Information Security Policy
INFORMATION SECURITY POLICY
As MERTAŞ Endüstriyel Temsilcilik ve Dış Tic. Ltd. Şti., we regard the protection of the confidentiality, integrity, and accessibility of information belonging to our customers, business partners, and employees as a fundamental obligation.
1. Scope
This policy covers all of MERTAŞ’s digital and physical information assets, customer and project data, consultancy documents, and information shared with third parties.
2. Confidentiality
Customer and business-partner information is processed only by authorized personnel for designated purposes. Project files and consultancy reports are not shared without written approval. BESS project information, financing structures, and customer investment plans are regarded as particularly sensitive data.
3. Access Control
Access to information systems is restricted according to job level. Passwords are renewed at regular intervals. Visitor and third-party access is logged.
4. Data Integrity and Backup
Critical business data is backed up regularly. Preventive measures are taken against circumstances that could lead to data loss, and any breach is reported immediately.
5. Physical Security
Unauthorized access to the company office and archive areas is prevented. Sensitive documents are kept in locked cabinets.
6. Internet and Email Security
Company email is used for business purposes only. File attachments from unknown sources are carefully evaluated. Data transmitted via the website is protected using HTTPS.
7. Breach Management
When an information security breach is detected, the affected systems are isolated, Company management is notified, and reports are made to the relevant legal authorities where necessary.
8. Legal Compliance
This policy is applied in compliance with Law No. 6698 (KVKK), Law No. 5651, and all other applicable legal regulations.
9. Review of the Policy
This Information Security Policy is reviewed and updated at least once a year.
English
Türkçe