
Penetration test. Periodically, penetration tests are performed on servers in the Codeway
system. The security gaps created as a result of this test are closed and a verification test is
performed to show that the relevant security gaps have been closed. Besides, Information
Security Threat and Event Management System automatically performs penetration tests.
Test results are recorded.
Information Security Management System (ISMS). At the ISMS meetings made within
Codeway, the topics contained in the control forum are audited monthly by the director of
information technology and the director of financial operations.
Training. In order to increase the awareness of Codeway employees against various
information security violations and to minimize the impact of the human factor in information
violation incidents, trainings are provided to employees at regular intervals.
Physical data security. It ensures that personal data on papers is necessarily stored in
lockers and accessed only by authorized persons. Adequate security measures (for
situations such as electric leakage, fire, deluge, thievery etc.) are taken based on the nature
of the environment where sensitive data is stored.
Backup. Codeway periodically backs up the data it stores. As a backup mechanism, it uses
the backup facilities provided by the cloud infrastructure providers, as well as the backup
solutions it develops when deemed necessary, provided that it is in compliance with relevant
legislation and provisions of this Policy.
Non-disclosure agreement. Non-disclosure agreements are concluded with employees
taking part in sensitive personal data processing.
Transfer of sensitive personal data. If transfer of sensitive personal data is required
through email; such transfer is done through (i) encrypted corporate email or (ii) Registered
E-mail.
In the event that the personal data is damaged as a result of attacks on ASK AI or on the
Codeway system, despite Codeway taking the necessary information security measures, or
the personal data is obtained by unauthorized third parties, Codeway notifies this situation to
Users immediately and, if necessary, to relevant data protection authority and takes
necessary measures.
4. Transferring Personal Data to Third Parties
The procedures and principles to be applied for transferring of personal data are regulated in
articles 8 and 9 of the PDP Law, and the personal and special categories of data of the
supplier may be transferred to third parties within the country or abroad since we may use
servers and cloud systems located abroad.
Your personal data may be transferred abroad for the following reasons:
● Conducting storage and archive activities
● Conducting business activities
● Conducting after-sales support services for goods/services
● Managing customer relationship management processes
Codeway may also transfer your personal data to services providers of our Company, third
parties such as Facebook SDK, Adjust and Firebase Analytics which are embedded into our
service for the following purposes: