Gizlilik Politikası ve Aydınlatma Metni
HarmoniQ — Son güncelleme: 13 Temmuz 2026
1. Veri Sorumlusu
HarmoniQ; puantaj (giriş-çıkış / PDKS), kapı geçiş, görev, denetim, form ve raporlama özellikleri sunan bir saha ve iş gücü yönetimi uygulamasıdır. 6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") kapsamında kişisel verileriniz, QUALİS TEKNOLOJİ LİMİTED ŞİRKETİ ("QUALİS") — Muallimköy Mah. Deniz Cad. No: 143/5/70, Gebze / Kocaeli, Türkiye — tarafından aşağıda açıklanan kapsamda işlenmektedir.
2. Rollerimiz
HarmoniQ'yu çoğunlukla işvereniniz ("Müşteri") aracılığıyla kullanırsınız. Puantaj ve görev kayıtları gibi çalışan verilerinin işlenme amaç ve yöntemlerini işvereniniz belirler; bu kayıtlar bakımından veri sorumlusu işvereninizdir ve QUALİS, veri işleyen sıfatıyla işverenin talimatları doğrultusunda hareket eder. Hizmetin işletilmesi (kullanıcı hesapları, güvenlik, bildirimler, çökme kayıtları) bakımından ise QUALİS veri sorumlusudur. İşvereninizin işleme faaliyetlerine ilişkin sorularınız için işvereninizin insan kaynakları birimine başvurabilirsiniz.
3. İşlenen Kişisel Veriler
- Kimlik ve hesap bilgileri: ad, soyad, personel kodu, kurumsal e-posta adresi, parola ve şirket / mağaza / bölüm atamanız.
- Puantaj (PDKS) verileri: giriş-çıkış zamanları; giriş-çıkış anındaki GPS koordinatlarınız; mola süreleri. Konum bilgisi, atandığınız iş yerinde bulunduğunuzun doğrulanması için zorunludur ve yalnızca giriş-çıkış veya benzeri konuma dayalı bir işlem yaptığınız anda alınır. Konum verileriniz yalnızca kendi sunucularımızda işlenir ve hiçbir üçüncü taraf hizmete gönderilmez. Uygulama konumunuzu sürekli olarak izlemez; konum verisi hiçbir şekilde reklam amacıyla kullanılmaz.
- Kapı geçiş verileri: QR kod ile giriş-çıkış kayıtları, zaman damgaları ve mevcudiyet durumu.
- Görev ve form içerikleri: görev, denetim ve formları doldururken eklediğiniz yanıtlar, fotoğraflar, videolar (ses içerebilir) ve belgeler.
- Cihaz ve teknik veriler: cihaz modeli ve işletim sistemi, uygulama sürümü, IP adresi, anlık bildirim (push) jetonu, çökme ve tanılama kayıtları ile cihaz bütünlüğü sinyalleri (örneğin cihazın root'lu / jailbreak'li olup olmadığı).
- Biyometrik giriş: Face ID / parmak izi ile girişi etkinleştirirseniz biyometrik doğrulama tamamen cihazınızda, işletim sisteminiz tarafından yapılır. Biyometrik verileriniz QUALİS'e hiçbir şekilde iletilmez ve tarafımızca saklanmaz.
Reklam amacıyla veri toplamayız, reklam veya pazarlama SDK'ları kullanmayız, pazarlama profili oluşturmayız ve kişisel verilerinizi satmayız.
4. İşleme Amaçları ve Hukuki Sebepler
Kişisel verileriniz; işvereniniz adına puantaj takibi ve raporlamanın yürütülmesi, iş yerlerinde kapı geçiş kontrolünün sağlanması, görev, denetim ve form süreçlerinin yürütülmesi ve belgelenmesi, vardiya, görev ve duyurulara ilişkin bildirimlerin gönderilmesi, Hizmetin güvenliğinin sağlanması (kimlik doğrulama, cihaz bütünlüğü kontrolleri, çökme tanılama), destek sunulması ve hukuki yükümlülüklerin yerine getirilmesi amaçlarıyla işlenir.
Hukuki sebepler, KVKK'nın 5. maddesi uyarınca; sözleşmenin kurulması ve ifası, hukuki yükümlülüğün yerine getirilmesi ve meşru menfaattir. Mevzuatın gerektirdiği hâllerde açık rızanıza başvurulur.
5. Kişisel Verilerin Aktarılması
- İşvereniniz: yukarıda sayılan iş gücü verileri (puantaj, kapı geçiş, görev, form, rapor) işvereninize ve yetkilendirdiği personele sunulur.
- Hizmet sağlayıcılar: Google LLC — anlık bildirim, oturum açma altyapısı ve çökme raporlama (Firebase / Crashlytics); barındırma / altyapı sağlayıcıları.
- Yetkili kurumlar: mevzuat uyarınca talep edilmesi hâlinde yetkili kamu kurum ve kuruluşları.
- Devir hâlleri: birleşme, devralma veya malvarlığı devri hâlinde, bu Politikaya uymayı sürdürmek kaydıyla ilgili halefe aktarım yapılabilir.
Kişisel verileriniz reklamcılara, reklam ağlarına, veri simsarlarına veya pazarlama ortaklarına aktarılmaz; konum verileriniz hiçbir üçüncü taraf hizmete gönderilmez.
6. Yurt Dışına Aktarım
Yukarıda belirtilen bazı hizmet sağlayıcıların (örneğin Google) sunucuları yurt dışında bulunabilir. Bu aktarımlar KVKK'nın 9. maddesinde öngörülen şartlar çerçevesinde gerçekleştirilir.
7. Saklama Süresi
Kişisel verileriniz, kullanıcı hesabınız ve işvereninizin bizimle olan hizmet sözleşmesi devam ettiği sürece ve sonrasında ilgili mevzuatta öngörülen saklama ve zamanaşımı süreleri (örneğin iş, vergi ve ticaret mevzuatı) boyunca saklanır. Bu sürelerin sonunda KVKK'ya uygun olarak silinir, yok edilir veya anonim hâle getirilir.
8. Veri Güvenliği
Veriler sunucularımıza TLS ile şifreli bağlantılar üzerinden iletilir; erişim kontrolleri, rol bazlı yetkilendirme ve cihaz bütünlüğü kontrolleri uygulanır. Hiçbir iletim veya saklama yönteminin tamamen güvenli olmadığını, mutlak güvenlik taahhüt edilemeyeceğini hatırlatırız.
9. KVKK Kapsamındaki Haklarınız
KVKK'nın 11. maddesi uyarınca; kişisel verilerinizin işlenip işlenmediğini öğrenme, işlenmişse buna ilişkin bilgi talep etme, işlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme, yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme, eksik veya yanlış işlenmişse düzeltilmesini isteme, silinmesini veya yok edilmesini isteme, düzeltme ve silme işlemlerinin aktarılan üçüncü kişilere bildirilmesini isteme, münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme ve kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme haklarına sahipsiniz.
Başvurularınızı info@qualisict.com adresine e-posta ile veya Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ'e uygun şekilde yukarıdaki posta adresimize iletebilirsiniz. Başvurular en geç 30 gün içinde sonuçlandırılır. İşvereninizin veri sorumlusu olduğu işleme faaliyetlerine ilişkin talepler işvereninize yönlendirilebilir.
10. Değişiklikler
Bu Politika, Hizmeti doğru şekilde yansıtmaya devam etmesi için güncellenebilir. Mevzuat aksini gerektirmedikçe, önemli değişiklikler yürürlüğe girmeden önce Hizmet üzerinden bilgilendirilirsiniz. Değişikliklerin yürürlüğe girmesinden sonra Hizmeti kullanmaya devam etmeniz, güncel Politikayı kabul ettiğiniz anlamına gelir.
11. İletişim
QUALİS TEKNOLOJİ LİMİTED ŞİRKETİ
Muallimköy Mah. Deniz Cad. No: 143/5/70, Gebze / Kocaeli, Türkiye
info@qualisict.com
Privacy Policy
HarmoniQ — Last updated: July 13, 2026
1. Who We Are
HarmoniQ is a workforce and field-operations application — covering attendance (check-in/check-out), door access, tasks, audits, forms and reports — provided by QUALİS TEKNOLOJİ LİMİTED ŞİRKETİ ("QUALİS", "we", "us"), Muallimköy Mah. Deniz Cad. No: 143/5/70, Gebze / Kocaeli, Türkiye. This Privacy Policy explains what personal data the HarmoniQ mobile application and its related services (together, the "Service") collect, how that data is used and shared, and the rights you have.
2. Our Role
Most people use HarmoniQ through their employer (our "Customer"). Your employer decides why and how workforce data — such as attendance and task records — is processed, and is the data controller of those records; QUALİS processes them on your employer's documented instructions. For the operation of the Service itself (user accounts, security, notifications, crash diagnostics), QUALİS acts as the data controller within the meaning of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). For questions about your employer's processing, please contact your employer's human resources department.
3. What We Collect
- Account and identity data: first and last name, employee code, corporate e-mail address, password, and your company / store / department assignment.
- Attendance (PDKS) data: check-in and check-out times; your GPS coordinates at the moment of check-in/check-out; break durations. Location is required to verify attendance at your assigned workplace and is captured only when you perform an attendance or similar location-based action. Location data is processed on our own servers and is not sent to any third-party service. The app does not continuously track your location, and location data is never used for advertising.
- Door access data: QR-code based entry and exit events, timestamps and presence status.
- Task and form content: answers, photographs, videos (which may include sound) and documents that you capture or attach while completing tasks, audits and forms.
- Device and technical data: device model and operating system, app version, IP address, push-notification token, crash and diagnostic reports, and device-integrity signals (for example, whether the device appears rooted or jailbroken).
- Biometric sign-in: if you enable Face ID / fingerprint sign-in, biometric verification is performed entirely on your device by your operating system. Your biometric data is never transmitted to, or stored by, QUALİS.
We do not collect data for advertising, we do not use advertising or marketing SDKs, we do not build marketing profiles, and we do not sell personal data.
4. Why We Process Your Data
We process personal data to: operate attendance tracking and reporting for your employer; control door access at workplaces; assign, complete and document tasks, audits and forms; send push notifications about shifts, tasks and announcements; keep the Service secure (authentication, device-integrity checks, crash diagnostics); provide support; and comply with legal obligations.
Legal bases under Article 5 of the KVKK are the establishment and performance of a contract, compliance with legal obligations, and our or your employer's legitimate interests; where the law requires it, we rely on your explicit consent. Where the EU General Data Protection Regulation ("GDPR") applies, the corresponding bases are Article 6(1)(b), (c) and (f) GDPR.
5. Who We Share Data With
- Your employer: the workforce data described above (attendance, door access, tasks, forms, reports) is made available to your employer and its authorised personnel.
- Service providers: Google LLC — Firebase services for push notifications, sign-in infrastructure and crash reporting (Crashlytics); and hosting / infrastructure providers that store and serve our systems.
- Authorities: where disclosure is required by applicable law, regulation or a binding request from a competent authority.
- Business transfers: in a merger, acquisition or asset transfer, data may be transferred to the successor, which must continue to honour this Policy.
We do not share your personal data with advertisers, ad networks, data brokers or marketing partners, and your location data is not sent to any third-party service.
6. International Transfers
Some service providers named above (for example Google) may process data on servers located outside Türkiye. Such transfers are carried out within the framework of Article 9 of the KVKK and, where the GDPR applies, the safeguards in Chapter V of the GDPR.
7. How Long We Keep Data
We keep personal data for the duration of your user account and your employer's service agreement with us, and thereafter for as long as required by applicable statutory retention and limitation periods (for example under Turkish labour, tax and commercial legislation). When these periods expire, data is deleted, destroyed or anonymised in accordance with the KVKK.
8. Security
Data is transmitted to our servers over TLS-encrypted connections, and we apply access controls, role-based authorisation and device-integrity checks. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; we work to protect your data with measures appropriate to the risk.
9. Your Rights
Under Article 11 of the KVKK you have the right to: learn whether your personal data is processed; request information about that processing; learn its purpose and whether data is used in line with it; know the third parties to whom data is transferred; request rectification of incomplete or inaccurate data; request erasure or destruction of data; request that rectification or erasure be notified to third-party recipients; object to results produced exclusively by automated analysis; and claim compensation for damage caused by unlawful processing.
Where the GDPR applies, you additionally have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority.
You can exercise these rights by e-mailing info@qualisict.com or writing to our address above. We respond within the statutory period (at the latest 30 days under the KVKK). For processing controlled by your employer, we may forward your request to, or ask you to contact, your employer.
10. Changes to This Policy
We may update this Policy so that it continues to reflect the Service accurately. Unless the law requires otherwise, we will notify you through the Service before material changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
11. Contact
QUALİS TEKNOLOJİ LİMİTED ŞİRKETİ
Muallimköy Mah. Deniz Cad. No: 143/5/70, Gebze / Kocaeli, Türkiye
info@qualisict.com
