04
Security policy
Security policy
Acarkon Entegre Ağaç San. ve Tic. A.Ş. (“Acarkon”) operates the Silva Stone website and related digital channels with a commitment to information security and the protection of personal data. This Security Policy summarises the principles applied to systems, applications and personnel. It should be read together with the Privacy policy and Privacy notice.
1. Purpose and scope
The purpose of this policy is to protect the confidentiality, integrity and availability of information assets used in connection with Silva Stone products, Acarkon Store operations, customer communications and website services. It applies to employees, contractors and service providers who access Acarkon systems.
2. Organisational measures
- Access to personal data and business systems is granted on a need-to-know basis
- Roles and responsibilities for information security are defined within the organisation
- Staff are informed about confidentiality and lawful data handling
- Contracts with processors include appropriate data-protection and security clauses where required
3. Technical measures
- Secure communication (HTTPS) for website forms and sensitive channels
- Access controls, authentication and authorisation for administrative systems
- Protection against common web threats within reasonable technical capability
- Backup and recovery practices for critical systems
- Logging and monitoring where necessary for security and audit
4. Personal data security
In line with the KVKK, Acarkon takes administrative and technical measures to prevent unlawful processing of personal data, unlawful access and loss of data. Data retention, deletion and breach notification practices are described in the Privacy Policy and related legal texts.
5. Third-party links and external sites
Our website may contain links to third-party sites. Acarkon does not control and cannot guarantee the security of those external environments. Users should review the security and privacy practices of any site they visit after leaving silvastone / acarkon pages.
6. Incident response
Suspected security incidents are assessed promptly. Where a personal data breach must be notified under the KVKK, Acarkon notifies the competent authority and affected individuals as required by law. Users who become aware of a security concern may contact bilgi@acarkon.com.
7. User responsibilities
Users should keep their devices and browsers updated, protect login credentials where accounts exist, and avoid sharing sensitive information through unofficial channels. Acarkon will never ask for passwords by unsolicited email.
8. Updates
This Security Policy may be revised to reflect technological or organisational changes. The current version is published on this page. Related documents: Cookie policy, Personal data protection, KVKK law text.