“My airport transfer was truly impressive. The driver arrived exactly on time, greeted me warmly, and made the ride very pleasant. The car was spotless and comfortable, which helped me relax after my flight. Everything was arranged smoothly, and I felt completely taken care of from beginning to end. I would definitely recommend this service to anyone who values reliability and comfort.”
A Tripadvisor traveler reviewPrivacy Policy
How your personal data is processed at Elemen Transfer under KVKK, what rights you have, and how to exercise them — concise, clear, and transparent.
- KVKK Compliant
- Transparent Processing
- Data Security
Policy Text
This text has been prepared to inform our website users and does not constitute legal advice. For specific questions regarding your personal data, we recommend consulting the official website of the Personal Data Protection Authority (kvkk.gov.tr) or a legal advisor.
1. 1. Data Controller Information
The controller responsible for the data processing activities described below (veri sorumlusu under KVKK Art. 3/1-ı) is Elemen Transfer. Our scope of responsibility and contact information are as follows:
- Trade name: Elemen Transfer Turizm ve Taşımacılık Hizmetleri
- Address: Istanbul / Turkey — for detailed information, please see our Contact page.
- KVKK contact email: complaints@elementransfer.com
- VERBİS: Our registration with the Data Controllers' Registry Information System (VERBİS) is in progress; the VERBİS number will be shared on this page upon completion of the registration.
2. 2. Types of Personal Data Processed
We process the following categories of data throughout our service processes:
- Identity: Name, surname, date of birth (for passenger registration).
- Contact: Phone, email, pickup address, drop-off address.
- Service: Reservation details, vehicle preference, extra service selections, number of passengers.
- Financial: Payment method, only the last 4 digits of the card number, billing address. Full card details never enter our system — they are processed by a PCI-DSS compliant payment service.
- Location: GPS data during the service, solely for matching the driver with the guest.
- Device / Access: IP address, browser type, cookie ID, date and duration of visit.
- Special categories of personal data (KVKK Art. 6): Processed with explicit consent if required for medical tourism reservations; not used for any other purpose or shared with third parties.
3. 3. Purposes of Processing Personal Data
The data we collect is processed solely for the following purposes:
- Creating and confirming the reservation, assigning a driver and vehicle.
- Managing guest relations (resolving support, complaint, and refund requests).
- Carrying out payment collection, invoicing, and financial tracking processes.
- Fulfilling legal obligations (tax legislation, transportation regulations, consumer rights).
- Measuring and improving service quality (anonymous analytics).
- Marketing communications when explicit consent is obtained (email, SMS, personalized campaigns).
4. 4. Legal Basis for Processing
Data is processed based on the following legal grounds:
- KVKK Art. 5/2-a: Explicitly provided for by law (tax, transportation, consumer).
- KVKK Art. 5/2-c: Establishment or performance of a contract (passenger transport agreement, purchase).
- KVKK Art. 5/2-ç: Compliance with a legal obligation to which the data controller is subject.
- KVKK Art. 5/2-e: Necessity for the establishment, exercise, or protection of a right.
- KVKK Art. 5/2-f: Legitimate interests (preventing fraud, improving service quality).
- KVKK Art. 6/3: Explicit consent for special categories of personal data (medical tourism reservations).
- KVKK Art. 5/1 (explicit consent): Separate, revocable explicit consent for marketing communications.
5. 5. Parties to Whom Data is Transferred
Your data is shared with the following parties, only to the extent required by the service:
- Payment services: Iyzico (Turkey) and Stripe (Ireland) — PCI-DSS compliant, with KVKK-compliant contracts.
- Map / navigation services: Google Maps API — only anonymous address data.
- Call center subcontractor: Bound by a confidentiality agreement, access is granted only to support operators.
- Driver partners: Only after a confirmed reservation, with the necessary contact data for the service.
- Authorized public institutions: Within legal limits, if a request is received from a court, prosecutor's office, or supervisory authority.
International transfers: Our cloud infrastructure is located in European Union data centers (on the list of countries providing adequate protection under KVKK Art. 9). If a transfer outside the EU is necessary, explicit consent will be obtained in accordance with KVKK Art. 9/2.
6. 6. Retention Periods
Data is retained for the following periods in connection with its processing purpose:
- Reservation records: 10 years, in accordance with Article 146 of the Turkish Code of Obligations.
- Commercial accounting documents: 5 years, in accordance with the Tax Procedure Law.
- Data for marketing purposes (with explicit consent): Until consent is withdrawn.
- Device / log records: 1 year, as required by Law No. 5651.
- Cookies: 30 days to 24 months, depending on the cookie type; details are in the Cookies section below.
When the period expires, the data is deleted, destroyed, or anonymized in accordance with KVKK Art. 7.
7. 7. Data Security Measures
Technical and administrative measures we take under KVKK Art. 12:
- End-to-end encryption with HTTPS / TLS 1.3 — all form and API calls are made over SSL.
- Integration with a PCI-DSS Level 1 certified payment service; raw card information does not reach our system.
- Role-based access control, two-factor authentication (2FA) on administrative panels.
- Regular penetration tests and independent security audits.
- Data breach procedure: In accordance with KVKK Art. 12/5...
Frequently Asked Questions
Eight common questions about your data — with short answers.
In accordance with KVKK art. 7, your data will be deleted within 30 days when you send a request verifying your identity to complaints@elementransfer.com. Records that must be retained due to tax and insurance regulations (such as reservation invoices for 10 years) are anonymized by separating personal identification information.
When you request account deletion, any active reservations are completed, after which your personal information is anonymized. Financial records (tax, insurance) are retained only in an anonymous form for the legally required period — your name, phone number, and email are dissociated.
For reservations involving guests under 18, parental or guardian consent is obtained. Data pertaining to the child is processed minimally (age, weight, seat type), is not used for marketing communications, and is retained only as long as necessary to perform the service.
Our cloud infrastructure is located in European Union data centers (adequate protection under KVKK art. 9). Our payment service providers are contracted (Iyzico Turkey, Stripe Ireland). If a transfer outside the EU is necessary, explicit consent is obtained in accordance with KVKK art. 9/2.
You can reject all non-essential cookies from the cookie management panel. Essential cookies (session ID, language preference, shopping cart) cannot be disabled as they are necessary for the site's basic functions. For details, please see the Cookies section below.
Yes — the guest's name, phone number, email, and pickup/drop-off addresses are essential for a reservation. If you are not a member, this data is used for a single transaction; it is not permanently linked to a profile and is only kept in the reservation record for the legally required retention period.
No. Full card details are processed by a PCI-DSS Level 1 certified payment service; only the last 4 digits and card type (Visa / Mastercard / Amex) are visible in our system. For recurring payments, a secure token is stored instead of the card, and this is only activated with your consent.
In accordance with KVKK art. 12/5, we will send a notification to your registered email address within 72 hours. The notification will detail the type of data affected, the measures taken, and your rights. A formal notification is also made to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurulu).
Apply for Access to Your Data
KVKK Art. 13 — we respond to your requests within 30 days, free of charge.