LEGAL DOCUMENT
Data Security
Explains the technical and organisational measures we apply to protect data on aiorvision.com and in the customer portal, how we handle security incidents, and how you can report a vulnerability to us.
Last updated: 30 September 2026
- Effective
- 2026-09-30
- Basis
- Law no. 6698 art. 12 · Turkish Data Protection Authority Personal Data Security Guide (Technical and Organisational Measures)
This English text is a translation. In case of any discrepancy, the Turkish version prevails.
1. Principles
This page lists only measures we actually apply; when a measure changes, the page is updated.
Organisational measures apply across AIOR: confidentiality undertakings, the least-privilege principle, staff awareness training, supplier assessment, a personal data processing inventory and periodic internal audit.
2. Infrastructure
- The site and the portal are hosted on servers in a data centre in the European Union (OVHcloud).
- All connections are encrypted with TLS (HTTPS); HSTS tells browsers to use encrypted connections only.
- Administrative access to the servers is restricted by IP address.
- Server data is backed up daily.
- Pages cannot be shown inside another site's frame (iframe); the content security policy (CSP) lets pages load resources from our own server only.
3. Customer Portal
- Each user can access only their own organisation's data; queries are limited on the server to the organisation of the session.
- Passwords are stored only in irreversible form (bcrypt).
- The session cookie is protected with the HttpOnly, Secure and SameSite=Strict attributes; a session lasts at most 12 hours and ends after 4 hours without activity.
- Five failed sign-ins in a row lock the account for 15 minutes; attempts with addresses that have no account are limited in the same way.
- Portal requests are checked for their headers and origin (Origin); requests sent from other sites are rejected.
- Sign-ins and other requests are rate-limited; actions such as sign-in, sign-out and password changes are written to an audit record.
- When a password is changed, all of the user's other sessions are closed.
- Portal pages are closed to search engines and are not stored in the browser cache.
4. Forms
- Information sent with the contact form is validated again on the server; field lengths are limited.
- An invisible trap field and a fill-time check guard against automated submissions; the number of submissions from one address is limited.
- No third-party verification service (CAPTCHA) is used, so your data is not passed to such a service.
- Form contents are not written to server logs.
5. Transfer of Station Data
The data transferred to the portal is limited to cycle, barcode and weld records; no camera images or operator details are transferred. The transfer method is agreed with the customer during installation and set out in the customer contract.
6. Incident Handling
- On detection of a personal data breach, notification is made to the Personal Data Protection Board as soon as possible and in any case within 72 hours.
- Affected data subjects are informed as soon as possible.
- Every breach is recorded; root-cause analysis is performed and corrective action is applied.
7. Reporting a Vulnerability
- If you believe you have found a vulnerability in the site or the portal, write to hi@aior.com. Including the relevant address (URL), the date and time, and the steps to reproduce the problem speeds up the investigation.
- Every report is recorded and tracked.
- Do not carry out unauthorised security scanning, port scanning, network sniffing or penetration testing; if you want to run a test, obtain written permission first.
- Security contact details are also published in the security.txt file.
8. User Responsibilities
- Keep your account and access details confidential; use a strong, unique password.
- If you used the portal on a shared computer, sign out with Sign Out when you have finished.
- If you suspect your account has been compromised, report it immediately to hi@aior.com.
Service Provider Details
- Legal name
- AIOR TEKNOLOJİ LİMİTED ŞİRKETİ
- Address
- Geçit Mahallesi 6. Gümüş Sokak No: 6
Balkar Plaza A Blok Kat: 1 Daire: 2
Osmangazi / Bursa / Türkiye - Tax office / Tax ID
- Osmangazi Tax Office · 0102359120
- MERSIS
- 0010235912000001
- Trade registry no
- 137841
- Chamber registry no
- 147909
- hi@aior.com
- Registered e-mail (KEP)
- aior@hs01.kep.tr
- Phone
- +90 850 309 80 80
All official registry data: Company details (opens in a new tab)