Skip to content
HEM Bilişim
How we work

We build and hand over — we don't write a report and leave

We run every engagement through the same five phases. The aim is to leave capability behind rather than dependency, which is why documentation and training are part of the delivery.

The model

Five phases

How long each phase takes depends on the size of the organisation and its current state; the order does not change.

Discovery

We map the current state: which systems exist, which data is processed, what you have and what is missing. This phase can start with the free initial assessment.

Output of this phase: Current state note and priority ordering

Scope and schedule

We write down what will be done, in what order and when it will be delivered. What is left out of scope is written down too — so no interpretation gap opens later.

Output of this phase: Scope document, delivery schedule and responsibility matrix

Implementation

Inventory, policy, controls and, where needed, software go into operation. We review each delivery together rather than saving it all for the end.

Output of this phase: A working system, the document set and the record-keeping arrangement

Handover and training

We transfer the arrangement to the people who will operate it. Documentation and training are part of the delivery, not an extra.

Output of this phase: Usage documentation and training record

Operational support

Optional. Periodic review, tracking changes in legislation, preparation before an audit, and support during a breach.

Output of this phase: Periodic status report and action list

Principles

Setting expectations

We write down how we work up front so both sides expect the same thing.

One point of contact

You do not chase separate people for compliance, software and security. There is one owner for the whole engagement, responsible for the whole.

Every delivery in writing

We do not proceed on verbal agreement. What was delivered, what is out of scope and what comes next is written down in every phase.

Capability stays with you

The goal is for your own team to be able to operate what we build. Source code, documentation and configuration stay with you.

Out-of-scope work is never a surprise

When a need arises outside the scope, we discuss it first. No line item appears without warning.

Both sides

Four things we need from you

What sets the pace is usually not the consultant but how quickly information comes out of the organisation. We say so up front so that it is not a surprise later.

A single point of contact

One person on your side who gathers the decisions. Having to route every question to a different unit stretches the work out.

Short sessions with each unit

An inventory does not come together at a desk. Half an hour per unit is usually enough, but those sessions have to make it onto a calendar.

The documents you already have

Whatever an earlier consultancy left behind, contracts, system lists. Incomplete or out of date is fine; assuming they do not exist is not.

Someone who can decide

Retention periods, narrowing access rights and disposal all need decisions. Knowing who makes them is the most critical part of the work.

On timelines

Phase durations vary with the size of the organisation, the number of systems and the current state. We give a concrete schedule only after the discovery phase; we do not promise a blanket timeline.

What comes next

If you want to see where you stand before discussing scope, the check is free; if the scope is already clear, go straight to the packages.

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation