Personal Data Protection Policy
Last updated: 17 July 2026
Data controller: BUS 1 TEKNOLOJİ HİZMETLERİ ANONİM ŞİRKETİ
Registered office: Maslak Mah. Maslak Meydan Sk. Beybi Giz Plaza A Blok No:1 İç Kapı No:99, Sarıyer / İstanbul, Türkiye
Email: info@bus1.com
A Turkish version is available via the footer link "Kişisel Verilerin Korunması Politikası (TR)". In case of inconsistency, the Turkish version prevails to the extent required by mandatory Turkish law.
1. Scope and Governing Law
This Notice is issued under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), its secondary legislation and binding decisions of the Personal Data Protection Board. Where relevant, Law No. 6563 on the Regulation of Electronic Commerce and other Turkish laws governing electronic communications, internet services, taxation, consumer protection and transport also apply.
It applies to personal data that BUS 1 TEKNOLOJİ HİZMETLERİ ANONİM ŞİRKETİ ("BUS1.com", "we", "us") processes when you:
- visit BUS1.com, istanbul.bus1.com, or any site or application linking to this Notice;
- request a quote, create an account, place or manage a booking, or are named as a passenger;
- interact with us at events, through social media, messaging services, or customer-support channels.
2. Definitions
- Data Controller / Data Processor – as defined in the KVKK. BUS1.com is the data controller for the processing purposes and means it determines; Carriers and payment institutions may be separate data controllers for their own activities.
- Personal Data – any information relating to an identified or identifiable natural person.
- Special Categories of Personal Data – the categories listed in Article 6 of the KVKK, including health, biometric and genetic data, criminal-conviction and security-measure data, and other protected categories. BUS1.com processes such data only where necessary, proportionate, supported by a lawful condition, and subject to the required safeguards (for example, accessibility information voluntarily provided for a journey).
3. Lawful Bases for Processing
Purpose | Lawful basis under KVKK | Typical data elements | Retention* |
Account creation and booking | Contract establishment/performance; legitimate interests where appropriate | Name, email, mobile number, passenger and booking data; ID/passport data where required | For the account/booking relationship and the applicable limitation period; longer only where required by law |
Marketing e-mails & SMS | Explicit consent and the conditions of Law No. 6563 | Name, email, mobile number, marketing preferences | Until consent is withdrawn, plus the period needed to record and honour the opt-out |
Fraud prevention & security logs | Legitimate interests; legal obligation where applicable | IP address, device ID, access and behavioural logs | For the period required by law and security needs, generally up to 2 years unless a longer period is necessary |
Regulatory reporting (e.g., VAT/invoicing) | Legal obligation; establishment or protection of rights | Invoice, payment-reference and transaction data | Generally 5 years under tax rules and up to 10 years where commercial-law record keeping requires it |
*Retention periods may be extended where necessary for an ongoing dispute, official request, audit, legal hold, or the establishment, exercise or protection of a right. Data are deleted, destroyed or anonymised when the processing purpose and legal retention basis end.
4. What Information We Collect
4.1 Data you provide – name, postal address, email, mobile number, passenger and booking information, and where required for the service, identity/passport or accessibility information; payment-related information and marketing preferences. Full card details are normally processed directly by the authorised payment service provider.
4.2 Data we collect automatically – IP address, browser type, device identifiers, timestamps, click-path, cookies and log records.
4.3 Data from third parties – Carriers, payment institutions, authorised partners, public business registers and public sources where lawful and relevant.
4.4 Google API – Where we use Google API services, our use of information received from Google APIs is intended to comply with the Google API Services User Data Policy, including the Limited Use requirements.
5. How We Use Your Information
We use personal data to:
- deliver and administer our website, account, quotation, booking and intermediation services;
- identify a suitable Carrier and vehicle and transmit the information needed to perform the transport;
- verify identity where necessary, manage payments and refunds, issue invoices and prevent fraud;
- personalise content, send service messages and, when you have validly opted in, marketing communications;
- analyse usage, maintain security and improve performance, service quality and safety;
- comply with audit, tax, accounting, consumer, transport and other legal obligations;
- establish, exercise or defend legal claims;
- perform another specific purpose where we have provided the required notice and, where legally required, obtained explicit consent.
6. Cookies & Similar Technologies
Essential cookies are used to operate and secure the Platform. Non-essential cookies, analytics tags and advertising pixels are activated only where a valid consent or user choice is required and obtained through our cookie banner, in line with the KVKK and applicable Board guidance. You may withdraw or adjust consent at any time through "Cookie Settings" in the website footer. A separate Cookie Notice identifies the cookies, providers, purposes and durations actually used.
We do not currently respond to DO-NOT-TRACK (DNT) browser signals or another automatic browser mechanism unless required by applicable law. Cookie choices made through our banner are respected.
7. Sharing Your Information
We disclose personal data only to the extent necessary and lawful, including to:
- Carriers and their authorised service providers, to quote, book and perform the transport;
- banks and authorised payment institutions, to process payments, chargebacks and refunds;
- cloud-hosting, IT, communications, customer-support, analytics and marketing providers acting under appropriate contractual and security obligations;
- accounting, audit, insurance and legal advisers;
- group companies for legitimate internal administration and service support, subject to the applicable transfer rules;
- administrative, judicial, law-enforcement and regulatory authorities where required or permitted by law.
We do not sell personal data.
8. International Transfers
Depending on the Carrier and the cloud, email, communications, analytics or support provider used, personal data may be hosted in Türkiye or transferred abroad. Any international transfer is carried out under Article 9 of the KVKK, using an applicable lawful mechanism, such as:
- an adequacy decision published by the Personal Data Protection Board;
- binding corporate rules approved by the Board;
- a standard contract published by the Board and notified to the Authority within five business days after signature;
- a written undertaking providing appropriate protection and approved by the Board;
- one of the limited incidental-transfer exceptions expressly set out in Article 9, where its conditions are met.
You may request general information on the categories of international transfers and the safeguards used by writing to info@bus1.com.
9. Security Measures & Breach Notification
We maintain risk-based technical and organisational measures appropriate to the nature of the data and processing, including access controls, encryption or secure transmission where appropriate, logging, backups, vulnerability management, supplier oversight, confidentiality obligations and staff awareness.
If personal data are unlawfully obtained by another person, we notify the Personal Data Protection Board without delay and no later than 72 hours after becoming aware of the breach, in accordance with the Board's applicable decision, and notify affected individuals as soon as reasonably possible in the manner required by the KVKK and Board guidance.
10. Minors' data processing
Our transport services may include passengers under 18, but a booking for a minor should normally be made by a parent, legal representative, school, employer or other authorised adult. We do not knowingly direct marketing to children. A minor's personal data are processed only to the extent necessary for the booking, safety and performance of the transport and for applicable legal obligations.
11. Your Rights under the KVKK
Under Article 11 of the KVKK, subject to verification, you may:
- learn whether your personal data are processed and request information if they have been processed;
- learn the purpose of processing and whether the data are used in accordance with that purpose;
- know the third parties to whom personal data are transferred in Türkiye or abroad;
- request correction of incomplete or inaccurate personal data;
- request deletion or destruction where the conditions in Article 7 are met;
- request that correction, deletion or destruction operations be notified to third parties to whom the data were transferred;
- object to a result arising against you through analysis exclusively by automated systems;
- claim compensation for damage arising from unlawful processing.
Where processing is based on explicit consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal or processing based on another lawful ground.
12. Exercising Your Rights
Submit a request to info@bus1.com or in writing to the postal address below, using a method permitted by the Communiqué on Application Procedures and Principles to the Data Controller. Include sufficient information to identify you, describe the request and allow us to verify your identity without collecting excessive data. We respond as soon as possible and no later than 30 days. A fee may be charged only where permitted by the tariff determined by the Board; if the request results from our fault, the fee is refunded.
13. Data Protection Officer
The KVKK does not generally require a statutory Data Protection Officer. BUS1.com has not identified a DPO in this public Notice. Data-protection requests may be sent to info@bus1.com or to the registered office below. If BUS1.com is required to register with the Data Controllers' Registry (VERBİS), the legally required contact person or representative will be appointed and notified through the relevant official process.
14. Marketing Communications
We send commercial electronic messages only where the consent or another condition required by Law No. 6563 and the applicable commercial-communications rules is satisfied. Each marketing channel provides an appropriate opt-out method. Preferences may also be managed through the Message Management System (İYS), where applicable, or by contacting info@bus1.com. Withdrawal from marketing does not prevent service, security or legally required messages.
15. Updates and Version History
We review this Policy periodically and whenever our processing activities or applicable law change. The current version is published on the Platform and takes effect on the stated date.
Version | Date | Key changes |
1.0 | 16 July 2026 | Initial Türkiye / KVKK publication using the BUS1.com website structure and Turkish company details |
16. Contact & Complaints
E-mail: info@bus1.com
Post: BUS 1 TEKNOLOJİ HİZMETLERİ ANONİM ŞİRKETİ, Maslak Mah. Maslak Meydan Sk. Beybi Giz Plaza A Blok No:1 İç Kapı No:99, Sarıyer / İstanbul, Türkiye
If you believe your rights have been infringed, you must first apply to the data controller under Article 13 of the KVKK. If the request is rejected, the response is insufficient, or no response is received in time, you may complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within the periods set out in Article 14. Your right to seek compensation under general law is reserved.