Last Updated: July 15, 2026
This Information Security Policy explains the fundamental principles regarding the provision of information security in the website, reservation, tour, transfer, communication, and customer support services offered under the Sunride Adventure brand.
The Sunride Adventure website and services are operated by HANTUR TURİZM TAŞIMACILIK, whose details are provided below.
The purpose of this policy is to;
This policy covers the following systems, services, individuals, and processes:
Our information security efforts are carried out in accordance with the following core principles.
Information can only be accessed by persons who need access due to their duty, authority, or the performance of a service. Customer and passenger information is not shared with unauthorized persons except for the provision of the service or the fulfillment of a legal obligation.
Appropriate measures are taken against unauthorized modification or corruption of reservation, passenger, tour, transfer, and communication information.
Reasonable technical and operational measures are implemented to ensure that the website, reservation, and communication services are accessible when needed.
Employees, managers, and service providers are given only the access rights necessary to perform their duties.
Efforts are made not to request personal data that is not necessary for the provision of the service. It is recommended not to write unnecessary identity, health, payment, or financial information in the special notes field of the reservation form.
Employees and service providers who have access to information systems are expected to comply with information security rules.
Appropriate technical and administrative measures are applied taking into account the nature of the processed information, the structure of the systems, existing risks, and current technological capabilities. These measures may include:
The security measures to be applied may be updated depending on changes in systems and encountered risks.
To ensure the security of the website, reasonable precautions are taken against the following risks:
Critical security risks detected on the website are evaluated as soon as possible, considering the nature and impact of the risk.
During reservation, only the information necessary for planning and executing the tour service is requested. Reservation information may be used for the following purposes:
Reservation information can only be accessed by authorized personnel who need to access it for the execution of the work.
Customers are advised not to write the following information on the reservation form:
Sunride Adventure never requests the following information from customers via phone, WhatsApp, email, or social media messages:
In case of providing card or online payment services, payment transactions can be carried out through the relevant bank or authorized payment service provider's system. The payment service provider's own security and privacy policies may apply.
In the event of a suspicious payment request, contact us via the following official communication channels before processing the transaction:
WhatsApp, email, and social media platforms are third-party services. During the use of these platforms, information may be processed by the relevant service providers under their own security and privacy policies.
It is recommended that customers take the following precautions:
If you encounter a suspicious person or account claiming to communicate on behalf of Sunride Adventure, verification should be made via our official contact details.
Access to information systems is managed based on the following principles:
Additional security methods such as multi-factor authentication may be used in deemed necessary systems.
Administrator, employee, and authorized user passwords are expected to be; created in a way that is not easily guessable, not the same as passwords used on other websites, not shared with unauthorized persons, not stored openly in insecure environments, and changed if a suspicious situation arises.
Customers are not asked for any account password unrelated to Sunride Adventure services.
Systems and data deemed necessary against data loss, system failure, attack, or human error risks may be backed up. The following aspects are considered in backup processes:
Interruptions originating from the server, internet connection, third-party platform, or force majeure events cannot be completely prevented. In these cases, reasonable efforts are made to restore services.
Services from the following third parties may be obtained within the scope of the website and tour services:
Only the information necessary for the provided service is shared with service providers. In appropriate cases, service providers are expected to comply with information security and confidentiality rules. Third-party services' own security measures, terms of use, and privacy policies may additionally apply.
Printed reservation lists, passenger lists, or operational documents containing personal data are protected by the following principles:
Certain technical logs may be kept for the security of systems and the continuity of services. These logs may include:
Logs are used solely for the purpose of security, error detection, maintaining the service, fulfilling legal obligations, and investigating unauthorized transactions.
When a suspicious security incident is detected, the following actions may be carried out depending on the nature of the incident:
Security incidents are evaluated considering the impact of the incident and the risk it creates.
If you believe you have found a security vulnerability on the Sunride Adventure website or systems, you can contact us via the following email address:
Email: info@sunrideadventure.com
It is recommended to write "Vulnerability Disclosure – Sunride Adventure" in the email subject line.
The disclosure should preferably include the following information: the page/system where the vulnerability is found, a brief description, steps to reproduce, potential security impact, screenshot or technical evidence, contact info of the reporter, and whether it has been disclosed to the public previously.
The following rules are expected to be observed during security vulnerability research or disclosure:
Unless there is a reward program explicitly announced by Sunride Adventure in advance, it cannot be accepted that the security vulnerability disclosure made creates a right to financial reward or payment.
It is recommended that users take the following precautions for their own security:
Sunride Adventure has no direct control over security problems originating from the user's device, email account, WhatsApp account, or internet connection.
Sunride Adventure’s official website: www.sunrideadventure.com
Official contact details:
In the event of encountering a fake website, social media account, advertisement, or payment request created on behalf of Sunride Adventure, contact us before making any payment or sharing personal information.
Sunride Adventure does not request bank account passwords, card PIN codes, SMS verification codes, email passwords, or social media passwords.
Although reasonable technical and administrative measures are taken to ensure information security, no website, electronic communication, data transfer, or storage system can be guaranteed to be completely risk-free.
A security risk may arise due to cyber attacks, third-party service interruptions, device security issues, user errors, communication infrastructure failures, and events beyond our control. In such a case, reasonable efforts are made to mitigate the impact of the incident, protect the systems, and restore the services.
Detailed explanations regarding the processing of personal data within the scope of information security are included in the Privacy and Personal Data Protection Policy published on our website.
This Information Security Policy should be evaluated together with the Privacy and Personal Data Protection Policy.
This policy may be updated in the event of changes in the website or reservation system, the addition of new tours or services, the use of new service providers, or changes in security risks or legislation. The updated policy will be published on the website along with the new "Last Updated" date.
You can contact us for information security, suspicious communications, fake accounts, fraud attempts, or vulnerability disclosures:
HANTUR TURİZM TAŞIMACILIK (Sunride Adventure)
Sarılar Mahallesi, Hastahane (Şelale) Caddesi No: 16
İç Kapı No: 4
Manavgat / Antalya