Last Updated: 24 July 2026 | Version: 1.0
This Data Security Policy describes the technical and administrative measures applied by Bimetrik Teknoloji Yazılım ve Danışmanlık Anonim Şirketi (“Bimetrik”, “Company”) to ensure the security of the personal and commercial data it processes. This document is for informational purposes; it does not require signature/approval. It is compliant with Article 12 of the KVKK and applicable legislation.
1. Purpose and Scope
This policy aims to protect the confidentiality, integrity and availability of data processed across all services, including the website, the SaaS application at https://app.bimetrik.com, mobile applications and the browser extension.
2. Responsibility
The Company is responsible for ensuring data security. All employees and service providers are responsible for the security and confidentiality of the data they access within the scope of their duties.
3. Technical Measures
- Encryption: Data is protected with SSL/TLS during transmission and with appropriate encryption methods at rest; passwords are stored irreversibly hashed.
- Access control: Role-based access control (RBAC) and the “least privilege” principle are applied; access is logged.
- Network security: Firewalls, network segmentation and abuse/intrusion prevention measures are used.
- Logging and monitoring: System and access logs are kept and security events are monitored.
- Backup: Data is backed up regularly and restore processes are tested.
- Environment separation and updates: Production and non-production environments are separated; software and dependencies are kept up to date and security patches are applied.
4. Administrative and Organizational Measures
- Confidentiality obligations and data protection awareness practices for employees,
- Authorization matrix and controlled management of access requests,
- Signing of Data Processing Agreements (DPA) and, where necessary, Standard Contractual Clauses (SCC) with service providers/sub-processors,
- Principle of processing limited by purpose and duration.
5. Authentication and Access Management
For account security, strong password requirements and two-factor authentication (2FA) are supported. Access permissions are reviewed periodically; access is removed in a timely manner for departing personnel and terminated service relationships.
6. Artificial Intelligence and Third-Party Security
In AI-powered features, no personal data is shared with cloud-based artificial intelligence technologies; data is anonymized/masked prior to processing. Commercial data is protected by mutual agreements (DPA/SCC) and “no-training” commitments (data is not used for model training). Sub-processor categories are transparently published in our Sub-processor List.
7. Breach Management
If a data breach is detected, the incident is assessed, its impact is contained and the necessary corrective measures are taken. The breach is reported to the Personal Data Protection Authority as soon as possible and no later than 72 hours after becoming aware of it, and to the relevant data subjects where necessary.
8. Data Retention and Destruction
Data is retained only for the necessary period; at the end of the period it is deleted, destroyed or anonymized. Details are set out in our Data Retention and Destruction Policy.
9. Monitoring, Auditing and Review
The effectiveness of security measures is reviewed regularly; improvements deemed necessary are implemented. This policy may be updated in line with changes in legislation and technical requirements.
10. Contact