Our Organization;
- Complying with all legislation, administrative regulations, legal responsibilities and standards related to quality,
- Taking into consideration the technologies and supporting factors used and taking all necessary measures,
- Ensuring a common perspective at every level of the organization in accordance with our Quality requirements,
- Providing all our employees with training and open communication opportunities,
- Providing our business partners and customers with quality services that meet their current and evolving needs and expectations,
- Working with our suppliers, dealers and business partners in cooperation and trust based on the win-win principle,
- Keeping customer satisfaction at the highest level by providing our customers with the best and fastest technical support services,
- Providing uninterrupted service to our customers through our redundant infrastructure operating 24/7 as part of our sustainable operations,
- Continuously improving and developing all our processes and management system practices and remaining always open to improvement,
- All processes related to certifications such as ISO 9001, ISO 27001, ISO 20000 and ISO 22301 have been completed and the relevant certifications have been obtained. In this way, we commit to an operational method secured in accordance with the Information Security Quality Management System, as well as to its continuity and periodic review for continuous improvement.
We act with a customer-oriented approach, aiming to respond to our customers’ needs and requests as quickly and accurately as possible. We provide our services on time and under the conditions we have promised, and we approach our customers within the framework of respect, dignity, justice, equality and courtesy.
- General: Your use of this website means that you have read and accepted the privacy and security terms and rules. If you believe that you cannot fulfill the obligations stipulated in the privacy terms, please do not use this website. Certain additional provisions and conditions may apply to the use of certain sections of the website or to interactions established through these sections.
- Monitoring/Changes to Privacy and Security Terms: Cloudy Bilişim (“Site Owner”) reserves the right to make changes to the privacy and security terms or introduce additional conditions at any time without prior notice. Any changes regarding the nature of the information collected during use, how such information is used, under which circumstances it is shared with others, and all necessary privacy terms will be presented on this page. Since the Site Owner reserves the right to modify the privacy terms, these terms must be reviewed regularly. Continued use of this website following such a change shall constitute acceptance of the changes to the privacy terms.
- Open System: Users; (The term User is used as a general definition referring to everyone who accesses the website, including members, if any.) acknowledge and accept that the internet is not a secure environment, that communication over the internet carries risks, and that all kinds of information, including personal information and passwords, may be subject to unlawful acts by third parties. The Site Owner provides no guarantee regarding security or malicious activities.
- Protection of Information: The Site Owner makes every effort to ensure the security of all pages on the website. Various technical and administrative practices are used to protect the confidentiality, security and integrity of the data registered on the website.
- Third-Party Websites: This website may contain websites operated by third parties that are not operated or controlled by the Site Owner, and links/information may be provided to such websites. The Site Owner provides no guarantee or specific commitment regarding the content, security, privacy policies or continuous availability of communication of these websites. Responsibility is subject to the terms stated on third-party websites. The security and privacy terms of such websites should be read before conducting any transaction. The Site Owner cannot be held responsible for personal information provided to such websites, content and services obtained from such websites, or the privacy policies and practices of such websites.
- Site Utilities: Certain utility programs may be required for users to benefit from some sections of the website. If these sections are used, data regarding the manner and scope of use may be recorded in the website database. Likewise, certain “cookies” may be used to make it easier for you to benefit from these sections, and some information may be sent to users through these cookies.
- Personal Information: Pursuant to the Law No. 6698 on the Protection of Personal Data (“Law”), any information relating to an identified or identifiable natural person constitutes personal data (“Personal Data”). When the User visits or uses the Website or receives services offered through the Website, the name, surname, telephone number, e-mail address, IP information, date and time of use may have been transmitted, disclosed or recorded to the Website. Users shall be deemed to have acknowledged and accepted that, by disclosing such information, they have taken into consideration that the Personal Data they have transmitted, disclosed or recorded shall be available to Cloudy Bilişim under the terms specified in these Website Terms, and that any Personal Data they disclose, record or reveal to the Website shall no longer be confidential against Cloudy Bilişim.
ii. Such personal data may be processed, in whole or in part by automated means, by Cloudy Bilişim pursuant to Article 5 of the Law, based on the legal grounds that “processing personal data belonging to the parties to a contract is necessary, provided that it is directly related to the establishment or performance of the contract, and that it is mandatory for the data controller to fulfill its legal obligation.” Such Personal Data may also be processed for other purposes specified in the Disclosure Notice published on the Website and/or presented to the User’s attention and/or approval in various sections, where the relevant User has given explicit consent.
iii. Special Categories of Personal Data: Unless required by law, Cloudy Bilişim does not request any information from Users relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, or biometric and genetic data. Cloudy Bilişim shall have no responsibility for such information being provided, recorded or disclosed to the Website or through the Website.
The Policy on the Protection, Processing, Storage and Destruction of Personal Data, which contains detailed information regarding Personal Data and is published on the Website, constitutes an integral part of these Website Terms. - Violation of Privacy and Security Terms: In the event that the privacy terms are not complied with or an attempt is made to violate the rules, whether or not the violation is fully realized, the Site Owner reserves the right to reject, remove or delete information available in the system and, without prior notice, suspend or terminate users’ access to the website and services and cancel their membership, although it is not obliged to do so. This rule also applies where the violation or attempted violation is indirectly committed by a third party acting on behalf of the user.
- Information and Communication: For questions regarding the privacy terms of https://www.cloudybilisim.com, you may obtain further information by contacting bilgi@localhost.
www.cloudybilisim.com: CLOUDY Bilişim Sistemleri ve Danışmanlık A.Ş. (“CLOUDY BİLİŞİM”) is a website (“Site”) presenting the corporate information of CLOUDY BİLİŞİM. Please read the following terms. By accessing the Site, you agree to the legal terms set out below between you and CLOUDY BİLİŞİM.
General Terms of Use: From the moment you begin using the Site, you obtain the right to access, use and receive commercial communications, commercial electronic communications, certain interfaces and functions provided through or via this website and any other related websites, if applicable.
Accessing and using this website means that you have read and accepted the usage policy and terms. No separate “declaration of acceptance” in any form is required for this purpose.
Where membership or an explicit declaration of acceptance is required, you shall be deemed to have accepted the terms of use stated herein by selecting the “accept and approve” steps.
If you believe that you cannot fulfill the obligations stipulated in the terms of use or meet the acceptance/permission conditions, please do not use this website. Likewise, if you are not of the age legally required for the validity of your declaration of acceptance or if you are legally restricted, your declaration of acceptance shall have no legal validity and you should not use this website.
Monitoring/Changes to Terms of Use: CLOUDY BİLİŞİM continuously renews and updates the website in order to provide users (the term User is used as a general term referring to everyone accessing the website, including membership, if any) with the best possible service.
Information and content provided may change as a result of innovations and updates.
CLOUDY BİLİŞİM reserves the right to change the terms of use or introduce new/additional terms at any time without prior notice. Changes will be published on the website so that users can be informed of all necessary terms of use. Continued use following such a change shall constitute acceptance of the changes.
Use of Content and Services:
The content on the Site, including CLOUDY BİLİŞİM, brands, promotional materials, data files, written texts, information, news, opinions, recommendations, advertisements, announcements, audio, music, video, photographs, visuals, software and similar content (“Site Content”), may be published partly directly by CLOUDY BİLİŞİM and partly from other sources.
CLOUDY BİLİŞİM does not guarantee the accuracy or reliability of information, communications or commercial electronic communications transferred from other websites or linked websites, nor does it assume any legal responsibility for such information or for other websites to which links or information are provided.
Information belonging to third parties and quotations contained on the Site are provided for promotional purposes. CLOUDY BİLİŞİM and/or the owners of such content reserve the right to change the content and service terms without notice.
There may be legal age restrictions regarding the Site. Users must comply with these restrictions.
Unless otherwise stipulated by CLOUDY BİLİŞİM, users have no right to sell products or services, publish commercial advertisements or announcements, or conduct similar commercial activities by using the Site pages or Site Content.
CLOUDY BİLİŞİM has the right to determine the Site and Site Content at its discretion and may present the Site together with advertisements and promotions. Advertisements and promotions do not necessarily have to be directly related to the Site. CLOUDY BİLİŞİM may change its practices and tariffs regarding advertisements at any time and at its discretion.
Users who benefit from the Site Content shall be deemed to have assumed the risks associated with the content obtained through the Site.
Liability Arising from the Use of the Site and Content:
By accepting the terms of use and benefiting from the Site in any way, you accept responsibility for all transactions you carry out. Users have the right to take or refrain from taking action based on Site Content or any communication carried out through the Site, regardless of its source. The legal consequences of such decisions belong solely to the user accessing the Site. CLOUDY BİLİŞİM assumes no responsibility in this regard.
CLOUDY BİLİŞİM cannot be held responsible for any material, moral, legal or financial consequences or indirect damages such as loss of profits arising from any use of the content and services provided through the Site, including use in erroneous or unlawful activities or in violation of the law.
The content on the Site is provided for informational purposes and does not constitute advice. Users acknowledge that the information presented on the Site is general and summarized in nature and that CLOUDY BİLİŞİM does not encourage users to use such information or benefit from any product of CLOUDY BİLİŞİM. Users are responsible for verifying the accuracy and currency of any information on the Site before using it. CLOUDY BİLİŞİM accepts no responsibility for any use of information on the Site by users and provides no assurance regarding the accuracy or currency of such information. CLOUDY BİLİŞİM declares that all damages arising from the use of information on the Site shall belong to the Site user.
The information, comments and recommendations available on the Site or any linked resources, if any, do not constitute investment advice. CLOUDY BİLİŞİM does not guarantee the accuracy or adequacy of any opinions, information, assessments, comments or statistical figures and values contained in resources accessed through the Site. CLOUDY BİLİŞİM cannot be held responsible for errors and omissions in resources accessed through the Site, disruptions, delays, deficiencies or inaccuracies in data publication, termination of data publication, direct and/or indirect damages, loss of profits, moral damages or damages suffered by third parties as a result of using the accessed information. CLOUDY BİLİŞİM may suspend, cancel, change and/or remove such data flow without prior notice.
If communication between users is possible through the Website, all responsibility relating to communication between users belongs to the parties. CLOUDY BİLİŞİM makes no commitment and assumes no responsibility regarding data security or malicious activities involving persons participating in the communication/connection/data traffic.
No Warranty:
This Site is provided to users on an “as is” basis and, to the fullest extent permitted by law, contains no express or implied, special or general warranty, whether written or oral.
CLOUDY BİLİŞİM does not warrant that the functions and content on this Site are secure and error-free, that defects will be corrected, or that the Site itself, the server used to provide the Site, or third-party websites/links contain no viruses or other harmful content.
CLOUDY BİLİŞİM makes no express or implied commitment that the Site and the content provided will meet all expectations, purposes and specific needs or will be uninterrupted and of sufficient quality. CLOUDY BİLİŞİM shall not be liable to members or Users for consequential damages, loss of profits or indirect damages arising from the Site or Site Content. CLOUDY BİLİŞİM reserves the right, without prior notice, to generally terminate or suspend publication of the Site, close the Site, partially or completely change or disable the content, visual design and similar elements on the Site, or make them subject to a fee.
Sub- and Top-Level Links: This Site may contain sub-sites and top-level sites operated by third parties that are not owned or controlled by CLOUDY BİLİŞİM, and links/information may be provided to such sites. CLOUDY BİLİŞİM provides no guarantee or specific commitment regarding the content, suitability, security, privacy policies or continuous availability of communication of such websites. CLOUDY BİLİŞİM cannot be held responsible for personal information provided to such websites, content and services obtained from such websites, or the privacy policies and practices of such websites.
Membership
CLOUDY BİLİŞİM may make the use of certain sections subject to membership/registration requirements and may establish different membership categories or modify existing categories. Certain identification and contact information may be requested during registration.
If a membership system is established, a username and password shall be provided to the Member or created by the Member.
The Member is responsible for all (i) identification information and (ii) contact information entered during registration, placed on the Site or Content, transmitted or sent through this Site. Identification and contact information provided for registration shall be deemed current, accurate and reliable. The Member is responsible for keeping the username and password secure.
CLOUDY BİLİŞİM accepts no responsibility for incorrect, unlawful or unauthorized use of the username and password. In cases of unauthorized use, the member responsible for such use shall be liable for any damages suffered by CLOUDY BİLİŞİM or third parties.
All transactions carried out through a membership account are the sole responsibility of the relevant member.
Members acknowledge and warrant that all information submitted to the Site or sent through the Site is reliable, accurate, not misleading, does not infringe the rights of third parties, is not contrary to law, is submitted in good faith and that they have the right to post or transmit such information. If CLOUDY BİLİŞİM receives an application, request or complaint indicating that content posted/transmitted by Users to the website causes harm to other Users or third parties, or determines that such content violates legislation or international legal instruments, it reserves the right to terminate the User’s membership. However, it has no obligation to do so.
The Member is obliged to take the necessary measures and notify CLOUDY BİLİŞİM immediately upon learning that the username or password has been used without authorization or an attempt has been made to obtain it.
Commercial Communication: Users declare and accept that, where permission/approval is legally required for sending electronic communications, CLOUDY BİLİŞİM may send electronic communications or commercial electronic communications upon obtaining such permission/approval; in other cases, such permission/approval shall not be required. Users may be contacted through any electronic communication means, whether commercial or non-commercial. Where permission/approval is required for sending commercial electronic communications, the User acknowledges that such permission/approval is not a prerequisite and/or mandatory condition for using the Website and/or receiving services. The User has the right to withdraw such permission/approval at any time and refuse commercial electronic communications. However, in such a case, informational, collection and approval-related electronic communications concerning services already paid for and/or received by the User may continue to be sent. Opt-out methods are indicated in electronic communications sent by CLOUDY BİLİŞİM.
Collection of Visit Information: When the Site is visited, web servers automatically begin collecting information in order to communicate with the visitor’s computer. In addition, the number of visits to the Site, the sections preferred by visitors, IP addresses, domain type, browser type, date and time information and navigation on the website are monitored, reviewed and stored. Use of the Site means that the User gives permission for the collection, processing and storage of the specified information.
Prohibition of Interference: It is prohibited to breach or attempt to breach the security of the Site. Criminal proceedings may be initiated against those attempting such violations and a public prosecution may be filed. Any allegation of violation shall be investigated by CLOUDY BİLİŞİM and, if an unlawful violation is suspected, the relevant legal authorities shall be contacted/cooperated with. If the actions specified in this article are determined to have been carried out, the relevant person’s or user’s access to the Site shall be terminated and any membership shall be cancelled. The person or persons responsible for the violation shall be financially, legally and criminally liable to the person whose rights have been violated and/or to CLOUDY BİLİŞİM under applicable laws.
Violation of Terms of Use: CLOUDY BİLİŞİM reserves the right, in the event of non-compliance with the “Website Terms of Use” or an attempt to violate the rules, whether or not the violation is fully realized, to reject, remove or delete information available in the system and, without prior notice, suspend or terminate users’ access to the Site or cancel their membership. This also applies to indirect violations or attempted violations by a third party acting on behalf of the User. Failure by CLOUDY BİLİŞİM to exercise or enforce any legal right or remedy stated herein shall not mean that it has waived such right or accepted the violation.
Site Policies:
Criminal Acts: Users are obliged not to engage in any behavior that i) constitutes a criminal offense under international or local legislation or ii) violates the relevant regulations and directives of the European Union.
Prohibited Conduct: Users agree and undertake not to operate or use software that sends more messages to the Site server within a given period than a human could send.
13. Termination: Unless otherwise provided in a separate agreement or in the Site Content, the User may terminate use of the Site and any membership at any time without restriction or notice. If the Site provides specific steps for terminating membership, these steps must be followed. CLOUDY BİLİŞİM may also, without notice, cancel membership, prevent or terminate use where (i) the User violates the terms or policies set out herein or determined by CLOUDY BİLİŞİM, (ii) the User has no right to use the Site due to legal restrictions, (iii) required by legislation or decisions of administrative regulatory bodies, (iv) access to the Site becomes impossible due to legal regulations or force majeure, or (v) the publication of the Site is suspended, stopped or terminated at the discretion of CLOUDY BİLİŞİM or for similar reasons.
Records: In disputes arising from the use of the Site, all computer records of CLOUDY BİLİŞİM, including its books and communication logs, as well as e-mail and fax notifications sent by CLOUDY BİLİŞİM to users, shall constitute conclusive and exclusive evidence.
Language: In the event of any inconsistency between the Turkish and foreign-language versions of the Website, the “Terms of Use” and the “Privacy and Security Terms”, the Turkish version shall prevail.
Notice Agreement: It is accepted that e-mail or fax notices sent by CLOUDY BİLİŞİM to the contact information provided by users on the Site shall have the same legal consequences as valid legal notices.
Applicable Law: The laws of the Republic of Türkiye shall apply to disputes that may arise in connection with the use of the Site.
Competent Courts and Enforcement Offices: Istanbul (Central) Courts and Enforcement Offices shall have jurisdiction over all disputes arising in connection with the Site and its terms of use.
Information and Communication: For questions regarding the terms of use of www.cloudybilisim.com, you may obtain further information by contacting bilgi@localhost.
Cookie Policy and Cookie Disclosure Notice
Policy Last Updated: 16.02.2022
Utility programs and cookies may be used through the www.cloudybilisim.com website (“Website”) for accessing certain Services or the Website, enabling faster and more active transactions, improving users’ experiences on the Website, evaluating user preferences, customizing/personalizing the Website according to user preferences, conducting advertising activities, and increasing Website functionality and performance.
When the Services/Website are used, the Website is visited, communication is established through the Site and/or any form, survey or similar field on the Website is completed, data regarding the manner and scope of such use, IP address and browser type may be recorded in the Website database and/or certain cookies may be used and information may be sent to the User through them. Data recorded through cookies are processed by CLOUDY Bilişim Hizmetleri A.Ş. (“CLOUDY BİLİŞİM”) in accordance with the provisions of the Personal Data Protection Law and may be shared with third parties referred to in this Policy/whose cookies are used, and may be transferred abroad within this scope. You may refer to your browser settings to change cookie settings or block cookies.
Unless you change your Cookie settings in your browser, you are deemed to have accepted the use of cookies on this Website.
If you block cookies or change the relevant settings, your access to the Website or its features and Services may be partially or completely restricted.
The cookies used on the Website may occasionally be changed or updated, the use of existing cookies may be discontinued or new cookies may begin to be used. Therefore, CLOUDY BİLİŞİM reserves the right to change this Cookie Policy without prior notice. Any such change shall take effect on the publication/update date on the Website, and the last update date of this Policy is indicated above.
The purpose of this Cookie Policy and Cookie Disclosure Notice is to provide information regarding the processing of personal data obtained through cookies used while operating the Website. This text explains which types of cookies and/or utility programs are used on the Website, for what purposes they are used, and how they can be controlled.
Cookies Used on the Website
Google Analytics:
Google Analytics is a free analytics tool provided by Google that helps website and application owners understand what visitors do on their websites and applications. It may use a series of cookies to collect information without identifying visitors and report website usage statistics to Google. The main cookie used by Google Analytics is the “_ga” cookie.
Learn more about Analytics cookies and privacy information and learn more.
Google Ads:
Google uses cookies such as NID and SID to help personalize advertisements on Google properties such as Google Search. For example, these cookies are used to remember your most recent searches, previous interactions with an advertiser’s advertisements or search results, and visits to an advertiser’s website. This use helps show you personalized advertisements on Google. Click for more information.
Facebook:
Facebook uses cookies if you have a Facebook account, use Facebook products including the website and applications, or visit websites or applications that use Facebook products, including the Like button and other Facebook Technologies. Cookies help Facebook provide its products to you and understand information it receives about you, including your use of other websites and applications, regardless of whether you are registered or logged in. Cookies are used for identity verification, security and site integrity, advertising, recommendations, measurement, analysis and reporting.
Click here for Facebook privacy principles.
Controlling the Use of Cookies
Although the use of cookies helps the Website provide better service, you may prevent the use of cookies or personalize your cookie preferences by changing your browser settings or following the other steps specified in the links below. However, please note that in such a case the Site may not function fully and you may not be able to benefit from all features. For more information, please visit the links in the table below:
Google Adwords https://support.google.com/ads/answer/2662922?hl=en
Google Analytics https://tools.google.com/dlpage/gaoptout
Criteo https://www.criteo.com/privacy/disable-criteo-services-on-internet-browsers/
Google Home http://www.google.com/support/ome/bin/answer.py?hl=en
Internet Explorer https://support.microsoft.com/en-us/help/17442/windows-internet-explorer–manage-cookies
Mozilla Firefox http://support.mozilla.com/en-US/kb/Cookies
Opera http://www.opera.com/browser/tutorials/security/privacy/
Safari https://support.apple.com/kb/ph19214?locale=tr_TR
Your Rights as a Data Subject
Regarding your personal data processed by CLOUDY BİLİŞİM under this Cookie Policy, if you wish to exercise your rights under Article 11 of the Personal Data Protection Law, you may fill out the application form and send it to our company’s address “Cumhuriyet Mah. Yeni Yol 1 Sok. Bomonti Business Center No: 8 İç Kapı No: 36 Şişli/ İstanbul” or to bilgi@cloudybilsim.com in accordance with the procedures set out in the Communiqué on the Procedures and Principles of Application to the Data Controller, or deliver it personally or through your representative to our company address. If you wish to exercise this right through your representative, a copy of the power of attorney containing special authorization must be attached to the form.
Documents verifying your identity and, where applicable, documents supporting your request must be attached to the form. If you wish to exercise this right through your representative, a notarized copy of the power of attorney containing special authorization must be attached.
In cases such as incomplete or incorrect information in the application, failure to state the request clearly and understandably, failure to provide supporting documents in full or properly, or failure to attach a copy of the power of attorney in applications made through a representative, we may experience difficulties in responding to your requests and delays may occur during the investigation process. Therefore, it is important to comply with these matters when exercising your rights. Our company shall not be responsible for delays arising from failure to comply with these requirements. Our company’s legal rights are reserved against inaccurate, false, unlawful or bad-faith applications.
Trade Name: CLOUDY Bilişim Hizmetleri A.Ş.
Address: Bomonti Cumhuriyet Mah. Yeni Yol 1 Sok. Bomonti Business Center No: 8 İç Kapı No: 36 Şişli/ İstanbul
MERSIS No: 00000000
Trade Registry No: 00000
Tel: 0850 441 32 53
Website: https://cloudybilisim.com
1. Purpose and Scope:
This policy aims to describe the methods adopted by CLOUDY BİLİŞİM for personal data processing activities and the protection of personal data in all activities carried out by CLOUDY BİLİŞİM in compliance with Law No. 6698 on the Protection of Personal Data (KVKK). The Personal Data Protection and Processing Policy includes the principles applied in the collection, use, sharing, storage and destruction of personal data by CLOUDY BİLİŞİM Bilişim.
This Policy covers all personal data processed within the processes of our organization through automated means or non-automated means provided that they form part of any data recording system, belonging to customers who are or are not affiliated with CLOUDY BİLİŞİM, company employees, interns and former employees.
2. Authorities and Responsibilities:
All employees, solution partners, business partners, external service providers and anyone else who stores or processes personal data on behalf of the organization are responsible for fulfilling the requirements regarding the destruction of data specified in the Law, Regulation and Policy. Each business unit is responsible for storing and protecting the data it generates within its own business processes.
The responsibility for receiving or accepting notifications or correspondence from the Personal Data Protection Board on behalf of the data controller and carrying out registration-related procedures belongs to the data controller’s contact person.
Within the Organization;
- Data Controller: CLOUDY BİLİŞİM Hizmetleri A.Ş.
- Data Controller Contact Person: Sema ÇINARBAŞ
has been designated as such.
3. Definitions and Abbreviations:
Explicit Consent; Consent based on being informed and freely declared regarding a specific matter.
Relevant User; Persons who process personal data within the organization of the data controller or under the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of data.
Destruction; Deletion, destruction or anonymization of personal data.
Law; Law No. 6698 on the Protection of Personal Data (KVKK).
Recording Medium; Any medium in which personal data processed by fully or partially automated means or non-automated means, provided that it forms part of any data recording system, is located.
Personal Data; Any information relating to an identified or identifiable natural person.
Processing of Personal Data; Any operation performed on personal data, including obtaining, recording, storing, preserving, modifying, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data through fully or partially automated means or non-automated means provided that it forms part of any data recording system.
Anonymization of Personal Data; Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even when matched with other data.
Deletion of Personal Data; Rendering personal data inaccessible and unusable again for Relevant Users in any way.
Destruction of Personal Data; Rendering personal data inaccessible, irretrievable and unusable again by anyone in any way.
Board; Personal Data Protection Board.
Special Categories of Personal Data; Data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data.
Periodic Destruction; The deletion, destruction or anonymization of personal data carried out automatically at recurring intervals specified in the data retention and destruction policy when all conditions for processing personal data specified in the Law have ceased to exist.
Data Subject/Relevant Person; The natural person whose personal data is processed.
Data Processor; A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.
Data Controller; The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Regulation; The Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette on October 28, 2017.
4. Personal Data Processing and Protection Policy:
CLOUDY BİLİŞİM sets out in concrete terms through this policy the measures and processes applied for the protection and processing of Personal Data. In cases where this policy is incompatible with applicable laws and regulations or is not up to date due to updated legislation, CLOUDY BİLİŞİM undertakes to comply with the legislation in force. This policy is updated and revised in line with changes in laws, regulations and legislation to ensure that CLOUDY BİLİŞİM fulfills its legal requirements.
4.1. Ensuring the Security of Personal Data
CLOUDY BİLİŞİM takes all necessary technical and administrative measures to provide the appropriate level of security required for the protection of personal data.
As stipulated in Article 12, paragraph 1 of the KVKK;
- Preventing unlawful processing of personal data,
- Preventing unlawful access to personal data,
- Ensuring the preservation of personal data.
Necessary measures are taken to ensure these conditions.
The measures implemented by CLOUDY BİLİŞİM to ensure the security of personal data are detailed in the subsections below.
4.1.1. Technical Measures
Technical measures are taken in accordance with developments in technology. Infrastructure investments are made in line with developing technology. Software and hardware containing antivirus systems and firewalls are installed. Access permissions to software containing personal data are restricted. Access controls are performed periodically. Access and authorization definitions are made in accordance with legal compliance requirements determined on a unit basis. Log records are kept for Portal and CRM applications accessed by personnel. Systems are kept on versions with necessary security measures against known vulnerabilities. Information obtained through security checks of systems is reported to relevant persons. Risks are identified and necessary technical measures are taken. Awareness is continuously expanded so that technical measures for maintaining the security of Personal Data operate continuously and become part of the organizational culture. Controls ensure that the measures taken remain effective. Vulnerability and penetration tests are carried out periodically to ensure the security of the corporate network. All hardware within CLOUDY BİLİŞİM is protected by antivirus applications. CLOUDY BİLİŞİM facilities are protected against unauthorized entry through alarm systems, fingerprint readers, security personnel and camera systems. Critical hardware is protected against possible natural disasters through UPS and fire suppression systems. Data subject to destruction periods is destroyed using paper shredders.
4.1.2. Administrative Measures
CLOUDY BİLİŞİM Bilişim takes the necessary administrative measures to ensure the security of personal data and supervises employees to ensure that they work in accordance with these measures. Within the organization, ISO 27001 standards are followed to ensure the secure protection, processing, deletion, destruction and anonymization of Personal Data. In addition, ISO 9001, ISO 22301 and ISO 20000-1 standards are maintained. CLOUDY BİLİŞİM Bilişim employs knowledgeable and experienced personnel to ensure data security and provides the necessary KVK training to its personnel. Necessary internal controls are carried out for established systems. Within established systems, risk analysis, data classification, information security risk assessment and business impact analysis processes are conducted. The access rights and rules of employees working in information technology units regarding personal data are defined. Employees are informed that they may not disclose personal data they have learned to others in violation of the Law or use it outside the purpose of processing, and that this obligation continues after they leave their positions. Necessary commitments are obtained from employees accordingly. Regarding the sharing of personal data with third parties, framework agreements are signed with the persons with whom personal data is shared or provisions are added to contracts to ensure data security. KVKK sanctions are included in dealer agreements according to the activities of the third party with whom data is shared. Third parties with whom personal data is shared accept provisions requiring them to take the necessary security measures to protect personal data and ensure compliance with these measures within their own organizations. If it is determined that personal data processed despite the measures taken has been unlawfully obtained by others, the data controller contact person notifies the relevant person and the Personal Data Protection Board. An investigation is conducted into how the personal data was obtained by others. CLOUDY BİLİŞİM Bilişim applies the necessary administrative measures to eliminate the vulnerability it has identified and takes technical measures when necessary.
4.1.3. Storage of Personal Data in a Secure Environment
CLOUDY BİLİŞİM takes the necessary technical and administrative measures according to technological capabilities and application costs to store the personal data it obtains in secure environments. For physical data, archives accessible only by authorized persons have been established. Information classifications are made to identify critical data within the organization. Personnel data is kept in appropriate environments accessible only to authorized personnel. For software-based data, voice recordings are stored in the virtual switchboard accessible only to authorized persons. Only authorized personnel have access to applications through which personal data can be accessed.
4.1.4. Audits Conducted to Ensure the Sustainability of Personal Data Protection
CLOUDY BİLİŞİM carries out or has the necessary audits carried out in accordance with Article 12 of the Law. Internal and external audits are conducted to ensure the sustainability of the Information Security Management System. Regular penetration tests are carried out against potential technical vulnerabilities in systems. Systems are regularly monitored by the IT department. Necessary technical and administrative measures are taken following the identification of findings through management system audits, data generated by warning systems and system monitoring. When unlawful access to or processing of personal data is identified during audits, the Information Security Management Representative is informed.
4.1.5. Measures Taken in Case of Unauthorized Disclosure of Personal Data
CLOUDY BİLİŞİM notifies the relevant personal data owner and the Personal Data Protection Board in the event of unauthorized disclosure of personal data processed in accordance with Article 12 of the Law.
If deemed necessary by the Personal Data Protection Board, this situation may be announced on the Board’s website or by another method.
4.1.6. Measures Applied to Ensure the Protection of Personal Data by Third Parties
CLOUDY BİLİŞİM includes reciprocal provisions in its agreements with third parties regarding the prevention of unlawful processing of personal data, prevention of unlawful access to data and preservation of data. Confidentiality agreements are signed before information is shared with third parties. Necessary information is provided to third parties to increase awareness.
4.1.7. Measures Applied for the Protection of Special Categories of Personal Data
Special categories of personal data require adequate measures due to their nature and because they may cause harm or discrimination to individuals. Article 6 of the Law defines as “Special Categories” personal data that may create a risk of harm or discrimination when processed unlawfully.
These data include race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data.
CLOUDY BİLİŞİM takes the necessary measures to protect special categories of personal data defined as “special categories” by the Law and processed lawfully. Special attention is paid to special categories of personal data in the technical and administrative measures taken to protect personal data.
CLOUDY BİLİŞİM processes special categories of personal data it processes provided that sufficient measures determined by the Personal Data Protection Board are taken. Explicit consent of the data subject is obtained before special categories of personal data are processed. If explicit consent is not obtained from the data subject, such data may be processed under the authority granted by law in accordance with the following criteria.
- Special categories of personal data other than health and sexual life data may be processed in cases stipulated by law,
- Special categories of personal data relating to the health and sexual life of the data subject may only be transferred to persons or authorized institutions and organizations under a confidentiality obligation for purposes such as protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and management of healthcare services and their financing.
4.1.8. Creating Awareness to Ensure the Protection of Personal Data
Necessary information is provided to business units, training is organized and its effectiveness is measured in order to increase awareness aimed at preventing unlawful processing of personal data, preventing unlawful access to data and ensuring the preservation of data. The “Personal Data Protection and Processing Policy” and related documents have been published on our organization’s website. CLOUDY BİLİŞİM employees have been informed about this policy.
Policies are revised and employees are informed again in case of changes to relevant laws, regulations or legislation.
4.2. Principles for Processing Personal Data:
The principles for processing personal data are set out in paragraph 2 of Article 4 of the Law. CLOUDY BİLİŞİM processes personal data in accordance with these principles.
Personal data is processed in accordance with the following principles;
- Being in compliance with the law and the rules of honesty,
- Being accurate and, where necessary, up to date,
- Being processed for specific, explicit and legitimate purposes,
- Being connected with, limited to and proportionate to the purposes for which they are processed,
- Being retained for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed.
4.3. Conditions for Processing Personal Data:
CLOUDY BİLİŞİM obtains and processes most of the data received from Relevant Persons due to legal obligations. Pursuant to Article 5/2 of the Personal Data Protection Law, personal data may be processed where:
- It is expressly provided for by law.
- It is necessary to protect the life or physical integrity of the person or another person who is unable to express consent due to actual impossibility or whose consent is not legally recognized.
- It is necessary to process personal data belonging to the parties to a contract, provided that it is directly related to the establishment or performance of the contract.
- It is mandatory for the data controller to fulfill its legal obligation.
- It has been made public by the relevant person.
- Data processing is mandatory for the establishment, exercise or protection of a right.
- Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person.
Outside the circumstances specified above, CLOUDY BİLİŞİM processes personal data only by obtaining the explicit consent of the data subjects.
4.4. Destruction of Personal Data:
CLOUDY BİLİŞİM destroys the personal data it obtains at the request of personal data subjects, unless it is required to use such data due to legal obligations or for the protection of public order. Personal data belonging to data subjects is destroyed upon the decision of the organization when the requirements for continuing services to citizens, fulfilling legal obligations, and planning employee rights and benefits no longer exist. The rules and methods regarding the destruction of personal data are detailed in the “Data Retention and Destruction Policy”.
4.5. Transfer of Personal Data to Persons in Türkiye:
CLOUDY BİLİŞİM carefully complies with the conditions stipulated in the Law regarding the sharing of personal data with third parties, without prejudice to provisions contained in other laws. Within this framework, personal data is not transferred to third parties without the explicit consent of the data subject. However, if one of the following conditions specified in the Law exists, personal data may also be transferred without obtaining the explicit consent of the data subject.
These circumstances are as follows:
- It is expressly provided for by law,
- It is necessary to protect the life or physical integrity of the person or another person who is unable to express consent due to actual impossibility or whose consent is not legally recognized,
- It is necessary to process personal data belonging to the parties to a contract, provided that it is directly related to the establishment or performance of the contract,
- It is mandatory for the data controller to fulfill its legal obligation,
- It has been made public by the data subject,
- Data processing is mandatory for the establishment, exercise or protection of a right,
- Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
Provided that adequate measures are taken, special categories of personal data may be transferred without explicit consent where permitted by law for special categories other than health and sexual life data, and for health and sexual life data for purposes such as:
- Protection of public health,
- Preventive medicine,
- Medical diagnosis,
- Carrying out treatment and care services,
- Planning and management of healthcare services and their financing.
The conditions specified for processing such data are also complied with when transferring special categories of personal data.
4.6. Transfer of Personal Data to Persons Abroad:
CLOUDY BİLİŞİM does not transfer personal data to foreign countries in any way and does not store personal data on servers located in foreign countries.
4.7. Categorization of Personal Data:
Personal data held by CLOUDY BİLİŞİM is categorized into two groups: “Data Subject Group” and “Data Type”.
- Data Subject Group Categories
- Customers: Personal data obtained for the purpose of providing sales and support services for CLOUDY BİLİŞİM’s Invoice & Sales Management, Purchase Management, Inventory & Warehouse Management, Current Account Management, Finance Management and Fixed Asset Management. Most of this data is personal data that must be collected under applicable laws. Explicit consent is obtained for personal data that is not mandatory.
- CLOUDY BİLİŞİM Employees: CLOUDY BİLİŞİM employees whose personal data is processed in accordance with applicable legislation, particularly Labor Law and Occupational Health and Safety legislation.
- Former CLOUDY BİLİŞİM Employees: Former CLOUDY BİLİŞİM employees whose personal data must continue to be processed for a certain period after termination of employment in accordance with applicable legislation, particularly Labor Law and Occupational Health and Safety legislation.
- Supplier Personal Data: Telephone numbers and e-mail addresses may be collected to ensure continuity in commercial relations with suppliers.
- Data Type Categories
- Identification Information
- Contact Information
- Address Information
- Bank Account Information
- Education Data
- Visual/Audio Data
- Criminal Record Information
- Financial Data
- Health Data
- Fingerprints
- Personnel Information
- Reference Data
- Professional Data
- Signature Data
- Military Service Data
- Tariff Information
- Tax Number
- Printed Documents
CLOUDY BİLİŞİM may in some cases obtain personal data in printed document format for the services it provides to its customers and employees. Such data is processed, stored and destroyed in accordance with the conditions specified in the Personal Data Protection Law.
- Personnel records used in human resources; All personal data processed to obtain information that forms the basis for the personnel rights of our employees or natural persons who have an employment relationship with our organization.
- Fingerprint Data; Fingerprint data used by CLOUDY BİLİŞİM employees when entering and leaving secure areas.
- Customer Services; Personal data obtained in accordance with the requirements of applicable laws in most cases during tariff and package provision processes for customers.
- Call / Voice Recordings; Recordings obtained to ensure continuity of services provided to customers and to improve the quality of CLOUDY BİLİŞİM customer services.
- Camera Recording.
For security purposes, CLOUDY BİLİŞİM carries out monitoring through security cameras in our buildings and facilities and processes personal data for tracking visitor entry and exit. The use of security cameras constitutes a personal data processing activity.
Within this scope, CLOUDY BİLİŞİM acts in accordance with the Constitution, the Personal Data Protection Law and other relevant legislation.
Image recordings of our visitors are obtained through camera monitoring systems at the entrances and within our organization’s buildings and facilities.
Our organization conducts camera monitoring activities for security purposes in order to increase the quality and reliability of the services provided and ensure the security of the organization, customers and other persons.
Our organization conducts camera monitoring activities for security purposes in accordance with the regulations of the Personal Data Protection Law.
Only a limited number of organization employees have access to digitally recorded and stored records. Confidentiality agreements have been signed with personnel who have access authorization.
Our organization takes the necessary technical and administrative measures to ensure the security of personal data obtained as a result of camera monitoring activities in accordance with Article 12 of the Personal Data Protection Law.
- Internet Website Cookie Information
Cookie information may be collected anonymously for the purpose of creating a customer portfolio.
- Personal Data of Visitors
For the purpose of ensuring the security of visitors to ERP CLOUDY Bilişim, only first and last names are collected from all relevant persons without obtaining personally identifying personal data.
- Biometric Personal Data
Photographs and camera recordings, excluding recordings falling within the scope of Physical Premises Security Information, voice recordings and fingerprint data obtained from personnel. Biometric Personal Data is processed, stored and destroyed in accordance with the Personal Data Protection Law.
4.8. Rights of the Personal Data Subject:
You may exercise the rights specified above by using the following methods;
- Written: CLOUDY BİLİŞİM by completing the KVKK Request Form,
- E-mail: by sending an e-mail to bilgi@cloudybisim.com,
- Telephone: 0850 441 32 53
- Address: Bomonti Business Center Cumhuriyet Mah. Yeni Yol 1 Sok. No:7 Floor: 7&9 Şişli / İstanbul
You may exercise your rights using these methods. In applications, identifying information must be provided to prevent incorrect processing and to identify the relevant person.
You may exercise your rights using these methods. In applications, identifying information must be provided to prevent incorrect processing and to identify the relevant person.
Pursuant to the relevant Law, the details of the data controller, data controller representative and data controller contact person are as follows:
- Data Controller: CLOUDY BİLİŞİM Sistemleri ve Danışmanlık Hizmetleri A.Ş.
- Data Controller Contact Person: Sema ÇINARBAŞ
4.9. CLOUDY BİLİŞİM’s Disclosure and Information Obligation:
Under Article 10 of the Law, data subjects must be informed before or at the latest when personal data is obtained. The information that must be provided to data subjects within the scope of this disclosure obligation is as follows:
- The identity of the data controller and, if applicable, its representative,
- The purposes for which personal data will be processed,
- To whom and for what purposes the processed personal data may be transferred,
- The method and legal basis for collecting personal data,
- Other rights listed in the relevant article of the Law.
On the other hand, within the scope of Article 28(1) of the Law, there is no disclosure obligation in the following cases:
- Processing of personal data by natural persons entirely within the scope of activities related to themselves or family members living in the same household, provided that the data is not disclosed to third parties and obligations regarding data security are complied with,
- Processing of personal data for purposes such as research, planning and statistics by making it anonymous for official statistics,
- Processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that national defense, national security, public security, public order, economic security, privacy or personality rights are not violated and no criminal offense is committed,
- Processing of personal data by public institutions and organizations authorized by law within the scope of preventive, protective and intelligence activities carried out to ensure national defense, national security, public security, public order or economic security,
- Processing of personal data by judicial authorities or execution authorities in relation to investigation, prosecution, adjudication or execution proceedings.
Cloudy Bilişim Disclosure Statement and KVKK Explicit Consent Statement documents have been prepared to inform data subjects and obtain their explicit consent.
4.10. Conditions for Deletion, Destruction and Anonymization of Personal Data:
CLOUDY BİLİŞİM deletes, destroys or anonymizes the personal data it obtains at the request of personal data subjects, unless it is required to use such data due to legal obligations or for the protection of public order. The rules and methods regarding the deletion, destruction and anonymization of personal data are detailed in the “Data Retention and Destruction Policy”.
4.11. Working Principles of the Personal Data Protection Committee
5. Reference Documents
- Law No. 6698 on the Protection of Personal Data,
- Regulation on the Deletion, Destruction or Anonymization of Personal Data.
6. Related Documents
- CLOUDY BİLİŞİM Bilişim Disclosure Statement
- KVKK Explicit Consent Statement
- CLOUDY BİLİŞİM Bilişim KVKK Request Form
Data Retention and Destruction Policy
- Purpose and Scope:
The purpose of this policy is to determine the rules, roles and responsibilities to be applied throughout the organization in order to fulfill the obligations regarding the retention and destruction of personal data and other obligations specified in the Regulation on the Deletion, Destruction or Anonymization of Personal Data, issued based on Law No. 6698 on the Protection of Personal Data and published in the Official Gazette No. 30224 on 28.10.2017, pursuant to Articles 5 and 6 of the Regulation.
This policy covers all personal data and special categories of personal data held by the organization, including all employees, consultants and, in cases where personal data is shared, affiliates, suppliers and other natural and legal persons with whom the organization has a legal relationship, where such data is processed by fully or partially automated means or non-automated means provided that it forms part of any data recording system, as defined by law.
- Authorities and Responsibilities:
All employees, consultants, external service providers and anyone else who stores or processes personal data on behalf of the Organization are responsible for fulfilling the requirements regarding the destruction of data specified in the Law, Regulation and Policy.
Each business unit is responsible for storing and protecting the data it generates within its own business processes.
- Definitions and Abbreviations:
Anonymization: Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even when matched with other data.
Destruction: Deletion, destruction or anonymization of personal data.
Personal Data: Any information relating to an identified or identifiable natural person.
Personal Data Processing Inventory: An inventory created by data controllers by associating personal data processing activities carried out according to their business processes with the purposes of processing personal data, data category, recipient group and data subject group, and detailing the maximum period required for personal data to be processed for the purposes for which it is processed, personal data intended to be transferred to foreign countries, and measures taken regarding data security.
Deletion of Personal Data: Rendering personal data inaccessible and unusable again for relevant users.
Destruction of Personal Data: Rendering personal data inaccessible, irretrievable and unusable again by anyone.
Special Categories of Personal Data: Data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data.
Periodic Destruction: The deletion, destruction or anonymization of personal data carried out automatically at recurring intervals specified in the data retention and destruction policy when all conditions for processing personal data specified in the Law have ceased to exist.
Data Recording System (VERBİS): A recording system in which personal data is structured and processed according to specific criteria.
Multi-Stakeholder Data: A single data field record concerning more than one stakeholder or person.
- Reference Documents:
- Law No. 6698 on the Protection of Personal Data
- Regulation on the Deletion, Destruction or Anonymization of Personal Data dated 28.10.2018 and numbered 30224
- Data Retention and Destruction Policy:
Destruction of Personal Data
When the purpose of processing personal data ceases to exist, explicit consent has been withdrawn, all conditions for processing personal data specified in Articles 5 and 6 of the Law cease to exist, or a situation arises where none of the exceptions specified in these articles can be applied, the personal data for which the processing conditions have ceased shall be deleted, destroyed or anonymized by the relevant business unit under Articles 7, 8, 9 or 10 of the Regulation (Articles on the Deletion, Destruction or Anonymization of Personal Data), taking business needs into consideration and explaining the reason for the method applied. However, where there is a final court decision, the destruction method ordered by the court must be applied.
As a result of periodic reviews or whenever it is determined that the conditions for data processing have ceased to exist, the relevant user or data subject shall decide, in accordance with this policy, whether the relevant personal data should be deleted, destroyed or anonymized from the recording medium held by the organization. In cases of doubt, written approval shall be obtained from the relevant department before the transaction is carried out. Pursuant to Law No. 6698, personal data whose retention period has expired is checked and destroyed by the archive officer from the organization’s archive (hardcopy & softcopy) every six months.
- Destruction of Multi-Stakeholder Data
When a decision needs to be made regarding the destruction of personal data with multi-stakeholder ownership in Central Information Systems, the opinion of the Data Controller Contact Person shall be obtained and a decision shall be made, in accordance with this policy, regarding the retention, deletion, destruction or anonymization of the relevant personal data.
- Destruction of Personal Data upon Data Subject Request
The natural person who owns the personal data may request the destruction of their personal data using the application methods specified in the CLOUDY Bilişim Disclosure Statement pursuant to Article 13 of the Law (Application to the Data Controller).
For applications submitted by mail to the addresses, registered mail with return receipt must be used to ensure proper tracking of the relevant person’s statutory thirty-day period. Such applications shall be accepted following identity verification by EDM Bilişim, and the relevant persons shall be responded to in writing or electronically within the statutory periods.
If the processing conditions have not ceased due to legal requirements, the data subject shall be informed that the personal data subject to the request cannot be deleted. The unit processing the relevant data examines whether all conditions for processing personal data have ceased to exist. If all processing conditions have ceased, the personal data subject to the request shall be deleted, destroyed or anonymized within three months at the latest. If all processing conditions have ceased and the personal data subject to the request has been transferred to third parties, the unit processing the relevant data shall immediately notify the third party to whom the transfer was made and ensure that action is taken regarding the request.
- Periodic Review of Personal Data
All users processing or storing personal data shall review, at least every six months, whether the conditions relating to processing have ceased to exist in the data recording media they use. Upon an application by the personal data subject or notification by a court, the relevant users and units shall conduct this review in the data recording media they use regardless of the periodic review period.
When deleting, destroying or anonymizing personal data, it is mandatory to act in accordance with the general principles in Article 4 of the Law (Processing of Personal Data), the technical and administrative measures required under Article 12 (Obligations Regarding Data Security), relevant legislation, Board decisions and court decisions.
- Retention of Personal Data
The processing periods for personal data are specified in the “Personal Data Inventory Table”.
These retention and destruction periods shall be taken into consideration in periodic destruction or destruction carried out upon request. Retention and destruction processes may vary upon the request of the data subject unless there is a legal obligation to retain the data.
- Technical Measures
- Corporate networks are protected against external attacks by firewalls.
- Guest access to the corporate network is restricted.
- Information system networks within the organization are monitored against potential intrusions, unauthorized access and cyber attacks.
- Physical areas where personal data processed within the organization is stored are protected against theft and loss through necessary physical security measures.
- Environments containing personal data are protected against external risks (fire, flood, earthquake, etc.) through appropriate methods. Access to critical units is restricted.
- Updates relating to system applications used within the organization are monitored and implemented.
- Access to systems within the organization is restricted according to the job descriptions of personnel. Passwords used to access systems, applications, databases and similar areas containing data are generated using a complex algorithm and systems require their use accordingly.
- The system infrastructure is secured against malicious software and various antivirus programs are used.
- Paper documents, servers, backup devices, CDs, DVDs and USB devices containing personal data are stored in appropriate environments with additional security measures. Measures to increase physical security, such as keeping these items locked when not in use and maintaining entry and exit records, are also implemented.
- The organization backs up personal data and ensures its security. The accuracy of backups is periodically tested.
- Access permissions are checked periodically.
- Reference Documents:
- Law No. 6698 on the Protection of Personal Data,
- Regulation on the Deletion, Destruction or Anonymization of Personal Data.
- Explicit Consent Declaration Form
- Related Documents
- Personal Data Protection and Processing Policy
- Explicit Consent Declaration Form
We always strive to protect the employment rights of our employees. We treat employees honestly and fairly and strive to provide a non-discriminatory, safe and healthy working environment. We make the necessary efforts for the individual development of our employees and take into consideration the balance between professional and private life.
Our Responsibilities
We take care to fulfill our legal responsibilities.
Integrity
Accuracy and integrity are our primary values in our business processes and relationships.
Our Responsibilities Towards Our Competitors
We compete only in areas that are legal and ethical.
Our Principles
- Ensuring quality, accuracy and consistency in service.
- Creating lasting advantages by creating differentiation.
- Achieving balanced and profitable growth.
- Our customers are our most valuable asset.
- Our most important capital is our human resources.
- Making business ethics and integrity our indispensable principles is among our foremost principles.
CLOUDY BİLİŞİM, in accordance with the Information Security Management System Standard;
Commits to ensuring secure access to the information assets of itself and its stakeholders,
Protecting the availability, integrity and confidentiality of information,
Assessing and managing risks that may arise on its own and its stakeholders’ information assets,
Protecting the reliability and brand image of the organization,
Applying the necessary sanctions in case of an information security breach,
Fulfilling the requirements of national, international or sectoral regulations, relevant legislation and standards to which it is subject, meeting its obligations arising from agreements, and providing information security requirements arising from corporate responsibilities towards internal and external stakeholders,
Reducing the impact of information security threats on business/service continuity and ensuring business continuity and sustainability,
Maintaining and improving the information security level through the established control infrastructure,
Providing training to improve competencies in order to increase information security awareness.
CLOUDY BİLİŞİM keeps itself continuously prepared against situations that may develop beyond its control and cause interruptions due to various factors while carrying out its activities, and maintains related efforts through the Business Continuity Management System it has established.
In the event of any unexpected incident, the safety and health of employees and visitors are the first priority. Once the health and safety of employees have been ensured, efforts continue to restart critical operations.
It is known from examples experienced around the world and in our country that serious damage may occur due to situations that may cause interruptions if business continuity activities are not carried out.
Our business continuity policy:
– Preventing interruptions in order to protect services from threats such as environmental causes, hardware failures, operational errors, malicious code attacks and natural disasters,
– Keeping the impact on services at the lowest possible level,
– Identifying incidents as quickly as possible in order to reduce recovery efforts and maintain service quality,
– Responding rapidly to prevent a minor incident from escalating to more serious levels,
– Carrying out recovery based on recovery priorities and restoring the most critical services first in order to ensure services are restarted on time and data integrity is maintained,
– Analyzing and reviewing lessons learned from incidents and continuously improving in order to be better prepared for incidents and interruptions.
BUSINESS CONTINUITY SCOPE
SCOPE: Pre-Accounting Program, Sales Management, Purchase Management, Inventory & Warehouse Management, Current Account Management, Finance Management and Fixed Asset Management, Marketplace Module, E-Reconciliation Module, Sign & Send Module, Human Resources Module, Virtual POS Transactions Module, Cash Register Module.
Internal Scope:
– Management, organizational structure, roles and responsibilities,
– Policies, objectives and strategies to be fulfilled,
– Capabilities understood in terms of resources and knowledge (e.g. capital, time, people, processes, systems and technologies),
– Relationships with internal stakeholders and their perceptions and values,
– The organization’s culture,
– Information systems, information flow and decision-making processes (formal and informal),
– Standards, guidelines and models adopted by the organization,
– The form and scope of contractual relationships.
External Scope:
- Social and cultural, political, legal, regulatory, financial, technological, economic, natural and competitive environment at international, national, regional or local levels; key drivers and trends affecting the organization’s objectives; and relationships with external stakeholders and their perceptions and values.
