Our policy and KVKK compliance framework
Personal Data Protection
Last updated: 22.06.2026
Protecting personal data is among our most fundamental obligations as an offensive-security partner. This page summarizes the policy framework, principles and information-security approach we apply as GCS SİBER GÜVENLİK TEKNOLOJİLERİ VE DANIŞMANLIK HİZMETLERİ LİMİTED ŞİRKETİ within the framework of Law No. 6698 on the Protection of Personal Data (KVKK).
Our approach
We provide offensive-security services; the heart of this service is validating how the data of our customers and their customers truly comes under risk in the real world. We apply the same discipline to our own data-processing operations.
We process personal data only for specific, explicit and legitimate purposes, and only to the extent necessary. There is a legal basis for every piece of data we collect; we fulfill our disclosure obligation every time.
We offer a fast, clear and frictionless channel for data subjects to exercise their rights. A separate application page has been set up for this purpose.
Our commitment to the KVKK principles
In accordance with Article 4 of the KVKK, we adhere to the following principles in processing personal data.
- Lawfulness and fairness: We clarify the legal basis and the fairness test of every processing activity in advance.
- Accuracy and, where necessary, currency: We keep data accurate and update it when needed.
- Processing for specific, explicit and legitimate purposes: We define purposes in advance and share them clearly in texts and processes.
- Relevant, limited and proportionate to the processing purpose: We take the minimum data required for the purpose.
- Retention only for the period stipulated by law or required by the purpose: We define retention periods by business process and legislation; data whose period has expired is deleted, destroyed or anonymized.
Our information-security approach
Pursuant to Article 12 of the KVKK, we take appropriate technical and administrative measures to prevent the unlawful processing of and access to personal data, and to ensure its safekeeping.
We apply the discipline we develop on the offensive-security side to our own internal processes. The following measures form the core of this approach.
- Access management: access to personal data is granted on a role-limited, least-privilege basis and reviewed regularly.
- Authentication: multi-factor authentication (MFA) is mandatory on critical systems.
- Encryption: communication containing personal data is encrypted with TLS; sensitive data is kept encrypted at rest.
- Logging and monitoring: access and transaction logs are kept and reviewed regularly with observability tools.
- Security-testing discipline: critical flows, including our own systems, are validated at regular intervals; findings are closed with a fix-first work list.
- Training and awareness: personal-data protection and security awareness for our staff is updated regularly.
- Incident response: in the event of a suspected data-security breach, the internal response flow is triggered; notification obligations required by the KVKK are fulfilled.
Our information-security measures also pass external validations; our standard certifications are documented by [Certification list - to be completed].
Our responsibility model
In some processes we act as data controller, in others as data processor; this distinction depends on which personal data is processed, for what reason and on whose account.
- In our own processes - such as our website, the discovery call, the expert-network application and the customer contract process - we act as data controller.
- Within the offensive-security services we provide to our customers, where we process the customer's data on its account under the contract, we act as data processor. In these processes we follow the customer's written instructions; confidentiality and security obligations are governed by contract.
In processes where we act as data processor, the disclosure obligation and data-subject applications are handled by our customer, who is the data controller; we fulfill our obligations under the contract.
Policy updates
This policy is reviewed and updated in line with legislative changes, Board decisions or changes in our internal processes. Significant changes are noted at the top of the current version; previous versions are kept in the archive.
This text was last updated on 22.06.2026.
The text is updated in line with legislative changes and Board decisions.
For questions about the policy, you can reach us via the contact page.