Bu Hizmet Kullanım Sözleşmesi, Gizlilik Politikası ve KVKK Aydınlatma Metni (birlikte "Sözleşme") aşağıdaki taraflar arasında akdedilmiştir:
OculaWork — oculawork.com alan adı üzerinden çalışan göz sağlığı ve yorgunluk analizi platformu ("OculaWork", "Platform", "Biz").
| Ticaret Unvanı | Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. |
| Vergi Dairesi / No | Maltepe V.D. — 2100357903 |
| Tebligat Adresi | Söğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara |
| E-posta | info@oculawork.com |
OculaWork'e abone olan, Platform'u kendi çalışanları için kullanan her türlü gerçek veya tüzel kişi, şirket, kurum ya da kuruluş ("Müşteri", "İşveren", "Siz").
Müşteri bünyesinde çalışan, Müşteri tarafından sisteme tanımlanan ve Platform üzerinden ölçüm gerçekleştiren kişiler ("Çalışan", "Son Kullanıcı").
| Terim | Tanım |
|---|---|
| Platform | oculawork.com ve bağlı alt domainlerinde sunulan yazılım, arayüzler ve tüm hizmetler bütünü |
| KVKK | 6698 sayılı Kişisel Verilerin Korunması Kanunu ve ilgili yönetmelikler |
| İSG Kanunu | 6331 sayılı İş Sağlığı ve Güvenliği Kanunu |
| Veri Sorumlusu | KVKK Md. 3/1-ı — İşleme amaç ve vasıtalarını belirleyen kişi. Çalışan verisinin Platform üzerinden işlenmesi bakımından Müşteri (bkz. §7.5) |
| Veri İşleyen | KVKK Md. 3/1-ğ — Veri sorumlusunun verdiği yetkiye dayanarak onun adına veriyi işleyen. Müşteri adına yürütülen çalışan verisi işleme faaliyetleri bakımından OculaWork (bkz. §7.5) |
| Altyapı Sağlayıcısı | Google Firebase / Google Cloud — verinin fiziksel olarak barındırıldığı platform; OculaWork'ten bağımsız bir tüzel kişi |
| Özel Nitelikli Veri | KVKK Md. 6 — Sağlık, biyometrik veriler dahil hassas kategori |
| EAR / PERCLOS | Göz açıklık oranı / göz kapama yüzdesi — Platform'un ölçtüğü kamera tabanlı fizyolojik ve davranışsal göstergeler. Bir verinin biyometrik veri niteliği taşıyıp taşımadığı, yalnızca sayısal olmasına göre değil, verinin belirli bir kişiyi benzersiz biçimde tanımlamak veya doğrulamak amacıyla kullanılıp kullanılmadığına göre somut olarak değerlendirilir (bkz. §7.1) |
| Açık Rıza | KVKK Md. 3/1-a — Belirli bir konuya ilişkin, bilgilendirmeye dayanan, özgür iradeyle verilen rıza |
| VERBİS | Kişisel Verileri Koruma Kurumu'nun Veri Sorumluları Sicili Bilgi Sistemi |
| SaaS | Software-as-a-Service — abonelik modeliyle sunulan bulut tabanlı yazılım hizmeti |
OculaWork; işyerlerinde çalışma koşulları, ergonomik maruziyet ve operasyonel risklerin değerlendirilmesine destek olmak amacıyla, standart bilgisayar kamerası aracılığıyla göz ve yüz hareketlerinden ölçülebilir davranışsal ve ergonomik göstergeler üreten, bilimsel literatürde yer alan yöntemlerden yararlanan ve işverenlere / iş yeri hekimlerine risk bazlı raporlar sunan bir SaaS platformudur. Platform tıbbi teşhis, hastalık taraması, tıbbi durum izleme veya tedavi amacı taşımaz; tıbbi karar vermez.
OculaWork, yüksek erişilebilirlik hedefiyle çalışmakla birlikte planlı bakım, mücbir sebep veya altyapı sağlayıcısından kaynaklanan kesintilerden sorumlu tutulamaz. Planlı kesintiler 48 saat öncesinden duyurulur. Bu, sayısal bir yüzde taahhüdü değil, genel bir hedef niteliğindedir; bir hizmet seviyesi taahhüdü (SLA) veya hizmet kredisi (service credit) programı oluşturmaz. Erişilebilirlik değerlendirilirken: ilgili aydaki toplam süre esas alınır; planlı bakım süreleri (bkz. aşağıda) ve Google Firebase/Google Cloud altyapısından kaynaklanan kesintiler bu değerlendirmeye dahil edilmez (bkz. §10.3).
Aynı fiyatlandırma dönemi içinde (bkz. §12) yürürlükteki abonelik ücreti değiştirilmez; fiyat değişikliği yalnızca bir sonraki yenileme döneminden itibaren uygulanabilir.
Planlı bakım, mümkün olduğunca hafta sonu veya gece saatlerinde yapılır ve tek seferde en fazla 4 saat sürecek şekilde planlanır. Platformun güvenliğini veya bütünlüğünü tehdit eden acil bir durum söz konusuysa (örn. aktif saldırı), acil bakım önceden bildirim yapılmaksızın uygulanabilir.
| Kapsam | Detay |
|---|---|
| Destek saatleri | Her gün 08:00–20:00 (Türkiye saati) |
| Kritik arıza (sistem tamamen erişilemez durumda) | Destek saatleri içinde 24 saat içinde ilk yanıt |
| Normal destek talebi | 2 iş günü içinde ilk yanıt |
| Yeni özellik talepleri | Değerlendirmeye alınır, teslim tarihi taahhüt edilmez |
Yukarıdaki yanıt süreleri yalnızca destek talebinin alındığını ve işleme koyulduğunu ifade eder; kesin bir çözüm süresi taahhüdü oluşturmaz.
Platform üzerinde "beta", "önizleme" veya "deneysel" olarak işaretlenen özellikler (yeni geliştirilen yapay zeka modülleri dahil) ön izleme niteliğindedir; kesintiye uğrayabilir, beklenmedik şekilde değişebilir veya kaldırılabilir. Bu özellikler için sonuç garantisi verilmez ve Sözleşme'nin genel hizmet sürekliliği/SLA taahhütleri bu özellikleri kapsamaz. Beta özellikler, veri kaybına veya hatalı veri üretimine yol açabilir; Müşteri, beta özellikleri kritik/tek kaynaklı veri için kullanmamalıdır.
OculaWork, ileride üçüncü taraf sistemlerle (kimlik/dizin servisleri, kurumsal iletişim araçları, ERP/İK yazılımları vb.) entegrasyon sunabilir. Bu tür entegrasyonlar, yayımlandıkları tarihte ayrıca duyurulacak ek şartlara tabidir; işbu Sözleşme hâlihazırda var olmayan bir entegrasyonu taahhüt etmez. Aynı şekilde, ileride bir genel API sunulması hâlinde; kullanım limitleri (rate limit), API anahtarı yönetimi ve kötüye kullanım politikaları ayrı bir API Kullanım Şartları belgesinde düzenlenir.
Platform, yalnızca iş hekiminin başlatabileceği (tek yönlü), çalışanla doğrudan görüntülü görüşme kurulmasını sağlayan bir özellik sunar. Bağlantı, üçüncü bir sunucudan geçmeden doğrudan iki cihaz arasında (WebRTC, ücretsiz Google STUN sunucusu) kurulur; ses/görüntü hiçbir sunucuda kaydedilmez veya saklanmaz. Görüşmeyi kurmak için gereken teknik bağlantı verisi (SDP/ICE), görüşme bitiminden birkaç saniye sonra otomatik olarak silinir. Görüşme sırasında, çalışanın kamera görüntüsünden — yalnızca görüşme süresince ve yalnızca o an görüşmedeki hekime gösterilmek üzere — kamera tabanlı yaklaşık bir nabız tahmini ile göz kırpma/PERCLOS bazlı anlık bir yorgunluk-stres göstergesi hesaplanır. Bu göstergeler tıbbi ölçüm veya teşhis niteliği taşımaz, klinik cihazın yerini tutmaz ve çalışanın kalıcı tarama geçmişine hiçbir zaman eklenmez/kaydedilmez. TURN sunucusu kullanılmadığından, çok katı kurumsal ağ/güvenlik duvarı yapılandırmalarında bağlantı nadiren kurulamayabilir.
| Aşama | Nerede İşlenir / Saklanır | OculaWork Erişimi |
|---|---|---|
| Kamera görüntüsü (ham video) | Yalnızca kullanıcının tarayıcısı (RAM) — hiçbir yere gönderilmez | ❌ Erişim yok |
| Hesaplanan sayısal metrikler (EAR, PERCLOS vb.) | Google Firebase Firestore (Google Cloud altyapısı) | Yazılım yönetimi için sınırlı admin erişimi |
| Kullanıcı hesap bilgileri | Google Firebase Authentication | Yazılım yönetimi için sınırlı admin erişimi |
| Uygulama dosyaları (HTML, JS) | Google Firebase Hosting (CDN) | Tam erişim — yazılım sahibi |
| OwO danışma profili (anonim sayısal metrikler — bkz. §7.4) | Google Cloud Functions (Avrupa) → yalnızca 0-1 arası bir sektörel bağlam skoru (owoContextScore) tarama kaydına eklenir | Kimlik bilgisi hiçbir zaman gönderilmez/işlenmez |
| OwO eğitim örneği (anonim özellik vektörü + etiket — bkz. §7.4) | Google Firebase Firestore (Avrupa) — yalnızca sayısal vektör, tarih ve 0/1 etiket; kimlik veya firma bilgisi hiçbir zaman içermez | Kimseye açık değil (admin dahil); yalnızca model eğitimi tarafından okunur, 180 gün sonra otomatik silinir |
| Doktor ekranınca tanınan ilaç adı (yalnızca sedasyon sınıfı sorgusu için) | Google Cloud Functions (Avrupa) — sorgu anlıktır, sonuç veya sorgu hiçbir yere kaydedilmez | Yalnızca doktorun zaten erişim yetkisi olan anamnez verisinden türetilir |
| OwO geri bildirimi (👍/👎, bkz. §7.4) | Google Firebase Firestore (Avrupa) — yalnızca bilgi türü + faydalı olup olmadığı | Kimseye açık değil (admin dahil); yalnızca toplulaştırılmış oran sunucu tarafında hesaplanır |
| Hekimin klinik doğruluk değerlendirmesi (bir tarama için "isabetli/düşük/yüksek/sevk gerekli", bkz. §7.4) | Google Firebase Firestore (Avrupa) — o tarama kaydına bağlı olarak saklanır; OwO'nun eğitimine anonim, düzeltilmiş bir etiket olarak dahil edilir | Yalnızca ilgili kiracının hekim/yönetimine açık |
| Hata bildirimi ve otomatik yakalanan teknik tanı verisi (tarayıcı hatası, cihaz/tarayıcı bilgisi — bkz. §9.4) | Google Firebase Firestore (Avrupa) | Yalnızca OculaWork admin'i erişebilir; çalışanın kendi işvereni bu veriyi göremez |
Google Firebase; Google LLC'ye bağlı, bağımsız bir bulut altyapısı ve veri barındırma hizmetidir. Firebase'in veri işleme koşulları ve güvenlik önlemleri Google'ın Gizlilik Politikası ile Firebase Veri İşleme Şartları'na tabidir.
Müşteri'ye ait tüm veriler (tarama sonuçları, raporlar, hesap bilgileri) Müşteri'ye aittir; OculaWork bu veriler üzerinde Sözleşme'de tanınanlar dışında hak iddia etmez. Kişisel veriler klasik anlamda mülkiyet konusu değildir; bu hüküm, Müşteri tarafından sağlanan ve Müşteri adına işlenen veriler üzerindeki kullanım ve tasarruf haklarını düzenler, ilgili kişilerin KVKK'dan doğan haklarını etkilemez. Müşteri talep ettiğinde verilerin dışa aktarımı sağlanır; dışa aktarım yalnızca OculaWork'ün o tarihte desteklediği formatlarda (örn. JSON/CSV) yapılır, başka bir format garanti edilmez. Dışa aktarım sırasında verinin OculaWork tarafındaki bütünlüğü korunur; ancak dışa aktarılan verinin üçüncü taraf sistemlerle (ör. Müşteri'nin kendi ERP/İK yazılımı) uyumluluğu veya bu sistemlere aktarımdan sonraki bütünlüğü garanti edilmez. Sözleşme sona erdiğinde veriler 90 gün içinde sistemden kalıcı olarak silinir. Bu 90 günlük süre, sözleşme sona erdikten sonra erişilebilir durumdaki operasyonel verilerin silinmesine ilişkindir; §7.2'de belirtilen saklama süreleri ile mevzuattan doğan saklama yükümlülükleri saklıdır. Hesap kapatılsa/veriler silinse dahi, muhasebe mevzuatı (VUK vb.), işlem kayıtları ve KVKK kapsamındaki yasal saklama yükümlülükleri nedeniyle bazı kayıtlar (örn. fatura bilgileri) yasal saklama süreleri boyunca ayrıca tutulabilir.
Müşteri, bünyesindeki çalışanların kişisel verilerinin işlenmesi bakımından 6698 sayılı KVKK kapsamında, çalışan verisinin Platform üzerinden işlenmesi bakımından Veri Sorumlusu sıfatını haizdir. Bu kapsamda aşağıdaki yükümlülükleri OculaWork'ten bağımsız olarak yerine getirir:
OculaWork; bir yazılım sağlayıcısıdır ve Müşteri verilerini yalnızca Müşteri'nin talimatları ve bu Sözleşme çerçevesinde işler. Verileri kendi menfaatine, üçüncü taraf pazarlamasına veya başka amaçlara kullanmaz.
| Alt İşleyen | Amaç | Veri Konumu |
|---|---|---|
| Google Firebase Firestore | Veri depolama | Avrupa (eur3) |
| Google Firebase Authentication | Kimlik doğrulama | Avrupa |
| Google Firebase Hosting | Uygulama barındırma | Global CDN |
| Google Cloud Functions | Arka uç işlemler | Avrupa |
| Resend | Kimlik bilgisi/bildirim e-postalarının gönderimi ve info@oculawork.com adresine gelen postanın yönlendirilmesi | Amerika Birleşik Devletleri. Sağlayıcı, kendi belgelerinde birincil işleme operasyonlarının ABD'de yürütüldüğünü ve kişisel verilerin AEA/Birleşik Krallık/İsviçre dışına aktarılabileceğini belirtmektedir. Bu nedenle e-posta kanalı KVKK Md. 9 aktarım zincirinin bir parçası olarak değerlendirilir (bkz. §4.2). Veri minimizasyonu: bu kanaldan bireysel ölçüm sonucu, yorgunluk/risk skoru veya sağlıkla ilişkili kişisel değerlendirme gönderilmez; yönetim raporlarında yalnızca §11'deki eşikleri geçmiş toplulaştırılmış veriler yer alır |
OculaWork, hizmetin sunulması amacıyla altyapı, barındırma, e-posta, güvenlik, analiz veya destek hizmeti sunan alt işleyenlerden yararlanabilir. Güncel alt işleyen listesi, işleme amaçları ve veri konumları yukarıda gösterilir ve Müşteri'nin erişimine açıktır.
Yeni bir alt işleyenin kişisel verilere erişimini gerektiren değişiklikler, yürürlüğe girmeden en az 30 gün önce Müşteri'ye bildirilir. Müşteri, haklı ve makul veri koruma gerekçeleriyle bu değişikliğe itiraz edebilir; itiraz hâlinde taraflar makul bir çözüm üzerinde iyi niyetle görüşür.
OculaWork, Müşteri'ye ait verileri yalnızca şu durumlarda üçüncü taraflarla paylaşır:
Taraflar, kişisel veriler veya bilgi güvenliği ile ilgili resmi inceleme, denetim veya yargısal süreçlerde birbirlerine makul ölçüde destek sağlamayı kabul eder.
Müşteri tarafından belirlenen amaç ve vasıtalar kapsamında yürütülen çalışan verisi işleme faaliyetlerinde Müşteri Veri Sorumlusu, OculaWork ise KVKK Md. 3/1-ğ uyarınca Veri İşleyen sıfatını taşır. OculaWork'ün kendi amaçlarıyla yürüttüğü faaliyetler (hesap yönetimi, faturalama, güvenlik kayıtları) bakımından sıfatı §7.5'te düzenlendiği üzere ayrıca belirlenir. Veri işleyen sıfatını taşıdığı faaliyetlerde OculaWork:
| Kategori | Örnek Veriler | Amaç | Hukuki Dayanak |
|---|---|---|---|
| Kimlik | Ad, soyad | Hesap yönetimi | KVKK Md. 5/2-c — Sözleşmenin ifası |
| İletişim | E-posta | Bildirimler | KVKK Md. 5/2-c — Sözleşmenin ifası |
| Sağlık / fizyolojik gösterge | EAR, PERCLOS, yorgunluk skoru | İSG risk analizi | KVKK Md. 6/3 — somut olaya uygulanabilir şart (bkz. §8.1); 6331 Md. 15 tek başına dayanak oluşturmaz |
| Davranışsal | Reaksiyon süresi, kırpma hızı | İSG risk analizi | KVKK Md. 5/2-f — meşru menfaat (Müşteri tarafından menfaat dengesi testi yapılmış olmak kaydıyla); denge testinin karşılanmadığı hâllerde Md. 5/1 uyarınca açık rıza |
| Organizasyon | Departman, vardiya | Raporlama | KVKK Md. 5/2-c — Sözleşmenin ifası |
| İşlem | Tarama tarihi/saati | Denetim kaydı | KVKK Md. 5/2-f — Meşru menfaat |
| Hekim klinik notu | İş yeri hekiminin bir çalışan hakkında yazdığı, bütünlüğü korunan klinik not (bkz. §7.2, §9.4) | Sağlık gözetimi kayıt bütünlüğü | KVKK Md. 6/3 — somut olaya uygulanabilir şart (bkz. §8.1) |
| Anket cevabı | Firma yönetiminin yayınladığı tek soruluk ankete çalışanın verdiği cevap | İSG risk analizi (OwO girdisi, bkz. §7.4), raporlama | KVKK Md. 5/2-f — meşru menfaat (Müşteri tarafından menfaat dengesi testi yapılmış olmak kaydıyla); denge testinin karşılanmadığı hâllerde Md. 5/1 uyarınca açık rıza |
| Teknik hata bildirimi | Kullanıcının yazdığı serbest metin + otomatik yakalanan tarayıcı hatası/cihaz bilgisi (bkz. §9.4) | Yazılım hatalarının teşhisi ve giderilmesi | KVKK Md. 5/2-f — Meşru menfaat |
| Bildirim/hatırlatma | Anlık bildirim gönderimi için cihaz push token'ı; hekimin belirli bir çalışan için oluşturduğu hatırlatma notu ve zamanı | Sağlık gözetimi takibi, sistem bildirimleri | KVKK Md. 5/2-c — Sözleşmenin ifası / Md. 6/3 |
| Veri Türü | Saklama Süresi |
|---|---|
| Ölçüm metrikleri ve raporlar | İç saklama politikamız kapsamında aktif abonelik + 2 yıl; ilgili mevzuattan doğan yasal saklama süreleri ve veri saklama-imha politikası saklıdır |
| Hesap ve kimlik bilgileri | Sözleşme sona ermesinden itibaren 90 gün |
| İşlem kayıtları (log) | 6 ay |
| OwO eğitim örnekleri (kimlik bilgileri ve doğrudan tanımlayıcılar içermeyen sayısal özellik vektörü + etiket; anonimlik değerlendirmesi ayrıca yapılır — bkz. §7.4) | 180 gün — her eğitim turunda otomatik olarak silinir |
Yüz biyometrik şablonu (faceEmbedding — yüz doğrulama için) | Aktif abonelik boyunca; çalışan "Verilerimi Sil" talebinde bulunduğunda veya hesabı kapatıldığında derhal ve otomatik olarak silinir |
Cihaz-içi öğrenme model ağırlıkları (federated_weights — bkz. §7.4) | Aktif abonelik boyunca; çalışan "Verilerimi Sil" talebinde bulunduğunda veya hesabı kapatıldığında silinir. Bu ağırlıklar önceden aynı firmadaki diğer çalışanların modelleriyle toplu (federe) olarak ortalanmış olabilir — bu durumda kişiye özel belgenin silinmesi, katkısının önceki toplu ortalamalardaki matematiksel izinin geriye dönük olarak tamamen kaldırılacağını garanti etmez |
| Hekim klinik notları | İş yeri hekimi tarafından oluşturulan sağlık gözetimi kayıtları, ilgili İSG mevzuatında öngörülen saklama süreleri ve KVKK'nın saklama ilkeleri çerçevesinde muhafaza edilir. Çalışma ve Sosyal Güvenlik Bakanlığı İSG Genel Müdürlüğü, kişisel sağlık dosyalarının çalışanın işten ayrılma tarihinden itibaren en az 15 yıl saklanması gerektiğini belirtmektedir. Kayıtlar, bütünlüğü korunacak şekilde tutulur; yazıldıktan sonra geçmişe dönük değiştirilmesi engellenir (bkz. §9.4). Silme talepleri, uygulanabilir yasal saklama yükümlülükleri saklı kalmak kaydıyla değerlendirilir |
| Uyarı/alarm kayıtları, klinik doğrulama geri bildirimi, muayene takvim kayıtları, başarısız yüz doğrulama güvenlik logu | Çalışanın kendi "Verilerimi Sil" talebiyle OTOMATİK silinmez — hekim klinik notlarıyla AYNI gerekçeyle (İSG/güvenlik denetim izi bütünlüğü) bilinçli olarak korunur. Silinmesi gerekiyorsa info@oculawork.com üzerinden admin aracılığıyla talep edilebilir. |
| Hata bildirimi ve teknik tanı verisi | OculaWork admin'i tarafından manuel olarak silinene kadar |
| Silme talebi sonrası | Talep tarihinden itibaren 30 gün içinde imha (hekim klinik notları hariç — yukarıya bkz.) |
Çalışanlar KVKK haklarını kendi işverenleri (Müşteri) aracılığıyla kullanır. OculaWork bu talepleri Müşteri'nin yönlendirmesiyle 30 gün içinde karşılar:
Yukarıdaki itiraz hakkının somut şekilde kullanılabilmesi için, Platform'da çalışan hakkında sonuç doğurabilecek otomatik/yarı-otomatik işleme noktaları açıkça belirtilir: (i) günlük tarama sonucu üretilen yorgunluk risk seviyesi (düşük/orta/yüksek/kritik), (ii) CUSUM ve İzolasyon Ormanı (Isolation Forest) tabanlı istatistiksel anomali tespiti uyarıları, (iii) "OwO" sektörel öğrenme modelinin, ilgili taramanın anonim sayısal profiline dayanarak ürettiği ve yalnızca bilgi amaçlı gösterilen sektörel bağlam skoru (owoContextScore, bkz. §7.4) — bu üç işleme noktası da yalnızca iş hekimine gösterilir, hiçbiri tek başına otomatik bir personel kararına dönüşmez. OwO'nun eğitim verisi ve model ağırlıkları kimlik bilgisi içermez; kimlikten ayrıştırılmış ve anonimleştirme amacıyla teknik ve idari tedbirlerden geçirilmiş verilerdir. Bu tedbirlerin uygulanmış olması tek başına söz konusu verinin hukuken anonim olduğu anlamına gelmez; anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır (bkz. §7.4). ancak danışma katmanının bilgi amaçlı ürettiği sektörel bağlam skoru, ilgili taramaya özel, bilgilendirici bir gösterge olarak yukarıdaki (iii) numaralı işleme noktasını oluşturur. Bir çalışan, risk seviyesi, anomali uyarısının veya sektörel bağlam skorunun kendisi hakkında olumsuz bir personel kararına (görev değişikliği, disiplin vb.) tek başına dayanak oluşturduğunu düşünüyorsa, işverenine itiraz edebilir; işveren böyle bir itirazı değerlendirirken kararın bir insan (iş hekimi/İK) tarafından gözden geçirilmesini sağlamakla yükümlüdür.
KVKK Md. 3/1-d uyarınca kişisel veri, kimliği belirli veya belirlenebilir gerçek kişiye ilişkin her türlü bilgiyi ifade eder. Geri döndürülemez şekilde anonim hâle getirilmiş veri bu tanımın dışında kalır ve KVKK hükümleri bu veriler bakımından uygulanmaz. OculaWork, Müşterilerin (dağıtım moduna göre kapsamı değişir — bkz. madde 5) tarama ve öz-değerlendirme verilerinden, sektör genelinde çalışan istatistiksel bir öğrenme modelini ("OwO") eğitir; bu eğitimde doğrudan kimlik ve şirket tanımlayıcıları içermeyecek şekilde teknik olarak ayrıştırılmış ve minimize edilmiş sayısal özelliklerden yararlanılır.
Bu işleme aşağıdaki teknik ve hukuki güvencelerle sınırlıdır:
modelSurumu, ornekSayisi, gradyan, gurultuOlcegi) taşınır, en az 50 ölçümden türetilmedikçe, gizlilik artırıcı gürültü uygulanmadıkça ve katkı büyüklüğü sınırlandırılmadıkça oluşturulmaz. Beyaz liste dışındaki her alan sunucu tarafında reddedilir. Kimlik bilgisi bu modelde de Müşteri'nin kendi altyapısında kalır. Bu tekniklerin uygulanmış olması, merkeze ulaşan verinin hukuken anonim olduğu anlamına gelmez; anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır.
Şeffaflık: Bu işlemenin tam teknik detayı — hangi veri kaynağının hangi sinyale indirgendiği dahil — OculaWork Teknik Metodoloji Belgesi'nde ("OwO Eğitim Modeli" başlıklı bölüm) ayrıntılı olarak belgelenmiştir ve talep üzerine Müşteri'ye ve ilgili kişilere sunulur.
KVKK mevzuatı ve Kurul içtihadı zaman içinde değişebilir. Mevzuat değişikliği hâlinde taraflar, işbu Sözleşme'yi ve ilgili uygulamaları güncel mevzuata uyumlu hâle getirmek için makul süre içinde gerekli iş birliğini gösterir.
Çalışanların Platform üzerinden gerçekleştirilen ölçüm faaliyetleri bakımından, işleme amaçlarını ve temel işleme vasıtalarını Müşteri belirlediği ölçüde Müşteri veri sorumlusu, OculaWork ise Müşteri adına hareket eden veri işleyen sıfatındadır.
OculaWork'ün kendi amaçları doğrultusunda gerçekleştirdiği ayrı veri işleme faaliyetleri (kendi müşteri hesap ve abonelik kayıtları, faturalama, destek, kendi pazarlama iletişimi, kendi güvenlik kayıtları gibi) bakımından ise ilgili faaliyet özelinde veri sorumlusu veya veri işleyen sıfatı ayrıca belirlenir.
Tarafların sıfatı, yalnızca sözleşmede kullanılan unvana göre değil, somut işleme faaliyetinin fiili niteliğine ve amaç ile vasıtaları kimin belirlediğine göre değerlendirilir.
Sıfat, faaliyetin amaç ve vasıtalarını kimin belirlediğine göre değişir. Aşağıdaki tablo bağlayıcı bir özet değil, yorum kılavuzudur; somut olayda fiilî durum esastır.
| Faaliyet | Amaç | Rol |
|---|---|---|
| Çalışan ölçümü ve raporlaması | İSG süreçlerine destek | Müşteri veri sorumlusu · OculaWork veri işleyen |
| Müşteri hesabı ve abonelik yönetimi | Hizmetin sunulması | OculaWork veri sorumlusu |
| Faturalama ve muhasebe | Yasal yükümlülük | OculaWork veri sorumlusu |
| Destek talebi yönetimi | Hizmetin sunulması | Talebin içeriğine göre ayrıca belirlenir |
| Güvenlik ve denetim kayıtları | Sistem güvenliği | OculaWork veri sorumlusu |
| Model geliştirme katkısı | Sektörel model | Ayrı hukuki değerlendirme (bkz. §7.4, EK-0.3C) |
EAR, PERCLOS ve yorgunluk skoru; işlemenin niteliğine göre KVKK Madde 6 kapsamında özel nitelikli kişisel veri kapsamında değerlendirilebilecek verilerdir ve bu hâlde ek koruma gerektirir.
Özel nitelikli kişisel verilerin işlenmesi, KVKK m.6/3'te düzenlenen şartlardan somut olaya uygulanabilir olanına dayanır. Açık rıza, bu şartlardan yalnızca biridir; iş ilişkisindeki yapısal güç dengesi ile işlemenin gereklilik ve ölçülülük koşulları ayrıca değerlendirilir.
Platform'un giriş/kimlik doğrulama amacıyla kullanabildiği yüz biyometrisi (face-embedding) özelliği, yorgunluk taraması metriklerinden (EAR/PERCLOS gibi) ayrı bir risk kategorisi oluşturur: bu veri doğrudan kimlik doğrulama amacıyla, işveren tarafından zorunlu tutulan bir biyometrik veri işlemedir. Kişisel Verileri Koruma Kurulu, 04.08.2022 tarih ve 2022/797 sayılı Kararı'nda işyerine giriş-çıkışlarda yüz tanıma sistemiyle biyometrik veri işlenmesini, Kanun'un 6. maddesi kapsamında herhangi bir işleme şartına dayanılmaksızın gerçekleştirildiği gerekçesiyle hukuka aykırı bulmuş; 29.04.2026 tarih ve 2026/921 sayılı İlke Kararı'nda ise mesai takibi amaçlı biyometrik veri işlemenin, çalışanın açık rızası bulunsa dahi hukuka aykırı olduğuna hükmetmiştir — gerekçe olarak işçi-işveren ilişkisindeki yapısal güç dengesizliğinin açık rızanın "özgür irade" unsurunu zedelediği belirtilmiştir. Anılan ilke kararı mesai takibi amaçlı biyometrik tanımlamaya ilişkindir ve Platform'un yorgunluk ölçümüne birebir uygulanmaz; bununla birlikte, çalışan rızasının her durumda otomatik bir güvenli liman oluşturmadığını gösteren güncel bir Kurul yaklaşımıdır. Bu doğrultuda yalnızca açık rızaya dayanmak, biyometrik veri işlemeyi tek başına hukuka uygun kılmayabilir. Müşteri, bu özelliği etkinleştirmeden önce (i) ölçülülük, gereklilik ve veri minimizasyonu ilkelerine uygunluğunu, (ii) şifreli kart/PIN, RFID/NFC kimlik kartı veya cihaz eşleştirme gibi daha az müdahaleci bir alternatifin yeterli olup olmadığını değerlendirmeli ve (iii) kendi hukuki danışmanına başvurmalıdır. OculaWork bu değerlendirmeyi Müşteri adına yapmaz ve bu konudaki hukuki riski üstlenmez.
OculaWork, kişisel verilerin güvenliğini etkileyebilecek bir olaydan haberdar olması hâlinde Müşteri'yi gecikmeksizin ve her hâlükârda 24 saat içinde yazılı olarak bilgilendirir. Bu sözleşmesel bildirim süresi, tarafların KVKK ve diğer uygulanabilir mevzuat kapsamındaki yasal bildirim sürelerini (KVKK Md. 12/5 uyarınca veri sorumlusunun Kurul'a bildirim yükümlülüğü dâhil) değiştirmez. Müşteri de, kendi tarafında (kendi hesapları, ağı veya sistemleri üzerinden) meydana gelen ve Platform verilerini etkileyebilecek bir güvenlik ihlalini fark ettiğinde, bunu gecikmeksizin OculaWork'e bildirmekle yükümlüdür.
| Rol | Erişebildiği Veri | Erişemediği Veri |
|---|---|---|
| Çalışan | Yalnızca kendi tarama sonuçları, kendi YZ Yaşam Koçu içeriği, kendi periyodik öz-tarama kaydı, kendi anket cevabı | Başka hiçbir çalışanın verisi; hekimin kendisi hakkında yazdığı klinik notlar; gönderdiği hata bildirimi ve teknik tanı verisi (yalnızca gönderim anında görünür, sonrasında yalnızca OculaWork admin'ine açıktır) |
| Yönetim / İK | Departman bazlı anonim/toplulaştırılmış istatistikler (min. 5 kişilik gruplar), personel/muayene yönetimi, bireysel anket cevapları, Karakter-Görev Uyum Endeksi (yalnızca en az 10 çalışan Karakter Analizi'ni tamamladığında görünen, tek bir yüzde ve güven değerinden oluşan toplulaştırılmış istatistik — bkz. §7.4) | Bireysel tarama detayları, YZ Yaşam Koçu içeriği (GAD-7/PHQ-9/CBI, Karakter Analizi bireysel sonucu dahil), periyodik öz-tarama anamnezi, hata bildirimi/teknik tanı verisi |
| İş Hekimi | Kendi kiracısındaki bireysel sağlık gözetimi/tarama verisi, TİTCK ilaç eşleştirme, periyodik öz-tarama anamnezi, resmi muayene kayıtları (exam_records), kendi yazdığı kalıcı klinik notlar (bkz. §7.1, §7.2 — İSG mevzuatındaki saklama süreleri çerçevesinde; bütünlüğü korunur, geçmişe dönük değiştirilemez), taramalara verdiği klinik doğruluk geri bildirimi | Çalışanın YZ Yaşam Koçu içeriği (GAD-7/PHQ-9/CBI, Sakinleş, Karakter) — bu veri hekime de kapalıdır; hata bildirimi/teknik tanı verisi |
| OculaWork Admin | Firma/abonelik yönetimi, anonim Veri Havuzu istatistikleri, Modül Kullanım Panosu (yalnızca sayı), OwO eğitim geçmişi (yalnızca ağırlık/skor), tüm kullanıcılardan gelen hata bildirimleri ve otomatik yakalanan teknik tanı verisi (bkz. §7.1) — bu veri, çalışanın kendi işvereniyle (yönetim/hekim) hiçbir zaman paylaşılmaz | Hiçbir çalışanın bireysel verisi, YZ Yaşam Koçu içeriği, anamnez serbest metni, hekim klinik notlarının içeriği — bkz. §7.4 |
Müşteri, KVKK kapsamındaki Veri Sorumlusu yükümlülüklerini yerine getirebilmek amacıyla, OculaWork'ün veri işleme süreçlerine ilişkin bilgi ve belge talep etme hakkına sahiptir. OculaWork, kendi ticari sırlarını ve diğer Müşterilere ait bilgileri ifşa etmeyecek şekilde, makul sıklıkta ve en az 15 gün önceden yazılı bildirim yapılması kaydıyla bu talebi karşılar. Yerinde (on-site) denetim veya bağımsız üçüncü taraf denetimi, ancak tarafların önceden yazılı olarak mutabık kaldığı kapsam, süre ve gizlilik şartları çerçevesinde mümkündür; denetim masrafları aksi kararlaştırılmadıkça talep eden Müşteri'ye aittir.
Platform'da bir güvenlik açığı tespit eden kişiler, bu durumu yalnızca info@oculawork.com adresine, sorumlu açıklama (Responsible Disclosure) ilkeleri kapsamında bildirebilir. Önceden OculaWork'ün yazılı izni alınmaksızın gerçekleştirilen aktif sızma testi, yük testi, fuzzing veya benzeri faaliyetler bu kapsamda değerlendirilmez ve §11.1'de tanımlanan Yasaklı Kullanımlar hükmüne tabidir.
OculaWork'ün herhangi bir nedenle tazminat yükümlülüğüne girmesi hâlinde toplam sorumluluğu, ihlalin gerçekleştiği tarihten önceki son 12 aylık abonelik bedeliyle sınırlıdır. Bu sınırlama; kasıt, ağır ihmal, fikri mülkiyet ihlali veya gizlilik/veri güvenliği yükümlülüklerinin ihlali hâllerinde uygulanmaz.
Taraflar, mücbir sebep süresince ve mücbir sebebin doğrudan etkilediği ölçüde, işbu Sözleşme'den doğan yükümlülüklerini yerine getirememekten sorumlu tutulamaz.
Herhangi bir çalışanın işverenine (Müşteri'ye) karşı Platform verileriyle ilgili dava açması durumunda OculaWork bu davada taraf değildir. Müşteri, OculaWork'ü bu tür davalardan muaf tutmayı ve olası masrafları karşılamayı kabul eder.
Kullanıcı, kendi hesabından yapılan tüm işlemlerden bizzat sorumludur. Şifrenin üçüncü kişilerle paylaşılması hâlinde bundan doğan tüm sonuçlar (veri erişimi, yetkisiz işlem, veri sızıntısı dahil) paylaşımı yapan kullanıcıya ve/veya Müşteri'ye aittir; OculaWork bu durumdan sorumlu tutulamaz. Kullanıcı hesapları kişiye özeldir; hesabın birden fazla kişi tarafından ortak kullanılması lisans ihlali sayılır ve OculaWork bu durumda ilgili hesabı askıya alma hakkını saklı tutar.
OculaWork, işbu Sözleşme kapsamındaki hizmetler için herhangi bir mesleki sorumluluk sigortası (E&O) veya başka bir sigorta taahhüdünde bulunmaz.
Platform, işbu Sözleşme'de açıkça belirtilenler dışında "olduğu gibi" (as-is) ve "mevcut haliyle" (as-available) sunulmaktadır. OculaWork; Platform'un kesintisiz, hatasız veya güvenlik açığından tamamen arınmış çalışacağına, belirli bir amaca uygunluğuna, satılabilirliğine veya Müşteri'nin beklentilerini karşılayacağına dair açık ya da zımni herhangi bir garanti vermez.
Tahliye Tatbikatı modülü; Müşteri'nin kendi çizdiği kat planı üzerinde mekânsal denetim bulguları, gereksinim listesi, senaryo üretimi ve tatbikat kayıtları oluşturan bir karar destek aracıdır. Modülün ürettiği hiçbir çıktı — bulgu, gereksinim, İSG Uyum Skoru, Risk Skoru veya tatbikat raporu dâhil — uygunluk belgesi, yangın güvenliği projesi, kaçış planı onayı veya resmî bir denetim raporu niteliği taşımaz ve yetkili idarelere karşı tek başına hukuki dayanak oluşturmaz.
Girdi sorumluluğu Müşteri'dedir. Kat sınırı, oda ölçüleri, kapı temiz genişlikleri, kat kişi sayısı, tesis türü ve ekipman konumları Müşteri tarafından girilir; OculaWork bu bilgilerin gerçek yapıyla uyumunu doğrulamaz ve doğrulayamaz. Çıktılar, girilen verinin doğruluğu ölçüsünde geçerlidir. Yanlış ya da eksik girilen bir ölçüden kaynaklanan sonuçlardan OculaWork sorumlu tutulamaz.
Ölçüm ile mevzuat sınırı ayrıdır. Sistem, plandan hesapladığı ölçümleri her hâlükârda gösterir; buna karşılık bir mevzuat maddesindeki sayısal sınırı yalnızca kaynağı doğrulanabildiği durumlarda belirtir. Kaynağı doğrulanamayan kalemlerde sınır yazılmaz, ölçüm verilir ve Müşteri'den teyit istenir; bu kalemler skor hesabına da dâhil edilmez. Tehlike sınıfı, yapı kullanım sınıfı, yağmurlama (sprinkler) varlığı, bina yüksekliği ve yapı ruhsatı gibi belirleyici unsurlar sistem tarafından bilinmez; bu unsurlar sonucu değiştirebilir.
İSG Uyum Skoru ve Risk Skoru tahminî göstergelerdir. Yalnızca sistemin denetleyebildiği kalemleri kapsar, ağırlıklandırma yöntemi OculaWork'ün açıkça ilan ettiği bir tasarım tercihidir ve mevzuattan kaynaklanmaz. Yüksek bir uyum skoru mevzuata uygunluk anlamına gelmez; düşük bir risk skoru güvenli bir işyeri anlamına gelmez. Nihai uygunluk değerlendirmesi münhasıran işverene ve görevlendirdiği iş güvenliği uzmanı / işyeri hekimine aittir.
Tatbikat kayıtları ve katılım defteri. Tatbikat sırasında toplanan davranış kayıtları (çizilen rota, süre, verim, soru cevapları) kimlik içermez ve yalnızca küme düzeyinde raporlanır; birey performansı ölçmek için kullanılamaz. Katılım defteri ise idari amaçla kimlik içerir ve davranış kayıtlarıyla birleştirilmez. Modülün ürettiği katılım kaydı, 6331 sayılı Kanun md.11 ve Acil Durumlar Yönetmeliği kapsamındaki tatbikat yükümlülüğünün yerine getirildiğine dair tek başına ispat teşkil etmez; resmî tatbikat tutanağı, tatbikatın fiilen sahada yapılmasına ve işveren tarafından usulüne uygun kayda bağlıdır.
Modül tarafından üretilen senaryolar (yangın, gaz kaçağı, kimyasal sızıntı vb.) eğitim ve farkındalık amaçlı kurgulardır; gerçek bir olayın nasıl gelişeceğine dair mühendislik öngörüsü, yangın modellemesi veya duman yayılım simülasyonu niteliği taşımaz.
Uyum ve risk skorlarının anonim aktarımı. Kat planı kaydedildiğinde, o plandan hesaplanan İSG Uyum Skoru ve Risk Skoru ile plana ilişkin türetilmiş ölçüler (alan, oda/kapı/ekipman sayıları, denetim bulgusu kodları) OculaWork sunucusuna aktarılır ve sektörel karşılaştırma amacıyla kullanılır. Bu aktarımda hiçbir gerçek kişiye ait veri bulunmaz; kimlik, ad, kullanıcı kimliği ve departman bilgisi gönderilmez. Veri bir kişiye değil, bir kat planına ilişkindir ve bu nedenle 6698 sayılı Kanun anlamında kişisel veri niteliği taşımaz.
Plan adı gönderilmez. Kat planına verdiğiniz ad serbest metindir ve işyeri, bina veya kat adı içerebilir; bu ad sunucuya ne olduğu gibi ne de özeti (hash) alınarak iletilir. Aynı planın kayıtlarının zaman içinde birbiriyle ilişkilendirilebilmesi için, içeriği olmayan rastgele bir kimlik yalnızca sizin tarayıcınızda üretilir ve saklanır; bu kimliğin plan adıyla bağı cihazınızdan dışarı çıkmaz. Aynı ada sahip bir plan başka bir cihazda farklı bir kimlik alır.
Aktarılan veriler işyerinize ait ticari bilgi niteliğindedir. Sektörel karşılaştırmalarda tekil bir işyerinin verisinin geri hesaplanmasını önlemek üzere k-anonimlik eşiği uygulanır; eşiğin altındaki gruplarda karşılaştırma gösterilmez. Modül bağımsız da çalışabilir: bu durumda hiçbir veri aktarılmaz ve tüm kayıtlar yalnızca cihazınızda kalır. Aktarım, geçmişe dönük değildir — yalnızca aktarımın etkin olduğu dönemde yapılan kayıtlar gönderilir.
Bu madde, Tahliye Tatbikatı modülünün katılım defteri için geçerlidir. Katılım defteri, modülün kimlik içeren tek kaydıdır; tatbikat sırasında toplanan davranış kayıtları (rota, süre, verim, cevaplar) kimlik içermez ve bu defterle hiçbir yerde birleştirilmez.
Veri sorumlusu ve veri işleyen. Katılım kaydının veri sorumlusu işverendir; OculaWork bu veriyi işverenin talimatıyla işleyen sıfatıyla barındırır.
İşlenen veriler. Sunucuda yalnızca şunlar tutulur: çalışanın kullanıcı kimliği (uid), tatbikatın tarihi ve katılım durumu (tamamladı / yarım bıraktı / süre doldu). Ad, soyad ve departman sunucuya yazılmaz — bu bilgiler zaten çalışan kaydında bulunduğundan ikinci bir kopya oluşturulmaz. Bu defterde rota, puan ve soru cevabı bulunmaz; sistem, bu alanların yazılmasını teknik olarak da reddeder.
İşleme amacı ve hukuki sebep. Veri, 6331 sayılı İş Sağlığı ve Güvenliği Kanunu ve İşyerlerinde Acil Durumlar Hakkında Yönetmelik kapsamındaki tatbikat yükümlülüğünün yerine getirildiğinin belgelenmesi amacıyla işlenir. Hukuki sebep, 6698 sayılı Kanun md.5/2-ç uyarınca veri sorumlusunun hukuki yükümlülüğünü yerine getirmesidir; bu nedenle ayrıca açık rıza aranmaz. Veri, birey performansını ölçmek için kullanılamaz.
Saklama ve imha. Katılım kaydı, işverenin ilgili mevzuat uyarınca İSG kayıtlarını saklamakla yükümlü olduğu süre boyunca saklanır; bu sürenin dolmasıyla silinir veya anonim hâle getirilir. Saklama süresinin belirlenmesi ve kişisel veri envanterine işlenmesi işverenin sorumluluğundadır.
Aktarım. Katılım kaydı üçüncü kişilere aktarılmaz. OculaWork'ün sektörel karşılaştırma amacıyla kullandığı anonim veri kümesine dâhil edilmez (bkz. 10.10).
Haklarınız. 6698 sayılı Kanun md.11 kapsamında verilerinize erişme, düzeltilmesini veya silinmesini isteme ve işlemeye itiraz etme haklarına sahipsiniz. Talebinizi işvereninize iletebilirsiniz.
Bu metin, sistemin fiilen işlediği veriyi ve teknik sınırlarını doğru biçimde tarif eder; işyerinize özgü aydınlatma metninin ve kişisel veri envanterinin hazırlanması ve hukuki uygunluk denetimi işverene aittir.
OculaLearn, 6331 sayılı Kanun md.17 ve "Çalışanların İş Sağlığı ve Güvenliği Eğitimleri Uygulama Rehberi" (R.G. Sayı 33212, 2 Nisan 2026) Ek-1 müfredatına dayalı, ayrı bir Firebase altyapısında (oculalearn.web.app) barındırılan uzaktan İSG eğitim modülüdür. Resmi Ek-1 müfredatının içeriğinden ve doğruluğundan OculaWork sorumludur. Müşteri'nin "İçerik Geliştir" arayüzü aracılığıyla girdiği işyerine özgü Konu-4 içerikleri ve/veya tamamen özel ek eğitimlerin doğruluğu, güncelliği ve mevzuata uygunluğu münhasıran Müşteri'nin sorumluluğundadır; bu içerikler ancak Müşteri, kayıttan önce sunulan sorumluluk kabul beyanını onayladıktan sonra (kimlik, zaman damgası ve IP adresi kaydedilerek) sisteme işlenir. Bu özel içerikler resmi 60/100 geçme notuna veya sertifikaya hiçbir şekilde dahil edilmez; yalnızca Ek-1 iskelet müfredatı puanlanır ve sertifikalandırılır. OculaWork, Müşteri'nin girdiği özel içerikten kaynaklanan hiçbir hukuki, idari veya cezai sonuçtan sorumlu tutulamaz.
Platform yazılımı, kaynak kodu, algoritmaları, tasarım ve marka OculaWork'ün münhasır fikri mülkiyetidir. Müşteri'ye; münhasır olmayan (non-exclusive), geri alınabilir (revocable), sınırlı (limited) ve dünya çapında (worldwide) geçerli, yalnızca abone olunan kullanıcı sayısı kadar, kullanım amaçlı bir lisans tanınır. Bu lisans devredilemez, başka bir firmaya kiralanamaz veya alt lisans olarak verilemez; Platform hiçbir şekilde kopyalanamaz veya tersine mühendisliğe tabi tutulamaz. Lisans, yalnızca satın alınan/abone olunan kullanıcı (kota) sayısı kadar aktif kullanıcı için geçerlidir; kota aşımı tespit edilirse Müşteri'den ek kota satın alması istenir. Lisanslanan kullanıcı sayısının sistematik şekilde aşılması hâlinde OculaWork, fazla kullanım bedelini geriye dönük olarak faturalandırabilir veya hesabı askıya alabilir. İşbu Sözleşme, OculaWork markası, ticari unvanı, algoritmaları veya olası patent başvuruları üzerinde Müşteri'ye herhangi bir hak devri oluşturmaz.
Müşteri ve çalışanlara ait ham tarama sonuçları ve raporlar Müşteri'nin mülkiyetindedir. OculaWork bu verileri yalnızca Sözleşme kapsamında işler; anonimleştirilerek toplulaştırılmış istatistikler Platform geliştirmesi amacıyla kullanılabilir.
Platform içerisinde üçüncü taraf açık kaynak yazılımlar kullanılabilir. Bu yazılımların lisans hakları ilgili lisans sahiplerine aittir. Açık kaynak bileşenlerinin kullanılması, işbu Sözleşme kapsamında OculaWork'ün fikri mülkiyet haklarını ortadan kaldırmaz.
Müşteri, OculaWork'ün önceden yazılı izni olmaksızın OculaWork marka, logo veya ticari unvanını reklam, referans veya tanıtım amacıyla kullanamaz.
OculaWork, aksi yazılı olarak kararlaştırılmadıkça Müşteri'nin ticaret unvanını yalnızca referans müşteri listesinde kullanabilir. Müşteri, dilediği zaman yazılı bildirimle bu izni geri alabilir.
OculaWork, aşağıdaki durumlarda Sözleşme'yi feshetmeden önce Müşteri'nin hesabını geçici olarak askıya alma hakkını saklı tutar: (i) Platform'un veya altyapının aktif bir siber saldırı altında olması, (ii) hesaptan kaynaklanan yetkisiz erişim/kötüye kullanım şüphesi, (iii) ödeme gecikmesi (bkz. §13.3), (iv) API kötüye kullanımı, bot trafiği, hizmet dışı bırakma (DDoS) girişimi, yetkisiz otomasyon veya olağan dışı yoğunlukta istek gönderimi (bkz. §11.1 Yasaklı Kullanımlar). (iv) numaralı hâllerde, Platform'un veya diğer Müşterilerin bütünlüğünü korumak amacıyla, hesap önceden bildirim yapılmaksızın askıya alınabilir. Askıya alma süresince Müşteri verilerine erişim geçici olarak kısıtlanır ancak veriler silinmez; durum netleştiğinde erişim yeniden açılır.
Her iki taraf 30 gün önceden yazılı bildirimde bulunarak Sözleşme'yi sona erdirebilir.
OculaWork aşağıdaki durumlarda derhal ve tazminatsız fesih hakkını saklı tutar:
Yetkili bir mahkeme kararı veya kanunen zorunlu kılan bir idari/yasal düzenleme mevcut olması hâlinde, OculaWork Platform'u kısmen veya tamamen durdurabilir/kaldırabilir. Bu durum, kaynağı OculaWork'ün kontrolünde olmayan bir hukuki zorunluluktan doğduğu ölçüde, §10.3 kapsamında sorumluluk dışı bir hâl olarak değerlendirilir.
Platform, bugün itibarıyla klasik anlamda bir HTTP çerezi (cookie) oluşturmamaktadır; aşağıdaki teknik depolama mekanizmaları tarayıcının yerel depolama alanında (localStorage) tutulur:
| Mekanizma | Amaç | Tür | Süre |
|---|---|---|---|
| ow_lang | Dil tercihi | İşlevsel | localStorage (kalıcı) |
| Firebase Auth Token | Oturum yönetimi | Zorunlu | 1 saat |
| "Beni Hatırla" jetonu ve rol bazlı e-posta hatırlatma anahtarları | Bir sonraki girişte oturumu/e-postayı hatırlama | İşlevsel | localStorage (kullanıcı çıkış yapana/reddedene kadar) |
| Cihaz-eşleştirme (biyometrik/parmak izi girişi) anahtarı | Cihazın daha önce biyometrik girişle eşleştirildiğini hatırlama | İşlevsel | localStorage (kullanıcı sıfırlayana kadar) |
| Bildirim tercihi ve cihaz push token anahtarları | Bildirim açık/kapalı tercihini ve bildirim gönderim adresini hatırlama | İşlevsel | localStorage (kalıcı, kapatılana kadar) |
| Firma kodu / son bağlanılan kiracı önbelleği | Self-host firmalarda giriş ekranını doğru firmaya yönlendirme | İşlevsel | localStorage (kalıcı) |
| Uygulama sürümü ve tarama önbelleği | Çevrimdışı/gecikmiş bağlantıda son bilinen veriyi gösterme, güncelleme kontrolü | İşlevsel | localStorage (kalıcı, güncellenene kadar) |
| Konu | İletişim |
|---|---|
| KVKK başvuruları / Veri silme | info@oculawork.com |
| Teknik destek | info@oculawork.com |
| Hukuki bildirimler | info@oculawork.com |
| Güvenlik açığı bildirimi | info@oculawork.com |
KVKK başvurularına 30 gün içinde yanıt verilir. KVKK Kurumu'na şikâyet için: kvkk.gov.tr
Bu Sözleşme kapsamında taraflarca bildirilen e-posta adresine yapılan bildirimler, gönderildiği tarihte tebliğ edilmiş sayılır. Müşteri, iletişim bilgilerini güncel tutmakla yükümlüdür. E-postanın alıcı tarafın spam/gereksiz posta klasörüne düşmesi, alıcının e-posta sağlayıcısındaki filtreleme ayarlarından kaynaklanır; bu durumdan OculaWork sorumlu tutulamaz. Taraflar, iletişim bilgilerindeki değişiklikleri en geç 7 gün içinde yazılı olarak bildirmekle yükümlüdür; bildirilmeyen değişikliklerden doğacak sonuçlardan ilgili taraf sorumludur.
Faturalar elektronik fatura (e-Fatura) veya elektronik arşiv fatura (e-Arşiv) olarak, mevzuatın izin verdiği ölçüde e-posta yoluyla gönderilir ve bu şekilde tebliğ edilmiş sayılır.
Müşteri, Platform'u Türkiye'nin veya Birleşmiş Milletler, Avrupa Birliği, ABD gibi uluslararası kuruluşların/yargı alanlarının yürürlükteki ihracat kontrolü ve yaptırım mevzuatını ihlal edecek şekilde kullanmayacağını; yaptırım listelerinde yer alan bir kişi/kuruluş adına veya yaptırım uygulanan bir ülkeden erişim sağlamayacağını beyan ve taahhüt eder.
Müşteri, işbu Sözleşme'yi OculaWork'ün önceden yazılı onayı olmaksızın devredemez. OculaWork, şirket birleşmesi, hisse devri, varlık satışı veya benzeri bir yapısal değişiklik hâlinde, işbu Sözleşme'yi ve bundan doğan hak ve yükümlülüklerini, Müşteri'ye önceden bildirimde bulunmak kaydıyla, üçüncü bir tarafa devredebilir.
İşbu Sözleşme metni ile ekleri (EK-1 Veri İşleme Sözleşmesi, Gizlilik Politikası, KVKK Aydınlatma Metinleri, Açık Rıza Metni) arasında bir çelişki bulunması hâlinde, aşağıdaki öncelik sırası uygulanır: (i) EK-1 Veri İşleme Sözleşmesi (yalnızca veri işleme hükümleri bakımından), (ii) işbu Sözleşme'nin ana metni, (iii) diğer ekler ve ayrı belgeler. Bildirimler, aksi belirtilmedikçe Türkçe yapılır; TR/EN metinler arasında çelişki hâlinde Türkçe metin esas alınır.
Taraflar, işbu Sözleşme kapsamında öğrendikleri veya erişim sağladıkları birbirlerine ait ticari sırları, fiyatlandırma bilgilerini, algoritma ve yazılım mimarisi detaylarını, müşteri/çalışan listelerini ve açıkça gizli olarak işaretlenmiş diğer bilgileri üçüncü kişilerle paylaşmamayı ve yalnızca işbu Sözleşme'nin ifası amacıyla kullanmayı kabul eder. Bu yükümlülük, kamuya mal olmuş bilgileri, yasal zorunluluk nedeniyle açıklanması gereken bilgileri veya bağımsız olarak geliştirilmiş bilgileri kapsamaz; Sözleşme sona erse dahi makul bir süre boyunca yürürlükte kalır.
Taraflardan birinin işbu Sözleşme'den doğan bir hakkını belirli bir durumda kullanmaması veya kullanmakta gecikmesi, o haktan veya ileride aynı ya da benzer bir durumda bu hakkı kullanmaktan feragat ettiği anlamına gelmez.
İşbu Sözleşme ve ekleri (EK-1 Veri İşleme Sözleşmesi ile bkz. §16.3'te belirtilen diğer belgeler), taraflar arasındaki konuya ilişkin bütün anlaşmayı oluşturur ve bu konudaki önceki yazılı veya sözlü tüm görüşme, teklif ve anlaşmaların yerine geçer. İşbu Sözleşme'de değişiklik, ancak OculaWork tarafından yazılı olarak (bkz. §16 güncelleme bildirimi) yapılabilir.
İşbu Sözleşme herhangi bir nedenle sona erse dahi, niteliği gereği sona ermeden sonra da uygulanması gereken hükümler yürürlükte kalmaya devam eder; bunlar arasında özellikle Gizli Bilgi (§16.6), Fikri Mülkiyet (§11), Tazmin Yükümlülüğü (§16.5), Kişisel Verilerin Korunması'na ilişkin hükümler (§7) ve Delil Sözleşmesi (§16.4) yer alır.
Bu ek yalnızca, Platform'u kendi altyapısında ve kendi veritabanında çalıştıran Müşteriler için geçerlidir. Self-host Firebase kurulumunda bu ek uygulanmaz; çelişki hâlinde bu ekteki hükümler ana metnin önüne geçer.
Kurumsal kurulumda çalışan tarama kayıtları ve bunlardan türetilen sağlık göstergeleri münhasıran Müşteri'nin kendi sunucusunda ve kendi veritabanında tutulur. Bu verilerin barındırılması, yedeklenmesi, erişilebilirliği ve bunlara ilişkin tüm maliyet Müşteri'ye aittir.
Ham kamera görüntüsü, video karesi veya yüz işaret noktası verisi hiçbir koşulda çalışanın cihazından çıkmaz; ne OculaWork'e ne de Müşteri'nin sunucusuna iletilir ve hiçbir yerde saklanmaz. Cihaz dışına çıkan tek veri sayısal ölçüm sonuçlarıdır.
Aşağıdakiler, hizmetin ifası için zorunlu olduğundan kurumsal kurulumda dahi OculaWork altyapısında bulunur ve Müşteri bunu kabul eder:
Bu bileşenler lisanslanan yazılıma dâhil değildir; hizmet olarak sunulur ve Müşteri'ye teslim edilmez.
EK-0.3.1 — Kurumsal lisans süreli bir kullanım hakkıdır; mülkiyet devri veya süresiz kullanım hakkı doğurmaz. Müşteri'nin Yazılım'ı kullanma hakkı, Sözleşme'de belirtilen lisans süresi ile sınırlıdır ve lisans süresinin sona ermesiyle kendiliğinden sona erer. Lisans süresinin sona ermesi üzerine erişimin teknik olarak sınırlandırılması veya durdurulması; ayıp, temerrüt veya sözleşmeye aykırılık olarak değerlendirilemez.
EK-0.3.2 — Lisans süresi devam ettiği sürece OculaWork, lisansın geçerliliğini teknik olarak doğrulamak amacıyla lisans doğrulama hizmetini kullanabilir.
EK-0.3.3 — Doğrulama sunucusuna erişilememesi lisansın sona ermesi değildir. Lisans doğrulama hizmetine geçici olarak erişilememesi, lisansın sona erdiği veya geçersiz hâle geldiği anlamına gelmez. Bu durumda Yazılım, geçerli lisansın doğrulanmış son durumunu esas alarak çevrimdışı çalışmaya devam eder; uzun süreli doğrulama probleminde Müşteri yöneticisine uyarı gösterilir.
EK-0.3.4 — OculaWork altyapısından kaynaklanan teknik kesinti, planlı bakım, altyapı arızası veya lisans doğrulama hizmetine erişilememesi nedeniyle, lisans süresi devam eden Müşteri'nin Yazılım'a erişimi durdurulamaz ve lisans süresi Müşteri'nin kusuru olmaksızın kısaltılmış sayılmaz.
EK-0.3.5 — Müşteri'nin lisans bedelini vadesinde ödememesi hâlinde OculaWork, yazılı bildirimde bulunarak borcun ödenmesi için en az 15 günlük ek süre tanır. Bu sürenin sonunda ödeme yapılmamış ve temerrüt hâli devam ediyorsa OculaWork, Yazılım kullanımını geçici olarak askıya alabilir. Askıya alma, Sözleşme'nin feshi anlamına gelmez ve Müşteri'nin diğer hak ve yükümlülüklerini ortadan kaldırmaz.
EK-0.3.6 — Askıya alma işleminden önce OculaWork, Müşteri'ye askıya alma tarihi ve ödeme tutarı hakkında yazılı bildirim gönderir. Ödeme uyuşmazlığının makul şekilde incelenmesinin gerekli olduğu durumlarda, uyuşmazlık sonuçlandırılıncaya kadar erişimin askıya alınması uygulanmaz. Geçerli bir lisans döneminde, yalnızca ödeme uyuşmazlığı bulunduğu gerekçesiyle ve bu bildirim/süreler işletilmeksizin hizmet teknik olarak devre dışı bırakılmaz.
EK-0.3.7 — Veri erişimi. Erişimin askıya alınması veya lisansın sona ermesi hâlinde dahi Müşteri, EK-0.8'de düzenlenen süre ve koşullarla kendi verilerini dışa aktarma hakkını korur.
Kurumsal kurulumda müşteri çalışanlarına ilişkin kişisel veriler, müşterinin kendi bilgi işlem altyapısından çıkarılmaksızın işlenir. OculaWork, müşteri tarafından yetkilendirilen yazılım bileşenleri aracılığıyla analiz faaliyetini müşterinin altyapısı içerisinde gerçekleştirir.
Kurumsal kurulumda müşterinin sunucusundan OculaWork merkezine gönderilebilecek alanlar teknik olarak sınırlandırılmıştır. Bu bir taahhüt değil, sistemin izin verdiği azami kapsamdır: beyaz liste dışındaki her alan sunucu tarafında reddedilir.
| Kanal | Gönderilebilecek alanlar | Reddedilen |
|---|---|---|
| Model geliştirme katkısı (varsayılan kapalı) | modelSurumu, ornekSayisi, gradyan, gurultuOlcegi | Şema dışı her alan — çalışan kimliği, departman, e-posta, ham ölçüm, serbest metin, tarih |
| Bildirim gönderimi (yalnızca "mail bizde" modunda) | Alıcı adresi, şablon kimliği, müşterinin kendi adresine bağlantı | Serbest metin, konu, HTML gövde, ek dosya |
| Lisans doğrulama | Lisans kimliği, sürüm, sistem sağlık durumu | Çalışan verisi |
| Günlük kurulum sinyali (sağlık ve kurcalama tespiti) | Kurulum kimliği, model sürümü, karar çekirdeği özeti, son eğitimden bu yana geçen kabaca süre, toplulaştırılmış ölçüm sayacı, reddedilen istek sayaçları | Kimlik, departman, serbest metin, kesin tarih damgası, şema dışı her alan |
| Merkezî psikososyal danışma (varsayılan kapalı) | Sektör kodu, çalışan sayısı bandı, ≥50 ölçümden türetilmiş dağılımlar (eşik altı hücreler bastırılmış), gürültü ölçeği | Bireysel kayıt, kimlik, departman adı, serbest metin, tarih, tam çalışan sayısı |
Model geliştirme katkısı ayrıca şu koşullara tabidir: en az 50 ölçümden türetilmiş olması, gizlilik artırıcı gürültünün uygulanmış olması ve katkı büyüklüğünün sınırlandırılmış olması. Bu tekniklerin uygulanmış olması, ilgili verinin hukuken anonim olduğu anlamına gelmez; anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır.
Kaynak kodun Müşteri'ye teslimi, ancak taraflar arasında ayrıca imzalanmış bir kaynak kod emaneti (escrow) sözleşmesinde tanımlanan tetikleyici olayların gerçekleşmesi hâlinde mümkündür. Escrow'un amacı Müşteri'nin kaynak koda dilediği an erişmesi değil, olağanüstü hâllerde operasyonel devamlılığının korunmasıdır.
Tetikleyici olaylar sınırlı sayıda ve açıkça tanımlıdır: OculaWork'ün faaliyetini kalıcı olarak durdurması, iflas/konkordato kapsamında sözleşmede belirlenen şartların oluşması, veya destek ve bakım hizmetinin kalıcı olarak sona ermesi. Geçici bir hizmet kesintisi tetikleyici olay değildir.
Müşteri sunucusundaki bileşen, yalnızca OculaWork tarafından geçerli özel anahtarla imzalanmış ve bütünlüğü doğrulanmış model paketlerini kabul eder. İmzasız ya da imzası doğrulanamayan paket çalıştırılmaz.
İmzalama özel anahtarı Müşteri ortamına hiçbir koşulda gönderilmez; Müşteri tarafında yalnızca doğrulama (açık) anahtarı bulunur. Bu ayrım, Müşteri'nin kendi ürettiği bir modeli sisteme sokmasını ve merkezî altyapının ele geçirilmesi hâlinde sahte model dağıtılmasını engeller.
OculaWork'ün Müşteri altyapısına uzaktan idari erişimi varsayılan olarak kapalıdır. Destek gerektiren hâllerde erişim, Müşteri tarafından geçici olarak ve amaçla sınırlı biçimde yetkilendirilir.
Yetkilendirilmiş her erişim; kim, ne zaman, hangi amaçla ve hangi kaynağa eriştiği bilgisiyle kayıt altına alınır. OculaWork destek personelinin çalışan içeriğine varsayılan erişimi yoktur.
Yurt dışına aktarım için standart sözleşme kullanılması hâlinde, sözleşmenin imzalanmasından itibaren 5 iş günü içinde Kurum'a bildirilmesi gerekir. Bildirim yükümlülüğünün hangi tarafça yerine getirileceği, aktarım senaryosuna ve tarafların sıfatına göre ilgili Sipariş Formu veya aktarım sözleşmesinde açıkça belirlenir.
Standart sözleşme metni, mevzuat gereği üzerinde değişiklik yapılmaksızın kullanılır; taraflara özgü ticari şartlar ayrı bir sözleşmede düzenlenir.
Müşteri; lisans denetimini devre dışı bırakamaz, değiştiremez veya baypas edemez. Yazılımı OculaWork lisans servisine bağlanmadan çalıştırmaya yönelik her girişim esaslı ihlal sayılır ve Sözleşme'nin haklı nedenle derhal feshi sonucunu doğurur.
Yazılımın istemci tarafı bileşenlerinin teknik olarak okunabilir olması, Müşteri'ye herhangi bir çoğaltma, türev çalışma üretme, devir veya alt lisans hakkı vermez.
OculaWork, makul bir bildirim süresiyle ve Müşteri'nin iş akışını aksatmayacak şekilde, kurulum sayısı ve lisans uyumu denetimi yapma hakkını saklı tutar. Yazılımın ürettiği imzalı lisans ve erişim kayıtlarının delil niteliği taşıdığı taraflarca kabul edilir. Denetimde uyumsuzluk tespit edilmesi hâlinde denetim masrafları Müşteri'ye aittir.
Raporlama eşikleri (departman bazında en az 5, şirket geneli en az 10 çalışan) sözleşmesel bir taahhüttür. Müşteri bu eşiklerin düşürülmesini veya toplulaştırma/baskılama korumasının baypas edilmesini talep edemez. Çalışanın sağlık verisine yönetici erişemez; bu veri yalnızca çalışanın kendisi ve yetkilendirilmiş iş yeri hekimi tarafından görülebilir.
Sunucunun kurulumu, güncellenmesi, yedeklenmesi ve işletilmesi Müşteri'nin sorumluluğundadır; bu yükümlülükler OculaWork tarafından sağlanan İşletme Kılavuzu'nda tanımlanmıştır ve işbu Sözleşme'nin eki sayılır. OculaWork'ün hizmet seviyesi taahhüdü yalnızca kendi sunduğu servislerle (lisans, analiz, e-posta) sınırlıdır; Müşteri altyapısındaki kesinti, veri kaybı veya performans sorunları kapsam dışıdır.
Fesih hâlinde Müşteri'nin verisi, halihazırda kendi sunucusunda bulunduğundan Müşteri'de kalır; OculaWork'ün ayrıca bir iade yükümlülüğü doğmaz. OculaWork tarafında bulunan kimliksizleştirilmiş model eğitim verisi; kimlik bilgisi ve doğrudan tanımlayıcı içermediği, gizlilik artırıcı tekniklerden geçirildiği ve belirli bir müşteriye geri bağlanabilir nitelikte olmadığı için silme kapsamı dışındadır. Bu, söz konusu verinin hukuken anonim olduğu anlamına gelmez (bkz. §7.4 ve EK-0.3C); anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır. Müşteri bu işlemeye §7.4 çerçevesinde muvafakat eder.
Bu ek, işbu Hizmet Sözleşmesi'nin ayrılmaz bir parçasıdır ve Müşteri ile OculaWork arasındaki veri işleme ilişkisini KVKK Md. 3/1-ğ kapsamında düzenler. Sözleşme metni içindeki ilgili hükümlerin konsolide bir özetidir; çelişki hâlinde ana metindeki ilgili bölüm esas alınır.
| Unsur | Açıklama |
|---|---|
| Veri Sorumlusu | Müşteri |
| Veri İşleyen | OculaWork (bkz. §1 Tanımlar) |
| İşlemenin Konusu ve Süresi | İşbu Sözleşme'nin süresi boyunca, İSG risk analizi ve ilgili amaçlarla (bkz. §7.1 tablosu) |
| İlgili Kişi Kategorileri | Müşteri'nin çalışanları |
| Kişisel Veri Kategorileri | Kimlik, iletişim, sağlık/biyometrik, davranışsal, organizasyon, işlem verisi (bkz. §7.1 tablosu) |
| İşleme Talimatları (Processing Instructions) | OculaWork, kişisel verileri yalnızca Müşteri'nin talimatları ve işbu Sözleşme'de belirtilen amaçlarla işler; farklı bir amaçla işlemez (bkz. §7.0, §7.4) |
| Veri İşleyenin Yükümlülükleri | bkz. §7.0 |
| Alt İşleyen | Google Firebase / Google Cloud (bkz. §4.2); değişiklik hâlinde Müşteri'ye önceden bildirilir |
| Güvenlik Tedbirleri | bkz. §9 (Veri Güvenliği) |
| Yurt Dışına Aktarım (International Transfers) | Veriler Avrupa bölgesinde (eur3) tutulur; olası aktarım KVKK Md. 9 rejimine tabidir (bkz. §4.2) |
| İhlal Bildirimi | Gecikmeksizin ve her hâlükârda 24 saat içinde (bkz. §9.3) |
| İmha Prosedürü (Deletion Procedure) | Sözleşme sonunda Müşteri talebi doğrultusunda veriler iade edilir; 90 gün sonunda kalıcı olarak imha edilir ve Müşteri'ye yazılı teyit edilir (bkz. §4.3, §13.4) |
This Terms of Service, Privacy Policy and Data Protection Agreement (collectively "Agreement") is entered into between the following parties:
OculaWork — employee eye health and fatigue analysis platform operating at oculawork.com ("OculaWork", "Platform", "We").
| Legal Trade Name | Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. |
| Tax Office / No. | Maltepe Tax Office — 2100357903 |
| Registered Address | Söğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara, Türkiye |
| info@oculawork.com |
Any individual or legal entity, company, institution or organization subscribing to OculaWork and using the Platform for their employees ("Customer", "Employer", "You").
Persons employed by the Customer, registered in the system by the Customer, and performing measurements via the Platform ("Employee", "End User").
| Term | Definition |
|---|---|
| Platform | The software, interfaces and all services provided at oculawork.com and related subdomains |
| KVKK | Turkish Personal Data Protection Law No. 6698 and related regulations (equivalent to GDPR) |
| OSH Law | Occupational Health and Safety Law No. 6331 |
| Data Controller | KVKK Art. 3 — Entity determining the purposes and means of processing personal data. The Customer, in respect of the processing of employee data through the Platform (see §7.5) |
| Data Processor | KVKK Art. 3 — Entity processing data on behalf of, and under authority granted by, the controller. OculaWork, in respect of employee-data processing carried out on the Customer's behalf (see §7.5) |
| Infrastructure Provider | Google Firebase / Google Cloud — the platform where data is physically hosted; a legal entity independent of OculaWork |
| Sensitive Data | KVKK Art. 6 — Special categories including health and biometric data |
| EAR / PERCLOS | Eye Aspect Ratio / Percentage of Eye Closure — camera-based physiological and behavioural indicators measured by the Platform. Whether such data constitutes biometric data is assessed on the facts, not merely because it is numerical, but according to whether it is used to uniquely identify or verify a specific individual (see §7.1) |
| Explicit Consent | KVKK Art. 3 — Freely given, specific and informed consent that can be withdrawn |
| SaaS | Software-as-a-Service — subscription-based cloud software |
OculaWork is a SaaS platform that produces measurable behavioural and ergonomic indicators from eye and facial movements via a standard webcam — using methods found in the scientific literature — in order to support the assessment of working conditions, ergonomic exposure and operational risk in the workplace, and provides risk-based reports to employers and occupational physicians. The Platform does not perform medical diagnosis, disease screening or medical-condition monitoring, does not propose treatment, and does not make medical decisions.
OculaWork operates with a high-availability target but cannot be held liable for planned maintenance, force majeure, or infrastructure provider outages. Planned downtime is announced 48 hours in advance. This is a general target, not a numeric percentage commitment; it does not constitute a service level agreement (SLA) or a service-credit program. When assessing availability: the total time in the relevant month is used as the base; scheduled maintenance windows (below) and outages attributable to Google Firebase/Google Cloud infrastructure are excluded from this assessment (see §10.3).
The subscription fee in effect will not change during the current pricing period (see §12); any price change may only take effect from the next renewal period onward.
Planned maintenance is scheduled, where possible, during weekends or nighttime hours, and is limited to a maximum of 4 hours per occurrence. Where an urgent situation threatens the security or integrity of the Platform (e.g., an active attack), emergency maintenance may be performed without prior notice.
| Scope | Detail |
|---|---|
| Support hours | Daily 08:00–20:00 (Turkey time) |
| Critical incident (system fully inaccessible) | Initial response within 24 hours, during support hours |
| Standard support request | Initial response within 2 business days |
| New feature requests | Considered for roadmap; no delivery date is guaranteed |
The response times above indicate only that a support request has been received and is being processed; they do not constitute a resolution-time commitment.
Features on the Platform marked "beta," "preview," or "experimental" (including newly developed AI modules) are provided on a preview basis; they may be interrupted, changed unexpectedly, or removed. No outcome is guaranteed for these features, and the Agreement's general service-continuity/SLA commitments do not cover them. Beta features may result in data loss or erroneous data output; the Customer should not rely on beta features for critical or single-source data.
OculaWork may in the future offer integrations with third-party systems (identity/directory services, enterprise communication tools, ERP/HR software, etc.). Such integrations, when released, will be subject to additional terms announced at that time; this Agreement does not commit to any integration that does not currently exist. Likewise, should a general-purpose API be released in the future, usage limits (rate limits), API key management, and abuse policies will be governed by a separate API Terms of Use document.
The Platform offers a feature enabling a direct video call with an employee, which only the occupational physician may initiate (one-directional). The connection is established directly between two devices (WebRTC, using Google's free public STUN server) without passing through any third-party server; audio/video is never recorded or stored on any server. The technical connection data (SDP/ICE) required to establish the call is automatically deleted a few seconds after the call ends. During the call, an approximate camera-based pulse estimate and an instantaneous blink/PERCLOS-based fatigue-stress indicator are computed from the employee's camera feed — shown only to the physician on that call, only for the call's duration. These indicators are not a medical measurement or diagnosis, do not replace a clinical device, and are never added to or stored in the employee's permanent scan history. As no TURN server is used, the connection may occasionally fail to establish under very strict corporate network/firewall configurations.
| Stage | Where Processed / Stored | OculaWork Access |
|---|---|---|
| Raw camera footage (video) | User's browser only (RAM) — never transmitted anywhere | ❌ No access |
| Computed numerical metrics (EAR, PERCLOS, etc.) | Google Firebase Firestore (Google Cloud infrastructure) | Limited admin access for software management |
| User account information | Google Firebase Authentication | Limited admin access for software management |
| Application files (HTML, JS) | Google Firebase Hosting (CDN) | Full access — software owner |
| OwO consult profile (anonymous numeric metrics — see §7.4) | Google Cloud Functions (Europe) → only a 0-1 sector-context score (owoContextScore) is appended to the scan record | Identity information is never sent or processed |
| OwO training sample (anonymous feature vector + label — see §7.4) | Google Firebase Firestore (Europe) — only a numeric vector, a timestamp, and a 0/1 label; never contains identity or company information | Accessible to no one (including admin); read only by the training process, automatically deleted after 180 days |
| Drug name recognized by the physician's screen (sedation-class lookup only) | Google Cloud Functions (Europe) — the query is instantaneous; neither the query nor its result is stored anywhere | Derived only from anamnesis data the physician already has access to |
| OwO feedback (👍/👎, see §7.4) | Google Firebase Firestore (Europe) — only the information type + whether it was helpful | Accessible to no one (including admin); only the aggregate ratio is computed server-side |
| Physician's clinical accuracy verdict on a scan ("accurate/under/over/referred", see §7.4) | Google Firebase Firestore (Europe) — stored tied to that scan record; fed into OwO training as an anonymous, corrected label | Accessible only to that tenant's physicians/management |
| Bug report and automatically captured technical diagnostics (browser error, device/browser info — see §9.4) | Google Firebase Firestore (Europe) | Accessible only to OculaWork's own admin; the reporting user's own employer cannot see it |
Google Firebase is an independent cloud infrastructure and data hosting service owned by Google LLC. Firebase's data processing terms and security measures are governed by Google's Privacy Policy and Firebase Data Processing Terms.
All Customer data (scan results, reports, account information) remains the property of the Customer; OculaWork asserts no rights over such data beyond those granted under this Agreement. Personal data is not a subject of ownership in the classical sense; this provision governs the rights of use and disposition over data supplied by, and processed on behalf of, the Customer, and does not affect data subjects’ rights under KVKK. Upon request, data export is provided; export is made only in formats OculaWork supports at that time (e.g., JSON/CSV), and no other format is guaranteed. Data integrity is maintained on OculaWork's side during export; however, no guarantee is made regarding compatibility with, or the integrity of the data after import into, third-party systems (e.g., the Customer's own ERP/HR software). Upon contract termination, data is permanently deleted within 90 days. This 90-day period concerns the deletion of operational data that remains accessible after termination; the retention periods set out in §7.2 and any retention obligations arising from legislation are reserved. Even if the account is closed/data is deleted, certain records (e.g., invoicing data) may be separately retained for the legally required retention period due to accounting regulations (e.g., Turkish Tax Procedure Law), transaction logs, and KVKK-related legal retention obligations.
The Customer exclusively holds the status of Data Controller under KVKK Law No. 6698 with respect to the processing of its employees' personal data. The Customer is independently responsible for:
OculaWork is a software provider and processes Customer data solely within the scope of this Agreement and the Customer's instructions. Data is not used for OculaWork's own benefit, third-party marketing, or any other purpose.
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Google Firebase Firestore | Data storage | Europe (eur3) |
| Google Firebase Authentication | Identity verification | Europe |
| Google Firebase Hosting | Application hosting | Global CDN |
| Google Cloud Functions | Backend processing | Europe |
| Resend | Sending credential/notification emails and forwarding mail received at info@oculawork.com | United States. The provider states in its own documentation that its primary processing operations are carried out in the USA and that personal data may be transferred outside the EEA/UK/Switzerland. The email channel is therefore treated as part of the KVKK Art. 9 transfer chain (see §4.2). Data minimisation: no individual measurement result, fatigue/risk score, or health-related personal assessment is sent through this channel; management reports contain only aggregated data that has passed the thresholds in §11 |
OculaWork may engage sub-processors providing infrastructure, hosting, email, security, analytics or support services in order to deliver the Service. The current sub-processor list, processing purposes and data locations are set out above and are available to the Customer.
Changes requiring a new sub-processor to access personal data are notified to the Customer at least 30 days before they take effect. The Customer may object on justified and reasonable data-protection grounds; in that case the parties will discuss a reasonable solution in good faith.
OculaWork shares Customer data with third parties only:
The parties agree to provide each other with reasonable assistance in official inquiries, audits, or judicial proceedings related to personal data or information security.
In respect of employee-data processing carried out within the purposes and means determined by the Customer, the Customer is the Data Controller and OculaWork holds the status of Data Processor under KVKK Art. 3. For activities OculaWork carries out for its own purposes (account management, billing, security logs), its status is determined separately as set out in §7.5. In activities where it acts as processor, OculaWork:
| Category | Example Data | Purpose | Legal Basis |
|---|---|---|---|
| Identity | Name, surname | Account management | KVKK Art. 5/2-c — Contract performance |
| Contact | Email address | Notifications | KVKK Art. 5/2-c — Contract performance |
| Health / physiological indicator | EAR, PERCLOS, fatigue score | OSH risk analysis | KVKK Art. 6/3 — whichever condition applies on the facts (see §8.1); OSH Law Art. 15 is not a legal basis on its own |
| Behavioral | Reaction time, blink rate | OSH risk analysis | KVKK Art. 5/2-f — legitimate interest (subject to a balancing test carried out by the Customer); where the balancing test is not satisfied, explicit consent under Art. 5/1 |
| Organizational | Department, shift | Reporting | KVKK Art. 5/2-c — Contract performance |
| Transaction | Scan date/time | Audit trail | KVKK Art. 5/2-f — Legitimate interest |
| Physician clinical note | Integrity-protected clinical note the occupational physician writes about an employee (see §7.2, §9.4) | Health-surveillance record integrity | KVKK Art. 6/3 — whichever condition applies on the facts (see §8.1) |
| Survey response | The employee's answer to a single-question survey published by management | OSH risk analysis (OwO input, see §7.4), reporting | KVKK Art. 5/2-f — legitimate interest (subject to a balancing test carried out by the Customer); where the balancing test is not satisfied, explicit consent under Art. 5/1 |
| Technical bug report | Free text written by the user + automatically captured browser error/device info (see §9.4) | Diagnosing and fixing software issues | KVKK Art. 5/2-f — Legitimate interest |
| Notification/reminder | Device push token for instant notifications; the reminder note and time the physician sets for a specific employee | Health-surveillance follow-up, system notifications | KVKK Art. 5/2-c — Contract performance / Art. 6/3 |
| Data Type | Retention Period |
|---|---|
| Measurement metrics and reports | Active subscription + 2 years under our internal retention policy; statutory retention periods arising from applicable legislation and our retention-and-destruction policy are reserved |
| Account and identity data | 90 days after contract termination |
| Transaction logs | 6 months |
| OwO training samples (numerical feature vector + label containing no identity information or direct identifiers; anonymity is assessed separately — see §7.4) | 180 days — automatically deleted on every training run |
Facial biometric template (faceEmbedding — for face verification) | For the duration of the active subscription; deleted immediately and automatically when the employee requests data deletion or the account is closed |
On-device learning model weights (federated_weights — see §7.4) | For the duration of the active subscription; deleted when the employee requests data deletion or the account is closed. These weights may have previously been averaged (federated) together with other employees' models at the same company — deleting the individual document does not guarantee the mathematical trace of its contribution is fully removed from earlier aggregate averages |
| Physician clinical notes | Health-surveillance records created by the occupational physician are retained in line with the retention periods prescribed by applicable OSH legislation and KVKK's retention principles. The Directorate General of OSH (Ministry of Labour and Social Security) states that personal health files must be kept for at least 15 years from the employee's date of leaving employment. Records are held so that their integrity is preserved; retroactive alteration after writing is prevented (see §9.4). Deletion requests are assessed subject to any applicable statutory retention obligations |
| Alert/warning records, clinical verdict feedback, exam scheduling records, failed face-verification security log | NOT automatically deleted by an employee's own "Delete My Data" request — retained deliberately, for the same reason as physician clinical notes (OHS/security audit-trail integrity). Deletion, if required, can be requested through admin at info@oculawork.com. |
| Bug reports and technical diagnostics | Until manually deleted by OculaWork's admin |
| After deletion request | Destroyed within 30 days of request date (physician clinical notes excepted — see above) |
Employees exercise their KVKK rights through their employer (Customer). OculaWork fulfills these requests upon Customer direction within 30 days:
For the objection right above to be exercised meaningfully, the Platform's automated/semi-automated processing points that may produce a result concerning an employee are identified explicitly: (i) the fatigue risk level produced by the daily scan (low/medium/high/critical), (ii) statistical anomaly-detection alerts based on CUSUM and Isolation Forest, and (iii) the sector-context score (owoContextScore, see §7.4) that the "OwO" sector-wide learning model produces, based on that scan's anonymous numeric profile, shown solely for informational purposes — all three are shown only to the occupational physician and none of them alone translates into an automated personnel decision. OwO's training data and model weights contain no identity information; they are identity-stripped data that has been subjected to technical and administrative measures aimed at anonymisation. The application of those measures does not, on its own, mean the data is legally anonymous; anonymity is assessed separately in light of the concrete circumstances (see §7.4). however, the sector-context score the consult layer produces for informational purposes is a scan-specific, informational indicator and constitutes processing point (iii) above. If an employee believes a risk level, an anomaly alert, or the sector-context score has been used as the sole basis for an adverse personnel decision concerning them (reassignment, discipline, etc.), they may object to their employer; the employer is responsible for ensuring such an objection is reviewed by a human (occupational physician/HR) before being acted upon.
Under KVKK Art. 3/1-d, personal data means any information relating to an identified or identifiable natural person. Data that has been irreversibly anonymized falls outside this definition, and KVKK provisions do not apply to it. OculaWork trains a sector-wide statistical learning model ("OwO") using scan and self-assessment data from Customers, regardless of whether they use shared or self-hosted infrastructure (see item 5 below); that training draws on numerical features that have been technically separated and minimised so as to contain no direct identity or company identifiers.
This processing is limited by the following technical and legal safeguards:
modelSurumu, ornekSayisi, gradyan, gurultuOlcegi) and is not generated unless derived from at least 50 measurements, with privacy-enhancing noise applied and its magnitude capped. Every field outside the allowlist is rejected server-side. Identity data likewise remains within the Customer's own infrastructure. The application of these techniques does not mean the data reaching the centre is legally anonymous; anonymity is assessed separately in light of the concrete circumstances.
Transparency: The full technical detail of this processing — including which data source is reduced to which signal — is documented in the OculaWork Technical Methodology Document (in the section titled "OwO Training Model") and is available to the Customer and data subjects upon request.
KVKK legislation and Board precedent may change over time. In the event of a regulatory change, the parties will cooperate in good faith, within a reasonable time, to bring this Agreement and related practices into compliance with the updated legislation.
In respect of the measurement activities carried out through the Platform in relation to employees, to the extent that the Customer determines the purposes and the essential means of processing, the Customer acts as data controller and OculaWork as data processor acting on the Customer's behalf.
In respect of separate processing activities that OculaWork carries out for its own purposes (such as its own customer account and subscription records, billing, support, its own marketing communications, and its own security logs), the status of data controller or data processor is determined separately for the activity concerned.
The status of the parties is assessed not merely by the label used in the contract, but by the actual nature of the specific processing activity and by who determines the purposes and means.
Status varies according to who determines the purposes and means of the activity. The table below is not a binding summary but an interpretive guide; the factual position governs in a specific case.
| Activity | Purpose | Role |
|---|---|---|
| Employee measurement and reporting | Supporting OSH processes | Customer controller · OculaWork processor |
| Customer account and subscription management | Provision of the service | OculaWork controller |
| Billing and accounting | Legal obligation | OculaWork controller |
| Support request handling | Provision of the service | Determined separately by the content of the request |
| Security and audit logs | System security | OculaWork controller |
| Model development contribution | Sector model | Separate legal assessment (see §7.4, APP-0.3C) |
Depending on the nature of the processing, EAR, PERCLOS and fatigue scores may fall to be assessed as sensitive personal data under KVKK Article 6, in which case they require additional protection.
The processing of sensitive personal data relies on whichever of the conditions set out in KVKK Art. 6/3 is applicable to the specific case. Explicit consent is only one of those conditions; the structural power imbalance in the employment relationship and the necessity and proportionality of the processing are assessed separately.
The Platform's optional facial biometric (face-embedding) feature used for login/identity verification is a distinct risk category from fatigue-scan metrics (EAR/PERCLOS etc.): it is a biometric identity capture mandated by the employer directly. In its Decision No. 2022/797 of 04.08.2022, the KVKK Board found facial-recognition-based entry/exit tracking unlawful for lacking any valid processing condition under Art. 6; more significantly, in its Principle Decision No. 2026/921 of 29.04.2026, the Board held that biometric data processing for attendance-tracking purposes is unlawful even where the employee's explicit consent has been obtained — reasoning that the structural power imbalance in the employment relationship undermines whether such consent is truly "freely given." That principle decision concerns biometric identification for attendance-tracking purposes and does not apply directly to the Platform's fatigue measurement; it nonetheless reflects the Board's current approach that employee consent is not automatically a safe harbour in every case. Accordingly, relying on explicit consent alone may not by itself render biometric processing lawful. Before enabling this feature, the Customer should assess (i) proportionality, necessity, and data minimization, (ii) whether a less intrusive alternative (e.g., encrypted card/PIN, RFID/NFC ID card, or device binding) would suffice, and (iii) consult its own legal counsel. OculaWork does not perform this assessment on the Customer's behalf and assumes no legal risk in this regard.
Where OculaWork becomes aware of an event that may affect the security of personal data, it will notify the Customer in writing without undue delay and in any event within 24 hours. This contractual notification period does not alter the parties' statutory notification deadlines under KVKK and other applicable legislation (including the controller's obligation to notify the Board under KVKK Art. 12/5). The Customer is likewise obligated to notify OculaWork without delay upon becoming aware of a security incident on its own side (its own accounts, network, or systems) that could affect Platform data.
| Role | Data Accessible | Data Not Accessible |
|---|---|---|
| Employee | Only their own scan results, their own AI Life Coach content, their own periodic self-screening record, their own survey answer | Any other employee's data; clinical notes the physician has written about them; their own submitted bug reports and technical diagnostics (visible only at the moment of submission, thereafter accessible only to OculaWork's own admin) |
| Management / HR | Department-level anonymous/aggregated statistics (min. 5-person groups), personnel/exam management, individual survey answers, the Character–Role Fit Index (an aggregate statistic — a single percentage and confidence value — shown only once at least 10 employees have completed the Character Analysis; see §7.4) | Individual scan detail, AI Life Coach content (GAD-7/PHQ-9/CBI, including any individual Character Analysis result), periodic self-screening anamnesis, bug reports/technical diagnostics |
| Occupational Physician | Individual health-surveillance/scan data within their own tenant, TİTCK drug matching, periodic self-screening anamnesis, official exam records, their own permanent clinical notes (see §7.1, §7.3 — indefinite retention, cannot be edited or deleted), their own clinical-accuracy feedback on scans | Employee's AI Life Coach content (GAD-7/PHQ-9/CBI, Calm Down, Character) — closed to the physician as well; bug reports/technical diagnostics |
| OculaWork Admin | Tenant/subscription management, anonymous Data Pool statistics, Module Usage Dashboard (counts only), OwO training history (weights/scores only), bug reports and automatically captured technical diagnostics from all users (see §7.1) — never shared with the reporting user's own employer (management/physician) | Any employee's individual data, AI Life Coach content, anamnesis free text, the content of physicians' clinical notes — see §7.4 |
To fulfill its Data Controller obligations under KVKK, the Customer may request information and documentation regarding OculaWork's data processing practices. OculaWork will provide such information at a reasonable frequency and upon at least 15 days' prior written notice, without disclosing its own trade secrets or information belonging to other Customers. On-site audits or independent third-party audits are possible only under scope, duration, and confidentiality terms agreed in writing in advance by both parties; unless otherwise agreed, audit costs are borne by the requesting Customer.
Anyone who identifies a security vulnerability on the Platform may report it only to info@oculawork.com, under the principles of Responsible Disclosure. Active penetration testing, load testing, fuzzing, or similar activity carried out without OculaWork's prior written consent is not covered by this provision and remains subject to the Prohibited Uses clause in §11.1.
Should OculaWork incur liability for any reason, its total liability is limited to the subscription fees paid in the 12 months preceding the breach. This limitation does not apply in cases of willful misconduct, gross negligence, intellectual property infringement, or breach of confidentiality/data-security obligations.
Neither party shall be liable for failure to perform its obligations under this Agreement for the duration of, and to the extent directly caused by, a force majeure event.
If any employee files a claim against the employer (Customer) related to Platform data, OculaWork is not a party to that dispute. The Customer agrees to indemnify OculaWork and cover any resulting costs.
The user is personally responsible for all actions taken from their own account. If a password is shared with a third party, all resulting consequences (including data access, unauthorized transactions, or data breaches) are the responsibility of the sharing user and/or the Customer; OculaWork cannot be held liable for this. User accounts are personal to the individual user; shared use of an account by multiple people constitutes a license violation, and OculaWork reserves the right to suspend the account in such a case.
OculaWork does not carry professional liability (errors & omissions) insurance or any other insurance coverage for the services under this Agreement.
Except as expressly stated in this Agreement, the Platform is provided "as-is" and "as-available." OculaWork makes no express or implied warranty that the Platform will operate uninterrupted, error-free, or entirely free of security vulnerabilities, or that it will be fit for a particular purpose, merchantable, or meet the Customer's expectations.
The Evacuation Drill module is a decision-support tool that produces spatial audit findings, a requirements list, scenarios and drill records on a floor plan drawn by the Customer. No output of the module — including findings, requirements, the OHS Compliance Score, the Risk Score or any drill report — constitutes a certificate of compliance, a fire-safety design, an approved escape plan or an official inspection report, and none of them alone forms a legal basis before the competent authorities.
Responsibility for inputs rests with the Customer. The building outline, room dimensions, clear door widths, floor occupancy, facility type and equipment positions are entered by the Customer; OculaWork does not and cannot verify that this information matches the actual structure. Outputs are valid only to the extent that the entered data is accurate. OculaWork cannot be held liable for results arising from incorrect or incomplete measurements.
Measurement and regulatory limit are distinct. The system always displays the measurements it computes from the plan; by contrast, it states a numeric limit from a regulation only where the source can be verified. Where the source cannot be verified, no limit is stated, the measurement is given and the Customer is asked to confirm it; such items are also excluded from the score. Determining factors such as hazard class, building use class, the presence of sprinklers, building height and the building permit are not known to the system and may change the outcome.
The OHS Compliance Score and Risk Score are estimative indicators. They cover only the items the system can check; the weighting method is a design choice that OculaWork declares openly and does not derive from regulation. A high compliance score does not mean regulatory compliance; a low risk score does not mean a safe workplace. The final compliance assessment rests solely with the employer and the occupational safety specialist / occupational physician they appoint.
Drill records and the attendance ledger. Behavioural records collected during a drill (the route drawn, duration, efficiency, answers) contain no identity and are reported only in aggregate; they may not be used to measure individual performance. The attendance ledger does contain identity for administrative purposes and is never merged with the behavioural records. The attendance record produced by the module does not by itself constitute proof that the drill obligation under Law No. 6331 Art. 11 and the Emergency Situations Regulation has been fulfilled; an official drill report depends on the drill actually being carried out on site and duly recorded by the employer.
Scenarios generated by the module (fire, gas leak, chemical spill, etc.) are constructs for training and awareness; they do not constitute an engineering prediction of how a real incident would develop, nor a fire model or smoke-propagation simulation.
Anonymous transfer of compliance and risk scores. When a floor plan is saved, the OHS Compliance Score and Risk Score computed from that plan, together with derived measures of the plan (area, counts of rooms, doors and equipment, audit finding codes), are transferred to the OculaWork server and used for sector-level comparison. This transfer contains no data relating to any natural person; no identity, name, user id or department is sent. The data relates to a floor plan, not to a person, and therefore does not constitute personal data within the meaning of Law No. 6698.
The plan name is not sent. The name you give a floor plan is free text and may contain the name of the workplace, building or floor; it is transmitted to the server neither as it is nor as a hash. So that records of the same plan can be related to one another over time, a random identifier with no content is generated and stored only in your browser; the link between that identifier and the plan name never leaves your device. A plan with the same name receives a different identifier on a different device.
The transferred data is commercial information belonging to your workplace. A k-anonymity threshold is applied in sector-level comparisons to prevent an individual workplace from being re-identified; no comparison is shown for groups below the threshold. The module can also run standalone: in that case no data is transferred and all records remain solely on your device. The transfer is not retroactive — only records made while the transfer is active are sent.
This clause applies to the attendance ledger of the Evacuation Drill module. The attendance ledger is the only record in the module that contains identity; the behavioural records collected during a drill (route, duration, efficiency, answers) contain no identity and are never merged with this ledger.
Controller and processor. The controller of the attendance record is the employer; OculaWork hosts this data as a processor acting on the employer's instructions.
Data processed. Only the following are stored on the server: the worker's user id (uid), the date of the drill and the attendance status (completed / left unfinished / time expired). Name, surname and department are not written to the server — they already exist in the worker record, so no second copy is created. This ledger contains no route, score or answer; the system also rejects such fields technically.
Purpose and legal basis. The data is processed to evidence fulfilment of the drill obligation under Occupational Health and Safety Law No. 6331 and the Regulation on Emergency Situations in Workplaces. The legal basis is compliance with a legal obligation of the controller under Art. 5/2-ç of Law No. 6698; explicit consent is therefore not required. The data may not be used to measure individual performance.
Retention and erasure. The attendance record is retained for the period during which the employer is obliged to keep OHS records under the applicable legislation; upon expiry it is erased or anonymised. Determining that period and recording it in the personal data inventory is the employer's responsibility.
Transfer. The attendance record is not transferred to third parties and is not included in the anonymous dataset OculaWork uses for sector-level comparison (see 10.10).
Your rights. Under Art. 11 of Law No. 6698 you have the right to access your data, to request its correction or erasure and to object to its processing. You may address your request to your employer.
This text accurately describes the data the system actually processes and its technical limits; preparing the workplace-specific privacy notice and personal data inventory, and verifying legal compliance, rests with the employer.
OculaLearn is a remote occupational health and safety (OHS) training module, hosted on separate Firebase infrastructure (oculalearn.web.app), based on the Annex-1 (Ek-1) curriculum of Turkish Law No. 6331 Art. 17 and the "Implementation Guide for Employees' Occupational Health and Safety Training" (Official Gazette No. 33212, April 2, 2026). OculaWork is responsible for the content and accuracy of the official Annex-1 curriculum. The accuracy, currency, and regulatory compliance of any workplace-specific Topic-4 content and/or fully custom additional trainings entered by the Customer via the "Develop Content" interface is the Customer's sole responsibility; such content is only recorded after the Customer accepts a mandatory liability acknowledgment (with identity, timestamp, and IP address logged) prior to saving. This custom content is never counted toward the official 60/100 pass score or the certificate — only the official Annex-1 curriculum is scored and certified. OculaWork cannot be held liable for any legal, administrative, or criminal consequence arising from Customer-entered custom content.
The Platform's software, source code, algorithms, design and brand are the exclusive intellectual property of OculaWork. Customers are granted a non-exclusive, revocable, limited, worldwide usage license scoped to their subscribed number of users. This license may not be transferred, rented out to another company, or sub-licensed; the Platform may not be copied or reverse-engineered under any circumstances. The license is valid only for the number of active users (seats) actually purchased/subscribed to; if usage exceeds the licensed quota, the Customer will be asked to purchase additional seats. If the licensed number of users is systematically exceeded, OculaWork may retroactively invoice for the excess usage or suspend the account. This Agreement does not transfer any right in the OculaWork brand, trade name, algorithms, or any pending patent applications to the Customer.
Raw scan results and reports belonging to the Customer and its employees remain the Customer's property. OculaWork processes this data solely within the scope of this Agreement; anonymized and aggregated statistics may be used for Platform improvement.
The Platform may incorporate third-party open source software. License rights to such software belong to the respective license holders. Use of open source components does not diminish OculaWork's intellectual property rights under this Agreement.
The Customer may not use OculaWork's brand, logo, or trade name for advertising, reference, or promotional purposes without OculaWork's prior written consent.
Unless otherwise agreed in writing, OculaWork may use the Customer's trade name solely in its reference customer list. The Customer may withdraw this permission at any time by written notice.
Before terminating the Agreement, OculaWork reserves the right to temporarily suspend the Customer's account in the following cases: (i) the Platform or its infrastructure is under an active cyberattack, (ii) suspected unauthorized access/misuse originating from the account, (iii) payment delay (see §13.3), (iv) API abuse, bot traffic, denial-of-service (DDoS) attempts, unauthorized automation, or an unusually high volume of requests (see §11.1 Prohibited Uses). In case (iv), the account may be suspended without prior notice in order to protect the integrity of the Platform or of other Customers. During suspension, access to Customer data is temporarily restricted but not deleted; access is restored once the situation is resolved.
Either party may terminate the Agreement with 30 days' prior written notice.
OculaWork reserves the right to terminate immediately and without compensation in the following cases:
Where a competent court order exists, or where an administrative/legal regulation legally requires it, OculaWork may partially or fully suspend/remove the Platform. To the extent this arises from a legal requirement outside OculaWork's control, it is treated as an exclusion from liability under §10.3.
As of today, the Platform does not set a classic HTTP cookie; the following technical storage mechanisms are kept in the browser's local storage (localStorage):
| Mechanism | Purpose | Type | Duration |
|---|---|---|---|
| ow_lang | Language preference | Functional | localStorage (persistent) |
| Firebase Auth Token | Session management | Essential | 1 hour |
| "Remember Me" token and per-role remembered-email keys | Remembering the session/email for the next login | Functional | localStorage (until logout/reset) |
| Device-pairing (biometric login) key | Remembering that this device was previously paired for biometric login | Functional | localStorage (until reset) |
| Notification preference and device push-token keys | Remembering the notification on/off preference and delivery address | Functional | localStorage (persistent, until disabled) |
| Firm code / last-connected tenant cache | Routing the login screen to the correct firm for self-host tenants | Functional | localStorage (persistent) |
| App version and scan cache | Showing the last known data during offline/delayed connections, update checks | Functional | localStorage (persistent, until updated) |
| Subject | Contact |
|---|---|
| Data protection requests / Data deletion | info@oculawork.com |
| Technical support | info@oculawork.com |
| Legal notices | info@oculawork.com |
| Security vulnerability disclosure | info@oculawork.com |
Data protection requests are responded to within 30 days. To file a complaint with the Turkish Personal Data Protection Authority: kvkk.gov.tr
Notices sent to the email address provided by the parties under this Agreement are deemed delivered on the date sent. The Customer is responsible for keeping its contact information up to date. A message being routed to the recipient's spam/junk folder results from the recipient's own email provider filtering settings; OculaWork cannot be held liable for this. The parties are obligated to notify each other in writing of any change to their contact information within 7 days; the party that fails to do so is responsible for any consequences arising from the failure.
Invoices are issued as e-Invoice or e-Archive Invoice, as permitted by applicable regulations, and are sent and deemed delivered via email.
The Customer represents and warrants that it will not use the Platform in violation of applicable export control and sanctions laws of Turkey or of international bodies/jurisdictions such as the United Nations, European Union, or United States; and that it will not access the Platform on behalf of a person/entity on a sanctions list or from a sanctioned country.
The Customer may not assign this Agreement without OculaWork's prior written consent. In the event of a merger, share transfer, asset sale, or similar corporate restructuring, OculaWork may assign this Agreement and the rights and obligations arising from it to a third party, provided the Customer is notified in advance.
In the event of a conflict between the text of this Agreement and its appendices (Appendix-1 Data Processing Agreement, Privacy Policy, KVKK Disclosure Notices, Consent Form), the following order of precedence applies: (i) Appendix-1 Data Processing Agreement (solely with respect to data-processing provisions), (ii) the main text of this Agreement, (iii) other appendices and separate documents. Notices are given in Turkish unless otherwise specified; in the event of a conflict between the TR/EN texts, the Turkish text prevails.
Each party agrees not to disclose to third parties, and to use solely for the performance of this Agreement, the other party's trade secrets, pricing information, algorithm and software architecture details, customer/employee lists, and other information expressly marked as confidential that it learns of or gains access to under this Agreement. This obligation does not extend to information that is publicly available, must be disclosed under legal requirement, or is independently developed; it survives termination of this Agreement for a reasonable period.
A party's failure to exercise, or delay in exercising, any right arising from this Agreement in a given instance does not constitute a waiver of that right, whether in that instance or in any future instance of the same or a similar nature.
This Agreement and its appendices (Appendix-1 Data Processing Agreement, together with the other documents referenced in §16.3) constitute the entire agreement between the parties regarding their subject matter and supersede all prior written or oral discussions, proposals, and agreements on the same subject. This Agreement may only be amended in writing by OculaWork (see the update-notice provision in §16).
Regardless of the reason this Agreement terminates, provisions that by their nature are intended to remain in effect after termination continue to survive; these include, in particular, Confidential Information (§16.6), Intellectual Property (§11), Indemnification (§16.5), the personal-data-protection provisions (§7), and the Evidentiary Agreement (§16.4).
This appendix applies only to Customers running the Platform on their own infrastructure and their own database. It does not apply to the self-hosted Firebase deployment. In case of conflict, the provisions of this appendix prevail over the main text.
In an enterprise deployment, employee scan records and the health indicators derived from them are held exclusively on the Customer's own server and database. Hosting, backup and availability of this data, and all costs relating to it, belong to the Customer.
Raw camera images, video frames and facial landmark data never leave the employee's device under any circumstances; they are transmitted neither to OculaWork nor to the Customer's server, and are not stored anywhere. The only data leaving the device is numerical measurement results.
The following remain on OculaWork's infrastructure even in an enterprise deployment, because they are required in order to perform the service, and the Customer accepts this:
These components are not included in the licensed software; they are provided as a service and are not delivered to the Customer.
APP-0.3.1 — The enterprise licence is a time-limited right of use; it does not transfer ownership and does not create a perpetual right of use. The Customer's right to use the Software is limited to the licence term stated in the Agreement and terminates automatically upon expiry of that term. Technical restriction or cessation of access upon expiry of the licence term cannot be characterised as a defect, default, or breach of contract.
APP-0.3.2 — For as long as the licence term continues, OculaWork may use the licence verification service in order to verify the validity of the licence by technical means.
APP-0.3.3 — Inability to reach the verification server is not expiry of the licence. Temporary unavailability of the licence verification service does not mean that the licence has expired or become invalid. In that case the Software continues to operate offline on the basis of the last verified status of the valid licence; where a verification problem persists, a warning is displayed to the Customer's administrator.
APP-0.3.4 — Access to the Software by a Customer whose licence term is still running may not be stopped by reason of a technical outage originating from OculaWork's infrastructure, planned maintenance, infrastructure failure, or unavailability of the licence verification service, and the licence term shall not be treated as shortened without fault on the Customer's part.
APP-0.3.5 — Where the Customer fails to pay the licence fee when due, OculaWork will give written notice and allow an additional period of at least 15 days for payment. If payment is not made by the end of that period and the default continues, OculaWork may temporarily suspend use of the Software. Suspension does not constitute termination of the Agreement and does not extinguish the Customer's other rights and obligations.
APP-0.3.6 — Before any suspension, OculaWork will send the Customer written notice stating the suspension date and the amount due. Where a payment dispute reasonably requires examination, access will not be suspended until the dispute has been resolved. During a valid licence period, the Service will not be technically disabled solely on the ground that a payment dispute exists, without operating the notices and periods set out above.
APP-0.3.7 — Access to data. Even where access is suspended or the licence expires, the Customer retains the right to export its own data on the terms and within the periods set out in APP-0.8.
In an enterprise deployment, personal data relating to the Customer's employees is processed without being removed from the Customer's own IT infrastructure. OculaWork carries out the analysis activity within the Customer's infrastructure, through software components authorised by the Customer.
In an enterprise deployment, the fields that may be sent from the Customer's server to OculaWork's central system are technically restricted. This is not merely an undertaking but the maximum the system permits: any field outside the allowlist is rejected server-side.
| Channel | Fields that may be sent | Rejected |
|---|---|---|
| Model development contribution (off by default) | modelVersion, sampleCount, gradient, noiseScale | Every field outside the schema — employee identity, department, email, raw measurements, free text, dates |
| Notification delivery (only in "mail sent by us" mode) | Recipient address, template identifier, link to the Customer's own address | Free text, subject, HTML body, attachments |
| Licence verification | Licence identifier, version, system health status | Employee data |
| Daily deployment signal (health and tamper detection) | Deployment identifier, model version, decision-core digest, coarse time since last training, aggregated measurement counter, rejected-request counters | Identity, department, free text, exact timestamp, any field outside the schema |
| Central psychosocial consult (off by default) | Sector code, employee-count band, distributions derived from ≥50 measurements (sub-threshold cells suppressed), noise scale | Individual records, identity, department name, free text, dates, exact employee count |
Model development contributions are further subject to: being derived from at least 50 measurements, having privacy-enhancing noise applied, and having the contribution magnitude bounded. The application of these techniques does not mean the data is legally anonymous; anonymity is assessed separately on the concrete circumstances.
Release of the source code to the Customer is possible only upon the occurrence of trigger events defined in a separately executed source code escrow agreement between the parties. The purpose of escrow is not to give the Customer access to the source code at will, but to protect the Customer's operational continuity in exceptional circumstances.
Trigger events are limited and expressly defined: OculaWork permanently ceasing operations, the conditions specified in the agreement arising in the context of bankruptcy/composition proceedings, or the permanent discontinuation of support and maintenance services. A temporary service interruption is not a trigger event.
The component on the Customer's server accepts only model packages signed with OculaWork's valid private key and whose integrity has been verified. An unsigned package, or one whose signature cannot be verified, is not executed.
The signing private key is under no circumstances sent to the Customer environment; only the verification (public) key resides on the Customer side. This separation prevents the Customer from introducing a self-produced model and prevents distribution of forged models should the central infrastructure be compromised.
OculaWork's remote administrative access to the Customer's infrastructure is disabled by default. Where support requires it, access is authorised by the Customer temporarily and limited to the purpose.
Every authorised access is logged with who, when, for what purpose and to which resource. OculaWork support personnel have no default access to employee content.
Where a standard contract is used for a cross-border transfer, it must be notified to the Authority within 5 business days of signature. Which party performs the notification is expressly determined in the relevant Order Form or transfer agreement, according to the transfer scenario and the parties' status.
The standard contract text is used without modification, as required by law; commercial terms specific to the parties are set out in a separate agreement.
The Customer may not disable, modify or circumvent the licence check. Any attempt to run the software without connecting to OculaWork's licence service constitutes a material breach and entitles OculaWork to terminate the Agreement immediately for cause.
The fact that client-side components of the software are technically readable does not grant the Customer any right of reproduction, creation of derivative works, transfer or sub-licensing.
OculaWork reserves the right to audit the number of installations and licence compliance, upon reasonable notice and without disrupting the Customer's operations. The parties agree that the signed licence and access records produced by the software have evidentiary value. If non-compliance is found, the costs of the audit are borne by the Customer.
The reporting thresholds (at least 5 employees per department, at least 10 company-wide) are a contractual undertaking. The Customer may not request that these thresholds be lowered or that the aggregation/suppression protection be circumvented. Managers cannot access an employee's health data; such data is visible only to the employee themselves and the authorised occupational physician.
Installation, updating, backup and operation of the server are the Customer's responsibility; these obligations are defined in the Operations Guide provided by OculaWork, which is deemed an annex to this Agreement. OculaWork's service level undertaking is limited solely to the services it provides (licence, analysis, e-mail); outages, data loss or performance issues within the Customer's infrastructure are out of scope.
Upon termination, the Customer's data remains with the Customer, as it already resides on their own server; no separate obligation of return arises for OculaWork. The de-identified model training data held at OculaWork is irreversibly anonymous and is therefore not deleted, and the Customer consents to this in advance.
This appendix is an integral part of this Service Agreement and governs the data-processing relationship between the Customer and OculaWork under KVKK Art. 3. It is a consolidated summary of the relevant provisions within the main text; in case of conflict, the corresponding section of the main text prevails.
| Element | Description |
|---|---|
| Data Controller | Customer |
| Data Processor | OculaWork (see §1 Definitions) |
| Subject Matter and Duration of Processing | For the duration of this Agreement, for OSH risk analysis and related purposes (see §7.1 table) |
| Categories of Data Subjects | The Customer's employees |
| Categories of Personal Data | Identity, contact, health/biometric, behavioral, organizational, transaction data (see §7.1 table) |
| Processing Instructions | OculaWork processes personal data only per the Customer's instructions and for the purposes stated in this Agreement; it does not process for a different purpose (see §7.0, §7.4) |
| Processor's Obligations | See §7.0 |
| Sub-Processor | Google Firebase / Google Cloud (see §4.2); the Customer is notified in advance of any change |
| Security Measures | See §9 (Data Security) |
| International Transfers | Data is stored in the European region (eur3); any transfer is subject to the KVKK Art. 9 regime (see §4.2) |
| Breach Notification | Without undue delay and in any event within 24 hours (see §9.3) |
| Deletion Procedure | Data is returned to the Customer upon request at contract end; permanently deleted after 90 days, with written confirmation to the Customer (see §4.3, §13.4) |