Information Security Policy
Purpose and Scope
This policy has been prepared to ensure the security of all information assets processed through the Turasistan platform.
The policy covers our employees, customers, business partners, and all real and legal persons using our platform. Turasistan takes all necessary administrative and technical measures under the Personal Data Protection Law No. 6698 (KVKK) and the European Union General Data Protection Regulation (GDPR).
Our information security management system aims to comply with the ISO 27001 standard, KVKK, GDPR, and relevant industry regulations.
Our Core Principles
Our information security approach is built on three core principles: confidentiality, integrity, and availability.
Confidentiality
Only authorized personnel can access information. Customer data is stored encrypted and is not shared with third parties.
Integrity
Data is ensured to be accurate, complete, and unaltered. Protection against unauthorized modifications is applied.
Availability
Authorized users can securely access information and systems when they need them.
Security Measures We Apply
3-Tier Security Architecture: Turasistan operates on a 3-Tier technology architecture preferred by banks. The system runs and is backed up on 3 different physical servers.
Firewall and Antivirus Protection: Dedicated firewall and antivirus solutions provide both hardware and software protection against threats.
Encryption: Customer information and all sensitive data are stored fully encrypted.
Access Control: Only authorized personnel can access information. User data is not shared with third parties without the user's consent.
Legal Compliance
We conduct our activities in full compliance with applicable national and international legislation.
KVKK (Law No. 6698)
We fulfill our obligations as data controller under the Personal Data Protection Law.
GDPR (EU General Data Protection Regulation)
We comply with GDPR principles when processing the data of European Union citizens.
ISO 27001
Our Information Security Management System (ISMS) processes are carried out in line with the ISO 27001 standard.
Responsibilities and Incident Reporting
Information security is a shared responsibility across the entire team. All our employees and business partners are obliged to comply with this policy.
Employee Responsibilities
All employees participate in information security awareness training and comply with security procedures.
Incident Reporting
Any security breach or suspicious situation must be reported immediately to the information security team.
Enforcement
Disciplinary processes are applied to employees who do not comply with the policy.
Do you have questions?
Contact us for more information about our information security policy or data protection practices.
Turasistan • Information Security Policy • Data Protection