This English page explains a policy that binds the company under Turkish law. The Turkish text is the legally operative version.
Artificial Intelligence Policy
- In force from
- 3 Eylül 2026
- Review
- Yılda bir kez, ihtiyaç hâlinde daha erken
1. Purpose and scope
This Policy sets out the principles under which Kulular Bilişim Teknolojileri Limited Şirketi (the Company) uses artificial intelligence systems in its own operations and in the products it develops for clients.
The Policy covers all employees, interns and third parties working on the Company's behalf. Artificial intelligence components within software the Company develops are also subject to this Policy.
The Policy is read together with applicable Turkish law. Where the Policy and the law conflict, the law applies. This is a Turkish-law document; it does not claim to state or track UK or EU obligations.
2. Core principles
- Human oversight is fundamental. No AI output may be solely determinative in a decision that produces a legal effect on a person or similarly significantly affects them.
- Transparency is fundamental. The use of AI is not concealed. The Company declares output produced with AI assistance as such.
- Accountability is fundamental. A named person is responsible for every output. A system's result does not remove that responsibility.
- Data minimisation is fundamental. A system is not given more data than the task requires.
- Non-discrimination is fundamental. Uses carrying a risk of discriminatory outcomes are separately assessed.
- Traceability is fundamental. Which version ran, on what input, and when, must be capable of being recorded.
3. Internal use
The Company uses AI assistance in research, analysis, software development and documentation. This assistance is identified by name within the team.
No output produced with AI assistance is published or delivered to a client directly. Every output is reviewed by a team member for accuracy, currency, data security and context.
AI systems hold no signature authority, representative authority or independent decision-making power at the Company.
- Client, patient, student and employee data, and confidential information belonging to third parties, is not entered into an external AI service without explicit written permission.
- Identity information, authentication details, access keys and passwords are never entered under any circumstances.
- Final control of legal text is not left to artificial intelligence.
- Output requiring cited sources is not published before those sources are verified.
4. Use in client projects
Where an AI component will be used in a client project, this is disclosed to the client in writing before the contract is concluded. The nature of the system used, the categories of data to be processed, and where human oversight applies, are put in writing.
Where an AI component processes personal data, the Company acts as a data processor within the meaning of Law No. 6698. The client is the data controller.
The Company does not use client data to train its own models without the client's explicit written permission.
5. Risk assessment
Every AI component is assessed for risk level according to its purpose. The assessment considers the decision's effect on individuals, the harm that would follow from an error, the nature of the data, and whether a remedy is available.
Uses that process special-category personal data, support decisions in health or education, or directly affect a person's rights, are treated as high risk. In these uses, human oversight is recorded and a challenge route is defined.
6. Prohibited uses
- Uses that covertly profile individuals, or aim to manipulate their behaviour or exploit their vulnerabilities.
- Uses that remotely identify individuals through biometric data without their consent.
- Automated decisions producing outcomes such as recruitment, dismissal, credit or insurance, made about a person without human oversight.
- Uses aimed at producing misleading content that impersonates a real person or organisation.
- Any other use prohibited by applicable law.
7. Reporting breaches and consequences
Any employee who becomes aware of a use contrary to this Policy reports it to the managing director without delay. A person who reports in good faith may not be subjected to any adverse treatment as a result.
A breach of this Policy may lead to disciplinary process and contractual consequences, depending on the nature of the work concerned.
8. Entry into force and review
This Policy takes effect on the date of its publication. It is reviewed at least once a year, and earlier where there is a material change in the law or in the Company's activities.
The managing director is responsible for the Policy's implementation.