Information Security and Privacy Policy
As INVENTO Technology and Information Services Inc., our goal is to ensure the security of all forms of information assets, personal data, locations, and processes used in company operations, in accordance with the principles of confidentiality, integrity, availability, and personal data security.
To achieve this goal, we commit to:
- Fulfilling and exceeding the requirements set by laws, standards, and our procedures regarding information security and privacy.
- Managing the Information Security and Personal Data Management System in accordance with TS ISO/IEC 27001:2013, the Personal Data Protection Law No. 6698, related secondary regulations, and TS ISO/IEC 27701:2019.
- Establishing the necessary organizational structure, resources, and infrastructure to enable reporting of information security and privacy breaches and to take prompt actions.
- Controlling the storage, transmission, modification, access, and processing of information assets and personal data based on best practices and ensuring that internal process controls are established in accordance with the principle of segregation of duties.
- Communicating this Policy to all our employees and providing the necessary resources and training for its implementation.
- Conducting Internal Audits to ensure compliance with and continuous improvement of the Information Security and Personal Data Security Management System, and considering the results in Information Security and Personal Data Protection Committee and Management Review meetings.
- Taking into account the Information Security and Privacy performance of suppliers, contractors, and their subcontractors in their selection, and collaborating with them on ISMS (Information Security Management System) and PDMS (Personal Data Management System) matters.
- Cooperating constructively with official institutions, individuals, and relevant citizens on ISMS-related matters.
- Implementing the necessary sanctions in cases of security and privacy breaches.
We hereby accept and commit to these principles.
General Manager