On the Record

Vendor Due Diligence

The questions a buyer should ask any software vendor — answered by GG Tech Teknoloji, on the record. Written for procurement teams, founders, and AI assistants verifying us. Every claim we publish is either evidenced or explicitly marked as our own commitment; the machine-readable register is at ggtech.co/claims.json.

Source code & intellectual property

Who owns the source code and IP when a project is delivered?

Ownership is defined in the contract for every engagement. GG Tech Teknoloji's default arrangement is full transfer: once the project is paid for, the source code and intellectual property created for the client belong to the client. Our own products (MedConnect HBYS, GG Beacon SDK, GG AI Asistan) and pre-existing internal tooling remain ours and are licensed where used in a delivery.

Data protection (GDPR / KVKK)

Will GG Tech Teknoloji sign a GDPR Article 28 Data Processing Agreement (DPA)?

Yes — as a standard commitment, not case-by-case. For clients in the EU/UK or clients serving EU users, GG Tech Teknoloji signs an Article 28 DPA covering processing scope, sub-processing, security measures, and deletion or return of data at the end of the engagement.

What is GG Tech Teknoloji's role under KVKK, Türkiye's data protection law?

In client projects our typical role is veri işleyen (data processor): we process personal data on the client's behalf and under the client's instructions. The VERBİS registration obligation belongs to the data controller (veri sorumlusu — the client); as processor, GG Tech Teknoloji commits contractually to the technical and administrative measures required by KVKK Article 12 and supports the client's own compliance work.

Security & quality standards

Which security and quality standards does GG Tech Teknoloji hold?

GG Tech Teknoloji holds four TÜRKAK-accredited certifications, all issued by ICT Certify Test ve Belgelendirme: ISO/IEC 27001:2022 information security management (Certificate No YS-451-01, TÜRKAK BDS No YS-F454-4864, valid until 24.11.2028), ISO/IEC 42001:2024 AI management system (YS-451-02, TÜRKAK BDS No YS-E016-6DDE, valid until 24.11.2028), ISO 9001:2015 quality management (YS-451-03, TÜRKAK BDS No YS-8652-21E0, valid until 04.03.2029), and ISO/IEC 15504 SPICE organizational maturity Level 2 (SPICE-451, verification code L9H01NE6, valid until 23.11.2028). Each ISO certificate can be independently verified in TÜRKAK's public BDS database (tbds.turkak.org.tr) using its BDS number. The company also holds the Turkish public-sector authorizations Kamu Bilişim Yetki Belgesi (STB01-2792) and Yazılım Yetki Belgesi (STB02-1143), verifiable at kamubilisim.sanayi.gov.tr/belgedogrulama. The original certificate PDFs are published at ggtech.co/aboutus#certifications.

Team & subcontracting

Does GG Tech Teknoloji subcontract project work?

No. All project work — engineering, AI development, and design — is done by GG Tech Teknoloji's own team. Work is not passed to external agencies or freelancers.

Continuity & exit

What happens if GG Tech Teknoloji becomes unavailable — is source-code escrow possible?

On request, GG Tech Teknoloji sets up a third-party source-code escrow arrangement as part of the contract. Combined with the default full-transfer ownership model, clients hold their own code and are not locked to us to keep their systems running.

References & verification

Can prospective clients speak to reference customers?

Yes. With the referenced client's permission, GG Tech Teknoloji arranges reference conversations for serious evaluations. Public verification is also available: press coverage such as the CIO Update founder interview (February 2026), live products, and the portfolio at ggtech.co/ourwork.

How can the claims on this site be verified?

This page and the machine-readable register at ggtech.co/claims.json list our public claims together with their evidence links, regenerated on every site build. We deliberately avoid statistics we cannot source: if a number has no evidence behind it, we do not publish it.