Saltar al contenido
Topkapı Palace — Tickets & Visitor Guide
Resumen Entradas y entrada guiada Visita Sobre Harén Preguntas frecuentes
Reserva desde €63 ES
Topkapı
  • Resumen
  • Entradas
  • Visita
  • Sobre
  • Preguntas frecuentes

Operador y responsable del tratamiento

Entidad jurídica
Check for Trips GmbH
Sede registrada
Hintergasse 6, 65428 Rüsselsheim, Germany
Registro mercantil
Darmstadt HRB 96248
NIF
DE310315188
Director gerente
Erdogan Tur
Email de soporte
info@istanbulwelcomecard.com
Teléfono (sede Alemania)
+49 6142 301 9620
Teléfono (Turquía, WhatsApp)
+90 544 870 31 34
Procesadores de pago y datos
Stripe (payment) · PayPal (payment) · Ratepay (BNPL) · Google Analytics 4 · Meta Pixel

Check for Trips GmbH actúa como responsable del tratamiento conforme al Art. 4(7) del RGPD. Todas las ventas de productos IWC — incluidas las realizadas a través de este micrositio — son tramitadas por el operador indicado. Reembolsos procesados en 5–10 días hábiles por el método de pago original.

Legal · Política de privacidad · Versión 2.2

Cómo gestionamos los datos detrás de tu visita al palacio.

Una entrada guiada al palacio requiere más coordinación que una entrada simple: el horario de un guía autorizado, una hora de inicio fija, un complemento del Harén. Esta política explica qué recopilamos para que todo funcione, por qué es necesario, cuánto tiempo lo conservamos y quién más lo ve. Lenguaje claro. Conforme con RGPD + KVKK. Sin sorpresas.

Vigencia
1 ene. 2026
Última revisión
15 mar. 2026
Versión
2.2
Responsable de datos
interno
Dieciséis secciones
  1. Quiénes somos
  2. Qué recopilamos
  3. Por qué lo recopilamos
  4. Cómo lo recopilamos
  5. Datos de reserva
  6. Conversaciones de soporte
  7. Analíticas e informes de fallos
  8. Proveedores que usamos
  9. Compartir con terceros
  10. Cuánto tiempo lo conservamos
  11. Transferencias internacionales
  12. Medidas de seguridad
  13. Tus derechos
  14. Datos de menores
  15. Cambios en esta política
  16. Contáctanos
01

Quiénes somos.

Este sitio es operado por Istanbul Tourist Information Ltd., una sociedad turca de responsabilidad limitada registrada en Estambul bajo licencia TÜRSAB A-7812 and VAT number 3470891204. Domicilio social: Sultanahmet Mah. Divan Yolu Cad. 17, 34122 Fatih, Estambul. Puedes contactar a nuestro responsable de datos en privacy@istanbul-tourist-information.com.

This privacy policy covers topkapi.istanbul-tourist-information.com, the dedicated booking and visitor-guide site for Topkapı Palace. It does not cover the Ministry of Culture's own site, the venue's official pages, or any reseller that may have sold you a ticket.

02

Qué recopilamos.

Cuatro categorías, nada más. Cualquier cosa fuera de esta lista no la pedimos y no sabríamos qué hacer con ella.

Datos de contacto y reserva — the cardholder's name, email, and phone number, plus the names of fellow visitors if you book for a group. Your preferred language for the tour (we match a guide accordingly) and any Harem add-on choice.

Datos de pago — the card number is entered on Stripe's hosted page, tokenised there, and we only store the last four digits + brand for your invoice. We never see nor store the full card number.

Datos de uso — which pages you visit, how you got here, what device you're using. Anonymised before aggregation (see section 07).

Datos de soporte — if you write to us, we keep your email and our reply. Nothing else about the conversation is shared or mined.

03

Por qué lo recopilamos.

Under GDPR, every piece of data we collect has to sit under a specific legal basis. Here are ours, item by item.

Contract performance. Your booking data — name, email, visit date, ticket type. Without it we literally cannot issue you a ticket or brief the guide on your arrival. Legal basis: Art. 6(1)(b) GDPR.

Legal obligation. Turkish tax law requires us to keep transaction records for 10 years. That means the cardholder name, total amount, date, and VAT portion of each sale. Legal basis: Art. 6(1)(c) GDPR.

Legitimate interest. Analytics, fraud detection, anonymised crash reports — we use these to keep the site working and resist fraud. You can opt out via the cookie panel. Legal basis: Art. 6(1)(f) GDPR.

Consent. Marketing cookies, retargeting, newsletter sign-ups — only with your explicit opt-in. Legal basis: Art. 6(1)(a) GDPR.

04

How we collect it.

Directly from you — when you fill a booking form, email support, or type into a field. We don't buy data lists, we don't enrich your profile with third-party sources, and we don't fingerprint your device. If you haven't told us something yourself, we don't know it.

The one exception: payment card details, which you enter directly into Stripe's form. Stripe confirms the payment and returns a reference to us — we never see the card number itself.

05

Datos de reserva.

Your booking record contains: booking reference, visit date, slot time, guide language, Harem add-on, cardholder name, contact email, phone, number of visitors in the group, VAT amount, total paid, and any refund history. This is the complete list.

It is visible to three people: you (via the confirmation email), your licensed guide on the day of your visit (name + group size + language only — they don't see your contact details), and our support team when you write to them.

06

Conversaciones de soporte.

When you email support, your message and our reply are stored in our helpdesk tool (Front). Conversations are retained for 36 months unless you ask us to purge them sooner — useful if a later agent needs context about a refund or a reschedule you previously discussed.

Support conversations are never used as training data for AI, never shared with marketing, and never visible to anyone outside the three-person support team plus the data officer.

07

Analíticas e informes de fallos.

We use Google Analytics 4 with IP anonymisation, ad-signals disabled, and demographics off. We see how many visitors arrive, which page they land on, and where they drop off — not who they are, what device model they use, or what else they look at across the web.

Sentry captures crash reports (JavaScript errors, server exceptions) with a scrubbed version of the page — any form field, cookie, or URL parameter that might carry personal data is stripped before the report leaves your browser. We use these to know what broke; we don't use them to identify people.

08

Proveedores que usamos.

Seven third parties touch data on this site. Here they are, what they do, and where they hold the data.

VendorPurposeData heldRegion
StripePayment processingCard details (tokenised)EU + US
External sales APIMinistry of Culture ticket issuanceVisit date, group sizeTürkiye
Transactional emailConfirmation + voucher deliveryEmail address, booking summaryEU
Google Analytics 4Anonymised usage statsAnonymised session IDEU + US
Meta PixelAd attribution (opt-in only)Opaque retargeting IDEU + US
SentryCrash reports (scrubbed)Error trace, no PIIEU
Hosting & CDNServing the siteIP, user-agent (transient)EU

Each vendor has signed a Data Processing Agreement with us and is audited annually. If you want a copy of the list, email the data officer.

09

Sharing with third parties.

We do not sell your data. We do not rent it. We do not share it with partners for their own marketing. The only third parties that touch your data are the vendors listed in section 08, all of whom act as data processors under our instructions.

Exception: if a Turkish court, a tax authority, or the Ministry of Culture issues a valid legal order, we will comply. You will be notified unless the order specifically forbids that disclosure. This has not happened in the history of the site.

10

Cuánto tiempo lo conservamos.

Booking records — 10 years (Turkish tax law requires the financial record for this duration).

Conversaciones de soporte — 36 months from last message, or until you ask for deletion.

Analytics data — 24 months in GA4, aggregated after that (no individual records).

Crash reports — 14 days (Sentry automatically purges beyond that).

Marketing cookies — 90 days or until you revoke consent, whichever comes first.

11

Transferencias internacionales.

Our primary infrastructure is EU-based (Frankfurt and Amsterdam). Two vendors — Stripe and Google — route a portion of data through US infrastructure. Both rely on the EU-US Data Privacy Framework and Standard Contractual Clauses under GDPR Art. 46 for lawful transfer.

If you are booking from Türkiye, data stays within the country to the extent the Ministry of Culture's external sales API is concerned — that transfer sits under KVKK equivalent safeguards.

12

Medidas de seguridad.

TLS 1.3 on every connection. Database encryption at rest. Two-factor authentication required for every staff account. Quarterly penetration tests by an independent Turkish security firm. A documented incident-response playbook with a 72-hour notification commitment (shorter than GDPR requires).

No system is perfectly secure. If a breach happens that affects you, we will notify you within 72 hours of detection with the specific data involved, the potential impact, and the steps we've taken — regardless of what the regulatory minimum requires.

13

Tus derechos.

Under GDPR (if you're in the EU) and KVKK (if you're in Türkiye), you have eight rights over your data. Here they are, plus how to exercise each one.

01

Access

Request a copy of every piece of data we hold on you. Delivered within 30 days as a downloadable archive.

02

Rectification

Fix anything that's wrong — a typo in your name, an outdated email address. Same-day turnaround.

03

Erasure

Delete your data outside the 10-year tax retention. For post-retention records, we can pseudonymise.

04

Restriction

Freeze your data — we keep it, but stop processing, usually during a rectification dispute.

05

Portability

Export your booking history in JSON or CSV — machine-readable, usable in another system.

06

Objection

Object to any legitimate-interest processing. We stop unless we can demonstrate a compelling legal reason.

07

Automated decisions

We don't make any automated decisions about you. No scoring, no profiling, no algorithmic calls.

08

Complain

Complain to KVKK (in Türkiye) or your EU country's DPA. You don't need to tell us first.

14

Datos de menores.

We do not knowingly collect data about children under 16. A parent can book palace entry for a child — in that case the cardholder's name is the parent's, and only first names of children appear on the voucher. No contact details are requested for minors.

15

Changes to this policy.

We may update this policy. When a change affects your rights materially, you will be emailed at the address on your most recent booking at least 30 days before the change takes effect. Minor edits (typo fixes, clarifications) are posted without notification, but the version number in the header increments either way.

Privacy & data questions

Write to our data officer — not a generic privacy inbox.

One in-house person reads every privacy request. First reply in eight business hours, resolution in under fifteen business days for 98% of cases. No chatbot, no ticketing system, no external vendor reading your message first.

Data protection officer privacy@istanbul-tourist-information.com
Related policies & tools
Terms of Booking Refund Policy Cookie Preferences Contact support
Topkapı Palace — Tickets & Visitor Guide

A dedicated booking and visitor-guide site for the Ottoman imperial palace. Part of the Istanbul Tourist Information portfolio.

Visita

  • Entradas
  • Visita
  • Sobre
  • Preguntas frecuentes

Soporte

  • Contact & support
  • Accesibilidad
  • Mapa del sitio
  • Política de reembolsos

Legal

  • Privacy
  • Términos
  • Cookie settings
© Istanbul Tourist Information · TÜRSAB A-7812Powered by istanbul-tourist-information.com