Platform'u kullanmaya başlamakla bu Sözleşme'nin tüm hükümlerini okuduğunuzu, anladığınızı ve kabul ettiğinizi beyan etmiş sayılırsınız. Kabul etmiyorsanız Platform'u kullanmayınız.
01 Taraflar ve Kapsam

Bu Hizmet Kullanım Sözleşmesi, Gizlilik Politikası ve KVKK Aydınlatma Metni (birlikte "Sözleşme") aşağıdaki taraflar arasında akdedilmiştir:

Hizmet Sağlayıcı

OculaWork — oculawork.com alan adı üzerinden çalışan göz sağlığı ve yorgunluk analizi platformu ("OculaWork", "Platform", "Biz").

Ticaret UnvanıCimedya Bilgi Sistemleri Reklam ve Tic. A.Ş.
Vergi Dairesi / NoMaltepe V.D. — 2100357903
Tebligat AdresiSöğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara
E-postainfo@oculawork.com
Müşteri

OculaWork'e abone olan, Platform'u kendi çalışanları için kullanan her türlü gerçek veya tüzel kişi, şirket, kurum ya da kuruluş ("Müşteri", "İşveren", "Siz").

Son Kullanıcı / Çalışan

Müşteri bünyesinde çalışan, Müşteri tarafından sisteme tanımlanan ve Platform üzerinden ölçüm gerçekleştiren kişiler ("Çalışan", "Son Kullanıcı").

⚠️ Önemli: Bu Sözleşme B2B (işletmeden işletmeye) bir hizmet ilişkisini düzenlemektedir. Müşteri; çalışanlarına karşı veri sorumlusu sıfatıyla, kendi belirlediği işleme amaçları ve vasıtaları bakımından KVKK ve ilgili mevzuattan doğan yükümlülüklerini yerine getirir. Bu hüküm, OculaWork'ün veri işleyen sıfatıyla kanundan veya işbu Sözleşme'den doğan kendi yükümlülüklerini ortadan kaldırmaz.
02 Tanımlar
TerimTanım
Platformoculawork.com ve bağlı alt domainlerinde sunulan yazılım, arayüzler ve tüm hizmetler bütünü
KVKK6698 sayılı Kişisel Verilerin Korunması Kanunu ve ilgili yönetmelikler
İSG Kanunu6331 sayılı İş Sağlığı ve Güvenliği Kanunu
Veri SorumlusuKVKK Md. 3/1-ı — İşleme amaç ve vasıtalarını belirleyen kişi. Çalışan verisinin Platform üzerinden işlenmesi bakımından Müşteri (bkz. §7.5)
Veri İşleyenKVKK Md. 3/1-ğ — Veri sorumlusunun verdiği yetkiye dayanarak onun adına veriyi işleyen. Müşteri adına yürütülen çalışan verisi işleme faaliyetleri bakımından OculaWork (bkz. §7.5)
Altyapı SağlayıcısıGoogle Firebase / Google Cloud — verinin fiziksel olarak barındırıldığı platform; OculaWork'ten bağımsız bir tüzel kişi
Özel Nitelikli VeriKVKK Md. 6 — Sağlık, biyometrik veriler dahil hassas kategori
EAR / PERCLOSGöz açıklık oranı / göz kapama yüzdesi — Platform'un ölçtüğü kamera tabanlı fizyolojik ve davranışsal göstergeler. Bir verinin biyometrik veri niteliği taşıyıp taşımadığı, yalnızca sayısal olmasına göre değil, verinin belirli bir kişiyi benzersiz biçimde tanımlamak veya doğrulamak amacıyla kullanılıp kullanılmadığına göre somut olarak değerlendirilir (bkz. §7.1)
Açık RızaKVKK Md. 3/1-a — Belirli bir konuya ilişkin, bilgilendirmeye dayanan, özgür iradeyle verilen rıza
VERBİSKişisel Verileri Koruma Kurumu'nun Veri Sorumluları Sicili Bilgi Sistemi
SaaSSoftware-as-a-Service — abonelik modeliyle sunulan bulut tabanlı yazılım hizmeti
03 Hizmetin Kapsamı ve Niteliği
🏢 B2B kabul sınırı: İşbu Sözleşme, Müşteri'nin yetkili temsilcisinin abonelik oluşturması veya Sipariş Formu'nu imzalaması ile kurulur. Çalışanın veya Son Kullanıcının Platform'u kullanması, onu işbu Sözleşme'nin tarafı ya da Müşteri adına sözleşme kabul etmeye yetkili kişi hâline getirmez. Çalışanlar bakımından geçerli olan belgeler Aydınlatma Metni ve —gerekiyorsa— Açık Rıza metinleridir.
3.1 Sunulan Hizmet

OculaWork; işyerlerinde çalışma koşulları, ergonomik maruziyet ve operasyonel risklerin değerlendirilmesine destek olmak amacıyla, standart bilgisayar kamerası aracılığıyla göz ve yüz hareketlerinden ölçülebilir davranışsal ve ergonomik göstergeler üreten, bilimsel literatürde yer alan yöntemlerden yararlanan ve işverenlere / iş yeri hekimlerine risk bazlı raporlar sunan bir SaaS platformudur. Platform tıbbi teşhis, hastalık taraması, tıbbi durum izleme veya tedavi amacı taşımaz; tıbbi karar vermez.

⚠️ İş kazası ve uygunluk garantisi verilmez. Platform çıktıları; bir iş kazasının gerçekleşmeyeceği, mevcut bir riskin tespit edileceği veya bir çalışanın belirli bir zamanda çalışmaya uygun olduğu yönünde hiçbir garanti oluşturmaz. Risk değerlendirmesi ve önleyici tedbirlerin alınması yükümlülüğü, ilgili mevzuat uyarınca işverene aittir.
3.2 Teknik Kapsam
  • 30 saniyelik aktif ölçüm ile EAR, PERCLOS, kırpma hızı, reaksiyon süresi ve 4 ek fizyolojik/davranışsal gösterge ölçülür
  • Kamera görüntüsü yalnızca tarayıcıda (client-side) işlenir; ham video verisi hiçbir sunucuya gönderilmez
  • Sunuculara yalnızca hesaplanmış sayısal metrikler iletilir
  • Yönetim paneli departman bazlı anonim istatistikler sunar; bireysel veriler yalnızca iş hekimine açıktır
3.3 Tıbbi Sorumluluk Reddi ve Yapay Zeka Karar Mekanizması
⚕️ Platform çıktıları bilgilendirme ve karar destek amaçlıdır. Tıbbi teşhis, tedavi önerisi, iş göremezlik belgesi veya hekimlik görüşü niteliği taşımaz. Platform sonuçları; işe giriş muayenesi, periyodik muayene ya da disiplin kararı için tek başına yeterli hukuki dayanak oluşturmaz. Yapay zekâ tarafından üretilen hiçbir çıktı (risk skoru, anomali uyarısı, OwO modeli dahil) otomatik bir personel kararı oluşturmaz veya oluşturamaz; nihai değerlendirme daima yetkili işyeri hekimi ve/veya işveren tarafından, insan gözetiminde yapılır. Platform çıktıları; performans puanlaması, maaş/ücret indirimi veya işten çıkarma gibi tek başına belirleyici bir sonuç için kullanılamaz. Yapay zekâ sistemleri, doğaları gereği yanlış pozitif veya yanlış negatif sonuçlar üretebilir; Müşteri ve Çalışan bu olasılığı kabul eder. Modelin genel çalışma mantığı (kullanılan veri kaynakları, yöntem) talep üzerine açıklanabilir; ancak ticari sır niteliğindeki spesifik algoritma detayları ve model ağırlıkları paylaşılmaz. Kural tabanlı algoritmalar ve OwO modeli zaman içinde güncellenebilir, iyileştirilebilir veya farklı sinyallerle yeniden eğitilebilir; bu nedenle aynı girdi için farklı zamanlarda üretilen çıktılar arasında değişiklik olabilir.
3.4 Hizmet Sürekliliği

OculaWork, yüksek erişilebilirlik hedefiyle çalışmakla birlikte planlı bakım, mücbir sebep veya altyapı sağlayıcısından kaynaklanan kesintilerden sorumlu tutulamaz. Planlı kesintiler 48 saat öncesinden duyurulur. Bu, sayısal bir yüzde taahhüdü değil, genel bir hedef niteliğindedir; bir hizmet seviyesi taahhüdü (SLA) veya hizmet kredisi (service credit) programı oluşturmaz. Erişilebilirlik değerlendirilirken: ilgili aydaki toplam süre esas alınır; planlı bakım süreleri (bkz. aşağıda) ve Google Firebase/Google Cloud altyapısından kaynaklanan kesintiler bu değerlendirmeye dahil edilmez (bkz. §10.3).

Aynı fiyatlandırma dönemi içinde (bkz. §12) yürürlükteki abonelik ücreti değiştirilmez; fiyat değişikliği yalnızca bir sonraki yenileme döneminden itibaren uygulanabilir.

Planlı bakım, mümkün olduğunca hafta sonu veya gece saatlerinde yapılır ve tek seferde en fazla 4 saat sürecek şekilde planlanır. Platformun güvenliğini veya bütünlüğünü tehdit eden acil bir durum söz konusuysa (örn. aktif saldırı), acil bakım önceden bildirim yapılmaksızın uygulanabilir.

💾 Yedekleme: Platform, Google Firebase'in kendi otomatik altyapı yedekleme mekanizmalarına dayanır. Şu an için ayrı, sayısal bir kurtarma süresi hedefi (RTO) veya kurtarma noktası hedefi (RPO) taahhüdü verilmemektedir.
3.5 Destek Hizmeti
KapsamDetay
Destek saatleriHer gün 08:00–20:00 (Türkiye saati)
Kritik arıza (sistem tamamen erişilemez durumda)Destek saatleri içinde 24 saat içinde ilk yanıt
Normal destek talebi2 iş günü içinde ilk yanıt
Yeni özellik talepleriDeğerlendirmeye alınır, teslim tarihi taahhüt edilmez

Yukarıdaki yanıt süreleri yalnızca destek talebinin alındığını ve işleme koyulduğunu ifade eder; kesin bir çözüm süresi taahhüdü oluşturmaz.

📖 Tanımlar: "Erişilebilirlik (uptime)", §3.4'te belirtilen hesaplama yöntemine göre değerlendirilir. "Planlı bakım (maintenance)", §3.4'te tanımlanan, önceden duyurulan ve en fazla 4 saat süren kesintileri ifade eder. "Kritik arıza (incident)", yukarıdaki tabloda tanımlandığı gibi Platform'un tamamen erişilemez olduğu durumu; bunun dışındaki tüm talepler "normal destek talebi" olarak sınıflandırılır. Bu Sözleşme, yukarıdaki iki kategori (kritik/normal) dışında ayrı bir resmi önem derecesi (severity) sınıflandırma sistemi taahhüt etmez.
3.6 Beta Özellikler

Platform üzerinde "beta", "önizleme" veya "deneysel" olarak işaretlenen özellikler (yeni geliştirilen yapay zeka modülleri dahil) ön izleme niteliğindedir; kesintiye uğrayabilir, beklenmedik şekilde değişebilir veya kaldırılabilir. Bu özellikler için sonuç garantisi verilmez ve Sözleşme'nin genel hizmet sürekliliği/SLA taahhütleri bu özellikleri kapsamaz. Beta özellikler, veri kaybına veya hatalı veri üretimine yol açabilir; Müşteri, beta özellikleri kritik/tek kaynaklı veri için kullanmamalıdır.

3.7 Gelecekteki Entegrasyonlar

OculaWork, ileride üçüncü taraf sistemlerle (kimlik/dizin servisleri, kurumsal iletişim araçları, ERP/İK yazılımları vb.) entegrasyon sunabilir. Bu tür entegrasyonlar, yayımlandıkları tarihte ayrıca duyurulacak ek şartlara tabidir; işbu Sözleşme hâlihazırda var olmayan bir entegrasyonu taahhüt etmez. Aynı şekilde, ileride bir genel API sunulması hâlinde; kullanım limitleri (rate limit), API anahtarı yönetimi ve kötüye kullanım politikaları ayrı bir API Kullanım Şartları belgesinde düzenlenir.

3.8 Teknik Gereksinimler
  • Kamera izni zorunludur: Kullanıcı kamera erişim iznini reddederse veya geri çekerse, kamera tabanlı tarama özellikleri çalışmaz; bu durumda hizmetin bu kısmı sağlanamaz
  • Desteklenen tarayıcılar: Güncel sürümleriyle Google Chrome, Microsoft Edge, Mozilla Firefox ve Safari; Internet Explorer desteklenmez
  • Asgari donanım: En az 640×480 çözünürlükte çalışan bir web kamerası, yeterli ortam aydınlatması ve kararlı bir internet bağlantısı
3.9 Görüntülü Görüşme

Platform, yalnızca iş hekiminin başlatabileceği (tek yönlü), çalışanla doğrudan görüntülü görüşme kurulmasını sağlayan bir özellik sunar. Bağlantı, üçüncü bir sunucudan geçmeden doğrudan iki cihaz arasında (WebRTC, ücretsiz Google STUN sunucusu) kurulur; ses/görüntü hiçbir sunucuda kaydedilmez veya saklanmaz. Görüşmeyi kurmak için gereken teknik bağlantı verisi (SDP/ICE), görüşme bitiminden birkaç saniye sonra otomatik olarak silinir. Görüşme sırasında, çalışanın kamera görüntüsünden — yalnızca görüşme süresince ve yalnızca o an görüşmedeki hekime gösterilmek üzere — kamera tabanlı yaklaşık bir nabız tahmini ile göz kırpma/PERCLOS bazlı anlık bir yorgunluk-stres göstergesi hesaplanır. Bu göstergeler tıbbi ölçüm veya teşhis niteliği taşımaz, klinik cihazın yerini tutmaz ve çalışanın kalıcı tarama geçmişine hiçbir zaman eklenmez/kaydedilmez. TURN sunucusu kullanılmadığından, çok katı kurumsal ağ/güvenlik duvarı yapılandırmalarında bağlantı nadiren kurulamayabilir.

04 Veri Mimarisi — Veri Minimizasyonu ve Veri Yerleşimi
🏢 Kurumsal kurulum: Platform'u kendi sunucunuzda ve kendi veritabanınızda çalıştırıyorsanız bu bölüm sizin için kısmen geçerlidir. Tarama kayıtlarınız Firebase'de değil, kendi veritabanınızda tutulur. Bu durumda öncelikli olarak EK-0 — Kurumsal Kurulum hükümleri uygulanır.
OculaWork'ün kendi fiziksel veri merkezi veya fiziksel sunucusu bulunmamaktadır. Müşteri verileri OculaWork'e ait donanımda veya OculaWork'ün işlettiği bir veri merkezinde saklanmaz; hizmet, OculaWork tarafından yönetilen bulut hizmetleri üzerinden sunulur (bu ayrım için bkz. EK-0.2). Tüm veri, Google Firebase / Google Cloud altyapısında barındırılır.
4.1 Veri Akış Mimarisi
AşamaNerede İşlenir / SaklanırOculaWork Erişimi
Kamera görüntüsü (ham video)Yalnızca kullanıcının tarayıcısı (RAM) — hiçbir yere gönderilmez❌ Erişim yok
Hesaplanan sayısal metrikler (EAR, PERCLOS vb.)Google Firebase Firestore (Google Cloud altyapısı)Yazılım yönetimi için sınırlı admin erişimi
Kullanıcı hesap bilgileriGoogle Firebase AuthenticationYazılım yönetimi için sınırlı admin erişimi
Uygulama dosyaları (HTML, JS)Google Firebase Hosting (CDN)Tam erişim — yazılım sahibi
OwO danışma profili (anonim sayısal metrikler — bkz. §7.4)Google Cloud Functions (Avrupa) → yalnızca 0-1 arası bir sektörel bağlam skoru (owoContextScore) tarama kaydına eklenirKimlik bilgisi hiçbir zaman gönderilmez/işlenmez
OwO eğitim örneği (anonim özellik vektörü + etiket — bkz. §7.4)Google Firebase Firestore (Avrupa) — yalnızca sayısal vektör, tarih ve 0/1 etiket; kimlik veya firma bilgisi hiçbir zaman içermezKimseye açık değil (admin dahil); yalnızca model eğitimi tarafından okunur, 180 gün sonra otomatik silinir
Doktor ekranınca tanınan ilaç adı (yalnızca sedasyon sınıfı sorgusu için)Google Cloud Functions (Avrupa) — sorgu anlıktır, sonuç veya sorgu hiçbir yere kaydedilmezYalnızca doktorun zaten erişim yetkisi olan anamnez verisinden türetilir
OwO geri bildirimi (👍/👎, bkz. §7.4)Google Firebase Firestore (Avrupa) — yalnızca bilgi türü + faydalı olup olmadığıKimseye açık değil (admin dahil); yalnızca toplulaştırılmış oran sunucu tarafında hesaplanır
Hekimin klinik doğruluk değerlendirmesi (bir tarama için "isabetli/düşük/yüksek/sevk gerekli", bkz. §7.4)Google Firebase Firestore (Avrupa) — o tarama kaydına bağlı olarak saklanır; OwO'nun eğitimine anonim, düzeltilmiş bir etiket olarak dahil edilirYalnızca ilgili kiracının hekim/yönetimine açık
Hata bildirimi ve otomatik yakalanan teknik tanı verisi (tarayıcı hatası, cihaz/tarayıcı bilgisi — bkz. §9.4)Google Firebase Firestore (Avrupa)Yalnızca OculaWork admin'i erişebilir; çalışanın kendi işvereni bu veriyi göremez
4.2 Google Firebase'in Rolü

Google Firebase; Google LLC'ye bağlı, bağımsız bir bulut altyapısı ve veri barındırma hizmetidir. Firebase'in veri işleme koşulları ve güvenlik önlemleri Google'ın Gizlilik Politikası ile Firebase Veri İşleme Şartları'na tabidir.

  • Google Firebase, ISO/IEC 27001, SOC 2 Type II gibi uluslararası güvenlik standartlarına sahip bir altyapıdır ve veri işleme süreçleri Google'ın yayımladığı güncel veri işleme şartlarına (DPA) tabidir
  • Veriler Avrupa bölgesinde (eur3 — Belçika/Hollanda) tutulur
  • Firebase, OculaWork'ten bağımsız bir kuruluş olarak verileri kendi politikalarına göre korur
🌍 Yurt Dışına Veri Aktarımı (KVKK Md. 9): 7499 sayılı Kanun ile değişik KVKK Md. 9 uyarınca, kişisel verilerin yurt dışına aktarımı ancak (i) Kurul'ca verilmiş bir yeterlilik kararı, (ii) yeterlilik kararı yoksa Kurul'un standart sözleşme metninin akdedilip Kurul'a bildirilmesi ya da onaylı bağlayıcı şirket kuralları, veya (iii) istisnai hâllerde Kurul izni ile mümkündür. Veriler Avrupa bölgesinde tutuluyor olsa dahi, Google'ın destek erişimi veya alt-işleyen kullanımı nedeniyle AB dışına aktarım söz konusu olabilir; bu aktarım Google Firebase'in güncel Veri İşleme Şartları'na (DPA) tabidir. Müşteri, kendi VERBİS/envanter kayıtlarında bu aktarımı doğru şekilde beyan etmekle ve gerekirse kendi hukuki danışmanıyla bu mekanizmanın KVKK Md. 9'un güncel şartlarını karşıladığını teyit etmekle yükümlüdür.
4.3 Veri Mülkiyeti ve Taşınabilirlik

Müşteri'ye ait tüm veriler (tarama sonuçları, raporlar, hesap bilgileri) Müşteri'ye aittir; OculaWork bu veriler üzerinde Sözleşme'de tanınanlar dışında hak iddia etmez. Kişisel veriler klasik anlamda mülkiyet konusu değildir; bu hüküm, Müşteri tarafından sağlanan ve Müşteri adına işlenen veriler üzerindeki kullanım ve tasarruf haklarını düzenler, ilgili kişilerin KVKK'dan doğan haklarını etkilemez. Müşteri talep ettiğinde verilerin dışa aktarımı sağlanır; dışa aktarım yalnızca OculaWork'ün o tarihte desteklediği formatlarda (örn. JSON/CSV) yapılır, başka bir format garanti edilmez. Dışa aktarım sırasında verinin OculaWork tarafındaki bütünlüğü korunur; ancak dışa aktarılan verinin üçüncü taraf sistemlerle (ör. Müşteri'nin kendi ERP/İK yazılımı) uyumluluğu veya bu sistemlere aktarımdan sonraki bütünlüğü garanti edilmez. Sözleşme sona erdiğinde veriler 90 gün içinde sistemden kalıcı olarak silinir. Bu 90 günlük süre, sözleşme sona erdikten sonra erişilebilir durumdaki operasyonel verilerin silinmesine ilişkindir; §7.2'de belirtilen saklama süreleri ile mevzuattan doğan saklama yükümlülükleri saklıdır. Hesap kapatılsa/veriler silinse dahi, muhasebe mevzuatı (VUK vb.), işlem kayıtları ve KVKK kapsamındaki yasal saklama yükümlülükleri nedeniyle bazı kayıtlar (örn. fatura bilgileri) yasal saklama süreleri boyunca ayrıca tutulabilir.

05 Müşterinin Yükümlülükleri
5.1 Veri Sorumlusu Sıfatı ve KVKK Yükümlülükleri

Müşteri, bünyesindeki çalışanların kişisel verilerinin işlenmesi bakımından 6698 sayılı KVKK kapsamında, çalışan verisinin Platform üzerinden işlenmesi bakımından Veri Sorumlusu sıfatını haizdir. Bu kapsamda aşağıdaki yükümlülükleri OculaWork'ten bağımsız olarak yerine getirir:

  • Aydınlatma (KVKK Md. 10): Çalışanlara işlenecek veriler ve amaçları hakkında önceden aydınlatma metni sunmak
  • Açık rıza (KVKK Md. 5-6): Sağlık/biyometrik veri işleme için gerekli hukuki dayanağı oluşturmak
  • İlgili kişi hakları (KVKK Md. 11): Çalışanların erişim, düzeltme, silme ve itiraz başvurularını karşılamak
  • VERBİS kaydı: Kapsama giriyorsa VERBİS'e kayıt yaptırmak ve güncel tutmak
  • Veri envanteri: İşlenen kişisel verilere ilişkin kayıt ve envanter tutmak
⚠️ Müşteri, yukarıdaki yükümlülükleri yerine getirdiğini Platform'u kullanmaya başlamakla beyan ve taahhüt eder. Bu yükümlülüklerin Müşteri tarafından yerine getirilmemesinden kaynaklanan ve OculaWork'ün kendi kusurundan veya işbu Sözleşme'den doğan yükümlülüklerinin ihlalinden kaynaklanmayan idari para cezası, tazminat ve yasal sorumluluk Müşteri'ye aittir. Bu hüküm, OculaWork'ün veri işleyen sıfatıyla kanundan ve işbu Sözleşme'den doğan kendi yükümlülüklerini ortadan kaldırmaz (bkz. §7.0, §7.5, §9.3).
📄 Aydınlatma ve Açık Rıza Metinlerinin Ayrı Düzenlenmesi: Kişisel Verileri Koruma Kurulu'nun 18.02.2026 tarih ve 2026/347 sayılı İlke Kararı uyarınca — 24.03.2026 tarihinde Resmî Gazete'de yayımlanarak yürürlüğe girmiştir — açık rıza şartına dayalı işlemelerde aydınlatma metni ile açık rıza metni farklı başlıklar altında, ayrı beyanlarla düzenlenmelidir; iki metnin iç içe sunulması veya tek bir onayla birleştirilmesi Kurul tarafından hukuka aykırı kabul edilmektedir. Bu yükümlülüğe uyulmaması Kanun'un 12. maddesi uyarınca idari para cezasına tabidir. Müşteri, çalışanlarına sunacağı KVKK metinlerini hazırlarken bu ayrımı gözetmekle yükümlüdür.
5.2 İSG Kanunu Kapsamındaki Yükümlülükler
  • Platform, işverenin 6331 sayılı Kanun kapsamındaki İSG süreçlerine destek amacıyla kullanılabilir. Anılan Kanun'un 15. maddesi sağlık gözetimi yükümlülüğünü düzenler; bundan Platform'un kamera tabanlı ölçümünün zorunlu olduğu sonucu çıkarılamaz (bkz. §8.1)
  • İş hekimi ile geçerli sözleşme bulunmalıdır; Platform verileri periyodik muayenenin yerini almaz
  • Risk tespiti sonrası aksiyon planları ve takibi Müşteri'nin sorumluluğundadır
5.3 Teknik ve Kullanım Yükümlülükleri
  • Sisteme yetkisiz üçüncü kişilerin erişimini engellemek
  • Platform'u yalnızca iş güvenliği amacıyla kullanmak; çalışanları izlemek, disipline etmek veya ayrımcılık amacıyla kullanmamak
  • Platform'u tersine mühendislik veya rakip ürün geliştirme amacıyla kullanmamak
  • Sözleşme süresince güncel ve doğru iletişim bilgileri sağlamak
06 OculaWork'ün Yükümlülükleri
6.1 Yazılım Sağlayıcısı Sıfatı

OculaWork; bir yazılım sağlayıcısıdır ve Müşteri verilerini yalnızca Müşteri'nin talimatları ve bu Sözleşme çerçevesinde işler. Verileri kendi menfaatine, üçüncü taraf pazarlamasına veya başka amaçlara kullanmaz.

6.2 Güvenlik Taahhütleri
  • Tüm veri iletişimi TLS 1.3 ile şifreli bağlantı üzerinden gerçekleştirilir
  • Firebase Firestore güvenlik kuralları ile rol bazlı erişim kontrolü (RBAC) uygulanır
  • Kamera görüntüsü client-side işlenmekte; ham görüntü sunucuya iletilmemektedir
  • Yönetim panelinde bireysel sonuçlar gösterilmez; yalnızca §11'deki eşikleri geçmiş toplulaştırılmış istatistikler görünür. Bireysel detaylara yalnızca çalışanın kendisi ve yetkilendirilmiş iş yeri hekimi erişir
  • Güvenlik ihlali durumunda Müşteri gecikmeksizin ve her hâlükârda 24 saat içinde bildirilir; KVKK Kurumu'na bildirim, veri sorumlusunun mevzuattan doğan süresi içinde yapılır
6.3 Alt İşleyenler
Alt İşleyenAmaçVeri Konumu
Google Firebase FirestoreVeri depolamaAvrupa (eur3)
Google Firebase AuthenticationKimlik doğrulamaAvrupa
Google Firebase HostingUygulama barındırmaGlobal CDN
Google Cloud FunctionsArka uç işlemlerAvrupa
ResendKimlik bilgisi/bildirim e-postalarının gönderimi ve info@oculawork.com adresine gelen postanın yönlendirilmesiAmerika Birleşik Devletleri. Sağlayıcı, kendi belgelerinde birincil işleme operasyonlarının ABD'de yürütüldüğünü ve kişisel verilerin AEA/Birleşik Krallık/İsviçre dışına aktarılabileceğini belirtmektedir. Bu nedenle e-posta kanalı KVKK Md. 9 aktarım zincirinin bir parçası olarak değerlendirilir (bkz. §4.2). Veri minimizasyonu: bu kanaldan bireysel ölçüm sonucu, yorgunluk/risk skoru veya sağlıkla ilişkili kişisel değerlendirme gönderilmez; yönetim raporlarında yalnızca §11'deki eşikleri geçmiş toplulaştırılmış veriler yer alır

OculaWork, hizmetin sunulması amacıyla altyapı, barındırma, e-posta, güvenlik, analiz veya destek hizmeti sunan alt işleyenlerden yararlanabilir. Güncel alt işleyen listesi, işleme amaçları ve veri konumları yukarıda gösterilir ve Müşteri'nin erişimine açıktır.

Yeni bir alt işleyenin kişisel verilere erişimini gerektiren değişiklikler, yürürlüğe girmeden en az 30 gün önce Müşteri'ye bildirilir. Müşteri, haklı ve makul veri koruma gerekçeleriyle bu değişikliğe itiraz edebilir; itiraz hâlinde taraflar makul bir çözüm üzerinde iyi niyetle görüşür.

🔗 Bildirim zinciri: Müşteri, OculaWork'e OSGB veya başka bir iş ortağı kanalıyla ulaşıyorsa, alt işleyen değişikliği bildirimi veri sorumlusu sıfatını taşıyan tarafa ulaştırılır. Bu kanaldaki iş ortağının yalnızca ticari aracı mı olduğu, yoksa veri işleme zincirinde ayrıca bir rolü bulunup bulunmadığı ilgili iş ortaklığı sözleşmesinde açıkça belirlenir.
6.4 Veri Paylaşımı

OculaWork, Müşteri'ye ait verileri yalnızca şu durumlarda üçüncü taraflarla paylaşır:

  • Müşteri'nin yazılı açık onayı alındığında
  • Yetkili mahkeme veya kanunen yetkili idari makam tarafından usulüne uygun şekilde talep edilmesi hâlinde; OculaWork bu talebi yürürlükteki mevzuat çerçevesinde karşılar ve hukuken yasaklanmadığı sürece durumu Müşteri'ye makul süre içinde bildirir
6.5 Yasal Süreçlerde İş Birliği

Taraflar, kişisel veriler veya bilgi güvenliği ile ilgili resmi inceleme, denetim veya yargısal süreçlerde birbirlerine makul ölçüde destek sağlamayı kabul eder.

07 Kişisel Verilerin Korunması (KVKK)
7.0 OculaWork'ün Veri İşleyen Olarak Yükümlülükleri (Veri İşleme Hükümleri)

Müşteri tarafından belirlenen amaç ve vasıtalar kapsamında yürütülen çalışan verisi işleme faaliyetlerinde Müşteri Veri Sorumlusu, OculaWork ise KVKK Md. 3/1-ğ uyarınca Veri İşleyen sıfatını taşır. OculaWork'ün kendi amaçlarıyla yürüttüğü faaliyetler (hesap yönetimi, faturalama, güvenlik kayıtları) bakımından sıfatı §7.5'te düzenlendiği üzere ayrıca belirlenir. Veri işleyen sıfatını taşıdığı faaliyetlerde OculaWork:

  • Kişisel verileri yalnızca Müşteri'nin talimatları ve işbu Sözleşme'de belirtilen amaçlarla işler; kendi başına farklı bir amaçla işlemez (anonim/agregatif işleme için bkz. §7.4)
  • Kişisel verilerin gizliliğini korur; verilere erişimi olan personelini gizlilik yükümlülüğü altına alır
  • Alt işleyen olarak yalnızca işbu Sözleşme'de ve §6.3'teki güncel alt işleyen listesinde belirtilen hizmet sağlayıcıları kullanır (bkz. §4.2, §6.3). Yeni bir alt işleyenin kişisel verilere erişimini gerektiren kullanımı, §6.3'teki önceden bildirim ve itiraz mekanizmasına tabidir
  • Çalışanların KVKK Madde 11 kapsamındaki taleplerinin karşılanmasında Müşteri'ye destek olur (bkz. §7.3)
  • Bir güvenlik ihlalinden haberdar olduğunda Müşteri'yi gecikmeksizin ve her hâlükârda 24 saat içinde bilgilendirir (bkz. §9.3)
  • Sözleşme sona erdiğinde, Müşteri'nin talebi doğrultusunda verileri iade eder veya siler (bkz. §4.3, §13)
  • Müşteri'nin makul talebi üzerine, işbu Sözleşme'deki veri işleme taahhütlerine uygunluğunu gösteren bilgi ve belgeleri paylaşır
7.1 İşlenen Veri Kategorileri
KategoriÖrnek VerilerAmaçHukuki Dayanak
KimlikAd, soyadHesap yönetimiKVKK Md. 5/2-c — Sözleşmenin ifası
İletişimE-postaBildirimlerKVKK Md. 5/2-c — Sözleşmenin ifası
Sağlık / fizyolojik göstergeEAR, PERCLOS, yorgunluk skoruİSG risk analiziKVKK Md. 6/3 — somut olaya uygulanabilir şart (bkz. §8.1); 6331 Md. 15 tek başına dayanak oluşturmaz
DavranışsalReaksiyon süresi, kırpma hızıİSG risk analiziKVKK Md. 5/2-f — meşru menfaat (Müşteri tarafından menfaat dengesi testi yapılmış olmak kaydıyla); denge testinin karşılanmadığı hâllerde Md. 5/1 uyarınca açık rıza
OrganizasyonDepartman, vardiyaRaporlamaKVKK Md. 5/2-c — Sözleşmenin ifası
İşlemTarama tarihi/saatiDenetim kaydıKVKK Md. 5/2-f — Meşru menfaat
Hekim klinik notuİş yeri hekiminin bir çalışan hakkında yazdığı, bütünlüğü korunan klinik not (bkz. §7.2, §9.4)Sağlık gözetimi kayıt bütünlüğüKVKK Md. 6/3 — somut olaya uygulanabilir şart (bkz. §8.1)
Anket cevabıFirma yönetiminin yayınladığı tek soruluk ankete çalışanın verdiği cevapİSG risk analizi (OwO girdisi, bkz. §7.4), raporlamaKVKK Md. 5/2-f — meşru menfaat (Müşteri tarafından menfaat dengesi testi yapılmış olmak kaydıyla); denge testinin karşılanmadığı hâllerde Md. 5/1 uyarınca açık rıza
Teknik hata bildirimiKullanıcının yazdığı serbest metin + otomatik yakalanan tarayıcı hatası/cihaz bilgisi (bkz. §9.4)Yazılım hatalarının teşhisi ve giderilmesiKVKK Md. 5/2-f — Meşru menfaat
Bildirim/hatırlatmaAnlık bildirim gönderimi için cihaz push token'ı; hekimin belirli bir çalışan için oluşturduğu hatırlatma notu ve zamanıSağlık gözetimi takibi, sistem bildirimleriKVKK Md. 5/2-c — Sözleşmenin ifası / Md. 6/3
📷 Kamera görüntüsü sunucuya gönderilmez. Video stream yalnızca kullanıcının tarayıcısında (RAM'de) işlenir. Sunuculara yalnızca hesaplanmış sayısal değerler (EAR: 0.312, PERCLOS: %6.4 gibi) iletilir.
7.2 Saklama Süreleri
Veri TürüSaklama Süresi
Ölçüm metrikleri ve raporlarİç saklama politikamız kapsamında aktif abonelik + 2 yıl; ilgili mevzuattan doğan yasal saklama süreleri ve veri saklama-imha politikası saklıdır
Hesap ve kimlik bilgileriSözleşme sona ermesinden itibaren 90 gün
İşlem kayıtları (log)6 ay
OwO eğitim örnekleri (kimlik bilgileri ve doğrudan tanımlayıcılar içermeyen sayısal özellik vektörü + etiket; anonimlik değerlendirmesi ayrıca yapılır — bkz. §7.4)180 gün — her eğitim turunda otomatik olarak silinir
Yüz biyometrik şablonu (faceEmbedding — yüz doğrulama için)Aktif abonelik boyunca; çalışan "Verilerimi Sil" talebinde bulunduğunda veya hesabı kapatıldığında derhal ve otomatik olarak silinir
Cihaz-içi öğrenme model ağırlıkları (federated_weights — bkz. §7.4)Aktif abonelik boyunca; çalışan "Verilerimi Sil" talebinde bulunduğunda veya hesabı kapatıldığında silinir. Bu ağırlıklar önceden aynı firmadaki diğer çalışanların modelleriyle toplu (federe) olarak ortalanmış olabilir — bu durumda kişiye özel belgenin silinmesi, katkısının önceki toplu ortalamalardaki matematiksel izinin geriye dönük olarak tamamen kaldırılacağını garanti etmez
Hekim klinik notlarıİş yeri hekimi tarafından oluşturulan sağlık gözetimi kayıtları, ilgili İSG mevzuatında öngörülen saklama süreleri ve KVKK'nın saklama ilkeleri çerçevesinde muhafaza edilir. Çalışma ve Sosyal Güvenlik Bakanlığı İSG Genel Müdürlüğü, kişisel sağlık dosyalarının çalışanın işten ayrılma tarihinden itibaren en az 15 yıl saklanması gerektiğini belirtmektedir. Kayıtlar, bütünlüğü korunacak şekilde tutulur; yazıldıktan sonra geçmişe dönük değiştirilmesi engellenir (bkz. §9.4). Silme talepleri, uygulanabilir yasal saklama yükümlülükleri saklı kalmak kaydıyla değerlendirilir
Uyarı/alarm kayıtları, klinik doğrulama geri bildirimi, muayene takvim kayıtları, başarısız yüz doğrulama güvenlik loguÇalışanın kendi "Verilerimi Sil" talebiyle OTOMATİK silinmez — hekim klinik notlarıyla AYNI gerekçeyle (İSG/güvenlik denetim izi bütünlüğü) bilinçli olarak korunur. Silinmesi gerekiyorsa info@oculawork.com üzerinden admin aracılığıyla talep edilebilir.
Hata bildirimi ve teknik tanı verisiOculaWork admin'i tarafından manuel olarak silinene kadar
Silme talebi sonrasıTalep tarihinden itibaren 30 gün içinde imha (hekim klinik notları hariç — yukarıya bkz.)
💾 Yedekler hakkında: Aktif sistemden silinen veriler, Google Firebase'in kendi otomatik altyapı yedeklerinde bir süre daha kalabilir; bu, Google'ın kendi yedekleme döngüsüne bağlıdır ve OculaWork'ün doğrudan kontrolünde değildir. Yedeklerdeki veri, normal yedek rotasyon süreciyle kendiliğinden silinir; ayrıca kalıcı olarak erişilebilir/işlenebilir durumda tutulmaz.
🗂️ İşlem kayıtları hakkında: Uygulama seviyesinde tutulan işlem kayıtları en az işlem zamanı, işlem türü ve işlemi gerçekleştiren kullanıcı kimliğini içerir; IP adresi/cihaz bilgisi gibi ek teknik veriler yalnızca Google Firebase altyapısının kendi güvenlik loglarında, Google'ın kendi politikaları kapsamında tutulabilir. Bu kayıtlar yalnızca güvenlik izleme ve hata teşhisi amacıyla tutulur; erişimi rol bazlı olarak kısıtlıdır (bkz. §9.4). Kayıtlar, normal işleyişte sonradan değiştirilmeyecek şekilde, yalnızca ekleme (append-only) mantığıyla tutulmaya çalışılır; ancak bu, bağımsız bir delil/adli inceleme sürecine uygun şekilde sertifikalandırılmış bir bütünlük garantisi anlamına gelmez. Sistem kayıtlarında Türkiye Cumhuriyeti saat dilimi (UTC+3) esas alınır.
🩺 Hekim klinik notları hakkında istisna: İş hekiminin bir çalışan hakkında yazdığı kalıcı klinik not (bkz. §7.1, §9.4), sağlık gözetimi kayıt bütünlüğünü korumak amacıyla yazıldıktan sonra hiçbir kullanıcı (çalışan, yönetim, hekimin kendisi veya OculaWork admin'i dahil) tarafından değiştirilemez veya silinemez. Bu, §7.3'te sayılan düzeltme/silme haklarının bu veri kategorisi için sınırlı olduğu anlamına gelir; Müşteri, çalışanlarına sunacağı KVKK aydınlatma metninde bu istisnayı açıkça belirtmekle yükümlüdür.
7.3 İlgili Kişi Hakları (KVKK Md. 11)

Çalışanlar KVKK haklarını kendi işverenleri (Müşteri) aracılığıyla kullanır. OculaWork bu talepleri Müşteri'nin yönlendirmesiyle 30 gün içinde karşılar:

  • Kişisel verilerin işlenip işlenmediğini öğrenme
  • İşlenmişse bilgi talep etme
  • Yanlış verilerin düzeltilmesini isteme
  • Koşullar oluşmuşsa silinmesini talep etme
  • Otomatik sistemler sonucu aleyhte karara itiraz etme
  • Kanuna aykırı işleme nedeniyle zararın giderilmesini talep etme
7.3.1 Otomatik İşleme Noktalarının Somutlaştırılması (KVKK Md. 11/1-g)

Yukarıdaki itiraz hakkının somut şekilde kullanılabilmesi için, Platform'da çalışan hakkında sonuç doğurabilecek otomatik/yarı-otomatik işleme noktaları açıkça belirtilir: (i) günlük tarama sonucu üretilen yorgunluk risk seviyesi (düşük/orta/yüksek/kritik), (ii) CUSUM ve İzolasyon Ormanı (Isolation Forest) tabanlı istatistiksel anomali tespiti uyarıları, (iii) "OwO" sektörel öğrenme modelinin, ilgili taramanın anonim sayısal profiline dayanarak ürettiği ve yalnızca bilgi amaçlı gösterilen sektörel bağlam skoru (owoContextScore, bkz. §7.4) — bu üç işleme noktası da yalnızca iş hekimine gösterilir, hiçbiri tek başına otomatik bir personel kararına dönüşmez. OwO'nun eğitim verisi ve model ağırlıkları kimlik bilgisi içermez; kimlikten ayrıştırılmış ve anonimleştirme amacıyla teknik ve idari tedbirlerden geçirilmiş verilerdir. Bu tedbirlerin uygulanmış olması tek başına söz konusu verinin hukuken anonim olduğu anlamına gelmez; anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır (bkz. §7.4). ancak danışma katmanının bilgi amaçlı ürettiği sektörel bağlam skoru, ilgili taramaya özel, bilgilendirici bir gösterge olarak yukarıdaki (iii) numaralı işleme noktasını oluşturur. Bir çalışan, risk seviyesi, anomali uyarısının veya sektörel bağlam skorunun kendisi hakkında olumsuz bir personel kararına (görev değişikliği, disiplin vb.) tek başına dayanak oluşturduğunu düşünüyorsa, işverenine itiraz edebilir; işveren böyle bir itirazı değerlendirirken kararın bir insan (iş hekimi/İK) tarafından gözden geçirilmesini sağlamakla yükümlüdür.

7.4 Anonim/Agregatif İşleme ve Yapay Zeka Model Eğitimi ("OwO")

KVKK Md. 3/1-d uyarınca kişisel veri, kimliği belirli veya belirlenebilir gerçek kişiye ilişkin her türlü bilgiyi ifade eder. Geri döndürülemez şekilde anonim hâle getirilmiş veri bu tanımın dışında kalır ve KVKK hükümleri bu veriler bakımından uygulanmaz. OculaWork, Müşterilerin (dağıtım moduna göre kapsamı değişir — bkz. madde 5) tarama ve öz-değerlendirme verilerinden, sektör genelinde çalışan istatistiksel bir öğrenme modelini ("OwO") eğitir; bu eğitimde doğrudan kimlik ve şirket tanımlayıcıları içermeyecek şekilde teknik olarak ayrıştırılmış ve minimize edilmiş sayısal özelliklerden yararlanılır.

⚠️ Önemli — "kimlik alanı yok" tek başına "anonim" demek değildir. Yalnızca doğrudan tanımlayıcıların kaldırılmış olması, verinin her durumda KVKK anlamında anonim veri olduğu anlamına gelmez. OculaWork, aşağıda sayılan teknik ve idari tedbirlerle yeniden kimliklendirme riskini azaltmayı hedefler; bir veri setinin anonim sayılıp sayılmayacağı ise somut koşullar ışığında ayrıca değerlendirilir. Anonimleştirme işlemi gerçekleşene kadar geçen süreçteki işlemeler KVKK kapsamındadır.

Bu işleme aşağıdaki teknik ve hukuki güvencelerle sınırlıdır:

  1. Kimlik bilgisi (ad, soyad, e-posta, çalışan kimlik numarası) modele hiçbir surette girdi olarak dahil edilmez veya model çıktısıyla ilişkilendirilmez.
  2. Serbest metin alanları (sağlık öyküsü, ilaç/alerji/hastalık anamnezi) hiçbir zaman okunmaz, işlenmez veya saklanmaz; yalnızca ilgili alanın doldurulup doldurulmadığına dair ikili (var/yok) bir gösterge kullanılır.
  3. Ruh sağlığı ve dikkat/uyanıklık öz-değerlendirme sonuçları (GAD-7, PHQ-9, CBI, WHO-5, Epworth, Karolinska, PSS-4, reaksiyon-süresi tabanlı uyanıklık testi, nefes/sakinleşme egzersizi ve karakter/kişilik testinin öz-bildirilen doğruluk geri bildirimi gibi ölçekler) yalnızca toplam şiddet skoruna veya ikili (evet/hayır) bir doğruluk göstergesine indirgenmiş biçimde işlenir. Bu indirgenmiş sayısal skorlar, kimlik veya firma bilgisi taşımayan, salt sayısal bir vektör olarak OwO'nun eğitim örneklerine ({0-1 arası sayılar} + tek bir 0/1 etiket) dahil edilip §7.2'de belirtilen 180 günlük süreyle saklanabilir; ancak bu ölçeklerin ham/serbest metin yanıtları veya kaynağı olan test kaydı (bkz. §9.4 — yalnızca çalışanın kendisine açık personelCoach kaydı) bu işlemenin hiçbir aşamasında OwO'ya gönderilmez veya OwO tarafında saklanmaz. PHQ-9 ölçeğinin kendine zarar verme riskini sorgulayan maddesi (madde 9) bu işleme kapsamının tamamen dışındadır ve yalnızca çalışana yönelik koşulsuz kriz kaynağı yönlendirmesi amacıyla kullanılır.
  4. İşlemenin nihai çıktısı, binlerce veri noktasının istatistiksel olarak harmanlanmasıyla oluşan sayısal model ağırlıklarından ibarettir; bu çıktıdan geriye doğru belirli bir çalışanın kimliğinin veya verdiği yanıtların tespit edilmesi teknik olarak mümkün değildir.
  5. Dağıtım moduna göre OwO'nun nerede çalıştığı. Bu madde, Müşteri'nin hangi kurulum modelini seçtiğine göre farklı uygulanır:
    • (a) Self-host Firebase kurulumu. Müşteri kendi Firebase projesini kurar. Kimlik bilgisi (e-posta, şifre özeti, rol, firma ataması) OculaWork'ün merkezi Firebase projesinde tutulur ve OwO'nun danışma fonksiyonu bu merkezi projede çalışır. Operasyonel veri (tarama, öz-değerlendirme sonuçları) Müşteri'nin kendi bulut projesinde kalır; işlemeye dahil olması gereken kısım (madde 1-3'te tanımlanan, kimlikten arındırılmış sayısal profil) merkezi projeye yalnızca anlık ve geçici olarak iletilir, kalıcı olarak kimlikle birlikte saklanmaz.
    • (b) Kurumsal kurulum (katmanlı model). Müşteri Platform'u kendi sunucusunda çalıştırır. Rutin değerlendirme — risk seviyesi, eşik sınıflandırması ve anomali tespiti — tamamen Müşteri'nin kendi sunucusunda yapılır ve bunun için OculaWork'e bağlantı gerekmez. Bu işlemede bireysel çalışan verisi OculaWork merkezine iletilmez; madde 1-3'te tanımlanan bireysel sayısal profil de iletilmez.

      Buna karşılık OwO'nun sektörel karşılaştırmaya dayanan psikososyal değerlendirme katmanı OculaWork merkezinde çalışır ve yalnızca toplulaştırılmış girdiyle çağrılır: sektör kodu, çalışan sayısı bandı (tam sayı değil), en az 50 ölçümden türetilmiş dağılımlar ve uygulanan gürültü ölçeği. Bu gönderimde bireysel kayıt, kimlik, departman adı, serbest metin ve tarih damgası bulunmaz; eşik altındaki her hücre gönderimden önce bastırılır (sıfırlanır). Bu kanal da varsayılan olarak kapalıdır. OculaWork merkezine erişilemediğinde bu katman devre dışı kalır; rutin değerlendirme Müşteri'nin sunucusunda kesintisiz çalışmaya devam eder (bkz. EK-0.3.3).

      Model geliştirme katkısı ayrıca ve yine Müşteri'nin açıkça etkinleştirmesi hâlinde (varsayılan kapalı) gönderilebilir; yalnızca EK-0.3C'deki beyaz listede sayılan dört alan (modelSurumu, ornekSayisi, gradyan, gurultuOlcegi) taşınır, en az 50 ölçümden türetilmedikçe, gizlilik artırıcı gürültü uygulanmadıkça ve katkı büyüklüğü sınırlandırılmadıkça oluşturulmaz. Beyaz liste dışındaki her alan sunucu tarafında reddedilir. Kimlik bilgisi bu modelde de Müşteri'nin kendi altyapısında kalır. Bu tekniklerin uygulanmış olması, merkeze ulaşan verinin hukuken anonim olduğu anlamına gelmez; anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır.
    Her iki modelde de madde 1-4 ve 6-13'teki güvenceler aynen geçerlidir. Kurumsal kurulumda gizlilik artırıcı tekniklerin uygulanmış olması, merkeze ulaşan katkının hukuken anonim olduğu anlamına gelmez (bkz. EK-0.3C); anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır.
  6. Yönetim, işveren ve OculaWork personeli dahil hiçbir insan kullanıcı, işleme konusu ham veriye (madde 2 ve 3'te belirtilen serbest metin ve ham test yanıtları) erişemez; erişim yalnızca otomatikleştirilmiş işleme fonksiyonuna aittir ve anlık, geçicidir.
  7. OwO modelinin çıktısı, madde 4 ve 7'de belirtildiği gibi yalnızca tek bir sektörel model ağırlıkları kümesidir — sektör, firma büyüklüğü veya başka bir kırılıma göre ayrıştırılmış, geri okunabilir bir alt-istatistik üretilmez. Bu, ayrı bir k-anonimlik eşiği olmasa dahi, tek bir küçük firmanın veya çalışan grubunun sonuçtan tekilleştirilmesini (singling-out) yapısal olarak zorlaştırır; buna karşın büyük ölçekli, otomatik ve özel nitelikli veri içeren bu işleme türü için bir Kişisel Verileri Koruma Etki Değerlendirmesi'nin (DPIA benzeri) yürütülmesi iyi uygulama olarak önerilir. Bu değerlendirme henüz resmi olarak tamamlanmamıştır; talep eden Müşteriler için hazırlık süreci başlatılabilir.
  8. OwO'nun ürettiği sektörel bağlam skoru, herhangi bir tarama sonucunun yanında yalnızca bilgi amaçlı, ek bir gösterge olarak sunulabilir; bu skor mevcut kural tabanlı risk seviyesinin (bkz. §7.3.1) yerine geçmez veya onu değiştirmez. OwO'nun eğitimine, akademik ölçekler veya bilinen tıbbi/fizyolojik yorgunluk faktörleri gibi harici, kaynağı belgelenmiş bilgiler de OculaWork tarafından sınırlı ve düşük ağırlıklı bir kalibrasyon olarak eklenebilir; bu harici bilgiler de kimliksizdir ve genel/istatistiksel niteliktedir, belirli bir çalışana veya olaya özgü değildir.
  9. Firma İçi Anket Sinyali: Müşteri yönetiminin yayınladığı, tek soruluk/iki seçenekli anketlerde çalışanın verdiği cevap, yönetimin önceden hangi cevabın "olumlu" sayılacağını belirlemesiyle ikili (0/1) bir sinyale dönüştürülüp OwO'nun eğitim vektörüne dahil edilebilir. Anketin kendisi ve çalışanın cevabı kimlikli olarak Müşteri'nin yönetim panelinde görülebilir kalır (bkz. §9.4); OwO'ya yalnızca bu 0/1 sinyal, madde 1-3'teki aynı kimliksizleştirme kurallarına tabi olarak iletilir.
  10. Hekimin Klinik Doğrulama Geri Bildirimi: İş hekimi, bir taramanın algoritmik risk seviyesini "isabetli / olması gerekenden yüksek / olması gerekenden düşük / sevk gerekli / izlemde" şeklinde değerlendirebilir. Bu değerlendirme, tıpkı madde 3'teki gibi, o taramanın kimlikten arındırılmış sayısal profiliyle birlikte OwO'nun eğitim örneklerine düzeltilmiş bir etiket olarak dahil edilebilir — bu, madde 1'deki "kimlik bilgisi modele hiçbir surette girdi olarak dahil edilmez" güvencesini değiştirmez; hekimin değerlendirmesi yalnızca o taramanın SONUÇ etiketini (yüksek riskli mi/değil mi) düzeltir, kimlik bilgisi OwO'ya yine hiçbir zaman gönderilmez. Hekimin bu değerlendirmesinin kendisi (hangi taramaya, dolayısıyla hangi çalışana ait olduğu) Müşteri'nin kendi kiracısında ayrıca, kimlikli olarak saklanır (bkz. §7.1, §9.4) — anonimleştirilen yalnızca OwO'ya giden türetilmiş sinyaldir.
  11. Karakter-Görev Uyum Endeksi: Müşteri'nin yönetim paneli, çalışanların bireysel Karakter Analizi sonuçlarına (bu veri yalnızca çalışanın kendisine açıktır, bkz. §9.4) hiçbir zaman erişemez. Bunun yerine, en az 10 çalışan Karakter Analizi'ni tamamladığında, yalnızca toplulaştırılmış tek bir yüzde (akademik olarak doğrulanmış, güvenlik davranışı/yorgunluk direnciyle ilişkili kişilik özellikleri gösteren çalışan oranı) ve bir istatistiksel güven değeri gösterilir; bu eşiğin altında istatistik tamamen gizlenir. Hiçbir bireysel sonuç, isim veya kimlik bu istatistiğin hiçbir aşamasında görünür veya geri hesaplanabilir değildir.
  12. Geri Bildirim Döngüsü: OwO'nun ürettiği bilgilerin (sektörel bağlam, ilaç sedasyon eşleşmesi, Karakter-Görev Uyum Endeksi) yanında, o bilgiyi gören kullanıcı (doktor/yönetim) isteğe bağlı olarak "faydalı mıydı" şeklinde bir geri bildirim (👍/👎) verebilir. Bu geri bildirim kimlikle hiçbir zaman ilişkilendirilmez — yalnızca bilgi türü (ör. "sektörel bağlam") ve faydalı olup olmadığı kaydedilir; hangi tarama/çalışan/kullanıcıya ait olduğu tutulmaz. Biriken geri bildirim oranı, OwO'nun o bilgi türü için gösterdiği güven yüzdesini besler; bu veri hiç kimse (admin dahil) tarafından okunamaz, yalnızca toplulaştırılmış oranı sunucu tarafında hesaplanır.
  13. Ortak Bilgi Havuzu: OwO'nun danışma katmanı (owoConsult), ilaç danışması (owoDrugCheck) ve Karakter-Görev Uyum Endeksi (getCharacterFitStats), aynı dış bilgi kaynakları havuzunu (owoExternalFactors) paylaşır. Bu sayede, bu havuya eklenen yeni ve gerçekten ilgili bir faktör, ek bir yazılım değişikliği yapılmaksızın, ilgili olduğu tüm noktalarda otomatik olarak (yalnızca toplulaştırılmış, kimliksiz bir gösterge olarak) katkı sağlayabilir. Bu otomatik katkı her zaman düşük ağırlıklı ve sınırlıdır; hiçbir noktada tek başına nihai bir sonuç oluşturmaz veya mevcut kural tabanlı/akademik eşiğe dayalı hesaplamaların yerini almaz.
  14. Cihaz-İçi Öğrenme Model Ağırlıkları (federated_weights) — OwO'DAN AYRI BİR MEKANİZMA: Yukarıdaki madde 1-10'da anlatılan OwO eğitim hattından bağımsız olarak, çalışanın kendi cihazında (tarayıcısında) çalışan, kişisel bir risk-tahmin modeli de bulunur. Bu modelin ağırlıkları, tekil bir belge olarak (belge kimliği ilgili çalışanın kullanıcı numarasıdır — bu bakımdan OwO'nun aksine kimlikten arındırılmamıştır) firmanın kendi veri katmanında saklanır ve yalnızca aynı firmadaki diğer çalışanların modelleriyle istatistiksel olarak ortalanarak (federe öğrenme) o firmanın çalışanları arasında paylaşılır; farklı bir firmaya asla aktarılmaz. Bu ağırlıklar tek başlarına yorumlanabilir/okunabilir bir "duygu" veya "kişilik" profili teşkil etmez — yalnızca sayısal bir model parametre kümesidir — ancak kimliğe bağlı olması nedeniyle §7.2'deki saklama/silme kurallarına tabidir ve çalışanın "Verilerimi Sil" talebiyle silinir. Bir çalışanın katkısı silinmeden önce diğer çalışanların modelleriyle zaten harmanlanmışsa, bu harmanlamanın matematiksel izinin geriye dönük olarak tam temizlenmesi teknik olarak garanti edilemez; bu durum madde 4'teki "geri okunamazlık" güvencesinin OwO hattına özgü olduğunu, bu ayrı mekanizmayı kapsamadığını netleştirmek için burada açıkça belirtilir.
OwO Şeffaflık: Bu işlemenin tam teknik detayı — hangi veri kaynağının hangi sinyale indirgendiği dahil — OculaWork Teknik Metodoloji Belgesi'nde ("OwO Eğitim Modeli" başlıklı bölüm) ayrıntılı olarak belgelenmiştir ve talep üzerine Müşteri'ye ve ilgili kişilere sunulur.
⚖️ Müşterinin Sorumluluğu: Müşteri, işbu Sözleşme'yi kabul ederek, çalışanlarına sunacağı KVKK aydınlatma metnine bu anonim/agregatif işleme ve model eğitimi amacını dahil etmeyi kabul eder. OculaWork bu bildirimin Müşteri tarafından yapıldığını Müşteri'nin beyanına dayanarak kabul eder; aksi durumdan kaynaklanan yasal sonuçlar münhasıran Müşteri'ye aittir.

KVKK mevzuatı ve Kurul içtihadı zaman içinde değişebilir. Mevzuat değişikliği hâlinde taraflar, işbu Sözleşme'yi ve ilgili uygulamaları güncel mevzuata uyumlu hâle getirmek için makul süre içinde gerekli iş birliğini gösterir.

7.5 Tarafların Veri Koruma Sıfatları

Çalışanların Platform üzerinden gerçekleştirilen ölçüm faaliyetleri bakımından, işleme amaçlarını ve temel işleme vasıtalarını Müşteri belirlediği ölçüde Müşteri veri sorumlusu, OculaWork ise Müşteri adına hareket eden veri işleyen sıfatındadır.

OculaWork'ün kendi amaçları doğrultusunda gerçekleştirdiği ayrı veri işleme faaliyetleri (kendi müşteri hesap ve abonelik kayıtları, faturalama, destek, kendi pazarlama iletişimi, kendi güvenlik kayıtları gibi) bakımından ise ilgili faaliyet özelinde veri sorumlusu veya veri işleyen sıfatı ayrıca belirlenir.

Tarafların sıfatı, yalnızca sözleşmede kullanılan unvana göre değil, somut işleme faaliyetinin fiili niteliğine ve amaç ile vasıtaları kimin belirlediğine göre değerlendirilir.

🏢 Kurumsal (self-host) kurulumda: Verinin Müşteri'nin kendi altyapısında bulunması, tek başına OculaWork'ün KVKK kapsamı dışında kaldığı anlamına gelmez. Müşterinin kendi altyapısındaki veriler üzerindeki erişim, yetkilendirme, yedekleme, güvenlik ve sistem yönetimi sorumluluklarının hangi tarafa ait olduğu Kurumsal Kurulum/Sipariş Formu'nda ayrıca belirlenir (bkz. EK-0).
7.5.1 Faaliyet Bazlı Rol Tablosu

Sıfat, faaliyetin amaç ve vasıtalarını kimin belirlediğine göre değişir. Aşağıdaki tablo bağlayıcı bir özet değil, yorum kılavuzudur; somut olayda fiilî durum esastır.

FaaliyetAmaçRol
Çalışan ölçümü ve raporlamasıİSG süreçlerine destekMüşteri veri sorumlusu · OculaWork veri işleyen
Müşteri hesabı ve abonelik yönetimiHizmetin sunulmasıOculaWork veri sorumlusu
Faturalama ve muhasebeYasal yükümlülükOculaWork veri sorumlusu
Destek talebi yönetimiHizmetin sunulmasıTalebin içeriğine göre ayrıca belirlenir
Güvenlik ve denetim kayıtlarıSistem güvenliğiOculaWork veri sorumlusu
Model geliştirme katkısıSektörel modelAyrı hukuki değerlendirme (bkz. §7.4, EK-0.3C)
08 Özel Nitelikli Veriler — Sağlık ve Biyometrik

EAR, PERCLOS ve yorgunluk skoru; işlemenin niteliğine göre KVKK Madde 6 kapsamında özel nitelikli kişisel veri kapsamında değerlendirilebilecek verilerdir ve bu hâlde ek koruma gerektirir.

8.1 Hukuki Dayanak

Özel nitelikli kişisel verilerin işlenmesi, KVKK m.6/3'te düzenlenen şartlardan somut olaya uygulanabilir olanına dayanır. Açık rıza, bu şartlardan yalnızca biridir; iş ilişkisindeki yapısal güç dengesi ile işlemenin gereklilik ve ölçülülük koşulları ayrıca değerlendirilir.

  1. Açık rıza (KVKK m.6/3): Çalışandan yazılı veya elektronik ortamda alınan, geri alınabilir, özgür iradeye dayalı rıza. Açık rıza, her veri işleme faaliyetinin otomatik ve genel hukuki dayanağı değildir.
  2. İstihdam ve İSG yükümlülüğü (KVKK m.6/3-f): İstihdam, iş sağlığı ve güvenliği alanlarındaki hukuki yükümlülüklerin yerine getirilmesi için zorunlu olması şartına bağlıdır.
⚖️ 6331 sayılı Kanun m.15 hakkında: Bu hüküm işverene çalışanların sağlık gözetimine ilişkin yükümlülükler öngörür; ancak OculaWork'ün kullandığı kamera tabanlı ölçüm yöntemini herhangi bir işyerinde zorunlu kılan bir hüküm olarak yorumlanamaz. Bu nedenle 6331 m.15'in varlığı, Platform'un kullanımının kendiliğinden KVKK m.6/3-f kapsamında "zorunlu" sayılacağı anlamına gelmez. Uygulanabilir hukuki sebep; Müşterinin somut işleme amacı, ilgili mevzuat ve işlemenin gereklilik/ölçülülük koşulları dikkate alınarak Müşteri tarafından belirlenir.
⚖️ Müşterinin Sorumluluğu: Hangi hukuki dayanağın seçildiğine bağımsız olarak, Müşteri çalışanlarını aydınlatmak ve gerekiyorsa açık rıza almakla sorumludur. OculaWork bu süreçlerin gerçekleştirildiğini Müşteri'nin beyanına dayanarak kabul eder. Aksi durumdan kaynaklanan yasal sonuçlar münhasıran Müşteri'ye aittir.
8.2 Yüz Biyometrisi ile Kimlik Doğrulama — Ek Uyarı

Platform'un giriş/kimlik doğrulama amacıyla kullanabildiği yüz biyometrisi (face-embedding) özelliği, yorgunluk taraması metriklerinden (EAR/PERCLOS gibi) ayrı bir risk kategorisi oluşturur: bu veri doğrudan kimlik doğrulama amacıyla, işveren tarafından zorunlu tutulan bir biyometrik veri işlemedir. Kişisel Verileri Koruma Kurulu, 04.08.2022 tarih ve 2022/797 sayılı Kararı'nda işyerine giriş-çıkışlarda yüz tanıma sistemiyle biyometrik veri işlenmesini, Kanun'un 6. maddesi kapsamında herhangi bir işleme şartına dayanılmaksızın gerçekleştirildiği gerekçesiyle hukuka aykırı bulmuş; 29.04.2026 tarih ve 2026/921 sayılı İlke Kararı'nda ise mesai takibi amaçlı biyometrik veri işlemenin, çalışanın açık rızası bulunsa dahi hukuka aykırı olduğuna hükmetmiştir — gerekçe olarak işçi-işveren ilişkisindeki yapısal güç dengesizliğinin açık rızanın "özgür irade" unsurunu zedelediği belirtilmiştir. Anılan ilke kararı mesai takibi amaçlı biyometrik tanımlamaya ilişkindir ve Platform'un yorgunluk ölçümüne birebir uygulanmaz; bununla birlikte, çalışan rızasının her durumda otomatik bir güvenli liman oluşturmadığını gösteren güncel bir Kurul yaklaşımıdır. Bu doğrultuda yalnızca açık rızaya dayanmak, biyometrik veri işlemeyi tek başına hukuka uygun kılmayabilir. Müşteri, bu özelliği etkinleştirmeden önce (i) ölçülülük, gereklilik ve veri minimizasyonu ilkelerine uygunluğunu, (ii) şifreli kart/PIN, RFID/NFC kimlik kartı veya cihaz eşleştirme gibi daha az müdahaleci bir alternatifin yeterli olup olmadığını değerlendirmeli ve (iii) kendi hukuki danışmanına başvurmalıdır. OculaWork bu değerlendirmeyi Müşteri adına yapmaz ve bu konudaki hukuki riski üstlenmez.

09 Veri Güvenliği
9.1 Teknik Tedbirler
  • TLS 1.3 ile şifreli veri iletimi — HTTP üzerinden erişim engellenir
  • Firebase Firestore güvenlik kuralları ile rol bazlı erişim kontrolü (RBAC)
  • Kamera görüntüsü client-side işlenmekte; sunucuya ham görüntü iletilmemektedir
  • Firebase Authentication ile oturum yönetimi; token süresi 1 saat
  • Yönetim paneli: bireysel sonuçlar gösterilmez; yalnızca §11’deki eşikleri geçmiş, departman bazında toplulaştırılmış istatistik gösterilir
  • OculaWork admin paneline erişim, parola ve ayrıca bir güvenlik sorusu cevabından oluşan iki adımlı doğrulama ile korunur; güvenlik sorusu düzenli aralıklarla yenilenir
9.2 Altyapı Güvenlik Sertifikaları (Google Firebase)
  • ISO/IEC 27001 Bilgi Güvenliği Yönetim Sistemi
  • SOC 2 Type II
  • Veri merkezleri, Google'ın kendi güvenlik ve veri işleme şartlarına tabidir; OculaWork, Google'ın hukuki uyumluluğu konusunda ayrıca bir garanti vermez
ℹ️ Açıklık: Yukarıdaki sertifikalar (ISO/IEC 27001, SOC 2 Type II) Google Firebase altyapısına aittir. OculaWork'ün kendisi şu an için ISO/IEC 27001 veya benzeri bir bilgi güvenliği yönetim sistemi sertifikasına sahip değildir.
9.3 İhlal Bildirimi

OculaWork, kişisel verilerin güvenliğini etkileyebilecek bir olaydan haberdar olması hâlinde Müşteri'yi gecikmeksizin ve her hâlükârda 24 saat içinde yazılı olarak bilgilendirir. Bu sözleşmesel bildirim süresi, tarafların KVKK ve diğer uygulanabilir mevzuat kapsamındaki yasal bildirim sürelerini (KVKK Md. 12/5 uyarınca veri sorumlusunun Kurul'a bildirim yükümlülüğü dâhil) değiştirmez. Müşteri de, kendi tarafında (kendi hesapları, ağı veya sistemleri üzerinden) meydana gelen ve Platform verilerini etkileyebilecek bir güvenlik ihlalini fark ettiğinde, bunu gecikmeksizin OculaWork'e bildirmekle yükümlüdür.

9.4 Rol Bazlı Erişim Tablosu
RolErişebildiği VeriErişemediği Veri
ÇalışanYalnızca kendi tarama sonuçları, kendi YZ Yaşam Koçu içeriği, kendi periyodik öz-tarama kaydı, kendi anket cevabıBaşka hiçbir çalışanın verisi; hekimin kendisi hakkında yazdığı klinik notlar; gönderdiği hata bildirimi ve teknik tanı verisi (yalnızca gönderim anında görünür, sonrasında yalnızca OculaWork admin'ine açıktır)
Yönetim / İKDepartman bazlı anonim/toplulaştırılmış istatistikler (min. 5 kişilik gruplar), personel/muayene yönetimi, bireysel anket cevapları, Karakter-Görev Uyum Endeksi (yalnızca en az 10 çalışan Karakter Analizi'ni tamamladığında görünen, tek bir yüzde ve güven değerinden oluşan toplulaştırılmış istatistik — bkz. §7.4)Bireysel tarama detayları, YZ Yaşam Koçu içeriği (GAD-7/PHQ-9/CBI, Karakter Analizi bireysel sonucu dahil), periyodik öz-tarama anamnezi, hata bildirimi/teknik tanı verisi
İş HekimiKendi kiracısındaki bireysel sağlık gözetimi/tarama verisi, TİTCK ilaç eşleştirme, periyodik öz-tarama anamnezi, resmi muayene kayıtları (exam_records), kendi yazdığı kalıcı klinik notlar (bkz. §7.1, §7.2 — İSG mevzuatındaki saklama süreleri çerçevesinde; bütünlüğü korunur, geçmişe dönük değiştirilemez), taramalara verdiği klinik doğruluk geri bildirimiÇalışanın YZ Yaşam Koçu içeriği (GAD-7/PHQ-9/CBI, Sakinleş, Karakter) — bu veri hekime de kapalıdır; hata bildirimi/teknik tanı verisi
OculaWork AdminFirma/abonelik yönetimi, anonim Veri Havuzu istatistikleri, Modül Kullanım Panosu (yalnızca sayı), OwO eğitim geçmişi (yalnızca ağırlık/skor), tüm kullanıcılardan gelen hata bildirimleri ve otomatik yakalanan teknik tanı verisi (bkz. §7.1) — bu veri, çalışanın kendi işvereniyle (yönetim/hekim) hiçbir zaman paylaşılmazHiçbir çalışanın bireysel verisi, YZ Yaşam Koçu içeriği, anamnez serbest metni, hekim klinik notlarının içeriği — bkz. §7.4
9.5 Denetim Hakkı (Audit Right)

Müşteri, KVKK kapsamındaki Veri Sorumlusu yükümlülüklerini yerine getirebilmek amacıyla, OculaWork'ün veri işleme süreçlerine ilişkin bilgi ve belge talep etme hakkına sahiptir. OculaWork, kendi ticari sırlarını ve diğer Müşterilere ait bilgileri ifşa etmeyecek şekilde, makul sıklıkta ve en az 15 gün önceden yazılı bildirim yapılması kaydıyla bu talebi karşılar. Yerinde (on-site) denetim veya bağımsız üçüncü taraf denetimi, ancak tarafların önceden yazılı olarak mutabık kaldığı kapsam, süre ve gizlilik şartları çerçevesinde mümkündür; denetim masrafları aksi kararlaştırılmadıkça talep eden Müşteri'ye aittir.

9.6 Güvenlik Açığı Bildirimi (Responsible Disclosure)

Platform'da bir güvenlik açığı tespit eden kişiler, bu durumu yalnızca info@oculawork.com adresine, sorumlu açıklama (Responsible Disclosure) ilkeleri kapsamında bildirebilir. Önceden OculaWork'ün yazılı izni alınmaksızın gerçekleştirilen aktif sızma testi, yük testi, fuzzing veya benzeri faaliyetler bu kapsamda değerlendirilmez ve §11.1'de tanımlanan Yasaklı Kullanımlar hükmüne tabidir.

10 Sorumluluk Sınırlaması ve Feragatler
10.1 Tıbbi Karar Sorumluluğu
⚕️ Platform çıktıları hiçbir koşulda tıbbi teşhis veya klinik karar yerine geçmez. Platforma dayanılarak alınan iş kısıtlaması, görev değişikliği veya disiplin kararlarından OculaWork sorumlu tutulamaz.
10.2 Genel Sorumluluk Sınırı

OculaWork'ün herhangi bir nedenle tazminat yükümlülüğüne girmesi hâlinde toplam sorumluluğu, ihlalin gerçekleştiği tarihten önceki son 12 aylık abonelik bedeliyle sınırlıdır. Bu sınırlama; kasıt, ağır ihmal, fikri mülkiyet ihlali veya gizlilik/veri güvenliği yükümlülüklerinin ihlali hâllerinde uygulanmaz.

10.3 Sorumluluk Dışı Haller
  • Müşterinin KVKK yükümlülüklerini yerine getirmemesinden kaynaklanan para cezası ve tazminatlar
  • Çalışanın açık rızasının alınmamasından kaynaklanan idari ve hukuki yaptırımlar
  • Platform verilerinin tek başına dayanak gösterilerek alınan personel kararlarının hukuki sonuçları
  • Müşterinin kullanıcı adı/şifresini yetkisiz kişilerle paylaşmasından kaynaklanan veri sızıntıları
  • Mücbir sebep (doğal afet, savaş, hükümet kararı, siber saldırı, elektrik kesintisi, internet omurga (backbone) arızaları, internet servis sağlayıcısı/DNS/DNSSEC/CDN kesintisi, kök sertifika (root certificate) sorunları, küresel internet kesintisi, bulut altyapı sağlayıcısı kesintisi, Apple/Google/Microsoft gibi platform sağlayıcılarının tarayıcı veya kamera API politikalarında yaptığı beklenmedik değişiklikler, veya üçüncü taraf yapay zeka servis sağlayıcılarının kesintisi)
  • Dolaylı, öngörülemeyen veya cezai nitelikteki zararlar; bu kapsama özellikle gelir kaybı, kâr kaybı, itibar kaybı, iş kaybı ve Müşteri'nin kendi yedekleme yükümlülüğünden, kendi altyapısından veya üçüncü taraf altyapıdan kaynaklanan veri kaybı dahildir — bu kalemler için tazminat ödenmez. OculaWork'ün kendi kusurundan veya §10.2'de sayılan istisnalardan (veri güvenliği ihlali dâhil) kaynaklanan zararlar bu hükmün kapsamı dışındadır. (§10.2'de belirtilen kasıt/ağır ihmal/fikri mülkiyet/gizlilik istisnaları hariç)
  • Google Firebase / Google Cloud altyapısından kaynaklanan kesinti veya veri kayıpları

Taraflar, mücbir sebep süresince ve mücbir sebebin doğrudan etkilediği ölçüde, işbu Sözleşme'den doğan yükümlülüklerini yerine getirememekten sorumlu tutulamaz.

10.4 Çalışan Hakları Davalarında Sorumluluk

Herhangi bir çalışanın işverenine (Müşteri'ye) karşı Platform verileriyle ilgili dava açması durumunda OculaWork bu davada taraf değildir. Müşteri, OculaWork'ü bu tür davalardan muaf tutmayı ve olası masrafları karşılamayı kabul eder.

10.5 Hesap Güvenliği

Kullanıcı, kendi hesabından yapılan tüm işlemlerden bizzat sorumludur. Şifrenin üçüncü kişilerle paylaşılması hâlinde bundan doğan tüm sonuçlar (veri erişimi, yetkisiz işlem, veri sızıntısı dahil) paylaşımı yapan kullanıcıya ve/veya Müşteri'ye aittir; OculaWork bu durumdan sorumlu tutulamaz. Kullanıcı hesapları kişiye özeldir; hesabın birden fazla kişi tarafından ortak kullanılması lisans ihlali sayılır ve OculaWork bu durumda ilgili hesabı askıya alma hakkını saklı tutar.

10.6 Sigorta

OculaWork, işbu Sözleşme kapsamındaki hizmetler için herhangi bir mesleki sorumluluk sigortası (E&O) veya başka bir sigorta taahhüdünde bulunmaz.

10.7 Garanti Reddi (No Warranty)

Platform, işbu Sözleşme'de açıkça belirtilenler dışında "olduğu gibi" (as-is) ve "mevcut haliyle" (as-available) sunulmaktadır. OculaWork; Platform'un kesintisiz, hatasız veya güvenlik açığından tamamen arınmış çalışacağına, belirli bir amaca uygunluğuna, satılabilirliğine veya Müşteri'nin beklentilerini karşılayacağına dair açık ya da zımni herhangi bir garanti vermez.

10.8 Firebase / Bulut Altyapısı Kullanım Bedelleri
☁️ Platform, Google Firebase/Google Cloud altyapısı üzerinde çalışır. Google, her Firebase projesi için sınırlı bir ücretsiz kullanım kotası (free tier) sunar; bu kotanın üzerindeki okuma/yazma/depolama/bant genişliği kullanımı Google tarafından ayrıca faturalandırılır. Müşteri'nin kendi Firebase/Google Cloud projesini kurduğu (self-hosted) kurulumlarda, ücretsiz kotayı aşan TÜM Google faturalandırması doğrudan Müşteri'nin kendi Google Cloud faturalandırma hesabına yansır ve münhasıran Müşteri'nin sorumluluğundadır. OculaWork bu faturalandırmayı ne tahsil eder ne de karşılar; Müşteri'nin kullanım hacmi, kullanıcı sayısı, tarama sıklığı veya panel kullanım yoğunluğu nedeniyle oluşabilecek herhangi bir Google Cloud faturası için OculaWork'ün hiçbir mali sorumluluğu ve tazminat yükümlülüğü yoktur. Müşteri, kendi Google Cloud Console hesabında bütçe uyarısı (budget alert) kurmaktan ve kullanımını izlemekten kendisi sorumludur. Bu madde, paylaşılan (shared) OculaWork altyapısını kullanan Müşteriler için de kıyasen uygulanır: OculaWork, makul/normal kullanım için altyapı maliyetini üstlenir; ancak anormal, kötüye kullanım niteliğinde veya sözleşmede belirtilen kota/kullanıcı sayısını sistematik olarak aşan kullanımdan doğan ek maliyetler Müşteri'ye yansıtılabilir.
10.10 Tahliye Tatbikatı Modülü — Kat Planı, Mekânsal Denetim ve Skorlar

Tahliye Tatbikatı modülü; Müşteri'nin kendi çizdiği kat planı üzerinde mekânsal denetim bulguları, gereksinim listesi, senaryo üretimi ve tatbikat kayıtları oluşturan bir karar destek aracıdır. Modülün ürettiği hiçbir çıktı — bulgu, gereksinim, İSG Uyum Skoru, Risk Skoru veya tatbikat raporu dâhil — uygunluk belgesi, yangın güvenliği projesi, kaçış planı onayı veya resmî bir denetim raporu niteliği taşımaz ve yetkili idarelere karşı tek başına hukuki dayanak oluşturmaz.

Girdi sorumluluğu Müşteri'dedir. Kat sınırı, oda ölçüleri, kapı temiz genişlikleri, kat kişi sayısı, tesis türü ve ekipman konumları Müşteri tarafından girilir; OculaWork bu bilgilerin gerçek yapıyla uyumunu doğrulamaz ve doğrulayamaz. Çıktılar, girilen verinin doğruluğu ölçüsünde geçerlidir. Yanlış ya da eksik girilen bir ölçüden kaynaklanan sonuçlardan OculaWork sorumlu tutulamaz.

Ölçüm ile mevzuat sınırı ayrıdır. Sistem, plandan hesapladığı ölçümleri her hâlükârda gösterir; buna karşılık bir mevzuat maddesindeki sayısal sınırı yalnızca kaynağı doğrulanabildiği durumlarda belirtir. Kaynağı doğrulanamayan kalemlerde sınır yazılmaz, ölçüm verilir ve Müşteri'den teyit istenir; bu kalemler skor hesabına da dâhil edilmez. Tehlike sınıfı, yapı kullanım sınıfı, yağmurlama (sprinkler) varlığı, bina yüksekliği ve yapı ruhsatı gibi belirleyici unsurlar sistem tarafından bilinmez; bu unsurlar sonucu değiştirebilir.

İSG Uyum Skoru ve Risk Skoru tahminî göstergelerdir. Yalnızca sistemin denetleyebildiği kalemleri kapsar, ağırlıklandırma yöntemi OculaWork'ün açıkça ilan ettiği bir tasarım tercihidir ve mevzuattan kaynaklanmaz. Yüksek bir uyum skoru mevzuata uygunluk anlamına gelmez; düşük bir risk skoru güvenli bir işyeri anlamına gelmez. Nihai uygunluk değerlendirmesi münhasıran işverene ve görevlendirdiği iş güvenliği uzmanı / işyeri hekimine aittir.

Tatbikat kayıtları ve katılım defteri. Tatbikat sırasında toplanan davranış kayıtları (çizilen rota, süre, verim, soru cevapları) kimlik içermez ve yalnızca küme düzeyinde raporlanır; birey performansı ölçmek için kullanılamaz. Katılım defteri ise idari amaçla kimlik içerir ve davranış kayıtlarıyla birleştirilmez. Modülün ürettiği katılım kaydı, 6331 sayılı Kanun md.11 ve Acil Durumlar Yönetmeliği kapsamındaki tatbikat yükümlülüğünün yerine getirildiğine dair tek başına ispat teşkil etmez; resmî tatbikat tutanağı, tatbikatın fiilen sahada yapılmasına ve işveren tarafından usulüne uygun kayda bağlıdır.

Modül tarafından üretilen senaryolar (yangın, gaz kaçağı, kimyasal sızıntı vb.) eğitim ve farkındalık amaçlı kurgulardır; gerçek bir olayın nasıl gelişeceğine dair mühendislik öngörüsü, yangın modellemesi veya duman yayılım simülasyonu niteliği taşımaz.

Uyum ve risk skorlarının anonim aktarımı. Kat planı kaydedildiğinde, o plandan hesaplanan İSG Uyum Skoru ve Risk Skoru ile plana ilişkin türetilmiş ölçüler (alan, oda/kapı/ekipman sayıları, denetim bulgusu kodları) OculaWork sunucusuna aktarılır ve sektörel karşılaştırma amacıyla kullanılır. Bu aktarımda hiçbir gerçek kişiye ait veri bulunmaz; kimlik, ad, kullanıcı kimliği ve departman bilgisi gönderilmez. Veri bir kişiye değil, bir kat planına ilişkindir ve bu nedenle 6698 sayılı Kanun anlamında kişisel veri niteliği taşımaz.

Plan adı gönderilmez. Kat planına verdiğiniz ad serbest metindir ve işyeri, bina veya kat adı içerebilir; bu ad sunucuya ne olduğu gibi ne de özeti (hash) alınarak iletilir. Aynı planın kayıtlarının zaman içinde birbiriyle ilişkilendirilebilmesi için, içeriği olmayan rastgele bir kimlik yalnızca sizin tarayıcınızda üretilir ve saklanır; bu kimliğin plan adıyla bağı cihazınızdan dışarı çıkmaz. Aynı ada sahip bir plan başka bir cihazda farklı bir kimlik alır.

Aktarılan veriler işyerinize ait ticari bilgi niteliğindedir. Sektörel karşılaştırmalarda tekil bir işyerinin verisinin geri hesaplanmasını önlemek üzere k-anonimlik eşiği uygulanır; eşiğin altındaki gruplarda karşılaştırma gösterilmez. Modül bağımsız da çalışabilir: bu durumda hiçbir veri aktarılmaz ve tüm kayıtlar yalnızca cihazınızda kalır. Aktarım, geçmişe dönük değildir — yalnızca aktarımın etkin olduğu dönemde yapılan kayıtlar gönderilir.

10.11 Tatbikat Katılım Defteri — Aydınlatma ve Saklama

Bu madde, Tahliye Tatbikatı modülünün katılım defteri için geçerlidir. Katılım defteri, modülün kimlik içeren tek kaydıdır; tatbikat sırasında toplanan davranış kayıtları (rota, süre, verim, cevaplar) kimlik içermez ve bu defterle hiçbir yerde birleştirilmez.

Veri sorumlusu ve veri işleyen. Katılım kaydının veri sorumlusu işverendir; OculaWork bu veriyi işverenin talimatıyla işleyen sıfatıyla barındırır.

İşlenen veriler. Sunucuda yalnızca şunlar tutulur: çalışanın kullanıcı kimliği (uid), tatbikatın tarihi ve katılım durumu (tamamladı / yarım bıraktı / süre doldu). Ad, soyad ve departman sunucuya yazılmaz — bu bilgiler zaten çalışan kaydında bulunduğundan ikinci bir kopya oluşturulmaz. Bu defterde rota, puan ve soru cevabı bulunmaz; sistem, bu alanların yazılmasını teknik olarak da reddeder.

İşleme amacı ve hukuki sebep. Veri, 6331 sayılı İş Sağlığı ve Güvenliği Kanunu ve İşyerlerinde Acil Durumlar Hakkında Yönetmelik kapsamındaki tatbikat yükümlülüğünün yerine getirildiğinin belgelenmesi amacıyla işlenir. Hukuki sebep, 6698 sayılı Kanun md.5/2-ç uyarınca veri sorumlusunun hukuki yükümlülüğünü yerine getirmesidir; bu nedenle ayrıca açık rıza aranmaz. Veri, birey performansını ölçmek için kullanılamaz.

Saklama ve imha. Katılım kaydı, işverenin ilgili mevzuat uyarınca İSG kayıtlarını saklamakla yükümlü olduğu süre boyunca saklanır; bu sürenin dolmasıyla silinir veya anonim hâle getirilir. Saklama süresinin belirlenmesi ve kişisel veri envanterine işlenmesi işverenin sorumluluğundadır.

Aktarım. Katılım kaydı üçüncü kişilere aktarılmaz. OculaWork'ün sektörel karşılaştırma amacıyla kullandığı anonim veri kümesine dâhil edilmez (bkz. 10.10).

Haklarınız. 6698 sayılı Kanun md.11 kapsamında verilerinize erişme, düzeltilmesini veya silinmesini isteme ve işlemeye itiraz etme haklarına sahipsiniz. Talebinizi işvereninize iletebilirsiniz.

Bu metin, sistemin fiilen işlediği veriyi ve teknik sınırlarını doğru biçimde tarif eder; işyerinize özgü aydınlatma metninin ve kişisel veri envanterinin hazırlanması ve hukuki uygunluk denetimi işverene aittir.

10.9 OculaLearn — İSG Eğitim İçeriği Sorumluluğu

OculaLearn, 6331 sayılı Kanun md.17 ve "Çalışanların İş Sağlığı ve Güvenliği Eğitimleri Uygulama Rehberi" (R.G. Sayı 33212, 2 Nisan 2026) Ek-1 müfredatına dayalı, ayrı bir Firebase altyapısında (oculalearn.web.app) barındırılan uzaktan İSG eğitim modülüdür. Resmi Ek-1 müfredatının içeriğinden ve doğruluğundan OculaWork sorumludur. Müşteri'nin "İçerik Geliştir" arayüzü aracılığıyla girdiği işyerine özgü Konu-4 içerikleri ve/veya tamamen özel ek eğitimlerin doğruluğu, güncelliği ve mevzuata uygunluğu münhasıran Müşteri'nin sorumluluğundadır; bu içerikler ancak Müşteri, kayıttan önce sunulan sorumluluk kabul beyanını onayladıktan sonra (kimlik, zaman damgası ve IP adresi kaydedilerek) sisteme işlenir. Bu özel içerikler resmi 60/100 geçme notuna veya sertifikaya hiçbir şekilde dahil edilmez; yalnızca Ek-1 iskelet müfredatı puanlanır ve sertifikalandırılır. OculaWork, Müşteri'nin girdiği özel içerikten kaynaklanan hiçbir hukuki, idari veya cezai sonuçtan sorumlu tutulamaz.

11 Fikri Mülkiyet
11.1 OculaWork'ün Mülkiyeti

Platform yazılımı, kaynak kodu, algoritmaları, tasarım ve marka OculaWork'ün münhasır fikri mülkiyetidir. Müşteri'ye; münhasır olmayan (non-exclusive), geri alınabilir (revocable), sınırlı (limited) ve dünya çapında (worldwide) geçerli, yalnızca abone olunan kullanıcı sayısı kadar, kullanım amaçlı bir lisans tanınır. Bu lisans devredilemez, başka bir firmaya kiralanamaz veya alt lisans olarak verilemez; Platform hiçbir şekilde kopyalanamaz veya tersine mühendisliğe tabi tutulamaz. Lisans, yalnızca satın alınan/abone olunan kullanıcı (kota) sayısı kadar aktif kullanıcı için geçerlidir; kota aşımı tespit edilirse Müşteri'den ek kota satın alması istenir. Lisanslanan kullanıcı sayısının sistematik şekilde aşılması hâlinde OculaWork, fazla kullanım bedelini geriye dönük olarak faturalandırabilir veya hesabı askıya alabilir. İşbu Sözleşme, OculaWork markası, ticari unvanı, algoritmaları veya olası patent başvuruları üzerinde Müşteri'ye herhangi bir hak devri oluşturmaz.

🚫 Yasaklı Kullanımlar: Platform üzerinde aşağıdaki faaliyetler kesinlikle yasaktır: otomatik veri toplama (scraping), bot kullanımı, yetkisiz otomasyon veya API benzeri erişim, API kötüye kullanımı, kullanım limiti aşma girişimi (rate limit bypass), kimlik bilgisi doldurma saldırısı (credential stuffing), hesap paylaşımı/kimlik bilgisi paylaşımı, spam, yetkisiz yük testi (load testing), model çıkarımı (model extraction), model ağırlıklarının çıkarımı (weight extraction), model çalınması (model stealing), parametre çıkarımı (parameter inference), yapay zeka istem/prompt çıkarımı (prompt extraction), model ince ayar saldırısı (fine-tuning attack), üyelik çıkarım saldırısı (membership inference attack), kaynak kodun/model çıktısının derlemesinin çözülmesi (decompile) veya parçalarına ayrılması (disassemble), yetkisiz karşılaştırmalı performans testi (benchmark), ve OculaWork'ün önceden yazılı izni olmaksızın güvenlik taraması (security scanning), sızma testi (penetration testing), fuzzing veya hizmet dışı bırakma saldırısı (DDoS) girişiminde bulunmak. Bu hükmün ihlali hâlinde lisans derhal ve tazminatsız olarak sona erer.
11.2 Müşteri Verilerinin Mülkiyeti

Müşteri ve çalışanlara ait ham tarama sonuçları ve raporlar Müşteri'nin mülkiyetindedir. OculaWork bu verileri yalnızca Sözleşme kapsamında işler; anonimleştirilerek toplulaştırılmış istatistikler Platform geliştirmesi amacıyla kullanılabilir.

11.3 Açık Kaynak Yazılımlar

Platform içerisinde üçüncü taraf açık kaynak yazılımlar kullanılabilir. Bu yazılımların lisans hakları ilgili lisans sahiplerine aittir. Açık kaynak bileşenlerinin kullanılması, işbu Sözleşme kapsamında OculaWork'ün fikri mülkiyet haklarını ortadan kaldırmaz.

11.4 Marka Kullanımı

Müşteri, OculaWork'ün önceden yazılı izni olmaksızın OculaWork marka, logo veya ticari unvanını reklam, referans veya tanıtım amacıyla kullanamaz.

11.5 Referans Müşteri

OculaWork, aksi yazılı olarak kararlaştırılmadıkça Müşteri'nin ticaret unvanını yalnızca referans müşteri listesinde kullanabilir. Müşteri, dilediği zaman yazılı bildirimle bu izni geri alabilir.

12 Abonelik, Ödeme ve İptal
  • Platform yıllık abonelik esasına göre sunulur; güncel fiyatlar oculawork.com'da yayınlanır
  • Yeni Müşteriler için 15 günlük ücretsiz deneme süresi tanınır; deneme süresi sonunda ücretli aboneliğe geçilmezse hesap otomatik olarak dondurulur, kart bilgisi talep edilmez
  • OculaWork, güncel fiyatları değiştirme hakkını saklı tutar; fiyat değişiklikleri Müşteri'ye en az 30 gün önceden bildirilir. Yeni fiyat, yalnızca bir sonraki yenileme (renewal) döneminden itibaren geçerli olur; hâlihazırda abone olan Müşterilerin ödemesi tamamlanmış, devam eden dönemine geriye dönük olarak kesinlikle uygulanmaz
  • Ödemeler dönem başında peşin tahsil edilir; KDV ve yasal kesintiler faturaya yansıtılır
  • Ödemenin gecikmesi hâlinde, gecikilen tutar üzerinden 6102 sayılı TTK ve ilgili mevzuatta öngörülen ticari temerrüt faiz oranı üzerinden gecikme faizi talep edilebilir; bu, §13.3'te belirtilen 15 günlük ihtar sürecine ek bir haktır
  • Vergi mevzuatında meydana gelen değişikliklerden kaynaklanan yeni vergi, fon veya benzeri mali yükümlülükler, yürürlük tarihinden itibaren fiyatlara yansıtılabilir
  • İptal bildirimi dönem bitiminden en az 15 gün önce yazılı olarak yapılmalıdır
  • Peşin ödenen abonelik ücretleri iade edilmez; iptal/fesih hâlinde dönemin kullanılmayan kısmı için kısmi iade yapılmaz
  • Bu Sözleşme B2B ilişkiyi düzenler; 6502 sayılı TKHK kapsamında cayma hakkı uygulanmaz
  • Platform reklamsızdır.
13 Sözleşmenin Sona Ermesi
13.1 Hesabın Geçici Olarak Askıya Alınması

OculaWork, aşağıdaki durumlarda Sözleşme'yi feshetmeden önce Müşteri'nin hesabını geçici olarak askıya alma hakkını saklı tutar: (i) Platform'un veya altyapının aktif bir siber saldırı altında olması, (ii) hesaptan kaynaklanan yetkisiz erişim/kötüye kullanım şüphesi, (iii) ödeme gecikmesi (bkz. §13.3), (iv) API kötüye kullanımı, bot trafiği, hizmet dışı bırakma (DDoS) girişimi, yetkisiz otomasyon veya olağan dışı yoğunlukta istek gönderimi (bkz. §11.1 Yasaklı Kullanımlar). (iv) numaralı hâllerde, Platform'un veya diğer Müşterilerin bütünlüğünü korumak amacıyla, hesap önceden bildirim yapılmaksızın askıya alınabilir. Askıya alma süresince Müşteri verilerine erişim geçici olarak kısıtlanır ancak veriler silinmez; durum netleştiğinde erişim yeniden açılır.

13.2 Olağan Fesih

Her iki taraf 30 gün önceden yazılı bildirimde bulunarak Sözleşme'yi sona erdirebilir.

13.3 Haklı Nedenle Fesih

OculaWork aşağıdaki durumlarda derhal ve tazminatsız fesih hakkını saklı tutar:

  • Müşterinin KVKK'yı açıkça ve ısrarla ihlal etmesi
  • Platform'un yasadışı amaçlarla kullanılması
  • Ödeme gecikmesi — Müşteri'ye 15 günlük yazılı ihtar süresi tanınır; bu süre içinde ödeme yapılmaz veya gecikme giderilmezse hesap askıya alınabilir ve/veya Sözleşme feshedilebilir
  • Platformun güvenliğini tehdit eden davranışlar
13.3.1 Kanuni Zorunluluk Nedeniyle Hizmetin Durdurulması

Yetkili bir mahkeme kararı veya kanunen zorunlu kılan bir idari/yasal düzenleme mevcut olması hâlinde, OculaWork Platform'u kısmen veya tamamen durdurabilir/kaldırabilir. Bu durum, kaynağı OculaWork'ün kontrolünde olmayan bir hukuki zorunluluktan doğduğu ölçüde, §10.3 kapsamında sorumluluk dışı bir hâl olarak değerlendirilir.

13.4 Sona Erme Sonrası Veri Yönetimi
  • Sözleşme sona ermesinden itibaren 90 gün içinde Müşteri verilerini dışa aktarabilir
  • 90 günlük süre sonunda tüm kişisel veriler geri döndürülemez biçimde silinir ve Müşteri'ye yazılı teyit edilir
  • Lisans, aboneliğin sona ermesiyle birlikte otomatik olarak sona erer; Müşteri ve çalışanları bu tarihten itibaren Platform'a erişemez
14 Çerez (Cookie) Politikası

Platform, bugün itibarıyla klasik anlamda bir HTTP çerezi (cookie) oluşturmamaktadır; aşağıdaki teknik depolama mekanizmaları tarayıcının yerel depolama alanında (localStorage) tutulur:

MekanizmaAmaçTürSüre
ow_langDil tercihiİşlevsellocalStorage (kalıcı)
Firebase Auth TokenOturum yönetimiZorunlu1 saat
"Beni Hatırla" jetonu ve rol bazlı e-posta hatırlatma anahtarlarıBir sonraki girişte oturumu/e-postayı hatırlamaİşlevsellocalStorage (kullanıcı çıkış yapana/reddedene kadar)
Cihaz-eşleştirme (biyometrik/parmak izi girişi) anahtarıCihazın daha önce biyometrik girişle eşleştirildiğini hatırlamaİşlevsellocalStorage (kullanıcı sıfırlayana kadar)
Bildirim tercihi ve cihaz push token anahtarlarıBildirim açık/kapalı tercihini ve bildirim gönderim adresini hatırlamaİşlevsellocalStorage (kalıcı, kapatılana kadar)
Firma kodu / son bağlanılan kiracı önbelleğiSelf-host firmalarda giriş ekranını doğru firmaya yönlendirmeİşlevsellocalStorage (kalıcı)
Uygulama sürümü ve tarama önbelleğiÇevrimdışı/gecikmiş bağlantıda son bilinen veriyi gösterme, güncelleme kontrolüİşlevsellocalStorage (kalıcı, güncellenene kadar)
✅ Platform; analitik, reklam veya üçüncü taraf izleme çerezi kullanmaz. Google Analytics veya benzer takip araçları entegre edilmemiştir. Platform, çalışması için gerekli zorunlu teknik depolama mekanizmalarını (çerez ve/veya localStorage) kullanabilir; bu mekanizmalar yalnızca hizmetin işlevselliği için kullanılır, izleme/reklam amacı taşımaz.
15 İletişim ve Başvuru
Konuİletişim
KVKK başvuruları / Veri silmeinfo@oculawork.com
Teknik destekinfo@oculawork.com
Hukuki bildirimlerinfo@oculawork.com
Güvenlik açığı bildirimiinfo@oculawork.com

KVKK başvurularına 30 gün içinde yanıt verilir. KVKK Kurumu'na şikâyet için: kvkk.gov.tr

15.1 Tebligat

Bu Sözleşme kapsamında taraflarca bildirilen e-posta adresine yapılan bildirimler, gönderildiği tarihte tebliğ edilmiş sayılır. Müşteri, iletişim bilgilerini güncel tutmakla yükümlüdür. E-postanın alıcı tarafın spam/gereksiz posta klasörüne düşmesi, alıcının e-posta sağlayıcısındaki filtreleme ayarlarından kaynaklanır; bu durumdan OculaWork sorumlu tutulamaz. Taraflar, iletişim bilgilerindeki değişiklikleri en geç 7 gün içinde yazılı olarak bildirmekle yükümlüdür; bildirilmeyen değişikliklerden doğacak sonuçlardan ilgili taraf sorumludur.

15.2 Faturalandırma

Faturalar elektronik fatura (e-Fatura) veya elektronik arşiv fatura (e-Arşiv) olarak, mevzuatın izin verdiği ölçüde e-posta yoluyla gönderilir ve bu şekilde tebliğ edilmiş sayılır.

16 Uygulanacak Hukuk ve Yetki
  • Bu Sözleşme Türkiye Cumhuriyeti hukukuna tabidir
  • Uyuşmazlıklarda 6698 sayılı KVKK, 6331 sayılı İSG Kanunu, 6102 sayılı TTK ve 6098 sayılı TBK uygulanır
  • Uyuşmazlıklarda Ankara Mahkemeleri ve İcra Daireleri münhasıran yetkilidir
  • Herhangi bir hükmün geçersizliği geri kalan hükümleri etkilemez (bölünebilirlik); geçersiz sayılan hükmün yerine, mümkün olduğu ölçüde, tarafların o hükümle ulaşmak istediği ticari amaca ve iradeye en yakın, hukuka uygun bir hüküm uygulanır
  • OculaWork bu Sözleşme'yi 30 gün önceden bildirimle güncelleme hakkını saklı tutar
  • Taraflar arasındaki uyuşmazlıklarda, sözleşmeden doğan talepler ilgili mevzuatta öngörülen zamanaşımı sürelerine tabidir
16.1 İhracat Kontrolleri ve Yaptırımlar

Müşteri, Platform'u Türkiye'nin veya Birleşmiş Milletler, Avrupa Birliği, ABD gibi uluslararası kuruluşların/yargı alanlarının yürürlükteki ihracat kontrolü ve yaptırım mevzuatını ihlal edecek şekilde kullanmayacağını; yaptırım listelerinde yer alan bir kişi/kuruluş adına veya yaptırım uygulanan bir ülkeden erişim sağlamayacağını beyan ve taahhüt eder.

16.2 Devir (Assignment)

Müşteri, işbu Sözleşme'yi OculaWork'ün önceden yazılı onayı olmaksızın devredemez. OculaWork, şirket birleşmesi, hisse devri, varlık satışı veya benzeri bir yapısal değişiklik hâlinde, işbu Sözleşme'yi ve bundan doğan hak ve yükümlülüklerini, Müşteri'ye önceden bildirimde bulunmak kaydıyla, üçüncü bir tarafa devredebilir.

16.3 Belgeler Arası Öncelik Sırası

İşbu Sözleşme metni ile ekleri (EK-1 Veri İşleme Sözleşmesi, Gizlilik Politikası, KVKK Aydınlatma Metinleri, Açık Rıza Metni) arasında bir çelişki bulunması hâlinde, aşağıdaki öncelik sırası uygulanır: (i) EK-1 Veri İşleme Sözleşmesi (yalnızca veri işleme hükümleri bakımından), (ii) işbu Sözleşme'nin ana metni, (iii) diğer ekler ve ayrı belgeler. Bildirimler, aksi belirtilmedikçe Türkçe yapılır; TR/EN metinler arasında çelişki hâlinde Türkçe metin esas alınır.

16.4 Delil Sözleşmesi
📋 Taraflar, zaman damgalı sistem loglarının, erişim kayıtlarının, Google Firebase kayıtlarının ve elektronik iletişimlerin (e-posta dahil) HMK Madde 193 kapsamında delil sözleşmesi niteliğinde olduğunu kabul eder. OculaWork, elektronik kayıtların makul güvenlik standartlarına uygun şekilde tutulmasını hedeflemekle birlikte, teknik arızalar, mevzuattan kaynaklanan silme yükümlülükleri veya §7.2'de belirtilen saklama süresi sonunda gerçekleştirilen imha işlemleri nedeniyle geçmiş tüm logların süresiz olarak korunacağını garanti etmez. Delil niteliğindeki kayıtlar yalnızca yürürlükteki saklama süreleri boyunca muhafaza edilir.
16.5 Tazmin Yükümlülüğü (İndemnification)
🛡️ Müşteri; (i) KVKK yükümlülüklerini ihlal etmesinden, (ii) çalışanlarının Platform verileriyle ilgili OculaWork'e karşı dava/talep açmasından, (iii) kendi kusurundan kaynaklanan bir veri ihlalinden, (iv) çalışanlarından gerekli açık rızayı almamasından, veya (v) Platform'un işbu Sözleşme'ye aykırı şekilde kullanılmasından doğan her türlü üçüncü kişi talebine, davaya, idari para cezasına ve zarara karşı OculaWork'ü tazmin etmeyi ve savunma masraflarını (avukatlık ücreti dahil) karşılamayı kabul eder. OculaWork, kendi payına düşen ölçüde, doğan zararı makul şekilde azaltmak için gerekli özeni gösterecektir.
16.6 Gizli Bilgi (Confidential Information)

Taraflar, işbu Sözleşme kapsamında öğrendikleri veya erişim sağladıkları birbirlerine ait ticari sırları, fiyatlandırma bilgilerini, algoritma ve yazılım mimarisi detaylarını, müşteri/çalışan listelerini ve açıkça gizli olarak işaretlenmiş diğer bilgileri üçüncü kişilerle paylaşmamayı ve yalnızca işbu Sözleşme'nin ifası amacıyla kullanmayı kabul eder. Bu yükümlülük, kamuya mal olmuş bilgileri, yasal zorunluluk nedeniyle açıklanması gereken bilgileri veya bağımsız olarak geliştirilmiş bilgileri kapsamaz; Sözleşme sona erse dahi makul bir süre boyunca yürürlükte kalır.

16.7 Feragat (Waiver)

Taraflardan birinin işbu Sözleşme'den doğan bir hakkını belirli bir durumda kullanmaması veya kullanmakta gecikmesi, o haktan veya ileride aynı ya da benzer bir durumda bu hakkı kullanmaktan feragat ettiği anlamına gelmez.

16.8 Sözleşmenin Bütünlüğü (Entire Agreement)

İşbu Sözleşme ve ekleri (EK-1 Veri İşleme Sözleşmesi ile bkz. §16.3'te belirtilen diğer belgeler), taraflar arasındaki konuya ilişkin bütün anlaşmayı oluşturur ve bu konudaki önceki yazılı veya sözlü tüm görüşme, teklif ve anlaşmaların yerine geçer. İşbu Sözleşme'de değişiklik, ancak OculaWork tarafından yazılı olarak (bkz. §16 güncelleme bildirimi) yapılabilir.

16.9 Sözleşme Sona Erdikten Sonra Yürürlükte Kalacak Hükümler (Survival)

İşbu Sözleşme herhangi bir nedenle sona erse dahi, niteliği gereği sona ermeden sonra da uygulanması gereken hükümler yürürlükte kalmaya devam eder; bunlar arasında özellikle Gizli Bilgi (§16.6), Fikri Mülkiyet (§11), Tazmin Yükümlülüğü (§16.5), Kişisel Verilerin Korunması'na ilişkin hükümler (§7) ve Delil Sözleşmesi (§16.4) yer alır.

Platform'u kullanmaya başlamak bu Sözleşme'nin tamamını okuduğunuzu ve kabul ettiğinizi gösterir. Platform üzerinden verilen elektronik onay, güvenli elektronik imza niteliğinde olmamakla birlikte, taraflar arasında bağlayıcı sözleşme kabulü olarak değerlendirilir. Çalışanların Aydınlatma Metni'ni okuduğuna ve Açık Rıza beyanını verdiğine dair onay; onay anındaki kullanıcı kimliği, zaman damgası ve tarayıcı bilgisi ile birlikte, sonradan değiştirilemeyecek şekilde (yalnızca oluşturma izni verilen, güncelleme/silme izni verilmeyen) ayrı bir kayıt defterinde tutulur (bkz. §16.4). Bu kayıt IP adresi içermez — IP adresi yalnızca Google Firebase altyapısının kendi güvenlik loglarında, Google'ın politikaları kapsamında tutulabilir (bkz. §7.2). Sorularınız için: info@oculawork.com
📄 Sürüm: 1.0 · Yürürlük Tarihi: 10.07.2026 · Son Güncelleme: 16.07.2026
EK-0 Kurumsal Kurulum (Kendi Sunucusunda Çalıştırma)

Bu ek yalnızca, Platform'u kendi altyapısında ve kendi veritabanında çalıştıran Müşteriler için geçerlidir. Self-host Firebase kurulumunda bu ek uygulanmaz; çelişki hâlinde bu ekteki hükümler ana metnin önüne geçer.

EK-0.1 Verinin Konumu

Kurumsal kurulumda çalışan tarama kayıtları ve bunlardan türetilen sağlık göstergeleri münhasıran Müşteri'nin kendi sunucusunda ve kendi veritabanında tutulur. Bu verilerin barındırılması, yedeklenmesi, erişilebilirliği ve bunlara ilişkin tüm maliyet Müşteri'ye aittir.

Ham kamera görüntüsü, video karesi veya yüz işaret noktası verisi hiçbir koşulda çalışanın cihazından çıkmaz; ne OculaWork'e ne de Müşteri'nin sunucusuna iletilir ve hiçbir yerde saklanmaz. Cihaz dışına çıkan tek veri sayısal ölçüm sonuçlarıdır.

EK-0.2 OculaWork'te Kalan Bileşenler

Aşağıdakiler, hizmetin ifası için zorunlu olduğundan kurumsal kurulumda dahi OculaWork altyapısında bulunur ve Müşteri bunu kabul eder:

  • Firma yapılandırma kayıtları ve hesap tercihleri,
  • Kimliksizleştirilmiş model eğitim verisi — bu kayıtlarda çalışan kimliği veya firma kimliği saklanmaz,
  • E-posta gönderim altyapısının tamamı (yeni üyelik, şifre işlemleri, personel ve iş yeri hekimi bildirimleri dâhil),
  • Analiz ve karar destek çekirdeği (sektör modeli, kıyaslama, hipotez motoru) ile lisans üretim altyapısı.

Bu bileşenler lisanslanan yazılıma dâhil değildir; hizmet olarak sunulur ve Müşteri'ye teslim edilmez.

EK-0.3 Lisans Süresi, Teknik Doğrulama ve Erişimin Askıya Alınması

EK-0.3.1 — Kurumsal lisans süreli bir kullanım hakkıdır; mülkiyet devri veya süresiz kullanım hakkı doğurmaz. Müşteri'nin Yazılım'ı kullanma hakkı, Sözleşme'de belirtilen lisans süresi ile sınırlıdır ve lisans süresinin sona ermesiyle kendiliğinden sona erer. Lisans süresinin sona ermesi üzerine erişimin teknik olarak sınırlandırılması veya durdurulması; ayıp, temerrüt veya sözleşmeye aykırılık olarak değerlendirilemez.

EK-0.3.2 — Lisans süresi devam ettiği sürece OculaWork, lisansın geçerliliğini teknik olarak doğrulamak amacıyla lisans doğrulama hizmetini kullanabilir.

EK-0.3.3 — Doğrulama sunucusuna erişilememesi lisansın sona ermesi değildir. Lisans doğrulama hizmetine geçici olarak erişilememesi, lisansın sona erdiği veya geçersiz hâle geldiği anlamına gelmez. Bu durumda Yazılım, geçerli lisansın doğrulanmış son durumunu esas alarak çevrimdışı çalışmaya devam eder; uzun süreli doğrulama probleminde Müşteri yöneticisine uyarı gösterilir.

EK-0.3.4 — OculaWork altyapısından kaynaklanan teknik kesinti, planlı bakım, altyapı arızası veya lisans doğrulama hizmetine erişilememesi nedeniyle, lisans süresi devam eden Müşteri'nin Yazılım'a erişimi durdurulamaz ve lisans süresi Müşteri'nin kusuru olmaksızın kısaltılmış sayılmaz.

EK-0.3.5 — Müşteri'nin lisans bedelini vadesinde ödememesi hâlinde OculaWork, yazılı bildirimde bulunarak borcun ödenmesi için en az 15 günlük ek süre tanır. Bu sürenin sonunda ödeme yapılmamış ve temerrüt hâli devam ediyorsa OculaWork, Yazılım kullanımını geçici olarak askıya alabilir. Askıya alma, Sözleşme'nin feshi anlamına gelmez ve Müşteri'nin diğer hak ve yükümlülüklerini ortadan kaldırmaz.

EK-0.3.6 — Askıya alma işleminden önce OculaWork, Müşteri'ye askıya alma tarihi ve ödeme tutarı hakkında yazılı bildirim gönderir. Ödeme uyuşmazlığının makul şekilde incelenmesinin gerekli olduğu durumlarda, uyuşmazlık sonuçlandırılıncaya kadar erişimin askıya alınması uygulanmaz. Geçerli bir lisans döneminde, yalnızca ödeme uyuşmazlığı bulunduğu gerekçesiyle ve bu bildirim/süreler işletilmeksizin hizmet teknik olarak devre dışı bırakılmaz.

EK-0.3.7 — Veri erişimi. Erişimin askıya alınması veya lisansın sona ermesi hâlinde dahi Müşteri, EK-0.8'de düzenlenen süre ve koşullarla kendi verilerini dışa aktarma hakkını korur.

EK-0.3B Veri İşleme Yeri ve Tarafların Konumu

Kurumsal kurulumda müşteri çalışanlarına ilişkin kişisel veriler, müşterinin kendi bilgi işlem altyapısından çıkarılmaksızın işlenir. OculaWork, müşteri tarafından yetkilendirilen yazılım bileşenleri aracılığıyla analiz faaliyetini müşterinin altyapısı içerisinde gerçekleştirir.

⚖️ Bu, OculaWork'ün kişisel veri işlemediği anlamına gelmez. Verinin müşterinin sunucusunda bulunması tek başına OculaWork'ü KVKK kapsamı dışına çıkarmaz; analiz faaliyeti müşteri adına yürütülen bir veri işleme faaliyetidir. Tarafların sıfatları §7.5'te düzenlenmiştir. Uzaktan bakım, destek ve güvenlik amaçlı erişimlerin kimin tarafından, hangi amaçla ve hangi kayıt altına alma yükümlülüğüyle yapılacağı Kurumsal Kurulum/Sipariş Formu'nda ayrıca belirlenir.
EK-0.3C Merkeze Gönderilebilecek Veriler (Veri Çıkış Beyaz Listesi)

Kurumsal kurulumda müşterinin sunucusundan OculaWork merkezine gönderilebilecek alanlar teknik olarak sınırlandırılmıştır. Bu bir taahhüt değil, sistemin izin verdiği azami kapsamdır: beyaz liste dışındaki her alan sunucu tarafında reddedilir.

KanalGönderilebilecek alanlarReddedilen
Model geliştirme katkısı (varsayılan kapalı)modelSurumu, ornekSayisi, gradyan, gurultuOlcegiŞema dışı her alan — çalışan kimliği, departman, e-posta, ham ölçüm, serbest metin, tarih
Bildirim gönderimi (yalnızca "mail bizde" modunda)Alıcı adresi, şablon kimliği, müşterinin kendi adresine bağlantıSerbest metin, konu, HTML gövde, ek dosya
Lisans doğrulamaLisans kimliği, sürüm, sistem sağlık durumuÇalışan verisi
Günlük kurulum sinyali (sağlık ve kurcalama tespiti)Kurulum kimliği, model sürümü, karar çekirdeği özeti, son eğitimden bu yana geçen kabaca süre, toplulaştırılmış ölçüm sayacı, reddedilen istek sayaçlarıKimlik, departman, serbest metin, kesin tarih damgası, şema dışı her alan
Merkezî psikososyal danışma (varsayılan kapalı)Sektör kodu, çalışan sayısı bandı, ≥50 ölçümden türetilmiş dağılımlar (eşik altı hücreler bastırılmış), gürültü ölçeğiBireysel kayıt, kimlik, departman adı, serbest metin, tarih, tam çalışan sayısı

Model geliştirme katkısı ayrıca şu koşullara tabidir: en az 50 ölçümden türetilmiş olması, gizlilik artırıcı gürültünün uygulanmış olması ve katkı büyüklüğünün sınırlandırılmış olması. Bu tekniklerin uygulanmış olması, ilgili verinin hukuken anonim olduğu anlamına gelmez; anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır.

EK-0.3D Kaynak Kod Emaneti (Escrow) ve Süreklilik

Kaynak kodun Müşteri'ye teslimi, ancak taraflar arasında ayrıca imzalanmış bir kaynak kod emaneti (escrow) sözleşmesinde tanımlanan tetikleyici olayların gerçekleşmesi hâlinde mümkündür. Escrow'un amacı Müşteri'nin kaynak koda dilediği an erişmesi değil, olağanüstü hâllerde operasyonel devamlılığının korunmasıdır.

Tetikleyici olaylar sınırlı sayıda ve açıkça tanımlıdır: OculaWork'ün faaliyetini kalıcı olarak durdurması, iflas/konkordato kapsamında sözleşmede belirlenen şartların oluşması, veya destek ve bakım hizmetinin kalıcı olarak sona ermesi. Geçici bir hizmet kesintisi tetikleyici olay değildir.

🔑 Model imzalama altyapısı escrow kapsamı dışındadır. Kaynak kod emaneti ile model imzalama anahtarları ayrı tutulur; imzalama anahtarı hiçbir koşulda emanete konulmaz. Escrow'un amacı Müşteri'nin sistemi çalıştırmaya devam edebilmesidir; OculaWork adına yeni model üretme ve imzalama yetkisi devredilmez. Escrow düzenlemesi Müşteri'ye kaynak kod üzerinde bu Sözleşme'de tanınmamış bir lisans veya mülkiyet hakkı vermez.
EK-0.3E Model Bütünlüğü ve İmza Doğrulaması

Müşteri sunucusundaki bileşen, yalnızca OculaWork tarafından geçerli özel anahtarla imzalanmış ve bütünlüğü doğrulanmış model paketlerini kabul eder. İmzasız ya da imzası doğrulanamayan paket çalıştırılmaz.

İmzalama özel anahtarı Müşteri ortamına hiçbir koşulda gönderilmez; Müşteri tarafında yalnızca doğrulama (açık) anahtarı bulunur. Bu ayrım, Müşteri'nin kendi ürettiği bir modeli sisteme sokmasını ve merkezî altyapının ele geçirilmesi hâlinde sahte model dağıtılmasını engeller.

🔑 Lisans doğrulaması ile model doğrulaması iki ayrı güvenlik katmanıdır ve birbirine bağlanmaz. Geçerli bir lisans, imzasız bir modeli kabul edilebilir kılmaz; geçerli bir model imzası da sona ermiş bir lisansı yürürlükte kılmaz. Hata durumları da ayrıdır (model reddi ≠ lisans sonu).
EK-0.3F Uzaktan Erişim ve Destek

OculaWork'ün Müşteri altyapısına uzaktan idari erişimi varsayılan olarak kapalıdır. Destek gerektiren hâllerde erişim, Müşteri tarafından geçici olarak ve amaçla sınırlı biçimde yetkilendirilir.

Yetkilendirilmiş her erişim; kim, ne zaman, hangi amaçla ve hangi kaynağa eriştiği bilgisiyle kayıt altına alınır. OculaWork destek personelinin çalışan içeriğine varsayılan erişimi yoktur.

EK-0.3G Yurt Dışına Aktarımda Bildirim Yükümlüsü

Yurt dışına aktarım için standart sözleşme kullanılması hâlinde, sözleşmenin imzalanmasından itibaren 5 iş günü içinde Kurum'a bildirilmesi gerekir. Bildirim yükümlülüğünün hangi tarafça yerine getirileceği, aktarım senaryosuna ve tarafların sıfatına göre ilgili Sipariş Formu veya aktarım sözleşmesinde açıkça belirlenir.

Standart sözleşme metni, mevzuat gereği üzerinde değişiklik yapılmaksızın kullanılır; taraflara özgü ticari şartlar ayrı bir sözleşmede düzenlenir.

EK-0.4 Tersine Mühendislik ve Baypas Yasağı

Müşteri; lisans denetimini devre dışı bırakamaz, değiştiremez veya baypas edemez. Yazılımı OculaWork lisans servisine bağlanmadan çalıştırmaya yönelik her girişim esaslı ihlal sayılır ve Sözleşme'nin haklı nedenle derhal feshi sonucunu doğurur.

Yazılımın istemci tarafı bileşenlerinin teknik olarak okunabilir olması, Müşteri'ye herhangi bir çoğaltma, türev çalışma üretme, devir veya alt lisans hakkı vermez.

EK-0.5 Denetim Hakkı

OculaWork, makul bir bildirim süresiyle ve Müşteri'nin iş akışını aksatmayacak şekilde, kurulum sayısı ve lisans uyumu denetimi yapma hakkını saklı tutar. Yazılımın ürettiği imzalı lisans ve erişim kayıtlarının delil niteliği taşıdığı taraflarca kabul edilir. Denetimde uyumsuzluk tespit edilmesi hâlinde denetim masrafları Müşteri'ye aittir.

EK-0.6 Gizlilik Eşikleri

Raporlama eşikleri (departman bazında en az 5, şirket geneli en az 10 çalışan) sözleşmesel bir taahhüttür. Müşteri bu eşiklerin düşürülmesini veya toplulaştırma/baskılama korumasının baypas edilmesini talep edemez. Çalışanın sağlık verisine yönetici erişemez; bu veri yalnızca çalışanın kendisi ve yetkilendirilmiş iş yeri hekimi tarafından görülebilir.

⚠️ Bu eşikler tek başına hukuken anonimleştirme garantisi değildir. Eşik altındaki gruplar gizlenir ve gizlenen grubun diğer gruplardan matematiksel çıkarımla geri hesaplanmasını önlemek için tamamlayıcı baskılama uygulanır. Bununla birlikte bir verinin KVKK anlamında anonim sayılıp sayılmayacağı, yalnızca doğrudan tanımlayıcıların kaldırılmasına değil, makul yollarla yeniden kimliklendirme imkânına ilişkin somut koşullara göre belirlenir.
EK-0.7 İşletme Sorumluluğu ve Hizmet Seviyesi

Sunucunun kurulumu, güncellenmesi, yedeklenmesi ve işletilmesi Müşteri'nin sorumluluğundadır; bu yükümlülükler OculaWork tarafından sağlanan İşletme Kılavuzu'nda tanımlanmıştır ve işbu Sözleşme'nin eki sayılır. OculaWork'ün hizmet seviyesi taahhüdü yalnızca kendi sunduğu servislerle (lisans, analiz, e-posta) sınırlıdır; Müşteri altyapısındaki kesinti, veri kaybı veya performans sorunları kapsam dışıdır.

EK-0.8 Sözleşme Sonu

Fesih hâlinde Müşteri'nin verisi, halihazırda kendi sunucusunda bulunduğundan Müşteri'de kalır; OculaWork'ün ayrıca bir iade yükümlülüğü doğmaz. OculaWork tarafında bulunan kimliksizleştirilmiş model eğitim verisi; kimlik bilgisi ve doğrudan tanımlayıcı içermediği, gizlilik artırıcı tekniklerden geçirildiği ve belirli bir müşteriye geri bağlanabilir nitelikte olmadığı için silme kapsamı dışındadır. Bu, söz konusu verinin hukuken anonim olduğu anlamına gelmez (bkz. §7.4 ve EK-0.3C); anonimlik değerlendirmesi somut koşullara göre ayrıca yapılır. Müşteri bu işlemeye §7.4 çerçevesinde muvafakat eder.

EK-1 Veri İşleme Sözleşmesi (Data Processing Agreement)

Bu ek, işbu Hizmet Sözleşmesi'nin ayrılmaz bir parçasıdır ve Müşteri ile OculaWork arasındaki veri işleme ilişkisini KVKK Md. 3/1-ğ kapsamında düzenler. Sözleşme metni içindeki ilgili hükümlerin konsolide bir özetidir; çelişki hâlinde ana metindeki ilgili bölüm esas alınır.

UnsurAçıklama
Veri SorumlusuMüşteri
Veri İşleyenOculaWork (bkz. §1 Tanımlar)
İşlemenin Konusu ve Süresiİşbu Sözleşme'nin süresi boyunca, İSG risk analizi ve ilgili amaçlarla (bkz. §7.1 tablosu)
İlgili Kişi KategorileriMüşteri'nin çalışanları
Kişisel Veri KategorileriKimlik, iletişim, sağlık/biyometrik, davranışsal, organizasyon, işlem verisi (bkz. §7.1 tablosu)
İşleme Talimatları (Processing Instructions)OculaWork, kişisel verileri yalnızca Müşteri'nin talimatları ve işbu Sözleşme'de belirtilen amaçlarla işler; farklı bir amaçla işlemez (bkz. §7.0, §7.4)
Veri İşleyenin Yükümlülükleribkz. §7.0
Alt İşleyenGoogle Firebase / Google Cloud (bkz. §4.2); değişiklik hâlinde Müşteri'ye önceden bildirilir
Güvenlik Tedbirleribkz. §9 (Veri Güvenliği)
Yurt Dışına Aktarım (International Transfers)Veriler Avrupa bölgesinde (eur3) tutulur; olası aktarım KVKK Md. 9 rejimine tabidir (bkz. §4.2)
İhlal BildirimiGecikmeksizin ve her hâlükârda 24 saat içinde (bkz. §9.3)
İmha Prosedürü (Deletion Procedure)Sözleşme sonunda Müşteri talebi doğrultusunda veriler iade edilir; 90 gün sonunda kalıcı olarak imha edilir ve Müşteri'ye yazılı teyit edilir (bkz. §4.3, §13.4)
By starting to use the Platform you represent that you have read, understood and accepted all provisions of this Agreement. If you do not agree, do not use the Platform.
01 Parties and Scope

This Terms of Service, Privacy Policy and Data Protection Agreement (collectively "Agreement") is entered into between the following parties:

Service Provider

OculaWork — employee eye health and fatigue analysis platform operating at oculawork.com ("OculaWork", "Platform", "We").

Legal Trade NameCimedya Bilgi Sistemleri Reklam ve Tic. A.Ş.
Tax Office / No.Maltepe Tax Office — 2100357903
Registered AddressSöğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara, Türkiye
Emailinfo@oculawork.com
Customer

Any individual or legal entity, company, institution or organization subscribing to OculaWork and using the Platform for their employees ("Customer", "Employer", "You").

End User / Employee

Persons employed by the Customer, registered in the system by the Customer, and performing measurements via the Platform ("Employee", "End User").

⚠️ Important: This Agreement governs a B2B (business-to-business) service relationship. The Customer assumes the role of Data Controller vis-à-vis its employees and exclusively accepts all legal obligations arising from that role.
02 Definitions
TermDefinition
PlatformThe software, interfaces and all services provided at oculawork.com and related subdomains
KVKKTurkish Personal Data Protection Law No. 6698 and related regulations (equivalent to GDPR)
OSH LawOccupational Health and Safety Law No. 6331
Data ControllerKVKK Art. 3 — Entity determining the purposes and means of processing personal data. The Customer, in respect of the processing of employee data through the Platform (see §7.5)
Data ProcessorKVKK Art. 3 — Entity processing data on behalf of, and under authority granted by, the controller. OculaWork, in respect of employee-data processing carried out on the Customer's behalf (see §7.5)
Infrastructure ProviderGoogle Firebase / Google Cloud — the platform where data is physically hosted; a legal entity independent of OculaWork
Sensitive DataKVKK Art. 6 — Special categories including health and biometric data
EAR / PERCLOSEye Aspect Ratio / Percentage of Eye Closure — camera-based physiological and behavioural indicators measured by the Platform. Whether such data constitutes biometric data is assessed on the facts, not merely because it is numerical, but according to whether it is used to uniquely identify or verify a specific individual (see §7.1)
Explicit ConsentKVKK Art. 3 — Freely given, specific and informed consent that can be withdrawn
SaaSSoftware-as-a-Service — subscription-based cloud software
03 Scope and Nature of the Service
🏢 B2B acceptance boundary: This Agreement is formed when the Customer's authorised representative creates a subscription or signs an Order Form. An employee's or End User's use of the Platform does not make them a party to this Agreement, nor a person authorised to accept it on the Customer's behalf. The documents applicable to employees are the Disclosure Notice and, where required, the Explicit Consent texts.
3.1 Service Overview

OculaWork is a SaaS platform that produces measurable behavioural and ergonomic indicators from eye and facial movements via a standard webcam — using methods found in the scientific literature — in order to support the assessment of working conditions, ergonomic exposure and operational risk in the workplace, and provides risk-based reports to employers and occupational physicians. The Platform does not perform medical diagnosis, disease screening or medical-condition monitoring, does not propose treatment, and does not make medical decisions.

⚠️ No guarantee regarding workplace accidents or fitness for work. Platform outputs constitute no guarantee that a workplace accident will not occur, that an existing risk will be detected, or that an employee is fit to work at a given time. The obligation to carry out risk assessment and to take preventive measures rests with the employer under applicable legislation.
3.2 Technical Scope
  • A 30-second active measurement captures EAR, PERCLOS, blink rate, reaction time, and 4 additional physiological/behavioural indicators
  • Camera footage is processed exclusively in the browser (client-side); raw video is never sent to any server
  • Only computed numerical metrics are transmitted to servers
  • The management panel shows only aggregated department-level statistics that have passed the thresholds in §11; individual results are not displayed. Individual data is accessible only to the employee themselves and the authorised occupational physician
3.3 Medical Disclaimer and AI Decision Mechanism
⚕️ Platform outputs are for informational and decision-support purposes only. They do not constitute medical diagnosis, treatment advice, or a physician's opinion. Platform results alone are not sufficient legal grounds for pre-employment exams, periodic medical exams, or disciplinary decisions. No output generated by artificial intelligence (risk scores, anomaly alerts, or the OwO model included) constitutes or can constitute an automated personnel decision; final evaluation is always made by the qualified occupational physician and/or the employer, under human oversight. Platform outputs may not be used as the sole determinative factor for performance scoring, salary/wage reduction, or termination of employment. AI systems, by their nature, may produce false positive or false negative results; the Customer and Employee accept this possibility. The model's general operating logic (data sources used, methodology) may be explained upon request; however, specific algorithmic details and model weights, which constitute trade secrets, are not disclosed. Rule-based algorithms and the OwO model may be updated, improved, or retrained over time with different signals; outputs for the same input may therefore differ between different points in time.
3.4 Service Continuity

OculaWork operates with a high-availability target but cannot be held liable for planned maintenance, force majeure, or infrastructure provider outages. Planned downtime is announced 48 hours in advance. This is a general target, not a numeric percentage commitment; it does not constitute a service level agreement (SLA) or a service-credit program. When assessing availability: the total time in the relevant month is used as the base; scheduled maintenance windows (below) and outages attributable to Google Firebase/Google Cloud infrastructure are excluded from this assessment (see §10.3).

The subscription fee in effect will not change during the current pricing period (see §12); any price change may only take effect from the next renewal period onward.

Planned maintenance is scheduled, where possible, during weekends or nighttime hours, and is limited to a maximum of 4 hours per occurrence. Where an urgent situation threatens the security or integrity of the Platform (e.g., an active attack), emergency maintenance may be performed without prior notice.

💾 Backup: The Platform relies on Google Firebase's own automatic infrastructure backup mechanisms. No separate, numeric Recovery Time Objective (RTO) or Recovery Point Objective (RPO) commitment is currently provided.
3.5 Support Service
ScopeDetail
Support hoursDaily 08:00–20:00 (Turkey time)
Critical incident (system fully inaccessible)Initial response within 24 hours, during support hours
Standard support requestInitial response within 2 business days
New feature requestsConsidered for roadmap; no delivery date is guaranteed

The response times above indicate only that a support request has been received and is being processed; they do not constitute a resolution-time commitment.

📖 Definitions: "Availability (uptime)" is assessed per the calculation method described in §3.4. "Planned maintenance" refers to the pre-announced windows, limited to a maximum of 4 hours, described in §3.4. "Critical incident" means the Platform being fully inaccessible, as defined in the table above; all other requests are classified as a "standard support request." This Agreement does not commit to a formal severity-tier classification system beyond these two categories (critical/standard).
3.6 Beta Features

Features on the Platform marked "beta," "preview," or "experimental" (including newly developed AI modules) are provided on a preview basis; they may be interrupted, changed unexpectedly, or removed. No outcome is guaranteed for these features, and the Agreement's general service-continuity/SLA commitments do not cover them. Beta features may result in data loss or erroneous data output; the Customer should not rely on beta features for critical or single-source data.

3.7 Future Integrations

OculaWork may in the future offer integrations with third-party systems (identity/directory services, enterprise communication tools, ERP/HR software, etc.). Such integrations, when released, will be subject to additional terms announced at that time; this Agreement does not commit to any integration that does not currently exist. Likewise, should a general-purpose API be released in the future, usage limits (rate limits), API key management, and abuse policies will be governed by a separate API Terms of Use document.

3.8 Technical Requirements
  • Camera permission is required: If the user denies or revokes camera access permission, camera-based scanning features will not function; this portion of the service cannot be provided in that case
  • Supported browsers: Current versions of Google Chrome, Microsoft Edge, Mozilla Firefox, and Safari; Internet Explorer is not supported
  • Minimum hardware: A webcam capable of at least 640×480 resolution, adequate ambient lighting, and a stable internet connection
3.9 Video Calling

The Platform offers a feature enabling a direct video call with an employee, which only the occupational physician may initiate (one-directional). The connection is established directly between two devices (WebRTC, using Google's free public STUN server) without passing through any third-party server; audio/video is never recorded or stored on any server. The technical connection data (SDP/ICE) required to establish the call is automatically deleted a few seconds after the call ends. During the call, an approximate camera-based pulse estimate and an instantaneous blink/PERCLOS-based fatigue-stress indicator are computed from the employee's camera feed — shown only to the physician on that call, only for the call's duration. These indicators are not a medical measurement or diagnosis, do not replace a clinical device, and are never added to or stored in the employee's permanent scan history. As no TURN server is used, the connection may occasionally fail to establish under very strict corporate network/firewall configurations.

04 Data Architecture — No Data Stored at OculaWork
🏢 Enterprise deployment: if you run the Platform on your own server and your own database, this section applies to you only in part. Your scan records are held in your own database, not in Firebase. In that case the provisions of APP-0 — Enterprise Deployment apply with priority.
OculaWork operates no physical data centre or physical servers of its own. Customer data is not stored on OculaWork-owned hardware or in a data centre operated by OculaWork; the Service is delivered through cloud services managed by OculaWork (for this distinction, see APP-0.2). All data is hosted exclusively on Google Firebase / Google Cloud infrastructure.
4.1 Data Flow Architecture
StageWhere Processed / StoredOculaWork Access
Raw camera footage (video)User's browser only (RAM) — never transmitted anywhere❌ No access
Computed numerical metrics (EAR, PERCLOS, etc.)Google Firebase Firestore (Google Cloud infrastructure)Limited admin access for software management
User account informationGoogle Firebase AuthenticationLimited admin access for software management
Application files (HTML, JS)Google Firebase Hosting (CDN)Full access — software owner
OwO consult profile (anonymous numeric metrics — see §7.4)Google Cloud Functions (Europe) → only a 0-1 sector-context score (owoContextScore) is appended to the scan recordIdentity information is never sent or processed
OwO training sample (anonymous feature vector + label — see §7.4)Google Firebase Firestore (Europe) — only a numeric vector, a timestamp, and a 0/1 label; never contains identity or company informationAccessible to no one (including admin); read only by the training process, automatically deleted after 180 days
Drug name recognized by the physician's screen (sedation-class lookup only)Google Cloud Functions (Europe) — the query is instantaneous; neither the query nor its result is stored anywhereDerived only from anamnesis data the physician already has access to
OwO feedback (👍/👎, see §7.4)Google Firebase Firestore (Europe) — only the information type + whether it was helpfulAccessible to no one (including admin); only the aggregate ratio is computed server-side
Physician's clinical accuracy verdict on a scan ("accurate/under/over/referred", see §7.4)Google Firebase Firestore (Europe) — stored tied to that scan record; fed into OwO training as an anonymous, corrected labelAccessible only to that tenant's physicians/management
Bug report and automatically captured technical diagnostics (browser error, device/browser info — see §9.4)Google Firebase Firestore (Europe)Accessible only to OculaWork's own admin; the reporting user's own employer cannot see it
4.2 Google Firebase's Role

Google Firebase is an independent cloud infrastructure and data hosting service owned by Google LLC. Firebase's data processing terms and security measures are governed by Google's Privacy Policy and Firebase Data Processing Terms.

  • Google Firebase is infrastructure that holds international security standards such as ISO/IEC 27001 and SOC 2 Type II, and its data processing operations are governed by Google's current published Data Processing Terms (DPA)
  • Data is stored in the European region (eur3 — Belgium/Netherlands)
  • Firebase, as an entity independent of OculaWork, protects data under its own policies
🌍 Cross-Border Data Transfer (KVKK Art. 9): Under KVKK Art. 9, as amended by Law No. 7499, personal data may be transferred abroad only (i) where the Board has issued an adequacy decision for the destination, (ii) absent an adequacy decision, via the Board's standard contract mechanism (notified to the Board) or approved binding corporate rules, or (iii) exceptionally, with Board authorization. Even where data is stored in the European region, transfer outside the EU may occur through Google's support access or sub-processors; such transfers are subject to Google Firebase's current Data Processing Terms (DPA). The Customer is responsible for accurately declaring this transfer in its own VERBİS/data inventory records and, where necessary, confirming with its own legal counsel that this mechanism satisfies the current requirements of KVKK Art. 9.
4.3 Data Ownership and Portability

All Customer data (scan results, reports, account information) remains the property of the Customer; OculaWork asserts no rights over such data beyond those granted under this Agreement. Personal data is not a subject of ownership in the classical sense; this provision governs the rights of use and disposition over data supplied by, and processed on behalf of, the Customer, and does not affect data subjects’ rights under KVKK. Upon request, data export is provided; export is made only in formats OculaWork supports at that time (e.g., JSON/CSV), and no other format is guaranteed. Data integrity is maintained on OculaWork's side during export; however, no guarantee is made regarding compatibility with, or the integrity of the data after import into, third-party systems (e.g., the Customer's own ERP/HR software). Upon contract termination, data is permanently deleted within 90 days. This 90-day period concerns the deletion of operational data that remains accessible after termination; the retention periods set out in §7.2 and any retention obligations arising from legislation are reserved. Even if the account is closed/data is deleted, certain records (e.g., invoicing data) may be separately retained for the legally required retention period due to accounting regulations (e.g., Turkish Tax Procedure Law), transaction logs, and KVKK-related legal retention obligations.

05 Customer Obligations
5.1 Data Controller Role and KVKK Obligations

The Customer exclusively holds the status of Data Controller under KVKK Law No. 6698 with respect to the processing of its employees' personal data. The Customer is independently responsible for:

  • Notification (KVKK Art. 10): Providing employees with a disclosure notice about the data to be processed and its purposes
  • Explicit consent (KVKK Art. 5-6): Establishing the appropriate legal basis for processing health/biometric data
  • Data subject rights (KVKK Art. 11): Handling employees' requests for access, correction, deletion and objection
  • VERBİS registration: Registering with Turkey's Data Controllers Registry if within scope
  • Data inventory: Maintaining records and inventory of personal data processed
⚠️ By beginning to use the Platform, the Customer represents and warrants that the above obligations have been fulfilled. Administrative fines, damages or legal liability that arise from the Customer's failure to fulfil these obligations and that do not stem from OculaWork's own fault or from a breach of its obligations under this Agreement belong to the Customer. This provision does not extinguish OculaWork's own obligations as a data processor under the law and under this Agreement (see §7.0, §7.5, §9.3).
📄 Disclosure and Consent Texts Must Be Separate Documents: Under the KVKK Board's Principle Decision No. 2026/347 of 18.02.2026 — published in the Official Gazette and effective 24.03.2026 — where processing relies on explicit consent, the disclosure notice and the consent form must be presented as separate documents under distinct headings, each requiring its own separate declaration; combining or nesting the two into a single approval is treated by the Board as unlawful and is subject to administrative fines under Art. 12. The Customer must observe this separation when preparing the KVKK notices provided to its employees.
5.2 Obligations Under OSH Law
  • The Platform may be used in support of the employer’s OSH processes under Law No. 6331. Article 15 of that Law regulates the health-surveillance obligation; it cannot be read as making the Platform’s camera-based measurement mandatory (see §8.1)
  • A valid contract with an occupational physician must exist; Platform data does not replace mandatory medical examinations
  • Action plans and follow-up after risk detection are the Customer's responsibility
5.3 Technical and Usage Obligations
  • Prevent unauthorized third-party access to the system
  • Use the Platform solely for occupational safety purposes; do not use it for employee monitoring, disciplinary action or discrimination
  • Do not reverse-engineer or copy the Platform for competing products
  • Maintain current and accurate contact information throughout the contract period
06 OculaWork Obligations
6.1 Software Provider Role

OculaWork is a software provider and processes Customer data solely within the scope of this Agreement and the Customer's instructions. Data is not used for OculaWork's own benefit, third-party marketing, or any other purpose.

6.2 Security Commitments
  • All data transmission is encrypted via TLS 1.3; HTTP access is blocked
  • Firebase Firestore security rules enforce role-based access control (RBAC)
  • Camera footage is processed client-side; raw video is not transmitted to servers
  • Individual results are not displayed in the management panel; only aggregated statistics that have passed the thresholds in §11 are shown. Individual details are accessible only to the employee themselves and the authorised occupational physician
  • In the event of a security breach the Customer is notified without undue delay and in any event within 24 hours; notification to the KVKK Authority is made within the period the controller is subject to under applicable law
6.3 Sub-Processors
Sub-ProcessorPurposeData Location
Google Firebase FirestoreData storageEurope (eur3)
Google Firebase AuthenticationIdentity verificationEurope
Google Firebase HostingApplication hostingGlobal CDN
Google Cloud FunctionsBackend processingEurope
ResendSending credential/notification emails and forwarding mail received at info@oculawork.comUnited States. The provider states in its own documentation that its primary processing operations are carried out in the USA and that personal data may be transferred outside the EEA/UK/Switzerland. The email channel is therefore treated as part of the KVKK Art. 9 transfer chain (see §4.2). Data minimisation: no individual measurement result, fatigue/risk score, or health-related personal assessment is sent through this channel; management reports contain only aggregated data that has passed the thresholds in §11

OculaWork may engage sub-processors providing infrastructure, hosting, email, security, analytics or support services in order to deliver the Service. The current sub-processor list, processing purposes and data locations are set out above and are available to the Customer.

Changes requiring a new sub-processor to access personal data are notified to the Customer at least 30 days before they take effect. The Customer may object on justified and reasonable data-protection grounds; in that case the parties will discuss a reasonable solution in good faith.

🔗 Notification chain: where the Customer reaches OculaWork through an OSH service provider (OSGB) or another partner channel, notice of a sub-processor change is delivered to the party holding data controller status. Whether the partner in that channel acts solely as a commercial intermediary or additionally holds a role in the processing chain is expressly determined in the relevant partnership agreement.
6.4 Data Sharing

OculaWork shares Customer data with third parties only:

  • With Customer's explicit written consent
  • Where duly requested by a competent court or a legally authorized administrative body; OculaWork complies with such a request under applicable law and, unless legally prohibited from doing so, notifies the Customer within a reasonable time
6.5 Cooperation in Legal Proceedings

The parties agree to provide each other with reasonable assistance in official inquiries, audits, or judicial proceedings related to personal data or information security.

07 Personal Data Protection (KVKK / GDPR)
7.0 OculaWork's Obligations as Data Processor (Data Processing Terms)

In respect of employee-data processing carried out within the purposes and means determined by the Customer, the Customer is the Data Controller and OculaWork holds the status of Data Processor under KVKK Art. 3. For activities OculaWork carries out for its own purposes (account management, billing, security logs), its status is determined separately as set out in §7.5. In activities where it acts as processor, OculaWork:

  • Processes personal data only per the Customer's instructions and for the purposes stated in this Agreement; it does not process data for a different purpose on its own initiative (for anonymous/aggregate processing, see §7.4)
  • Maintains the confidentiality of personal data; binds personnel with data access under confidentiality obligations
  • Engages only those service providers identified in this Agreement and in the current sub-processor list in §6.3 (see §4.2, §6.3). Engaging a new sub-processor that requires access to personal data is subject to the prior notice and objection mechanism in §6.3
  • Assists the Customer in fulfilling employees' KVKK Article 11 requests (see §7.3)
  • Notifies the Customer without undue delay and in any event within 24 hours upon becoming aware of a security breach (see §9.3)
  • Returns or deletes data upon contract termination, per the Customer's instruction (see §4.3, §13)
  • Shares information and documentation demonstrating compliance with the data-processing commitments in this Agreement upon the Customer's reasonable request
7.1 Categories of Data Processed
CategoryExample DataPurposeLegal Basis
IdentityName, surnameAccount managementKVKK Art. 5/2-c — Contract performance
ContactEmail addressNotificationsKVKK Art. 5/2-c — Contract performance
Health / physiological indicatorEAR, PERCLOS, fatigue scoreOSH risk analysisKVKK Art. 6/3 — whichever condition applies on the facts (see §8.1); OSH Law Art. 15 is not a legal basis on its own
BehavioralReaction time, blink rateOSH risk analysisKVKK Art. 5/2-f — legitimate interest (subject to a balancing test carried out by the Customer); where the balancing test is not satisfied, explicit consent under Art. 5/1
OrganizationalDepartment, shiftReportingKVKK Art. 5/2-c — Contract performance
TransactionScan date/timeAudit trailKVKK Art. 5/2-f — Legitimate interest
Physician clinical noteIntegrity-protected clinical note the occupational physician writes about an employee (see §7.2, §9.4)Health-surveillance record integrityKVKK Art. 6/3 — whichever condition applies on the facts (see §8.1)
Survey responseThe employee's answer to a single-question survey published by managementOSH risk analysis (OwO input, see §7.4), reportingKVKK Art. 5/2-f — legitimate interest (subject to a balancing test carried out by the Customer); where the balancing test is not satisfied, explicit consent under Art. 5/1
Technical bug reportFree text written by the user + automatically captured browser error/device info (see §9.4)Diagnosing and fixing software issuesKVKK Art. 5/2-f — Legitimate interest
Notification/reminderDevice push token for instant notifications; the reminder note and time the physician sets for a specific employeeHealth-surveillance follow-up, system notificationsKVKK Art. 5/2-c — Contract performance / Art. 6/3
📷 Camera footage is not sent to servers. The video stream is processed exclusively in the user's browser (RAM). Only computed numerical values (EAR: 0.312, PERCLOS: 6.4%, etc.) are transmitted to servers.
7.2 Retention Periods
Data TypeRetention Period
Measurement metrics and reportsActive subscription + 2 years under our internal retention policy; statutory retention periods arising from applicable legislation and our retention-and-destruction policy are reserved
Account and identity data90 days after contract termination
Transaction logs6 months
OwO training samples (numerical feature vector + label containing no identity information or direct identifiers; anonymity is assessed separately — see §7.4)180 days — automatically deleted on every training run
Facial biometric template (faceEmbedding — for face verification)For the duration of the active subscription; deleted immediately and automatically when the employee requests data deletion or the account is closed
On-device learning model weights (federated_weights — see §7.4)For the duration of the active subscription; deleted when the employee requests data deletion or the account is closed. These weights may have previously been averaged (federated) together with other employees' models at the same company — deleting the individual document does not guarantee the mathematical trace of its contribution is fully removed from earlier aggregate averages
Physician clinical notesHealth-surveillance records created by the occupational physician are retained in line with the retention periods prescribed by applicable OSH legislation and KVKK's retention principles. The Directorate General of OSH (Ministry of Labour and Social Security) states that personal health files must be kept for at least 15 years from the employee's date of leaving employment. Records are held so that their integrity is preserved; retroactive alteration after writing is prevented (see §9.4). Deletion requests are assessed subject to any applicable statutory retention obligations
Alert/warning records, clinical verdict feedback, exam scheduling records, failed face-verification security logNOT automatically deleted by an employee's own "Delete My Data" request — retained deliberately, for the same reason as physician clinical notes (OHS/security audit-trail integrity). Deletion, if required, can be requested through admin at info@oculawork.com.
Bug reports and technical diagnosticsUntil manually deleted by OculaWork's admin
After deletion requestDestroyed within 30 days of request date (physician clinical notes excepted — see above)
💾 On backups: Data deleted from the active system may persist for some additional time in Google Firebase's own automatic infrastructure backups; this depends on Google's own backup cycle and is not under OculaWork's direct control. Data in backups is deleted automatically through the normal backup rotation process and is not kept permanently accessible or processable.
🗂️ On transaction logs: Application-level transaction logs contain, at minimum, the timestamp, the type of action, and the identity of the user who performed it; additional technical data such as IP address or device information may only be captured within Google Firebase's own infrastructure security logs, under Google's own policies. These logs are kept solely for security monitoring and troubleshooting purposes; access to them is role-restricted (see §9.4). Logs are maintained on a best-effort, append-only basis so that they are not modified during normal operation; however, this does not constitute a certified, forensic-grade integrity guarantee for independent evidentiary use. System logs use Turkey time (UTC+3).
🩺 Exception for physician clinical notes: A permanent clinical note the occupational physician writes about an employee (see §7.1, §9.4), in order to preserve the integrity of the health-surveillance record, cannot be edited or deleted by anyone once written — not the employee, not management, not the physician themselves, and not OculaWork's admin. This means the correction/deletion rights listed in §7.3 are limited for this data category; the Customer is responsible for clearly disclosing this exception in the KVKK notice provided to its employees.
7.3 Data Subject Rights (KVKK Art. 11)

Employees exercise their KVKK rights through their employer (Customer). OculaWork fulfills these requests upon Customer direction within 30 days:

  • The right to learn whether personal data is being processed
  • The right to request information about processing
  • The right to request correction of inaccurate data
  • The right to request deletion where conditions are met
  • The right to object to decisions made solely by automated processing
  • The right to seek compensation for damages from unlawful processing
7.3.1 Concrete Automated Processing Points (KVKK Art. 11/1-g)

For the objection right above to be exercised meaningfully, the Platform's automated/semi-automated processing points that may produce a result concerning an employee are identified explicitly: (i) the fatigue risk level produced by the daily scan (low/medium/high/critical), (ii) statistical anomaly-detection alerts based on CUSUM and Isolation Forest, and (iii) the sector-context score (owoContextScore, see §7.4) that the "OwO" sector-wide learning model produces, based on that scan's anonymous numeric profile, shown solely for informational purposes — all three are shown only to the occupational physician and none of them alone translates into an automated personnel decision. OwO's training data and model weights contain no identity information; they are identity-stripped data that has been subjected to technical and administrative measures aimed at anonymisation. The application of those measures does not, on its own, mean the data is legally anonymous; anonymity is assessed separately in light of the concrete circumstances (see §7.4). however, the sector-context score the consult layer produces for informational purposes is a scan-specific, informational indicator and constitutes processing point (iii) above. If an employee believes a risk level, an anomaly alert, or the sector-context score has been used as the sole basis for an adverse personnel decision concerning them (reassignment, discipline, etc.), they may object to their employer; the employer is responsible for ensuring such an objection is reviewed by a human (occupational physician/HR) before being acted upon.

7.4 Anonymous/Aggregate Processing and AI Model Training ("OwO")

Under KVKK Art. 3/1-d, personal data means any information relating to an identified or identifiable natural person. Data that has been irreversibly anonymized falls outside this definition, and KVKK provisions do not apply to it. OculaWork trains a sector-wide statistical learning model ("OwO") using scan and self-assessment data from Customers, regardless of whether they use shared or self-hosted infrastructure (see item 5 below); that training draws on numerical features that have been technically separated and minimised so as to contain no direct identity or company identifiers.

⚠️ Important — "no identity field" does not by itself mean "anonymous". The mere removal of direct identifiers does not mean the data constitutes anonymous data under KVKK in every case. Through the technical and organisational measures listed below, OculaWork aims to reduce the risk of re-identification; whether a given dataset qualifies as anonymous is assessed separately in light of the concrete circumstances. Processing carried out before anonymisation is achieved remains within the scope of KVKK.

This processing is limited by the following technical and legal safeguards:

  1. Identifying information (name, surname, email, employee ID) is never included as model input or associated with model output in any way.
  2. Free-text fields (health history, medication/allergy/illness anamnesis) are never read, processed, or stored; only a binary (present/absent) indicator of whether the field was filled in is used.
  3. Mental-health and attention/alertness self-assessment results (GAD-7, PHQ-9, CBI, WHO-5, Epworth, Karolinska, PSS-4, a reaction-time-based alertness test, a breathing/calming exercise module, and the self-rated accuracy feedback on the character/personality test) are used only as a reduced total-severity score or a binary (yes/no) accuracy indicator. These reduced numeric scores may be included, as a purely numeric vector carrying no identity or company information, in OwO's training samples (a {0-1 numbers} vector plus a single 0/1 label) and retained for the 180-day period stated in §7.2; however, the raw/free-text answers behind these scales, or the underlying test record itself (see §9.4 — the personalCoach record, accessible only to the employee themselves), are never sent to or stored by OwO at any stage of this processing. The PHQ-9 item that screens for self-harm risk (item 9) is entirely excluded from this process and is used only for the employee's unconditional crisis-resource routing.
  4. The final output of this processing consists solely of numerical model weights formed by statistically blending thousands of data points; it is not technically possible to reconstruct a specific employee's identity or answers from this output.
  5. Where OwO runs, by deployment model. This item applies differently depending on which deployment model the Customer selects:
    • (a) Self-hosted Firebase deployment. The Customer sets up its own Firebase project. Identity data (email, password hash, role, tenant assignment) is held in OculaWork's central Firebase project, and OwO's consult function runs in that central project. Operational data (scan and self-assessment results) remains in the Customer's own cloud project; only the part that must enter this processing (the identity-stripped numeric profile defined in items 1-3) is transmitted to the central project momentarily and transiently, and is never permanently stored together with identity.
    • (b) Enterprise (on-premise) deployment — layered model. The Customer runs the Platform on its own server. Routine evaluation — risk level, threshold classification and anomaly detection — is performed entirely on the Customer's own server and requires no connection to OculaWork. In this processing, no individual employee data is transmitted to OculaWork's central infrastructure, including the individual numeric profile defined in items 1-3.

      By contrast, OwO's psychosocial evaluation layer, which relies on sector-wide comparison, runs at OculaWork's centre and is invoked only with aggregated input: sector code, an employee-count band (not an exact figure), distributions derived from at least 50 measurements, and the noise scale applied. This transmission contains no individual record, identity, department name, free text or timestamp; every cell below the threshold is suppressed (set to zero) before transmission. This channel is likewise off by default. Where OculaWork's central infrastructure is unreachable, this layer is disabled and routine evaluation continues uninterrupted on the Customer's server (see APP-0.3.3).

      A model-development contribution may additionally be sent, again only where the Customer has expressly enabled it (default: off); it carries only the four fields listed in the allowlist in APP-0.3C (modelSurumu, ornekSayisi, gradyan, gurultuOlcegi) and is not generated unless derived from at least 50 measurements, with privacy-enhancing noise applied and its magnitude capped. Every field outside the allowlist is rejected server-side. Identity data likewise remains within the Customer's own infrastructure. The application of these techniques does not mean the data reaching the centre is legally anonymous; anonymity is assessed separately in light of the concrete circumstances.
    In both models, the safeguards in items 1-4 and 6-13 apply unchanged. In the enterprise deployment, the application of privacy-enhancing techniques does not mean the contribution reaching the central infrastructure is legally anonymous (see APP-0.3C); anonymity is assessed separately in light of the concrete circumstances.
  6. No human user — including management, the employer, or OculaWork personnel — has access to the raw data subject to this processing (the free-text and raw test answers referenced in items 2 and 3); access is limited to the automated processing function, and is instantaneous and transient.
  7. OwO's output, as described in items 4 and 7, is solely a single set of sector-wide model weights — no readable sub-statistic broken down by sector, company size, or any other grouping is produced. This structurally limits the risk of singling out any one small company or employee group even absent a separate k-anonymity threshold; nonetheless, for large-scale, automated processing involving special-category data of this kind, conducting a Data Protection Impact Assessment (DPIA-equivalent) is recommended as good practice. This assessment has not yet been formally completed; a preparation process can be initiated for Customers who request it.
  8. The sector-context score produced by OwO may be presented alongside any scan result solely as an informational, supplementary indicator; this score does not replace or alter the existing rule-based risk level (see §7.3.1). Externally sourced, documented information — such as academic scales or known medical/physiological fatigue factors — may also be added by OculaWork to OwO's training as a limited, low-weight calibration; such external information is likewise anonymous and general/statistical in nature, not specific to any individual employee or event.
  9. Company-Internal Survey Signal: An employee's answer to a single-question, two-option survey published by Customer management may be converted into a binary (0/1) signal — management decides in advance which answer counts as "positive" — and included in OwO's training vector. The survey itself and the employee's answer remain visible, with identity, in the Customer's own management panel (see §9.4); only this derived 0/1 signal is transmitted to OwO, subject to the same de-identification rules as items 1-3.
  10. Physician's Clinical Verdict Feedback: An occupational physician may rate a scan's algorithmic risk level as "accurate / higher than warranted / lower than warranted / referral needed / follow-up." Like item 3 above, this assessment — together with that scan's identity-stripped numeric profile — may be included in OwO's training samples as a corrected label; this does not alter the guarantee in item 1 that identity is never included as model input — the physician's assessment only corrects the OUTCOME label (high-risk or not) of that scan, identity is still never sent to OwO. The physician's assessment itself (and which scan, and therefore which employee, it relates to) continues to be stored, with identity, in the Customer's own tenant (see §7.1, §9.4) — only the derived signal sent to OwO is anonymized.
  11. Character–Role Fit Index: The Customer's management panel never has access to any employee's individual Character Analysis result (this data is accessible only to the employee themselves; see §9.4). Instead, once at least 10 employees have completed the Character Analysis, a single aggregate percentage (the share of employees showing academically verified traits associated with safety behavior/fatigue resilience) and a statistical confidence value are shown; below this threshold the statistic is fully hidden. No individual result, name, or identity is ever visible or reverse-derivable at any stage of this statistic.
  12. Feedback Loop: Alongside any information OwO produces (sector context, drug sedation match, Character–Role Fit Index), the user viewing it (physician/management) may optionally submit "was this useful" feedback (👍/👎). This feedback is never linked to any identity — only the type of information (e.g., "sector context") and whether it was helpful is recorded; which scan/employee/user it relates to is never stored. The accumulated feedback ratio feeds into the confidence percentage OwO displays for that type of information; this data cannot be read by anyone (including admin) — only the aggregate ratio is computed server-side.
  13. Shared Knowledge Pool: OwO's consult layer (owoConsult), drug consult (owoDrugCheck), and Character–Role Fit Index (getCharacterFitStats) all draw on the same pool of external knowledge sources (owoExternalFactors). This means a new, genuinely relevant factor added to this pool can automatically contribute — as a low-weight, aggregate, anonymous indicator only — at every point it is relevant to, without any additional software change. This automatic contribution is always low-weight and bounded; it never single-handedly determines a final result or replaces the existing rule-based/academic-threshold calculations at any point.
OwO Transparency: The full technical detail of this processing — including which data source is reduced to which signal — is documented in the OculaWork Technical Methodology Document (in the section titled "OwO Training Model") and is available to the Customer and data subjects upon request.
⚖️ Customer Responsibility: By accepting this Agreement, the Customer agrees to include this anonymous/aggregate processing and model-training purpose in the KVKK disclosure notice provided to its employees. OculaWork relies on the Customer's representation that this notice has been provided; any legal consequences arising otherwise are the Customer's sole responsibility.

KVKK legislation and Board precedent may change over time. In the event of a regulatory change, the parties will cooperate in good faith, within a reasonable time, to bring this Agreement and related practices into compliance with the updated legislation.

7.5 Data Protection Roles of the Parties

In respect of the measurement activities carried out through the Platform in relation to employees, to the extent that the Customer determines the purposes and the essential means of processing, the Customer acts as data controller and OculaWork as data processor acting on the Customer's behalf.

In respect of separate processing activities that OculaWork carries out for its own purposes (such as its own customer account and subscription records, billing, support, its own marketing communications, and its own security logs), the status of data controller or data processor is determined separately for the activity concerned.

The status of the parties is assessed not merely by the label used in the contract, but by the actual nature of the specific processing activity and by who determines the purposes and means.

🏢 In an enterprise (self-hosted) deployment: the fact that data resides on the Customer's own infrastructure does not by itself place OculaWork outside the scope of KVKK. Which party bears responsibility for access, authorisation, backup, security and system administration in respect of data held on the Customer's own infrastructure is determined separately in the Enterprise Deployment/Order Form (see APP-0).
7.5.1 Activity-Based Role Table

Status varies according to who determines the purposes and means of the activity. The table below is not a binding summary but an interpretive guide; the factual position governs in a specific case.

ActivityPurposeRole
Employee measurement and reportingSupporting OSH processesCustomer controller · OculaWork processor
Customer account and subscription managementProvision of the serviceOculaWork controller
Billing and accountingLegal obligationOculaWork controller
Support request handlingProvision of the serviceDetermined separately by the content of the request
Security and audit logsSystem securityOculaWork controller
Model development contributionSector modelSeparate legal assessment (see §7.4, APP-0.3C)
08 Sensitive Data — Health and Biometric

Depending on the nature of the processing, EAR, PERCLOS and fatigue scores may fall to be assessed as sensitive personal data under KVKK Article 6, in which case they require additional protection.

8.1 Legal Basis

The processing of sensitive personal data relies on whichever of the conditions set out in KVKK Art. 6/3 is applicable to the specific case. Explicit consent is only one of those conditions; the structural power imbalance in the employment relationship and the necessity and proportionality of the processing are assessed separately.

  1. Explicit consent (KVKK Art. 6/3): Written or electronic consent obtained from the employee — specific, informed, freely given and revocable. Explicit consent is not an automatic, general legal basis for every processing activity.
  2. Employment and OSH obligation (KVKK Art. 6/3-f): Conditional upon the processing being necessary for the fulfilment of legal obligations in the fields of employment and occupational health and safety.
⚖️ Regarding Art. 15 of Law No. 6331: That provision imposes health-surveillance obligations on the employer; however, it cannot be construed as a provision that makes OculaWork's camera-based measurement method mandatory in any workplace. The existence of Art. 15 therefore does not mean that use of the Platform is automatically "necessary" within the meaning of KVKK Art. 6/3-f. The applicable legal basis is determined by the Customer, taking into account its specific processing purpose, the relevant legislation, and the necessity and proportionality of the processing.
⚖️ Customer's Responsibility: Regardless of which legal basis is chosen, the Customer is responsible for notifying employees and obtaining explicit consent where required. OculaWork relies on the Customer's representation that these steps have been completed. Legal consequences of non-compliance belong exclusively to the Customer.
8.2 Facial Biometric Identity Verification — Additional Notice

The Platform's optional facial biometric (face-embedding) feature used for login/identity verification is a distinct risk category from fatigue-scan metrics (EAR/PERCLOS etc.): it is a biometric identity capture mandated by the employer directly. In its Decision No. 2022/797 of 04.08.2022, the KVKK Board found facial-recognition-based entry/exit tracking unlawful for lacking any valid processing condition under Art. 6; more significantly, in its Principle Decision No. 2026/921 of 29.04.2026, the Board held that biometric data processing for attendance-tracking purposes is unlawful even where the employee's explicit consent has been obtained — reasoning that the structural power imbalance in the employment relationship undermines whether such consent is truly "freely given." That principle decision concerns biometric identification for attendance-tracking purposes and does not apply directly to the Platform's fatigue measurement; it nonetheless reflects the Board's current approach that employee consent is not automatically a safe harbour in every case. Accordingly, relying on explicit consent alone may not by itself render biometric processing lawful. Before enabling this feature, the Customer should assess (i) proportionality, necessity, and data minimization, (ii) whether a less intrusive alternative (e.g., encrypted card/PIN, RFID/NFC ID card, or device binding) would suffice, and (iii) consult its own legal counsel. OculaWork does not perform this assessment on the Customer's behalf and assumes no legal risk in this regard.

09 Data Security
9.1 Technical Measures
  • All data transmission encrypted via TLS 1.3; HTTP access is blocked
  • Firebase Firestore security rules enforce role-based access control (RBAC)
  • Camera footage is processed client-side; raw video is not transmitted to servers
  • Firebase Authentication manages sessions; token lifespan 1 hour
  • Management panel shows only aggregated department statistics that have passed the thresholds in §11
  • Access to the OculaWork admin panel is protected by two-step verification consisting of a password and a separate security-question answer; the security question is periodically rotated
9.2 Infrastructure Security Certifications (Google Firebase)
  • ISO/IEC 27001 Information Security Management System
  • SOC 2 Type II
  • Data centers are governed by Google's own security and data-processing terms; OculaWork does not separately warrant Google's legal compliance
ℹ️ Clarification: The certifications above (ISO/IEC 27001, SOC 2 Type II) belong to the Google Firebase infrastructure. OculaWork itself does not currently hold an ISO/IEC 27001 or similar information security management system certification.
9.3 Breach Notification

Where OculaWork becomes aware of an event that may affect the security of personal data, it will notify the Customer in writing without undue delay and in any event within 24 hours. This contractual notification period does not alter the parties' statutory notification deadlines under KVKK and other applicable legislation (including the controller's obligation to notify the Board under KVKK Art. 12/5). The Customer is likewise obligated to notify OculaWork without delay upon becoming aware of a security incident on its own side (its own accounts, network, or systems) that could affect Platform data.

9.4 Role-Based Access Table
RoleData AccessibleData Not Accessible
EmployeeOnly their own scan results, their own AI Life Coach content, their own periodic self-screening record, their own survey answerAny other employee's data; clinical notes the physician has written about them; their own submitted bug reports and technical diagnostics (visible only at the moment of submission, thereafter accessible only to OculaWork's own admin)
Management / HRDepartment-level anonymous/aggregated statistics (min. 5-person groups), personnel/exam management, individual survey answers, the Character–Role Fit Index (an aggregate statistic — a single percentage and confidence value — shown only once at least 10 employees have completed the Character Analysis; see §7.4)Individual scan detail, AI Life Coach content (GAD-7/PHQ-9/CBI, including any individual Character Analysis result), periodic self-screening anamnesis, bug reports/technical diagnostics
Occupational PhysicianIndividual health-surveillance/scan data within their own tenant, TİTCK drug matching, periodic self-screening anamnesis, official exam records, their own permanent clinical notes (see §7.1, §7.3 — indefinite retention, cannot be edited or deleted), their own clinical-accuracy feedback on scansEmployee's AI Life Coach content (GAD-7/PHQ-9/CBI, Calm Down, Character) — closed to the physician as well; bug reports/technical diagnostics
OculaWork AdminTenant/subscription management, anonymous Data Pool statistics, Module Usage Dashboard (counts only), OwO training history (weights/scores only), bug reports and automatically captured technical diagnostics from all users (see §7.1) — never shared with the reporting user's own employer (management/physician)Any employee's individual data, AI Life Coach content, anamnesis free text, the content of physicians' clinical notes — see §7.4
9.5 Audit Right

To fulfill its Data Controller obligations under KVKK, the Customer may request information and documentation regarding OculaWork's data processing practices. OculaWork will provide such information at a reasonable frequency and upon at least 15 days' prior written notice, without disclosing its own trade secrets or information belonging to other Customers. On-site audits or independent third-party audits are possible only under scope, duration, and confidentiality terms agreed in writing in advance by both parties; unless otherwise agreed, audit costs are borne by the requesting Customer.

9.6 Responsible Disclosure

Anyone who identifies a security vulnerability on the Platform may report it only to info@oculawork.com, under the principles of Responsible Disclosure. Active penetration testing, load testing, fuzzing, or similar activity carried out without OculaWork's prior written consent is not covered by this provision and remains subject to the Prohibited Uses clause in §11.1.

10 Limitation of Liability and Disclaimers
10.1 Medical Decision Liability
⚕️ Under no circumstances do Platform outputs substitute for medical diagnosis or clinical decisions. OculaWork cannot be held liable for employment restrictions, role changes or disciplinary decisions made based on Platform data.
10.2 General Liability Cap

Should OculaWork incur liability for any reason, its total liability is limited to the subscription fees paid in the 12 months preceding the breach. This limitation does not apply in cases of willful misconduct, gross negligence, intellectual property infringement, or breach of confidentiality/data-security obligations.

10.3 Exclusions from Liability
  • Fines and damages arising from Customer's failure to fulfill KVKK obligations
  • Administrative and legal sanctions from failure to obtain employee explicit consent
  • Legal consequences of personnel decisions made solely on the basis of Platform data
  • Data breaches resulting from Customer sharing credentials with unauthorized persons
  • Force majeure (natural disaster, war, government decision, cyberattack, power outage, internet backbone failures, internet service provider/DNS/DNSSEC/CDN outage, root certificate issues, global internet outage, cloud infrastructure provider outage, unexpected changes to browser or camera API policies by platform providers such as Apple/Google/Microsoft, or outage of third-party AI service providers)
  • Indirect, unforeseen or punitive damages; this specifically includes loss of revenue, loss of profit, loss of reputation, loss of business, and loss of data attributable to the Customer's own backup obligations, the Customer's own infrastructure, or third-party infrastructure — no compensation is paid for these items. Losses arising from OculaWork's own fault or from the carve-outs listed in §10.2 (including a data-security breach) fall outside the scope of this provision. (except for the willful misconduct/gross negligence/IP/confidentiality carve-outs stated in §10.2)
  • Outages or data loss attributable to Google Firebase / Google Cloud infrastructure

Neither party shall be liable for failure to perform its obligations under this Agreement for the duration of, and to the extent directly caused by, a force majeure event.

10.4 Indemnification for Employee Claims

If any employee files a claim against the employer (Customer) related to Platform data, OculaWork is not a party to that dispute. The Customer agrees to indemnify OculaWork and cover any resulting costs.

10.5 Account Security

The user is personally responsible for all actions taken from their own account. If a password is shared with a third party, all resulting consequences (including data access, unauthorized transactions, or data breaches) are the responsibility of the sharing user and/or the Customer; OculaWork cannot be held liable for this. User accounts are personal to the individual user; shared use of an account by multiple people constitutes a license violation, and OculaWork reserves the right to suspend the account in such a case.

10.6 Insurance

OculaWork does not carry professional liability (errors & omissions) insurance or any other insurance coverage for the services under this Agreement.

10.7 No Warranty

Except as expressly stated in this Agreement, the Platform is provided "as-is" and "as-available." OculaWork makes no express or implied warranty that the Platform will operate uninterrupted, error-free, or entirely free of security vulnerabilities, or that it will be fit for a particular purpose, merchantable, or meet the Customer's expectations.

10.10 Evacuation Drill Module — Floor Plan, Spatial Audit and Scores

The Evacuation Drill module is a decision-support tool that produces spatial audit findings, a requirements list, scenarios and drill records on a floor plan drawn by the Customer. No output of the module — including findings, requirements, the OHS Compliance Score, the Risk Score or any drill report — constitutes a certificate of compliance, a fire-safety design, an approved escape plan or an official inspection report, and none of them alone forms a legal basis before the competent authorities.

Responsibility for inputs rests with the Customer. The building outline, room dimensions, clear door widths, floor occupancy, facility type and equipment positions are entered by the Customer; OculaWork does not and cannot verify that this information matches the actual structure. Outputs are valid only to the extent that the entered data is accurate. OculaWork cannot be held liable for results arising from incorrect or incomplete measurements.

Measurement and regulatory limit are distinct. The system always displays the measurements it computes from the plan; by contrast, it states a numeric limit from a regulation only where the source can be verified. Where the source cannot be verified, no limit is stated, the measurement is given and the Customer is asked to confirm it; such items are also excluded from the score. Determining factors such as hazard class, building use class, the presence of sprinklers, building height and the building permit are not known to the system and may change the outcome.

The OHS Compliance Score and Risk Score are estimative indicators. They cover only the items the system can check; the weighting method is a design choice that OculaWork declares openly and does not derive from regulation. A high compliance score does not mean regulatory compliance; a low risk score does not mean a safe workplace. The final compliance assessment rests solely with the employer and the occupational safety specialist / occupational physician they appoint.

Drill records and the attendance ledger. Behavioural records collected during a drill (the route drawn, duration, efficiency, answers) contain no identity and are reported only in aggregate; they may not be used to measure individual performance. The attendance ledger does contain identity for administrative purposes and is never merged with the behavioural records. The attendance record produced by the module does not by itself constitute proof that the drill obligation under Law No. 6331 Art. 11 and the Emergency Situations Regulation has been fulfilled; an official drill report depends on the drill actually being carried out on site and duly recorded by the employer.

Scenarios generated by the module (fire, gas leak, chemical spill, etc.) are constructs for training and awareness; they do not constitute an engineering prediction of how a real incident would develop, nor a fire model or smoke-propagation simulation.

Anonymous transfer of compliance and risk scores. When a floor plan is saved, the OHS Compliance Score and Risk Score computed from that plan, together with derived measures of the plan (area, counts of rooms, doors and equipment, audit finding codes), are transferred to the OculaWork server and used for sector-level comparison. This transfer contains no data relating to any natural person; no identity, name, user id or department is sent. The data relates to a floor plan, not to a person, and therefore does not constitute personal data within the meaning of Law No. 6698.

The plan name is not sent. The name you give a floor plan is free text and may contain the name of the workplace, building or floor; it is transmitted to the server neither as it is nor as a hash. So that records of the same plan can be related to one another over time, a random identifier with no content is generated and stored only in your browser; the link between that identifier and the plan name never leaves your device. A plan with the same name receives a different identifier on a different device.

The transferred data is commercial information belonging to your workplace. A k-anonymity threshold is applied in sector-level comparisons to prevent an individual workplace from being re-identified; no comparison is shown for groups below the threshold. The module can also run standalone: in that case no data is transferred and all records remain solely on your device. The transfer is not retroactive — only records made while the transfer is active are sent.

10.11 Drill Attendance Ledger — Notice and Retention

This clause applies to the attendance ledger of the Evacuation Drill module. The attendance ledger is the only record in the module that contains identity; the behavioural records collected during a drill (route, duration, efficiency, answers) contain no identity and are never merged with this ledger.

Controller and processor. The controller of the attendance record is the employer; OculaWork hosts this data as a processor acting on the employer's instructions.

Data processed. Only the following are stored on the server: the worker's user id (uid), the date of the drill and the attendance status (completed / left unfinished / time expired). Name, surname and department are not written to the server — they already exist in the worker record, so no second copy is created. This ledger contains no route, score or answer; the system also rejects such fields technically.

Purpose and legal basis. The data is processed to evidence fulfilment of the drill obligation under Occupational Health and Safety Law No. 6331 and the Regulation on Emergency Situations in Workplaces. The legal basis is compliance with a legal obligation of the controller under Art. 5/2-ç of Law No. 6698; explicit consent is therefore not required. The data may not be used to measure individual performance.

Retention and erasure. The attendance record is retained for the period during which the employer is obliged to keep OHS records under the applicable legislation; upon expiry it is erased or anonymised. Determining that period and recording it in the personal data inventory is the employer's responsibility.

Transfer. The attendance record is not transferred to third parties and is not included in the anonymous dataset OculaWork uses for sector-level comparison (see 10.10).

Your rights. Under Art. 11 of Law No. 6698 you have the right to access your data, to request its correction or erasure and to object to its processing. You may address your request to your employer.

This text accurately describes the data the system actually processes and its technical limits; preparing the workplace-specific privacy notice and personal data inventory, and verifying legal compliance, rests with the employer.

10.9 OculaLearn — Liability for OHS Training Content

OculaLearn is a remote occupational health and safety (OHS) training module, hosted on separate Firebase infrastructure (oculalearn.web.app), based on the Annex-1 (Ek-1) curriculum of Turkish Law No. 6331 Art. 17 and the "Implementation Guide for Employees' Occupational Health and Safety Training" (Official Gazette No. 33212, April 2, 2026). OculaWork is responsible for the content and accuracy of the official Annex-1 curriculum. The accuracy, currency, and regulatory compliance of any workplace-specific Topic-4 content and/or fully custom additional trainings entered by the Customer via the "Develop Content" interface is the Customer's sole responsibility; such content is only recorded after the Customer accepts a mandatory liability acknowledgment (with identity, timestamp, and IP address logged) prior to saving. This custom content is never counted toward the official 60/100 pass score or the certificate — only the official Annex-1 curriculum is scored and certified. OculaWork cannot be held liable for any legal, administrative, or criminal consequence arising from Customer-entered custom content.

11 Intellectual Property
11.1 OculaWork's Property

The Platform's software, source code, algorithms, design and brand are the exclusive intellectual property of OculaWork. Customers are granted a non-exclusive, revocable, limited, worldwide usage license scoped to their subscribed number of users. This license may not be transferred, rented out to another company, or sub-licensed; the Platform may not be copied or reverse-engineered under any circumstances. The license is valid only for the number of active users (seats) actually purchased/subscribed to; if usage exceeds the licensed quota, the Customer will be asked to purchase additional seats. If the licensed number of users is systematically exceeded, OculaWork may retroactively invoice for the excess usage or suspend the account. This Agreement does not transfer any right in the OculaWork brand, trade name, algorithms, or any pending patent applications to the Customer.

🚫 Prohibited Uses: The following activities are strictly prohibited on the Platform: automated data collection (scraping), bot usage, unauthorized automation or API-like access, API abuse, rate limit bypass attempts, credential stuffing, account/credential sharing, spam, unauthorized load testing, model extraction, weight extraction, model stealing, parameter inference, AI prompt extraction, fine-tuning attacks, membership inference attacks, decompiling or disassembling the source code or model output, unauthorized benchmarking, and — without OculaWork's prior written consent — security scanning, penetration testing, fuzzing, or denial-of-service (DDoS) attempts. Violation of this provision results in immediate, uncompensated termination of the license.
11.2 Customer Data Ownership

Raw scan results and reports belonging to the Customer and its employees remain the Customer's property. OculaWork processes this data solely within the scope of this Agreement; anonymized and aggregated statistics may be used for Platform improvement.

11.3 Open Source Software

The Platform may incorporate third-party open source software. License rights to such software belong to the respective license holders. Use of open source components does not diminish OculaWork's intellectual property rights under this Agreement.

11.4 Trademark Use

The Customer may not use OculaWork's brand, logo, or trade name for advertising, reference, or promotional purposes without OculaWork's prior written consent.

11.5 Reference Customer

Unless otherwise agreed in writing, OculaWork may use the Customer's trade name solely in its reference customer list. The Customer may withdraw this permission at any time by written notice.

12 Subscription, Payment and Cancellation
  • The Platform is offered on a monthly or annual subscription basis; current pricing is published at oculawork.com
  • New Customers are granted a 15-day free trial period; if no paid subscription is started by the end of the trial, the account is automatically frozen and no payment card is required
  • OculaWork reserves the right to change its published pricing; price changes are communicated to the Customer at least 30 days in advance. The new price takes effect only from the next renewal period onward; it is never applied retroactively to an already-paid, ongoing subscription period of an existing Customer
  • Payments are collected in advance at the start of each period; VAT and applicable taxes are included on invoices
  • In the event of late payment, late-payment interest may be charged on the overdue amount at the commercial default interest rate prescribed under Turkish Commercial Code No. 6102 and applicable law; this is in addition to, not in lieu of, the 15-day cure process described in §13.3
  • New taxes, fees, or similar financial obligations resulting from changes in tax law may be passed through to pricing from their effective date
  • Cancellation notice must be provided in writing at least 15 days before the end of the period
  • Prepaid subscription fees are non-refundable; no partial refund is given for the unused portion of a period upon cancellation/termination
  • This Agreement governs a B2B relationship; consumer withdrawal rights do not apply
  • The Platform is ad-free.
13 Termination
13.1 Temporary Account Suspension

Before terminating the Agreement, OculaWork reserves the right to temporarily suspend the Customer's account in the following cases: (i) the Platform or its infrastructure is under an active cyberattack, (ii) suspected unauthorized access/misuse originating from the account, (iii) payment delay (see §13.3), (iv) API abuse, bot traffic, denial-of-service (DDoS) attempts, unauthorized automation, or an unusually high volume of requests (see §11.1 Prohibited Uses). In case (iv), the account may be suspended without prior notice in order to protect the integrity of the Platform or of other Customers. During suspension, access to Customer data is temporarily restricted but not deleted; access is restored once the situation is resolved.

13.2 Ordinary Termination

Either party may terminate the Agreement with 30 days' prior written notice.

13.3 Termination for Cause

OculaWork reserves the right to terminate immediately and without compensation in the following cases:

  • Persistent and clear violation of KVKK by the Customer
  • Use of the Platform for illegal purposes
  • Payment delay — the Customer is given a 15-day written cure notice; if payment is not made or the delay is not remedied within this period, the account may be suspended and/or the Agreement terminated
  • Actions threatening the security of the Platform
13.3.1 Service Suspension Due to Legal Requirement

Where a competent court order exists, or where an administrative/legal regulation legally requires it, OculaWork may partially or fully suspend/remove the Platform. To the extent this arises from a legal requirement outside OculaWork's control, it is treated as an exclusion from liability under §10.3.

13.4 Post-Termination Data Management
  • Customer may export their data within 90 days of contract termination
  • After 90 days, all personal data is permanently and irreversibly deleted, confirmed in writing to the Customer
  • The license automatically terminates upon expiration of the subscription; the Customer and its employees lose access to the Platform from that date
14 Cookie Policy

As of today, the Platform does not set a classic HTTP cookie; the following technical storage mechanisms are kept in the browser's local storage (localStorage):

MechanismPurposeTypeDuration
ow_langLanguage preferenceFunctionallocalStorage (persistent)
Firebase Auth TokenSession managementEssential1 hour
"Remember Me" token and per-role remembered-email keysRemembering the session/email for the next loginFunctionallocalStorage (until logout/reset)
Device-pairing (biometric login) keyRemembering that this device was previously paired for biometric loginFunctionallocalStorage (until reset)
Notification preference and device push-token keysRemembering the notification on/off preference and delivery addressFunctionallocalStorage (persistent, until disabled)
Firm code / last-connected tenant cacheRouting the login screen to the correct firm for self-host tenantsFunctionallocalStorage (persistent)
App version and scan cacheShowing the last known data during offline/delayed connections, update checksFunctionallocalStorage (persistent, until updated)
✅ The Platform uses no analytics, advertising or third-party tracking cookies. Google Analytics or similar tracking tools are not integrated. The Platform may use technical storage mechanisms (cookies and/or localStorage) required for its operation; these mechanisms are used solely for service functionality, not for tracking or advertising purposes.
15 Contact and Requests
SubjectContact
Data protection requests / Data deletioninfo@oculawork.com
Technical supportinfo@oculawork.com
Legal noticesinfo@oculawork.com
Security vulnerability disclosureinfo@oculawork.com

Data protection requests are responded to within 30 days. To file a complaint with the Turkish Personal Data Protection Authority: kvkk.gov.tr

15.1 Notice

Notices sent to the email address provided by the parties under this Agreement are deemed delivered on the date sent. The Customer is responsible for keeping its contact information up to date. A message being routed to the recipient's spam/junk folder results from the recipient's own email provider filtering settings; OculaWork cannot be held liable for this. The parties are obligated to notify each other in writing of any change to their contact information within 7 days; the party that fails to do so is responsible for any consequences arising from the failure.

15.2 Invoicing

Invoices are issued as e-Invoice or e-Archive Invoice, as permitted by applicable regulations, and are sent and deemed delivered via email.

16 Governing Law and Jurisdiction
  • This Agreement is governed by the laws of the Republic of Turkey
  • KVKK Law No. 6698, OSH Law No. 6331, Commercial Code No. 6102, and Code of Obligations No. 6098 apply to disputes
  • Ankara Courts and Enforcement Offices have exclusive jurisdiction over disputes
  • Invalidity of any provision does not affect the remaining provisions (severability); the invalid provision shall be replaced, to the extent possible, with a lawful provision that most closely reflects the commercial purpose and intent the parties sought to achieve with that provision
  • OculaWork reserves the right to update this Agreement with 30 days' prior notice
  • Claims arising from this Agreement are subject to the statute of limitations periods prescribed by applicable law
16.1 Export Controls and Sanctions

The Customer represents and warrants that it will not use the Platform in violation of applicable export control and sanctions laws of Turkey or of international bodies/jurisdictions such as the United Nations, European Union, or United States; and that it will not access the Platform on behalf of a person/entity on a sanctions list or from a sanctioned country.

16.2 Assignment

The Customer may not assign this Agreement without OculaWork's prior written consent. In the event of a merger, share transfer, asset sale, or similar corporate restructuring, OculaWork may assign this Agreement and the rights and obligations arising from it to a third party, provided the Customer is notified in advance.

16.3 Order of Precedence

In the event of a conflict between the text of this Agreement and its appendices (Appendix-1 Data Processing Agreement, Privacy Policy, KVKK Disclosure Notices, Consent Form), the following order of precedence applies: (i) Appendix-1 Data Processing Agreement (solely with respect to data-processing provisions), (ii) the main text of this Agreement, (iii) other appendices and separate documents. Notices are given in Turkish unless otherwise specified; in the event of a conflict between the TR/EN texts, the Turkish text prevails.

16.4 Evidentiary Agreement
📋 The parties agree that timestamped system logs, access logs, Google Firebase records, and electronic communications between the parties (including email) constitute an evidentiary agreement under Article 193 of the Turkish Code of Civil Procedure (HMK). OculaWork aims to maintain electronic records in accordance with reasonable security standards; however, it does not guarantee that all historical logs will be preserved indefinitely, due to technical failures, statutory deletion obligations, or the destruction carried out at the end of the retention periods specified in §7.2. Records of evidentiary value are retained only for the applicable retention periods.
16.5 Indemnification
🛡️ The Customer agrees to indemnify OculaWork and cover its defense costs (including attorney fees) against any third-party claim, lawsuit, administrative fine, or damage arising from: (i) the Customer's breach of its KVKK obligations, (ii) an employee filing a claim/lawsuit against OculaWork related to Platform data, (iii) a data breach resulting from the Customer's own fault, (iv) the Customer's failure to obtain the necessary explicit consent from its employees, or (v) use of the Platform in violation of this Agreement. OculaWork will use reasonable efforts, to the extent within its own control, to mitigate any resulting damages.
16.6 Confidential Information

Each party agrees not to disclose to third parties, and to use solely for the performance of this Agreement, the other party's trade secrets, pricing information, algorithm and software architecture details, customer/employee lists, and other information expressly marked as confidential that it learns of or gains access to under this Agreement. This obligation does not extend to information that is publicly available, must be disclosed under legal requirement, or is independently developed; it survives termination of this Agreement for a reasonable period.

16.7 Waiver

A party's failure to exercise, or delay in exercising, any right arising from this Agreement in a given instance does not constitute a waiver of that right, whether in that instance or in any future instance of the same or a similar nature.

16.8 Entire Agreement

This Agreement and its appendices (Appendix-1 Data Processing Agreement, together with the other documents referenced in §16.3) constitute the entire agreement between the parties regarding their subject matter and supersede all prior written or oral discussions, proposals, and agreements on the same subject. This Agreement may only be amended in writing by OculaWork (see the update-notice provision in §16).

16.9 Survival

Regardless of the reason this Agreement terminates, provisions that by their nature are intended to remain in effect after termination continue to survive; these include, in particular, Confidential Information (§16.6), Intellectual Property (§11), Indemnification (§16.5), the personal-data-protection provisions (§7), and the Evidentiary Agreement (§16.4).

Beginning to use the Platform indicates that you have read and accepted this Agreement in its entirety. Electronic acceptance given through the Platform, while not constituting a qualified/secure electronic signature, is deemed a binding acceptance of this Agreement between the parties. An employee's acknowledgment of the Disclosure Notice and their Explicit Consent declaration are recorded, at the moment given, in a separate log with the user's identity, a timestamp, and browser information, which cannot subsequently be modified (create-only permissions; no update or delete access is granted to anyone) (see §16.4). This log does not contain an IP address — IP address may only be captured within Google Firebase's own infrastructure security logs, under Google's own policies (see §7.2). For questions: info@oculawork.com
📄 Version: 1.0 · Effective Date: 10.07.2026 · Last Updated: 16.07.2026
APP-0 Enterprise Deployment (Running on Your Own Server)

This appendix applies only to Customers running the Platform on their own infrastructure and their own database. It does not apply to the self-hosted Firebase deployment. In case of conflict, the provisions of this appendix prevail over the main text.

APP-0.1 Location of Data

In an enterprise deployment, employee scan records and the health indicators derived from them are held exclusively on the Customer's own server and database. Hosting, backup and availability of this data, and all costs relating to it, belong to the Customer.

Raw camera images, video frames and facial landmark data never leave the employee's device under any circumstances; they are transmitted neither to OculaWork nor to the Customer's server, and are not stored anywhere. The only data leaving the device is numerical measurement results.

APP-0.2 Components Remaining at OculaWork

The following remain on OculaWork's infrastructure even in an enterprise deployment, because they are required in order to perform the service, and the Customer accepts this:

  • Company configuration records and account preferences,
  • De-identified model training data — employee identity and company identity are not stored in these records,
  • The entire e-mail delivery infrastructure (including new membership, password operations, personnel and occupational physician notifications),
  • The analysis and decision-support core (sector model, benchmarking, hypothesis engine) and the licence issuing infrastructure.

These components are not included in the licensed software; they are provided as a service and are not delivered to the Customer.

APP-0.3 Licence Term, Technical Verification and Suspension of Access

APP-0.3.1 — The enterprise licence is a time-limited right of use; it does not transfer ownership and does not create a perpetual right of use. The Customer's right to use the Software is limited to the licence term stated in the Agreement and terminates automatically upon expiry of that term. Technical restriction or cessation of access upon expiry of the licence term cannot be characterised as a defect, default, or breach of contract.

APP-0.3.2 — For as long as the licence term continues, OculaWork may use the licence verification service in order to verify the validity of the licence by technical means.

APP-0.3.3 — Inability to reach the verification server is not expiry of the licence. Temporary unavailability of the licence verification service does not mean that the licence has expired or become invalid. In that case the Software continues to operate offline on the basis of the last verified status of the valid licence; where a verification problem persists, a warning is displayed to the Customer's administrator.

APP-0.3.4 — Access to the Software by a Customer whose licence term is still running may not be stopped by reason of a technical outage originating from OculaWork's infrastructure, planned maintenance, infrastructure failure, or unavailability of the licence verification service, and the licence term shall not be treated as shortened without fault on the Customer's part.

APP-0.3.5 — Where the Customer fails to pay the licence fee when due, OculaWork will give written notice and allow an additional period of at least 15 days for payment. If payment is not made by the end of that period and the default continues, OculaWork may temporarily suspend use of the Software. Suspension does not constitute termination of the Agreement and does not extinguish the Customer's other rights and obligations.

APP-0.3.6 — Before any suspension, OculaWork will send the Customer written notice stating the suspension date and the amount due. Where a payment dispute reasonably requires examination, access will not be suspended until the dispute has been resolved. During a valid licence period, the Service will not be technically disabled solely on the ground that a payment dispute exists, without operating the notices and periods set out above.

APP-0.3.7 — Access to data. Even where access is suspended or the licence expires, the Customer retains the right to export its own data on the terms and within the periods set out in APP-0.8.

APP-0.3B Place of Processing and Roles of the Parties

In an enterprise deployment, personal data relating to the Customer's employees is processed without being removed from the Customer's own IT infrastructure. OculaWork carries out the analysis activity within the Customer's infrastructure, through software components authorised by the Customer.

⚖️ This does not mean that OculaWork processes no personal data. The fact that data resides on the Customer's server does not by itself place OculaWork outside the scope of KVKK; the analysis is a processing activity carried out on the Customer's behalf. The roles of the parties are set out in §7.5. Who performs remote maintenance, support and security access, for what purpose, and under what logging obligation, is determined separately in the Enterprise Deployment/Order Form.
APP-0.3C Data That May Leave for the Central System (Data Egress Allowlist)

In an enterprise deployment, the fields that may be sent from the Customer's server to OculaWork's central system are technically restricted. This is not merely an undertaking but the maximum the system permits: any field outside the allowlist is rejected server-side.

ChannelFields that may be sentRejected
Model development contribution (off by default)modelVersion, sampleCount, gradient, noiseScaleEvery field outside the schema — employee identity, department, email, raw measurements, free text, dates
Notification delivery (only in "mail sent by us" mode)Recipient address, template identifier, link to the Customer's own addressFree text, subject, HTML body, attachments
Licence verificationLicence identifier, version, system health statusEmployee data
Daily deployment signal (health and tamper detection)Deployment identifier, model version, decision-core digest, coarse time since last training, aggregated measurement counter, rejected-request countersIdentity, department, free text, exact timestamp, any field outside the schema
Central psychosocial consult (off by default)Sector code, employee-count band, distributions derived from ≥50 measurements (sub-threshold cells suppressed), noise scaleIndividual records, identity, department name, free text, dates, exact employee count

Model development contributions are further subject to: being derived from at least 50 measurements, having privacy-enhancing noise applied, and having the contribution magnitude bounded. The application of these techniques does not mean the data is legally anonymous; anonymity is assessed separately on the concrete circumstances.

APP-0.3D Source Code Escrow and Continuity

Release of the source code to the Customer is possible only upon the occurrence of trigger events defined in a separately executed source code escrow agreement between the parties. The purpose of escrow is not to give the Customer access to the source code at will, but to protect the Customer's operational continuity in exceptional circumstances.

Trigger events are limited and expressly defined: OculaWork permanently ceasing operations, the conditions specified in the agreement arising in the context of bankruptcy/composition proceedings, or the permanent discontinuation of support and maintenance services. A temporary service interruption is not a trigger event.

🔑 The model signing infrastructure is outside the scope of escrow. Source code escrow and model signing keys are kept separate; the signing key is under no circumstances placed into escrow. The purpose of escrow is to allow the Customer to keep operating the system; the authority to produce and sign new models on OculaWork's behalf is not transferred. The escrow arrangement grants the Customer no licence or ownership right over the source code beyond those granted in this Agreement.
APP-0.3E Model Integrity and Signature Verification

The component on the Customer's server accepts only model packages signed with OculaWork's valid private key and whose integrity has been verified. An unsigned package, or one whose signature cannot be verified, is not executed.

The signing private key is under no circumstances sent to the Customer environment; only the verification (public) key resides on the Customer side. This separation prevents the Customer from introducing a self-produced model and prevents distribution of forged models should the central infrastructure be compromised.

🔑 Licence verification and model verification are two separate security layers and are not coupled. A valid licence does not make an unsigned model acceptable; a valid model signature does not keep an expired licence in force. Their error states are also distinct (model rejection ≠ end of licence).
APP-0.3F Remote Access and Support

OculaWork's remote administrative access to the Customer's infrastructure is disabled by default. Where support requires it, access is authorised by the Customer temporarily and limited to the purpose.

Every authorised access is logged with who, when, for what purpose and to which resource. OculaWork support personnel have no default access to employee content.

APP-0.3G Notification Duty for Cross-Border Transfers

Where a standard contract is used for a cross-border transfer, it must be notified to the Authority within 5 business days of signature. Which party performs the notification is expressly determined in the relevant Order Form or transfer agreement, according to the transfer scenario and the parties' status.

The standard contract text is used without modification, as required by law; commercial terms specific to the parties are set out in a separate agreement.

APP-0.4 Prohibition of Reverse Engineering and Circumvention

The Customer may not disable, modify or circumvent the licence check. Any attempt to run the software without connecting to OculaWork's licence service constitutes a material breach and entitles OculaWork to terminate the Agreement immediately for cause.

The fact that client-side components of the software are technically readable does not grant the Customer any right of reproduction, creation of derivative works, transfer or sub-licensing.

APP-0.5 Audit Right

OculaWork reserves the right to audit the number of installations and licence compliance, upon reasonable notice and without disrupting the Customer's operations. The parties agree that the signed licence and access records produced by the software have evidentiary value. If non-compliance is found, the costs of the audit are borne by the Customer.

APP-0.6 Privacy Thresholds

The reporting thresholds (at least 5 employees per department, at least 10 company-wide) are a contractual undertaking. The Customer may not request that these thresholds be lowered or that the aggregation/suppression protection be circumvented. Managers cannot access an employee's health data; such data is visible only to the employee themselves and the authorised occupational physician.

⚠️ These thresholds are not, on their own, a legal guarantee of anonymisation. Groups below the threshold are hidden, and complementary suppression is applied to prevent a hidden group from being reconstructed by mathematical inference from the remaining groups. Nevertheless, whether data qualifies as anonymous under KVKK is determined not merely by the removal of direct identifiers but by the concrete circumstances bearing on the possibility of re-identification by reasonably available means.
APP-0.7 Operational Responsibility and Service Level

Installation, updating, backup and operation of the server are the Customer's responsibility; these obligations are defined in the Operations Guide provided by OculaWork, which is deemed an annex to this Agreement. OculaWork's service level undertaking is limited solely to the services it provides (licence, analysis, e-mail); outages, data loss or performance issues within the Customer's infrastructure are out of scope.

APP-0.8 End of Agreement

Upon termination, the Customer's data remains with the Customer, as it already resides on their own server; no separate obligation of return arises for OculaWork. The de-identified model training data held at OculaWork is irreversibly anonymous and is therefore not deleted, and the Customer consents to this in advance.

APP-1 Data Processing Agreement (DPA)

This appendix is an integral part of this Service Agreement and governs the data-processing relationship between the Customer and OculaWork under KVKK Art. 3. It is a consolidated summary of the relevant provisions within the main text; in case of conflict, the corresponding section of the main text prevails.

ElementDescription
Data ControllerCustomer
Data ProcessorOculaWork (see §1 Definitions)
Subject Matter and Duration of ProcessingFor the duration of this Agreement, for OSH risk analysis and related purposes (see §7.1 table)
Categories of Data SubjectsThe Customer's employees
Categories of Personal DataIdentity, contact, health/biometric, behavioral, organizational, transaction data (see §7.1 table)
Processing InstructionsOculaWork processes personal data only per the Customer's instructions and for the purposes stated in this Agreement; it does not process for a different purpose (see §7.0, §7.4)
Processor's ObligationsSee §7.0
Sub-ProcessorGoogle Firebase / Google Cloud (see §4.2); the Customer is notified in advance of any change
Security MeasuresSee §9 (Data Security)
International TransfersData is stored in the European region (eur3); any transfer is subject to the KVKK Art. 9 regime (see §4.2)
Breach NotificationWithout undue delay and in any event within 24 hours (see §9.3)
Deletion ProcedureData is returned to the Customer upon request at contract end; permanently deleted after 90 days, with written confirmation to the Customer (see §4.3, §13.4)