INFORMATION SECURITY POLICY

Last Updated: July 15, 2026

This Information Security Policy explains the fundamental principles regarding the provision of information security in the website, reservation, tour, transfer, communication, and customer support services offered under the Sunride Adventure brand.

The Sunride Adventure website and services are operated by HANTUR TURİZM TAŞIMACILIK, whose details are provided below.

1. Company Details

2. Purpose of the Policy

The purpose of this policy is to;

  • Protect the information belonging to customers, visitors, employees, and business partners,
  • Ensure the security of the website and reservation systems,
  • Prevent unauthorized access to information,
  • Reduce the risks of unauthorized modification, disclosure, loss, or damage to information,
  • Ensure uninterrupted and reliable execution of services,
  • Detect and manage security incidents,
  • Comply with legal and contractual obligations.

3. Scope of the Policy

This policy covers the following systems, services, individuals, and processes:

  • www.sunrideadventure.com website
  • Website reservation forms
  • Tour and activity reservations
  • Communications conducted via WhatsApp
  • Email and phone conversations
  • Customer and passenger information
  • Hotel, transfer, and tour operation information
  • Management panel and user accounts
  • Server, database, and backup systems
  • Employees and authorized service providers
  • Tour operators, drivers, guides, and business partners
  • Physical and electronic environments where personal data is processed

4. Our Information Security Principles

Our information security efforts are carried out in accordance with the following core principles.

4.1. Confidentiality

Information can only be accessed by persons who need access due to their duty, authority, or the performance of a service. Customer and passenger information is not shared with unauthorized persons except for the provision of the service or the fulfillment of a legal obligation.

4.2. Integrity

Appropriate measures are taken against unauthorized modification or corruption of reservation, passenger, tour, transfer, and communication information.

4.3. Availability

Reasonable technical and operational measures are implemented to ensure that the website, reservation, and communication services are accessible when needed.

4.4. Least Privilege

Employees, managers, and service providers are given only the access rights necessary to perform their duties.

4.5. Data Minimization

Efforts are made not to request personal data that is not necessary for the provision of the service. It is recommended not to write unnecessary identity, health, payment, or financial information in the special notes field of the reservation form.

4.6. Responsibility

Employees and service providers who have access to information systems are expected to comply with information security rules.

5. Applied Security Measures

Appropriate technical and administrative measures are applied taking into account the nature of the processed information, the structure of the systems, existing risks, and current technological capabilities. These measures may include:

  • Transmitting website traffic over a secure connection
  • Limiting access to the management panel
  • Using strong and hard-to-guess passwords
  • Creating user accounts uniquely for each individual
  • Monitoring unauthorized access attempts
  • Ensuring server and hosting security
  • Implementing firewalls and access controls
  • Performing software and system updates
  • Conducting malware and suspicious file checks
  • Closing unused accounts and accesses
  • Regularly backing up data and protecting backups against unauthorized access
  • Keeping access and error logs
  • Executing critical operations by authorized personnel
  • Evaluating the security competencies of service providers
  • Informing personnel about information security
  • Protecting documents containing personal data from unauthorized persons

The security measures to be applied may be updated depending on changes in systems and encountered risks.

6. Website Security

To ensure the security of the website, reasonable precautions are taken against the following risks:

  • Unauthorized management panel accesses
  • Installation of malicious software
  • Automated and abusive submissions of forms
  • Creation of fake reservations
  • SQL injection and similar database attacks
  • Cross-site scripting (XSS) attempts
  • File upload vulnerabilities
  • Session and authentication attacks
  • Denial of service (DoS) or excess traffic generation attempts
  • Suspicious links and redirections
  • Unauthorized data download or modification attempts

Critical security risks detected on the website are evaluated as soon as possible, considering the nature and impact of the risk.

7. Reservation Security

During reservation, only the information necessary for planning and executing the tour service is requested. Reservation information may be used for the following purposes:

  • Creating the tour record, Determining the number of passengers
  • Calculating the tour fee, Planning the hotel pick-up operation
  • Organizing the transfer vehicle
  • Tour operator, driver, and guide coordination
  • Communicating with the customer, Making reservation changes or cancellations

Reservation information can only be accessed by authorized personnel who need to access it for the execution of the work.

Customers are advised not to write the following information on the reservation form:

  • Internet banking password, Credit or debit card password, Card PIN code
  • One-time SMS verification code
  • Email or social media password
  • Unnecessary identity or passport images, Health information not required for the service

8. Payment Security

Sunride Adventure never requests the following information from customers via phone, WhatsApp, email, or social media messages:

  • Debit card PIN code
  • Internet banking password, Mobile banking password
  • SMS verification code
  • Email account password, Social media account password

In case of providing card or online payment services, payment transactions can be carried out through the relevant bank or authorized payment service provider's system. The payment service provider's own security and privacy policies may apply.

In the event of a suspicious payment request, contact us via the following official communication channels before processing the transaction:

9. WhatsApp and Communication Security

WhatsApp, email, and social media platforms are third-party services. During the use of these platforms, information may be processed by the relevant service providers under their own security and privacy policies.

It is recommended that customers take the following precautions:

  • Communicate only through our official phone number
  • Do not click on suspicious links
  • Do not share passwords and verification codes
  • Do not make payments to unofficial accounts
  • Check recipient details before making a payment
  • Report suspicious messages to us
  • Do not leave personal information open on shared devices

If you encounter a suspicious person or account claiming to communicate on behalf of Sunride Adventure, verification should be made via our official contact details.

10. Access Control

Access to information systems is managed based on the following principles:

  • Granting authority to each user limited to their duty
  • Avoiding the use of shared user accounts as much as possible
  • Using strong and unique passwords
  • Not sharing access information with others
  • Updating the accesses of persons whose duties change or end
  • Closing unused accounts
  • Keeping administrator privileges limited
  • Investigating suspicious sessions and accesses

Additional security methods such as multi-factor authentication may be used in deemed necessary systems.

11. Password Security

Administrator, employee, and authorized user passwords are expected to be; created in a way that is not easily guessable, not the same as passwords used on other websites, not shared with unauthorized persons, not stored openly in insecure environments, and changed if a suspicious situation arises.

Customers are not asked for any account password unrelated to Sunride Adventure services.

12. Backup and Business Continuity

Systems and data deemed necessary against data loss, system failure, attack, or human error risks may be backed up. The following aspects are considered in backup processes:

  • Creating backups regularly and protecting them from unauthorized access
  • Being able to restore data when needed
  • Deleting old and unnecessary backups appropriately
  • Restarting critical services as soon as possible

Interruptions originating from the server, internet connection, third-party platform, or force majeure events cannot be completely prevented. In these cases, reasonable efforts are made to restore services.

13. Third-Party Service Providers

Services from the following third parties may be obtained within the scope of the website and tour services:

  • Server and hosting companies, Domain name and DNS service providers
  • Email service providers, WhatsApp and communication platforms
  • Map and location services, Analysis and performance services
  • Payment service providers
  • Tour and transfer operators, Guides and drivers
  • Technical support and software service providers

Only the information necessary for the provided service is shared with service providers. In appropriate cases, service providers are expected to comply with information security and confidentiality rules. Third-party services' own security measures, terms of use, and privacy policies may additionally apply.

14. Physical Document Security

Printed reservation lists, passenger lists, or operational documents containing personal data are protected by the following principles:

  • Documents are used only by authorized persons
  • Storing in a way that unauthorized persons cannot see
  • Not creating unnecessary copies
  • Safely destroying documents whose purpose of use has ended
  • Not leaving documents in open and unattended areas

15. Security Logs and Monitoring

Certain technical logs may be kept for the security of systems and the continuity of services. These logs may include:

  • IP address, Login and logout time, Management panel accesses
  • Failed login attempts, System and application errors
  • Suspicious transaction logs, Server and firewall logs

Logs are used solely for the purpose of security, error detection, maintaining the service, fulfilling legal obligations, and investigating unauthorized transactions.

16. Security Incident Management

When a suspicious security incident is detected, the following actions may be carried out depending on the nature of the incident:

  1. Recording the security incident,
  2. Determining the affected systems, Stopping unauthorized access,
  3. Temporarily closing necessary accounts or accesses,
  4. Changing passwords and access information,
  5. Cleaning malicious files or software,
  6. Determining the affected information and individuals, Limiting data loss or damage,
  7. Restoring from backups,
  8. Investigating the cause of the incident, Taking precautions to prevent recurrence,
  9. Making notifications to the relevant persons and authorized institutions in case legal conditions are met.

Security incidents are evaluated considering the impact of the incident and the risk it creates.

17. Vulnerability Disclosure

If you believe you have found a security vulnerability on the Sunride Adventure website or systems, you can contact us via the following email address:

Email: info@sunrideadventure.com

It is recommended to write "Vulnerability Disclosure – Sunride Adventure" in the email subject line.

The disclosure should preferably include the following information: the page/system where the vulnerability is found, a brief description, steps to reproduce, potential security impact, screenshot or technical evidence, contact info of the reporter, and whether it has been disclosed to the public previously.

18. Rules Expected from Security Researchers

The following rules are expected to be observed during security vulnerability research or disclosure:

  • Testing only to the extent necessary to verify the vulnerability
  • Not accessing data belonging to other users, not changing or deleting data
  • Not saving or sharing accessed personal data
  • Not performing actions that will prevent the system from working
  • Not applying high traffic or denial of service attacks
  • Not installing malicious software
  • Not attempting social engineering against employees or customers
  • Not attempting physical security breaches
  • Not using password guessing or compromised password lists
  • Not making a public disclosure without allowing a reasonable time to fix the vulnerability
  • Not using the security vulnerability for blackmail, threat, or gaining benefit

Unless there is a reward program explicitly announced by Sunride Adventure in advance, it cannot be accepted that the security vulnerability disclosure made creates a right to financial reward or payment.

19. Security Responsibilities of Users

It is recommended that users take the following precautions for their own security:

  • Check the official website address
  • Communicate only through the official phone number
  • Do not click on suspicious links
  • Do not share passwords and verification codes with anyone
  • Do not leave personal information on shared computers
  • Use updated browser and operating system, ensure device security
  • Verify suspicious payment requests
  • Do not write unnecessary personal information on the reservation form
  • Immediately report a suspicious transaction or message

Sunride Adventure has no direct control over security problems originating from the user's device, email account, WhatsApp account, or internet connection.

20. Fake Site and Fraud Warning

Sunride Adventure’s official website: www.sunrideadventure.com

Official contact details:

In the event of encountering a fake website, social media account, advertisement, or payment request created on behalf of Sunride Adventure, contact us before making any payment or sharing personal information.

Sunride Adventure does not request bank account passwords, card PIN codes, SMS verification codes, email passwords, or social media passwords.

21. No Absolute Security Guarantee

Although reasonable technical and administrative measures are taken to ensure information security, no website, electronic communication, data transfer, or storage system can be guaranteed to be completely risk-free.

A security risk may arise due to cyber attacks, third-party service interruptions, device security issues, user errors, communication infrastructure failures, and events beyond our control. In such a case, reasonable efforts are made to mitigate the impact of the incident, protect the systems, and restore the services.

22. Protection of Personal Data

Detailed explanations regarding the processing of personal data within the scope of information security are included in the Privacy and Personal Data Protection Policy published on our website.

This Information Security Policy should be evaluated together with the Privacy and Personal Data Protection Policy.

23. Review of the Policy

This policy may be updated in the event of changes in the website or reservation system, the addition of new tours or services, the use of new service providers, or changes in security risks or legislation. The updated policy will be published on the website along with the new "Last Updated" date.

24. Contact

You can contact us for information security, suspicious communications, fake accounts, fraud attempts, or vulnerability disclosures:

HANTUR TURİZM TAŞIMACILIK (Sunride Adventure)

Sarılar Mahallesi, Hastahane (Şelale) Caddesi No: 16
İç Kapı No: 4
Manavgat / Antalya