of communication, we may process the following categories of personal data:

Identity and contact information

  • First name and surname
  • Telephone and WhatsApp number
  • Email address
  • Identity, address or tax information required for invoicing
  • Names and surnames of other passengers included in the booking

Booking and travel information

  • Pickup and destination points
  • Hotel, accommodation or full address details
  • Transfer date and time
  • Flight number and scheduled arrival or departure time
  • Number of adults, children and infants
  • Luggage information
  • Vehicle and transfer preferences
  • Child seat, accessibility or other travel-related special requests
  • Booking number, amendment, cancellation and no-show records

Payment and transaction information

  • Transfer price and currency
  • Payment method and payment status
  • Transaction, collection, refund and payment references
  • Invoice and accounting records
  • Payment dispute or chargeback records

Card payments may be processed through the secure infrastructure of authorised payment service providers. CKT may process limited transaction and verification information supplied by the payment provider. Full card numbers and security codes are processed within the payment provider’s own secure infrastructure.

Communication and support information

  • Messages sent through WhatsApp, email or the website
  • Booking confirmations and operational notifications
  • Requests, complaints, cancellations and refund correspondence
  • Customer support and supplier communication records

Technical and security information

  • IP address
  • Browser and device information
  • Login, transaction and security logs
  • Information collected through cookies and similar technologies
  • Records used to prevent fraud and unauthorised access

Incident and claim records

  • Accident reports and documents supplied for insurance procedures
  • Records concerning luggage, vehicle damage or exceptional soiling
  • Correspondence relating to legal claims and disputes
  • Photographs or recordings obtained by authorised parties in accordance with applicable law

4. Special Categories of Personal Data and Children’s Data

Information concerning health, disability or accessibility requirements is processed only where necessary to plan the journey safely and appropriately and where it has been provided by the passenger. Passengers should not provide health information or other special-category personal data that is not required for the service.

Information relating to children must be provided by a parent, legal guardian or authorised adult making the booking. The person making the booking confirms that they are authorised to provide information about the other passengers and that the necessary information has been given to them.

5. Purposes of Processing Personal Data

Personal data may be processed for the following purposes:

  • Receiving a transfer request and finding an appropriate supplier
  • Creating, confirming and amending a booking
  • Transmitting booking information to the actual carrier
  • Ensuring that passengers are collected at the correct location and time
  • Monitoring flight information and operational changes
  • Facilitating communication between the customer and supplier
  • Administering payments, collections, invoices, refunds and accounting processes
  • Handling cancellation, no-show, complaint and support requests
  • Improving service quality, security and platform operation
  • Preventing fraud, misuse and unauthorised transactions
  • Coordinating communication between the relevant parties in accident, insurance and legal claim processes
  • Complying with legal obligations and responding to competent authorities
  • Establishing, exercising or defending legal rights and claims

6. Legal Grounds for Processing

Depending on the specific processing activity, personal data may be processed on one or more of the following legal grounds:

  • Processing is necessary to enter into or perform a contract
  • Processing is necessary to take steps at the data subject’s request before entering into a contract
  • Processing is necessary for compliance with a legal obligation
  • Processing is necessary for the establishment, exercise or defence of legal rights
  • Processing is necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not adversely affected
  • The data subject has given explicit consent where consent is legally required
  • Processing is necessary to protect the vital interests of the passenger or another person in an emergency

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

7. Parties to Whom Personal Data May Be Disclosed

Personal data may be shared, strictly to the extent necessary for the relevant purpose, with the following categories of recipients:

  • Independent transportation suppliers that accept the booking
  • Authorised drivers and operations personnel
  • Payment service providers, banks and financial service providers
  • Hosting, software, security, backup, email and communication service providers
  • WhatsApp and similar communication infrastructure providers
  • Accountants, financial advisers, auditors and legal advisers
  • Insurance companies and authorised parties involved in claim procedures
  • Courts, law enforcement bodies, administrative authorities and legally authorised public institutions

The passenger’s name, contact information, route, date, time, flight information, passenger and luggage details and any special requests necessary to perform the service may be disclosed to the supplier. The supplier must use this information only to perform the transportation service and comply with its own legal obligations.

CKT does not sell personal data to independent third parties as commercial marketing or contact lists.

8. International Transfers of Personal Data

Some personal data may be transferred abroad or made accessible from abroad where communication, cloud computing, email, security, payment or other technical service providers operate or store data outside Türkiye.

International transfers are carried out in accordance with Article 9 of the KVKK, the Turkish Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad and, where applicable, the GDPR provisions governing international transfers.

Depending on the nature of the transfer, CKT may rely on an adequacy decision, appropriate safeguards, standard contractual clauses, binding corporate rules or another transfer mechanism permitted by applicable legislation.

9. Retention Periods

Personal data is retained only for as long as necessary for the purposes for which it was processed and for the periods required under applicable tax, commercial, consumer, transportation, accounting and limitation legislation.

Booking, payment, invoice, contract and dispute records may be retained throughout the applicable statutory retention and limitation periods. Support correspondence, security records and technical data are retained for as long as reasonably necessary to resolve the request, maintain security and manage potential legal claims.

When the applicable retention period expires and no other legal ground requires continued processing, personal data is deleted, destroyed or anonymised.

10. Cookies and Similar Technologies

The website may use cookies and similar technologies to provide essential functions, maintain session security, remember user preferences, measure performance and improve the user experience.

Where required by applicable law, non-essential analytics or marketing cookies are subject to the user’s preferences. Cookie preferences may be changed through the relevant cookie panel or browser settings.

11. Commercial Electronic Communications

Booking confirmations, flight and pickup updates, payment notifications and security messages are operational communications required to provide the requested service.

Promotional electronic communications concerning campaigns, discounts or advertising are sent on the basis of a separate marketing permission where required. Users may withdraw marketing permission at any time. Withdrawal of marketing permission does not prevent essential operational messages relating to an existing booking.

12. Data Security

CKT takes appropriate technical and organisational measures designed to prevent unauthorised access to personal data and the loss, alteration or unlawful disclosure of personal data.

These measures may include limiting booking information to authorised personnel and the relevant supplier, account security, access logs, backups and the use of secure payment infrastructure.

Passengers must not send full card numbers, card security codes, online banking passwords, one-time verification codes or account passwords through WhatsApp or email.

13. Rights of Data Subjects

Under Article 11 of the KVKK and, where applicable, the GDPR, data subjects may have the following rights:

  • To learn whether their personal data is being processed
  • To access their personal data and request information about its processing
  • To request the correction of inaccurate or incomplete data
  • To request deletion or destruction where the applicable conditions are met
  • To request restriction of processing
  • To object to processing in certain circumstances
  • To request data portability where applicable
  • To withdraw consent where processing is based on consent
  • To object to decisions based solely on automated processing that produce significant effects
  • To claim compensation where damage results from unlawful processing
  • To submit a complaint to the competent data protection authority

Some rights are not absolute. A request may be limited or refused where continued processing is required by a legal retention obligation, the establishment or defence of legal claims, the rights of other persons or another exception recognised under applicable law.

14. How to Exercise Your Rights

Requests relating to personal data may be submitted using one of the following methods:

  • Email: [email protected]
  • By post or in person: CKT TAŞ.TUR.SEY.TİC.LTD.ŞTİ, Müftü Mah. Atatürk Cad. Genç Apt. No: 481/21, Merkez/Rize, Türkiye

The request should include the applicant’s first name and surname, contact information sufficient to verify the request, the subject of the request and, where relevant, the booking number. Where a request is submitted on behalf of another person, proof of authority may be required.

Reasonable identity-verification information may be requested to protect the applicant’s identity and personal data. Requests will be reviewed within the periods specified by applicable legislation.

15. Information Relating to Other Passengers

A person making a booking on behalf of multiple passengers confirms that they are authorised to provide the other passengers’ information, will make this notice available to them and will provide only the information necessary for the booking.

16. Changes to This Notice

This notice may be updated to reflect changes in legislation, platform features, payment methods, supplier processes or personal data processing activities.

The updated notice becomes effective on the date it is published on the website. Significant changes may also be communicated through appropriate communication channels.