Last updated: 2 September 2026
1. Scope
This policy explains the privacy principles applied to the website at www.ongsec.com and to ONGSEC client projects. For detailed information on the processing of personal data, please see the Personal Data Notice.
2. Data collection on the website
Our site uses no third-party advertising or profiling technology that tracks visitor behaviour. In particular:
- Fonts are self-hosted; no request is made to an external font service.
- No third-party advertising network, social media tracking pixel or cross-site tracking cookie is used.
- The web server keeps standard access logs (IP address, timestamp, requested path, browser information) for security and troubleshooting. These logs are not used for marketing.
3. Confidentiality in client projects
Confidentiality is not a marketing promise for us; it is a contractual commitment:
- Client names, project scope and technical data are never shared in any medium without written consent. This applies to our marketing material and to this website.
- Projects are carried out under a non-disclosure agreement; project data is processed in a segregated environment.
- The project team accesses only the information it needs (need-to-know principle).
- Penetration test and audit data is securely destroyed at the end of the project by an agreed method.
- Subcontractor use is disclosed transparently and is subject to client approval.
4. Information security measures
Within the scope of its ISO/IEC 27001 Information Security Management System, ONGSEC applies administrative and technical measures:
- Access authorisation, multi-factor authentication and regular entitlement review
- Encryption in transit and at rest
- Backup, restore testing and incident response procedures
- Regular information security and confidentiality training for personnel
- Supplier security assessment
5. Linked sites
Our site may link to third-party sites. ONGSEC is not responsible for the content or privacy practices of those sites.
6. Vulnerability disclosure
If you believe you have found a security vulnerability in our systems, we ask that you report it to info@ongsec.com before disclosing it publicly. Good-faith reports receive a response within the same business day.
7. Changes
This policy is updated as necessary. The current version is always published on this page and the date above is updated accordingly.
This text has been drafted on the basis of ONGSEC’s actual data processing activities. Before publication it should be reviewed by your legal counsel and completed with the company’s registered trade name, MERSİS number and VERBİS registration details. In the event of any discrepancy, the Turkish version prevails.