Skip to Content

Security Policy

Last updated: 8 August 2026

At ATESINO GROUP (HONG KONG) LIMITED we regard the protection of our customers information and the safe operation of the machines we deliver as an inseparable part of our commercial activity. This policy explains the information security measures we apply on makinachina.com and our approach to product safety.

1. Purpose and Scope of the Policy

The purpose of this policy is to set out transparently the technical and organisational measures taken to protect the confidentiality, integrity and availability of the information the Company processes.

The policy covers the makinachina.com website and its infrastructure, order and customer management systems, Company employees, and suppliers and service providers processing data on behalf of the Company.

2. Connection Security and Encryption

All traffic between the Site and your browser is encrypted over HTTPS (TLS). Form submissions, login credentials and order data are not transmitted outside an encrypted channel.

On the server side, sensitive data is held on encrypted storage; user passwords are stored using irreversible hashing algorithms and cannot be viewed by Company personnel.

3. Payment Security

The Company does not store or view credit card numbers, expiry dates or CVV codes in its own systems.

Card payments are collected through the infrastructure of licensed payment institutions compliant with PCI DSS, and 3D Secure verification is applied. The Company sees only the approval or rejection status of the transaction and its reference number.

For payments made by bank transfer, please verify that our account details match those shown on our official quotations and invoices. Be cautious of emails containing changes to account numbers; when in doubt, call us to confirm before making the payment.

4. Access Authorisation

The principle of least privilege applies across our systems: each employee can access only the data required to perform their role.

  • Access to administrative interfaces is provided through individual accounts; shared accounts are not used.
  • Multi-factor authentication is applied to critical accounts.
  • Access rights are removed without delay on role change or departure.
  • The authorisation inventory is reviewed regularly.

5. Infrastructure and System Security

Our Site and business applications are hosted in data centres holding security certification.

  • Server and application software is updated as security patches are released.
  • Network traffic is filtered by firewall; management ports are closed to public access.
  • Automated intrusion and anomalous traffic detection together with rate limiting are applied.
  • System and access logs are retained and reviewed regularly.

6. Backup and Business Continuity

Customer, order and content data is backed up at regular intervals; backups are stored encrypted in a location separate from the primary system.

Restore procedures are tested periodically, so that in the event of a failure data can be recovered within an acceptable timeframe.

7. Staff Awareness

Our employees sign a confidentiality undertaking when they join and are required to comply with information security rules.

Regular briefings are provided on phishing attacks, social engineering attempts, strong password practice and correct handling of customer data.

8. Supplier and Partner Security

Agreements containing confidentiality and data protection obligations are signed with logistics companies, customs brokers, payment institutions and software providers processing data on behalf of the Company.

Only the minimum data required to deliver the service is shared with these parties.

9. Protection of Personal Data

Your personal data is processed in accordance with Turkish Law No. 6698 on the Protection of Personal Data and related legislation. Which data is processed for which purpose, and how you may exercise your rights, is explained on the Privacy Policy page; cookie usage is described on the Cookie Policy page.

Data is deleted or anonymised once the purpose of processing and the retention periods required by legislation have expired.

10. Security Incident Response

When a security incident is detected, the following steps are applied: verification of the incident and determination of its scope, isolation of the affected system, closing of the vulnerability, assessment of impact through log review, and implementation of preventive improvements.

Where a personal data breach is involved, notification is made to the individuals concerned and the competent authority within the period required by legislation.

11. Vulnerability Disclosure

If you believe you have identified a security vulnerability on our Site, we ask you to send your findings to admin@makinachina.com.

Our approach when assessing your report: reviewing your finding within a reasonable period, remediating the vulnerability, and staying in contact with you throughout. We ask that reports be sent to us without accessing user data, without disrupting the service and before disclosing the vulnerability publicly.

12. Product and Installation Safety

Alongside information security, the safe operation on site of the machines we deliver forms part of this policy.

  • For the machines we supply, a declaration of conformity and technical file are requested in line with applicable product safety and CE requirements.
  • Machines are delivered together with safety equipment such as protective guarding, emergency stop, interlocking and warning labels.
  • Electrical connection and earthing are checked during installation; safety functions are tested before commissioning.
  • Operator training covers safe working rules, lockout/tagout (LOTO) practice and periodic maintenance requirements.
  • A Turkish operating and maintenance manual is supplied.

Disabling safety equipment has serious consequences both for operator safety and for warranty coverage, and is therefore strongly discouraged.

13. Review of the Policy

This policy is reviewed at least once a year, and additionally whenever a significant change occurs in technology, legislation or business processes. The current version is always published on this page.

14. Contact

For questions and requests regarding security and data protection: