Privacy and Personal Data Protection Policy
Last Update:
Privacy and Personal Data Protection Policy
1. Purpose and Scope
This policy (“Policy”) explains the principles adopted regarding the protection of personal data by the Homeyday brand and authorized persons/entities processing data on behalf of Homeyday (“Homeyday” or the “Company”). The Policy covers the principles for processing, storing, transferring, and destroying personal data belonging to Visitors, Online Visitors, Customers, Prospective Customers, Employee Candidates, Suppliers/Business Partners, and Third Parties (“Data Subject Groups”). Homeyday provides residential/villa management for tourism purposes and related operational services.
2. Principles on the Processing of Personal Data
Homeyday processes personal data in accordance with the Law on the Protection of Personal Data No. 6698 (“KVKK”) and the relevant legislation;
In accordance with the law and honesty rules,
Accurate and up-to-date when necessary,
For specific, explicit, and legitimate purposes,
Relevant, limited, and proportionate to the purpose,
For the period stipulated in the relevant legislation or required for the purpose for which they are processed
and applies technical/administrative measures in line with these principles.
3. Conditions for Processing Personal Data
Homeyday processes personal data when one of the following legal grounds exists:
Explicitly provided for in the laws,
Cases of actual impossibility (obligation to protect life/physical integrity),
Directly related to the establishment/performance of a contract,
Fulfillment of the legal obligation of the data controller,
Made public by the data subject themselves,
Establishment, exercise, or protection of a right,
Legitimate interest (provided that it does not harm your fundamental rights and freedoms),
Explicit consent (in cases where other conditions are not present).
4. Data Categories and Data Subject Groups
The processed data may be collected under the following categories depending on the nature of our activities (examples are not exhaustive):
Identity (name-surname, TR identity number*, signature*, camera recording*),
Contact (address, e-mail, telephone),
Finance (bank/IBAN*, billing details*),
Transaction Security (IP, log records, session/password details*),
CV (employee candidate – CV content),
Marketing and Request/Complaint Management (campaign interaction, feedback).
*When required by the relevant process and legislation.
Data Subject Groups: Customer, Prospective Customer, Visitor/Online Visitor, Employee Candidate, Supplier/Business Partner, Third Party.
5. Processing Purposes (Group-Based)
5.1 Customer
Execution of reservation, accommodation, and property management processes; contract and accounting transactions; guest communication and satisfaction management; fulfillment of legal obligations; information security, auditing, and reporting.
5.2 Prospective Customer
Promotion and personalization of products/services; bidding; planning of commercial/operational processes; marketing analytics within the limits of consent/legitimate interest.
5.3 Visitor / Online Visitor
Facility and asset security (CCTV); keeping internet/application logs; obligations arising from Law No. 5651 and relevant legislation; request/complaint processes.
5.4 Employee Candidate
Execution of HR processes; evaluation of applications; obligations arising from legislation; recruitment communication.
5.5 Supplier / Business Partner
Contract and supply management; billing/payments; operational security; fulfillment of legal obligations.
5.6 Third Party
Fulfillment of obligations arising from contractual relationships; establishment/protection of rights; request/complaint management.
6. Transfer of Personal Data
Data may be transferred to suppliers we receive services from/collaborate with, business partners, independent auditors, our legal/financial advisors; IT, hosting, security, and marketing service providers; authorized public institutions and organizations, and when necessary abroad within the scope of the conditions in KVKK Articles 8-9 and relevant secondary regulations, in a limited to the purpose manner.
7. Method of Collection and Legal Grounds
Data is obtained directly from the data subject during the contract and pre-contract stages, through digital channels (website, mobile, contact forms), call/messaging records, camera systems during facility visits, supplier and platform integrations (e.g., booking/payment platforms) via automatic or partially automatic means; based on the applicable legal grounds in KVKK Articles 5-6. Homeyday carries out its reservation/revenue process activities with professional management and software support.
8. Data Security Measures
Technical measures: network/application security, access authorization, logging, encryption, backup, penetration testing.
Administrative measures: policy/procedure sets, authority matrix, confidentiality agreements, employee/supplier awareness trainings, periodic audits.
Breach management: impact analysis is performed in case of potential breaches; notification processes are operated in accordance with the KVKK.
9. Third-Party Data
Regarding third-party data you share with Homeyday (e.g., guest lists), it is deemed declared by you that these individuals have been informed within the scope of KVKK and their necessary consents have been obtained. Otherwise, the party sharing the data is legally responsible for any claims that may arise.
10. Retention Periods and Destruction
Data is stored for the periods stipulated in the relevant legislation or for the period required by the processing purpose; upon expiration of the period or disappearance of the purpose, it is deleted, destroyed, or anonymized in accordance with our periodic destruction processes.
11. Rights of the Data Subject (KVKK Art. 11)
By applying to us, you have the right to;
Learn whether your personal data is processed,
Request information if it has been processed,
Learn the purpose of processing and whether it is used in accordance with its purpose,
Know the third parties to whom it is transferred domestically/abroad,
Request correction if it is processed incompletely/incorrectly,
Request deletion/destruction in accordance with relevant legislation,
Request notification of the operations performed to the third parties to whom the data has been transferred,
Object to an adverse result by analyzing the processed data exclusively through automatic systems,
Request compensation for damages in case of loss due to unlawful processing
rights.
12. Application Method
You can submit your requests regarding your rights, along with documents verifying your identity, through the following channels:
E-mail: info@homeyday.com.tr
Address: Kemerağzı Mah. Yaşar Sobutay Bulvarı, 5. Hacı Gebizli Sitesi No:31, D Blok, Kat 2, Daire 20, Aksu/Antalya
Phone (for information): +90 536 794 0739, +90 555 888 45 30
Web: www.homeyday.com.tr
Homeyday concludes your application as soon as possible and within 30 days at the latest, depending on its nature; if the process requires an additional cost, the fee in the Board's tariff may be requested.
13. Cookies and Similar Technologies
Mandatory, functional, and performance/analytical cookies may be used on our website. The types of cookies used, their purposes, and your management preferences are explained in the "Cookie Information Text" and/or cookie management panel.
14. Cross-Border Transfers
Infrastructure providers (hosting/cloud), reservation and communication platforms may in some cases be located abroad. In these cases, the transfer is carried out using transfer mechanisms compliant with the KVKK, such as adequacy decisions announced by the Board or commitment/contract.
15. Entry into Force of the Policy and Updates
This Policy enters into force on the date of publication and is updated when necessary. The most up-to-date version is published on our website.

