Privacy & Cookie Policy
Last updated: 28 September 2026
1. About This Policy
This Privacy and Cookie Policy explains how Eskinazi Tours & Events collects, uses, stores, shares, and protects personal information when you:
Visit www.eskinazi.com; submit an inquiry; request or receive a quotation; make or manage a booking; use our secure passenger-information, document-upload, or Mail Order authorization portal; participate in a tour, transfer, package, activity, or event; communicate with us by email, telephone, WhatsApp, or another channel; or otherwise use our services.
This Policy also explains your privacy rights and how cookies and similar technologies are used on our website.
2. Who We Are
The data controller responsible for the processing described in this Policy is:
Eskinazi Turizm ve Ticaret Limited Sirketi
Trading as: Eskinazi Tours & Events
TURSAB-registered agency: Examplar Travel
TURSAB Licence No.: A-6996
MERSIS No.: 0069045259200013
Registered address:
Hasanpasa Mahallesi, Nabizade Sokak No: 42 D: 4
Kadikoy, Istanbul, Türkiye
Email: info@eskinazi.com
Telephone/WhatsApp: +90 530 700 35 53
In this Policy, “Eskinazi Tours & Events,” “we,” “us,” and “our” refer to Eskinazi Turizm ve Ticaret Limited Sirketi.
3. Scope
This Policy applies to personal information processed in connection with Eskinazi Tours & Events’ travel, tourism, transportation, accommodation, event, and website services.
It covers individual travelers, people included in group bookings, corporate customers, travel-agency customers, event attendees, website visitors, inquiry contacts, and other people whose personal information is provided to us.
This Policy does not govern websites, booking systems, social networks, or services independently operated by third parties. Those organizations process information under their own privacy policies.
4. Personal Information We Collect
Depending on your interaction with us, we may collect the following categories of information.
4.1 Identity information
This may include:
Full name; date of birth; nationality; gender, where required for a booking or legal reporting; passport number; Turkish identity number or foreign identity number; passport or identity-document copies; and signature.
4.2 Contact information
This may include:
Email address; telephone or mobile number; WhatsApp contact details; postal or billing address; emergency-contact information; and contact details of a group organizer, travel agent, corporate contact, or representative.
4.3 Booking and travel information
This may include:
Travel dates; group size and passenger list; tour interests and itinerary preferences; flight numbers, arrival times, and departure information; hotel and accommodation details; transfer and transportation information; room, seating, and ticket preferences; activity and event reservations; special requests; booking history; supplier confirmations; and information required for passenger-reporting systems.
4.4 Health and special-requirement information
Where relevant and voluntarily disclosed, we may process information concerning:
Allergies; dietary requirements; mobility limitations; disabilities; pregnancy; medical conditions relevant to safe participation; accessibility needs; and emergency assistance requirements.
We request only information reasonably necessary to assess or provide the requested service.
Health and disability information may be treated as sensitive or special-category personal data. Where required, we will request explicit consent or rely on another lawful condition permitted by applicable law.
4.5 Payment and transaction information
This may include:
Payment amount and currency; payment date and status; bank-transfer details; partial or masked payment-card information; transaction references; refund information; billing details; and records needed to prevent fraud, resolve disputes, or meet accounting requirements.
Credit-card link payments are processed through Turkiye Is Bankasi or another payment provider identified during the payment process.
Customers should not send full payment-card numbers or card security codes through ordinary email, WhatsApp, or another unsecured messaging channel.
Where payment through our ordinary bank payment link is not reasonably available, Eskinazi Tours & Events may invite the cardholder or an authorized representative to use our secure portal for a specific Mail Order transaction. The secure form displays the amount and currency to be authorized and may collect the cardholder’s full name, card number, expiry date, card security code, and affirmative authorization for the displayed amount.
Mail Order card details are encrypted before database storage and used only to authorize and complete the displayed transaction. They are permanently deleted immediately after the transaction has been authorized and marked as processed by authorized staff. If the transaction has not been completed earlier, the secure system automatically deletes the card details no later than seven days after submission. Card security codes, including CVV or CVC values, are never retained after authorization.
Payment-card information is not copied into Trello or Google Drive and is not included in submission-notification emails. We do not use payment-card information for unrelated purposes.
4.6 Inquiry and communication information
When you contact us, we may collect:
Your full name; email address; message; information included in your inquiry; email and WhatsApp correspondence; complaint and support records; and notes relating to calls or meetings.
We do not record telephone or WhatsApp calls.
4.7 Event information
For corporate and private events, we may process:
Client and organizer details; attendee or guest lists; event schedules; venue and catering requirements; dietary and accessibility needs; supplier arrangements; technical requirements; payment and invoicing information; and information relating to safety, permits, or event management.
4.8 Website and technical information
When you use our website, we or our technology providers may collect:
IP address; browser type and version; device type; operating system; approximate location derived from an IP address; pages visited; referring page or website; date and time of access; website interactions; cookie identifiers; advertising or analytics identifiers; security and fraud-prevention information; and technical logs.
4.9 Photographs and video
We may process photographs or video from tours or events where:
You have separately agreed to their use; they are necessary to deliver a requested photography or event service; or another lawful basis applies.
We will not use an identifiable guest’s image for Eskinazi Tours & Events marketing without separate permission.
Permission for an identifiable child’s image must be provided by a parent or legal guardian.
5. How We Collect Personal Information
We may collect information:
Directly from you; through website inquiry forms; through our secure passenger-information, document-upload, and Mail Order authorization portal at secure.eskinazi.com; by email; through WhatsApp Business; by telephone or during an in-person conversation; through quotations, contracts, and booking documents; through payment and bank records; from a person making a booking on your behalf; from travel agencies, corporate clients, group leaders, event organizers, hotels, or other booking partners; from airlines, hotels, transport companies, guides, venues, and other service providers; from cookies and similar website technologies; and from public authorities or official systems where necessary.
A person providing information about another traveler or participant must be authorized to do so and should provide that person with this Policy.
6. Why We Process Personal Information
We may process personal information for the following purposes:
Responding to inquiries; preparing quotations, proposals, and customized itineraries; taking steps requested before entering into a contract; confirming and administering bookings; providing tours, transfers, accommodation, transportation, flights, activities, cruises, charters, events, and related services; coordinating guides, drivers, hotels, airlines, venues, and suppliers; issuing tickets, reservations, confirmations, and travel documents; managing payments, deposits, balances, refunds, and invoices; communicating service updates and meeting instructions; providing customer support and emergency assistance; meeting dietary, accessibility, medical, or safety requirements; managing corporate and private events; complying with U-ETDS passenger reporting and other legal obligations; meeting tourism, transportation, tax, accounting, insurance, security, and regulatory requirements; detecting and preventing fraud, misuse, or security threats; protecting customers, staff, suppliers, and the public; investigating complaints and resolving disputes; establishing, exercising, or defending legal claims; maintaining and improving our website and services; measuring website performance; measuring advertising effectiveness, where permitted; protecting website availability and security; and complying with lawful requests from authorities.
We do not make decisions that have a significant legal or similar effect on customers solely through automated processing.
7. Legal Bases for Processing
Depending on the information and circumstances, we may rely on one or more of the following legal bases:
Processing necessary to take steps at your request before a contract; processing necessary to perform a booking or other contract; processing necessary to comply with a legal obligation; processing necessary for our legitimate interests or the legitimate interests of another party, where those interests are not overridden by your rights; your explicit consent, where processing legally requires consent; processing necessary to establish, exercise, or defend legal rights; processing necessary to protect a person’s vital interests in an emergency; or another processing condition permitted by applicable law.
Our legitimate interests may include responding to customers, operating and securing our business, coordinating suppliers, improving services, preventing fraud, maintaining appropriate records, and handling legal claims.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal will not affect processing that was lawful before the withdrawal.
A privacy notice and a request for consent are separate matters. We will not treat general acceptance of this Policy as consent for every processing activity.
8. Sensitive and Health Information
We may need limited health, allergy, dietary, disability, mobility, or accessibility information to provide a requested service safely.
We will:
Request only relevant information; use it only for the applicable service, safety, or legal purpose; restrict access to authorized personnel; share it only with providers who reasonably need it; request explicit consent where required; and delete it according to our retention schedule unless longer retention is legally necessary.
Please do not provide detailed medical records unless we specifically request them and provide a secure method for doing so.
Eskinazi Tours & Events does not provide medical advice and may ask you to obtain professional medical guidance before participating in an activity.
9. Children’s Information
The website and booking services are intended for adults aged 18 or older.
We may process information about children where a parent, legal guardian, group organizer, travel agent, or other authorized adult makes a booking that includes them.
The responsible adult must ensure that:
The child’s information is accurate; sharing the information is lawful; required permissions and travel documents are obtained; and information concerning the child is provided only where necessary.
We do not knowingly invite children to submit booking inquiries independently.
10. Secure Passenger Information and Mail Order Portal
For a particular booking, Eskinazi Tours & Events may provide a unique link to our secure portal at secure.eskinazi.com.
The categories requested are selected for that booking and may include:
Passenger full name, nationality, and passport number; a passport or travel-document copy in an accepted file format; and/or Mail Order authorization information for the exact amount and currency displayed on the form.
We request only the categories reasonably necessary for the applicable booking or transaction.
Passenger and passport information is used to arrange and provide the requested travel services, complete required reservations, satisfy applicable passenger-reporting or supplier requirements, and meet related operational or legal obligations.
Mail Order information is used only to authorize and complete the displayed transaction.
Information submitted through the portal is transmitted over HTTPS. Passport numbers and Mail Order authorization details are encrypted before database storage. Passport files are held in private, access-controlled object storage and are not publicly accessible. The administrative area is restricted through Cloudflare Access.
Submission-notification emails do not contain passenger names, nationalities, passport numbers, passport files, card numbers, expiry dates, card security codes, or guest submission links.
For secure passenger-information requests, Eskinazi Tours & Events sets the first service date associated with the request. The passenger cannot modify this date through the secure submission form. Passenger information and passport documents submitted through the secure portal are scheduled for automatic deletion at the end of that first service date, unless earlier deletion is appropriate or continued retention is required by applicable law or another lawful necessity.
A person who submits information about another passenger or cardholder confirms that they are authorized to provide that information and should make this Policy available to that person.
11. How We Use Trello and Google Workspace
We use Google Workspace, Google Drive, and Trello to communicate, organize bookings, manage schedules, coordinate arrangements, and maintain operational records.
Trello may contain information concerning:
Travelers and participants; contact details; itineraries and schedules; supplier arrangements; limited passenger information necessary for operational coordination, excluding passport numbers, passport copies, and Mail Order card details submitted through the secure portal; dietary, accessibility, or health requirements; payment status; and other information necessary to manage the booked services.
Access is limited to the owner and authorized employees of Eskinazi Tours & Events who require the information for their work. Access controls and two-factor authentication are used.
Payment-card numbers and card security codes must not be stored in Trello or Google Drive.
Passport numbers, passport copies, and Mail Order details submitted through the secure portal are not copied into Trello or Google Drive. Staff access those items through the protected administrative area only when reasonably necessary for the applicable booking or transaction.
Passport copies, sensitive information, and other short-term operational data are deleted according to the retention periods described in this Policy.
12. Who We Share Information With
We may share relevant information with the following categories of recipients where necessary:
Hotels and accommodation providers; airlines and ticketing providers; guides and tour personnel; drivers and transportation companies; hot-air-balloon operators; yacht, Bosphorus cruise, and gulet operators; private jet operators; restaurants, caterers, and venues; museums, attractions, synagogues, religious locations, and activity providers; event suppliers and entertainment providers; payment providers and banks, including Turkiye Is Bankasi; insurance providers where applicable; Google Workspace and Google Drive; Atlassian/Trello; SiteGround; Cloudflare and Turnstile; Google Analytics, Google Ads, Google Maps, YouTube, and reCAPTCHA; Meta, where the Meta Pixel or a Meta service is used; Trustindex; WhatsApp/Meta; website, hosting, IT, cybersecurity, and technical-service providers; government passenger-reporting systems; tourism, transportation, immigration, tax, law-enforcement, judicial, or regulatory authorities; and other parties where disclosure is required by law or necessary for a legal claim.
We disclose only information reasonably necessary for the relevant purpose.
Independent suppliers may also act as separate data controllers under their own privacy policies.
13. International Transfers
Some customers, suppliers, and technology providers are located outside Turkiye. Personal information may therefore be processed or stored in another country.
International recipients may include:
Overseas airlines, hotels, and travel suppliers; Google; Atlassian/Trello; Meta and WhatsApp; Cloudflare; SiteGround or its infrastructure providers; international payment or communications providers; and other providers necessary for a booking.
Where personal information is transferred outside Turkiye, we will use a transfer method permitted by applicable law.
Depending on the circumstances, this may include:
A country, sector, or organization recognized as providing adequate protection; a legally approved standard contract; binding corporate rules; another appropriate safeguard; a statutory exception; or explicit consent where consent is legally available and appropriate.
Where the GDPR or UK GDPR applies, we will use an applicable adequacy decision, approved contractual safeguard, statutory exception, or other lawful transfer mechanism.
14. Data Security
We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
Measures may include:
Access restrictions; two-factor authentication; password and account controls; secure website connections; protected cloud services; staff access based on operational need; timely removal of unnecessary access; secure document deletion; website-security and anti-bot services; security monitoring; incident-response procedures; and periodic review of access and retention.
No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we will act reasonably to reduce risk and respond to suspected incidents.
Customers should not send full card details, CVV codes, or unnecessary sensitive documents through ordinary email, WhatsApp, or other unsecured channels.
15. Data Breaches
If we become aware of a suspected personal-data breach, we will:
Investigate the incident; take reasonable steps to contain and reduce harm; preserve necessary evidence; assess the type of information and people affected; contact relevant providers where necessary; and notify regulators and affected individuals where required by law.
16. Retention and Deletion
We retain personal information only for as long as reasonably necessary for its purpose, legal obligations, and legitimate legal needs.
Our general retention periods are:
Unsuccessful inquiries: two years after the last communication.
Website inquiry-form submissions: two years.
Confirmed booking contracts, quotations, invoices, payment records, and material contractual correspondence: ten years, or longer where legally required.
Routine booking communications that are not required as formal records: three years after the service.
Passenger information and passport documents submitted through our secure portal: scheduled for automatic deletion at the end of the first service date associated with the relevant secure request. The first service date is entered and controlled by Eskinazi Tours & Events and cannot be modified by the passenger through the secure submission form. Information may be deleted earlier where it is no longer required or retained longer where continued retention is required by law or another lawful necessity.
Passport or operational identity information received outside the secure portal: deleted when no longer needed, normally within 30 days after the relevant service, unless longer retention is legally required.
Health, dietary, mobility, accessibility, and emergency-contact information: normally within 30 days after the service.
Mail Order card authorization information submitted through the secure portal: permanently deleted immediately after the transaction has been authorized and marked as processed by authorized staff. If the transaction has not been completed earlier, the secure system automatically deletes the card details no later than seven days after submission.
Card security codes (CVV/CVC): never retained after authorization.
Security and technical logs: normally 12 months.
Google Analytics user-level data: normally configured for a maximum of 14 months.
Complaint, chargeback, audit, investigation, or legal-claim records: until the matter and applicable limitation period have ended.
Information may be retained for longer where required by law, a court order, an authority, an active dispute, or another lawful necessity.
When information is no longer required, it will be deleted, destroyed, anonymized, or placed beyond ordinary use in accordance with applicable law.
17. Your Privacy Rights
Depending on the law that applies, you may have the right to:
Ask whether we process your personal information; request information about that processing; obtain access to your personal information; request correction of inaccurate or incomplete information; request deletion, destruction, or anonymization where legally available; request restriction of processing; object to certain processing; request data portability where applicable; withdraw consent; object to certain automated decisions; ask that correction or deletion be communicated to relevant recipients; request compensation where permitted by law; and lodge a complaint with a competent authority.
Rights may be limited where continued processing is required by law, necessary for a contract, or needed to establish, exercise, or defend legal rights.
18. How to Exercise Your Rights
To make a privacy request, contact:
Email: info@eskinazi.com
Please describe your request clearly and identify the information or booking concerned.
We may request reasonable information to verify your identity and protect personal information from unauthorized disclosure. We will not request more identity information than reasonably necessary.
We will respond within the period required by applicable law.
You may also have the right to complain to:
The Turkish Personal Data Protection Authority; a competent supervisory authority in the European Union; the United Kingdom Information Commissioner’s Office; or another authority available under applicable law.
We encourage you to contact us first so we can try to address your concern.
19. Cookies and Similar Technologies
Cookies are small files or identifiers stored on or accessed through a device when a website is visited.
We may use cookies, pixels, local storage, scripts, and similar technologies for:
Website operation; security; fraud and bot prevention; remembering preferences; analytics; performance measurement; embedded content; advertising measurement; and understanding how visitors use the website.
Some technologies are set directly by Eskinazi Tours & Events. Others are set by third-party providers.
20. Cookie Categories
20.1 Strictly necessary cookies
These technologies are required for website operation, security, network management, consent management, or fraud prevention.
They may include technologies used by:
SiteGround; Cloudflare; Cloudflare Turnstile; Google reCAPTCHA; and the website’s content-management and security systems.
Strictly necessary technologies do not require consent where applicable law permits them to operate without consent.
20.2 Analytics cookies
Analytics technologies help us understand:
How many people visit the website; which pages are viewed; how visitors navigate the website; whether errors occur; and how the website can be improved.
Google Analytics may be used for these purposes.
Analytics cookies will be activated only after consent where consent is legally required.
20.3 Advertising and measurement cookies
Google Ads and Meta Pixel may be used to measure whether advertising leads to website visits or inquiries.
Eskinazi Tours & Events does not currently use this information to create remarketing audiences or deliberately show targeted advertisements to previous website visitors.
Advertising and measurement cookies will be activated only after consent where required.
20.4 Functionality and embedded-content cookies
Third-party content or features may use cookies or similar technologies, including:
Google Maps; YouTube; Trustindex review widgets; WhatsApp buttons; and social-media content.
These providers may receive technical information when a feature is loaded or used.
Where required, non-essential embedded content will be blocked until the visitor consents.
21. Cookie Choices
Where legally required, the website will provide a cookie-consent mechanism allowing visitors to:
Accept non-essential cookies; reject non-essential cookies; choose cookie categories; and change or withdraw their choices later.
Rejecting non-essential cookies should not prevent access to the website’s core content, although some embedded features may not function.
Visitors may also manage cookies through their browser settings. Deleting or blocking cookies may affect website functionality.
Consent choices apply to the particular browser and device used. A visitor may need to repeat their choice when using another device, clearing cookies, or using a different browser.
22. Third-Party Services
Third-party services used on the website may process information according to their own privacy and cookie policies.
These providers may include:
Google; Meta and WhatsApp; Cloudflare; SiteGround; Trustindex; and Atlassian/Trello.
We encourage visitors to review the relevant third-party policies.
We are not responsible for the privacy practices of unrelated third-party websites reached through external links.
23. Marketing Communications
Eskinazi Tours & Events does not currently operate an email newsletter.
We will not send electronic direct-marketing messages where consent or another lawful basis is required unless that requirement has been satisfied.
You may object to direct marketing or withdraw marketing consent at any time by contacting info@eskinazi.com.
Service messages concerning an inquiry, booking, safety issue, schedule, payment, or requested service are not marketing communications.
24. Sale of Personal Information
Eskinazi Tours & Events does not sell or rent personal information.
Where laws provide a specific right to opt out of the “sale” or “sharing” of personal information, we will honor that right to the extent the relevant legal definition applies to our activities.
25. Changes to This Policy
We may update this Policy to reflect changes in:
Our services; website technologies; suppliers; legal requirements; security practices; or data-processing activities.
The current version will be published on this page with its last-updated date.
Where a change materially affects how we use previously collected information, we will provide additional notice where required by law.
26. Contact Us
Questions, cancellation requests, change requests, and complaints should be sent to:
Eskinazi Tours & Events
Eskinazi Turizm ve Ticaret Limited Sirketi
Hasanpasa Mahallesi, Nabizade Sokak No: 42 D: 4
Kadikoy, Istanbul, Türkiye
Email: info@eskinazi.com
Telephone/WhatsApp: +90 530 700 35 53
TURSAB agency: Examplar Travel
TURSAB Licence No.: A-6996
MERSIS No.: 0069045259200013