Production sites with large workforces
Factories where personnel, health, entry-exit and camera data all sit side by side. The volume and variety here make keeping the inventory current by hand practically impossible.
We build a system that runs your personal data inventory, retention and disposal schedule, data subject requests and breach response records. The software manages the process and the evidence; legal interpretation and the content of your notices belong to your lawyer.
Personal data in a factory lives in far more places than assumed. Employee personnel files and payroll data, job applications, entry-exit terminal logs, camera footage, the visitor book, customer and dealer contact details, contractor staff lists, e-mail archives and backups. Some of this data is kept deliberately; much of it simply accumulates over the years — and because nobody ever makes a deletion decision, nothing gets deleted.
In most businesses, compliance with KVKK (Turkish data protection law) is done as a one-off project. The inventory is drawn up, the notices are written, the registration is filed and the folder is closed. The problem is that data and processes do not stand still: a new system is bought, a new data collection point opens, an employee leaves, a camera is added. A year later the inventory no longer reflects reality. Compliance is not a document but an arrangement that needs maintenance; compliance without maintenance exists only on paper.
The system we build aims to keep the inventory alive. Which data is held in which system, for what purpose it is processed, for how long it will be retained and with whom it is shared is on record; retention periods are tied to a calendar, and when a period expires a disposal task lands with its owner. When a data subject request arrives, a traceable flow begins: which systems were searched, what was found and what answer was given are recorded. And when a breach is suspected, the incident record, the assessment and the actions taken travel in the same place.
The boundary is clear, and we state it up front: this software makes no legal interpretation, gives no advice and does not replace your lawyer. Which processing rests on which legal basis, whether explicit consent is required, what the privacy notice says and whether a breach is notifiable are matters of legal assessment. The layer we build turns the decisions that are made into something workable, tracks the deadlines and produces evidence of the work done. That is what it means for compliance to live in a system rather than on paper.
Factories where personnel, health, entry-exit and camera data all sit side by side. The volume and variety here make keeping the inventory current by hand practically impossible.
Businesses collecting personal data through a B2B portal, e-commerce or a call line. Data collection points multiply fast on these channels and are usually never added to the inventory at all.
Firms working with an overseas group company, buyer or cloud service provider. What data a transfer covers and which basis it rests on must be on record.
Businesses bringing new software live. A new system always means a new data processing point; adding it to the inventory is usually forgotten, and the omission is discovered at the worst possible moment.
Which data is processed in which system, for what purpose, on which legal basis and with whom it is shared is put on record. The inventory is kept alive so that it is updated whenever a new system or process is added; it has an owner and a defined review cycle.
The information filed with VERBİS (Türkiye's data controllers registry) is compared against the current state of the inventory; items that diverge become visible. Changes that require the registration to be updated are flagged. You make the filing; the system puts in front of you what has changed and what needs reporting.
The retention period set for each data category is tied to a calendar. When a period expires, a disposal task is created and the completed disposal is put on record. Backups and archives are handled separately — the most commonly overlooked spot.
An incoming request is logged and turns into a defined task list of which systems to search; the records found and the answer given are stored. Deadlines are tracked. You decide the content of the answer after legal assessment; the system keeps the trail of the process.
When something suspicious surfaces, an incident record is opened: what happened, which data it covers, who was informed, the technical and organisational measures taken, and the timeline. This record is the basis of every later assessment — and if it is not kept at the time of the incident, it cannot be produced afterwards.
Privacy notices and the explicit consents obtained are stored with their versions: who was shown which version of which text, and on what date. When a text changes, the old versions are preserved. Without this record, no question about the past can be answered with evidence.
Together we map which personal data sits in which system. This step is as much fieldwork as it is technical; the data missing from the inventory usually sits in an Excel file, an e-mail folder or a camera recorder.
The decisions made by your lawyer or adviser — which processing rests on which basis, and what the retention periods are — are entered into the system as definitions. We do not make the decision; we make the decision workable and traceable.
Retention periods, review cycles and responsibilities are defined; reminders are switched on. The first pass usually uncovers a backlog of data whose period expired long ago; we decide together how to handle it.
The data subject request and breach response flows are defined, and the relevant people and permissions are assigned. These flows must not be built once and forgotten; a short drill makes clear who does what when a real incident hits.
Who reviews the inventory, and how often, is put in writing. Sustaining compliance is not a one-off installation but this routine working; the handover documentation is prepared accordingly.
No. Legal assessment, the content of your notices and whether a breach is notifiable are your lawyer's and adviser's domain. We build the software side: keeping the inventory alive, tracking deadlines, running the request and incident flows and producing evidence of the work done. Preserving that separation is in your interest too; when services are blended, responsibility blurs.
Software alone does not prove compliance; it lets you produce the evidence of it. An up-to-date inventory, disposals actually carried out, requests answered on time and incident records kept are concrete records you can show during an examination. If the content of those records is wrong, the system will not fix it — only make it visible.
They should be, and in practice they are the most overlooked areas. Camera retention periods, who can access the footage and where the recordings are kept go into the inventory. Backups likewise: deleting data from the live system while it lives on in the backups is an incomplete disposal. We raise this specifically during discovery.
No. This layer sits on top of your existing systems; the inventory registers them as sources. In some cases a small connection is needed so that a system can be searched or a disposal executed — we assess those one by one. The aim is not to build a new pile of systems, but to make the existing arrangement traceable.
The scope is sized to the scale. In a small business the inventory is short and the number of processes low, and the system is sized accordingly. The gain here is that compliance stops living in one person's memory and stays with the organisation — which matters more as the scale shrinks, because in a small business that person is usually the only one.
A living data and processing inventory; a retention and disposal calendar with disposal records; a data subject request flow and answer archive; a breach response record arrangement; privacy notice and consent version records; and an audit trail across all of it. Everything produced, source code included, belongs to you; your data stays in your own environment.
In a 30-minute discovery call we listen to what you need and tell you honestly whether custom development or an off-the-shelf product is the better answer.
We build a system that traces waste from the moment it is generated to the moment it leaves the site, feeds your declarations and tracks permit and licence deadlines. The figures are not compiled at declaration time; they fall into place the moment they are recorded.
Details →We build a system that keeps the evidence your buyer's social compliance audit will demand continuously ready, instead of gathering it as the audit approaches. Findings, corrective actions and closure evidence run in one place; you walk into audit day knowing exactly what is missing.
Details →We build a system that calculates the preferential origin of your exported products rule by rule, tracks supplier origin declarations at product and validity level, and records HS classification decisions together with their reasoning. The goal is to be able to show the calculation behind an origin claim the moment it is asked for.
Details →We build a layer that calculates the embedded emissions of the products you export to the European Union at plant, line and batch level. It combines production, energy and raw material data and produces the result in a form your buyer will accept and a verifier can trace.
Details →We build an infrastructure that collects the data behind sustainability reports at source, stores it with an auditable trail and manages the recurring reporting calendar. We are not the ones who sign the report; we produce what the report rests on.
Details →For manufacturers of machines and devices with embedded software, we build a regime that generates the software bill of materials, keeps the component and licence inventory current, monitors known vulnerabilities and establishes notification and update processes.
Details →