01.Our Policy
Güncel Yazılım adopts the lawful processing and protection of personal data as a fundamental principle. As a data controller, we operate a management system aligned with the principles of the KVKK and the GDPR across all of our processes.
02.Compliance Framework
Our KVK Compliance Management System comprises the following components:
- Governance: KVKK committee, data protection officer (DPO) and regular audits
- Risk Analysis: Risk-based assessment of personal data processing activities
- VERBİS Compliance: Timely and accurate registration with the Data Controllers Registry Information System
- Technical Measures: Encryption, access controls, logging and backups
- Administrative Measures: Employee training, confidentiality agreements and policies
- Breach Management: Notification and response procedures in the event of a potential breach
03.Retention & Destruction Policy
We retain personal data only for as long as the purpose of processing requires, save for the periods mandated by the applicable legislation. When the purpose no longer applies or the retention period expires, we anonymise, delete or destroy the data through periodic destruction processes.
04.Employee Training
All of our employees receive KVKK awareness training when they start work and every year thereafter. In particular, role-based in-depth training is provided for the departments that process personal data (customer services, HR and finance).
05.Audit & Improvement
The KVK Compliance Management System is subject to internal and external independent audits. Findings are reported, corrective actions are planned and the system is continuously improved. Together with the Information Security Management System, it forms an integrated control framework.
