Zum Inhalt springen
Topkapı Palace — Tickets & Visitor Guide
Übersicht Tickets & geführter Eintritt Besuch Über Harem FAQ
Ab €63 buchen DE
Topkapı
  • Übersicht
  • Tickets
  • Besuch
  • Über
  • FAQ

Betreiber & Verantwortlicher

Rechtsträger
Check for Trips GmbH
Sitz
Hintergasse 6, 65428 Rüsselsheim, Germany
Handelsregister
Darmstadt HRB 96248
USt-IdNr.
DE310315188
Geschäftsführer
Erdogan Tur
Support-E-Mail
info@istanbulwelcomecard.com
Telefon (Deutschland HQ)
+49 6142 301 9620
Telefon (Türkei, WhatsApp)
+90 544 870 31 34
Zahlungs- & Datenverarbeiter
Stripe (payment) · PayPal (payment) · Ratepay (BNPL) · Google Analytics 4 · Meta Pixel

Die Check for Trips GmbH ist Verantwortlicher im Sinne von Art. 4(7) DSGVO. Alle IWC-Produktverkäufe — einschließlich der über diese Microsite — werden vom oben genannten Betreiber abgewickelt. Erstattungen werden innerhalb von 5–10 Werktagen über das ursprüngliche Zahlungsmittel bearbeitet.

Rechtliches · Datenschutzerklärung · Version 2.2

Wie wir die Daten hinter Ihrem Palastbesuch verarbeiten.

Ein geführter Palasteintritt erfordert mehr Koordination als ein einfaches Ticket – den Zeitplan eines lizenzierten Guides, eine feste Startzeit, einen Harem-Zusatz. Diese Richtlinie beschreibt, was wir erheben, damit das funktioniert, warum es benötigt wird, wie lange es gespeichert wird und wer es noch sieht. In klarer Sprache. DSGVO + KVKK-konform. Keine Überraschungen.

Inkrafttreten
1. Jan. 2026
Zuletzt geprüft
15. März 2026
Version
2.2
Datenschutzbeauftragter
intern
Sechzehn Abschnitte
  1. Wer wir sind
  2. Was wir erheben
  3. Warum wir es erheben
  4. Wie wir es erheben
  5. Buchungsdaten
  6. Support-Gespräche
  7. Analytik & Absturzberichte
  8. Eingesetzte Dienstleister
  9. Weitergabe an Dritte
  10. Speicherdauer
  11. Internationale Übermittlungen
  12. Sicherheitsmaßnahmen
  13. Ihre Rechte
  14. Daten von Kindern
  15. Änderungen dieser Richtlinie
  16. Kontakt
01

Wer wir sind.

Diese Website wird betrieben von Istanbul Tourist Information Ltd., einer türkischen Gesellschaft mit beschränkter Haftung mit Sitz in Istanbul, registriert unter TÜRSAB-Lizenz A-7812 and VAT number 3470891204. Eingetragener Sitz: Sultanahmet Mah. Divan Yolu Cad. 17, 34122 Fatih, Istanbul. Sie erreichen unseren Datenschutzbeauftragten unter privacy@istanbul-tourist-information.com.

This privacy policy covers topkapi.istanbul-tourist-information.com, the dedicated booking and visitor-guide site for Topkapı Palace. It does not cover the Ministry of Culture's own site, the venue's official pages, or any reseller that may have sold you a ticket.

02

Was wir erheben.

Vier Kategorien, mehr nicht. Alles, was nicht auf dieser Liste steht, fragen wir nicht ab und wüssten auch nicht, wofür.

Kontakt- & Buchungsdaten — Name, E-Mail-Adresse und Telefonnummer des Karteninhabers, plus the names of fellow visitors if you book for a group. Your preferred language for the tour (we match a guide accordingly) and any Harem add-on choice.

Zahlungsdaten — the card number is entered on Stripe's hosted page, tokenised there, and we only store the last four digits + brand for your invoice. We never see nor store the full card number.

Nutzungsdaten — which pages you visit, how you got here, what device you're using. Anonymised before aggregation (see section 07).

Support-Daten — if you write to us, we keep your email and our reply. Nothing else about the conversation is shared or mined.

03

Warum wir es erheben.

Under GDPR, every piece of data we collect has to sit under a specific legal basis. Here are ours, item by item.

Contract performance. Your booking data — name, email, visit date, ticket type. Without it we literally cannot issue you a ticket or brief the guide on your arrival. Legal basis: Art. 6(1)(b) GDPR.

Legal obligation. Turkish tax law requires us to keep transaction records for 10 years. That means the cardholder name, total amount, date, and VAT portion of each sale. Legal basis: Art. 6(1)(c) GDPR.

Legitimate interest. Analytics, fraud detection, anonymised crash reports — we use these to keep the site working and resist fraud. You can opt out via the cookie panel. Legal basis: Art. 6(1)(f) GDPR.

Consent. Marketing cookies, retargeting, newsletter sign-ups — only with your explicit opt-in. Legal basis: Art. 6(1)(a) GDPR.

04

How we collect it.

Directly from you — when you fill a booking form, email support, or type into a field. We don't buy data lists, we don't enrich your profile with third-party sources, and we don't fingerprint your device. If you haven't told us something yourself, we don't know it.

The one exception: payment card details, which you enter directly into Stripe's form. Stripe confirms the payment and returns a reference to us — we never see the card number itself.

05

Buchungsdaten.

Your booking record contains: booking reference, visit date, slot time, guide language, Harem add-on, cardholder name, contact email, phone, number of visitors in the group, VAT amount, total paid, and any refund history. This is the complete list.

It is visible to three people: you (via the confirmation email), your licensed guide on the day of your visit (name + group size + language only — they don't see your contact details), and our support team when you write to them.

06

Support-Gespräche.

When you email support, your message and our reply are stored in our helpdesk tool (Front). Conversations are retained for 36 months unless you ask us to purge them sooner — useful if a later agent needs context about a refund or a reschedule you previously discussed.

Support conversations are never used as training data for AI, never shared with marketing, and never visible to anyone outside the three-person support team plus the data officer.

07

Analytik & Absturzberichte.

We use Google Analytics 4 with IP anonymisation, ad-signals disabled, and demographics off. We see how many visitors arrive, which page they land on, and where they drop off — not who they are, what device model they use, or what else they look at across the web.

Sentry captures crash reports (JavaScript errors, server exceptions) with a scrubbed version of the page — any form field, cookie, or URL parameter that might carry personal data is stripped before the report leaves your browser. We use these to know what broke; we don't use them to identify people.

08

Eingesetzte Dienstleister.

Seven third parties touch data on this site. Here they are, what they do, and where they hold the data.

VendorPurposeData heldRegion
StripePayment processingCard details (tokenised)EU + US
External sales APIMinistry of Culture ticket issuanceVisit date, group sizeTürkiye
Transactional emailConfirmation + voucher deliveryEmail address, booking summaryEU
Google Analytics 4Anonymised usage statsAnonymised session IDEU + US
Meta PixelAd attribution (opt-in only)Opaque retargeting IDEU + US
SentryCrash reports (scrubbed)Error trace, no PIIEU
Hosting & CDNServing the siteIP, user-agent (transient)EU

Each vendor has signed a Data Processing Agreement with us and is audited annually. If you want a copy of the list, email the data officer.

09

Sharing with third parties.

We do not sell your data. We do not rent it. We do not share it with partners for their own marketing. The only third parties that touch your data are the vendors listed in section 08, all of whom act as data processors under our instructions.

Exception: if a Turkish court, a tax authority, or the Ministry of Culture issues a valid legal order, we will comply. You will be notified unless the order specifically forbids that disclosure. This has not happened in the history of the site.

10

Speicherdauer.

Booking records — 10 years (Turkish tax law requires the financial record for this duration).

Support-Gespräche — 36 months from last message, or until you ask for deletion.

Analytics data — 24 months in GA4, aggregated after that (no individual records).

Crash reports — 14 days (Sentry automatically purges beyond that).

Marketing cookies — 90 days or until you revoke consent, whichever comes first.

11

Internationale Übermittlungen.

Our primary infrastructure is EU-based (Frankfurt and Amsterdam). Two vendors — Stripe and Google — route a portion of data through US infrastructure. Both rely on the EU-US Data Privacy Framework and Standard Contractual Clauses under GDPR Art. 46 for lawful transfer.

If you are booking from Türkiye, data stays within the country to the extent the Ministry of Culture's external sales API is concerned — that transfer sits under KVKK equivalent safeguards.

12

Sicherheitsmaßnahmen.

TLS 1.3 on every connection. Database encryption at rest. Two-factor authentication required for every staff account. Quarterly penetration tests by an independent Turkish security firm. A documented incident-response playbook with a 72-hour notification commitment (shorter than GDPR requires).

No system is perfectly secure. If a breach happens that affects you, we will notify you within 72 hours of detection with the specific data involved, the potential impact, and the steps we've taken — regardless of what the regulatory minimum requires.

13

Ihre Rechte.

Under GDPR (if you're in the EU) and KVKK (if you're in Türkiye), you have eight rights over your data. Here they are, plus how to exercise each one.

01

Access

Request a copy of every piece of data we hold on you. Delivered within 30 days as a downloadable archive.

02

Rectification

Fix anything that's wrong — a typo in your name, an outdated email address. Same-day turnaround.

03

Erasure

Delete your data outside the 10-year tax retention. For post-retention records, we can pseudonymise.

04

Restriction

Freeze your data — we keep it, but stop processing, usually during a rectification dispute.

05

Portability

Export your booking history in JSON or CSV — machine-readable, usable in another system.

06

Objection

Object to any legitimate-interest processing. We stop unless we can demonstrate a compelling legal reason.

07

Automated decisions

We don't make any automated decisions about you. No scoring, no profiling, no algorithmic calls.

08

Complain

Complain to KVKK (in Türkiye) or your EU country's DPA. You don't need to tell us first.

14

Daten von Kindern.

We do not knowingly collect data about children under 16. A parent can book palace entry for a child — in that case the cardholder's name is the parent's, and only first names of children appear on the voucher. No contact details are requested for minors.

15

Changes to this policy.

We may update this policy. When a change affects your rights materially, you will be emailed at the address on your most recent booking at least 30 days before the change takes effect. Minor edits (typo fixes, clarifications) are posted without notification, but the version number in the header increments either way.

Privacy & data questions

Write to our data officer — not a generic privacy inbox.

One in-house person reads every privacy request. First reply in eight business hours, resolution in under fifteen business days for 98% of cases. No chatbot, no ticketing system, no external vendor reading your message first.

Data protection officer privacy@istanbul-tourist-information.com
Related policies & tools
Terms of Booking Refund Policy Cookie Preferences Contact support
Topkapı Palace — Tickets & Visitor Guide

A dedicated booking and visitor-guide site for the Ottoman imperial palace. Part of the Istanbul Tourist Information portfolio.

Besuch

  • Tickets
  • Besuch
  • Über
  • FAQ

Support

  • Contact & support
  • Barrierefreiheit
  • Sitemap
  • Rückerstattungsrichtlinie

Rechtliches

  • Privacy
  • AGB
  • Cookie settings
© Istanbul Tourist Information · TÜRSAB A-7812Powered by istanbul-tourist-information.com