Privacy Policy

Effective Date: 22.08.2026

This Privacy Policy describes how your personal data is collected, used for what purposes, shared with whom, and protected on ERSA İNŞAAT PROJE TURİZM SANAYİ VE TİCARET ANONİM ŞİRKETİ operated by https://pullmanistanbul.com .

The scope of the policy is what the site actually uses is limited to features: the following sections are automatically generated based on the modules, widgets, and integrations active on this site. Sections belonging to an unused service are not included in this text.

1. Data Controller

TitleERSA İNŞAAT PROJE TURİZM SANAYİ VE TİCARET ANONİM ŞİRKETİ
Company TypeJoint Stock Company
AddressYenibosna Merkez Mah. 1. Asena Sok. No: 15, Bahçelievler / İstanbul
Tax Office / NoYenibosna Vergi Dairesi / 3680247978
MERSİS Number0368024797800015
Phone+90 212 411 10 00

2. Personal Data We Process

The following data is always processed for the core operation of the site:

  • Identity and contact information: name, surname, email address and phone number information you have provided to us
  • Transaction security: IP address, session logs, browser and device information, mandatory cookie data
  • Request records: the content and history of communications you have had with us

Any other data processed is only included below if the relevant service is active on this site.

3. Our Processing Purposes

  • Fulfillment of your requests and applications
  • Ensuring account and session security
  • Compliance with legal obligations (tax, trade, consumer legislation)
  • Prevention of fraud and misuse
  • Measurement and improvement of site performance

4. Legal Bases (KVKK Article 5)

  • It is mandatory for the formation or performance of a contract
  • It is explicitly provided for by law and is necessary for the fulfillment of a legal obligation
  • Data processing is mandatory for the establishment, exercise, or protection of a right
  • Our legitimate interests, provided that they do not harm your fundamental rights and freedoms
  • Your explicit consent (for commercial communications, cookie-based marketing, etc.)

5. Who do we share with?

Your data is limited solely to the relevant purpose, and is shared with IT infrastructure and hosting providers, financial and legal advisors, and authorized public institutions and organizations upon request. The scope of data sharing for each additional service active on the site (such as payment, shipping, marketplace, messaging, measurement, etc.) is also specified in the relevant section below. In cases where data transfer abroad is required, the conditions stipulated by KVKK are complied with.

6. Retention Periods

  • Commercial ledgers and documents: 10 years (Turkish Commercial Code)
  • Tax and invoice records: 5 years (Tax Procedure Law)
  • Membership and communication records: a reasonable period after the relationship ends
  • Commercial communication consent records: 3 years from the withdrawal of consent
  • Traffic and transaction security records: as per the legislation's requirements

Your data will be deleted, destroyed, or anonymized at the end of these periods.

7. Data Security

Your data is protected by administrative and technical measures such as authorized access, encryption, secure connection (SSL/TLS), logging, and regular backups. Our staff is bound by confidentiality obligations.

8. Cookies

The full list of cookies used on the site, the service they belong to, and their retention periods are published on the Cookie Policy page; that list is also generated from the services that are actually active on this site. Non-essential cookies only operate with your consent, and you can change your preferences at any time.

9. Membership and Account Data

When you create an account on the site, your full name, email, phone number, and an irreversible hash of your password are processed. Login logs, IP address, and device information are retained for account security and to prevent abuse. You can view and edit your account and the information in it from the dashboard, as well as request the deletion of your account; upon a deletion request, records subject to legal retention obligations are stored in a limited manner until their retention period expires.

10. Two-Factor Authentication

When you protect your account with two-step verification, the secret key that matches your verification app and — if used — the phone number to which the verification code is sent are processed. Recovery codes are stored irretrievably. This data is used only to verify your identity and prevent unauthorized access to your account; it is not used for marketing purposes.

11. Payment Data

Payments are collected through licensed payment institutions. Your card number, expiration date, and CVC information are not visible to us and are not stored by us; this information is transmitted directly to the payment institution's infrastructure. We only keep data that helps match the transaction, such as the transaction result, transaction number, amount, installment information, and the first/last digits of the card. If you choose to use the card storage feature, the card information is again stored with the payment institution and only a reference (token) is returned to us.

12. Reservation and Appointment Data

When creating a reservation or appointment, your full name, contact information, date/time, number of guests, and any special requests are processed. This data is used to establish the reservation, send reminders, provide the service, and handle cancellation or modification requests. For group reservations, only the participant information strictly necessary to provide the service is processed.

13. Reservation Channels (Booking, Airbnb, etc.)

Our accommodation and availability information is also published on online reservation channels. For reservations made through these channels, the guest's name, contact information, accommodation dates, and payment status transmitted by the channel are forwarded to us and recorded in our system. The channel through which you made the reservation is also a data controller within the scope of its own privacy policy; the conditions of that channel also apply to cancellation and change rules.

14. Application and Registration Forms

When you fill out the application forms on the site (expert, trainer, author, organizer, venue owner, campaign application); name-surname, contact information, professional information and documents you added to the application are processed. This data is only used for the evaluation of the application and notification of the result. If your application is rejected, the records are kept for the period required for proof in case of potential disputes and deleted afterwards. You can request the deletion of your application at any time.

15. Form and Request Data

When you fill out the contact, offer, and application forms on the website, the name, contact information, and message content you share are processed for the purpose of evaluating your request, responding to you, and tracking the history of your request. We recommend that you do not write any sensitive information (ID number, health information, card details) that is not required in the form's message field. Unless you have specifically indicated your consent to receive commercial communications, your form data will not be used for marketing purposes.

16. Reviews and Ratings

When you submit a review, rating, or evaluation, your visible name, comment text, uploaded images (if any), submission date, and IP address are processed. Your comment's visible name and content are publicly accessible once it is published. Submitted content is filtered before publication; comments containing illegal material, insults, or advertisements are not published. You may request the removal of your comment.

17. Customer Relationships and Segmentation

Your communication history, requests, purchase, and interaction records are consolidated into a single customer record to manage the relationship established with you. These records are used to improve service quality, expedite your requests, and identify suitable campaigns for you and can be automatically segmented (e.g., new customer, regular shopper, long-term inactive).

Segmentation does not produce an automated decision with legal consequences for you; it merely determines the relevance of communication and offers. You have the right to object to this assessment and request a review of the decision.

18. Automatic Reminders and Notifications

When there is an unfinished order in your basket, an automatic reminder can be sent when a product you are following is back in stock or when you are asked to review a product you have purchased. For this, your basket/order record, e-mail address, and — if you have given permission — your phone number are processed. Each message contains an unsubscribe link; when you unsubscribe, reminders stop, and mandatory notifications regarding your order (confirmation, shipping, return) continue.

19. Notifications and Device Data

When you accept to receive notifications, your browser/device notification address (token), device type, and language information are processed. This data is solely used for sending notifications and measuring the success of the delivery. You can revoke the notification permission at any time through your browser or device settings; when you do so, your record is deleted.

20. Measurement and Analytics

Analytical tools are used to understand how the website is utilized. These tools collect data such as pages visited, session duration, referring address, approximate location (at city level), device, and browser information. Measurement cookies only operate with your consent, and you can withdraw your consent from the Cookie Policy page. As the providers' servers may be located abroad, data transfer to foreign countries may occur within this scope.

21. External Evaluation Platforms

The comments and ratings you write on external platforms (map/business profile, review sites) where our business profile is located are published within the framework of the rules of that platform. To be able to respond to these comments, the comment text, your visible name, and response history are transferred to our panel. The relevant platform is also a data controller in terms of this data; you can also request the deletion of your comment from the tools of that platform.

22. Social Media Components

The website may feature social media feeds or sharing buttons. When these components load, the respective platform may process data such as your IP address and the page you visited according to its own policies. Sharing a post is subject to the terms of the relevant platform.

23. Map and Location

A map service is used to display address and route information. When the map loads, it processes your IP address and device details provided by your browser. If your browser requests location permission, this is optional and you can decline; your location is not stored by us.

24. Google API Services and Connected Google Accounts

This website and its management panel run on the Milenyums platform operated by Millenniums. The application that connects to Google services from the panel is named Milenyums Dijital; its homepage is https://www.milenyums.com and its management panel is at https://partners.milenyums.com. The rules in this section apply to data obtained from Google when you voluntarily connect your Google account to the application.

Connecting is optional

Connecting a Google account is not mandatory; the website and the panel can be used in full without it. The connection is only established by you, through the “Connect with Google” button on the Integrations screen of the panel, and you see the permissions you grant on Google's consent screen. The authorisation flow returns to https://partners.milenyums.com/oauth/geri-donus/….

Requested permissions and how they are used

Only the permission of the service you choose to connect is requested; no permission is requested for a service you do not use.

Google Business Profile.../auth/business.manageRead the business account and location list, import customer reviews into the panel and reply to them, update business information and posts
Google Search Console.../auth/webmasters, .../auth/siteverificationVerify site ownership, add the property to your account, submit sitemaps and read search performance data
Google Analytics.../auth/analytics.editCreate the GA4 property and web data stream and place the measurement ID on the site
Google Tag Manager.../auth/tagmanager.manage.accounts, .edit.containers, .edit.containerversions, .publishCreate the tag container, set up the GA4 tag and publish the version
Google AdSense.../auth/adsense.readonlySee the publisher ID and whether the site is registered with AdSense, read-only
Google Ads.../auth/adwordsBring campaign, impression and spend reports into the panel
YouTube.../auth/youtube.upload, .../auth/youtube.readonly, .../auth/youtube.force-sslUpload videos from the panel, read channel and video information
Google Drive.../auth/drive.fileWrite site backups only to files created by the application; the rest of your Drive is not accessed
Google account identityopenid, .../auth/userinfo.emailShow which Google account is connected in the panel

What we do with data obtained from Google

  • Authorisation tokens: access and refresh tokens are stored encrypted on our servers and are used solely to perform the operations above on your behalf.
  • Account identifiers: the e-mail address of the connected account together with business account, location, property and container identifiers are stored so that we can write to the correct target and display the “connected account” information in the panel.
  • Service content: data such as business profile reviews, search performance and advertising reports are processed in order to be displayed and reported in the panel.
  • This data is shown only to the authorised panel users of the relevant site; it is never exposed to another site or customer.

What we do not do

  • We do not sell or rent data obtained from Google APIs and do not use it for advertising targeting.
  • We do not transfer it to third parties for advertising, credit assessment or similar purposes.
  • We do not use it to train artificial intelligence or machine learning models (including generalised model training).
  • We do not allow humans to read it. The only exceptions are: resolving your support request with your explicit consent, security-related investigation (abuse/violation), data that has been aggregated and de-identified, and cases required by law.

Limited Use statement

Milenyums Dijital's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Withdrawing consent and deletion of data

You may remove the connection at any time from the panel via Integrations → Disconnect, or from the Google Account → Third-party apps with account access page. When the connection is removed, the tokens are deleted from our systems immediately; data obtained from Google and shown in the panel is deleted within 30 days at the latest. You may send your deletion request to , through the channels on our Contact page or to the platform support address destek@milenyums.com.

Retention and international transfer

Data obtained from Google is retained only for as long as the relevant service is provided and is deleted when the connection ends. As Google's infrastructure is located abroad, transfers within this scope are carried out in accordance with the conditions set out by the KVKK.

25. Messaging and Inbox

When you reach out to us via our website or through our messaging channels (email, WhatsApp, social media inboxes), the message content, sender's name and contact information, along with the time of the message, are collected in a single inbox. These records are stored for the resolution of your request, for tracking purposes, and as proof in case of any disputes. Message contents are not used for marketing purposes and are not accessible to irrelevant staff members.

26. Web Service and Automation Connections

The site can exchange data with authorized external systems through web service (API) and automation connections. In these connections, order, product, customer or request records are transferred only within the scope determined by the business that establishes the connection. Each connection is authorized with a separate key, access scope is limited, and requests are recorded. A connection whose authorization is removed immediately loses its access.

27. Your Rights (KVKK Art. 11)

  1. Learning whether your personal data is processed
  2. Requesting information regarding this if it has been processed
  3. Learning the purpose of processing and whether it is used in accordance with its purpose
  4. Knowing the third parties to whom it is transferred domestically or abroad
  5. Requesting correction if it has been processed incompletely or inaccurately
  6. Requesting its deletion or destruction
  7. Requesting notification of correction/deletion processes to the third parties to whom data has been transferred
  8. Objecting to an outcome against you resulting from analysis exclusively by automated systems
  9. Requesting compensation if you suffer damage due to unlawful processing

28. Application Methods

To exercise your rights, you can send an email to , write to the registered electronic mail (KEP) address , or submit a wet-signed petition to Yenibosna Merkez Mah. 1. Asena Sok. No: 15, Bahçelievler / İstanbul. Your application will be processed within 30 days at the latest.

29. Changes

This policy may be updated in accordance with regulations and service changes. When a new module, widget, or integration is enabled on the site, the corresponding section is automatically added to this text; when removed, it is removed from the text. The current version is always published on this page.