Personal Data Processing Policy (GDPR)

Last updated: August 2026

1. Terms and Definitions

  • “Persono” / “we” / “us” refers to Volitek Yazılım ve Bilişim Hizmetleri A.Ş., the company operating the Persono Digital HR platform at personohr.com.
  • “Client” refers to organizations that subscribe to Persono’s services.
  • “End User” refers to employees and managers who access Persono through a Client’s account.
  • “Personal Data” means any information relating to an identified or identifiable natural person.
  • “Processing” means any operation performed on personal data, including collection, storage, use, and deletion.

2. Overview

The General Data Protection Regulation (GDPR) (EU) 2016/679 establishes rules for the protection of natural persons with regard to the processing of personal data. Persono is committed to full compliance with GDPR and equivalent data protection frameworks including Turkey’s Personal Data Protection Law (KVKK).

Persono operates in the following capacities:

  • Data Processor — for personal data belonging to Client employees, processed on behalf of the Client.
  • Data Controller — for Client contact information, billing data, and Persono’s own employee records.

3. Data We Process

On behalf of our Clients, Persono may process the following categories of personal data:

  • Employee identity information (name, national ID, date of birth)
  • Contact details (email, phone, address)
  • Employment records (position, department, salary, benefits)
  • Performance and evaluation data
  • Training and competency records
  • Leave and attendance records
  • Disciplinary records
  • Documents and files uploaded by the Client

4. Legal Basis for Processing

Persono processes personal data under the following legal bases:

  • Contractual necessity — to deliver the services agreed with the Client
  • Legitimate interests — for platform security, fraud prevention, and service improvement
  • Legal obligation — where required by applicable law
  • Consent — where explicitly obtained from the data subject

5. Data Subject Rights

Under GDPR, individuals whose data is processed have the following rights:

  • Right of access — to obtain a copy of their personal data
  • Right to rectification — to correct inaccurate data
  • Right to erasure — to request deletion of their data
  • Right to restriction — to limit how their data is processed
  • Right to data portability — to receive their data in a machine-readable format
  • Right to object — to processing based on legitimate interests

Requests related to personal data held within a Client’s Persono account should be directed to the Client (Data Controller). Requests related to data held directly by Persono can be submitted to: [email protected]


6. Data Security

Persono implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure:

  • Data encryption in transit (TLS) and at rest
  • Role-based access controls
  • Regular security audits and penetration testing
  • ISO 27001-aligned information security practices
  • Secure cloud infrastructure with automated backups

7. Data Retention

Persono retains Client data for the duration of the service agreement. Upon termination, data is retained for a maximum of 90 days before permanent deletion, unless a longer retention period is required by law or agreed in writing with the Client.


8. International Data Transfers

Persono’s primary infrastructure is hosted within Turkey. Where data is transferred outside Turkey or the EEA, Persono ensures appropriate safeguards are in place in accordance with GDPR Article 46, including standard contractual clauses where applicable.


9. Sub-processors

Persono uses a limited number of trusted third-party sub-processors to deliver its services (such as cloud hosting and email delivery providers). All sub-processors are contractually bound to process data only on Persono’s instructions and in compliance with GDPR.

A current list of sub-processors is available upon request.


10. Data Processing Agreement

Clients who require a Data Processing Agreement (DPA) in accordance with GDPR Article 28 may request one by contacting [email protected]. The DPA defines the responsibilities of Persono as Data Processor and the Client as Data Controller.


11. Breach Notification

In the event of a personal data breach, Persono will notify affected Clients without undue delay and, where required, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.


12. Contact

For any questions regarding this policy or data protection practices:

Cumhuriyet Mah. FSM Bulvarı Cadde 224 Sitesi No:41A/A
Nilüfer — Bursa / Türkiye
📧 [email protected]
📞 +90 (224) 909 8170