Confidentiality and Data Security Undertaking
This Undertaking is a binding unilateral commitment given by Orginsight Yönetim Danışmanlığı Ltd. Şti. ("Orginsight"), a company having its registered office at Esentepe, Büyükdere Cad. No: 175/7, Şişli, Istanbul, and operating the job evaluation and organizational analysis platform under the "Job-E" brand, for the benefit of customers using the Job-E platform (each, a "Customer"). Orginsight assumes the obligations set out below unconditionally, without requiring any signature or reciprocal undertaking from the Customer.
1. Scope
1.1. This Undertaking covers data uploaded by the Customer to the Job-E platform, or otherwise shared with Orginsight, relating to organizational charts, position inventories, reporting relationships, unit structures and headcount ("Organizational Data"), together with all other commercial, financial and technical information belonging to the Customer ("Confidential Information").
1.2. Orginsight does not request, and does not require the upload of, directly identifying information relating to the Customer's employees — such as name and surname, national identity number, email address or personnel number — for the provision of the service.
1.3. Orginsight does not request salary, benefits or individual personnel records under this Undertaking, except in respect of the pay equity module. Data uploaded through that module is keyed to an anonymous identifier and contains none of the directly identifying information referred to in Article 1.2. Where any other module requiring the processing of such data is activated, a separate Data Processing Agreement shall be entered into with the Customer in accordance with applicable data protection legislation.
2. Limitation of Purpose
2.1. Organizational Data and Confidential Information are processed solely for the purpose of providing the service to the Customer.
2.2. Organizational Data and Confidential Information are not sold, rented or licensed to third parties, and are not used for marketing purposes.
2.3. The Customer's data is not used in services provided to any other customer, nor in any cross-customer comparison or benchmarking exercise.
3. Security Measures
Orginsight applies, as a minimum, the following technical and administrative measures: encryption in transit and at rest; role-based access controls; logical segregation by customer; access logging; regular backup; and restriction of access to Confidential Information to personnel who need to know it in order to perform their duties. Orginsight is directly liable for any conduct of such personnel in breach of this Undertaking.
4. Service Providers
4.1. Orginsight uses cloud infrastructure and artificial intelligence service providers in order to provide the service. Some of these providers are established in jurisdictions other than that of the Customer.
4.2. Orginsight binds such providers to confidentiality and security obligations equivalent to those set out in this Undertaking and remains responsible for their acts and omissions as if they were its own.
4.3. A current list of service providers is made available to the Customer on request.
5. Retention, Deletion and Destruction
5.1. Organizational Data is stored in digital form only; no printed or written copies are created.
5.2. Organizational Data may be retained during the service relationship and after its termination, for the purposes of maintaining service continuity, enabling comparison with prior-period results, and preserving the traceability of the evaluation results produced. Throughout the retention period it remains subject to all provisions of this Undertaking.
5.3. Upon the Customer's written request, Orginsight shall, within 30 (thirty) days of receipt of the request, delete or irreversibly anonymize the Organizational Data and provide written confirmation of destruction.
5.4. Retention obligations arising from applicable legislation, and copies held in routine backup systems that are not technically susceptible to selective deletion, are reserved. Such copies are deleted at the end of the backup cycle and remain protected by this Undertaking until deleted.
6. Breach Notification
Where it is determined that Confidential Information or Organizational Data has been subject to unauthorized access, disclosure or loss, Orginsight shall notify the Customer in writing within 24 hours of such determination, providing information on the scope and effects of the breach and on the measures taken.
7. Compelled Disclosure
Confidential Information may be disclosed only where required by applicable legislation or by a decision of a competent judicial or administrative authority. In such cases Orginsight shall notify the Customer, to the extent legally permitted and within a reasonable time in advance.
8. Term
The obligations under this Undertaking take effect when the Customer begins using the platform and continue for 10 (ten) years following termination of the service relationship. In respect of information constituting a trade secret, the confidentiality obligation is of unlimited duration.
9. Amendment
Orginsight may update this Undertaking. Updates do not apply retroactively to data uploaded to the platform before their effective date, and no update may extinguish rights that have already accrued in favour of the Customer.
10. Legal Nature
10.1. Orginsight acknowledges, declares and undertakes that it assumes the obligations set out in this Undertaking unconditionally, and that it may not unilaterally withdraw from them.
10.2. This Undertaking takes effect between the Parties when the Customer begins using the Platform; no separate signature or express declaration of acceptance by the Customer is required.
10.3. This Undertaking is governed by Turkish law. The Istanbul Central (Çağlayan) Courts and Enforcement Offices have jurisdiction over any dispute.