Aydınlatma Metni
6698 sayılı Kişisel Verilerin Korunması Kanunu’nun 10. maddesi uyarınca, ControlAtWork üzerinden yürütülen psikososyal risk değerlendirmesinde kişisel verilerinizin nasıl işlendiği.
Özetle: Yazdıklarınızı yöneticiniz görmez. Ham sohbet metniniz değerlendirme biter bitmez silinir. Kuruma yalnızca en az 10 kişilik gruplar hâlinde toplulaştırılmış göstergeler gider. Kişiye özel kod olmadığı için kimin katıldığı bilgisi hiç üretilmez.
1. Veri sorumlusu kim
Veri sorumlusu, çalıştığınız kurumdur. Değerlendirmeyi başlatan, kapsamını belirleyen ve sonuçlarını kullanan taraf odur.
ControlAtWork — Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. tarafından işletilir — kurumla arasındaki veri işleme sözleşmesi çerçevesinde veri işleyen sıfatıyla hareket eder. Verilerinizi kendi amaçları için kullanmaz, satmaz, reklam veya profilleme amacıyla işlemez ve kurumun talimatı dışında bir işleme yapmaz.
Kurumunuzun veri sorumlusu iletişim bilgileri, sohbete başlarken size gösterilir ve kurumunuzun kendi KVKK aydınlatma metninde yer alır.
2. Hangi veriler işlenir
| Veri | Kaynak | Nitelik |
|---|---|---|
| Firma erişim kodu | Sizin girdiğiniz | Kurumu belirler, sizi belirlemez |
| Oturum kimliği (rastgele üretilen) | Sistem | Kimliğinizle ilişkilendirilmez |
| Sohbet metni | Sizin yazdıklarınız | Özel nitelikli veri içerebilir |
| Yapılandırılmış bulgular (kategori, sıklık, süre) | Sohbetten türetilir | Özel nitelikli |
| Risk göstergeleri ve öneriler | Türetilir | Özel nitelikli |
| Onay kayıtları (ne zaman, neye, hangi metin sürümüne) | Sistem | İspat amaçlı |
| Departman / birim bilgisi | Kurumun tanımı | Raporlamada gruplama için |
Hiçbir koşulda işlenmeyen veriler: din ve mezhep, etnik köken, siyasi görüş, felsefi inanç, cinsel yönelim, sendika üyeliği, ceza mahkûmiyeti, biyometrik ve genetik veri. Bunları sohbette kendiniz anlatsanız dahi sistem tarafından çıkarılmaz ve kayda geçirilmez.
Kamera görüntüsü, ses kaydı, ses tonu analizi ve tuş vuruşu analizi yapılmaz.
3. Hangi amaçla işlenir
- İşyerinde psikososyal risklerin ve işyerinde psikolojik tacize ilişkin göstergelerin tespiti
- İşverenin işçiyi koruma ve psikolojik tacizi önleme yükümlülüğünün (TBK m.417; 6331 sayılı Kanun m.4) yerine getirilmesi
- Size özel, kuruma gitmeyen kişisel bir geri bildirim ve öneri seti sunulması
- Kuruma, kimseyi belirlemeyen toplulaştırılmış bir risk haritası sunulması
- Kriz durumunda uygun destek hatlarına yönlendirme yapılması
- Verilen onayların ispatlanabilir biçimde kayıt altına alınması
Bu veriler; performans değerlendirmesi, terfi, ücretlendirme, disiplin süreci veya iş sözleşmesinin feshi amacıyla işlenmez. Kurumla imzalanan sözleşme bu kullanımı açıkça yasaklar.
4. Hukuki sebep
| İşleme | Hukuki sebep |
|---|---|
| Psikososyal risk göstergelerinin üretilmesi (özel nitelikli veri) | KVKK m.6/3(f) — istihdam, iş sağlığı ve güvenliği ile sosyal güvenliğe ilişkin yükümlülüklerin yerine getirilmesi |
| İşverenin önleme yükümlülüğünün belgelenmesi | KVKK m.5/2(ç) — hukuki yükümlülüğün yerine getirilmesi (TBK m.417, 6331 s. K. m.4) |
| Sohbet metninin yapay zekâ hizmetine gönderilmesi | KVKK m.6/2 ve m.5/1 — açık rızanız |
| Kriz durumunda yönlendirme | Açık rızanız; rıza vermeye fiilen imkân bulunmayan hâllerde KVKK m.5/2(a) — hayati menfaatin korunması |
| Onay kayıtlarının tutulması | KVKK m.5/2(e) — hakkın tesisi ve korunması |
| Sistem güvenliği ve kötüye kullanımın engellenmesi | KVKK m.5/2(f) — meşru menfaat |
Açık rızaya dayanan işlemeler, rıza vermediğinizde yapılmaz ve bu durum sizin aleyhinize hiçbir sonuç doğurmaz. Katılım tamamen isteğe bağlıdır.
5. Kimlere aktarılır
- Kurumunuzun yetkili yöneticilerine: yalnızca toplulaştırılmış göstergeler. Bir kırılım en az 10 kişi içermiyorsa hiç gösterilmez. Yönetici; ham metin, alıntı, kelime bulutu, katılımcı listesi veya katılım sayısı görmez.
- Bulut altyapı sağlayıcısına (Google Cloud / Firebase): veri işleyen sıfatıyla, barındırma amacıyla.
- Yapay zekâ hizmet sağlayıcısına (Google Vertex AI): yalnızca açık rıza verdiyseniz. Sağlayıcı, gönderilen içeriği kendi modellerinin eğitiminde kullanmaz.
- Yetkili kamu kurum ve kuruluşlarına: yalnızca kanunen zorunlu hâllerde ve talebin dayanağı denetlenerek.
Bunların dışında hiçbir üçüncü tarafa aktarım yapılmaz. Analitik, reklam ve ölçümleme araçları sohbet içeriğine erişmez.
6. Yurt dışına aktarım
Veriler Google Cloud’un Frankfurt (europe-west3) bölgesinde işlenir ve saklanır. Aktarım, KVKK m.9 kapsamında; sağlayıcı ile imzalanan standart sözleşme hükümleri ve ek teknik güvenlik tedbirleri esas alınarak gerçekleştirilir. Yapay zekâ hizmeti de aynı bölgede çalıştırılır.
7. Ne kadar süreyle saklanır
| Veri | Süre |
|---|---|
| Ham sohbet metni | Değerlendirme tamamlanır tamamlanmaz silinir. Tamamlanmayan oturumlarda en geç 30 gün. |
| Yapılandırılmış bulgular ve risk göstergeleri | Değerlendirme döneminin bitiminden itibaren 24 ay |
| Toplulaştırılmış kurum raporu | Kurumun saklama politikasına göre, azami 5 yıl |
| Onay kayıtları | Zamanaşımı süresince (10 yıl), ispat amacıyla |
Süre dolduğunda veriler silinir veya geri döndürülemez biçimde anonim hâle getirilir.
8. Otomatik değerlendirme ve itiraz
Anlattıklarınız, otomatik bir sistem tarafından değerlendirilir ve bu değerlendirmeden göstergeler ile öneriler üretilir. Bu değerlendirme hakkınızda hukuki sonuç doğuran veya sizi önemli ölçüde etkileyen bir karar üretmez; bir tanı, teşhis veya sınıflandırma değildir ve tek başına hiçbir idari işleme dayanak yapılamaz.
KVKK m.11/1(g) uyarınca, münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç doğduğunu düşünüyorsanız buna itiraz edebilir ve değerlendirmenin bir insan tarafından incelenmesini isteyebilirsiniz.
9. Haklarınız
KVKK m.11 uyarınca:
- Kişisel verilerinizin işlenip işlenmediğini öğrenme
- İşlenmişse buna ilişkin bilgi talep etme
- İşlenme amacını ve amaca uygun kullanılıp kullanılmadığını öğrenme
- Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme
- Eksik veya yanlış işlenmişse düzeltilmesini isteme
- Silinmesini veya yok edilmesini isteme
- Düzeltme, silme ve yok etme işlemlerinin aktarıldığı üçüncü kişilere bildirilmesini isteme
- Münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç çıkmasına itiraz etme
- Kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme
Taleplerinizi kurumunuzun veri sorumlusu iletişim kanalına iletebilirsiniz. Talep en geç 30 gün içinde sonuçlandırılır. Sonuçtan memnun kalmazsanız Kişisel Verileri Koruma Kurulu’na şikâyette bulunma hakkınız saklıdır.
Sohbet oturumunuz kimliğinizle ilişkilendirilmediği için, belirli bir oturuma ilişkin talepte bulunabilmeniz adına sohbet sonunda size bir sonuç kodu verilir. Bu kodu saklamanız, ileride o oturumun silinmesini talep edebilmeniz için gereklidir.
10. Açık rıza ve geri çekme
Açık rıza gerektiren her işleme için ayrı onay istenir; onaylar tek bir kutuda birleştirilmez. Her onayı diğerlerinden bağımsız olarak verebilir ve istediğiniz an geri çekebilirsiniz. Geri çekme, o ana kadar yapılmış işlemeyi geçmişe etkili olarak geçersiz kılmaz; ancak geri çekme anından itibaren o işleme durdurulur ve talebiniz hâlinde ilgili veriler silinir.
Hangi onayı ne zaman ve metnin hangi sürümüne verdiğiniz kayıt altına alınır; bu kaydı talep ettiğinizde size sunarız.
Privacy Notice
How your personal data is processed in the psychosocial risk assessment carried out through ControlAtWork, under Article 10 of Turkish Data Protection Law No. 6698 (KVKK).
In short: Your manager never sees what you write. Your raw conversation is deleted as soon as the assessment completes. The organisation receives only indicators aggregated over groups of at least 10 people. Because there are no personal codes, the information of who took part is never created.
1. Who the controller is
The data controller is the organisation you work for. It initiates the assessment, defines its scope and uses its results.
ControlAtWork — operated by Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. — acts as a data processor under a data processing agreement with that organisation. We do not use your data for our own purposes, do not sell it, do not process it for advertising or profiling, and do not process it outside the organisation’s instructions.
Your organisation’s controller contact details are shown to you when the conversation begins and appear in its own privacy notice.
2. What data is processed
| Data | Source | Nature |
|---|---|---|
| Company access code | Entered by you | Identifies the organisation, not you |
| Session identifier (randomly generated) | System | Not linked to your identity |
| Conversation text | What you write | May contain special category data |
| Structured findings (category, frequency, duration) | Derived from the conversation | Special category |
| Risk indicators and suggestions | Derived | Special category |
| Consent records (when, to what, which text version) | System | Kept as evidence |
| Department / unit | Defined by the organisation | For grouping in reports |
Never processed, under any circumstances: religion or denomination, ethnic origin, political opinion, philosophical belief, sexual orientation, trade union membership, criminal convictions, biometric and genetic data. Even if you mention these yourself, the system does not infer or record them.
There is no camera footage, audio recording, voice-tone analysis or keystroke analysis.
3. For what purposes
- Identifying psychosocial risks and indicators of psychological harassment at work
- Meeting the employer’s duty to protect employees and prevent harassment (Turkish Code of Obligations Art. 417; Occupational Health and Safety Law No. 6331 Art. 4)
- Giving you personal feedback and suggestions that are not shared with the organisation
- Giving the organisation an aggregated risk map that identifies no one
- Referring you to appropriate support lines in a crisis
- Recording the consents you gave in a demonstrable form
This data is not processed for performance appraisal, promotion, pay, disciplinary process or termination of employment. The contract with the organisation expressly prohibits such use.
4. Legal basis
| Processing | Legal basis |
|---|---|
| Producing psychosocial risk indicators (special category data) | KVKK Art. 6/3(f) — obligations in employment, occupational health and safety, and social security |
| Documenting the employer’s preventive duty | KVKK Art. 5/2(ç) — compliance with a legal obligation (TCO Art. 417; Law No. 6331 Art. 4) |
| Sending conversation text to the AI service | KVKK Art. 6/2 and 5/1 — your explicit consent |
| Referral in a crisis | Your explicit consent; where consent cannot in fact be obtained, KVKK Art. 5/2(a) — protection of vital interests |
| Keeping consent records | KVKK Art. 5/2(e) — establishment and protection of a right |
| System security and abuse prevention | KVKK Art. 5/2(f) — legitimate interest |
Processing that relies on explicit consent does not take place if you do not consent, and this has no adverse consequence for you. Participation is entirely voluntary.
5. Who it is shared with
- Authorised managers in your organisation: aggregated indicators only. A breakdown covering fewer than 10 people is not shown at all. Managers never see raw text, quotes, word clouds, participant lists or participation counts.
- The cloud infrastructure provider (Google Cloud / Firebase): as a processor, for hosting.
- The AI service provider (Google Vertex AI): only if you gave explicit consent. The provider does not use the submitted content to train its own models.
- Competent public authorities: only where legally required, and after the basis of the request has been checked.
No other third party receives the data. Analytics, advertising and measurement tools have no access to conversation content.
6. International transfers
Data is processed and stored in Google Cloud’s Frankfurt (europe-west3) region. Transfers are made under KVKK Art. 9, on the basis of standard contractual clauses agreed with the provider together with supplementary technical safeguards. The AI service runs in the same region.
7. How long it is kept
| Data | Retention |
|---|---|
| Raw conversation text | Deleted as soon as the assessment completes. For sessions never completed, within 30 days at the latest. |
| Structured findings and risk indicators | 24 months from the end of the assessment period |
| Aggregated organisational report | Per the organisation’s retention policy, maximum 5 years |
| Consent records | For the limitation period (10 years), as evidence |
At the end of the period, data is deleted or irreversibly anonymised.
8. Automated assessment and objection
What you describe is assessed by an automated system, which produces indicators and suggestions. That assessment does not produce any decision with legal effect or similarly significant effect on you; it is not a diagnosis or a classification, and it cannot on its own form the basis of any administrative action.
Under KVKK Art. 11/1(g), if you believe an adverse outcome has arisen from analysis carried out solely by automated means, you may object to it and request that the assessment be reviewed by a person.
9. Your rights
Under KVKK Art. 11 you may:
- Learn whether your personal data is being processed
- Request information if it has been processed
- Learn the purpose of processing and whether it is used accordingly
- Know the third parties to whom it is transferred, at home or abroad
- Request rectification if it is incomplete or inaccurate
- Request erasure or destruction
- Request that rectification, erasure and destruction be notified to third parties to whom the data was transferred
- Object to an adverse outcome arising from analysis solely by automated means
- Claim compensation for damage caused by unlawful processing
Send requests to your organisation’s controller contact. A request is answered within 30 days at the latest. If you are not satisfied with the outcome, you retain the right to complain to the Turkish Personal Data Protection Board.
Because your session is not linked to your identity, you are given a result code at the end of the conversation so that you can make a request about that particular session. Keep this code if you may want that session deleted later.
10. Consent and withdrawal
Consent is requested separately for each processing activity that requires it; consents are never bundled into a single checkbox. You may give each one independently and withdraw it at any time. Withdrawal does not retroactively invalidate processing already carried out, but that processing stops from the moment of withdrawal and, if you ask, the relevant data is deleted.
Which consent you gave, when, and to which version of the text is recorded; we provide that record on request.