ClickCease
EN

Information Security and Privacy Policy

In line with our company’s vision, we regard the protection of our information assets and of the personal data we process as one of the fundamental elements of our corporate sustainability. In accordance with the ISO/IEC 27001 and ISO/IEC 27701 standards, our information security and privacy policy is;

  • To protect the confidentiality, integrity and availability of our information assets and personal data,
  • To ensure that information assets and personal data are managed on the basis of ownership, that responsibilities are clearly defined, and that all employees fulfill their information security and privacy obligations,
  • To identify and assess information security and privacy risks with a risk-based approach and to implement the controls necessary to reduce them to an acceptable level,
  • To adhere, in the processing of personal data, to the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality,
  • To comply with the 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK), the personal data protection regulations applicable in the countries of operation, and the legal, regulatory, contractual and other applicable requirements related to information security,
  • To integrate information security and privacy requirements into business processes, products, services and new technologies from the design stage onwards,
  • To implement the necessary technical and administrative measures against unauthorized access, modification, loss, disclosure and interruptions by ensuring that access to information takes place in line with duties, authorizations and business needs,
  • To support business continuity and ensure information security continuity by taking information security and privacy requirements into account,
  • To manage information security incidents and personal data breaches effectively, to make the necessary notifications on time, and to carry out improvement activities that will prevent their recurrence,
  • To ensure that our suppliers, business partners and service providers work in compliance with information security and privacy obligations,
  • To provide the necessary training in order to increase our employees’ awareness of information security and the protection of personal data, and to spread the security culture,
  • To provide the human resources, technology, infrastructure and other resources necessary for the establishment, implementation, maintenance and continuous improvement of the Information Security Management System and the Privacy Information Management System,
  • To establish information security and privacy objectives in alignment with our organization’s strategic objectives, to monitor their performance regularly and to improve them continuously,
  • To develop the information security and privacy culture with the participation of all our employees and our interested parties in line with our strategic objectives, and to adopt a reliable and sustainable management approach that protects our digital assets and personal data,
  • To maintain and improve the effectiveness of the Information Security Management System and the Privacy Information Management System, and to preserve and strengthen the trust of our customers, employees, business partners and other interested parties,
  • To regularly review the suitability, adequacy and effectiveness of this policy and to update it when necessary,

We undertake to act in accordance with the principles and commitments stated above, to ensure their implementation and to improve them continuously.

Deputy General Manager of Technical Affairs