Every item of data we hold has a written justification
HR software holds a company’s most sensitive data: pay, medical certificates, identity, location. On this page we set out, one by one, which data we process and why, and how long we keep it, under Turkish Personal Data Protection Law No. 6698 (KVKK).
Data controller contact: kvkk@hrandtomorrow.com • Response within 30 days
Four principles, each of them setting a limit
Every item says not only what we do, but also what we do not do.
Only what is needed
We do not ask for data that is not essential to running the service. We do not open a field on the grounds that “it might be useful later”; every item in the inventory has a purpose.
Transparency
Which data we process, for which purpose and on which legal basis is written out item by item in the table below. When that table changes, we tell our customers.
Security
Access is granted by role, every action is logged, and data is stored encrypted. The detail of the technical measures and the independent audit reports are on a separate page. Technical measures
Retention period
Data is not kept indefinitely. Records whose statutory retention period has expired are deleted or anonymised under a defined destruction procedure, and the action is logged.
The personal data we process
The table below summarises the categories processed for the platform to work. The full inventory and retention periods are shared as an annex to the contract.
| Data category | Examples | Purpose of processing | Legal basis |
|---|---|---|---|
| Identity | First name, surname, national ID number, date of birth | Employment contract, social security filings, legislative compliance | Legal obligation |
| Contact | Email, phone, address | Notifications, support, emergency contact | Legitimate interest |
| Financial | IBAN, salary, bonuses, deductions | Payroll calculation and payment processing | Legal obligation |
| Attendance and location | Clock-in and clock-out times, QR record location | Timesheets, overtime calculation, attendance tracking | Legal obligation / explicit consent |
| Health | Medical certificates, disability status | Leave management and statutory incentive processes | Explicit consent + legal obligation |
Identity
- Examples
- First name, surname, national ID number, date of birth
- Purpose of processing
- Employment contract, social security filings, legislative compliance
Legal obligation
Contact
- Examples
- Email, phone, address
- Purpose of processing
- Notifications, support, emergency contact
Legitimate interest
Financial
- Examples
- IBAN, salary, bonuses, deductions
- Purpose of processing
- Payroll calculation and payment processing
Legal obligation
Attendance and location
- Examples
- Clock-in and clock-out times, QR record location
- Purpose of processing
- Timesheets, overtime calculation, attendance tracking
Legal obligation / explicit consent
Health
- Examples
- Medical certificates, disability status
- Purpose of processing
- Leave management and statutory incentive processes
Explicit consent + legal obligation
The six rights the law gives you
The rights under Article 11 of Law No. 6698 — translated out of legal language.
To be informed
You can ask whether your personal data is being processed and, if so, for what purpose.
Access and a copy
You can access the data processed about you and request a copy, in writing or electronically.
Rectification
You can ask for incomplete or incorrectly recorded data to be corrected, and for the correction to be notified to any party it was transferred to.
Erasure and destruction
Where the conditions set out in the law are met, you can request that your data be deleted or destroyed.
Objection
If an analysis carried out solely by automated systems produces a result against you, you can object to it.
Compensation
If you have suffered loss because your data was processed unlawfully, you can request that the loss be remedied.
How to exercise your rights
Making a request is free, and you do not need a lawyer to do it.
- 01
Send your request
By email or a signed written petition. Information verifying your identity, plus a clear statement of your request, is enough.
- 02
Logging and verification
The request is logged and you receive a reference number. Where needed we ask for further information to verify your identity.
- 03
Response
Your request is answered free of charge within 30 days at the latest. If a separate cost arises we tell you beforehand.
- 04
The right to complain
If you find the response inadequate, or receive no response in time, you can complain to the Personal Data Protection Board (KVKK Kurulu).
Request channels
With a signed written petition.
Who the data is shared with
Saying “we do not share with third parties” is not enough; who it is shared with, and why, has to be written down.
Public authorities
Social security institution, tax offices and competent authorities
Only within the scope of filings the law makes mandatory.
Service providers
Cloud infrastructure, email and SMS providers
To the extent required for the service to run; a data processing agreement is signed with each of them.
Nobody
Advertising, marketing, data sale or rental
Personal data is never transferred to third parties for commercial purposes, under any circumstances.
Let’s answer your legal team’s questions in writing
The data processing agreement, privacy notices and the retention and destruction policy are shared during the purchasing process. We can also send them ahead for review.
