1. Statement of commitment
Calculativa Yazılım ve Veri Analitiği Limited Şirketi develops and operates software that holds commercially sensitive and, in many cases, personal data. We treat the confidentiality, integrity and availability of that data as a contractual obligation rather than a best-effort aspiration.
This is a public summary. Our full information security management framework, risk register and control matrix are confidential documents made available to clients, auditors and prospective counterparties under a non-disclosure agreement.
2. Scope
This policy applies to:
- all employees, contractors and third parties acting on our behalf;
- all systems we develop, host, operate or administer for clients;
- all corporate systems and endpoints used to deliver our services;
- all data processed in the course of an engagement, in any format or location.
3. Governance
Accountability for information security rests with the board, which appoints a responsible officer for security and data protection. The framework, the risk register and this policy are reviewed at least annually and whenever a material change occurs in our services, systems or regulatory obligations.
4. Access control
- Least privilege. Access is granted only to what a role demonstrably requires, and is revoked when the requirement ends.
- Named accounts. Shared credentials are prohibited. Every action is attributable to an individual.
- Multi-factor authentication is mandatory on all administrative and remote-access paths.
- Client environments are segregated. Access to a client system is limited to the named team assigned to that engagement.
- Periodic review. Access rights are re-certified on a scheduled basis, and immediately on any role change or departure.
5. Data protection
- Data is encrypted in transit using current TLS, and at rest on all systems under our control.
- Production data is not copied into development or test environments. Where realistic test data is required, it is anonymised or synthetic.
- Retention follows a documented schedule; data is deleted or returned at the end of an engagement in line with the service agreement.
- Personal data is handled in accordance with our Privacy Policy, the Turkish Personal Data Protection Law (KVKK, No. 6698), and the EU General Data Protection Regulation where applicable.
6. Secure development
- Changes pass through version control, peer review and a defined release process. Direct changes to production are not permitted.
- Dependencies are monitored for known vulnerabilities and patched on a risk-prioritised schedule.
- Environments are separated: development, staging and production are distinct, with independent credentials.
- Secrets are held in a managed secret store, never in source code or configuration files committed to a repository.
7. Infrastructure and availability
- Systems are monitored continuously for availability, error rates and anomalous activity.
- Backups are taken on a defined schedule and restoration is tested — an untested backup is treated as no backup.
- Recovery objectives (RTO and RPO) are agreed per engagement and stated in the service agreement rather than assumed.
- Infrastructure changes follow a change-management process with documented rollback.
8. Personnel security
All personnel are bound by written confidentiality obligations that survive the end of their engagement. Security and data protection training is delivered on joining and repeated periodically. Access is provisioned only after onboarding is complete and revoked on the day a role ends.
9. Third parties and subprocessors
Suppliers with access to client systems or data are assessed before engagement and bound by written contractual terms covering confidentiality, security and data protection. A current list of subprocessors is available to clients on request.
10. Incident response
We maintain a documented incident response procedure covering detection, containment, eradication, recovery and post-incident review. In the event of a security incident affecting a client:
- the affected client is notified without undue delay, with the facts known at the time;
- where personal data is involved, notification to the Turkish Personal Data Protection Authority and to affected data subjects is made within the periods required by law;
- a written post-incident report setting out root cause and remedial action is provided.
11. Reporting a vulnerability
If you believe you have found a security vulnerability in any Calculativa system or website, please report it to info@calculativa.com with enough detail to reproduce it. We will acknowledge your report, investigate, and keep you informed of the outcome. We ask that you do not publicly disclose the issue until it has been resolved, and that you avoid accessing or modifying data belonging to others while testing. We will not pursue action against researchers who report in good faith and follow this guidance.
12. Contact
Security questionnaires, due-diligence requests and questions about this policy should be addressed to info@calculativa.com, or by registered electronic mail (KEP) to calculativa@info.kep.tr.