Skip to content
Tuna Digital Platformby Tuna Industrial
SECURITY AND INTEGRATION

Digital growth, without putting data at risk.

Websites, chatbots, WhatsApp, switchboard, and email agents all work with customer data. That is why every proposal we write explains how data will be protected and how we will talk to your existing systems before it describes the service scope.

Our working principles

08 PRINCIPLES
01Data ownershipDomains, accounts, CRM records, and content are opened in your company’s name. When the engagement ends, every access right and all data are handed over in full.
02KVKK and consentWeb forms, chatbot, WhatsApp, and call records are set up with an information notice, explicit consent, and retention periods.
03Access controlRole-based permissions, two-factor authentication, and single sign-on where supported. Access for departing staff is removed through a defined process.
04Encrypted transfer and storageData travels over encrypted connections (TLS). On the storage side, the chosen provider’s encryption features are enabled.
05AI and dataAI providers are chosen under enterprise terms where customer data is not used for model training. The data each agent can access is limited to its task.
06Human approvalAgents only draft replies that contain quotes, prices, or commitments. The decision to send stays with an authorised person on your team.
07Logs and audit trailAgent actions, integration calls, and permission changes are logged, so the question of who did what and when can be answered.
08Email securitySPF, DKIM, and DMARC make it harder to send forged email in your domain’s name and protect deliverability.
THE SECURITY SECTION OF THE PROPOSAL

The document you receive after the corporate needs analysis.

After the free visibility analysis, we map your systems and processes together in a corporate needs analysis. The security and integration section of the proposal covers these headings.

PROPOSAL · SECURITY AND INTEGRATION PLAN§ 2
2.1Data inventoryWhich personal and commercial data each service will process.
2.2HostingWhere data is held and by which providers, with Turkey or EU options when needed.
2.3Access matrixWhich role accesses which system, with which permissions.
2.4Integration mapThe connections to your ERP, CRM, and email systems, and their direction.
2.5Retention and deletionHow long records are kept and how they are deleted.
2.6Incident responseThe steps followed in a security incident and who communicates.
2.7Handover planHow accounts, data, and documents are delivered when the engagement ends.
INTEGRATION

Your existing systems stay in place.

Adding a new channel never means giving up a working system. Connections are built over APIs, webhooks, or file transfer, and each one is documented. These are the systems we meet most often; the list is not limited to them.

ERP and productionD11 · D13
Matching customer, quote, order, and stock data with the sales channels.
LogoNetsisSAPERPNextTuna Industrial Platform
CRMD11
Collecting requests from every channel in one customer record.
HubSpotZohoSalesforcePipedrive
Email and collaborationD04 · D12
Corporate mailboxes, calendars, and document sharing.
Google WorkspaceMicrosoft 365
Messaging and phoneD05 · D06
Logging WhatsApp conversations and switchboard calls.
WhatsApp Business APISIP / IP PBXMeta Business Suite
Web, search, and analyticsD02 · D10
Measuring visitor, search, and visibility data.
Google Analytics 4Search ConsoleGoogle Business Profile
Automation layerD13
Letting agents talk to systems securely and traceably.
REST APIWebhookSFTP / CSV

This page describes our working approach; it is not a certificate, audit, or compliance statement. The scope of controls applied is defined with the proposal for each project.

The security plan comes with the proposal.

Let us start with the free digital visibility analysis, then map your systems together during the needs analysis.

Request a free digital visibility analysis