Last updated: 15 August 2026
This policy explains how Canvilia collects, uses, shares and protects personal data when you browse our website, create an account, contact us, offer a villa or make and manage a booking. It also explains the choices and rights available to you.
JV Turizm Gıda ve İnş. Tic. Ltd. Şti., trading as Canvilia, is the data controller.
The data we collect depends on how you use Canvilia.
| Category | Examples |
|---|---|
| Identity and contact data | Name, surname, email address and phone number |
| Account data | Account identifier, sign-in credentials in protected form, preferred language and account settings |
| Booking and stay data | Villa choice, arrival and departure dates, adult, child and infant counts, flight details, booking status, notes and special requests |
| Billing data | Billing address, company name, tax number and other information needed for an invoice |
| Payment records | Amount, currency, date, status, payment method, transaction reference, deposit, balance and refund records |
| Communications | Email, phone, WhatsApp, customer-service and CRM correspondence |
| Technical and security data | IP address, device and browser information, session records, security logs and fraud-prevention signals |
| Usage and analytics data | Pages and villas viewed, interactions, referral and campaign information, cookie choices, and Google Analytics client and session identifiers |
| Villa-owner enquiry data | Contact details, property information and the contents of an owner enquiry |
Canvilia does not store or log your full card number, card security code or card expiry date. Card details are sent to the relevant bank or payment provider to complete the transaction.
If you make a booking for other guests, you should give us only information you are authorised to provide and tell those guests how their data will be used.
We collect data directly from you when you use a form, create an account, contact us or make a booking. We also collect technical and usage data automatically through our website, cookies and similar technologies. We may receive data from a person booking on your behalf, a villa owner or operator, a bank or payment provider, or a service provider helping us operate the booking.
We use personal data only where we have a recognised legal basis.
| Purpose | Main legal basis |
|---|---|
| Respond to questions and take steps requested before a booking or contract | Steps before a contract and legitimate interests |
| Create and operate an account | Contract |
| Receive, review, confirm and manage a booking | Contract |
| Coordinate a stay with the relevant villa owner or operator | Contract |
| Process payments, deposits, balances and refunds | Contract and legal obligations |
| Issue invoices and keep tax and accounting records | Legal obligations |
| Provide customer service and maintain relevant correspondence | Contract and legitimate interests |
| Respond to villa owners offering a property | Steps before a contract and legitimate interests |
| Protect accounts, prevent fraud, secure our systems and establish or defend legal claims | Legal obligations and legitimate interests |
| Measure website use and marketing performance | Consent where required |
| Send marketing communications | Consent where required |
Our legitimate interests include operating and improving Canvilia, answering enquiries, preventing misuse, keeping appropriate business records and protecting our legal rights. We consider the effect on your rights before relying on legitimate interests. You may object to this processing in the circumstances described below.
We share only the data reasonably needed for the relevant purpose. Recipients may include:
We do not sell personal data.
Canvilia is based in Türkiye and its primary hosting is in Türkiye. Some providers, including Google, Cloudflare and Meta, may process data in other countries.
Where a transfer requires a legal mechanism, we use the mechanism available under the applicable law. Depending on the destination, this may include an adequacy decision, approved standard contractual clauses, the UK transfer addendum, a mechanism under Article 9 of the KVKK or another safeguard recognised by the GDPR or UK GDPR. You may contact us for information about the safeguard relevant to your data.
We do not keep personal data indefinitely simply because it may be useful later. The following maximum periods apply unless a longer or shorter period is required by law, a dispute or a regulator:
| Record | Maximum retention |
|---|---|
| Booking, payment, invoice and booking-related correspondence | 10 years after the end of the relevant financial year |
| Active account profile | While the account remains active |
| Closed account profile | Deleted or anonymised within 90 days, except records kept for another lawful purpose |
| Guest or villa-owner enquiry that does not become a booking or contract | 2 years after the last meaningful contact |
| General support, email, WhatsApp and CRM correspondence | Up to 5 years after the last contact |
| Routine security and access logs | 12 months |
| Records connected with a security incident, dispute or legal claim | Until the matter closes, then up to 5 years where necessary |
| Google Analytics user-level and event-level data | Up to 14 months |
| Analytics identifiers stored with a booking | The booking record's 10-year period |
| Records showing deletion, destruction or anonymisation | At least 3 years |
Deleted operational data may remain in protected backups for up to 90 days before being overwritten. When a legal hold applies, we restrict the relevant record and keep it only for the hold's duration.
We use cookies and browser storage for sign-in, language and currency preferences, consent choices, security, website measurement and selected third-party features. Analytics and advertising storage is controlled through our consent mechanism where consent is required. Details are in our Cookie policy.
Your rights depend on the law and the legal basis that applies. They may include the right to:
We do not make decisions that produce legal or similarly significant effects solely by automated means. Every booking request is reviewed by a person before confirmation.
To exercise a right, email [email protected] or write to our address above. Please describe your request and the account, booking or contact details needed to locate the relevant records. We may ask for reasonable proof of identity. We will respond within the period required by the law that applies to your request.
You may also complain to the Turkish Personal Data Protection Authority, the UK Information Commissioner's Office or the data-protection authority in the EEA country where you live or work.
We use technical and organisational safeguards designed for the nature of the data and the risks involved. These include access controls, protected authentication cookies, encrypted connections, logging, backups and restrictions on who may access operational records. No internet service can guarantee absolute security.
We may update this policy when our services, providers or legal obligations change. The date at the top shows the latest revision. If a change materially affects how we use personal data, we will provide an appropriate notice and request consent again where required.
For privacy questions or requests: