Hedef İK
HomeTerms and policies
Mobile app privacy

Hedefik Mobile App Privacy Policy

Information about personal data, location and device permissions, retention periods and your privacy rights in the Hedefik mobile app.

Last updated: 6 October 2026

TürkçeEnglish

Terms and policies

Cookie Notice (Turkish)Cookies, analytics and preference managementTerms of Use (Turkish)Rights and responsibilities when using Hedef İKKVKK Privacy Notice (Turkish)Information about personal data processingMobile App Privacy PolicyMobile app data, permissions and privacy rights

On this page

  • 1. Who is responsible for your data?
  • 2. What data is processed?
  • 3. Location and background access
  • 4. Camera, photos and other permissions
  • 5. Purposes and legal bases
  • 6. Who receives data?
  • 7. Hosting
  • 8. Retention periods
  • 9. Account closure and deletion requests
  • 10. Security and device storage
  • 11. Your rights and requests
  • 12. Children, external links and changes
On this page
  • 1. Who is responsible for your data?
  • 2. What data is processed?
  • 3. Location and background access
  • 4. Camera, photos and other permissions
  • 5. Purposes and legal bases
  • 6. Who receives data?
  • 7. Hosting
  • 8. Retention periods
  • 9. Account closure and deletion requests
  • 10. Security and device storage
  • 11. Your rights and requests
  • 12. Children, external links and changes

Effective date: 6 October 2026
Service provider: PIXSELECT TEKNOLOJİ A.Ş. (“PIXSELECT”)
Address: ITU Teknoloji Bölgesi ARI6 Zemin Kat Z19 Maslak Sarıyer İstanbul
Contact: solution.center@pixselect.com.tr

This policy explains how personal data is collected, used, shared and retained in the Hedefik mobile app. Hedefik is a workplace application that provides access to employee information, shifts and attendance, leave, salary and payroll, advance and expense requests, the company directory, and notifications about these activities. Available features depend on your employer’s configuration and your access permissions.

Reading this policy or using the app does not constitute consent to every processing activity. Where consent is required, separate information and a choice will be provided. Granting a device permission does not, by itself, constitute explicit consent under Turkish data protection law.

1. Who is responsible for your data?

Your employer generally determines the purposes of processing employee, payroll, leave, attendance and internal approval records and acts as the data controller for those activities. PIXSELECT acts as a processor to the extent it handles these records on your employer’s behalf and instructions.

PIXSELECT may act as a controller for activities whose purposes and means it independently determines, such as its own support services, service security and legal obligations. Roles depend on the activity and contractual arrangements. Contact your employer’s HR or privacy contact for its identity and detailed employee privacy notice. This policy does not replace your employer’s processing-specific employee notice.

2. What data is processed?

Not every category is collected from every user. The information depends on the feature you use and the records maintained by your employer.

Category Examples and purpose
Account and identity Name, employee number, email, phone number and profile photo for authentication, account identification and employee profiles. Identity number, date of birth, address and other personnel details may also be displayed if present in your employer’s records.
Employment and organization Company, branch, department, job title, career, education, certificates and assigned assets for authorized personnel processes and the company directory.
Attendance and requests Shifts, workplace entry/exit events, leave, request descriptions, approval/rejection decisions and timestamps for attendance and request management.
Financial information Salary, payroll, payments, bank/IBAN details, advance and expense amounts, and receipt/invoice images for payroll and reimbursement processes. Bank details are displayed if available in your employer’s records.
Documents and communications Expense documents you upload, visa document requests where enabled, emergency contact details and support correspondence for the relevant process.
Device and session information Device identifier, model, manufacturer, operating system, app version, installation identifiers and session tokens for secure access, device association and compatibility.
Notification information Push token, app installation identifier, notification content and read status to deliver notifications about your activities to the appropriate device.
Location-related information Whether the device entered or exited a workplace area, area and monitoring session identifiers, and event timestamps for the automatic attendance feature described below.
Technical and security records IP address, request/action timestamps, errors and connection information for service delivery, troubleshooting and abuse prevention.

Data is obtained electronically from you, authorized employer users and systems, your device, operating system events and the service infrastructure. Passwords or one-time verification codes are used for authentication and verification. Do not include them in support messages.

3. Location and background access

Hedefik processes device location during applicable monitoring periods to detect automatic entry into and exit from your employer’s designated workplace areas and support shift/attendance records, including when the app is closed or not in use. This feature requires enabled location services and the necessary foreground/background permissions. Operating system restrictions, force-closing the app and other device limitations may affect event detection.

The feature uses workplace areas and monitoring start/end times configured by your employer. Monitoring may be enabled before a manual check-in to detect automatic arrival. Location use is therefore not limited to the interval between manual check-in and check-out.

In the current geofencing flow, the operating system compares device location with the workplace boundary. A continuous stream of GPS coordinates or a movement route is not transmitted to the server. The transmitted event includes the area and monitoring session identifiers, entry/exit type, timestamps, event identifier and platform information. These events can be linked to you and reveal your presence at a particular workplace.

Events may be queued on the device while offline and delivered when connectivity returns. Events outside a valid monitoring period are not processed for attendance. Monitoring is limited to the areas and periods enabled by the employer and is not used to continuously track routes in your private life.

You may change or revoke location permissions in device settings. Automatic entry/exit detection may then stop working; contact your employer about an alternative attendance method. The sign-out flow closes the device’s monitoring session. Previously recorded events remain subject to retention and deletion rules.

4. Camera, photos and other permissions

  • Camera: Used when you choose to photograph an expense receipt or invoice.
  • Photo selection: Images you select are used as expense attachments; your entire photo library is not uploaded. The current document capture flow does not automatically save the photo to your gallery.
  • Location: Used for workplace entry/exit detection as described above.
  • Notifications: Used to deliver updates about leave, advances, expenses and related workplace activities. Refusing this permission does not prevent access to notifications inside the app.

Permissions can be managed in device settings. Refusal may limit the corresponding feature. Images may contain information about other people or retained metadata such as dates or location; upload only what the process requires. If a health report or other sensitive data is required, your employer must provide the appropriate legal basis and separate notice. Avoid unnecessary sensitive information.

The employee directory is built from company records, rather than bulk collection of your phone’s contacts. The current mobile features do not use microphone recording or advertising-related tracking across apps.

5. Purposes and legal bases

Data is processed to authenticate your corporate account, enforce access permissions, manage employee and request workflows, display attendance and financial records, send notifications, provide support and protect service security.

For processing in Türkiye, applicable grounds under Article 5 of Law No. 6698 on the Protection of Personal Data (“KVKK”) include contractual necessity, legal obligations or express statutory provisions, establishing/exercising/protecting rights, and legitimate interests that do not override your fundamental rights. Where another appropriate ground is unavailable, separate explicit consent is obtained for the relevant activity. Where special-category data is involved, the applicable Article 6 condition and additional safeguards apply.

Your employer’s notice identifies the basis for the specific employee activity. Employment legislation does not automatically require location collection from every employee. The necessity and proportionality of location processing must be assessed for the particular workplace and feature.

Hedefik does not use personal data for sale or targeted advertising. The current mobile version does not integrate an advertising SDK, Google Analytics or Firebase Crashlytics. New purposes will be reflected in this policy and any required notices.

6. Who receives data?

Data may be disclosed to the following recipients to the extent necessary for the relevant purpose:

Recipient Purpose and relevant information
Authorized employer users HR, finance and relevant managers perform personnel, attendance, payroll and request processes within their permissions. Limited professional directory information may be displayed to authorized colleagues.
PIXSELECT and technical providers Hosting, storage, security, maintenance and support, with access limited to the service purpose and authorization.
Google Firebase Cloud Messaging and Apple Push Notification Service Notification delivery using push/installation identifiers and notification payloads. Notifications may appear on the lock screen; you can manage preview settings on your device.
Update infrastructure Checking and downloading app updates using IP addresses, an update-specific device identifier, version/channel and compatibility information. The update server is hosted on Microsoft Azure servers in European regions and uses the Capawesome Live Update SDK.
SMS verification provider, when used Phone number and delivery information to send a sign-in code. Provider: Verimor Telekomünikasyon A.Ş..
Competent authorities and legal advisers Records required by legal obligations, valid official requests or protection of rights.

Personnel records are not made available to other companies outside your employer’s directory or approval authorization. Using a technical SDK does not mean that all personnel, payroll or expense records are sent to its provider.

The notification SDK may process technical installation information needed for its operation independently of operating system notification permission. Identifiers used by Firebase and its deletion processes are described in Firebase’s privacy information.

7. Hosting

Main service and database hosting provider and region: Microsoft Azure — servers in European regions.
Update server and backups: Hosted on Microsoft Azure servers in European regions.

8. Retention periods

Data is retained only for the necessary purpose and the applicable statutory period. The following schedule does not prescribe a single period for all information:

Record Retention rule
User account and current profile While needed for corporate access. Unnecessary profile copies are deleted after access ends; statutory employee records are assessed separately.
Private-sector workplace records subject to social security retention, including qualifying payroll and attendance documents 10 years from the beginning of the year following the relevant year. Different statutory periods may apply, including 30 years for public-sector employers.
Tax and commercial records, including qualifying receipt/invoice and financial transaction documents 5 years under the Tax Procedure Law and 10 years under the Turkish Commercial Code. Where both apply, the longer applicable obligation controls; the starting point follows the relevant statutory calendar-year rule.
Raw geofence events delivered to the server and not incorporated into a statutory attendance document Up to 30 days after delivery. Necessary results incorporated into statutory records follow the corresponding record category above.
Geofence events waiting on the device Until delivery, monitoring session cleanup or removal under the local queue limit. This is different from the server’s 30-day period.
Routine technical error and security logs Up to 90 days after creation. Records needed for a specific security incident or legal dispute are separately restricted.
Routine support correspondence Up to 1 year after closure. Requests that constitute legal records are assessed under the applicable obligation.
Active push tokens and session credentials While necessary for the relevant device/session; active use ends on revocation, invalidation or replacement. Audit records follow log retention rules.
Deleted records in rolling backups managed by PIXSELECT Removed from the backup cycle within 90 days of deletion from active systems, excluding legally required archives.

Statutory periods apply to qualifying documents, not as a general justification for keeping all location events or device information for ten years. Data is deleted, destroyed or anonymized once its period expires and no other valid processing ground remains.

A documented dispute or legal retention requirement may justify longer retention of only the necessary records, for the necessary time, with restricted access. Merely awaiting a general employer approval does not justify indefinite retention.

Google states that Firebase installation IDs can take up to 180 days to be removed from live and backup systems after the deletion API call. Deleting a push token does not perform this operation. Firebase’s data processing information.

9. Account closure and deletion requests

Signing out, uninstalling the app or disabling account access does not delete all personal data held on servers. Closing access and deleting data are separate actions.

You can submit an account or data deletion request to your employer’s HR/privacy contact or solution.center@pixselect.com.tr. Using the subject “Hedefik — account/data deletion request” and providing your registered email and employer helps route the request. Only information necessary to verify your identity is requested.

PIXSELECT assesses requests for data for which it is controller in accordance with applicable law. For employer-controlled records, it assists in directing the request to the relevant employer. You will be informed about deletable data, records that must be retained, the reasons and the processing timeline. KVKK requests are normally answered within 30 days; this response deadline is not a promise to delete every record unconditionally within 30 days.

10. Security and device storage

Access authorization, secure session management and encrypted communications with production services are among the safeguards used. The mobile app keeps short-lived access tokens in memory and refresh tokens in protected iOS/Android storage. Installation association information and some technical records may be held in local device storage.

The mobile app is not designed around advertising cookies; it uses functional local storage. Clearing device data or uninstalling the app does not delete employer records on servers. No information system provides absolute security. Protect your account and device, do not share passwords, and report suspicious access.

11. Your rights and requests

Under Article 11 of the KVKK, you may request information about processing, its purposes and recipients; correction of inaccurate information; deletion/destruction and notification of recipients where the conditions apply; object to adverse results arising solely from automated analysis; and seek compensation for damage caused by unlawful processing. Rights under other applicable laws remain available. See the Turkish authority’s information on individual rights.

Submit requests to the relevant controller using legally recognized methods. For PIXSELECT, you can contact the address above from your registered email or send a written request to its registered address. Requests meeting the legal requirements are answered within 30 days. You may complain to the Turkish Personal Data Protection Board where the applicable conditions are met.

12. Children, external links and changes

Hedefik is intended for corporate employee users and is not a service directed at children. If unnecessary or mistakenly submitted children’s data is identified, appropriate correction/deletion steps are taken with the relevant controller.

Services opened through external links may have their own privacy policies. Hedefik’s obligations concerning the purposes of any disclosures to those services continue to apply.

When this policy changes, the updated text and revision date will be published. Material changes in data use will also be communicated through the app or another appropriate channel, with separate consent obtained before processing where required.

Questions: PIXSELECT TEKNOLOJİ A.Ş. — solution.center@pixselect.com.tr.

Related documents

Cookie Notice (Turkish)Cookies, analytics and preference managementTerms of Use (Turkish)Rights and responsibilities when using Hedef İKKVKK Privacy Notice (Turkish)Information about personal data processing
solution.center@pixselect.com.tr

PIXSELECT TEKNOLOJİ A.Ş.