Security Standards
What the portal is certified for, which regimes it complies with and what the infrastructure guarantees.
Optifora is equipped with the highest security standards and compliance certificates. The security and privacy of your data is our priority.
The Optifora platform has been developed in compliance with national and international security standards.
ISO 27001
Information Security Management System (ISMS) standard. Internationally recognized information security certificate.
KVKK Compliant
Fully compliant with the Personal Data Protection Law (KVKK). All your personal data is processed in accordance with legal regulations.
GDPR Compliant
Full compliance with the European General Data Protection Regulation (GDPR). International data protection standards.
SSL A+ Rating
A+ security certificate approved by Qualys SSL Labs. All your data is protected with 256-bit SSL encryption.
Ministry of Labor Approved
OHS software approved by the Ministry of Labor and Social Security. Supported by official institutional integrations.
IBYS Integration
Fully integrated with the Occupational Health and Safety Information Management System (IBYS). Automatic data transfer and synchronization.
Made in Türkiye
Local and national software. Designed, developed and supported in Türkiye. The work of our Turkish engineers.
99.9% Uptime
Uninterrupted service with high availability guarantee. 24/7 active monitoring and automatic backup systems.
Continuous Updates
Regular software updates and new features. Fast adaptation to technology and regulatory changes.
Security Measures
- 256-bit SSL EncryptionAll your data is protected with banking-level SSL/TLS encryption.
- Secure Data CenterYour data is safely stored in ISO 27001 certified data centers.
- KVKK & GDPR CompliantYour personal data is processed in accordance with all legal regulations.
- 24/7 MonitoringOur systems are continuously monitored and automatically backed up.
What is checked continuously
Legal basis
The table shows the obligations of the legislation region you pick in the top bar; it refreshes without reloading the page when the region changes.
Türkiye — obligations and their legal basis
| Obligation | Legal basis | How the page covers it |
|---|---|---|
| Where processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject, processing may be carried out without explicit consent. | Law No. 6698, art. 5(2)(f) | The badge 'KVKK compliant — fully compliant with the Personal Data Protection Law (KVKK)'. |
| Everyone has the right to apply to the data controller to learn whether their personal data are processed, to request information, to request rectification or erasure and to claim compensation for damage. | Law No. 6698, art. 11(1) | The data subject rights in the 'KVKK & GDPR compliant' section. |
The legal bases were read from fingerprinted source texts: Law No. 6698, art. 5(2)(f) · Law No. 6698, art. 11(1).
European Union — obligations and their legal basis
| Obligation | Legal basis | How the page covers it |
|---|---|---|
| Processing shall be lawful where it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. | Regulation (EU) 2016/679 (GDPR), art. 6(1)(f) | The badge 'GDPR compliant — full compliance with the EU General Data Protection Regulation'. |
| The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and access to that personal data. | Regulation (EU) 2016/679 (GDPR), art. 15(1) | The data subject right of access covered by the same badge. |
The legal bases were read from fingerprinted source texts: Regulation (EU) 2016/679 (GDPR), art. 6(1)(f) · Regulation (EU) 2016/679 (GDPR), art. 15(1).
Legal basis — United Kingdom
| Obligation | Legal basis | How the page covers it |
|---|---|---|
| The UK GDPR and this Act protect individuals with regard to the processing of personal data, in particular by requiring personal data to be processed lawfully and fairly and by conferring rights on the data subject. | Data Protection Act 2018, s. 2(1) | The UK counterpart of the 'GDPR compliant' badge. |
| This Part applies to the types of processing of personal data to which the UK GDPR applies by virtue of Article 2, and supplements and must be read with the UK GDPR. | Data Protection Act 2018, s. 4(2) | The supplementing UK legislation behind the same badge. |
The legal bases were read from fingerprinted source texts: Data Protection Act 2018, s. 2(1) · Data Protection Act 2018, s. 4(2).
Looking for a Secure and Compliant Solution?
Ensure the security of your data and legal compliance with Optifora. Contact us for detailed information.
Contact Us