Skip to content
AIORAIORVision
How It WorksReports & PortalAboutContact
TREN
Customer Login
How It WorksReports & PortalAboutContactCustomer Login
Language
TREN
Theme

LEGAL DOCUMENT

Data Security

Explains the technical and organisational measures we apply to protect data on aiorvision.com and in the customer portal, how we handle security incidents, and how you can report a vulnerability to us.

Last updated: 30 September 2026

Effective
2026-09-30
Basis
Law no. 6698 art. 12 · Turkish Data Protection Authority Personal Data Security Guide (Technical and Organisational Measures)

This English text is a translation. In case of any discrepancy, the Turkish version prevails.

Contents

  1. 1. Principles
  2. 2. Infrastructure
  3. 3. Customer Portal
  4. 4. Forms
  5. 5. Transfer of Station Data
  6. 6. Incident Handling
  7. 7. Reporting a Vulnerability
  8. 8. User Responsibilities
  9. Service Provider Details
  10. Related Documents

1. Principles

This page lists only measures we actually apply; when a measure changes, the page is updated.

Organisational measures apply across AIOR: confidentiality undertakings, the least-privilege principle, staff awareness training, supplier assessment, a personal data processing inventory and periodic internal audit.

2. Infrastructure

  • The site and the portal are hosted on servers in a data centre in the European Union (OVHcloud).
  • All connections are encrypted with TLS (HTTPS); HSTS tells browsers to use encrypted connections only.
  • Administrative access to the servers is restricted by IP address.
  • Server data is backed up daily.
  • Pages cannot be shown inside another site's frame (iframe); the content security policy (CSP) lets pages load resources from our own server only.

3. Customer Portal

  • Each user can access only their own organisation's data; queries are limited on the server to the organisation of the session.
  • Passwords are stored only in irreversible form (bcrypt).
  • The session cookie is protected with the HttpOnly, Secure and SameSite=Strict attributes; a session lasts at most 12 hours and ends after 4 hours without activity.
  • Five failed sign-ins in a row lock the account for 15 minutes; attempts with addresses that have no account are limited in the same way.
  • Portal requests are checked for their headers and origin (Origin); requests sent from other sites are rejected.
  • Sign-ins and other requests are rate-limited; actions such as sign-in, sign-out and password changes are written to an audit record.
  • When a password is changed, all of the user's other sessions are closed.
  • Portal pages are closed to search engines and are not stored in the browser cache.

4. Forms

  • Information sent with the contact form is validated again on the server; field lengths are limited.
  • An invisible trap field and a fill-time check guard against automated submissions; the number of submissions from one address is limited.
  • No third-party verification service (CAPTCHA) is used, so your data is not passed to such a service.
  • Form contents are not written to server logs.

5. Transfer of Station Data

The data transferred to the portal is limited to cycle, barcode and weld records; no camera images or operator details are transferred. The transfer method is agreed with the customer during installation and set out in the customer contract.

6. Incident Handling

  • On detection of a personal data breach, notification is made to the Personal Data Protection Board as soon as possible and in any case within 72 hours.
  • Affected data subjects are informed as soon as possible.
  • Every breach is recorded; root-cause analysis is performed and corrective action is applied.

7. Reporting a Vulnerability

  • If you believe you have found a vulnerability in the site or the portal, write to hi@aior.com. Including the relevant address (URL), the date and time, and the steps to reproduce the problem speeds up the investigation.
  • Every report is recorded and tracked.
  • Do not carry out unauthorised security scanning, port scanning, network sniffing or penetration testing; if you want to run a test, obtain written permission first.
  • Security contact details are also published in the security.txt file.

8. User Responsibilities

  • Keep your account and access details confidential; use a strong, unique password.
  • If you used the portal on a shared computer, sign out with Sign Out when you have finished.
  • If you suspect your account has been compromised, report it immediately to hi@aior.com.

Service Provider Details

Legal name
AIOR TEKNOLOJİ LİMİTED ŞİRKETİ
Address
Geçit Mahallesi 6. Gümüş Sokak No: 6
Balkar Plaza A Blok Kat: 1 Daire: 2

Osmangazi / Bursa / Türkiye
Tax office / Tax ID
Osmangazi Tax Office · 0102359120
MERSIS
0010235912000001
Trade registry no
137841
Chamber registry no
147909
E-mail
hi@aior.com
Registered e-mail (KEP)
aior@hs01.kep.tr
Phone
+90 850 309 80 80

All official registry data: Company details↗ (opens in a new tab)

Related Documents

  • Privacy Policy and KVKK Disclosure Notice
  • Cookie Policy
  • Terms of Use
  • Company details (aior.com)↗ (opens in a new tab)
AIORAIORVision

Traceability for welding cells with thermal cameras and a digital twin.

  • hi@aior.com
  • +90 850 309 80 80
  • Osmangazi / Bursa

Product

  • How It Works
  • Reports & Portal
  • Customer Login

Company

  • About
  • Contact
  • aior.com↗ (opens in a new tab)

Legal

  • Privacy & KVKK
  • Cookie Policy
  • Terms of Use
  • Data Security
  • Company Details↗ (opens in a new tab)

© 2026 AIOR Teknoloji Limited Şirketi. All rights reserved.

AIOR Vision is an aior.com↗ (opens in a new tab) brand.