fb-pixel
HRCORE Logo
verified_user SECURITY AND PRIVACY

A Controlled and Transparent Approach to Employee Data

HRCORE's privacy-first architecture supports controlled access. It does not track employee location continuously or covertly and focuses only on verifications at the moment of a transaction.

check
Transparent Data Processing
check
Role-Based Access
check
KVKK-Compliant Architecture
shield HRCORE Security Panel
security
Active Protection & Verification
2-Stage End-to-End Encryption
Active
phone_iphone
iPhone 15 Pro — Corporate Last Access: Today, 09:42 • Kadıköy Office
check_circle Approved
laptop_mac
MacBook Pro M2
Pending New Device Verification
verified
Security Status: Optimal
Continuous location monitoring is disabled. Location verification is active only when a QR code is scanned or a Beacon clock-in is confirmed.
PRIVACY-FOCUSED ARCHITECTURE

Event-Based Verification, Not Continuous Location Tracking

We respect employee privacy; we firmly reject intrusive methods that run in the background or collect continuous location data.

location_off
Continuous Location Tracking (None)

No Intrusive or Covert Monitoring

HRCORE never records, monitors, or reports where staff are throughout the day or their routes. The privacy of employees' private lives, during and outside working hours, is our red line.

  • cancel No covert GPS tracking runs in the background
  • cancel Route, travel, and geographic movement history is not stored
  • cancel No psychological pressure from surveillance is placed on employees
event_available
Event-Based Verification (Active)

Security Confirmation Only at the Moment of the Transaction

Location or distance verification is triggered only at the moment the employee scans the clock-in/out QR code. Tracking ends as soon as the transaction is complete; it is not continuous.

  • check_circle Checked only when scanning a QR or confirming a Beacon clock-in
  • check_circle Instant safe-zone and geographic boundary (geofence) confirmation
  • check_circle Transparent and auditable records that employees can also see
SECURITY PILLARS

3 Core Focus Areas That Keep You in Control

Your company data is secured at every moment with advanced modules developed for HR and IT managers.

phonelink_lock

1. Device Approval

The device approval process is an optional parameter; when your organization turns it on, an employee's first login to the mobile app or web browser requires manager approval, and unauthorized or lost devices are instantly blocked from accessing the company system.

mobile_friendly
Manager Control The "Ahmet Yılmaz - iPhone 14" device is awaiting approval.
lock_reset

2. Session Control

View active sessions in real time, and when you detect suspicious activity, end the session with one click or securely sign out all connected devices.

sync_saved_locally
Session Management 3 active devices connected • Last action: 2 min ago
admin_panel_settings

3. Permission and Action Visibility

Determine which employees can access which modules with role-based authorization. All actions that read or change data, as well as approval actions, are stored as encrypted audit logs.

history_edu
Audit Trail (Audit Log) All actions are timestamped and traceable retroactively.
SECURITY WORKFLOW

How Does the Device and Session Approval Process Work?

Every new device joining the system for the first time goes through strict security steps to integrate into the corporate network.

1
download

New Device

The employee downloads the HRCORE mobile app to their personal or corporate device and submits their first login request.

2
notifications_active

Approval Request

The system automatically sends a notification with the device details to HR and IT managers.

3
how_to_reg

Manager Decision

The authorized manager reviews the device information and approves with one click or rejects for security reasons.

4
key

Secure Session

The approved device receives a secure token and gains encrypted and authorized access to HRCORE modules.

KVKK & PRIVACY

Our Data Privacy Principles

Our Türkiye-based server infrastructure operates in full compliance with the Turkish Personal Data Protection Law No. 6698 (KVKK).

gavel

KVKK Compliance

Employee personal data is collected only on lawful grounds and under clearly defined processing conditions, and is never shared with unauthorized third parties under any circumstances.

cloud_done

Secure Server Infrastructure

Your data is kept end-to-end encrypted within Türkiye's borders on a server infrastructure with high security standards.

lock

Transparent Privacy Notice

Which data is processed, for what purpose, and for how long is always reported in a clear, understandable, and accessible way for both employees and managers.

COMMON QUESTIONS

Frequently Asked Questions

The most frequently asked questions about security, privacy, and KVKK compliance.

GET STARTED

Let's Evaluate Our Security Approach Together

Talk to our experts about HR automation that fits your company's needs and our KVKK-compliant infrastructure.