enerwiseai mobile app is now available on Android and iOS! Download now.

enerwiseai

Personal Data Protection & Information Security

Our information notice on the protection of personal data, together with the corporate policy that underpins our information security management system.

Information Notice & Privacy Policy

ENERWISE ENERJİ YÖNETİMİ VE VERİMLİLİĞİ ÇÖZÜMLERİ A.Ş.
Personal Data Protection and Processing Information Notice


1) Identity of the Data Controller

Pursuant to the Turkish Personal Data Protection Law No. 6698 (“KVKK”), the data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
In this context, the data controller is:

ENERWISE ENERJİ YÖNETİMİ VE VERİMLİLİĞİ ÇÖZÜMLERİ ANONİM ŞİRKETİ

  • Trade Registry No: 1016392

  • MERSİS No: 0335092770000001

  • Tax Identification No: 3350927700

  • Registered Address: Altunizade, Mahir İz Cd. No:30/1, 34662 Üsküdar / Istanbul

  • Phone: +90 (216) 402 10 00

  • Email: info@enerwisetech.com

  • Website: www.enerwisetech.com


2) Categories of Personal Data Processed

  • Identity and Contact Information: name-surname, company information, email address, phone number

  • Account Information: username, password (stored in hashed form), authorization details

  • Transaction Security: IP address, session information

  • Device Data: diagnostic data of energy monitoring devices belonging to the enterprise

  • Communication Content: support requests, email correspondence


3) Purposes of Processing Personal Data

  • Provision of products and services, creation of user accounts

  • Operation and continuity of the energy monitoring software

  • Execution of technical support, maintenance, and troubleshooting processes

  • Improvement of user experience and enhancement of service quality

  • Fulfillment of legal obligations and responding to official requests

  • Conducting security audits and risk analyses

  • Other purposes, provided that written consent is obtained if required in the future


4) Legal Grounds

Your personal data is processed in accordance with Articles 5 and 6 of the KVKK based on the following legal grounds:

  • Performance of a contract,

  • Fulfillment of legal obligations,

  • Legitimate interest,

  • Establishment, exercise, or protection of a legal right.


5) Parties to Whom Personal Data May Be Transferred

  • Authorized public institutions and organizations (in case of legal obligation)

  • Legally authorized private persons (lawyers, auditors, etc.)

  • Technical service providers (hosting, backup services, etc.)

Note: Your personal data is not transferred abroad. If an overseas transfer becomes necessary in the future, the required permissions will be obtained in accordance with Article 9 of the KVKK.


6) Retention Periods

  • User account data: for the duration of the account + 2 years

  • Device data: (retention period determined according to operational and legal requirements)


7) Data Security Measures

  • Passwords are stored in hashed form (not kept in plain text).


8) Rights of the Data Subject

Pursuant to Article 11 of the KVKK, you have the right to:

  • Learn whether your personal data is being processed,

  • Request information if your data has been processed,

  • Learn whether your data is used in accordance with its purpose,

  • Request correction if your data is incomplete or inaccurate,

  • Learn the third parties to whom your data has been transferred, provided that this does not affect the performance of the contract or the provision of services,

  • Claim compensation if you suffer damage due to unlawful processing of your data.


9) Application Methods

You may submit your requests regarding your rights via the following channels:

Your applications will be finalized within 30 days.

Information Security Policy

Document No
PO-YN-01
Publication Date
15.01.2026
Revision
00

Enerwise Information Security has adopted the following objectives as policy in order to protect the reputation and reliability of the organisation and its information assets, and to keep core and supporting business activities running with the least possible interruption:

  1. 1To protect the information assets the organisation processes, stores and shares with other organisations in line with the principles of confidentiality, integrity and availability,
  2. 2To manage information assets, to determine the security values, needs and risks of those assets, and to develop and continually improve the management system established to implement controls against security risks,
  3. 3To identify continual improvement needs and opportunities by assessing the risks arising from its activities in line with the corporate strategic plan,
  4. 4To keep pace with and follow technological developments and changes within the scope of the services provided,
  5. 5To ensure business continuity by reducing the impact of information security risks,
  6. 6To comply with the national and international regulations it is subject to, with legal and relevant statutory requirements, with obligations arising from agreements, and with corporate responsibilities towards internal and external stakeholders,
  7. 7To have the competence to respond rapidly to information security incidents that may occur and to minimise their impact,
  8. 8To maintain and improve the level of information security over time through a cost-effective control infrastructure,
  9. 9To enhance the reputation of the organisation and protect it from adverse effects arising from information security,
  10. 10To safeguard personal information within the scope of the Personal Data Protection Law,
  11. 11To deliver training that develops employees’ information security awareness and competence and, by providing the necessary support, to become an exemplary organisation in the sector with a system integrated with our other management systems.

Every member of Enerwise is responsible for acting in line with these objectives and for contributing to the system.