In our field of activity, it is crucial to meet legal requirements, provide services that satisfy the needs and expectations of customers, suppliers, and third parties, ensure access to services that are delivered in a quality, fast, and secure manner, and allow our employees to access information assets in a timely, complete, accurate, and uninterrupted way. To protect information belonging to itself, its customers, and third parties, the Company has decided to establish an Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022. The purpose of establishing the ISMS is to protect information—within the scope of confidentiality, integrity, and availability—from any threats that may arise intentionally or accidentally from inside and/or outside, and to ensure that activities are carried out effectively, accurately, quickly, and securely. Information security is a corporate responsibility and aligns with our corporate goals. Necessary roles have been defined, responsibilities assigned, and responsible persons appointed to ensure the proper operation of information security processes. These responsibilities cover all units using IT infrastructure, third-party users accessing information systems, and suppliers providing technical support. During the ISMS establishment process, potential risks within the scope are identified and evaluated, matched with standard-compliant controls, and reduced to acceptable levels; the ISMS is kept alive within the organization through the application of the risk assessment procedure.
In our field of activity, meeting legal requirements, providing services that satisfy the needs and expectations of customers, suppliers, and third parties, ensuring access to high-quality, fast, and secure services, and achieving customer satisfaction are of great importance. The Quality Management System is a corporate responsibility and aligned with our corporate goals. Our primary objectives in delivering products and services are to maximize customer satisfaction, increase effectiveness and efficiency, manage resources efficiently, handle customer feedback effectively, and continuously improve. Necessary roles have been defined, responsibilities assigned, and responsible persons appointed to ensure the effective operation of the quality management system processes.
In our field of activity, we commit to ensuring that services are delivered in accordance with ISO 20000-1 IT Service Management standards; continuously improving the effectiveness of the Service Management System and services; ensuring the continuity of IT service infrastructure for all transactions carried out via the institution’s electronic applications; ensuring satisfaction of users and stakeholders receiving IT services; prioritizing customer needs and ensuring alignment among service-providing units to meet those needs correctly; establishing and improving a structure in line with IT service management requirements; implementing necessary measures; meeting legal requirements; managing risks and opportunities effectively; fulfilling ISO 20000 requirements; and continuously improving all IT processes.
In our field of activity, we commit to conducting services in accordance with ISO 22301 Business Continuity Management System standards; ensuring life safety first in events beyond our control such as disasters or emergencies by keeping and improving business continuity plans; then minimizing or preventing impacts on all services and activities; carrying out drills to ensure plans function in emergencies by considering legal obligations, policies, and customer expectations; performing analyses to identify risks that may cause service interruptions and taking measures; managing internal and external communication on business continuity; meeting the requirements of suppliers, customers, stakeholders, employees, and legal authorities; and preparing business continuity plans in line with customer expectations, institutional policies, and legal obligations.
The main purpose of this Policy is to provide explanations about lawful personal data processing activities and the systems adopted for personal data protection, and to ensure transparency by informing individuals whose personal data are processed by our Company, including customers, potential customers, employees, employee candidates, company officials, visitors, employees and officials of partner organizations, and third parties. For personal data processed by the Company, we commit to operating in accordance with ISO 27701 Personal Data Management System standards, meeting legal requirements, and continuously improving by managing related risks.
The Company follows a customer-focused approach where customers can easily submit requests and complaints; these are handled objectively, fairly, carefully, and confidentially; evaluated in compliance with legal requirements and company policies; and continuously improved to prevent recurrence. The Company adopts transparency in customer relations and accepts resolving all customer complaints as a core principle.
Our customer satisfaction rules:
No fee is charged from the customer for the evaluation of complaints, and no profit is gained. Company employees observe objectivity criteria during the resolution process: the complaint procedure is open and accessible to customers. Complaints are handled without prejudice and fairly. Integrity is maintained in uncovering facts related to the complaint; all involved parties are considered. Customer information in complaints is confidential and is not shared with third-party organizations or individuals outside the Company unless required for resolution.
In this context, our company commits to fulfilling the requirements of Integrated Management System standards, meeting legal requirements, activating all applicable controls, and continuously improving the established Integrated Management System annually with new application areas and evolving technology.
We conduct preventive efforts to eliminate or reduce hazards that may cause occupational accidents and diseases, and ensure participation of employees and stakeholders. The health and safety of our employees, business partners, customers, and visitors—our most fundamental value—are our highest priority in all areas we operate.
Accordingly, as part of our responsibility to create healthy individuals and a healthy workforce;
Our organization conducts its activities with environmental sensitivity as a principle. For this purpose, it commits to the following fundamental elements.

