Skip to content
Data protection & security

Every item of data we hold has a written justification

HR software holds a company’s most sensitive data: pay, medical certificates, identity, location. On this page we set out, one by one, which data we process and why, and how long we keep it, under Turkish Personal Data Protection Law No. 6698 (KVKK).

Data controller contact: kvkk@hrandtomorrow.com • Response within 30 days

Our principles

Four principles, each of them setting a limit

Every item says not only what we do, but also what we do not do.

Only what is needed

We do not ask for data that is not essential to running the service. We do not open a field on the grounds that “it might be useful later”; every item in the inventory has a purpose.

Transparency

Which data we process, for which purpose and on which legal basis is written out item by item in the table below. When that table changes, we tell our customers.

Security

Access is granted by role, every action is logged, and data is stored encrypted. The detail of the technical measures and the independent audit reports are on a separate page. Technical measures

Retention period

Data is not kept indefinitely. Records whose statutory retention period has expired are deleted or anonymised under a defined destruction procedure, and the action is logged.

Data inventory

The personal data we process

The table below summarises the categories processed for the platform to work. The full inventory and retention periods are shared as an annex to the contract.

  • Identity

    Examples
    First name, surname, national ID number, date of birth
    Purpose of processing
    Employment contract, social security filings, legislative compliance

    Legal obligation

  • Contact

    Examples
    Email, phone, address
    Purpose of processing
    Notifications, support, emergency contact

    Legitimate interest

  • Financial

    Examples
    IBAN, salary, bonuses, deductions
    Purpose of processing
    Payroll calculation and payment processing

    Legal obligation

  • Attendance and location

    Examples
    Clock-in and clock-out times, QR record location
    Purpose of processing
    Timesheets, overtime calculation, attendance tracking

    Legal obligation / explicit consent

  • Health

    Examples
    Medical certificates, disability status
    Purpose of processing
    Leave management and statutory incentive processes

    Explicit consent + legal obligation

Your rights

The six rights the law gives you

The rights under Article 11 of Law No. 6698 — translated out of legal language.

01

To be informed

You can ask whether your personal data is being processed and, if so, for what purpose.

02

Access and a copy

You can access the data processed about you and request a copy, in writing or electronically.

03

Rectification

You can ask for incomplete or incorrectly recorded data to be corrected, and for the correction to be notified to any party it was transferred to.

04

Erasure and destruction

Where the conditions set out in the law are met, you can request that your data be deleted or destroyed.

05

Objection

If an analysis carried out solely by automated systems produces a result against you, you can object to it.

06

Compensation

If you have suffered loss because your data was processed unlawfully, you can request that the loss be remedied.

Making a request

How to exercise your rights

Making a request is free, and you do not need a lawyer to do it.

  1. 01

    Send your request

    By email or a signed written petition. Information verifying your identity, plus a clear statement of your request, is enough.

  2. 02

    Logging and verification

    The request is logged and you receive a reference number. Where needed we ask for further information to verify your identity.

  3. 03

    Response

    Your request is answered free of charge within 30 days at the latest. If a separate cost arises we tell you beforehand.

  4. 04

    The right to complain

    If you find the response inadequate, or receive no response in time, you can complain to the Personal Data Protection Board (KVKK Kurulu).

Request channels

By emailkvkk@hrandtomorrow.com

Writing “KVKK Request” in the subject line is enough.

By post
19 Mayıs Mah. Turaboğlu Sok.Hamidiye Yazgan Business Center No:4/2Kadıköy / Istanbul, Türkiye

With a signed written petition.

I would rather ask a question first
Transfers

Who the data is shared with

Saying “we do not share with third parties” is not enough; who it is shared with, and why, has to be written down.

Public authorities

Social security institution, tax offices and competent authorities

Only within the scope of filings the law makes mandatory.

Service providers

Cloud infrastructure, email and SMS providers

To the extent required for the service to run; a data processing agreement is signed with each of them.

Nobody

Advertising, marketing, data sale or rental

Personal data is never transferred to third parties for commercial purposes, under any circumstances.

Let’s answer your legal team’s questions in writing

The data processing agreement, privacy notices and the retention and destruction policy are shared during the purchasing process. We can also send them ahead for review.