3000 TL ve üzeri siparişlerde Kargo Ücretsiz!

Information Security Policy

INFORMATION SECURITY POLICY

At Hiber Bilisim, we consider the security of information belonging to our customers, visitors, business partners and employees an important part of our operations.

This Information Security Policy describes our general approach to protecting information processed or stored through websites, e-commerce systems, servers, software, communication infrastructure and other information systems operated by Hiber Bilisim.

Our information security practices take into account applicable legislation, including Türkiye's Personal Data Protection Law No. 6698 (KVKK), as well as appropriate and current information security practices.

1. CORE PRINCIPLES OF INFORMATION SECURITY

Our information security approach is based on three fundamental principles:

Confidentiality:
Information should be accessible only to authorized persons, systems and processes.

Integrity:
Appropriate controls are implemented to protect information against unauthorized alteration, deletion or corruption.

Availability:
Information and services should remain appropriately accessible to authorized users and systems when required.

2. SCOPE

This Policy applies, as appropriate, to information assets associated with:

- Websites and e-commerce platforms,
- Customer and user accounts,
- Orders and transaction records,
- Servers, databases and backup systems,
- APIs and integration services,
- Administration systems,
- Email and communication systems,
- Supplier and business partner integrations,
- Internal information systems.

3. PERSONAL DATA SECURITY

We aim to implement technical and organizational measures appropriate to the relevant risks in order to prevent unlawful processing of personal data, prevent unauthorized access and ensure the secure storage of personal data.

Information regarding the purposes and legal grounds for processing personal data, potential recipients and data subject rights is provided separately in the applicable Hiber Bilisim Privacy Notice and Personal Data Protection Notice.

4. TECHNICAL SECURITY MEASURES

Depending on the nature of the relevant systems and identified risks, appropriate technical safeguards may include:

- Encrypted communication protocols such as HTTPS/TLS,
- Access control systems,
- Authentication mechanisms,
- Authorization controls,
- Firewalls,
- Software and security updates,
- System and access logging,
- Backup systems,
- Network security,
- Protection against malicious software.

Access to critical systems is restricted according to operational requirements and authorization levels.

Security vulnerabilities identified in software, servers and other information systems are evaluated and appropriate updates or corrective measures are implemented where necessary.

5. ACCESS CONTROL AND AUTHORIZATION

Access to information systems is managed, where appropriate, according to the Principle of Least Privilege.

Users should have access only to systems and information necessary for their duties or authorized activities.

Access rights that are no longer required may be revoked or restricted.

6. PASSWORD AND ACCOUNT SECURITY

Appropriate password and authentication practices may be implemented to protect user accounts.

Users are encouraged to:

- Use strong and unique passwords,
- Never share passwords with third parties,
- Avoid reusing the same password across different online services,
- Promptly report suspicious account activity.

Hiber Bilisim employees or authorized representatives will not request users to disclose their account passwords via email, telephone or similar communication channels.

7. PAYMENT SECURITY

Online payment transactions may be processed through authorized payment service providers and/or banks depending on the selected payment method.

Security requirements applicable to payment card information are handled according to the infrastructure of the relevant payment service provider and applicable legal requirements.

Depending on the payment method, card information may be transmitted directly to the secure infrastructure of the relevant payment service provider.

8. BACKUP AND BUSINESS CONTINUITY

Backup measures appropriate to operational requirements and identified risks may be implemented for critical systems and information.

Technical and operational measures are developed where appropriate to support service continuity and data recovery in the event of hardware failures, software problems, cybersecurity incidents or other unexpected events.

9. LOGGING AND SECURITY MONITORING

System and access logs may be maintained where necessary for security, troubleshooting, prevention of misuse and compliance with legal obligations.

Access to these records is restricted according to authorization requirements.

Records may be retained for periods required by applicable law or necessary for the relevant processing purpose.

10. THIRD PARTIES AND SERVICE PROVIDERS

Hiber Bilisim may use third-party providers for services including hosting, shipping, payments, communications, infrastructure, cloud services and software.

Where sharing information or personal data with such parties is necessary, we aim to limit such sharing to the information required to provide the relevant service and to comply with applicable data protection requirements.

11. SECURITY INCIDENT MANAGEMENT

Where unauthorized access, data loss, malicious software, a system breach or another information security incident is identified, appropriate measures are taken to:

- Identify the incident,
- Contain the incident,
- Assess its impact,
- Remediate the incident,
- Evaluate measures designed to reduce the risk of recurrence.

Where a security incident affects personal data, notification and other obligations required under applicable legislation will be followed.

12. EMPLOYEES AND AUTHORIZED USERS

Employees and other authorized users with access to information systems are expected to comply with applicable information security requirements.

Customer information, commercial information and company information accessed in connection with their duties must not be disclosed to unauthorized persons and should be used only for authorized purposes.

13. RISK MANAGEMENT AND CONTINUOUS IMPROVEMENT

Information security is treated as an ongoing process rather than a one-time activity.

Security risks are reviewed as appropriate in light of new technologies, emerging security threats, infrastructure changes and regulatory developments, and security safeguards may be improved accordingly.

14. USER RESPONSIBILITIES

Users are responsible for taking reasonable precautions to protect their own devices and account credentials.

Users are encouraged not to share login credentials with third parties, to use trusted devices and network connections and to report suspicious activity as soon as possible.

15. CHANGES TO THIS POLICY

This Information Security Policy may be updated in response to changes in legislation, technology, company operations or information security practices.

The current version becomes effective when published on our website.

Hiber Bilisim
Last Updated: September 7, 2026

Hızlı Kargo Hafta içi saat 15:00 öncesinde oluşturduğunuz tüm siparişler aynı gün kargoya verilmektedir.
Güvenli Alışveriş Tüm bilgileriniz 256 Bit SSL sertifikasıyla korunmaktadır.
Uzman Teknik Servis Ürünleriniz için profesyonel bakım ve onarım.
Ücretsiz Kargo Belirli tutarın üzerindeki alışverişlerinizde kargo ücreti ödemezsiniz.

Bültenimize Abone Ol

Kampanya ve fırsatlardan ilk siz haberdar olun.

Kuruköprü Mah. Sefa Özler Cad. özden İşmerkezi kat 7/74 Seyhan / adana

Ödeme Yöntemleri

Visa Mastercard Banka Kartı World

©2017 - 2026 All rights reserved.