Norm Makina accepts as one of its fundamental corporate responsibilities to protect the confidentiality, integrity, and accessibility of the information assets it holds within its activities, and to ensure the lawful processing and security of personal data. In this direction, Norm Makina adopts the following principles and commitments:
Information Security
We commit to protecting commercial, technical, financial, and operational information, as well as personal data of employees, customers, suppliers, and other stakeholders, against unauthorized access, loss, alteration, and disclosure.
Storage of Personal Data
We process personal data in accordance with the law and rules of good faith, for specific, explicit, and legitimate purposes, in a manner connected, limited, and proportionate to the purposes for which they are processed, and retains them for the periods prescribed by relevant legislation.
Risk Based Approach
We regularly assess information security risks; implements administrative, technical, and physical security measures to keep risks at an acceptable level, and continuously improves them.
Authorization
We apply access authorization, authority matrices, monitoring, and logging mechanisms for information systems, digital infrastructure, and record environments; we adopt the principle of access to information only on a needtoknow basis.
Awareness and Training
We make awareness and training activities regarding information security and the protection of personal data mandatory for all employees.
Precautionary Approach
We establish incident management and notification processes to detect information security or personal data violation risks in advance and mitigate their effects; we notify relevant individuals and authorities when required by law.
Supply Chain
We request and secure through contracts adequate assurance of information security and KVKK compliance from third parties and suppliers that process personal data.