Kullanım Koşulları ve Hizmet Sözleşmesi
ControlAtWork hizmetini kullanan çalışanlar ve kurumlar için geçerli koşullar. Türkçe metin asıldır.
Kısaca: Katılım gönüllüdür ve kimlik istenmez. Yazdığınız metin değerlendirme biter bitmez silinir. Kurumunuz yalnızca 10 kişiden az olmayan gruplara ait toplu sayılar görür — kimin katıldığını göremez, çünkü bu bilgi hiç üretilmez. Kurum, çıktıları hiçbir çalışan hakkında terfi, ücret, disiplin veya işten çıkarma kararında kullanamaz; bu bir taahhüt değil, sözleşmenin esaslı unsurudur.
1. Taraflar ve tanımlar
1.1 Hizmet sağlayıcı. ControlAtWork, aşağıda bilgileri yer alan Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. («Cimedya», «Platform», «Biz») tarafından işletilen bir yazılım hizmetidir.
| Ticaret Unvanı | Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. |
|---|---|
| Vergi Dairesi / No | Maltepe V.D. — 2100357903 |
| Tebligat Adresi | Söğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara |
| E-posta | info@oculawork.com |
1.2 Kurum. Hizmeti kendi çalışanlarına sunmak üzere Cimedya ile abonelik ilişkisi kuran tüzel kişi.
1.3 Tanımlar.
- Platform: işyerinde psikososyal risk ve psikolojik taciz (mobbing) göstergelerinin değerlendirilmesine yönelik yazılım hizmeti.
- OwO: katılımcıyla yazılı sohbet yürüten yapay zekâ bileşeni.
- Katılımcı: Platformu erişim kodu ile veya misafir modunda kullanan gerçek kişi.
- Erişim kodu: kuruma tahsis edilen tek bir koddur; kişiye özgü değildir ve bir kimlik doğrulama aracı değildir.
- Misafir modu: hiçbir kod girilmeden, hiçbir kuruma bağlanmadan yapılan kullanım.
- Ham sohbet metni: katılımcının yazdığı serbest metin ile OwO’nun ürettiği yanıtların tamamı.
- Bulgu: ham sohbet metninden türetilen, yapılandırılmış ve sayısallaştırılmış gösterge.
- Toplulaştırılmış çıktı: kuruma sunulan, kişiye indirgenemeyen istatistiksel rapor.
- Asgari toplulaştırma eşiği: her bir kırılım için ayrı ayrı uygulanan, 10 kişiden az katılımcıyı kapsayan hiçbir kırılımın ve hiçbir göstergenin gösterilmemesi kuralı. Bu eşik, tek başına bir veri kümesinin hukuken «anonim» olduğunu garanti etmez; Platformun teknik ve idari gizlilik tedbirlerinden biridir.
- KVKK: 6698 sayılı Kişisel Verilerin Korunması Kanunu.
1.4 Kabul. Kurum adına Platformu satın alan veya panele erişen kişi, bu sözleşmeyi kurumu bağlayacak şekilde kabul etmeye yetkili olduğunu beyan eder. Katılımcı bakımından kabul, değerlendirmeye başlamadan önce gösterilen onay ekranıyla gerçekleşir.
1.5 Ekler. Aydınlatma Metni, veri işleyen sözleşmesi, Gizlilik ve Çerez Politikası ile Sipariş Formu bu sözleşmenin ayrılmaz parçasıdır. Çelişki hâlinde sırasıyla Sipariş Formu, işbu sözleşme ve ekler uygulanır.
2. Hizmetin niteliği ve kapsamı
2.1 Ne yapar. Platform, çalışanla yazılı bir sohbet yürütür; sohbetten yapılandırılmış bulgular çıkarır; bu bulguları kurum düzeyinde toplulaştırarak psikososyal risk göstergeleri ve psikolojik taciz ölçütlerinin karşılanma durumu hakkında bir rapor üretir.
2.2 Ne yapmaz.
- Bu bir sağlık hizmeti değildir. Platform tıbbi cihaz değildir; tedavi, terapi veya psikolojik danışmanlık sağlamaz.
- Tanı koymaz. Hiçbir ruhsal veya bedensel hastalık teşhisi konulmaz. Yalnızca beş ölçütten hangilerinin karşılandığı bildirilir; bu klinik bir değerlendirme değildir.
- Hukuki mütalaa değildir. Çıktılar psikolojik tacizin hukuken sabit olduğu anlamına gelmez, yargılamada delil olarak kullanılmak üzere tasarlanmamıştır ve avukatlık hizmetinin yerine geçmez.
- Karar aracı değildir. Çıktılar hiçbir çalışan hakkında bireysel bir insan kaynakları kararına dayanak yapılamaz (bkz. 4.3).
2.3 Yapılmayan işlemler — mimari taahhüt. Cimedya, Platformun aşağıdakileri yapmadığını ve sözleşme süresince yapmayacağını taahhüt eder:
- kamera, görüntü kaydı veya yüz analizi;
- ses tonundan duygu çıkarımı veya biyometrik veriden herhangi bir duygu çıkarımı;
- kişilik profilleme veya psikometrik kişilik testi;
- kuşak (X/Y/Z) etiketlemesi;
- katılımcı listesi, katılım sayacı veya «kim katıldı» bilgisinin üretilmesi.
Son kalem mimari bir kısıttır: bu bilgi kuruma gösterilmediği gibi hiç üretilmez.
2.4 Sesli kullanım. Konuşmadan metne ve metinden konuşmaya dönüştürme, katılımcının tarayıcısında yerel olarak çalışır. Ses verisi hiçbir aşamada Cimedya sunucularına iletilmez ve kaydedilmez. Tarayıcının bu işlevleri nasıl gerçekleştirdiği tarayıcı ve işletim sistemi sağlayıcısının kendi politikalarına tabidir.
2.5 Ham metnin silinmesi. Ham sohbet metni, değerlendirme tamamlanır tamamlanmaz silinir. Yarıda bırakılan oturumlarda metin, oturumun zaman aşımına uğramasıyla birlikte silinir. Silme işleminden sonra metnin geri getirilmesi teknik olarak mümkün değildir; kurumun ham metne erişim talebi karşılanamaz.
2.6 Yanıt örüntüsü yoğunlaşması. Platform, birden çok oturumun yüksek oranda örtüşen yanıt örüntüsü taşıdığı durumları işaretler. Bu gösterge, kötüye kullanım ile gerçekten benzer deneyimleri birbirinden ayırt etmez ve hangi ihtimalin gerçekleştiğini söylemez; rapor bunu açıkça yazar. Gösterge asgari toplulaştırma eşiğine tabidir: eşiğin altındaki hiçbir kümede gösterilmez. Hiçbir kişiye bağlanamaz ve bireysel bir işleme dayanak yapılamaz (4.3).
2.7 Yapay zekânın doğası. OwO olasılıksal bir dil modeline dayanır; hatalı, eksik veya bağlamı yanlış anlayan çıktı üretebilir. Cimedya çıktıların mutlak doğruluğunu garanti etmez. Garanti ettiği husus şudur: puanlama değerleri denetlenebilir bir katalogdan okunur, modele bırakılmaz.
2.8 Asgari katılımcı sayısı. Toplam katılımcı sayısı asgari toplulaştırma eşiğinin altında kaldığı sürece hiçbir rapor üretilmez. Kurum, değerlendirmeyi tek bir ekiple sınırlandırarak veya katılımcı havuzunu daraltarak bu eşiği dolanamaz.
3. Çalışan olarak kullanım
3.1 Gönüllülük. Katılım tamamen gönüllüdür. Katılmamak, yarıda bırakmak veya soruları yanıtsız bırakmak hiçbir olumsuz sonuç doğurmaz. Bu, kurum bakımından 4.2 uyarınca bağlayıcı bir taahhüttür.
3.2 Kimlik istenmez. Ad, soyad, e-posta, telefon, sicil numarası veya kişiye özgü bir kod istenmez. Yalnızca kuruma ait tek bir erişim kodu girilir.
3.3 Kendinizi ele vermeyin. Serbest metne kendi adınızı, yöneticinizin adını veya sizi tanınır kılacak ayrıntıları yazmayın. Yazılsa dahi ham metin 2.5 uyarınca silinir ve toplulaştırılmış çıktıya aktarılmaz; ancak katılımcının kendi iradesiyle yazdığı içerikten doğan tanınabilirlik riski Cimedya’ya yüklenemez.
3.3/a Mutlak anonimlik iddiası yoktur. Platformun temel ilkesi kişiyi belirlemeye yönelik veri üretmemek ve kurum raporlarını kişi düzeyinde sunmamaktır. Bununla birlikte ortak erişim kodunun kullanılması ve katılımcının serbest metne kendi iradesiyle yazabileceği bilgiler nedeniyle, teknik ve fiilî koşulların kişiyi herhangi bir şekilde belirlenebilir hâle getirme ihtimali tamamen ortadan kaldırılmış sayılmaz. Bu nedenle Cimedya, Platformu «mutlak anonimlik» garantisi olarak sunmaz.
3.4 Misafir modu. Kod girilmeden yapılan kullanım hiçbir kuruma bağlanmaz, hiçbir kurumsal rapora dâhil edilmez ve hiçbir kurum tarafından görülemez. Sonuç yalnızca ekranda katılımcıya gösterilir.
3.5 Onay ve geri çekme. Katılımcıdan işleme ve yapay zekâ altyapısına aktarım için tek bir açık rıza alınır. Rıza her zaman geri çekilebilir; geri çekme ileriye etkilidir. Değerlendirmeyi tamamlamadan oturumu terk eden katılımcının verisi işlenmez ve saklanmaz.
3.6 Silme. Katılımcı, oturumu tamamlamadan önce oturum içindeki silme seçeneğiyle o ana kadarki verisini sildirebilir. Değerlendirme tamamlandıktan sonra bulgular kimliğe bağlanamayacak biçimde toplulaştırıldığından, bireysel silme talebinin karşılanması teknik olarak mümkün değildir. Bu, silmeden kaçınma değil, kimliksizleştirmenin doğal sonucudur ve Aydınlatma Metninde de açıkça belirtilir.
3.7 Rıza kütüğü. Gösterilen metnin sürümü ve SHA-256 karması ile birlikte onay kaydı, yalnızca ekleme yapılabilen bir kütüğe yazılır. Bu kayıt kimlik içermez; yalnızca ispat amacıyla tutulur.
3.8 Kötüye kullanım. Katılımcı, üçüncü kişiler hakkında bilerek gerçek dışı beyanda bulunmamalı ve sistemi tekrar tekrar aynı örüntüyle doldurarak sonucu çarpıtmamalıdır (bkz. 6).
4. Kurum olarak kullanım — bağlayıcı taahhütler
Bu maddedeki taahhütler sözleşmenin esaslı unsurudur. İhlali, Cimedya’ya 13.3 uyarınca haklı nedenle derhâl fesih hakkı verir.
4.1 Veri sorumlusu sıfatı. Kurum, çalışanlarının verileri bakımından veri sorumlusudur. Cimedya veri işleyendir ve yalnızca kurumun talimatları ile bu sözleşme çerçevesinde işlem yapar. Cimedya, hukuka aykırı bulduğu bir talimatı yerine getirmeyi reddeder ve durumu kuruma yazılı olarak bildirir.
4.2 Zorunlu tutma yasağı. Kurum katılımı zorunlu tutamaz; performans hedefi, prim koşulu, devam çizelgesi veya benzeri bir yükümlülüğe bağlayamaz; katılmayan çalışanı belirlemeye veya katılmama nedeniyle çalışana olumsuzluk yaşatmaya yönelik hiçbir tedbir alamaz. Bu yasak, işveren-çalışan ilişkisinde rızanın özgür irade unsurunun sağlanabilmesinin ön koşuludur.
4.3 Bireysel karar yasağı. Kurum, Platformun ürettiği hiçbir çıktıyı — toplulaştırılmış rapor ve yanıt örüntüsü göstergesi dâhil — herhangi bir çalışan hakkında terfi, ücret, prim, görev değişikliği, disiplin, iş sözleşmesinin feshi veya yenilenmemesi kararlarına dayanak yapamaz, bu kararlarda gerekçe olarak anamaz ve bu amaçla üçüncü kişilere aktaramaz.
4.4 Yeniden kimliklendirme yasağı. Kurum, toplulaştırılmış çıktıyı başka veri kümeleriyle (devam kayıtları, ağ günlükleri, kamera kayıtları, VPN/oturum logları, anket sonuçları vb.) birleştirerek veya başka herhangi bir yöntemle katılımcıları kimliklendirmeye teşebbüs edemez; bu yönde tersine mühendislik yapamaz ve üçüncü kişilere yaptıramaz. Kurum, böyle bir teşebbüsün 5237 sayılı Türk Ceza Kanunu m.136 (verileri hukuka aykırı olarak verme veya ele geçirme) kapsamında cezai sorumluluk doğurabileceğini bildiğini kabul eder.
4.5 Kırılım talebi yasağı. Kurum, asgari toplulaştırma eşiğinin altında kalan bir kırılımın (küçük ekip, tek şube, tek unvan vb.) gösterilmesini talep edemez; Cimedya böyle bir talebi karşılamaz. Eşik her kırılım için ayrı ayrı uygulanır ve sözleşme süresince düşürülemez.
4.6 Dönemler arası karşılaştırma. Katılımcı havuzu eşikten daha küçük bir farkla değişmiş iki dönem birbiriyle karşılaştırılarak gösterilmez. Bu kısıt, kişilerin dönem farkından çıkarsanmasını önler.
4.6/a VERBİS. VERBİS kayıt yükümlülüğü; kurumun somut faaliyetleri, yıllık çalışan sayısı, yıllık mali bilanço toplamı ve ana faaliyet konusu dâhil olmak üzere yürürlükteki Kurul kararları çerçevesinde ayrıca değerlendirilir. Kişisel Verileri Koruma Kurulu’nun 04.09.2025 tarihli ve 2025/1572 sayılı kararı (Resmî Gazete, 1 Ekim 2025) uyarınca; ana faaliyet konusu özel nitelikli kişisel veri işleme olmakla birlikte yıllık çalışan sayısı 10’dan az ve yıllık mali bilanço toplamı 10 milyon TL’den az olan veri sorumluları sicile kayıt ve bildirim yükümlülüğünden istisna tutulmuştur. Bu kriterler birlikte aranır. Cimedya, kurumun VERBİS yükümlülüğünün kendiliğinden ortadan kalktığını garanti etmez.
4.7 Kurumun kendi aydınlatma yükümlülüğü. Kurum, çalışanlarını kendi adına aydınlatmakla yükümlüdür; Cimedya’nın metin sağlaması bu yükümlülüğü ortadan kaldırmaz. Kurum, VERBİS kayıt yükümlülüğü kendisine düşüyorsa bu işleme faaliyetini sicilde beyan etmekle yükümlüdür.
4.8 Bulgular üzerine aksiyon yükümlülüğü. Raporda psikolojik taciz veya ağır psikososyal risk göstergesi bulunduğunda kurum, gerekli koruyucu ve önleyici tedbirleri almakla yükümlüdür. Bu yükümlülük Cimedya’dan değil, doğrudan aşağıdaki kaynaklardan doğar:
- 6098 sayılı Türk Borçlar Kanunu m.417 — işverenin, işçinin kişiliğini korumak ve psikolojik tacize uğramaması için gerekli önlemleri almak borcu;
- 6331 sayılı İş Sağlığı ve Güvenliği Kanunu m.4 — işverenin mesleki riskleri önleme ve gerekli her türlü tedbiri alma yükümlülüğü;
- 2025/3 sayılı Cumhurbaşkanlığı Genelgesi (Resmî Gazete, 6 Mart 2025, sayı 32833) — «İş Yerlerinde Psikolojik Tacizin (Mobbing) Önlenmesi». Genelge, 2011/2 sayılı Başbakanlık Genelgesi’ni yürürlükten kaldırmış ve önleyici ile denetleyici politika geliştirme sorumluluğunu öncelikle işveren ve yöneticilere yüklemiştir.
Raporun varlığı kurumu bu yükümlülüklerden kurtarmaz; aksine, bilgiye sahip olması nedeniyle harekete geçme beklentisini artırır. Cimedya, kurumun tedbir almaması nedeniyle üçüncü kişilere karşı doğan sorumluluktan sorumlu değildir.
4.9 Misilleme yasağı. Kurum, değerlendirmeye katıldığı düşünülen veya bulguların ortaya çıkardığı sorunu dile getiren hiçbir çalışana misilleme yapamaz.
4.10 İç iletişim. Kurum, Platformu çalışanlarına duyururken 3.1, 3.2, 4.2 ve 4.3’teki güvenceleri açıkça yazmakla yükümlüdür. Cimedya bu amaçla örnek duyuru metni sağlar.
5. Hesaplar, erişim kodları ve güvenlik
5.1 Erişim kodunun niteliği. Kuruma tek bir kod tahsis edilir. Kod kişiye özgü değildir ve bir kimlik doğrulama aracı değildir; katılımı kurum havuzuna bağlayan bir tahsis anahtarıdır. Kurum bunun sonucunu — kodu bilen herkesin veri gönderebileceğini — bilerek kabul eder.
5.2 Kod hijyeni. Kurum:
- kodu yalnızca kapalı kanallardan (kurum içi e-posta, intranet, basılı duyuru) paylaşır;
- kodu herkese açık internet sayfasında, sosyal medyada veya kuruma ait olmayan gruplarda yayımlayamaz;
- kodu tedarikçilerine, müşterilerine veya kurum dışı üçüncü kişilere veremez;
- kodun sızdığından şüphelenirse gecikmeksizin panelden kod yenilemesi yapar veya Cimedya’dan talep eder;
- her değerlendirme dönemi kapandığında kodu yeniler.
Cimedya ayrıca kod başına dönemsel oturum sınırı ve hız sınırlaması uygular; bu sınırlar veri bütünlüğünü korumaya yöneliktir.
5.3 Panel hesapları ve roller. Panel hesapları kişiye özgüdür ve paylaşılamaz. En az iki rol tanımlıdır: Yönetici (hesap, fatura, kod yönetimi) ve Raporlayan (yalnızca toplulaştırılmış rapor görüntüleme). Yetkiler en az yetki ilkesine göre verilir.
5.4 Ayrılan personel. Panel erişimi olan bir kişinin işten ayrılması, görev değişikliği veya yetkisinin sona ermesi hâlinde kurum, ilgili hesabı en geç 24 saat içinde kapatmak veya yetkisini kaldırmakla yükümlüdür. Bu süre, ayrılan personel erişiminin bilinen en yaygın yetkisiz erişim sebeplerinden biri olması nedeniyle kısa tutulmuştur.
5.5 Parolalar. Cimedya parolaları düz metin olarak saklamaz, e-posta ile göndermez ve destek personeline göstermez. Kurum, panel hesaplarında çok faktörlü kimlik doğrulamayı etkinleştirmekle yükümlüdür.
5.6 Kurumun kendi güvenlik yükümlülükleri. Cihaz güvenliği, kurumsal e-posta güvenliği, panelin görüntülendiği ekranların üçüncü kişilerce görülmemesi, raporların kurum içinde yetkisiz dağıtılmaması ve rapor çıktılarının fiziksel güvenliği kuruma aittir.
5.7 Cimedya personelinin erişimi. Cimedya personeli gizlilik yükümlülüğü altındadır ve en az yetki ilkesine tabidir. Kuruma ait raporlara erişim, yalnızca gerekçelendirilmiş ve kayda geçen hâllerde mümkündür.
5.8 Veri ihlali bildirimi.
- Cimedya, kendi sistemlerinde bir kişisel veri ihlalini öğrendiğinde kuruma gecikmeksizin ve mümkün olan en kısa sürede bilgilendirir. Bildirim, kurumun kendi yasal bildirim süresini kullanabilmesine imkân verecek şekilde yapılır.
- Kurum, veri sorumlusu sıfatıyla ihlali Kişisel Verileri Koruma Kurulu’na KVKK m.12/5 uyarınca en kısa sürede bildirmekle yükümlüdür.
- Katılımcılar tasarım gereği kimliksiz olduğundan, ilgili kişilere doğrudan bildirim yapılması mümkün değildir; bu hâlde bildirim kamuya duyuru yoluyla yapılır.
- Cimedya; ihlalin kapsamının belirlenmesi, kanıtların korunması ve bildirim içeriğinin hazırlanması bakımından kuruma makul destek verir.
5.9 Denetim. Kurum, yılda bir kez ve masrafı kendisine ait olmak üzere, önceden yazılı bildirimle Cimedya’nın bu sözleşmeye uygunluğunu denetleyebilir veya bağımsız denetim raporlarının paylaşılmasını talep edebilir. Kurum, Cimedya’nın canlı ortamına izinsiz sızma testi yapamaz; test yapılacaksa kapsam ve zaman önceden yazılı olarak kararlaştırılır.
6. Yasak kullanımlar
- Platformu tersine mühendislik, kaynak koda dönüştürme, kopyalama, kiralama veya üçüncü kişilere yeniden satma;
- otomatik betik, bot, tekrar oynatma veya toplu veri gönderimi ile sonuçları çarpıtma;
- erişim kodunu herkese açık biçimde yayma veya kurum dışına dağıtma;
- başka bir kişinin adına, onun bilgisi dışında değerlendirme doldurma;
- çıktıları 4.3’e aykırı biçimde bireysel kararlara dayanak yapma;
- katılımcıları yeniden kimliklendirmeye teşebbüs (4.4);
- Platformu, katılımcıları izlemek, denetlemek veya sadakat ölçmek üzere bir gözetim aracı olarak kullanma;
- yürürlükteki mevzuata, kamu düzenine veya üçüncü kişi haklarına aykırı her tür kullanım;
- Platformun güvenlik önlemlerini aşmaya, hizmet dışı bırakmaya veya aşırı yük bindirmeye yönelik davranışlar.
Cimedya, 2, 3, 6 ve 9 numaralı bentlerin ihlali hâlinde erişimi önceden bildirim yapmaksızın geçici olarak durdurabilir; durdurma sonrası gerekçe kuruma gecikmeksizin yazılı olarak bildirilir.
7. Kriz durumları ve acil hâller
7.1 Platform bir acil yardım hattı değildir. OwO gerçek zamanlı insan desteği sağlamaz, müdahale ekibi yönlendirmez ve mesajlar bir uzman tarafından anlık olarak izlenmez.
7.2 Acil yönlendirme. Kendinize veya bir başkasına zarar verme riski, şiddet, cinsel taciz veya yaşamsal tehlike söz konusuysa Platformu kullanmayı bırakın ve derhâl aşağıdaki hatlara başvurun:
| Hat | Kurum | Kapsam |
|---|---|---|
| 112 | Acil Çağrı Merkezi | Tüm acil durumlar (sağlık, polis, jandarma, itfaiye) |
| ALO 183 | Aile ve Sosyal Hizmetler Bakanlığı — Sosyal Destek Hattı | Kadın, çocuk, engelli ve aile içi şiddet; sosyal destek |
| ALO 170 | Çalışma ve Sosyal Güvenlik Bakanlığı — İletişim Merkezi | Çalışma hayatı; psikolojik taciz (mobbing) başvuruları dâhil |
7.3 Cimedya’nın müdahale sınırı. Ham sohbet metni 2.5 uyarınca silindiğinden ve katılımcı kimliksiz olduğundan, Cimedya bir katılımcıyı tespit edip kendisine ulaşamaz. Bu, hizmetin bilinçli bir tasarım tercihidir ve ihmal olarak yorumlanamaz.
7.4 Kurumun kriz protokolü. Kurum, Platformu devreye almadan önce kendi iç kriz ve psikolojik taciz başvuru protokolünü oluşturup çalışanlarına duyurmakla yükümlüdür (2025/3 sayılı Genelge ve 6331 sayılı Kanun m.4 çerçevesinde).
8. Veri koruma
8.1 Roller.
- Kurum çalışanlarına ait değerlendirme verileri: kurum = veri sorumlusu, Cimedya = veri işleyen (KVKK m.12/2 uyarınca yazılı sözleşme ile).
- Panel hesap ve fatura verileri ile tanıtım sitesindeki iletişim formu verileri: Cimedya = veri sorumlusu (bkz. 8.8).
8.2 İşlenen veri türleri. Katılımcı bakımından: erişim kodu ile ilişkilendirilmiş oturum kaydı, yapılandırılmış bulgular ve teknik günlükler. Ad, e-posta, telefon, konum, cihaz kimliği veya biyometrik veri işlenmez. Ham sohbet metni yalnızca değerlendirme süresince tutulur, ardından silinir (2.5).
8.3 Özel nitelikli veri. İşyerinde psikolojik taciz ve psikososyal risk bulguları ruh sağlığına ilişkin çıkarım içerebileceğinden, KVKK m.6 anlamında özel nitelikli kişisel veri sınırında kabul edilir ve bu sözleşmede en yüksek koruma standardına tabi tutulur.
8.4 Hukuki sebepler. Katılımcıdan işleme ve yapay zekâ altyapısına aktarım için tek bir açık rıza alınır. Bunun ötesindeki işleme faaliyetleri rızaya değil; KVKK’da yer alan istihdam ile iş sağlığı ve güvenliği alanındaki yükümlülüklerin yerine getirilmesi ve veri sorumlusunun hukuki yükümlülüğünü yerine getirmesi şartlarına dayanır. Bu kalemler katılımcıya aydınlatma olarak sunulur, rıza olarak sorulmaz. Ayrım bilinçlidir: işveren-çalışan ilişkisinde rızanın özgür irade unsuru tartışmalı olduğundan, hizmetin sürekliliği tek bir rızaya bağlanmamıştır. Rıza hizmetin ön şartı hâline getirilmez ve birden çok amaç tek kutucukta toplanmaz.
8.5 Saklama. Ham sohbet metni değerlendirme tamamlanınca derhâl silinir. Yapılandırılmış bulguların, toplulaştırılmış raporun, rıza kütüğünün ve teknik günlüklerin saklama süreleri Sipariş Formunda ve Aydınlatma Metninde belirtilir. Fatura ve ticari defter kayıtları, ilgili mali mevzuatın öngördüğü zorunlu süreler boyunca saklanır; bu istisna yalnızca muhasebe kayıtlarını kapsar, değerlendirme verisini kapsamaz.
8.6 Yurt dışına aktarım. Barındırma ve yapay zekâ işleme, Google Cloud / Vertex AI europe-west3 (Frankfurt) bölgesinde gerçekleşir. Bu, KVKK bakımından bir yurt dışına aktarımdır ve KVKK m.9’da öngörülen sıraya uyularak yapılır: yeterlilik kararı varsa ona; yoksa Kurulca ilan edilen standart sözleşme veya taahhütname gibi uygun güvencelere dayanılır. Standart sözleşme yolu seçildiğinde imza, mevzuatın öngördüğü süre içinde Kuruma bildirilir; taahhütname yolu seçildiğinde aktarım Kurul izni alınmadan başlatılmaz. Kurum kendi tarafındaki bildirim ve izin yükümlülüğünü, Cimedya ise kendi zincirindeki sözleşmeleri kurmakla yükümlüdür.
8.7 Alt veri işleyenler. Cimedya, güncel alt işleyen listesini talep hâlinde paylaşır. Yeni bir alt işleyen eklenmeden en az 30 gün önce kuruma bildirilir; kurum bu süre içinde haklı gerekçeyle itiraz eder ve çözüm bulunamazsa aboneliği cezasız feshedebilir. Cimedya, alt işleyenin fiilinden kendi fiili gibi sorumludur.
8.8 İlgili kişi başvuruları. Katılımcı başvuruları KVKK m.13 uyarınca kuruma (veri sorumlusuna) yapılır. Cimedya, doğrudan kendisine ulaşan başvuruyu gecikmeksizin kuruma yönlendirir ve yanıtın hazırlanmasında destek olur. Katılımcı kimliksiz olduğundan Cimedya bir başvuru sahibini kendi kayıtlarında eşleştiremez.
8.9 İletişim formu — ayrı ilişki. Tanıtım sitesindeki iletişim formunda toplanan ad-soyad, kurum, e-posta, telefon ve mesaj verileri kimlik belirleyicidir ve değerlendirme verisinden tamamen ayrı bir sistemde tutulur. Bu veriler bakımından Cimedya kendisi veri sorumlusudur. Bu forma yazılan hiçbir bilgi değerlendirme verisiyle ilişkilendirilmez.
8.10 Ticari elektronik ileti. 6563 sayılı Kanun kapsamında gönderilen ticari elektronik iletilerde alıcının ret hakkı her zaman saklıdır ve İleti Yönetim Sistemi (İYS) üzerinden kullanılabilir. Cimedya, ret bildirimini aldığı andan itibaren mevzuatta öngörülen süre içinde ileti göndermeyi durdurur.
8.11 Yapay zekâ ve duygu çıkarımı. Cimedya biyometrik veriden duygu çıkarımı yapmaz ve yapmayacağını taahhüt eder (2.3). Bu tercih, (AB) 2024/1689 sayılı Yapay Zekâ Tüzüğü m.5(1)(f) ile işyeri ve eğitim ortamlarında duygu çıkarımı yapan sistemlerin yasaklanmış olmasıyla da uyumludur. Bu yasak bakımından rıza bir mazeret oluşturmaz. Kurumun Avrupa Birliği’nde çalışanı bulunması ihtimaline karşı bu yasak bir tasarım kısıtı olarak benimsenmiştir.
9. Fikri mülkiyet
9.1 Platform, kaynak kodu, arayüz, soru kataloğu, puanlama motoru ile «ControlAtWork», «OwO» ve «Cimedya» adları ve tüm ilgili haklar Cimedya’ya aittir. Sözleşme kuruma yalnızca abonelik süresiyle sınırlı, münhasır olmayan, devredilemez ve alt lisansa konu edilemez bir kullanım hakkı verir.
9.2 Kurumun verisi. Kurum tarafından girilen kurumsal bilgiler ve kurum adına üretilen toplulaştırılmış raporlar kuruma aittir; Cimedya bunları yalnızca hizmeti sunmak için kullanır.
9.3 Geliştirme ve istatistik. Cimedya, hizmeti geliştirmek amacıyla hiçbir şekilde tekil kuruma veya kişiye geri götürülemeyecek, asgari toplulaştırma eşiğine tabi, toplu istatistikleri kullanabilir. Ham sohbet metni bu amaçla kullanılamaz — zaten silinmiştir. Kurumun ticari unvanı, ayrıca yazılı izin olmadıkça referans olarak kullanılamaz.
9.4 Geri bildirim. Kurumun ilettiği öneri ve geri bildirimler, karşılıksız ve süresiz olarak Cimedya tarafından kullanılabilir.
10. Ücret, fatura ve vergi
10.1 Abonelik bedeli, dönemi ve kapsamı Sipariş Formunda belirlenir. Aksi yazılmadıkça bedeller KDV hariçtir.
10.2 Ödeme, Sipariş Formunda belirlenen vade içinde yapılır. Gecikme hâlinde 6102 sayılı TTK m.1530 hükümleri saklıdır.
10.3 Askıya alma. Sipariş Formunda belirlenen süreyi aşan ödeme gecikmesinde Cimedya, yazılı ihtar ve en az 7 günlük ek süre tanıyarak hizmeti askıya alabilir. Askı süresince veri silinmez.
10.4 Fiyat değişikliği. Fiyat değişiklikleri, yürürlükteki abonelik döneminin sonundan en az 30 gün önce yazılı olarak bildirilir ve yalnızca yenilenen dönemde uygulanır.
10.5 Belge ve saklama. Faturalar mevzuatın öngördüğü şekilde düzenlenir. Ticari defter, belge ve vergi kayıtları ilgili mali mevzuatın öngördüğü zorunlu süreler boyunca saklanır. Bu saklama 8.5’teki silme taahhütlerine istisna oluşturmaz; yalnızca fatura ve muhasebe kayıtlarını kapsar.
10.6 Tüketici mevzuatı. Kurum, hizmeti ticari veya mesleki amaçla aldığından 6502 sayılı Tüketicinin Korunması Hakkında Kanun anlamında tüketici değildir; anılan Kanunun mesafeli sözleşme, cayma hakkı ve tüketici hakem heyeti hükümleri bu sözleşmeye uygulanmaz.
11. Hizmet seviyesi, bakım ve değişiklik bildirimi
11.1 Erişilebilirlik. Hedeflenen aylık erişilebilirlik oranı ve hedefin altında kalınması hâlinde uygulanacak servis kredisi Sipariş Formunda belirlenir.
11.2 Planlı bakım. En az 48 saat önce bildirilir ve mümkün olduğunca düşük kullanım saatlerinde yapılır.
11.3 Acil bakım. Güvenlik açığı veya veri bütünlüğü riski hâlinde bildirimsiz acil bakım yapılabilir; işlem sonrası makul süre içinde bilgi verilir.
11.4 Değişiklik bildirimi. Bu sözleşmede veya hizmetin kapsamında kurum aleyhine esaslı değişiklik yapılacaksa en az 30 gün önce yazılı bildirim yapılır. Kurum bu süre içinde itiraz ederse aboneliği dönem sonunda cezasız feshedebilir. Mevzuat değişikliğinden kaynaklanan zorunlu uyarlamalar bu süreye tabi değildir ancak gerekçesiyle bildirilir.
11.5 Değiştirilemez taahhütler. 2.3 (yapılmayan işlemler), 2.4 (sesin sunucuya gitmemesi), 2.5 (ham metnin silinmesi), 2.8 (asgari katılımcı sayısı) ve 4.5 (asgari toplulaştırma eşiği) maddeleri kurumun yazılı onayı olmadan kurum aleyhine değiştirilemez; bu maddeler tek taraflı değişiklik yetkisinin dışındadır.
12. Sorumluluğun sınırı
12.1 Emredici sınır. 6098 sayılı Türk Borçlar Kanunu m.115 uyarınca, borçlunun ağır kusurundan doğan sorumluluğunu önceden kaldıran anlaşmalar kesin olarak hükümsüzdür. Bu maddedeki hiçbir sınırlama; Cimedya’nın kasıt veya ağır kusurundan doğan sorumluluğunu, ölüm veya bedensel bütünlüğün ihlalinden doğan sorumluluğu ya da emredici hükümlerle sınırlandırılması yasaklanan diğer sorumlulukları kapsamaz.
12.2 Sınırlanabilir kalem. Yukarıdaki emredici sınır saklı kalmak üzere, Cimedya’nın hafif kusurundan doğan toplam sorumluluğu, zararın doğduğu olaydan önceki on iki ay içinde kurumun fiilen ödediği abonelik bedeli ile sınırlıdır.
12.3 Dolaylı zarar. Hafif kusur hâlinde Cimedya; kâr kaybı, itibar kaybı, iş kesintisi ve veri kullanım kaybı gibi dolaylı zararlardan sorumlu değildir.
12.4 Sorumluluk dışı hâller. Cimedya aşağıdakilerden sorumlu değildir:
- kurumun 4. maddedeki taahhütlere aykırı davranışı ve bunun doğurduğu iş hukuku, ceza hukuku veya KVKK sorumluluğu;
- katılımcıların beyanlarının doğruluğu, eksikliği veya kasıtlı çarpıtılması;
- kurumun raporu yanlış yorumlaması veya bulgular üzerine gerekli tedbiri almaması (4.8);
- erişim kodunun kurumun kusuruyla sızmasından doğan kirlenmiş veri;
- katılımcının kendi tarayıcısı, cihazı veya işletim sistemi kaynaklı sorunlar.
12.5 Kurumun tazmin yükümlülüğü. Kurumun 4. veya 6. maddeye aykırılığı nedeniyle Cimedya aleyhine üçüncü kişilerce ileri sürülen talepler, kesilen idari para cezaları ve makul savunma giderleri kurum tarafından karşılanır. Kurum hakkında veri sorumlusu sıfatıyla kesilen idari para cezaları kurumun kendisine aittir.
12.6 Bildirim süresi. Kurum, sözleşmeye aykırılığa dayalı taleplerini aykırılığı öğrendiği tarihten itibaren 60 gün içinde yazılı olarak Cimedya’ya bildirir. Bu bildirim bir usul şartıdır; kanuni zamanaşımı sürelerini kısaltmaz.
13. Süre, fesih ve fesih sonrası veri
13.1 Süre. Sözleşme, Sipariş Formundaki abonelik süresince yürürlüktedir ve aksi bildirilmedikçe aynı süreyle yenilenir. Yenilememe bildirimi dönem bitiminden en az 30 gün önce yapılır.
13.2 Olağan fesih. Taraflar, Sipariş Formunda belirlenen ihbar süresine uyarak dönem sonunda feshedebilir.
13.3 Haklı nedenle derhâl fesih. Cimedya; 4.2, 4.3, 4.4, 4.5, 4.6 veya 6. maddenin ihlali hâlinde sözleşmeyi derhâl ve tazminatsız feshedebilir ve erişimi kapatabilir. Kurum; Cimedya’nın 2.3, 2.4, 2.5, 2.8 veya 11.5’teki taahhütlerini ihlal etmesi hâlinde aynı hakka sahiptir.
13.4 Ödeme temerrüdü. 10.3’teki ihtar ve ek süreye rağmen ödenmeyen bedel için Cimedya sözleşmeyi feshedebilir.
13.5 Veri iadesi. Kurum, fesihten itibaren 30 gün içinde toplulaştırılmış raporlarının makine tarafından okunabilir bir formatta kendisine verilmesini talep edebilir.
13.6 İmha. Otuz günlük sürenin sonunda veya kurumun daha erken talebi hâlinde derhâl, Cimedya ve alt işleyenleri nezdindeki tüm kurum verisi, saklama ve imha politikasında belirlenen süre içinde silinir, yok edilir veya anonim hâle getirilir; işlem tamamlandığında kuruma yazılı imha beyanı verilir. Yedeklerdeki veriler yedek döngüsünün tamamlanmasıyla, en geç aynı süre içinde imha edilir. 10.5’teki zorunlu mali kayıtlar bu hükmün dışındadır.
13.7 Ayakta kalan hükümler. 4.3, 4.4, 8, 9, 12, 13.6 ve 16. maddeler fesihten sonra da yürürlükte kalır.
14. Mücbir sebep
14.1 Deprem, sel, yangın, salgın, savaş, terör, seferberlik, genel grev, kamu otoritesi kararı, ülke çapında elektrik veya internet altyapısı kesintisi, siber saldırı ve tarafların makul kontrolü dışındaki benzeri hâller mücbir sebep sayılır. Bulut altyapı sağlayıcısının kendi mücbir sebebi Cimedya bakımından da mücbir sebep sayılır.
14.2 Mücbir sebebe maruz kalan taraf durumu 5 iş günü içinde yazılı olarak bildirir; yükümlülükler sebep devam ettiği sürece askıya alınır.
14.3 Mücbir sebep 60 günü aşarsa taraflardan her biri sözleşmeyi tazminatsız feshedebilir; ifa edilmemiş dönemin bedeli oranlanarak iade edilir.
14.4 Mücbir sebep, 5.8’deki veri ihlali bildirim yükümlülüğünü ve 8. maddedeki veri koruma yükümlülüklerini ortadan kaldırmaz.
15. Devir, bildirimler, bölünebilirlik
15.1 Devir. Kurum, sözleşmeyi Cimedya’nın yazılı izni olmadan devredemez. Cimedya; birleşme, bölünme veya işletmenin devri hâlinde sözleşmeyi devredebilir. Devir kuruma 30 gün önce bildirilir ve kurum bu süre içinde cezasız fesih hakkına sahiptir. Veri koruma yükümlülükleri devralan bakımından da aynen geçerlidir.
15.2 Bildirimler. Bildirimler Sipariş Formundaki adreslere KEP, noter veya iadeli taahhütlü posta ile yapılır. Rutin operasyonel bildirimler (bakım, sürüm, alt işleyen listesi) e-posta ile geçerli olarak yapılabilir; fesih, ihlal ve fiyat bildirimleri yazılı şekle tabidir. Adres değişikliği 7 gün içinde bildirilir; aksi hâlde eski adrese yapılan bildirim geçerlidir.
15.3 Bölünebilirlik. Bir hükmün geçersizliği diğerlerini etkilemez; geçersiz hüküm, tarafların amacına en yakın geçerli hükümle ikame edilir.
15.4 Feragat. Bir hakkın kullanılmaması ondan feragat sayılmaz.
15.5 Bütünlük. Bu sözleşme ve ekleri, konuya ilişkin önceki tüm yazılı ve sözlü mutabakatların yerine geçer.
15.6 Bağımsız taraflar. Taraflar arasında ortaklık, acentelik veya iş ilişkisi kurulmaz.
15.7 Dil. Sözleşmenin Türkçe metni asıldır. İngilizce çeviri bilgilendirme amaçlıdır; çelişki hâlinde Türkçe metin esas alınır.
16. Uygulanacak hukuk ve yetki
16.1 Bu sözleşmeye Türkiye Cumhuriyeti hukuku uygulanır.
16.2 Doğacak uyuşmazlıklarda Ankara mahkemeleri ve icra daireleri yetkilidir.
16.3 Ticari uyuşmazlıklarda, konusu bir miktar paranın ödenmesi olan alacak ve tazminat talepleri bakımından arabuluculuğa başvurulmasına ilişkin dava şartı hükümleri saklıdır.
16.4 Çalışan sıfatından doğan emredici yetki kuralları saklıdır. İdari başvuru yolları da saklıdır: veri koruma konularında Kişisel Verileri Koruma Kurumu, çalışma hayatına ilişkin konularda Çalışma ve Sosyal Güvenlik Bakanlığı.
İletişim
Bu koşullara ilişkin sorular için: info@oculawork.com
Terms of Service and Service Agreement
Terms applying to employees and organisations using ControlAtWork. This is a translation; the Turkish text prevails.
In short: Participation is voluntary and no identity is requested. What you write is deleted the moment the assessment completes. Your organisation sees only aggregate figures for groups of no fewer than ten people — it cannot see who took part, because that information is never generated. The organisation may not use any output in decisions about promotion, pay, discipline or dismissal for any employee; this is not a promise but an essential term of the contract.
1. Parties and definitions
1.1 Provider. ControlAtWork is a software service operated by Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. (“Cimedya”, the “Platform”, “we”), whose details are set out below.
| Legal name | Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. |
|---|---|
| Tax office / no. | Maltepe Tax Office — 2100357903 |
| Address for notices | Söğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara, Türkiye |
| info@oculawork.com |
1.2 Company. The legal entity subscribing in order to make the service available to its own employees.
1.3 Definitions.
- Platform: the software service for assessing workplace psychosocial risk and psychological harassment (mobbing) indicators.
- OwO: the AI component that conducts a written conversation with the participant.
- Participant: the natural person using the Platform with an access code or in guest mode.
- Access code: a single company-wide code; it is not personal and is not an authentication credential.
- Guest mode: use without any code and without linkage to any organisation.
- Raw conversation text: the participant’s free text and OwO’s replies in full.
- Finding: a structured, quantified indicator derived from the raw conversation text.
- Aggregated output: the statistical report shown to the organisation, which cannot be reduced to an individual.
- Minimum aggregation threshold: the rule, applied separately to every breakdown, that no breakdown and no indicator covering fewer than 10 participants is displayed. This threshold does not by itself guarantee that a dataset is legally “anonymous”; it is one of the Platform’s technical and organisational privacy measures.
- KVKK: Turkish Personal Data Protection Law no. 6698.
1.4 Acceptance. The person purchasing or accessing the panel on the Company’s behalf warrants authority to bind the Company. For a participant, acceptance occurs through the consent screen shown before the assessment begins.
1.5 Annexes. The privacy notice, the data processing agreement, the privacy and cookie policy and the Order Form form an integral part hereof. In case of conflict the order of precedence is: Order Form, this agreement, annexes.
2. Nature and scope of the service
2.1 What it does. The Platform conducts a written conversation with an employee, extracts structured findings, aggregates those findings at organisation level, and produces a report on psychosocial risk indicators and on whether the five criteria are met.
2.2 What it does not do.
- This is not a healthcare service. The Platform is not a medical device and provides no treatment, therapy or psychological counselling.
- It makes no diagnosis. No mental or physical condition is diagnosed. It reports only which of the five criteria are met; this is not a clinical assessment.
- It is not legal advice. Outputs do not establish that psychological harassment is legally proven, are not designed as evidence in proceedings, and do not replace legal counsel.
- It is not a decision-making tool. Outputs may not ground any individual HR decision about any employee (see 4.3).
2.3 Operations deliberately not performed — architectural undertaking. Cimedya undertakes that the Platform does not, and will not during the term:
- use a camera, record video, or perform facial analysis;
- infer emotion from voice tone or from any biometric data;
- perform personality profiling or psychometric personality testing;
- apply generational (X/Y/Z) labels;
- generate a participant list, a participation counter, or any “who took part” information.
The last item is an architectural constraint: this information is not merely withheld from the organisation — it is never generated.
2.4 Voice features. Speech-to-text and text-to-speech run locally in the participant’s browser. Audio is never transmitted to or stored on Cimedya’s servers. How the browser performs these functions is subject to the browser and operating system vendor’s own policies.
2.5 Deletion of raw text. The raw conversation text is deleted as soon as the assessment completes. For abandoned sessions it is deleted when the session times out. After deletion it is technically impossible to restore; a request by the organisation for access to raw text can never be fulfilled.
2.6 Response-pattern concentration. The Platform flags cases where multiple sessions share a highly overlapping response pattern. This indicator does not distinguish misuse from genuinely similar experiences and does not say which occurred; the report states this expressly. The indicator is subject to the minimum aggregation threshold and is not shown for any cluster below it. It cannot be linked to any individual and may not ground any individual measure (4.3).
2.7 Nature of AI. OwO relies on a probabilistic language model and may produce inaccurate, incomplete or contextually mistaken output. Cimedya does not warrant absolute accuracy. What it does warrant is this: scoring values are read from an auditable catalogue and are not left to the model.
2.8 Minimum participant count. No report is produced while the total number of participants remains below the minimum aggregation threshold. The organisation may not circumvent the threshold by limiting the assessment to a single team or otherwise narrowing the participant pool.
3. Use by employees
3.1 Voluntariness. Participation is entirely voluntary. Declining, abandoning, or leaving questions unanswered carries no adverse consequence. This is a binding undertaking of the organisation under 4.2.
3.2 No identity requested. No name, e-mail, phone number, staff number or personal code is required. Only a single company-wide access code is entered.
3.3 Do not identify yourself. Do not write your own name, your manager’s name, or identifying details into free text. Even if written, the raw text is deleted under 2.5 and is not carried into the aggregated output; however, identifiability risk arising from content the participant voluntarily wrote cannot be attributed to Cimedya.
3.4 Guest mode. Use without a code is linked to no organisation, included in no organisational report, and is not visible to any organisation. The result is shown on screen to the participant only.
3.5 Consent and withdrawal. A single item of explicit consent is collected, covering processing and transfer to the AI infrastructure. Consent may be withdrawn at any time, with prospective effect. Data of a participant who leaves before completion is not processed or retained.
3.6 Deletion. Before completing the session the participant may use the in-session delete option to erase data collected so far. After completion, findings are aggregated beyond identifiability, so an individual erasure request cannot technically be fulfilled. This is a consequence of de-identification, not an avoidance of erasure, and is stated expressly in the privacy notice.
3.7 Consent ledger. The consent record, together with the version and SHA-256 hash of the text displayed, is written to an append-only ledger. It contains no identity and is kept solely for evidentiary purposes.
3.8 Misuse. Participants must not knowingly make false statements about third parties, nor repeatedly submit the same pattern to distort results (see 6).
4. Use by the organisation — binding undertakings
The undertakings in this section are essential terms. Their breach entitles Cimedya to immediate termination for cause under 13.3.
4.1 Controller status. The organisation is the data controller for its employees’ data. Cimedya is the data processor and acts only on the organisation’s instructions and within this agreement. Cimedya will refuse to carry out an instruction it considers unlawful and will notify the organisation in writing.
4.2 No compulsion. The organisation may not make participation mandatory; may not tie it to performance targets, bonus conditions, attendance records or any similar obligation; and may not take any measure to identify non-participants or to disadvantage an employee for not participating. This prohibition is a precondition for consent to satisfy the freely given element in an employer-employee relationship.
4.3 No individual decisions. The organisation may not use any Platform output — including the aggregated report and the response-pattern indicator — as a basis for, or as a stated reason in, decisions on promotion, pay, bonus, reassignment, discipline, termination or non-renewal of any employee, nor transfer it to third parties for such purposes.
4.4 No re-identification. The organisation may not attempt to identify participants by combining the aggregated output with other datasets (attendance records, network logs, camera footage, VPN or session logs, survey results and the like) or by any other means, may not reverse-engineer to that end, and may not have third parties do so. The organisation acknowledges that such an attempt may give rise to criminal liability under article 136 of the Turkish Criminal Code no. 5237 (unlawfully giving or obtaining data).
4.5 No sub-threshold breakdowns. The organisation may not request display of any breakdown falling below the minimum aggregation threshold (a small team, a single branch, a single job title and the like), and Cimedya will not fulfil such a request. The threshold applies separately to every breakdown and may not be lowered during the term.
4.6 Comparison across periods. Two periods whose participant pools differ by less than the threshold are not displayed in comparison with one another. This constraint prevents individuals being inferred from the difference between periods.
4.7 The organisation’s own transparency duty. The organisation must inform its employees in its own name; Cimedya’s provision of template text does not discharge that duty. If the organisation is subject to VERBİS registration, it must declare this processing activity in the registry.
4.8 Duty to act on findings. Where the report shows indicators of psychological harassment or serious psychosocial risk, the organisation must take the necessary protective and preventive measures. This duty arises not from Cimedya but directly from:
- Article 417 of the Turkish Code of Obligations no. 6098 — the employer’s duty to protect the employee’s personality and to take the measures necessary to prevent psychological harassment;
- Article 4 of the Occupational Health and Safety Law no. 6331 — the employer’s duty to prevent occupational risks and take all necessary measures;
- Presidential Circular no. 2025/3 (Official Gazette, 6 March 2025, no. 32833) on the Prevention of Psychological Harassment (Mobbing) in Workplaces. The circular repealed Prime Ministry Circular no. 2011/2 and places responsibility for developing preventive and supervisory policies primarily on employers and managers.
Possession of the report does not relieve the organisation of these duties; it heightens the expectation to act. Cimedya is not liable for the organisation’s failure to act.
4.9 No retaliation. The organisation may not retaliate against any employee believed to have participated or who raises an issue surfaced by the findings.
4.10 Internal communication. When announcing the Platform, the organisation must state expressly the guarantees in 3.1, 3.2, 4.2 and 4.3. Cimedya provides a template announcement.
5. Accounts, access codes and security
5.1 Nature of the access code. A single code is allocated to the organisation. It is not personal and is not an authentication credential; it is an allocation key attaching a session to the organisation’s pool. The organisation knowingly accepts the consequence: anyone who knows the code can submit data.
5.2 Code hygiene. The organisation shall:
- distribute the code only through closed channels (internal e-mail, intranet, printed notice);
- not publish it on a public web page, on social media, or in groups not belonging to the organisation;
- not give it to suppliers, customers or external third parties;
- if leakage is suspected, promptly rotate the code from the panel or request rotation from Cimedya;
- rotate the code at the close of each assessment period.
Cimedya additionally applies a per-code session cap per period and rate limiting; these limits exist to protect data integrity.
5.3 Panel accounts and roles. Panel accounts are personal and non-shareable. At least two roles exist: Administrator (account, billing, code management) and Reporter (aggregated report viewing only). Rights are granted on a least-privilege basis.
5.4 Leavers. Where a person holding panel access leaves, changes role, or loses authorisation, the organisation must disable the account or revoke the rights within 24 hours. This period is short because leaver access is among the most common known causes of unauthorised access.
5.5 Passwords. Cimedya does not store passwords in plaintext, does not send them by e-mail, and does not display them to support staff. The organisation must enable multi-factor authentication on panel accounts.
5.6 The organisation’s own security duties. Device security, corporate e-mail security, preventing third parties from viewing panel screens, preventing unauthorised internal distribution of reports, and the physical security of printed reports rest with the organisation.
5.7 Access by Cimedya staff. Cimedya staff are bound by confidentiality and subject to least privilege. Access to an organisation’s reports is possible only where justified and logged.
5.8 Breach notification.
- On becoming aware of a personal data breach in its systems, Cimedya will notify the organisation without undue delay and as soon as reasonably possible. The notification is made so as to allow the organisation to use its own statutory notification window.
- As controller, the organisation must notify the Personal Data Protection Board as soon as possible under KVKK article 12/5.
- Because participants are unidentified by design, direct notification to data subjects is impossible; in that case notification is made by public announcement.
- Cimedya will provide reasonable assistance in scoping the breach, preserving evidence, and preparing notification content.
5.9 Audit. Once a year, at its own cost and on prior written notice, the organisation may audit Cimedya’s compliance with this agreement or request independent audit reports. The organisation may not conduct unauthorised penetration testing against Cimedya’s production environment; any testing must be agreed in writing as to scope and timing.
6. Prohibited uses
- reverse-engineering, decompiling, copying, leasing or reselling the Platform;
- distorting results via scripts, bots, replay or bulk submission;
- publicly disseminating the access code or distributing it outside the organisation;
- completing an assessment on another person’s behalf without their knowledge;
- using outputs to ground individual decisions contrary to 4.3;
- attempting to re-identify participants (4.4);
- using the Platform as a surveillance tool to monitor, police or measure the loyalty of participants;
- any use contrary to applicable law, public order or third-party rights;
- conduct aimed at circumventing security measures, causing denial of service, or imposing excessive load.
For breaches of items 2, 3, 6 and 9 Cimedya may suspend access temporarily without prior notice; reasons are given to the organisation in writing without delay thereafter.
7. Crisis situations and emergencies
7.1 The Platform is not a helpline. OwO provides no real-time human support, dispatches no response team, and messages are not monitored live by a professional.
7.2 Emergency referral. If there is a risk of harm to yourself or another, violence, sexual harassment, or danger to life, stop using the Platform and contact:
| Line | Body | Scope |
|---|---|---|
| 112 | Emergency Call Centre | All emergencies (medical, police, gendarmerie, fire) |
| ALO 183 | Ministry of Family and Social Services — Social Support Line | Women, children, persons with disabilities, domestic violence, social support |
| ALO 170 | Ministry of Labour and Social Security — Communication Centre | Working life, including psychological harassment (mobbing) reports |
7.3 Limits of Cimedya’s intervention. Because the raw conversation text is deleted under 2.5 and participants are unidentified, Cimedya cannot locate or contact a participant. This is a deliberate design choice and may not be construed as negligence.
7.4 The organisation’s crisis protocol. Before deploying the Platform, the organisation must establish and communicate its own internal crisis and harassment-reporting protocol (within the framework of Circular 2025/3 and article 4 of Law no. 6331).
8. Data protection
8.1 Roles.
- Employee assessment data: organisation = controller, Cimedya = processor (under a written agreement per KVKK article 12/2).
- Panel account and billing data, and marketing-site contact-form data: Cimedya = controller (see 8.9).
8.2 Data processed. For participants: a session record linked to the access code, structured findings, and technical logs. No name, e-mail, phone, location, device identifier or biometric data is processed. Raw conversation text is held only for the duration of the assessment, then deleted (2.5).
8.3 Special categories. Because workplace harassment and psychosocial risk findings may carry inferences about mental health, they are treated as bordering on special category personal data under KVKK article 6 and are subject to the highest protection standard in this agreement.
8.4 Legal bases. A single explicit consent is collected from the participant for processing and transfer to the AI infrastructure. Processing beyond that rests not on consent but on the KVKK conditions concerning the performance of obligations in the fields of employment and occupational health and safety and compliance with a legal obligation of the controller. These are presented to the participant as transparency information, not asked as consent. The distinction is deliberate: because the freely-given element of consent is contested in an employer-employee relationship, the continuity of the service is not made to depend on a single consent. Consent is not made a precondition of the service and multiple purposes are not bundled into one checkbox.
8.5 Retention. Raw conversation text is deleted immediately on completion. Retention periods for structured findings, the aggregated report, the consent ledger and technical logs are set out in the Order Form and the privacy notice. Invoices and commercial books are retained for the mandatory periods prescribed by financial legislation; that exception covers accounting records only, never assessment data.
8.6 International transfer. Hosting and AI processing take place on Google Cloud / Vertex AI in the europe-west3 (Frankfurt) region. Under KVKK this is a transfer abroad and follows the sequence set out in KVKK article 9: an adequacy decision where one exists; failing that, appropriate safeguards such as the standard contract published by the Board, or an undertaking. Where the standard contract route is used, signature is notified to the Authority within the period prescribed by legislation; where the undertaking route is used, transfers do not begin before Board authorisation. The organisation shall meet its own notification and authorisation duties; Cimedya shall put in place the contracts in its own chain.
8.7 Sub-processors. Cimedya shares its current sub-processor list on request. New sub-processors are notified at least 30 days in advance; if the organisation objects on reasonable grounds within that period and no solution is found, it may terminate without penalty. Cimedya is liable for its sub-processors’ acts as for its own.
8.8 Data subject requests. Participant requests are made to the organisation as controller under KVKK article 13. Cimedya forwards any request received directly to the organisation without delay and assists in preparing the response. Because participants are unidentified, Cimedya cannot match a requester to its records.
8.9 Contact form — a separate relationship. Name, organisation, e-mail, phone and message collected via the marketing-site contact form are identifying and are held in a system entirely separate from assessment data. For this data Cimedya is itself the controller. Nothing entered in this form is linked to assessment data.
8.10 Commercial electronic messages. For commercial electronic messages sent under Law no. 6563, the recipient’s right to refuse always remains and may be exercised through the Message Management System (İYS). Cimedya ceases sending within the statutory period after receiving a refusal.
8.11 AI and emotion inference. Cimedya does not, and undertakes not to, infer emotion from biometric data (2.3). This aligns with article 5(1)(f) of Regulation (EU) 2024/1689 (the AI Act), which prohibits AI systems inferring emotions in workplace and educational settings. Consent is no cure for that prohibition. The prohibition has been adopted as a design constraint in case the organisation has staff based in the European Union.
9. Intellectual property
9.1 The Platform, its source code, interface, question catalogue, scoring engine, and the “ControlAtWork”, “OwO” and “Cimedya” names and all related rights belong to Cimedya. This agreement grants the organisation only a non-exclusive, non-transferable, non-sublicensable right of use limited to the subscription term.
9.2 The organisation’s data. Organisational information entered and aggregated reports produced for the organisation belong to the organisation; Cimedya uses them solely to provide the service.
9.3 Improvement and statistics. Cimedya may use fully anonymous aggregate statistics, subject to the minimum aggregation threshold and incapable of being traced back to any organisation or individual, to improve the service. Raw conversation text may not be used for this — it has already been deleted. The organisation’s trade name may not be used as a reference without its separate written consent.
9.4 Feedback. Suggestions and feedback provided by the organisation may be used by Cimedya without compensation and without time limit.
10. Fees, invoicing and tax
10.1 Subscription fee, term and scope are set out in the Order Form. Unless stated otherwise, amounts are exclusive of VAT.
10.2 Payment is due within the term set out in the Order Form. On default, article 1530 of the Turkish Commercial Code no. 6102 is reserved.
10.3 Suspension. Where payment is later than the period set out in the Order Form, Cimedya may suspend the service after written notice and at least 7 days’ grace. Data is not deleted during suspension.
10.4 Price changes. Price changes are notified in writing at least 30 days before the end of the current subscription term and apply only to the renewed term.
10.5 Records. Invoices are issued as required by law. Commercial books, documents and tax records are retained for the mandatory periods prescribed by financial legislation. This retention is not an exception to the deletion undertakings in 8.5; it covers only invoicing and accounting records.
10.6 Consumer law. As the organisation acquires the service for commercial or professional purposes, it is not a consumer under Consumer Protection Law no. 6502; that Law’s distance-contract, withdrawal-right and consumer arbitration provisions do not apply.
11. Service levels, maintenance and change notice
11.1 Availability. The target monthly availability rate and the service credit applying where the target is missed are set out in the Order Form.
11.2 Planned maintenance. Notified at least 48 hours in advance and performed, where possible, during low-usage hours.
11.3 Emergency maintenance. In the event of a security vulnerability or data-integrity risk, emergency maintenance may be performed without notice; the organisation is informed without undue delay afterwards.
11.4 Change notice. Material changes adverse to the organisation, to this agreement or to the scope of the service, require at least 30 days’ written notice. If the organisation objects within that period it may terminate at the end of the term without penalty. Mandatory adaptations required by changes in law are not subject to that period but are notified with reasons.
11.5 Unamendable undertakings. Clauses 2.3 (operations not performed), 2.4 (audio never leaving the browser), 2.5 (deletion of raw text), 2.8 (minimum participant count) and 4.5 (minimum aggregation threshold) may not be changed to the organisation’s detriment without its written consent; they fall outside any unilateral amendment right.
12. Limitation of liability
12.1 Mandatory floor. Under article 115 of the Turkish Code of Obligations no. 6098, any agreement purporting to exclude in advance liability arising from the obligor’s gross negligence is absolutely void. Nothing in this section limits Cimedya’s liability for intent or gross negligence; for death or personal injury; or any other liability that may not lawfully be limited.
12.2 What may be limited. Subject to the mandatory floor above, Cimedya’s aggregate liability for slight negligence is limited to the subscription fees actually paid by the organisation in the twelve months preceding the event giving rise to the loss.
12.3 Indirect loss. In cases of slight negligence, Cimedya is not liable for indirect loss such as loss of profit, loss of reputation, business interruption or loss of data use.
12.4 Exclusions. Cimedya is not liable for:
- the organisation’s breach of section 4 and the resulting labour, criminal or data protection liability;
- the truthfulness, completeness or deliberate distortion of participants’ statements;
- the organisation’s misinterpretation of the report or failure to take measures on the findings (4.8);
- contaminated data resulting from leakage of the access code through the organisation’s fault;
- issues originating in the participant’s own browser, device or operating system.
12.5 Indemnity. The organisation shall bear third-party claims, administrative fines and reasonable defence costs incurred by Cimedya arising from the organisation’s breach of section 4 or section 6. Administrative fines imposed on the organisation in its capacity as controller are its own.
12.6 Notice period. The organisation shall notify Cimedya in writing of any claim for breach within 60 days of becoming aware of it. This is a procedural requirement and does not shorten statutory limitation periods.
13. Term, termination and post-termination data
13.1 Term. This agreement runs for the subscription term set out in the Order Form and renews for equal terms unless notice is given. Non-renewal notice must be given at least 30 days before term end.
13.2 Ordinary termination. Either party may terminate effective at term end on the notice period set out in the Order Form.
13.3 Termination for cause. Cimedya may terminate immediately and without compensation, and close access, on breach of 4.2, 4.3, 4.4, 4.5, 4.6 or section 6. The organisation has the same right on Cimedya’s breach of 2.3, 2.4, 2.5, 2.8 or 11.5.
13.4 Payment default. Cimedya may terminate for amounts unpaid despite the notice and grace period in 10.3.
13.5 Return of data. Within 30 days of termination the organisation may request delivery of its aggregated reports in a machine-readable format.
13.6 Destruction. At the end of that 30-day window — or immediately on the organisation’s earlier request — all organisational data held by Cimedya and its sub-processors is deleted, destroyed or anonymised within the period set out in the retention and destruction policy, and a written certificate of destruction is issued. Data in backups is destroyed on completion of the backup cycle and within the same period at the latest. Mandatory financial records under 10.5 are excepted.
13.7 Survival. Clauses 4.3, 4.4, 8, 9, 12, 13.6 and 16 survive termination.
14. Force majeure
14.1 Earthquake, flood, fire, epidemic, war, terrorism, mobilisation, general strike, act of public authority, nationwide power or internet infrastructure failure, cyber-attack and similar events beyond the parties’ reasonable control constitute force majeure. A force majeure event affecting the cloud infrastructure provider is likewise force majeure for Cimedya.
14.2 The affected party shall give written notice within 5 business days; obligations are suspended for the duration of the event.
14.3 If force majeure exceeds 60 days, either party may terminate without compensation, with a pro-rata refund for the unperformed period.
14.4 Force majeure does not suspend the breach-notification duty in 5.8 or the data protection obligations in section 8.
15. Assignment, notices, severability
15.1 Assignment. The organisation may not assign without Cimedya’s written consent. Cimedya may assign in a merger, demerger or transfer of business, on 30 days’ notice, during which the organisation may terminate without penalty. Data protection obligations bind the assignee identically.
15.2 Notices. Notices are given to the addresses in the Order Form by registered electronic mail (KEP), notary or registered post with return receipt. Routine operational notices (maintenance, releases, sub-processor list) may validly be given by e-mail; termination, breach and price notices require written form. Address changes must be notified within 7 days, failing which notice to the old address is valid.
15.3 Severability. Invalidity of one provision does not affect the others; the invalid provision is replaced by the valid provision closest to the parties’ intent.
15.4 Waiver. Failure to exercise a right is not a waiver of it.
15.5 Entire agreement. This agreement and its annexes supersede all prior written or oral understandings on the subject.
15.6 Independent parties. No partnership, agency or employment relationship is created.
15.7 Language. The Turkish text is the original. This English translation is for information; in case of conflict the Turkish text prevails.
16. Governing law and jurisdiction
16.1 This agreement is governed by the laws of the Republic of Türkiye.
16.2 The courts and enforcement offices of Ankara have jurisdiction.
16.3 In commercial disputes, the provisions making recourse to mediation a procedural precondition for claims for payment of a sum of money and for compensation are reserved.
16.4 Mandatory jurisdiction rules arising from employee status are reserved, as are administrative remedies: the Personal Data Protection Authority for data protection matters and the Ministry of Labour and Social Security for employment matters.
Contact
For questions about these terms: info@oculawork.com