1. Purpose
This policy describes the principles used to protect the website, business systems, communication channels and information handled by Seymenoğlu Cağ Kebap Et & Köfte Salonu.
2. Security principles
- Data minimisation and purpose limitation
- Access restricted to authorised persons with a business need
- Confidentiality, integrity and reasonable availability
- Secure and current software and configuration
- Traceability and accountability for important administrative and security actions
3. Technical measures
- HTTPS/TLS protection for website traffic
- Strong, unique administrative passwords and multi-factor authentication where available
- Current PHP, server software and dependencies
- Input validation, output escaping and secure coding practices
- Controls against unauthorised uploads and code execution
- Protected application and server logs, abuse monitoring and incident review
- Controlled backups and protection of backup copies
- Removal of unnecessary services, accounts, ports and file permissions
- Rotation of passwords and access keys after a security incident
4. Organisational measures
- Documenting who may access personal data and systems
- Removing access promptly after role changes or departure
- Communicating confidentiality obligations to staff and providers
- Limiting data sharing to the necessary purpose
- Including confidentiality and security terms in provider agreements
- Reviewing obsolete data and accounts periodically
- Preparing backups and a rollback plan before critical changes
5. Hosting and service providers
Hosting and infrastructure providers are responsible for the security of services under their control. The Business remains responsible for its application, content updates, administrator accounts, access rights, third-party components and customer records.
6. Payment security
The website does not currently process online card payments. Users must not send card numbers, security codes, passwords or similar sensitive payment information through WhatsApp, SMS, social media, email or free-text fields.
7. User security
- Use only
seymenogluetkofte.comand official communication accounts - Do not submit personal or payment information through suspicious links
- Verify accounts requesting money or information in the Business’s name
- Do not leave private messages or account details open on shared devices
- Report imitation domains or suspicious accounts to the Business
8. Reporting a vulnerability
A good-faith security report should identify the affected page, date and time, a short description, the browser and device, and a screenshot that contains no personal data. Do not exploit, disrupt or access other people’s information while testing.
9. Security incidents
When an incident is identified, affected access is restricted, technical evidence is preserved, the cause is investigated, credentials are renewed and the vulnerability is fixed or mitigated. Providers and authorities are notified where required by law.
10. Limits of security assurance
No technical system can be guaranteed to be entirely free of risk. The Business applies reasonable safeguards and reviews them according to the nature of the website and information processed.
11. Updates
This policy may be updated following technical, operational or legal changes. The current version applies when published.
Contact
Business name: Seymenoğlu Cağ Kebap Et & Köfte Salonu
Official title: Seymenoğlu Cağ Kebap Et & Köfte Salonu
Data controller: FARUK SEYMENOĞLU
Address: İkizdere Yolu Üzeri 6. km, Ormanlı Köyü, İyidere/Rize, Türkiye
Phone and WhatsApp: +90 545 959 93 53
Email: