Last updated: 6 October 2026
This policy explains what personal data Bodrum Discovery collects, what we use it for, who we share it with and what rights you have. It applies under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and, where it applies to you, the EU General Data Protection Regulation (GDPR).
The data controller is 4 S Bilgi İşlem Turizm Seyahat Reklam İthalat Ve İhracat Ticaret Limited Şirketi, trading as SunMed Travel Agency (TÜRSAB licence no. A-12195). "We", "us" and "our" in this policy mean this company and Bodrum Discovery.
Siteler Mah. 206 Sok. No. 2 K. 1 D. 111 48700 Marmaris / Muğla / Türkiye
Email: info@marmarisexcursions.com
Phone / WhatsApp / Telegram: +90 553 259 2481
Office: +90 252 417 11 28 / +90 252 417 11 69
Fax: +90 252 417 07 14
Website: bodrumdiscovery.com
When you book, we collect what we need to arrange the tour: your name, email address and phone number, the tour and date, the number of people, your hotel (and room number if it's needed for pickup), pickup and drop-off details, the booking reference, and any notes or special requests you give us. If you enter your details on the payment page but don't complete the booking, we keep them so we can contact you and help you finish it.
Depending on the tour, this can also include passenger details, such as passport details for ferries to the Greek islands, and any accessibility or dietary needs you tell us about. Please only give us information the booking actually needs.
When you visit the website, some technical data is recorded automatically: IP address, browser and operating system, device type, language, which pages you visit and when, the site you came from, and error and security logs.
We process your data because it is needed to carry out your booking (or steps you asked for before booking), because the law requires it, because we have a legitimate business interest such as security and fraud prevention, to establish or defend legal claims, or with your consent where consent is required. Under Turkish law we rely on the conditions set out in KVKK; where the GDPR applies, on the corresponding GDPR legal bases.
Card payments are processed by our bank with 3D Secure. We do not store full card numbers, CVV/CVC codes or card authentication data; we only keep a masked card number with most digits hidden. We keep a record of the transaction itself (amount, currency, status, reference number, date and any refund) for accounting, customer support, fraud prevention and legal reasons.
We do not sell your personal data. We share it only when it's needed to provide your booking or when the law requires it:
Some of our technology, payment, messaging and analytics providers may process data outside Türkiye or the European Economic Area. When that happens we use the safeguards that data protection law requires, such as contractual protections, approved transfer mechanisms or adequacy decisions.
The website uses cookies and similar technologies. Essential cookies keep the site working: your booking session and basket, language and currency choice, login, security and fraud prevention. Where analytics or marketing cookies are used, they help us see how the site is used and measure advertising. If the law requires consent for non-essential cookies, we only set them after you agree. You can block or delete cookies in your browser settings.
Where the law allows, we may send you offers and information about tours and travel services. You can unsubscribe at any time. Unsubscribing does not stop messages about a booking you already have.
If you contact us by WhatsApp, Telegram, email, phone or text message, we use what you send to answer you and manage your booking. These platforms also process data under their own privacy policies. Please don't send sensitive information by message unless we ask for it.
We protect personal data against unauthorised access, loss, alteration and disclosure with HTTPS encryption, access controls, restricted admin access, server security, firewalls, monitoring, backups and security logging. No system on the internet is completely secure, but we take reasonable technical and organisational measures.
We keep personal data only as long as we need it for the purposes above, or longer where tax, accounting, commercial, consumer protection or tourism law requires it. After that we delete it, anonymise it or dispose of it securely.
Subject to applicable law, you can ask us whether we process your data; get access to it; have it corrected if it is wrong or incomplete; have it deleted or destroyed where the law allows; restrict or object to certain processing; receive your data in a portable format where the GDPR applies; and withdraw consent where we rely on it. Under KVKK these rights are set out in Article 11. You can also complain to the relevant data protection authority.
Email us at info@marmarisexcursions.com with the subject "Personal Data Request". We may ask for information to confirm your identity first. We will reply within the period set by law.
Tours can be booked for children. Information about a child should be given by a parent, legal guardian or another person authorised to do so. We do not use children's data for anything other than the booking.
If a payment is disputed or charged back, we may give the bank or payment provider the relevant records: the booking and its confirmation, the voucher, transaction details, cancellation and refund records, relevant messages with you, and evidence of the service we provided or offered. We use this only to respond to the dispute and to prevent fraud.
Our site links to other websites and services, such as the bank's payment page or maps. We are not responsible for their content, security or privacy practices, so please read their own policies.
We use automated systems for analytics, security, fraud prevention and day-to-day operations. We do not normally make decisions with legal or similarly significant effects about you based only on automated processing. Any additional rights the law gives you on this point are unaffected.
We may update this policy when our services, website, technology, providers, the law or the way we process data change. The current version is always on this page with its "last updated" date. Where the law requires it, we will notify you or ask for your consent before significant changes.
This policy is governed by the laws of the Republic of Türkiye. Where the GDPR or another mandatory data protection law applies to you, its mandatory provisions also apply. Nothing in this policy removes or restricts a right you have by law. If any part of it is found invalid, the rest still applies as far as the law allows.