Bu Hizmet Kullanım Sözleşmesi, Gizlilik Politikası ve KVKK Aydınlatma Metni (birlikte "Sözleşme") aşağıdaki taraflar arasında akdedilmiştir:
OculaWork — oculawork.com alan adı üzerinden çalışan göz sağlığı ve yorgunluk analizi platformu ("OculaWork", "Platform", "Biz").
| Ticaret Unvanı | Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. |
| Vergi Dairesi / No | Maltepe V.D. — 2100357903 |
| Tebligat Adresi | Söğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara |
| E-posta | info@oculawork.com |
OculaWork'e abone olan, Platform'u kendi çalışanları için kullanan her türlü gerçek veya tüzel kişi, şirket, kurum ya da kuruluş ("Müşteri", "İşveren", "Siz").
Müşteri bünyesinde çalışan, Müşteri tarafından sisteme tanımlanan ve Platform üzerinden göz yorgunluğu taraması gerçekleştiren kişiler ("Çalışan", "Son Kullanıcı").
| Terim | Tanım |
|---|---|
| Platform | oculawork.com ve bağlı alt domainlerinde sunulan yazılım, arayüzler ve tüm hizmetler bütünü |
| KVKK | 6698 sayılı Kişisel Verilerin Korunması Kanunu ve ilgili yönetmelikler |
| İSG Kanunu | 6331 sayılı İş Sağlığı ve Güvenliği Kanunu |
| Veri Sorumlusu | KVKK Md. 3/1-ı — İşleme amaçlarını belirleyen kişi; bu Sözleşme'de Müşteri |
| Veri İşleyen | KVKK Md. 3/1-ğ — Veri sorumlusu adına veriyi işleyen; bu Sözleşme'de OculaWork (yazılım sağlayıcısı) |
| Altyapı Sağlayıcısı | Google Firebase / Google Cloud — verinin fiziksel olarak barındırıldığı platform; OculaWork'ten bağımsız bir tüzel kişi |
| Özel Nitelikli Veri | KVKK Md. 6 — Sağlık, biyometrik veriler dahil hassas kategori |
| EAR / PERCLOS | Göz açıklık oranı / göz kapama yüzdesi — Platform'un ölçtüğü biyometrik parametreler |
| Açık Rıza | KVKK Md. 3/1-a — Belirli bir konuya ilişkin, bilgilendirmeye dayanan, özgür iradeyle verilen rıza |
| VERBİS | Kişisel Verileri Koruma Kurumu'nun Veri Sorumluları Sicili Bilgi Sistemi |
| SaaS | Software-as-a-Service — abonelik modeliyle sunulan bulut tabanlı yazılım hizmeti |
OculaWork; çalışanların göz yorgunluğunu standart bilgisayar kamerası aracılığıyla analiz eden, bilimsel literatürde yer alan yöntemlerden yararlanan biyometrik analizler gerçekleştiren ve işverenlere / iş hekimlerine risk bazlı raporlar sunan bir SaaS platformudur.
OculaWork, yüksek erişilebilirlik hedefiyle çalışmakla birlikte planlı bakım, mücbir sebep veya altyapı sağlayıcısından kaynaklanan kesintilerden sorumlu tutulamaz. Planlı kesintiler 48 saat öncesinden duyurulur. Bu, sayısal bir yüzde taahhüdü değil, genel bir hedef niteliğindedir; bir hizmet seviyesi taahhüdü (SLA) veya hizmet kredisi (service credit) programı oluşturmaz. Erişilebilirlik değerlendirilirken: ilgili aydaki toplam süre esas alınır; planlı bakım süreleri (bkz. aşağıda) ve Google Firebase/Google Cloud altyapısından kaynaklanan kesintiler bu değerlendirmeye dahil edilmez (bkz. §10.3).
Aynı fiyatlandırma dönemi içinde (bkz. §12) yürürlükteki abonelik ücreti değiştirilmez; fiyat değişikliği yalnızca bir sonraki yenileme döneminden itibaren uygulanabilir.
Planlı bakım, mümkün olduğunca hafta sonu veya gece saatlerinde yapılır ve tek seferde en fazla 4 saat sürecek şekilde planlanır. Platformun güvenliğini veya bütünlüğünü tehdit eden acil bir durum söz konusuysa (örn. aktif saldırı), acil bakım önceden bildirim yapılmaksızın uygulanabilir.
| Kapsam | Detay |
|---|---|
| Destek saatleri | Her gün 08:00–20:00 (Türkiye saati) |
| Kritik arıza (sistem tamamen erişilemez durumda) | Destek saatleri içinde 24 saat içinde ilk yanıt |
| Normal destek talebi | 2 iş günü içinde ilk yanıt |
| Yeni özellik talepleri | Değerlendirmeye alınır, teslim tarihi taahhüt edilmez |
Yukarıdaki yanıt süreleri yalnızca destek talebinin alındığını ve işleme koyulduğunu ifade eder; kesin bir çözüm süresi taahhüdü oluşturmaz.
Platform üzerinde "beta", "önizleme" veya "deneysel" olarak işaretlenen özellikler (yeni geliştirilen yapay zeka modülleri dahil) ön izleme niteliğindedir; kesintiye uğrayabilir, beklenmedik şekilde değişebilir veya kaldırılabilir. Bu özellikler için sonuç garantisi verilmez ve Sözleşme'nin genel hizmet sürekliliği/SLA taahhütleri bu özellikleri kapsamaz. Beta özellikler, veri kaybına veya hatalı veri üretimine yol açabilir; Müşteri, beta özellikleri kritik/tek kaynaklı veri için kullanmamalıdır.
OculaWork, ileride üçüncü taraf sistemlerle (kimlik/dizin servisleri, kurumsal iletişim araçları, ERP/İK yazılımları vb.) entegrasyon sunabilir. Bu tür entegrasyonlar, yayımlandıkları tarihte ayrıca duyurulacak ek şartlara tabidir; işbu Sözleşme hâlihazırda var olmayan bir entegrasyonu taahhüt etmez. Aynı şekilde, ileride bir genel API sunulması hâlinde; kullanım limitleri (rate limit), API anahtarı yönetimi ve kötüye kullanım politikaları ayrı bir API Kullanım Şartları belgesinde düzenlenir.
Platform, yalnızca iş hekiminin başlatabileceği (tek yönlü), çalışanla doğrudan görüntülü görüşme kurulmasını sağlayan bir özellik sunar. Bağlantı, üçüncü bir sunucudan geçmeden doğrudan iki cihaz arasında (WebRTC, ücretsiz Google STUN sunucusu) kurulur; ses/görüntü hiçbir sunucuda kaydedilmez veya saklanmaz. Görüşmeyi kurmak için gereken teknik bağlantı verisi (SDP/ICE), görüşme bitiminden birkaç saniye sonra otomatik olarak silinir. Görüşme sırasında, çalışanın kamera görüntüsünden — yalnızca görüşme süresince ve yalnızca o an görüşmedeki hekime gösterilmek üzere — kamera tabanlı yaklaşık bir nabız tahmini ile göz kırpma/PERCLOS bazlı anlık bir yorgunluk-stres göstergesi hesaplanır. Bu göstergeler tıbbi ölçüm veya teşhis niteliği taşımaz, klinik cihazın yerini tutmaz ve çalışanın kalıcı tarama geçmişine hiçbir zaman eklenmez/kaydedilmez. TURN sunucusu kullanılmadığından, çok katı kurumsal ağ/güvenlik duvarı yapılandırmalarında bağlantı nadiren kurulamayabilir.
| Aşama | Nerede İşlenir / Saklanır | OculaWork Erişimi |
|---|---|---|
| Kamera görüntüsü (ham video) | Yalnızca kullanıcının tarayıcısı (RAM) — hiçbir yere gönderilmez | ❌ Erişim yok |
| Hesaplanan sayısal metrikler (EAR, PERCLOS vb.) | Google Firebase Firestore (Google Cloud altyapısı) | Yazılım yönetimi için sınırlı admin erişimi |
| Kullanıcı hesap bilgileri | Google Firebase Authentication | Yazılım yönetimi için sınırlı admin erişimi |
| Uygulama dosyaları (HTML, JS) | Google Firebase Hosting (CDN) | Tam erişim — yazılım sahibi |
| OwO danışma profili (anonim sayısal metrikler — bkz. §7.4) | Google Cloud Functions (Avrupa) → yalnızca 0-1 arası bir sektörel bağlam skoru (owoContextScore) tarama kaydına eklenir | Kimlik bilgisi hiçbir zaman gönderilmez/işlenmez |
| OwO eğitim örneği (anonim özellik vektörü + etiket — bkz. §7.4) | Google Firebase Firestore (Avrupa) — yalnızca sayısal vektör, tarih ve 0/1 etiket; kimlik veya firma bilgisi hiçbir zaman içermez | Kimseye açık değil (admin dahil); yalnızca model eğitimi tarafından okunur, 180 gün sonra otomatik silinir |
| Doktor ekranınca tanınan ilaç adı (yalnızca sedasyon sınıfı sorgusu için) | Google Cloud Functions (Avrupa) — sorgu anlıktır, sonuç veya sorgu hiçbir yere kaydedilmez | Yalnızca doktorun zaten erişim yetkisi olan anamnez verisinden türetilir |
| OwO geri bildirimi (👍/👎, bkz. §7.4) | Google Firebase Firestore (Avrupa) — yalnızca bilgi türü + faydalı olup olmadığı | Kimseye açık değil (admin dahil); yalnızca toplulaştırılmış oran sunucu tarafında hesaplanır |
| Hekimin klinik doğruluk değerlendirmesi (bir tarama için "isabetli/düşük/yüksek/sevk gerekli", bkz. §7.4) | Google Firebase Firestore (Avrupa) — o tarama kaydına bağlı olarak saklanır; OwO'nun eğitimine anonim, düzeltilmiş bir etiket olarak dahil edilir | Yalnızca ilgili kiracının hekim/yönetimine açık |
| Hata bildirimi ve otomatik yakalanan teknik tanı verisi (tarayıcı hatası, cihaz/tarayıcı bilgisi — bkz. §9.4) | Google Firebase Firestore (Avrupa) | Yalnızca OculaWork admin'i erişebilir; çalışanın kendi işvereni bu veriyi göremez |
Google Firebase; Google LLC'ye bağlı, bağımsız bir bulut altyapısı ve veri barındırma hizmetidir. Firebase'in veri işleme koşulları ve güvenlik önlemleri Google'ın Gizlilik Politikası ile Firebase Veri İşleme Şartları'na tabidir.
Müşteri'ye ait tüm veriler (tarama sonuçları, raporlar, hesap bilgileri) Müşteri'nin münhasır mülkiyetindedir. Müşteri talep ettiğinde verilerin dışa aktarımı sağlanır; dışa aktarım yalnızca OculaWork'ün o tarihte desteklediği formatlarda (örn. JSON/CSV) yapılır, başka bir format garanti edilmez. Dışa aktarım sırasında verinin OculaWork tarafındaki bütünlüğü korunur; ancak dışa aktarılan verinin üçüncü taraf sistemlerle (ör. Müşteri'nin kendi ERP/İK yazılımı) uyumluluğu veya bu sistemlere aktarımdan sonraki bütünlüğü garanti edilmez. Sözleşme sona erdiğinde veriler 90 gün içinde sistemden kalıcı olarak silinir. Hesap kapatılsa/veriler silinse dahi, muhasebe mevzuatı (VUK vb.), işlem kayıtları ve KVKK kapsamındaki yasal saklama yükümlülükleri nedeniyle bazı kayıtlar (örn. fatura bilgileri) yasal saklama süreleri boyunca ayrıca tutulabilir.
Müşteri, bünyesindeki çalışanların kişisel verilerinin işlenmesi bakımından 6698 sayılı KVKK kapsamında münhasıran Veri Sorumlusu sıfatını haizdir. Bu kapsamda aşağıdaki yükümlülükleri OculaWork'ten bağımsız olarak yerine getirir:
OculaWork; bir yazılım sağlayıcısıdır ve Müşteri verilerini yalnızca Müşteri'nin talimatları ve bu Sözleşme çerçevesinde işler. Verileri kendi menfaatine, üçüncü taraf pazarlamasına veya başka amaçlara kullanmaz.
| Alt İşleyen | Amaç | Veri Konumu |
|---|---|---|
| Google Firebase Firestore | Veri depolama | Avrupa (eur3) |
| Google Firebase Authentication | Kimlik doğrulama | Avrupa |
| Google Firebase Hosting | Uygulama barındırma | Global CDN |
| Google Cloud Functions | Arka uç işlemler | Avrupa |
| Resend | Kimlik bilgisi/bildirim e-postalarının gönderimi ve info@oculawork.com adresine gelen postanın yönlendirilmesi | Sağlayıcının kendi altyapısı — bölge Google Firebase'inki gibi sözleşmeyle Avrupa'ya sabitlenmemiştir; güncel veri işleme şartları için sağlayıcının kendi belgelerine bakılmalıdır |
Alt işleyenler değiştirildiğinde Müşteriler 30 gün önceden bilgilendirilir.
OculaWork, Müşteri'ye ait verileri yalnızca şu durumlarda üçüncü taraflarla paylaşır:
Taraflar, kişisel veriler veya bilgi güvenliği ile ilgili resmi inceleme, denetim veya yargısal süreçlerde birbirlerine makul ölçüde destek sağlamayı kabul eder.
Müşteri Veri Sorumlusu, OculaWork ise KVKK Md. 3/1-ğ uyarınca Veri İşleyen sıfatını taşır. Bu sıfatla OculaWork:
| Kategori | Örnek Veriler | Amaç | Hukuki Dayanak |
|---|---|---|---|
| Kimlik | Ad, soyad | Hesap yönetimi | KVKK Md. 5/2-c — Sözleşmenin ifası |
| İletişim | E-posta | Bildirimler | KVKK Md. 5/2-c — Sözleşmenin ifası |
| Sağlık / Biyometrik | EAR, PERCLOS, yorgunluk skoru | İSG risk analizi | KVKK Md. 6/3 — Açık rıza / 6331 Md. 15 |
| Davranışsal | Reaksiyon süresi, kırpma hızı | İSG risk analizi | KVKK Md. 5/2-f — Meşru menfaat / açık rıza |
| Organizasyon | Departman, vardiya | Raporlama | KVKK Md. 5/2-c — Sözleşmenin ifası |
| İşlem | Tarama tarihi/saati | Denetim kaydı | KVKK Md. 5/2-f — Meşru menfaat |
| Hekim klinik notu | İş hekiminin bir çalışan hakkında yazdığı kalıcı, silinemez/değiştirilemez klinik not (bkz. §7.2, §9.4) | Sağlık gözetimi kayıt bütünlüğü | KVKK Md. 6/3 — Açık rıza / 6331 Md. 15 |
| Anket cevabı | Firma yönetiminin yayınladığı tek soruluk ankete çalışanın verdiği cevap | İSG risk analizi (OwO girdisi, bkz. §7.4), raporlama | KVKK Md. 5/2-f — Meşru menfaat / açık rıza |
| Teknik hata bildirimi | Kullanıcının yazdığı serbest metin + otomatik yakalanan tarayıcı hatası/cihaz bilgisi (bkz. §9.4) | Yazılım hatalarının teşhisi ve giderilmesi | KVKK Md. 5/2-f — Meşru menfaat |
| Bildirim/hatırlatma | Anlık bildirim gönderimi için cihaz push token'ı; hekimin belirli bir çalışan için oluşturduğu hatırlatma notu ve zamanı | Sağlık gözetimi takibi, sistem bildirimleri | KVKK Md. 5/2-c — Sözleşmenin ifası / Md. 6/3 |
| Veri Türü | Saklama Süresi |
|---|---|
| Tarama metrikleri ve raporlar | Aktif abonelik + 2 yıl (zamanaşımı koruması) |
| Hesap ve kimlik bilgileri | Sözleşme sona ermesinden itibaren 90 gün |
| İşlem kayıtları (log) | 6 ay |
| OwO eğitim örnekleri (anonim özellik vektörü + etiket) | 180 gün — her eğitim turunda otomatik olarak silinir |
Yüz biyometrik şablonu (faceEmbedding — yüz doğrulama için) | Aktif abonelik boyunca; çalışan "Verilerimi Sil" talebinde bulunduğunda veya hesabı kapatıldığında derhal ve otomatik olarak silinir |
Cihaz-içi öğrenme model ağırlıkları (federated_weights — bkz. §7.4) | Aktif abonelik boyunca; çalışan "Verilerimi Sil" talebinde bulunduğunda veya hesabı kapatıldığında silinir. Bu ağırlıklar önceden aynı firmadaki diğer çalışanların modelleriyle toplu (federe) olarak ortalanmış olabilir — bu durumda kişiye özel belgenin silinmesi, katkısının önceki toplu ortalamalardaki matematiksel izinin geriye dönük olarak tamamen kaldırılacağını garanti etmez |
| Hekim klinik notları | Süresizdir; yazıldıktan sonra değiştirilemez veya silinemez (bkz. §9.4) — sağlık gözetimi kayıt bütünlüğünü korumak amacıyla bilinçli bir tasarım tercihidir |
| Uyarı/alarm kayıtları, klinik doğrulama geri bildirimi, muayene takvim kayıtları, başarısız yüz doğrulama güvenlik logu | Çalışanın kendi "Verilerimi Sil" talebiyle OTOMATİK silinmez — hekim klinik notlarıyla AYNI gerekçeyle (İSG/güvenlik denetim izi bütünlüğü) bilinçli olarak korunur. Silinmesi gerekiyorsa info@oculawork.com üzerinden admin aracılığıyla talep edilebilir. |
| Hata bildirimi ve teknik tanı verisi | OculaWork admin'i tarafından manuel olarak silinene kadar |
| Silme talebi sonrası | Talep tarihinden itibaren 30 gün içinde imha (hekim klinik notları hariç — yukarıya bkz.) |
Çalışanlar KVKK haklarını kendi işverenleri (Müşteri) aracılığıyla kullanır. OculaWork bu talepleri Müşteri'nin yönlendirmesiyle 30 gün içinde karşılar:
Yukarıdaki itiraz hakkının somut şekilde kullanılabilmesi için, Platform'da çalışan hakkında sonuç doğurabilecek otomatik/yarı-otomatik işleme noktaları açıkça belirtilir: (i) günlük tarama sonucu üretilen yorgunluk risk seviyesi (düşük/orta/yüksek/kritik), (ii) CUSUM ve İzolasyon Ormanı (Isolation Forest) tabanlı istatistiksel anomali tespiti uyarıları, (iii) "OwO" sektörel öğrenme modelinin, ilgili taramanın anonim sayısal profiline dayanarak ürettiği ve yalnızca bilgi amaçlı gösterilen sektörel bağlam skoru (owoContextScore, bkz. §7.4) — bu üç işleme noktası da yalnızca iş hekimine gösterilir, hiçbiri tek başına otomatik bir personel kararına dönüşmez. OwO'nun eğitim verisi ve model ağırlıkları anonimdir ve hiçbir çalışanın kimliğini ifşa etmez; ancak danışma katmanının bilgi amaçlı ürettiği sektörel bağlam skoru, ilgili taramaya özel, bilgilendirici bir gösterge olarak yukarıdaki (iii) numaralı işleme noktasını oluşturur. Bir çalışan, risk seviyesi, anomali uyarısının veya sektörel bağlam skorunun kendisi hakkında olumsuz bir personel kararına (görev değişikliği, disiplin vb.) tek başına dayanak oluşturduğunu düşünüyorsa, işverenine itiraz edebilir; işveren böyle bir itirazı değerlendirirken kararın bir insan (iş hekimi/İK) tarafından gözden geçirilmesini sağlamakla yükümlüdür.
KVKK Md. 3/1-d uyarınca kişisel veri, kimliği belirli veya belirlenebilir gerçek kişiye ilişkin her türlü bilgiyi ifade eder. Geri döndürülemez şekilde anonim hâle getirilmiş veri bu tanımın dışında kalır ve KVKK hükümleri bu veriler bakımından uygulanmaz. OculaWork, Müşterilerin (paylaşımlı veya self-host altyapı fark etmeksizin, bkz. madde 5) tarama ve öz-değerlendirme verilerinden, sektör genelinde çalışan istatistiksel bir öğrenme modelini ("OwO") bu esasa dayanarak eğitir. OculaWork, bu anonimleştirme işleminin geri döndürülemez olmasını, aşağıda açıklanan teknik ve idari tedbirlerle sağlamayı hedefler.
Bu işleme aşağıdaki teknik ve hukuki güvencelerle sınırlıdır:
Şeffaflık: Bu işlemenin tam teknik detayı — hangi veri kaynağının hangi sinyale indirgendiği dahil — OculaWork Teknik Metodoloji Belgesi'nde ("OwO Eğitim Modeli" başlıklı bölüm) ayrıntılı olarak belgelenmiştir ve talep üzerine Müşteri'ye ve ilgili kişilere sunulur.
KVKK mevzuatı ve Kurul içtihadı zaman içinde değişebilir. Mevzuat değişikliği hâlinde taraflar, işbu Sözleşme'yi ve ilgili uygulamaları güncel mevzuata uyumlu hâle getirmek için makul süre içinde gerekli iş birliğini gösterir.
EAR, PERCLOS ve yorgunluk skoru; KVKK Madde 6 kapsamında özel nitelikli kişisel veri sayılabilir ve ek koruma gerektirir.
Platform'un giriş/kimlik doğrulama amacıyla kullanabildiği yüz biyometrisi (face-embedding) özelliği, yorgunluk taraması metriklerinden (EAR/PERCLOS gibi) ayrı bir risk kategorisi oluşturur: bu veri doğrudan kimlik doğrulama amacıyla, işveren tarafından zorunlu tutulan bir biyometrik veri işlemedir. Kişisel Verileri Koruma Kurulu, 04.08.2022 tarih ve 2022/797 sayılı Kararı'nda işyerine giriş-çıkışlarda yüz tanıma sistemiyle biyometrik veri işlenmesini, Kanun'un 6. maddesi kapsamında herhangi bir işleme şartına dayanılmaksızın gerçekleştirildiği gerekçesiyle hukuka aykırı bulmuş; 29.04.2026 tarih ve 2026/921 sayılı İlke Kararı'nda ise mesai takibi amaçlı biyometrik veri işlemenin, çalışanın açık rızası bulunsa dahi hukuka aykırı olduğuna hükmetmiştir — gerekçe olarak işçi-işveren ilişkisindeki yapısal güç dengesizliğinin açık rızanın "özgür irade" unsurunu zedelediği belirtilmiştir. Bu doğrultuda yalnızca açık rızaya dayanmak, biyometrik veri işlemeyi tek başına hukuka uygun kılmayabilir. Müşteri, bu özelliği etkinleştirmeden önce (i) ölçülülük, gereklilik ve veri minimizasyonu ilkelerine uygunluğunu, (ii) şifreli kart/PIN, RFID/NFC kimlik kartı veya cihaz eşleştirme gibi daha az müdahaleci bir alternatifin yeterli olup olmadığını değerlendirmeli ve (iii) kendi hukuki danışmanına başvurmalıdır. OculaWork bu değerlendirmeyi Müşteri adına yapmaz ve bu konudaki hukuki riski üstlenmez.
Güvenlik ihlali tespit edilmesi hâlinde Müşteriler ve ilgili ise KVKK Kurumu 72 saat içinde yazılı olarak bildirilir (KVKK Md. 12/5). Müşteri de, kendi tarafında (kendi hesapları, ağı veya sistemleri üzerinden) meydana gelen ve Platform verilerini etkileyebilecek bir güvenlik ihlalini fark ettiğinde, bunu gecikmeksizin OculaWork'e bildirmekle yükümlüdür.
| Rol | Erişebildiği Veri | Erişemediği Veri |
|---|---|---|
| Çalışan | Yalnızca kendi tarama sonuçları, kendi YZ Yaşam Koçu içeriği, kendi periyodik öz-tarama kaydı, kendi anket cevabı | Başka hiçbir çalışanın verisi; hekimin kendisi hakkında yazdığı klinik notlar; gönderdiği hata bildirimi ve teknik tanı verisi (yalnızca gönderim anında görünür, sonrasında yalnızca OculaWork admin'ine açıktır) |
| Yönetim / İK | Departman bazlı anonim/toplulaştırılmış istatistikler (min. 5 kişilik gruplar), personel/muayene yönetimi, bireysel anket cevapları, Karakter-Görev Uyum Endeksi (yalnızca en az 10 çalışan Karakter Analizi'ni tamamladığında görünen, tek bir yüzde ve güven değerinden oluşan toplulaştırılmış istatistik — bkz. §7.4) | Bireysel tarama detayları, YZ Yaşam Koçu içeriği (GAD-7/PHQ-9/CBI, Karakter Analizi bireysel sonucu dahil), periyodik öz-tarama anamnezi, hata bildirimi/teknik tanı verisi |
| İş Hekimi | Kendi kiracısındaki bireysel sağlık gözetimi/tarama verisi, TİTCK ilaç eşleştirme, periyodik öz-tarama anamnezi, resmi muayene kayıtları (exam_records), kendi yazdığı kalıcı klinik notlar (bkz. §7.1, §7.3 — süresiz, değiştirilemez/silinemez), taramalara verdiği klinik doğruluk geri bildirimi | Çalışanın YZ Yaşam Koçu içeriği (GAD-7/PHQ-9/CBI, Sakinleş, Karakter) — bu veri hekime de kapalıdır; hata bildirimi/teknik tanı verisi |
| OculaWork Admin | Firma/abonelik yönetimi, anonim Veri Havuzu istatistikleri, Modül Kullanım Panosu (yalnızca sayı), OwO eğitim geçmişi (yalnızca ağırlık/skor), tüm kullanıcılardan gelen hata bildirimleri ve otomatik yakalanan teknik tanı verisi (bkz. §7.1) — bu veri, çalışanın kendi işvereniyle (yönetim/hekim) hiçbir zaman paylaşılmaz | Hiçbir çalışanın bireysel verisi, YZ Yaşam Koçu içeriği, anamnez serbest metni, hekim klinik notlarının içeriği — bkz. §7.4 |
Müşteri, KVKK kapsamındaki Veri Sorumlusu yükümlülüklerini yerine getirebilmek amacıyla, OculaWork'ün veri işleme süreçlerine ilişkin bilgi ve belge talep etme hakkına sahiptir. OculaWork, kendi ticari sırlarını ve diğer Müşterilere ait bilgileri ifşa etmeyecek şekilde, makul sıklıkta ve en az 15 gün önceden yazılı bildirim yapılması kaydıyla bu talebi karşılar. Yerinde (on-site) denetim veya bağımsız üçüncü taraf denetimi, ancak tarafların önceden yazılı olarak mutabık kaldığı kapsam, süre ve gizlilik şartları çerçevesinde mümkündür; denetim masrafları aksi kararlaştırılmadıkça talep eden Müşteri'ye aittir.
Platform'da bir güvenlik açığı tespit eden kişiler, bu durumu yalnızca info@oculawork.com adresine, sorumlu açıklama (Responsible Disclosure) ilkeleri kapsamında bildirebilir. Önceden OculaWork'ün yazılı izni alınmaksızın gerçekleştirilen aktif sızma testi, yük testi, fuzzing veya benzeri faaliyetler bu kapsamda değerlendirilmez ve §11.1'de tanımlanan Yasaklı Kullanımlar hükmüne tabidir.
OculaWork'ün herhangi bir nedenle tazminat yükümlülüğüne girmesi hâlinde toplam sorumluluğu, ihlalin gerçekleştiği tarihten önceki son 12 aylık abonelik bedeliyle sınırlıdır. Bu sınırlama; kasıt, ağır ihmal, fikri mülkiyet ihlali veya gizlilik/veri güvenliği yükümlülüklerinin ihlali hâllerinde uygulanmaz.
Taraflar, mücbir sebep süresince ve mücbir sebebin doğrudan etkilediği ölçüde, işbu Sözleşme'den doğan yükümlülüklerini yerine getirememekten sorumlu tutulamaz.
Herhangi bir çalışanın işverenine (Müşteri'ye) karşı Platform verileriyle ilgili dava açması durumunda OculaWork bu davada taraf değildir. Müşteri, OculaWork'ü bu tür davalardan muaf tutmayı ve olası masrafları karşılamayı kabul eder.
Kullanıcı, kendi hesabından yapılan tüm işlemlerden bizzat sorumludur. Şifrenin üçüncü kişilerle paylaşılması hâlinde bundan doğan tüm sonuçlar (veri erişimi, yetkisiz işlem, veri sızıntısı dahil) paylaşımı yapan kullanıcıya ve/veya Müşteri'ye aittir; OculaWork bu durumdan sorumlu tutulamaz. Kullanıcı hesapları kişiye özeldir; hesabın birden fazla kişi tarafından ortak kullanılması lisans ihlali sayılır ve OculaWork bu durumda ilgili hesabı askıya alma hakkını saklı tutar.
OculaWork, işbu Sözleşme kapsamındaki hizmetler için herhangi bir mesleki sorumluluk sigortası (E&O) veya başka bir sigorta taahhüdünde bulunmaz.
Platform, işbu Sözleşme'de açıkça belirtilenler dışında "olduğu gibi" (as-is) ve "mevcut haliyle" (as-available) sunulmaktadır. OculaWork; Platform'un kesintisiz, hatasız veya güvenlik açığından tamamen arınmış çalışacağına, belirli bir amaca uygunluğuna, satılabilirliğine veya Müşteri'nin beklentilerini karşılayacağına dair açık ya da zımni herhangi bir garanti vermez.
Platform yazılımı, kaynak kodu, algoritmaları, tasarım ve marka OculaWork'ün münhasır fikri mülkiyetidir. Müşteri'ye; münhasır olmayan (non-exclusive), geri alınabilir (revocable), sınırlı (limited) ve dünya çapında (worldwide) geçerli, yalnızca abone olunan kullanıcı sayısı kadar, kullanım amaçlı bir lisans tanınır. Bu lisans devredilemez, başka bir firmaya kiralanamaz veya alt lisans olarak verilemez; Platform hiçbir şekilde kopyalanamaz veya tersine mühendisliğe tabi tutulamaz. Lisans, yalnızca satın alınan/abone olunan kullanıcı (kota) sayısı kadar aktif kullanıcı için geçerlidir; kota aşımı tespit edilirse Müşteri'den ek kota satın alması istenir. Lisanslanan kullanıcı sayısının sistematik şekilde aşılması hâlinde OculaWork, fazla kullanım bedelini geriye dönük olarak faturalandırabilir veya hesabı askıya alabilir. İşbu Sözleşme, OculaWork markası, ticari unvanı, algoritmaları veya olası patent başvuruları üzerinde Müşteri'ye herhangi bir hak devri oluşturmaz.
Müşteri ve çalışanlara ait ham tarama sonuçları ve raporlar Müşteri'nin mülkiyetindedir. OculaWork bu verileri yalnızca Sözleşme kapsamında işler; anonimleştirilerek toplulaştırılmış istatistikler Platform geliştirmesi amacıyla kullanılabilir.
Platform içerisinde üçüncü taraf açık kaynak yazılımlar kullanılabilir. Bu yazılımların lisans hakları ilgili lisans sahiplerine aittir. Açık kaynak bileşenlerinin kullanılması, işbu Sözleşme kapsamında OculaWork'ün fikri mülkiyet haklarını ortadan kaldırmaz.
Müşteri, OculaWork'ün önceden yazılı izni olmaksızın OculaWork marka, logo veya ticari unvanını reklam, referans veya tanıtım amacıyla kullanamaz.
OculaWork, aksi yazılı olarak kararlaştırılmadıkça Müşteri'nin ticaret unvanını yalnızca referans müşteri listesinde kullanabilir. Müşteri, dilediği zaman yazılı bildirimle bu izni geri alabilir.
OculaWork, aşağıdaki durumlarda Sözleşme'yi feshetmeden önce Müşteri'nin hesabını geçici olarak askıya alma hakkını saklı tutar: (i) Platform'un veya altyapının aktif bir siber saldırı altında olması, (ii) hesaptan kaynaklanan yetkisiz erişim/kötüye kullanım şüphesi, (iii) ödeme gecikmesi (bkz. §13.3), (iv) API kötüye kullanımı, bot trafiği, hizmet dışı bırakma (DDoS) girişimi, yetkisiz otomasyon veya olağan dışı yoğunlukta istek gönderimi (bkz. §11.1 Yasaklı Kullanımlar). (iv) numaralı hâllerde, Platform'un veya diğer Müşterilerin bütünlüğünü korumak amacıyla, hesap önceden bildirim yapılmaksızın askıya alınabilir. Askıya alma süresince Müşteri verilerine erişim geçici olarak kısıtlanır ancak veriler silinmez; durum netleştiğinde erişim yeniden açılır.
Her iki taraf 30 gün önceden yazılı bildirimde bulunarak Sözleşme'yi sona erdirebilir.
OculaWork aşağıdaki durumlarda derhal ve tazminatsız fesih hakkını saklı tutar:
Yetkili bir mahkeme kararı veya kanunen zorunlu kılan bir idari/yasal düzenleme mevcut olması hâlinde, OculaWork Platform'u kısmen veya tamamen durdurabilir/kaldırabilir. Bu durum, kaynağı OculaWork'ün kontrolünde olmayan bir hukuki zorunluluktan doğduğu ölçüde, §10.3 kapsamında sorumluluk dışı bir hâl olarak değerlendirilir.
Platform, bugün itibarıyla klasik anlamda bir HTTP çerezi (cookie) oluşturmamaktadır; aşağıdaki teknik depolama mekanizmaları tarayıcının yerel depolama alanında (localStorage) tutulur:
| Mekanizma | Amaç | Tür | Süre |
|---|---|---|---|
| ow_lang | Dil tercihi | İşlevsel | localStorage (kalıcı) |
| Firebase Auth Token | Oturum yönetimi | Zorunlu | 1 saat |
| "Beni Hatırla" jetonu ve rol bazlı e-posta hatırlatma anahtarları | Bir sonraki girişte oturumu/e-postayı hatırlama | İşlevsel | localStorage (kullanıcı çıkış yapana/reddedene kadar) |
| Cihaz-eşleştirme (biyometrik/parmak izi girişi) anahtarı | Cihazın daha önce biyometrik girişle eşleştirildiğini hatırlama | İşlevsel | localStorage (kullanıcı sıfırlayana kadar) |
| Bildirim tercihi ve cihaz push token anahtarları | Bildirim açık/kapalı tercihini ve bildirim gönderim adresini hatırlama | İşlevsel | localStorage (kalıcı, kapatılana kadar) |
| Firma kodu / son bağlanılan kiracı önbelleği | Self-host firmalarda giriş ekranını doğru firmaya yönlendirme | İşlevsel | localStorage (kalıcı) |
| Uygulama sürümü ve tarama önbelleği | Çevrimdışı/gecikmiş bağlantıda son bilinen veriyi gösterme, güncelleme kontrolü | İşlevsel | localStorage (kalıcı, güncellenene kadar) |
| Konu | İletişim |
|---|---|
| KVKK başvuruları / Veri silme | info@oculawork.com |
| Teknik destek | info@oculawork.com |
| Hukuki bildirimler | info@oculawork.com |
| Güvenlik açığı bildirimi | info@oculawork.com |
KVKK başvurularına 30 gün içinde yanıt verilir. KVKK Kurumu'na şikâyet için: kvkk.gov.tr
Bu Sözleşme kapsamında taraflarca bildirilen e-posta adresine yapılan bildirimler, gönderildiği tarihte tebliğ edilmiş sayılır. Müşteri, iletişim bilgilerini güncel tutmakla yükümlüdür. E-postanın alıcı tarafın spam/gereksiz posta klasörüne düşmesi, alıcının e-posta sağlayıcısındaki filtreleme ayarlarından kaynaklanır; bu durumdan OculaWork sorumlu tutulamaz. Taraflar, iletişim bilgilerindeki değişiklikleri en geç 7 gün içinde yazılı olarak bildirmekle yükümlüdür; bildirilmeyen değişikliklerden doğacak sonuçlardan ilgili taraf sorumludur.
Faturalar elektronik fatura (e-Fatura) veya elektronik arşiv fatura (e-Arşiv) olarak, mevzuatın izin verdiği ölçüde e-posta yoluyla gönderilir ve bu şekilde tebliğ edilmiş sayılır.
Müşteri, Platform'u Türkiye'nin veya Birleşmiş Milletler, Avrupa Birliği, ABD gibi uluslararası kuruluşların/yargı alanlarının yürürlükteki ihracat kontrolü ve yaptırım mevzuatını ihlal edecek şekilde kullanmayacağını; yaptırım listelerinde yer alan bir kişi/kuruluş adına veya yaptırım uygulanan bir ülkeden erişim sağlamayacağını beyan ve taahhüt eder.
Müşteri, işbu Sözleşme'yi OculaWork'ün önceden yazılı onayı olmaksızın devredemez. OculaWork, şirket birleşmesi, hisse devri, varlık satışı veya benzeri bir yapısal değişiklik hâlinde, işbu Sözleşme'yi ve bundan doğan hak ve yükümlülüklerini, Müşteri'ye önceden bildirimde bulunmak kaydıyla, üçüncü bir tarafa devredebilir.
İşbu Sözleşme metni ile ekleri (EK-1 Veri İşleme Sözleşmesi, Gizlilik Politikası, KVKK Aydınlatma Metinleri, Açık Rıza Metni) arasında bir çelişki bulunması hâlinde, aşağıdaki öncelik sırası uygulanır: (i) EK-1 Veri İşleme Sözleşmesi (yalnızca veri işleme hükümleri bakımından), (ii) işbu Sözleşme'nin ana metni, (iii) diğer ekler ve ayrı belgeler. Bildirimler, aksi belirtilmedikçe Türkçe yapılır; TR/EN metinler arasında çelişki hâlinde Türkçe metin esas alınır.
Taraflar, işbu Sözleşme kapsamında öğrendikleri veya erişim sağladıkları birbirlerine ait ticari sırları, fiyatlandırma bilgilerini, algoritma ve yazılım mimarisi detaylarını, müşteri/çalışan listelerini ve açıkça gizli olarak işaretlenmiş diğer bilgileri üçüncü kişilerle paylaşmamayı ve yalnızca işbu Sözleşme'nin ifası amacıyla kullanmayı kabul eder. Bu yükümlülük, kamuya mal olmuş bilgileri, yasal zorunluluk nedeniyle açıklanması gereken bilgileri veya bağımsız olarak geliştirilmiş bilgileri kapsamaz; Sözleşme sona erse dahi makul bir süre boyunca yürürlükte kalır.
Taraflardan birinin işbu Sözleşme'den doğan bir hakkını belirli bir durumda kullanmaması veya kullanmakta gecikmesi, o haktan veya ileride aynı ya da benzer bir durumda bu hakkı kullanmaktan feragat ettiği anlamına gelmez.
İşbu Sözleşme ve ekleri (EK-1 Veri İşleme Sözleşmesi ile bkz. §16.3'te belirtilen diğer belgeler), taraflar arasındaki konuya ilişkin bütün anlaşmayı oluşturur ve bu konudaki önceki yazılı veya sözlü tüm görüşme, teklif ve anlaşmaların yerine geçer. İşbu Sözleşme'de değişiklik, ancak OculaWork tarafından yazılı olarak (bkz. §16 güncelleme bildirimi) yapılabilir.
İşbu Sözleşme herhangi bir nedenle sona erse dahi, niteliği gereği sona ermeden sonra da uygulanması gereken hükümler yürürlükte kalmaya devam eder; bunlar arasında özellikle Gizli Bilgi (§16.6), Fikri Mülkiyet (§11), Tazmin Yükümlülüğü (§16.5), Kişisel Verilerin Korunması'na ilişkin hükümler (§7) ve Delil Sözleşmesi (§16.4) yer alır.
Bu ek, işbu Hizmet Sözleşmesi'nin ayrılmaz bir parçasıdır ve Müşteri ile OculaWork arasındaki veri işleme ilişkisini KVKK Md. 3/1-ğ kapsamında düzenler. Sözleşme metni içindeki ilgili hükümlerin konsolide bir özetidir; çelişki hâlinde ana metindeki ilgili bölüm esas alınır.
| Unsur | Açıklama |
|---|---|
| Veri Sorumlusu | Müşteri |
| Veri İşleyen | OculaWork (bkz. §1 Tanımlar) |
| İşlemenin Konusu ve Süresi | İşbu Sözleşme'nin süresi boyunca, İSG risk analizi ve ilgili amaçlarla (bkz. §7.1 tablosu) |
| İlgili Kişi Kategorileri | Müşteri'nin çalışanları |
| Kişisel Veri Kategorileri | Kimlik, iletişim, sağlık/biyometrik, davranışsal, organizasyon, işlem verisi (bkz. §7.1 tablosu) |
| İşleme Talimatları (Processing Instructions) | OculaWork, kişisel verileri yalnızca Müşteri'nin talimatları ve işbu Sözleşme'de belirtilen amaçlarla işler; farklı bir amaçla işlemez (bkz. §7.0, §7.4) |
| Veri İşleyenin Yükümlülükleri | bkz. §7.0 |
| Alt İşleyen | Google Firebase / Google Cloud (bkz. §4.2); değişiklik hâlinde Müşteri'ye önceden bildirilir |
| Güvenlik Tedbirleri | bkz. §9 (Veri Güvenliği) |
| Yurt Dışına Aktarım (International Transfers) | Veriler Avrupa bölgesinde (eur3) tutulur; olası aktarım KVKK Md. 9 rejimine tabidir (bkz. §4.2) |
| İhlal Bildirimi | 72 saat içinde (bkz. §9.3) |
| İmha Prosedürü (Deletion Procedure) | Sözleşme sonunda Müşteri talebi doğrultusunda veriler iade edilir; 90 gün sonunda kalıcı olarak imha edilir ve Müşteri'ye yazılı teyit edilir (bkz. §4.3, §13.4) |
This Terms of Service, Privacy Policy and Data Protection Agreement (collectively "Agreement") is entered into between the following parties:
OculaWork — employee eye health and fatigue analysis platform operating at oculawork.com ("OculaWork", "Platform", "We").
| Legal Trade Name | Cimedya Bilgi Sistemleri Reklam ve Tic. A.Ş. |
| Tax Office / No. | Maltepe Tax Office — 2100357903 |
| Registered Address | Söğütözü Mah. Söğütözü Cad. Koç İkiz Kuleleri A Blok No: 2 A/9, Ankara, Türkiye |
| info@oculawork.com |
Any individual or legal entity, company, institution or organization subscribing to OculaWork and using the Platform for their employees ("Customer", "Employer", "You").
Persons employed by the Customer, registered in the system by the Customer, and performing eye fatigue scans via the Platform ("Employee", "End User").
| Term | Definition |
|---|---|
| Platform | The software, interfaces and all services provided at oculawork.com and related subdomains |
| KVKK | Turkish Personal Data Protection Law No. 6698 and related regulations (equivalent to GDPR) |
| OSH Law | Occupational Health and Safety Law No. 6331 |
| Data Controller | KVKK Art. 3 — Entity determining purposes and means of processing personal data; in this Agreement, the Customer |
| Data Processor | KVKK Art. 3 — Entity processing data on behalf of the data controller; in this Agreement, OculaWork (software provider) |
| Infrastructure Provider | Google Firebase / Google Cloud — the platform where data is physically hosted; a legal entity independent of OculaWork |
| Sensitive Data | KVKK Art. 6 — Special categories including health and biometric data |
| EAR / PERCLOS | Eye Aspect Ratio / Percentage of Eye Closure — biometric parameters measured by the Platform |
| Explicit Consent | KVKK Art. 3 — Freely given, specific and informed consent that can be withdrawn |
| SaaS | Software-as-a-Service — subscription-based cloud software |
OculaWork is a SaaS platform that analyzes employee eye fatigue via a standard webcam, performs biometric analyses using methods found in the scientific literature, and provides risk-based reports to employers and occupational physicians.
OculaWork operates with a high-availability target but cannot be held liable for planned maintenance, force majeure, or infrastructure provider outages. Planned downtime is announced 48 hours in advance. This is a general target, not a numeric percentage commitment; it does not constitute a service level agreement (SLA) or a service-credit program. When assessing availability: the total time in the relevant month is used as the base; scheduled maintenance windows (below) and outages attributable to Google Firebase/Google Cloud infrastructure are excluded from this assessment (see §10.3).
The subscription fee in effect will not change during the current pricing period (see §12); any price change may only take effect from the next renewal period onward.
Planned maintenance is scheduled, where possible, during weekends or nighttime hours, and is limited to a maximum of 4 hours per occurrence. Where an urgent situation threatens the security or integrity of the Platform (e.g., an active attack), emergency maintenance may be performed without prior notice.
| Scope | Detail |
|---|---|
| Support hours | Daily 08:00–20:00 (Turkey time) |
| Critical incident (system fully inaccessible) | Initial response within 24 hours, during support hours |
| Standard support request | Initial response within 2 business days |
| New feature requests | Considered for roadmap; no delivery date is guaranteed |
The response times above indicate only that a support request has been received and is being processed; they do not constitute a resolution-time commitment.
Features on the Platform marked "beta," "preview," or "experimental" (including newly developed AI modules) are provided on a preview basis; they may be interrupted, changed unexpectedly, or removed. No outcome is guaranteed for these features, and the Agreement's general service-continuity/SLA commitments do not cover them. Beta features may result in data loss or erroneous data output; the Customer should not rely on beta features for critical or single-source data.
OculaWork may in the future offer integrations with third-party systems (identity/directory services, enterprise communication tools, ERP/HR software, etc.). Such integrations, when released, will be subject to additional terms announced at that time; this Agreement does not commit to any integration that does not currently exist. Likewise, should a general-purpose API be released in the future, usage limits (rate limits), API key management, and abuse policies will be governed by a separate API Terms of Use document.
The Platform offers a feature enabling a direct video call with an employee, which only the occupational physician may initiate (one-directional). The connection is established directly between two devices (WebRTC, using Google's free public STUN server) without passing through any third-party server; audio/video is never recorded or stored on any server. The technical connection data (SDP/ICE) required to establish the call is automatically deleted a few seconds after the call ends. During the call, an approximate camera-based pulse estimate and an instantaneous blink/PERCLOS-based fatigue-stress indicator are computed from the employee's camera feed — shown only to the physician on that call, only for the call's duration. These indicators are not a medical measurement or diagnosis, do not replace a clinical device, and are never added to or stored in the employee's permanent scan history. As no TURN server is used, the connection may occasionally fail to establish under very strict corporate network/firewall configurations.
| Stage | Where Processed / Stored | OculaWork Access |
|---|---|---|
| Raw camera footage (video) | User's browser only (RAM) — never transmitted anywhere | ❌ No access |
| Computed numerical metrics (EAR, PERCLOS, etc.) | Google Firebase Firestore (Google Cloud infrastructure) | Limited admin access for software management |
| User account information | Google Firebase Authentication | Limited admin access for software management |
| Application files (HTML, JS) | Google Firebase Hosting (CDN) | Full access — software owner |
| OwO consult profile (anonymous numeric metrics — see §7.4) | Google Cloud Functions (Europe) → only a 0-1 sector-context score (owoContextScore) is appended to the scan record | Identity information is never sent or processed |
| OwO training sample (anonymous feature vector + label — see §7.4) | Google Firebase Firestore (Europe) — only a numeric vector, a timestamp, and a 0/1 label; never contains identity or company information | Accessible to no one (including admin); read only by the training process, automatically deleted after 180 days |
| Drug name recognized by the physician's screen (sedation-class lookup only) | Google Cloud Functions (Europe) — the query is instantaneous; neither the query nor its result is stored anywhere | Derived only from anamnesis data the physician already has access to |
| OwO feedback (👍/👎, see §7.4) | Google Firebase Firestore (Europe) — only the information type + whether it was helpful | Accessible to no one (including admin); only the aggregate ratio is computed server-side |
| Physician's clinical accuracy verdict on a scan ("accurate/under/over/referred", see §7.4) | Google Firebase Firestore (Europe) — stored tied to that scan record; fed into OwO training as an anonymous, corrected label | Accessible only to that tenant's physicians/management |
| Bug report and automatically captured technical diagnostics (browser error, device/browser info — see §9.4) | Google Firebase Firestore (Europe) | Accessible only to OculaWork's own admin; the reporting user's own employer cannot see it |
Google Firebase is an independent cloud infrastructure and data hosting service owned by Google LLC. Firebase's data processing terms and security measures are governed by Google's Privacy Policy and Firebase Data Processing Terms.
All Customer data (scan results, reports, account information) remains the exclusive property of the Customer. Upon request, data export is provided; export is made only in formats OculaWork supports at that time (e.g., JSON/CSV), and no other format is guaranteed. Data integrity is maintained on OculaWork's side during export; however, no guarantee is made regarding compatibility with, or the integrity of the data after import into, third-party systems (e.g., the Customer's own ERP/HR software). Upon contract termination, data is permanently deleted within 90 days. Even if the account is closed/data is deleted, certain records (e.g., invoicing data) may be separately retained for the legally required retention period due to accounting regulations (e.g., Turkish Tax Procedure Law), transaction logs, and KVKK-related legal retention obligations.
The Customer exclusively holds the status of Data Controller under KVKK Law No. 6698 with respect to the processing of its employees' personal data. The Customer is independently responsible for:
OculaWork is a software provider and processes Customer data solely within the scope of this Agreement and the Customer's instructions. Data is not used for OculaWork's own benefit, third-party marketing, or any other purpose.
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Google Firebase Firestore | Data storage | Europe (eur3) |
| Google Firebase Authentication | Identity verification | Europe |
| Google Firebase Hosting | Application hosting | Global CDN |
| Google Cloud Functions | Backend processing | Europe |
| Resend | Sending credential/notification emails and forwarding mail received at info@oculawork.com | Provider's own infrastructure — not contractually pinned to Europe the way Google Firebase is; refer to the provider's own current data processing terms |
Customers will be notified 30 days in advance of any change to sub-processors.
OculaWork shares Customer data with third parties only:
The parties agree to provide each other with reasonable assistance in official inquiries, audits, or judicial proceedings related to personal data or information security.
The Customer is the Data Controller; OculaWork holds the status of Data Processor under KVKK Art. 3. In this capacity, OculaWork:
| Category | Example Data | Purpose | Legal Basis |
|---|---|---|---|
| Identity | Name, surname | Account management | KVKK Art. 5/2-c — Contract performance |
| Contact | Email address | Notifications | KVKK Art. 5/2-c — Contract performance |
| Health / Biometric | EAR, PERCLOS, fatigue score | OSH risk analysis | KVKK Art. 6/3 — Explicit consent / OSH Law Art. 15 |
| Behavioral | Reaction time, blink rate | OSH risk analysis | KVKK Art. 5/2-f — Legitimate interest / explicit consent |
| Organizational | Department, shift | Reporting | KVKK Art. 5/2-c — Contract performance |
| Transaction | Scan date/time | Audit trail | KVKK Art. 5/2-f — Legitimate interest |
| Physician clinical note | Permanent, immutable clinical note the occupational physician writes about an employee (see §7.2, §9.4) | Health-surveillance record integrity | KVKK Art. 6/3 — Explicit consent / OSH Law Art. 15 |
| Survey response | The employee's answer to a single-question survey published by management | OSH risk analysis (OwO input, see §7.4), reporting | KVKK Art. 5/2-f — Legitimate interest / explicit consent |
| Technical bug report | Free text written by the user + automatically captured browser error/device info (see §9.4) | Diagnosing and fixing software issues | KVKK Art. 5/2-f — Legitimate interest |
| Notification/reminder | Device push token for instant notifications; the reminder note and time the physician sets for a specific employee | Health-surveillance follow-up, system notifications | KVKK Art. 5/2-c — Contract performance / Art. 6/3 |
| Data Type | Retention Period |
|---|---|
| Scan metrics and reports | Active subscription + 2 years (statute of limitations protection) |
| Account and identity data | 90 days after contract termination |
| Transaction logs | 6 months |
| OwO training samples (anonymous feature vector + label) | 180 days — automatically deleted on every training run |
Facial biometric template (faceEmbedding — for face verification) | For the duration of the active subscription; deleted immediately and automatically when the employee requests data deletion or the account is closed |
On-device learning model weights (federated_weights — see §7.4) | For the duration of the active subscription; deleted when the employee requests data deletion or the account is closed. These weights may have previously been averaged (federated) together with other employees' models at the same company — deleting the individual document does not guarantee the mathematical trace of its contribution is fully removed from earlier aggregate averages |
| Physician clinical notes | Indefinite; cannot be edited or deleted once written (see §9.4) — a deliberate design choice to preserve the integrity of the health-surveillance record |
| Alert/warning records, clinical verdict feedback, exam scheduling records, failed face-verification security log | NOT automatically deleted by an employee's own "Delete My Data" request — retained deliberately, for the same reason as physician clinical notes (OHS/security audit-trail integrity). Deletion, if required, can be requested through admin at info@oculawork.com. |
| Bug reports and technical diagnostics | Until manually deleted by OculaWork's admin |
| After deletion request | Destroyed within 30 days of request date (physician clinical notes excepted — see above) |
Employees exercise their KVKK rights through their employer (Customer). OculaWork fulfills these requests upon Customer direction within 30 days:
For the objection right above to be exercised meaningfully, the Platform's automated/semi-automated processing points that may produce a result concerning an employee are identified explicitly: (i) the fatigue risk level produced by the daily scan (low/medium/high/critical), (ii) statistical anomaly-detection alerts based on CUSUM and Isolation Forest, and (iii) the sector-context score (owoContextScore, see §7.4) that the "OwO" sector-wide learning model produces, based on that scan's anonymous numeric profile, shown solely for informational purposes — all three are shown only to the occupational physician and none of them alone translates into an automated personnel decision. OwO's training data and model weights are anonymous and never reveal any employee's identity; however, the sector-context score the consult layer produces for informational purposes is a scan-specific, informational indicator and constitutes processing point (iii) above. If an employee believes a risk level, an anomaly alert, or the sector-context score has been used as the sole basis for an adverse personnel decision concerning them (reassignment, discipline, etc.), they may object to their employer; the employer is responsible for ensuring such an objection is reviewed by a human (occupational physician/HR) before being acted upon.
Under KVKK Art. 3/1-d, personal data means any information relating to an identified or identifiable natural person. Data that has been irreversibly anonymized falls outside this definition, and KVKK provisions do not apply to it. On this basis, OculaWork trains a sector-wide statistical learning model ("OwO") using scan and self-assessment data from Customers, regardless of whether they use shared or self-hosted infrastructure (see item 5 below). OculaWork aims to ensure that this anonymization process is irreversible through the technical and organizational measures described below.
This processing is limited by the following technical and legal safeguards:
Transparency: The full technical detail of this processing — including which data source is reduced to which signal — is documented in the OculaWork Technical Methodology Document (in the section titled "OwO Training Model") and is available to the Customer and data subjects upon request.
KVKK legislation and Board precedent may change over time. In the event of a regulatory change, the parties will cooperate in good faith, within a reasonable time, to bring this Agreement and related practices into compliance with the updated legislation.
EAR, PERCLOS and fatigue scores may qualify as sensitive personal data under KVKK Article 6 and require additional protection.
The Platform's optional facial biometric (face-embedding) feature used for login/identity verification is a distinct risk category from fatigue-scan metrics (EAR/PERCLOS etc.): it is a biometric identity capture mandated by the employer directly. In its Decision No. 2022/797 of 04.08.2022, the KVKK Board found facial-recognition-based entry/exit tracking unlawful for lacking any valid processing condition under Art. 6; more significantly, in its Principle Decision No. 2026/921 of 29.04.2026, the Board held that biometric data processing for attendance-tracking purposes is unlawful even where the employee's explicit consent has been obtained — reasoning that the structural power imbalance in the employment relationship undermines whether such consent is truly "freely given." Accordingly, relying on explicit consent alone may not by itself render biometric processing lawful. Before enabling this feature, the Customer should assess (i) proportionality, necessity, and data minimization, (ii) whether a less intrusive alternative (e.g., encrypted card/PIN, RFID/NFC ID card, or device binding) would suffice, and (iii) consult its own legal counsel. OculaWork does not perform this assessment on the Customer's behalf and assumes no legal risk in this regard.
In the event of a detected security breach, Customers and, where applicable, the KVKK Authority will be notified in writing within 72 hours (KVKK Art. 12/5). The Customer is likewise obligated to notify OculaWork without delay upon becoming aware of a security incident on its own side (its own accounts, network, or systems) that could affect Platform data.
| Role | Data Accessible | Data Not Accessible |
|---|---|---|
| Employee | Only their own scan results, their own AI Life Coach content, their own periodic self-screening record, their own survey answer | Any other employee's data; clinical notes the physician has written about them; their own submitted bug reports and technical diagnostics (visible only at the moment of submission, thereafter accessible only to OculaWork's own admin) |
| Management / HR | Department-level anonymous/aggregated statistics (min. 5-person groups), personnel/exam management, individual survey answers, the Character–Role Fit Index (an aggregate statistic — a single percentage and confidence value — shown only once at least 10 employees have completed the Character Analysis; see §7.4) | Individual scan detail, AI Life Coach content (GAD-7/PHQ-9/CBI, including any individual Character Analysis result), periodic self-screening anamnesis, bug reports/technical diagnostics |
| Occupational Physician | Individual health-surveillance/scan data within their own tenant, TİTCK drug matching, periodic self-screening anamnesis, official exam records, their own permanent clinical notes (see §7.1, §7.3 — indefinite retention, cannot be edited or deleted), their own clinical-accuracy feedback on scans | Employee's AI Life Coach content (GAD-7/PHQ-9/CBI, Calm Down, Character) — closed to the physician as well; bug reports/technical diagnostics |
| OculaWork Admin | Tenant/subscription management, anonymous Data Pool statistics, Module Usage Dashboard (counts only), OwO training history (weights/scores only), bug reports and automatically captured technical diagnostics from all users (see §7.1) — never shared with the reporting user's own employer (management/physician) | Any employee's individual data, AI Life Coach content, anamnesis free text, the content of physicians' clinical notes — see §7.4 |
To fulfill its Data Controller obligations under KVKK, the Customer may request information and documentation regarding OculaWork's data processing practices. OculaWork will provide such information at a reasonable frequency and upon at least 15 days' prior written notice, without disclosing its own trade secrets or information belonging to other Customers. On-site audits or independent third-party audits are possible only under scope, duration, and confidentiality terms agreed in writing in advance by both parties; unless otherwise agreed, audit costs are borne by the requesting Customer.
Anyone who identifies a security vulnerability on the Platform may report it only to info@oculawork.com, under the principles of Responsible Disclosure. Active penetration testing, load testing, fuzzing, or similar activity carried out without OculaWork's prior written consent is not covered by this provision and remains subject to the Prohibited Uses clause in §11.1.
Should OculaWork incur liability for any reason, its total liability is limited to the subscription fees paid in the 12 months preceding the breach. This limitation does not apply in cases of willful misconduct, gross negligence, intellectual property infringement, or breach of confidentiality/data-security obligations.
Neither party shall be liable for failure to perform its obligations under this Agreement for the duration of, and to the extent directly caused by, a force majeure event.
If any employee files a claim against the employer (Customer) related to Platform data, OculaWork is not a party to that dispute. The Customer agrees to indemnify OculaWork and cover any resulting costs.
The user is personally responsible for all actions taken from their own account. If a password is shared with a third party, all resulting consequences (including data access, unauthorized transactions, or data breaches) are the responsibility of the sharing user and/or the Customer; OculaWork cannot be held liable for this. User accounts are personal to the individual user; shared use of an account by multiple people constitutes a license violation, and OculaWork reserves the right to suspend the account in such a case.
OculaWork does not carry professional liability (errors & omissions) insurance or any other insurance coverage for the services under this Agreement.
Except as expressly stated in this Agreement, the Platform is provided "as-is" and "as-available." OculaWork makes no express or implied warranty that the Platform will operate uninterrupted, error-free, or entirely free of security vulnerabilities, or that it will be fit for a particular purpose, merchantable, or meet the Customer's expectations.
The Platform's software, source code, algorithms, design and brand are the exclusive intellectual property of OculaWork. Customers are granted a non-exclusive, revocable, limited, worldwide usage license scoped to their subscribed number of users. This license may not be transferred, rented out to another company, or sub-licensed; the Platform may not be copied or reverse-engineered under any circumstances. The license is valid only for the number of active users (seats) actually purchased/subscribed to; if usage exceeds the licensed quota, the Customer will be asked to purchase additional seats. If the licensed number of users is systematically exceeded, OculaWork may retroactively invoice for the excess usage or suspend the account. This Agreement does not transfer any right in the OculaWork brand, trade name, algorithms, or any pending patent applications to the Customer.
Raw scan results and reports belonging to the Customer and its employees remain the Customer's property. OculaWork processes this data solely within the scope of this Agreement; anonymized and aggregated statistics may be used for Platform improvement.
The Platform may incorporate third-party open source software. License rights to such software belong to the respective license holders. Use of open source components does not diminish OculaWork's intellectual property rights under this Agreement.
The Customer may not use OculaWork's brand, logo, or trade name for advertising, reference, or promotional purposes without OculaWork's prior written consent.
Unless otherwise agreed in writing, OculaWork may use the Customer's trade name solely in its reference customer list. The Customer may withdraw this permission at any time by written notice.
Before terminating the Agreement, OculaWork reserves the right to temporarily suspend the Customer's account in the following cases: (i) the Platform or its infrastructure is under an active cyberattack, (ii) suspected unauthorized access/misuse originating from the account, (iii) payment delay (see §13.3), (iv) API abuse, bot traffic, denial-of-service (DDoS) attempts, unauthorized automation, or an unusually high volume of requests (see §11.1 Prohibited Uses). In case (iv), the account may be suspended without prior notice in order to protect the integrity of the Platform or of other Customers. During suspension, access to Customer data is temporarily restricted but not deleted; access is restored once the situation is resolved.
Either party may terminate the Agreement with 30 days' prior written notice.
OculaWork reserves the right to terminate immediately and without compensation in the following cases:
Where a competent court order exists, or where an administrative/legal regulation legally requires it, OculaWork may partially or fully suspend/remove the Platform. To the extent this arises from a legal requirement outside OculaWork's control, it is treated as an exclusion from liability under §10.3.
As of today, the Platform does not set a classic HTTP cookie; the following technical storage mechanisms are kept in the browser's local storage (localStorage):
| Mechanism | Purpose | Type | Duration |
|---|---|---|---|
| ow_lang | Language preference | Functional | localStorage (persistent) |
| Firebase Auth Token | Session management | Essential | 1 hour |
| "Remember Me" token and per-role remembered-email keys | Remembering the session/email for the next login | Functional | localStorage (until logout/reset) |
| Device-pairing (biometric login) key | Remembering that this device was previously paired for biometric login | Functional | localStorage (until reset) |
| Notification preference and device push-token keys | Remembering the notification on/off preference and delivery address | Functional | localStorage (persistent, until disabled) |
| Firm code / last-connected tenant cache | Routing the login screen to the correct firm for self-host tenants | Functional | localStorage (persistent) |
| App version and scan cache | Showing the last known data during offline/delayed connections, update checks | Functional | localStorage (persistent, until updated) |
| Subject | Contact |
|---|---|
| Data protection requests / Data deletion | info@oculawork.com |
| Technical support | info@oculawork.com |
| Legal notices | info@oculawork.com |
| Security vulnerability disclosure | info@oculawork.com |
Data protection requests are responded to within 30 days. To file a complaint with the Turkish Personal Data Protection Authority: kvkk.gov.tr
Notices sent to the email address provided by the parties under this Agreement are deemed delivered on the date sent. The Customer is responsible for keeping its contact information up to date. A message being routed to the recipient's spam/junk folder results from the recipient's own email provider filtering settings; OculaWork cannot be held liable for this. The parties are obligated to notify each other in writing of any change to their contact information within 7 days; the party that fails to do so is responsible for any consequences arising from the failure.
Invoices are issued as e-Invoice or e-Archive Invoice, as permitted by applicable regulations, and are sent and deemed delivered via email.
The Customer represents and warrants that it will not use the Platform in violation of applicable export control and sanctions laws of Turkey or of international bodies/jurisdictions such as the United Nations, European Union, or United States; and that it will not access the Platform on behalf of a person/entity on a sanctions list or from a sanctioned country.
The Customer may not assign this Agreement without OculaWork's prior written consent. In the event of a merger, share transfer, asset sale, or similar corporate restructuring, OculaWork may assign this Agreement and the rights and obligations arising from it to a third party, provided the Customer is notified in advance.
In the event of a conflict between the text of this Agreement and its appendices (Appendix-1 Data Processing Agreement, Privacy Policy, KVKK Disclosure Notices, Consent Form), the following order of precedence applies: (i) Appendix-1 Data Processing Agreement (solely with respect to data-processing provisions), (ii) the main text of this Agreement, (iii) other appendices and separate documents. Notices are given in Turkish unless otherwise specified; in the event of a conflict between the TR/EN texts, the Turkish text prevails.
Each party agrees not to disclose to third parties, and to use solely for the performance of this Agreement, the other party's trade secrets, pricing information, algorithm and software architecture details, customer/employee lists, and other information expressly marked as confidential that it learns of or gains access to under this Agreement. This obligation does not extend to information that is publicly available, must be disclosed under legal requirement, or is independently developed; it survives termination of this Agreement for a reasonable period.
A party's failure to exercise, or delay in exercising, any right arising from this Agreement in a given instance does not constitute a waiver of that right, whether in that instance or in any future instance of the same or a similar nature.
This Agreement and its appendices (Appendix-1 Data Processing Agreement, together with the other documents referenced in §16.3) constitute the entire agreement between the parties regarding their subject matter and supersede all prior written or oral discussions, proposals, and agreements on the same subject. This Agreement may only be amended in writing by OculaWork (see the update-notice provision in §16).
Regardless of the reason this Agreement terminates, provisions that by their nature are intended to remain in effect after termination continue to survive; these include, in particular, Confidential Information (§16.6), Intellectual Property (§11), Indemnification (§16.5), the personal-data-protection provisions (§7), and the Evidentiary Agreement (§16.4).
This appendix is an integral part of this Service Agreement and governs the data-processing relationship between the Customer and OculaWork under KVKK Art. 3. It is a consolidated summary of the relevant provisions within the main text; in case of conflict, the corresponding section of the main text prevails.
| Element | Description |
|---|---|
| Data Controller | Customer |
| Data Processor | OculaWork (see §1 Definitions) |
| Subject Matter and Duration of Processing | For the duration of this Agreement, for OSH risk analysis and related purposes (see §7.1 table) |
| Categories of Data Subjects | The Customer's employees |
| Categories of Personal Data | Identity, contact, health/biometric, behavioral, organizational, transaction data (see §7.1 table) |
| Processing Instructions | OculaWork processes personal data only per the Customer's instructions and for the purposes stated in this Agreement; it does not process for a different purpose (see §7.0, §7.4) |
| Processor's Obligations | See §7.0 |
| Sub-Processor | Google Firebase / Google Cloud (see §4.2); the Customer is notified in advance of any change |
| Security Measures | See §9 (Data Security) |
| International Transfers | Data is stored in the European region (eur3); any transfer is subject to the KVKK Art. 9 regime (see §4.2) |
| Breach Notification | Within 72 hours (see §9.3) |
| Deletion Procedure | Data is returned to the Customer upon request at contract end; permanently deleted after 90 days, with written confirmation to the Customer (see §4.3, §13.4) |