Data and Information Security Policy

Secure processing of personal and corporate records.

Last content review: 13.08.2026MYK YB-0306TÜRKAK AB-0403-P

Information security scope

Application, identity verification, examination, assessment, certification, document and communication records are treated as organisational information assets. Access is restricted according to role and authorisation.

Core controls

  • User- and role-based access controls.
  • Logging and traceability for forms and administrative actions.
  • File type, size and security controls for uploads.
  • Controlled access and retention for personal data and examination records.
  • Backup, error logging and incident-review processes.
  • Controls designed to reduce unauthorised changes, data loss and incorrect disclosure.

Visitor security

Public forms use secure validation controls; mandatory privacy information is separated from optional email and SMS permissions. Sensitive documents and examination results are not published openly.

Call Now WhatsApp