Olimpos PDKS Privacy Policy

Your privacy matters. Protect yourself with a secure VPN.
Sponsored

# Olimpos PDKS — Privacy Policy


 

**Effective date: 2026-08-25**


 

This privacy policy applies to the Olimpos PDKS mobile application (the "Application"),

published by OLIMPOS BILISIM HIZMETLERI SANAYI VE TICARET ANONIM SIRKETI

(the "Service Provider").


 

## About this Application


 

Olimpos PDKS is a workplace time-and-attendance application. It is provided to the

employees of organisations that use the Olimpos PDKS system. It is not a consumer

application: accounts are created from your employer's personnel records, the

Application does not offer account registration, and it cannot be used without an

existing employment record.


 

**Roles.** Your employer decides what personal data is processed and why, and is

therefore the **data controller** under the Turkish Personal Data Protection Law

(KVKK No. 6698). The Service Provider supplies and operates the software on your

employer's behalf as a **data processor**. Requests concerning your personal data

should be directed to your employer; the Service Provider will assist your employer

in responding.


 

---


 

## Information you provide


 

Collected when you sign in:


 

- National identification number (T.C. Kimlik No)

- Employee registration number (Sicil No)

- Mobile phone number

- Company code


 

## Information obtained from your employer's records


 

Displayed in the Application after you sign in:


 

- Your full name

- Your business unit / branch

- Whether you hold supervisory authorisation

- Your shift schedule


 

## Information collected automatically


 

- **Precise location (GPS coordinates)** — read **only at the moment you record a

clock-in, clock-out or break event**, and sent with that event so your employer can

confirm it was recorded at your assigned workplace. The Application does **not**

track or log your location in the background, and does not build a location history.

- **Push notification token** — a device-specific identifier issued by Firebase Cloud

Messaging, used solely to deliver notifications to your device.

- **Device model, platform and application version** — sent together with the push

notification token so notifications can be delivered correctly and support requests

can be diagnosed.

- **Bluetooth beacon identifiers** — the identifiers of workplace beacon devices

detected nearby, used as an alternative to GPS for confirming workplace presence.

No data is transmitted to the beacons.


 

## Information about other employees (supervisors only)


 

If your employer has granted you supervisory authorisation, the Application displays

personal data belonging to other employees within your unit: their names, their

photographs as held in your employer's records, and their attendance and break

status. This information is made available by your employer for workforce management

purposes and may be used only for those purposes.


 

---


 

## What the Application does not collect


 

For clarity, the Application does **not**:


 

- contain any advertising, analytics, or tracking software

- use cookies, pixels, advertising identifiers, or similar tracking technologies

- collect your IP address, browsing history, or usage statistics

- store or transmit camera images (see Permissions below)

- track your location in the background

- sell your personal data, or share it for advertising or analytics purposes


 

## Permissions


 

| Permission | Why it is required |

|---|---|

| Location | To confirm an attendance event is recorded at your workplace |

| Camera | **Only** to read QR codes at workplace terminals. Images are not stored or transmitted; only the decoded code is used. |

| Bluetooth | To detect workplace beacon devices |

| Notifications | To deliver shift and break reminders and company announcements |


 

You may withdraw any of these permissions in your device settings. Some attendance

features will not work without them.


 

---


 

## How information is used


 

Personal data is used solely to operate the attendance system: to authenticate you,

to record and verify attendance and break events, to display your shift schedule, to

show workforce information to authorised supervisors, and to deliver shift, break and

company notifications. It is **not** used for advertising, profiling, or marketing.


 

## Sharing and third-party services


 

Personal data is transmitted to your employer's own servers for the purposes above.


 

The Application additionally uses the following services, solely to deliver push

notifications:


 

- **Firebase Cloud Messaging** (Google) — receives the push notification token and

the content of notifications addressed to your device.

https://firebase.google.com/support/privacy

- **Apple Push Notification service** (Apple) — delivers notifications to iOS devices.

https://www.apple.com/legal/privacy/


 

Personal data is not sold and is not shared with any other third party, except where

disclosure is required by law, or is necessary to establish, exercise, or defend legal

claims.


 

## International data transfers


 

Push notification delivery involves Google and Apple infrastructure that may be

located outside Türkiye. Where applicable law requires safeguards for such transfers,

the Service Provider and your employer rely on the transfer mechanisms permitted under

KVKK and, where relevant, standard contractual clauses. No other personal data

processed by the Application is transferred abroad.


 

## Storage on your device


 

To avoid repeated sign-in, the following are stored in your device's encrypted secure

storage (iOS Keychain / Android Keystore): national identification number, employee

registration number, phone number, full name, business unit, supervisory authorisation

status, and the push notification token. Please note that on iOS this data is held 

in the system Keychain, which by design is
not erased when an application is deleted. It is removed when your employer
deactivates your personnel record (the Application then clears the stored data on next
launch), or when you erase the device. If you wish to have the locally stored data
removed, contact the Service Provider at info@olimpos.com.tr


 

## Retention


 

Attendance records form part of your employment records and are retained by your

employer for as long as required by applicable employment and tax legislation. The

Service Provider does not determine these retention periods.


 

Push notification tokens become invalid when you delete the Application, and are
removed from the employer's systems once delivery to that token fails.


 

## Security


 

The Service Provider applies physical, electronic, and procedural safeguards to the

systems it operates, and personal data held on your device is kept in the operating

system's encrypted secure storage. Where the Application connects to an employer's

on-premise server over that employer's private network, the security of that network

is the employer's responsibility.


 

## Data breach notification


 

If a data breach affecting your personal data occurs, notification will be provided in

accordance with applicable legal requirements, including notification to the Turkish

Personal Data Protection Authority (KVKK) where required.


 

---


 

## Your rights


 

Under KVKK No. 6698 you have the right to learn whether your personal data is

processed, to request information about it, to request correction of inaccurate data,

to request erasure where the legal grounds for processing no longer apply, to object

to results produced solely by automated analysis, and to claim compensation for damage

caused by unlawful processing.


 

Because your employer is the data controller, please direct these requests to your

employer. You may also contact the Service Provider at **info@olimpos.com.tr** and

your request will be forwarded to the responsible controller.


 

### California residents


 

If you are a California resident, you have the right to know what personal information

is collected, to request its deletion, to opt out of the sale or sharing of personal

information, and not to be discriminated against for exercising these rights. The

Service Provider does **not** sell or share personal information as those terms are

defined under the CCPA/CPRA. To exercise these rights, contact **info@olimpos.com.tr**.


 

## Children


 

The Application is intended solely for use by employed adults and is not directed to

children. The Service Provider does not knowingly collect personal data from children.

If you believe a child has provided personal data, contact **info@olimpos.com.tr** so

it can be deleted.


 

## Opting out


 

You can stop all further collection by uninstalling the Application. Uninstalling does

not delete attendance records already recorded in your employer's systems, which are

retained as described under Retention.


 

## Changes to this policy


 

This policy may be updated from time to time. Material changes will be published here

with an updated effective date. Previous versions are available on request from

**info@olimpos.com.tr**.


 

## Contact


 

Questions about this policy may be sent to **info@olimpos.com.tr**.