Datassist Trust Center
We protect your most sensitive and critical data as confidential and privileged at every level. Access our information security certifications, security controls and compliance documents here.
Compliance & Certifications
Audited and certified by independent organizations.
- ISO 27001:2022
- ISO 9001:2015
- ISO 14001:2015
- ISO 42001:2023
- ISO 22301:2019
- ISAE 3402 SOC
- KVKK/GDPR
Documents & Resources
Access our compliance documents
You can request all documents listed below.
- PDFISO 27001:2022 CertificateOn RequestRequest
- PDFISO 9001:2015 CertificateOn RequestRequest
- PDFISO 14001:2015 CertificateOn RequestRequest
- PDFISO 42001:2023 CertificateOn RequestRequest
- PDFISO 22301:2019 CertificateOn RequestRequest
- PDFInformation Security PolicyOn RequestRequest
- PDFKVKK Data Retention & Disposal PolicyOn RequestRequest
- PDFKVKK Data Processing & Protection PolicyOn RequestRequest
- PDFBusiness Continuity PlanOn RequestRequest
- PDFDisaster Recovery PlanOn RequestRequest
- PDFISAE 3402 SOC Audit ReportOn RequestRequest
- PDFPenetration Test ReportOn RequestRequest
Compliance & Certifications
Security validated by independent audits
Our security and quality standards are periodically audited and certified by accredited organizations.
- ISO 27001:2022Certified
Information Security Management System
International standard ensuring the confidentiality, integrity and availability of information assets.
- ISO 9001:2015Certified
Quality Management System
Management standard based on process quality and continuous improvement.
- ISO 14001:2015Certified
Environmental Management System
Standard covering the systematic management of environmental impact.
- ISO 42001:2023Certified
AI Management System
International standard ensuring that artificial intelligence technologies are managed in a secure, responsible and controlled manner.
- ISO 22301:2019Certified
Business Continuity Management System
Standard covering the assurance of business continuity and the strengthening of organizational resilience against potential disruptions.
- ISAE 3402 SOCAudited
Service Organization Controls
Independent assurance report on internal controls at service organizations.
- KVKK/GDPRCompliant
Personal Data Protection Compliance
Full compliance with legal regulations on the processing of personal data.
Security Posture
Multi-layered security architecture
We apply end-to-end controls at the infrastructure, application, organizational and process levels to protect your data. You can view the details of each category.
Data Privacy
Respect and transparency for your personal data
We protect personal data processed in payroll and human resources operations in full compliance with KVKK and GDPR regulations.
Data Residency
Your data is hosted in İstanbul and Ankara, within Türkiye, in secure data centers built to Tier 4 standards.
Legal Compliance
All obligations under Turkish Data Protection Law No. 6698 (KVKK) and the EU GDPR are met.
Transparency
The purpose, retention period and recipients of data are clearly stated through disclosure notices.
Confidentiality
Your sensitive and critical data is protected as confidential and privileged at every level with strict access controls.
Subprocessors
The subprocessors we rely on
The key subprocessors we use to deliver our services and their purposes are listed below.
| Provider | Purpose | Data Location |
|---|---|---|
| Hosting & Data Center | Application hosting and storage | Türkiye |
| Backup Infrastructure | Redundant data storage | Türkiye |
| Monitoring & Log Management | Security monitoring and logging | Türkiye |
| Email & Communication | Corporate communication | Türkiye / EU |
Frequently Asked Questions
What people ask
Where is my data stored?
Datassist's own servers are hosted in the KKB Anadolu Data Center in Ankara, while disaster recovery is provided from the Doruknet facility in İstanbul. The server infrastructure is wholly owned by Datassist, and our suppliers have no access to customer data.
Which certifications and reports do you hold?
We hold ISO 27001:2022, ISO 9001:2015, ISO 14001:2015, ISO 42001:2023 (AI Management System) and ISO 22301:2019 (Business Continuity Management System) certifications. We are also independently audited under ISAE 3402 SOC and conduct regular penetration tests.
How do you ensure KVKK and GDPR compliance?
The processing of personal data is fully compliant with Turkish Law No. 6698 (KVKK) and GDPR. Disclosure notices, data processing agreements and retention processes are managed within this framework.
How do you manage security vulnerabilities?
Penetration tests are conducted regularly by third parties, vulnerabilities are prioritized and remediated, and systems are updated regularly.
How can I report a security incident?
You can report security concerns to us at kvkk@datassist.com. They are assessed as quickly as possible under our incident response procedures.
How can I access compliance documents?
You can create a request by selecting the relevant document in the Documents section. Some documents may require a non-disclosure agreement (NDA).
