INFORMATION SECURITY POLICY REGARDING PERSONAL DATA

I. COMMITMENT TO KVKK AND ISMS CONFIDENTIALITY

This Personal Data Protection and Information Security Policy establishes the principles to be observed within and by Beysu Global Enerji Anonim Şirketi regarding the processing of Personal Data. It outlines the company’s obligations to protect Personal Data in accordance with relevant legislation—primarily the Personal Data Protection Law No. 6698—and the requirements of the ISO 27001 Information Security Management System (ISMS), ensuring compliance with international standards.

The Company commits to acting in accordance with the procedures implemented under its Personal Data Protection and Information Security Management System Policy.

II. PURPOSE OF THE POLICY

The primary purpose of this Policy is to establish the principles regarding the methods and processes—aligned with Information Security Management System requirements—that the Company follows for the processing and protection of Personal Data.

III. SCOPE OF THE POLICY

This Policy covers and applies to all activities related to the Personal Data processed by the Company and the Information Security Management System.

We ensure the highest level of protection for Personal Data and corporate information at all times by meeting the needs and expectations associated with Information Security objectives and goals.

We operate in compliance with international standards as well as all relevant laws, regulations, and legislation, particularly the Personal Data Protection Law No. 6698. We strive to ensure the continuous satisfaction of our employees, suppliers, business partners, the environment, and society through a balanced approach and collaboration, while diligently complying with the Personal Data Protection Law No. 6698 and other applicable legal requirements.

We maintain the highest level of information security—particularly regarding the protection of personal data—by meeting relevant needs and objectives.

We continuously improve our system by adhering to the requirements of the Information Security Management System and all processes affecting our success and quality, including applicable laws and regulations.

We communicate our Personal Data Protection and Information Security Policy to relevant internal and external parties to ensure they are fully informed.

This policy may be amended from time to time with the approval of the Board of Directors, as required by KVKK (Personal Data Protection Law) and ISMS (Information Security Management System) regulations, or when deemed necessary by the Clinic’s Data Controller Representative or the Committee. In the event of any inconsistency between the KVKK, ISMS, related regulations, and this Policy, the KVKK regulations shall prevail.

Shopping Basket