Information Security Policy

1) Information Security Policy

On matters within our field of activity as a company; It is of great importance to meet legal requirements, to provide service in a way that meets the needs and expectations of our customers, suppliers and third party interlocutors, to ensure access to services offered in a quality, fast and safe manner, and to ensure that our company's employees have timely, complete, accurate and uninterrupted access to information assets. The company has decided to establish an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001:2022 standard in order to protect the information of itself, its customers and 3rd Party interlocutors. The purpose of establishing an Information Security Management System is to protect information from all threats that may come from inside and/or outside, intentionally or accidentally, by evaluating it within the scope of confidentiality, integrity and accessibility, and to ensure that the activities carried out are carried out effectively, accurately, quickly and safely. Information security is a corporate responsibility and is in line with our corporate goals.Necessary roles have been defined, responsibilities have been determined and responsible people have been appointed for the healthy operation of information security processes. These responsibilities include all units that use the information technology infrastructure, users who access information systems as third parties, and suppliers who provide technical support to information systems. With the process of establishing the ISMS in our company, it is aimed to identify and evaluate possible risks in all areas within the scope, reduce them to an acceptable level by matching them with standard-compliant controls, and keep the ISMS alive within the organization by applying the risk assessment procedure.

2) Quality Policy

On matters within our field of activity as a company; Meeting legal requirements, providing services in a way that meets the needs and expectations of our customers, suppliers and third party interlocutors, ensuring access to quality, fast and safe services, and customer satisfaction are of great importance.    Quality Management System is a corporate responsibility and is in line with our corporate goals; In the products and services we provide; Our primary goals are to keep customer satisfaction at the highest level, to increase effectiveness and efficiency, to manage resources efficiently, to effectively manage customer feedback and to continuously improve. Necessary roles have been defined, responsibilities have been determined and responsible people have been appointed for the healthy operation of the processes of the quality management system. 

3) Information Technologies Service Management Policy

To ensure that the services offered on the subjects within our field of activity as a company are carried out in accordance with the ISO 20000-1 Information Technology Service Management standard, to constantly increase the effectiveness of the Service Management System and services, to ensure the IT service infrastructure and continuity regarding all transactions carried out through the electronic applications offered by the Institution, to ensure the satisfaction of the users and stakeholders to whom IT services are provided,  understanding and prioritizing customer needs and ensuring harmony between the departments providing the service in order to meet these needs correctly,To implement the necessary measures to create, develop and ensure the effectiveness of a structure in accordance with the requirements of information technologies service management. It is committed to meeting the requirements of the ISO 20000 standard and continuously improving all IT processes by effectively managing risks and opportunities, meeting legal requirements.

4) Business Continuity Management Policy

To ensure that the services offered as a company in our field of activity are carried out in accordance with the ISO 22301 Business Continuity Management System standard, In events beyond its control such as a disaster or any emergency; By keeping business continuity plans constantly ready and improving, first of all, ensuring life safety, and then ensuring that all services and activities provided are not affected or are affected as little as foreseen within the framework of previous studies, To ensure that our plans work in emergency situations, carrying out exercises by taking into account our legal obligations, policies and customer expectations, ensuring that analyzes are carried out to identify possible risks that may cause service interruptions and taking precautions against these risks, Managing internal and external communication on Business Continuity issues, Suppliers, customers, shareholders, employees, legal authorities, To fulfill their requirements, we prepare our business continuity plans by taking into account our customers' expectations, corporate policies and legal obligations, 

5) Personal Data Protection Policy

The main purpose of this Policy is to make statements about the personal data processing activities carried out by the Company in accordance with the law and the systems adopted for the protection of personal data, and in this context, to ensure transparency by informing the persons whose personal data are processed by our company, especially our customers, potential customers, employees, prospective employees, company officials, visitors, employees and officials of the institutions we cooperate with and third parties. For personal data processed by the company: It undertakes to ensure that it is carried out in accordance with the ISO 27701 Personal Data management system standard, to meet legal requirements and to continuously improve personal data by managing the relevant risks.

6) Customer Satisfaction Policy

The company follows a customer-oriented approach, where customers can easily convey their demands and dissatisfaction, where these are handled objectively, fairly, carefully and confidentially, where they are evaluated in a way that does not contradict legal conditions and our company policy, where necessary improvements and controls are constantly made to prevent the same dissatisfaction from occurring again, where it is based on transparency in its relations with customers, and accepts the resolution of all customer dissatisfaction as the main principle. Our customer satisfaction rules: We first accept our customers as "Rightful" and examine the reason for their complaint from this perspective. We investigate every issue submitted to us and have the chance to improve ourselves. We foster an understanding in line with our customers' expectations of quality service from us. We want to create a strong, accurate, clear and ongoing customer relationship after the products and services our organization offers to customers.

7) Complaint Policy

No fee is charged from the customer for the evaluation of complaints, and no profit is made in any way. Company employees take into account objectivity criteria in the resolution process: The complaint procedure is clear and accessible to customers. Complaints are handled fairly and without prejudice.  Integrity is taken into account in revealing the facts regarding the subject of the complaint, and all parties are taken into consideration. Complaining customer information is confidential. Information is not shared with third party organizations and individuals outside the Company unless necessary to resolve the complaint. 

In this context, our company undertakes to fulfill the requirements of the Integrated Management System standards, to meet the legal requirements, to activate all applicable controls, and to continuously improve the established Integrated Management System at regular intervals every year with new application areas and developing technology.

8) Privacy Policy

As ehealth.com.tr, we respect your personal privacy rights and strive to ensure this during the time you spend on our site. Explanations regarding the security of your personal information are explained below and presented to your information.

9) Scope of the Privacy Policy
ehealth.com.tr site requests some personal information from you during and after the membership phase. The information you provide will not be used in any context other than the rules and purposes specified in the membership and site agreement and will not be shared with third parties and institutions. However, it reserves the right to share your personal information upon request by official authorities responsible for public security.

Your registered personal information cannot be sold, rented or exchanged with any other institution or organization. The information collected by the site is stored in a secure environment that is not available to the general public. ehealth.com.tr takes every precaution to protect the information in the environment. However, it does not provide a guarantee on security-related issues.

You have the right to update and change the personal information you entered during registration at any time. If you do not comply with the privacy policy and site agreement, the site is authorized to delete or suspend your membership.

Due to the structure of the Internet, information can circulate on the Internet without taking adequate security measures and can be received and used by unauthorized persons. This use and any damages arising from it do not belong to ehealth.com.tr.

The site cares about the security of cardholders who pay by debit or credit card and does not store credit card information in the system in any way. It is used only for provisioning by being transmitted securely to the relevant banks during the collection process, and is deleted from the system after the provisioning. On ehealth.com.tr, your personal information is 100% secure with the latest software and techniques offered by internet technology. All information on our site is encrypted and protected with SSL (Secure Sockets Layer) encryption technique. In this way, your information is prevented from being seized by unwanted persons and institutions.

ehealth.com.tr records and uses the IP address of its members in order to identify system-related problems and quickly resolve any problems or disputes that may arise regarding the service provided. IP addresses may be used to generally identify users and gather broad demographic information.

10)External Links
The application may provide links to other sites within the website. The site does not bear any responsibility for the privacy practices and content of the sites accessed through these links. The confidentiality agreement and membership agreement of the relevant sites are valid for the use of other websites that can be accessed via links from this website. The linking process mentioned here is legally considered "referencing".

11) Ads
We publish advertisements of external companies on our site (Google, Private Companies, etc.). These advertisements may contain cookies and cookie information may be collected by these companies and it is not possible for us to access this information.

12) Information Update and Change
ehealth.com.tr may change the content of this Privacy Policy at any time in order to keep its privacy and data protection principles up to date and to comply with the relevant legislation. The changed Privacy Policy will be announced on the ehealth.com.tr website. You can always access the most up-to-date version of the Privacy Policy at https://ehealth.com.tr/gizliği-sozlesmesi/. If you continue to use ehealth.com.tr services and/or applications after this Privacy Policy has been changed, it will be assumed that you accept the changes. The amended Privacy Policy provisions of ehealth.com.tr come into force on the date they are published on the website.

13) Cookies
Cookies; We use it to facilitate the use of ehealth.com.tr and to better customize ehealth.com.tr and our consultancy and other services in line with your interests and needs. Cookies may also be used to speed up your future activities and experiences on our site. We also use cookies to help us compile anonymous and aggregated statistical data that allows us to understand how people use our site and to help us improve the structure and content of our site. This data is not information that can enable us to identify you.

The site undertakes to keep confidential information strictly private and confidential, to consider this as a confidentiality obligation, and to take all necessary precautions and exercise due care to ensure and maintain confidentiality, to prevent all or any part of the confidential information from entering the public domain or unauthorized use or disclosure to a third party.

By using this service or visiting the website, each member will be deemed to have accepted the terms and conditions of this privacy policy.