Legal & trust
Information Security Policy
Our approach is based on confidentiality, integrity and availability, supported by risk-based access, incident and supplier management.
- Version
- 2026.09
- Last updated
- 6 September 2026
- Data controller
- Omega-Pro Proje Araştırma Geliştirme Ltd. Şti.
Purpose and scope
This policy covers staff, contractors, information systems, business records, personal data and providers that process information for Omega Depot.
Core principles
Access is limited by role and need to know, with periodic review.
Integrity is supported by change, logging and backup controls; availability by continuity and recovery planning.
Measures are proportionate to information classification and risk.
Operational controls
Applicable controls include identity and access management, secure software development, security updates, logging and monitoring, backup, malware and phishing awareness, physical security, supplier assessment and incident response.
Staff and supplier duties
People with access must follow confidentiality obligations, report suspicious events promptly and avoid unauthorised disclosure. Provider security and data-protection duties are contractually governed.
Incident management
Suspected access, loss, misdelivery or vulnerability is recorded; scope and impact are assessed; and required technical, organisational and regulatory notification steps are performed.
Continual improvement
The policy is reviewed in light of risk, business change, incidents, audits and law. Public security claims remain limited to controls that are implemented and verifiable.
Have a question or request?
Contact the data controller with a clear description of your subject and request.
[email protected]