Personal Data Protection Compliance

Güncel Yazılım has established the KVK Compliance Management System to ensure full compliance with Law No. 6698 on the Protection of Personal Data and the related legislation.

This English text is a courtesy translation provided for information only; the legally binding version is the Turkish original.
Last updated: 1 March 2026

01.Our Policy

Güncel Yazılım adopts the lawful processing and protection of personal data as a fundamental principle. As a data controller, we operate a management system aligned with the principles of the KVKK and the GDPR across all of our processes.

02.Compliance Framework

Our KVK Compliance Management System comprises the following components:

  • Governance: KVKK committee, data protection officer (DPO) and regular audits
  • Risk Analysis: Risk-based assessment of personal data processing activities
  • VERBİS Compliance: Timely and accurate registration with the Data Controllers Registry Information System
  • Technical Measures: Encryption, access controls, logging and backups
  • Administrative Measures: Employee training, confidentiality agreements and policies
  • Breach Management: Notification and response procedures in the event of a potential breach

03.Retention & Destruction Policy

We retain personal data only for as long as the purpose of processing requires, save for the periods mandated by the applicable legislation. When the purpose no longer applies or the retention period expires, we anonymise, delete or destroy the data through periodic destruction processes.

04.Employee Training

All of our employees receive KVKK awareness training when they start work and every year thereafter. In particular, role-based in-depth training is provided for the departments that process personal data (customer services, HR and finance).

05.Audit & Improvement

The KVK Compliance Management System is subject to internal and external independent audits. Findings are reported, corrective actions are planned and the system is continuously improved. Together with the Information Security Management System, it forms an integrated control framework.

Questions?

For questions about the items in this document, you can contact our KVKK and compliance team.