Privacy policy
Last updated: 6 October 2026
1. Who we are
CYNTMS is a back-office service for tour operators and travel agencies. It is run by the CYNTMS platform team ("we"). This policy covers this website, sign-up, and the sign-in of the companies that use the service.
What a company enters inside CYNTMS (its bookings, guests, partners, prices, invoices) belongs to that company. We process it for the company, on its instructions, as its processor.
2. What we collect
Account data: your name, email address, company, language and time zone.
Security and usage records: sign-ins, IP address, browser type and the actions kept in the audit log. They protect your account and help us find faults.
Billing data: handled by our payment provider; we receive the plan, the amount and the status, not your card number.
Messages you send us.
3. Why we use it
To provide the service and keep it secure, to invoice and support you, and to improve the product. Our legal bases are the contract with you, our legitimate interest in running a safe service, our legal duties, and your consent where we ask for it.
4. Cookies and analytics
We use essential cookies only: to keep you signed in and to remember your language and light or dark choice. Visitor statistics come from a privacy-friendly tool that sets no cookies. There are no advertising trackers.
5. Who receives it
Only the providers we need to run the service: hosting, email delivery and payment processing. We do not sell personal data. We disclose data to an authority only when the law requires it.
6. How long we keep it
Account data is kept while the company has an account and for the period the law requires after it. Each company chooses how long its own records are kept in Settings, Privacy. Security records are kept for a limited time, and backups are replaced on a rolling basis.
7. Your rights
You can ask to see, correct, export or erase your personal data, to restrict or object to its use, and to withdraw consent, under the GDPR and the Turkish KVKK. Company owners can export their company's data and close the company in Settings, Privacy. Write to us to use any right; you may also complain to your data protection authority.
8. Security
Companies are kept apart by the database itself, not only by the application. Connections are encrypted, passport numbers are stored encrypted, two-step sign-in is available, and important actions are written to an audit log.
9. Changes
When this policy changes we publish the new text here with its date.