Privacy Policy

Last updated: 15 August 2026

This policy explains how Canvilia collects, uses, shares and protects personal data when you browse our website, create an account, contact us, offer a villa or make and manage a booking. It also explains the choices and rights available to you.

Who is responsible for your data?

JV Turizm Gıda ve İnş. Tic. Ltd. Şti., trading as Canvilia, is the data controller.

  • Address: Bezirgan Mahallesi, Ulugöl Sokak No: 707/9 D, 07960 Kaş/Antalya, Türkiye
  • MERSİS number: 0484082923600001
  • Tax number: 4840829236
  • Email: [email protected]
  • Phone: +90 538 240 10 67

What personal data do we collect?

The data we collect depends on how you use Canvilia.

CategoryExamples
Identity and contact dataName, surname, email address and phone number
Account dataAccount identifier, sign-in credentials in protected form, preferred language and account settings
Booking and stay dataVilla choice, arrival and departure dates, adult, child and infant counts, flight details, booking status, notes and special requests
Billing dataBilling address, company name, tax number and other information needed for an invoice
Payment recordsAmount, currency, date, status, payment method, transaction reference, deposit, balance and refund records
CommunicationsEmail, phone, WhatsApp, customer-service and CRM correspondence
Technical and security dataIP address, device and browser information, session records, security logs and fraud-prevention signals
Usage and analytics dataPages and villas viewed, interactions, referral and campaign information, cookie choices, and Google Analytics client and session identifiers
Villa-owner enquiry dataContact details, property information and the contents of an owner enquiry

Canvilia does not store or log your full card number, card security code or card expiry date. Card details are sent to the relevant bank or payment provider to complete the transaction.

If you make a booking for other guests, you should give us only information you are authorised to provide and tell those guests how their data will be used.

How do we collect personal data?

We collect data directly from you when you use a form, create an account, contact us or make a booking. We also collect technical and usage data automatically through our website, cookies and similar technologies. We may receive data from a person booking on your behalf, a villa owner or operator, a bank or payment provider, or a service provider helping us operate the booking.

Why do we use personal data?

We use personal data only where we have a recognised legal basis.

PurposeMain legal basis
Respond to questions and take steps requested before a booking or contractSteps before a contract and legitimate interests
Create and operate an accountContract
Receive, review, confirm and manage a bookingContract
Coordinate a stay with the relevant villa owner or operatorContract
Process payments, deposits, balances and refundsContract and legal obligations
Issue invoices and keep tax and accounting recordsLegal obligations
Provide customer service and maintain relevant correspondenceContract and legitimate interests
Respond to villa owners offering a propertySteps before a contract and legitimate interests
Protect accounts, prevent fraud, secure our systems and establish or defend legal claimsLegal obligations and legitimate interests
Measure website use and marketing performanceConsent where required
Send marketing communicationsConsent where required

Our legitimate interests include operating and improving Canvilia, answering enquiries, preventing misuse, keeping appropriate business records and protecting our legal rights. We consider the effect on your rights before relying on legitimate interests. You may object to this processing in the circumstances described below.

Who receives personal data?

We share only the data reasonably needed for the relevant purpose. Recipients may include:

  • the villa owner or operator responsible for your stay, who may receive the lead guest's name and phone number, guest count and relevant arrival or stay information;
  • Yapı Kredi Posnet, other banks and payment institutions involved in a payment;
  • accounting, invoicing and professional advisers;
  • our hosting provider in Türkiye and providers of IT, security, content delivery, email and CRM services;
  • Cloudflare for website delivery and security;
  • Google for Analytics, Maps and Places services;
  • Meta when you choose to communicate with us through WhatsApp;
  • public bodies, courts, law-enforcement authorities or regulators where disclosure is required or legally permitted.

We do not sell personal data.

Do we transfer data internationally?

Canvilia is based in Türkiye and its primary hosting is in Türkiye. Some providers, including Google, Cloudflare and Meta, may process data in other countries.

Where a transfer requires a legal mechanism, we use the mechanism available under the applicable law. Depending on the destination, this may include an adequacy decision, approved standard contractual clauses, the UK transfer addendum, a mechanism under Article 9 of the KVKK or another safeguard recognised by the GDPR or UK GDPR. You may contact us for information about the safeguard relevant to your data.

How long do we keep personal data?

We do not keep personal data indefinitely simply because it may be useful later. The following maximum periods apply unless a longer or shorter period is required by law, a dispute or a regulator:

RecordMaximum retention
Booking, payment, invoice and booking-related correspondence10 years after the end of the relevant financial year
Active account profileWhile the account remains active
Closed account profileDeleted or anonymised within 90 days, except records kept for another lawful purpose
Guest or villa-owner enquiry that does not become a booking or contract2 years after the last meaningful contact
General support, email, WhatsApp and CRM correspondenceUp to 5 years after the last contact
Routine security and access logs12 months
Records connected with a security incident, dispute or legal claimUntil the matter closes, then up to 5 years where necessary
Google Analytics user-level and event-level dataUp to 14 months
Analytics identifiers stored with a bookingThe booking record's 10-year period
Records showing deletion, destruction or anonymisationAt least 3 years

Deleted operational data may remain in protected backups for up to 90 days before being overwritten. When a legal hold applies, we restrict the relevant record and keep it only for the hold's duration.

Cookies and similar technologies

We use cookies and browser storage for sign-in, language and currency preferences, consent choices, security, website measurement and selected third-party features. Analytics and advertising storage is controlled through our consent mechanism where consent is required. Details are in our Cookie policy.

What are your rights?

Your rights depend on the law and the legal basis that applies. They may include the right to:

  • ask whether we process your personal data and receive a copy;
  • correct incomplete or inaccurate data;
  • request deletion or destruction when there is no continuing lawful reason to keep the data;
  • restrict processing in certain circumstances;
  • receive data you provided in a portable format where the right applies;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent at any time, without affecting processing that took place before withdrawal;
  • ask about recipients in Türkiye or abroad and request notification of certain corrections or deletions; and
  • seek compensation where unlawful processing causes damage.

We do not make decisions that produce legal or similarly significant effects solely by automated means. Every booking request is reviewed by a person before confirmation.

To exercise a right, email [email protected] or write to our address above. Please describe your request and the account, booking or contact details needed to locate the relevant records. We may ask for reasonable proof of identity. We will respond within the period required by the law that applies to your request.

You may also complain to the Turkish Personal Data Protection Authority, the UK Information Commissioner's Office or the data-protection authority in the EEA country where you live or work.

How do we protect personal data?

We use technical and organisational safeguards designed for the nature of the data and the risks involved. These include access controls, protected authentication cookies, encrypted connections, logging, backups and restrictions on who may access operational records. No internet service can guarantee absolute security.

Changes to this policy

We may update this policy when our services, providers or legal obligations change. The date at the top shows the latest revision. If a change materially affects how we use personal data, we will provide an appropriate notice and request consent again where required.

Contact us

For privacy questions or requests:

  • Email: [email protected]
  • Phone: +90 538 240 10 67
  • Address: Bezirgan Mahallesi, Ulugöl Sokak No: 707/9 D, 07960 Kaş/Antalya, Türkiye
Privacy Policy - Canvilia