Information Security Policy
This policy explains how we, as the International Liability Association (ILA Association), protect the information we collect through iladernegi.org. The security of donors’ personal, contact, and payment information is an integral part of our association’s responsibility toward our donors.
This text has been prepared in accordance with the obligations regarding data security set forth in Article 12 of the Personal Data Protection Law No. 6698. The specific personal data processed and the purposes for which they are processed are further explained on the Personal Data Protection Law Information Notice page.
1. Security of Donation Payments
We are currently working on our credit card donation infrastructure. Once we begin accepting donations by credit card, the following guidelines will apply.
- We do not store your card information. Your credit or debit card number, expiration date, and security code are never recorded, stored, or viewed on the ILA Association’s servers at any stage. This information is transmitted directly to the partner bank’s virtual POS infrastructure.
- 3D Secure verification. When a donation is accepted via credit card, the payment is verified by redirecting the user to the card-issuing bank’s 3D Secure page. Only the cardholder can complete the verification step.
- Encrypted transmission. All data exchanged on the site, including the payment step, is encrypted using SSL/TLS. Our site currently uses TLS 1.3 and AES-256 encryption, which exceeds the minimum 128-bit requirement for virtual POS transactions.
- Payment infrastructure provider. Payment transactions are processed by banks and payment institutions that are subject to card storage and processing standards (PCI-DSS).
- Stored transaction information. For donation records, only the donation amount, transaction date, transaction reference number, and the donor’s first and last name, email address, and phone number are retained.
2. Website Security
- The site is hosted entirely over HTTPS; unencrypted (HTTP) access is redirected to an encrypted connection.
- The validity of the SSL certificate is monitored, and it is renewed before it expires.
- A strong password is required to access the admin panel; login attempts are limited, and protection against brute-force attacks is in place.
- The WordPress core, themes, and plugins are updated regularly; security updates are applied as a priority.
- Access logs are maintained at the server and application levels.
3. Technical Measures
- Access to personal data is limited to those who need it to perform their duties.
- Each user conducts transactions using their own account; accounts are not shared.
- Access privileges are revoked for individuals whose terms of service have ended.
- The site and database are backed up daily on our hosting provider (Hostinger).
- Protection against malware and security scans are performed.
4. Administrative Measures
- Relevant individuals are informed about data security.
- Data security is ensured in our relationships with service providers (hosting, payment infrastructure, email).
5. In the Event of a Data Breach
If we determine that personal data has been unlawfully obtained by third parties:
- The situation is reported to the Personal Data Protection Board as soon as possible.
- Individuals whose data has been affected will be notified as soon as reasonably possible.
- The necessary steps are taken to limit the impact of the violation and prevent its recurrence.
6. Our Privacy Commitment
- We do not sell, rent, or share our donors’ personal information with third parties for marketing purposes.
- Your information will be used solely to process your donation, issue your receipt, and fulfill our legal obligations.
- Information about the person or organization to which you make a donation will not be disclosed to the public unless you request it.
- Your information will not be disclosed to third parties except in response to requests from authorized public institutions based on applicable laws and regulations.
7. Policy Review
This policy is reviewed in light of changes in legislation and changes to the infrastructure used by our association. The current version is published on this page.
8. Communication
For questions, reports, and suspicious incidents related to information security:
- International Responsibility Association (ILA Association)
- Namık Kemal Neighborhood, Sütçü İmam Street, No. 92, Ümraniye, Istanbul, Turkey
- Email: yardim@iladernegi.org.tr
- Telephone: +90 216 606 45 63
Related pages: KVKK Information Notice · Privacy Policy · Cookie Policy · Donation Cancellation and Refund Terms · Delivery and Fulfillment Policy
Last updated: September 16, 2026