Menu
MECHSOFT

Personal Data Protection Policy

We are committed to protecting personal data through responsible, secure, and transparent data management practices that respect fundamental rights and freedoms and comply with applicable data protection laws and regulations.

At MECHSOFT, our approach is built on the following commitments:

  1. We collect and process personal data in accordance with applicable data protection laws in Türkiye and the European Union, with a strong commitment to safeguarding individuals’ fundamental rights and freedoms, particularly the right to privacy.

  2. Our policy applies to all personal data processing activities across our organization. This includes the processing of personal data and sensitive personal data relating to employees, job applicants, customers, suppliers, and other relevant individuals, as well as personal data collected and processed from any applicable source.

  3. We implement appropriate technical and organizational measures to prevent the unlawful processing of personal data and to ensure its secure storage and protection. We also conduct and commission regular reviews and audits to verify the effectiveness of these safeguards and maintain an appropriate level of data security.

  4. We process personal data lawfully, fairly, and transparently, ensuring that it is accurate and kept up to date where necessary. Personal data is collected and processed only for specified, explicit, and legitimate purposes and is limited to what is relevant, necessary, and proportionate to those purposes.

  5. We retain personal data only for as long as required by applicable laws and regulations or as necessary to fulfill the purposes for which the data was collected and processed.

  6. We provide individuals with clear and transparent information about how their personal data is processed and respond appropriately to requests for information regarding their personal data and related rights.

  7. We process sensitive personal data in accordance with applicable data protection requirements and do not carry out such processing without explicit consent unless otherwise expressly permitted or required by applicable law.

  8. We transfer personal data only in accordance with applicable data protection laws and regulatory requirements, ensuring that appropriate safeguards are applied throughout the transfer process.

  9. Awareness of personal data protection is promoted across relevant internal and external stakeholders, with clear communication of their respective responsibilities and obligations.

  10. Regular training programs support the development of technical and behavioral competencies while strengthening awareness of personal data protection across the organization.

  11. Personal data breaches are managed in accordance with established disciplinary procedures. Any breach or violation requiring disciplinary or legal action is promptly assessed and reported to the appropriate authorities and responsible governing bodies.

  12. Process-based asset inventories and risk assessments are used to continuously monitor the confidentiality and integrity of personal data, maintain data accuracy, and ensure that access rights remain appropriate and up to date.

  13. MechSoft is committed to the effective implementation and systematic management of its Personal Data Protection Management System, ensuring its continuous improvement and allocating the resources necessary to maintain and enhance its effectiveness.

These principles are adopted as the policies of our Personal Data Protection Management System