Privacy Policy
This policy explains what data the ISG3GEN web and Android applications process, why it is needed, and the choices available to you.
Data we process
We process account and contact details; company, workplace, employee, contract and compliance records; information returned by e-Government, İSG-KATİP and SGK operations you initiate; security and audit logs; and, with your permission, push subscription, camera and location data.
Purposes
Data is used to operate and secure accounts, enforce roles and tenant boundaries, perform requested occupational safety and integration workflows, send notifications, provide support and meet legal record obligations. We do not sell personal data or build advertising profiles.
Device permissions
The camera is used only for QR scanning. Location is used only by attendance and route features. Push notifications are optional and can be disabled from your profile. No write operation is submitted while the app is offline.
Retention and security
Active account data is kept while the service is used. Business, audit and statutory records are retained for the applicable legal or contractual period. Account deletion removes sign-in, profile, sessions and personal push links; legally required business records may be detached from the account and retained. Deleted data may remain under restricted access until backup cycles complete.
We use encryption in transit, encrypted credential storage, role- and tenant-scoped access, audit logs and limited administrative access.
Service providers and transfers
Hosting, content delivery, email and browser notification providers process only data necessary to deliver those services. Government systems are contacted only for a user-initiated operation. Contact us for current subprocessor information.
Your choices
You can update notification preferences and delete your account in Profile, or use the web deletion page. For Turkish data protection rights, see the KVKK notice.