Our Information Security Policies

  1. The Purpose, Scope of Information Security and Adoption of the Subject by Management

WalnutLab considers corporate information to be an extremely valuable asset. Information is of critical importance for the sustainability of our business activities and must be protected appropriately.

WalnutLab aims to minimise the risks that may arise regarding the Confidentiality, Integrity, and Availability of corporate information and the impacts of these risks by implementing the ISO 27001 Information Security Management System (ISMS) standard.

This policy has been approved by WalnutLab's senior management.

WalnutLab management has specifically committed to the fulfillment of the following matters:

  • Ensuring the confidentiality, integrity, and availability of WalnutLab's information and information systems,

  • Identifying risks to information assets and managing these risks in a systematic manner,

  • Fulfilling the requirements of Information Security Standards,

  • Ensuring compliance with all legal regulations regarding Information Security,

  • Evaluating continuous improvement opportunities and carrying out activities to keep the Information Security Management System alive,

  • Conducting training sessions to develop technical and behavioural competencies in order to increase information security awareness,

  • Ensuring that other sub-procedures linked to this policy are prepared and published by the respective department heads.

WalnutLab's Information Security Policies are valid and mandatory for all personnel using corporate information or business systems, whether full-time or part-time, permanent or contracted, regardless of geographical location or business unit. All individuals who do not fall into these classifications but require access to corporate information, such as third-party service providers and their associated support staff, must adhere to the general principles of this policy and other security responsibilities and obligations they are required to comply with.

  1. Responsibilities of All Employees

The purpose of Information Security and this policy is to protect, maintain, and manage the confidentiality, integrity, and availability of information and all supporting business systems, processes, and applications. This means ensuring that WalnutLab's information remains in authorised hands, that information is complete, accurate, and usable, and that information and systems are ready for use when needed. Therefore, all internal and outsourced personnel, as well as interns, regardless of their position or duties, are responsible for performing their work in a manner that ensures the protection of information within the organisation.

In addition to ensuring that WalnutLab's information is complete, accurate, and ready for use, all personnel must also comply with the protection of confidential information as specified in the Personnel agreements and the principles of business ethics of the organisation. WalnutLab undertakes to take the measures specified in the Personal Data Protection Law and to work in full compliance with the Personal Data Protection Policy.

  1. Policy Ownership and Providing Guidance on Information Security

Functional ownership of this policy and all standards and other supporting documents and training activities will be maintained by the ISMS Team, who will also be the source of advice and guidance on the implementation of the policy throughout the organisation.

The ISMS Team will ensure that all employees receive appropriate training to ensure an adequate level of awareness of Information Security issues and will provide guidance on the handling of information security incidents in general. Where necessary, it will ensure that this policy is supported by detailed standards, procedures and processes, and that these are available as and when required. It will also be responsible for ensuring that the requirements of this policy are communicated to all employees (permanent or temporary) and all contractor personnel.

The ISMS Representative will be responsible for establishing and maintaining the overall management framework for Information Security and for the ongoing review of this policy to ensure that it remains live and continues to reflect the business requirements of the organisation's affiliates or changes in the risk environment or threats faced by their information and information systems.

Information Security policies are reviewed at least once a year in parallel with asset and risk updates made to reflect the current risks faced by WalnutLab information assets. To keep new risks and changes in risks under control, Information Security Policies are updated with new necessary additions. In addition, any organisation employee may request the ISMS Team to modify the policies in order to improve the Information Security Policies and better reflect the controls required by the organisation. Requests made are handled and evaluated by the ISMS Team.

Information Security Policy principles should be applied in parallel with the personnel rules of the WalnutLab Human Resources department. Employees are also responsible for being aware of and complying with the Information Security Policy.

  1. Audit and Compliance with Policies and Resolution of Non-Compliance

Each unit manager is primarily responsible for taking the necessary measures to ensure compliance with the Information Security Policy and for monitoring the system.

The ISMS Team is responsible for periodically auditing compliance with all published policies and procedures, especially the Information Security Policy, as well as the related standards, and reporting to the relevant parties.

Violations of the Information Security Policy may cause WalnutLab to suffer damage as a result of not implementing the necessary controls against risks, and may also lead to criminal liability according to the new Turkish Penal Code and the liability to compensate for financial damages. Therefore, the violation in question is also a violation of the institution's Personnel Regulations and may result in disciplinary action. Information Security Policy violations detected through monitoring, auditing or reporting may result in internal disciplinary actions that could go as far as termination of employment or even the initiation of judicial and criminal legal proceedings.

Working together on the implementation of this policy will help to continuously

protect our information and reputation and ensure the ongoing success of our business.

  1. Information Security Policy

WalnutLab Information Security has adopted the following objectives as its policy in order to protect the corporate reputation, reliability, and information assets, and to ensure that the core and supporting business activities continue with the minimum possible interruption:

  • To protect the information assets processed, preserved, and shared by the institution with other organisations in accordance with the principles of confidentiality, integrity, and availability,

  • To manage information assets, determine the security values, needs, and risks of assets, and to develop and continuously improve the management system established to implement controls against security risks,

  • To determine the continuous improvement needs and opportunities by assessing the risks arising from activities in line with the vision and mission of the institution,

  • To keep up with and follow technological developments and changes within the scope of the services provided,

  • To ensure business continuity by reducing the impact of information security risks,

  • To comply with national and international regulations, legal and relevant legislative requirements, obligations arising from agreements, and corporate responsibilities towards internal and external stakeholders,

  • To have the competence to respond rapidly to potential information security incidents and minimise the impact of the incident,

  • To maintain and improve the level of information security over time with a cost-effective control infrastructure,

  • To enhance corporate reputation and protect it from information security-based negative impacts,

  • To preserve personal data within the scope of the Law on the Protection of Personal Data,

  • To conduct training to improve employees' information security awareness and competencies, and to be an exemplary organisation in the sector integrated with other management systems by providing the necessary support.

Each member of WalnutLab is responsible for acting in line with these specified goals and contributing to the system.

WalnutLab Management

Our Privacy Policies

  1. Entry

As Walnut Lab Teknoloji ve Dijital Çözümler A.Ş. (“Walnut Lab”, “we”, “our” or “our company”), we attach great importance to the privacy of your personal data. This Privacy Policy explains how your personal data is collected, used, shared and protected when using our website www.plannet.com.tr and related services.

We advise you to read this policy carefully. By using our website, you are deemed to have accepted the practices specified in this policy.

  1. Data We Collect

We may collect the following types of information from you directly or indirectly:

2.1. Information You Provide Directly

  • Identity Information: First name, last name, username or similar identifiers.

  • Contact Information: Email address, telephone number, company name, address information.

  • Account Information: Username, password, account preferences.

  • Transaction Information: Details regarding your purchases or requests.

  • Marketing Preferences: Your preferences for receiving marketing communications from us.

2.2. Information Collected Automatically

  • Technical Information: IP address, browser type and version, time zone setting, browser plug-in types, operating system and platform.

  • Usage Information: The pages you visit on our website, the time spent on our site, click data, search queries.

  • Device Information: Information about the device you use to access our site.

2.3. Cookies and Similar Technologies

We use cookies and similar tracking technologies on our website. For more information about these technologies, you can refer to our Cookie Policy.

  1. Our Purpose for Using Your Data

We use your personal data for the following purposes:

  • To provide and manage our services

  • To create and manage your account

  • To complete your transactions and maintain their records

  • To communicate with you and answer your questions

  • To improve our products and services

  • To ensure the security of our website and systems

  • To prevent and detect fraud or other illegal activities

  • To fulfil our legal obligations

  • To send marketing communications, if you have given your consent

  1. Sharing of Your Data

We may share your personal data with the following parties:

4.1. Service Providers

We work with third-party service providers who provide services such as IT, system administration and platform services, marketing, data analysis, and payment processing. These service providers can only access your data in accordance with our instructions and in compliance with this privacy policy.

4.2. Business Partners

We may work with our business partners to provide you with products or services. In this case, our business partners can only access the information necessary to offer their services.

4.3. Legal Requirements

We may also share your personal data in the following circumstances:

  • To comply with a legal obligation

  • To protect the rights or property of Walnut Lab

  • To prevent or investigate potential wrongdoings

  • To protect the personal safety of Plannet users or the public

  1. Security of Your Data

We take appropriate technical and organisational measures to ensure the security of your personal data. However, please remember that no method of transmission over the internet, or method of electronic storage, is 100% secure.

Our company implements the following security measures:

  • Encryption technologies

  • Physical access controls

  • Regular security assessments

  • Staff training and awareness programmes

  1. Storage of Your Data

We retain your personal data for as long as necessary for the purpose for which they were collected, or as required by our legal obligations. Retention periods may vary depending on the type of data and the purpose of collection.

  1. Your rights

Under the Law on the Protection of Personal Data No. 6698, you have the following rights:

  • To learn whether your personal data is being processed or not

  • To request information if your personal data has been processed

  • To learn the purpose of processing your personal data and whether they are used in accordance with their purpose

  • To know the third parties to whom your personal data is transferred at home or abroad

  • To request correction of your personal data if it is incomplete or incorrectly processed

  • To request the erasure or destruction of your personal data

  • To object to the occurrence of a result against you by analyzing your processed data exclusively through automated systems

  • To demand compensation for the damage in case you suffer damage due to unlawful processing of your personal data

To exercise these rights, you can contact us using the contact information below.

  1. Children's Privacy

Our services are not intended for children under the age of 18. We do not knowingly collect personal data from anyone under the age of 18. If you are under the age of 18, please do not send your personal data to us.

  1. Third-Party Links

Our website may contain links to third-party websites, applications and services. When you access these third-party services, their privacy policies will apply. We are not responsible for the privacy practices of these third-party services.

  1. . Changes to This Policy

We may update this Privacy Policy from time to time. In the event of any changes, we will post the updated policy on our website and notify you of any material changes.

  1. Contact Us

If you have any questions, concerns or requests regarding this Privacy Policy or the use of your personal data, please contact us using the contact information below:

Walnut Lab Teknoloji ve Dijital Çözümler A.Ş.
Address: GAZİ Teknopark, Bahçelievler, Gazi Ünv. Gölbaşı Yerleşkesi No:24, 06830 Gölbaşı/Ankara
E-mail: info@walnutlab.io

  1. Complaints

If you have a complaint regarding our data protection practices, we kindly ask that you contact us first. However, you also have the right to lodge a complaint with the Personal Data Protection Authority.

This privacy policy reflects the data protection practices of Walnut Lab. This policy has been prepared in accordance with the provisions of the Law on the Protection of Personal Data No. 6698 of the Republic of Turkey and other relevant legislation.

@

&

Walnut Lab. Technology & Digital Solutions Inc.

Copywrite © 2026 WalnutLab A.Ş. All rights reserved.

@

&

Copywrite © 2026 Walnut Lab. Inc. All rights reserved.