CORPORATE
CORPORATE
SinerjiBT Information Technologies Inc. may have access to the private access and connection information of its customers, as well as configuration and communication information of critical devices, during its operations. Ensuring the trust of the institutions and organizations we serve, and guaranteeing the security of this information and our own information assets, is our primary objective.
The continuity of the services we provide, the confidentiality of the information we hold, and the integrity of the information assets belonging to both our clients and our organization are of utmost importance.
To this end, we, as senior management, commit to the following:
- With the participation of our employees, we aim to establish, maintain, and continuously improve the effectiveness of the TS ISO/IEC 27001:2022 Information Security Management System and the ISO/IEC 27701:2019 Personal Data Management System.
- We are committed to treating corporate information, personnel records, and customer data as valuable and critical; and to protecting their confidentiality, integrity, and accessibility.
- To systematically identify and assess risks to our information assets, and to implement controls for risks exceeding acceptable levels.
- To process personal data in accordance with the Law No. 6698 on the Protection of Personal Data and related legislation, in a lawful, limited and proportionate manner; to protect the rights of the data subjects,
- Our organization is committed to fully fulfilling its obligations arising from its roles as data controller and data processor.
- To comply with all legal regulations, regulatory requirements, and contracts related to information security and the protection of personal data,
- To increase information security awareness, we will regularly conduct training sessions that will improve technical and behavioral competencies.
- To encourage the reporting of information security breaches and personal data breaches, to protect those who report them, and to address incidents in a timely manner.
- To provide the necessary infrastructure and take measures to ensure business continuity,
- To define and periodically monitor information security objectives within the framework of PL.04.01 Management Systems Objectives and Goals Plan,
- We will review this policy at least once a year to keep it up-to-date.
- To provide the necessary resources for the operation of the Integrated Management System,
We are committed to working with all our might to be a model organization in our sector in terms of information security and personal data protection.