🛡️ Information Security Policy
Last updated: June 2026
This translation was prepared using AI and is for informational purposes only. The Turkish original is the legally binding version.
1. Purpose and Scope
This policy explains the technical and administrative security measures implemented to protect the confidentiality, integrity, and accessibility of user data processed on the On Eğitim TV platform. The policy covers student, teacher, and parent data as well as the entire Platform infrastructure.
2. Core Security Principles
- Confidentiality: Ensuring only authorized persons can access data.
- Integrity: Preventing unauthorized modification of data.
- Availability: Ensuring services and data are accessible when needed.
3. Data Encryption and Transmission Security
All data traffic between the Platform and users is encrypted with TLS/SSL (HTTPS). Passwords are stored as irreversible hashes; they are never kept in plain text. Sensitive configuration information is protected in environment variables.
4. Access Control and Authentication
Access is restricted through role-based authorization (student, teacher, administrator). Session management is carried out using HttpOnly cookies. Two-factor authentication (2FA / TOTP) is supported for accounts. For critical actions such as password changes, existing session tokens are invalidated to preserve account security.
5. Payment Security
Payment transactions are carried out through the 3D Secure-supported secure infrastructure of our authorized payment institution, PayTR. Card information is not stored on On Eğitim TV servers and does not pass through our servers; it is processed directly by the payment institution.
6. Backup and Business Continuity
Our data is regularly backed up using the backup facilities provided by our infrastructure provider. Infrastructure maintenance and updates are carried out on a planned basis.
7. Monitoring, Logging, and Incident Response
System access and critical operations are logged. When suspicious activity is detected, the necessary response steps are implemented and affected accounts are protected.
8. Personnel and Third-Party Obligations
All parties with access to data are bound by confidentiality obligations. Agreements containing data processing and security commitments under the KVKK are made with critical suppliers that process personal data (e.g. payment infrastructure).
9. Data Breach Notification
In the event of unlawful acquisition of personal data, the matter is reported as soon as possible to the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) and to affected users, in accordance with the Turkish Law No. 6698 on the Protection of Personal Data (KVKK).
10. Contact
For questions and notifications regarding information security: destek@onegitim.tv

