Skip to content

Our policies

The written commitments that govern how we work. Four of them are the policies our certified management systems require, and they are independently audited every year.

Information Security Policy

This policy is subject to annual audit under ISO/IEC 27001. Certifications page

Eclit undertakes to protect its customers' information assets as it protects its own. Information security is not a compliance obligation for us but a direct part of the service: when a customer hands over their infrastructure, its confidentiality, integrity and availability become our responsibility.

Our information security management system is established and operated in line with ISO/IEC 27001. Risk assessment is repeated at regular intervals and on every significant change, and the controls we select are recorded together with the reasoning behind them.

Access rights are granted on the principle of segregation of duties. No individual holds the authority to erase a system's audit trail alone. Rights are bound to a role, reviewed regularly, and updated immediately when a role changes.

Security incidents are handled through a defined process: detection, containment, remediation and post-incident review. For any incident affecting a customer, notification is made within the period set out in the contract.

All employees receive information security training on joining and at regular intervals thereafter. Compliance with this policy forms part of the employment contract.

Service Management Policy

This policy is subject to annual audit under ISO/IEC 20000-1. Certifications page

Eclit delivers its managed services through a service management system aligned with ISO/IEC 20000-1. What we sell is not a product but an operating discipline, and that discipline has to be defined, measurable and auditable.

Service levels are set out in writing in each customer's contract. Incident, problem, change and capacity management run as separate processes; none substitutes for another.

No change is applied without approval. Every change has an owner, a rollback plan and an implementation window. Emergency changes are recorded the same way; only the order of approval differs.

We measure service performance periodically and share it with the customer. Where a target is missed, we report the cause and the action taken.

Business Continuity Policy

This policy is subject to annual audit under ISO 22301. Certifications page

Eclit undertakes to keep both its own operation and the services it provides to customers sustainable through disruption. Our business continuity management system is established in line with ISO 22301.

A business impact analysis is carried out for our critical processes, and a recovery time objective (RTO) and data loss tolerance (RPO) are set for each. These are kept consistent with the commitments in customer contracts.

Plans are not merely written; they are exercised. An untested plan does not count. Exercise results are recorded and any shortcomings are carried into the next version of the plan.

Our disaster recovery architecture spans geographically separate facilities: the loss of one site is not the loss of the service.

Quality Policy

This policy is subject to annual audit under ISO 9001. Certifications page

Eclit bases service quality on defined processes rather than on individual effort. Our quality management system operates in line with ISO 9001.

Our processes are written down and each has an owner. Failures are not hidden: they are recorded and traced to a root cause. The aim is not to find fault but to stop the same failure from recurring.

We treat customer feedback as an input to improvement. Complaints, satisfaction measurements and audit findings feed the same improvement cycle.

We measure improvement. An improvement that cannot be measured does not count as one.

Personal Data Protection Policy

Eclit acts in accordance with its obligations under Turkish Law No. 6698 on the Protection of Personal Data and related legislation. For customers established in the European Union, GDPR requirements are observed in addition.

We process personal data only for specified, explicit and legitimate purposes. We do not request or retain data that is not necessary for delivering the service.

In the services we provide, we usually act as a data processor: our processing is limited to the controller's instructions and to the contract between us.

Which facility holds the data is set out in the contract. Data is not transferred abroad without agreement with the customer.

A defined process handles data subject requests. Requests are answered within the period prescribed by law.

Code of Ethics and Anti-Corruption Policy

Eclit conducts its business on principles of integrity and transparency. We have no tolerance for bribery or corruption of any kind, and that holds even at the cost of losing business.

Employees may not accept gifts or benefits capable of influencing their decisions. Any offer beyond token value is reported to a manager.

Relationships that could give rise to a conflict of interest are declared. A declared relationship is not in itself a breach; failing to declare one is.

Employees who report a suspected breach are protected. A report made in good faith will not be allowed to count against the person who made it.

Compliance with competition law is fundamental. We do not exchange information with competitors on pricing, market allocation or bidding behavior.

People and Equal Opportunity Policy

Hiring, promotion and pay decisions at Eclit are based on competence and performance. Language, religion, ethnicity, gender, age, disability and comparable characteristics play no part in them.

Discrimination, harassment and bullying of any kind are prohibited. A defined channel exists for reporting, and reports are handled in confidence.

Engineering discipline is sustained by learning. We support our employees' technical development and certification.

We treat our legal obligations on occupational health and safety as a floor, not a target.

Supplier and Partner Policy

The commitments Eclit makes to its customers extend across the whole supply chain. A subcontractor's practice counts as our practice.

We expect our suppliers to act in line with the information security, data protection and ethics policies on this page. That expectation is written into contracts.

Suppliers with access to customer data are assessed for security before the service begins, and their access is limited on the principle of least privilege.

Price is not the only criterion in supplier selection: technical competence, continuity capacity and compliance history are weighed alongside it.

Environmental Policy

Eclit undertakes to reduce the environmental impact of its operations and to comply with applicable environmental legislation.

In data center operations we treat energy efficiency as a design criterion. Virtualization and capacity optimization reduce energy consumption as well as customer cost.

In hardware lifecycle management we prioritize extending equipment life, and route decommissioned equipment to licensed recycling channels.

Disposal of electronic waste and of media carrying data follows both environmental legislation and our information security policy; disposal is recorded.

Tell us what your supplier assessment or contract review needs and we will send it. Get in touch