Back

Last updated: September 25, 2026Part of the Terms of Use, version 2026-09-25.2

Data Processing Terms

A business that uses WorkIsHere decides why and how its people’s attendance is recorded, and we process that data for it. These terms are the agreement the GDPR (Art. 28) and KVKK (Law No. 6698) require between the two. They are part of the Terms of Use, and a business accepts them together.

At a glance

Controller
The business (the employer)
Processor
FreedX Technologies OÜ
Where data is stored
In the EU (Ireland)

Who these terms are between

These terms are between each business that uses WorkIsHere (“the business”), as the controller (veri sorumlusu), and FreedX Technologies OÜ (“we”), as its processor (veri işleyen). They cover the personal data of the business’s people that we process in the service.

For the account and billing data of owners, and for running the service itself, we are the controller, and the Privacy Policy applies instead.

If these terms and the rest of the Terms of Use differ about processing personal data, these terms apply. We change them only as “Changes to these terms” in the Terms of Use describes, and ask each business to accept a change before it applies. An Enterprise agreement may replace them with a signed data processing agreement.

The processing

What we process for the business, and why:

  • Subject and purpose: recording attendance for the business, as it sets the service up: check-ins and check-outs, location checks during shifts, optional auto-pilot, working hours, leave and work-hour requests, notifications and the records managers review.
  • Duration: while the business uses WorkIsHere, and afterwards until the data is deleted as described in “When the business leaves”.
  • Nature: storing, organising, showing, sending notifications about, and deleting data, in the web app and the phone apps.
  • Personal data: name, e-mail address, phone number if added, language, role and membership; check-in and check-out times with coordinates, GPS accuracy and distance to the site; location reports and whether each location check was answered; auto-pilot crossings; working hours, leave and work-hour requests; consents given in the app; device type, browser, app version and notification tokens; and the business’s audit log.
  • People concerned: the business’s employees and other staff, its managers and owners.

The service is not meant for special categories of data (such as health data). The business does not put such data in free-text fields, like a leave reason, unless the law allows it.

What the business is responsible for

As the controller, the business:

  • has a lawful basis for recording its people’s attendance and location (under the GDPR Art. 6 and KVKK Art. 5), and for each optional feature it turns on;
  • tells its people, before they start, how and why it uses WorkIsHere (GDPR Art. 13, KVKK Art. 10); the Privacy Policy can help, but does not replace its own notice;
  • assesses the effect on its people’s privacy before it starts where the law requires, for example with a data protection impact assessment (GDPR Art. 35), and registers with VERBİS in Turkey if the law requires it;
  • consults employee representatives or works councils where the law requires it;
  • uses WorkIsHere only for working time, keeps its settings (such as how long location reports are kept) no wider than it needs, and never uses it to follow someone outside working time;
  • answers its people’s requests about their data, with our help.

Instructions

We process the business’s personal data only on its documented instructions: these terms, the Terms of Use, and the settings and actions of its owners and managers in the service. We do not use it for our own purposes, and never sell it or use it for advertising.

If the law requires us to process the data in another way, we tell the business first, unless that law forbids it. If we think an instruction breaks data protection law, we tell the business.

Confidentiality

Only the people who need access to run the service can reach the business’s data, and they are bound to keep it confidential.

Security

We protect the data with technical and organisational measures that fit the risk (GDPR Art. 32, KVKK Art. 12), including:

  • encryption in transit (HTTPS) and at rest at our database provider;
  • separation of each business’s data by database row-level security, so no business can see another’s records;
  • access by our own staff only where it is needed to run or support the service;
  • no continuous tracking: location is read only at the moments the Privacy Policy lists, and location reports are deleted automatically after the period the business sets;
  • a log of important changes in each business, which its owners and managers can review.

We review these measures as the service changes. We may improve them, but never lower the overall level of protection.

Sub-processors

The business allows us to use the service providers listed in the Privacy Policy as sub-processors. We bind each one by a written contract to data protection obligations at least as strict as these, and we remain responsible to the business for their work.

Before we add or replace a sub-processor, we update that list and tell the owners of each business at least 30 days in advance, in the service or by e-mail. The business may object on reasonable data protection grounds within that time.

If we cannot resolve an objection, the business may end its plan before the change takes effect, and we refund what it paid on the web for the time after the end.

Transfers abroad

The database is hosted in the EU (Ireland). Some of our providers, or companies in their groups, are outside the EU, mainly in the United States (and, for Supabase, Singapore), and may reach data from there, for example for support or to deliver notifications. We allow this only with a safeguard the GDPR allows (Chapter V): the European Commission’s standard contractual clauses, which our providers’ data processing agreements include, or, for companies certified under the EU-US Data Privacy Framework, the Commission’s adequacy decision.

For a business in Turkey, using WorkIsHere is itself a transfer of personal data abroad under KVKK Art. 9. On request, we sign with the business the standard contract the Personal Data Protection Board (KVKK Kurulu) has published for such transfers; the business then notifies the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) of it within 5 business days, as the law requires.

Ask for any of these documents at omerbabadogan@gmail.com.

Helping the business

We help the business answer its people’s requests to see, correct, delete or receive their data, or to object. Managers can see and correct records in the service; for anything else, the business writes to us. If a person sends such a request to us, we pass it to their business without delay and do not answer it ourselves, unless the business asks us to.

We also give the business the information it reasonably needs about the service for its own duties: security, impact assessments, and consulting a supervisory authority (GDPR Arts. 32 to 36). On request, we send a description of the processing and of our measures to use in its data protection impact assessment.

Personal data breaches

If we become aware of a breach of security affecting the business’s personal data, we tell its owners without undue delay, and within 48 hours where we can. We tell them what happened, the data and people likely affected, the likely consequences and what we are doing about it, and add details as we learn them.

The business decides whether to notify its supervisory authority and its people (GDPR Arts. 33 and 34; in Turkey, KVKK Art. 12(5)); we help it do so.

When the business leaves

When a business ends its use of WorkIsHere (its owners archive it, ask us to close it, or switch to another provider), the owner can ask for a copy of all the data listed in “The processing”, in a common machine-readable format such as CSV or JSON, until at least 30 days after the end. We send it within 30 days of the request, free of charge.

After that, and within 90 days after the end, we delete the business’s personal data, unless the law requires us to keep some of it; copies in our providers’ backups are overwritten in their normal cycle. Location reports are deleted sooner, after the period the business set.

Information and audits

On request, we give the business the information it needs to show that these terms are kept, and answer its reasonable questions about security in writing.

If that is not enough, or a supervisory authority asks, the business, or an auditor bound to confidentiality, may audit our compliance once a year, with 30 days’ notice, at its own cost, and without access to other businesses’ data or our providers’ systems. For our providers, we rely on their own certifications and audit reports.

Liability

Liability under these terms follows “Limitation of liability” in the Terms of Use, except where data protection law does not allow it to be limited. Nothing in these terms limits a person’s rights against the business or us under the GDPR (Art. 82) or KVKK.