Information Security Policy

HotelRunner aims to constantly improve its system to demonstrate the ability to regularly
provide a product that meets the requirements of the Information Security Management System in its
activities for its stakeholders. In this context, it develops and implements the Information Security
Management System in order to assure the customer that regulatory requirements are complied with
and to increase customer satisfaction through effective and secure implementation of the system,
including processes. At HotelRunner, we adopt, implement, and maintain the ISO 27001 Information
Security Management System standard in order to provide our services in accordance with national
and international standards.


We are aware that information security is the responsibility of all our employees and that both
our company and our stakeholders may suffer significant damages in case of voluntary or involuntary
loss or improper use of information. With this awareness, we protect the confidentiality, integrity, and
accessibility of information belonging to our company and our stakeholders by adopting a sustainable
understanding.


In line with this understanding;
We determine the authorities, roles, and responsibilities for the establishment and execution of
the Information Security Management System, and we periodically review these authorities, roles, and
responsibilities.


We identify and classify our information assets, identify the risks that threaten them, and
develop and effectively implement the required methods to manage these risks.
We keep abreast of developments in relevant legislation, all applicable laws, contracts, and
customer requirements, and we take the necessary measures to ensure their implementation and to
prevent possible violations.


With the fact that the most important element in ensuring information security is humans, we
organize training programs, seminars, and various awareness-raising activities that will raise the
awareness of our employees and other stakeholders, when necessary, about information security, and
we monitor the results.


We prepare and test business continuity plans to ensure that our business and our
responsibilities to our stakeholders are not interrupted in the event of any adverse events.
We prepare procedures and instructions and identify checkpoints to help our Information
Security Management System operate in accordance with the standards, and we regularly measure,
audit, and review its effectiveness in line with the philosophy of continuous improvement.
Thus, as the senior management of HotelRunner, we are committed to ensuring effective and
continuous improvement of the Information Security Management System in accordance with the
relevant standards and legislation by allocating all necessary resources.