Skip to document
EN TR

Legal document

Privacy Policy

Effective: 4 September 2026 Published by PowerWise

This policy explains how your personal data is handled when you use Oclockr. Oclockr is a time tracking and workforce management product built and operated by PowerWise.

1. Controller and contact

Data controller: PowerWise ("we").

This policy is written under Turkish Personal Data Protection Law No. 6698 (KVKK) and aligns with the principles of the EU General Data Protection Regulation (GDPR).

2. Whose data we process

GroupWho
UserA person holding an Oclockr account
Client recordDetails of a person or company the user enters as their own client
VisitorSomeone browsing oclockr.com without an account

An important distinction for client records: when a user enters their own client's name, trade title or tax details, the user is the controller of that data; we act as a processor. We process it only to provide the service, on the user's instructions.

3. What we process

3.1 Account data

  • Full name
  • Email address
  • Password — stored only as an irreversible hash (bcrypt). Your plaintext password is never stored and cannot be seen by us.
  • Interface language preference
  • Last sign-in time
  • Device details of your open sessions: browser/operating system (User-Agent) and IP address. We keep this so we can show you which devices you are signed in on and let you sign out one you don't recognise; the record is deleted when the session ends or expires.
  • Marketing email opt-out preference and time
  • Account deletion request time, if any
  • Your role in the workspace (owner, admin, project manager, member)
  • If automatic provisioning (SCIM) is in use: your email address and provider user id as sent by your employer's identity provider. Name, phone, department and similar fields are deliberately not collected — data we never receive is data we never have to protect. In this flow your employer is the data controller; we act on their instruction.

3.2 Single sign-on (SSO)

If you choose to sign in with Google or Microsoft, no password is ever created. From those providers we receive only your name, email address and a unique user identifier.

We do not access your calendar, email, files or contacts. The permissions requested are only enough to verify who you are: basic profile and keeping the session alive.

3.3 Work data

  • Time entries: start and end time, duration, description, billable flag
  • Projects, clients, tasks, tags
  • Weekly timesheets, submission and approval states
  • Proformas and their contents
  • Hourly rates and amounts, where your plan includes them
  • Billing profile: trade title, tax number, tax office, address

3.4 Technical data

  • Server logs: request time, path, HTTP status code, request id, duration
  • Session cookie (see the Cookie Policy)
  • Rate-limit counters, short-lived, to prevent abuse

Our server logs never contain email addresses, passwords or session tokens. This is not a matter of policy but a rule enforced in code: permitted fields are restricted to an explicit allow-list, and a field outside that list never reaches the log.

3.5 Audit trail

Sensitive actions (timesheet approval, entry deletion, role change, subscription update) are recorded with who did them and when. This record protects both you and us, and contains no raw secrets (tokens, password hashes).

PurposeLegal basis
Providing the service: tracking, reporting, timesheets, proformasPerformance of contract
Account creation and authenticationPerformance of contract
Account security, abuse and fraud preventionLegitimate interest
Automatic membership management from a corporate identity provider (SCIM)Performance of the contract — on the workspace owner's instruction
Responding to support requestsContract / legitimate interest
Billing and financial record-keepingLegal obligation
Improving the service, debuggingLegitimate interest
Product announcements and campaign emailConsent — withdrawable at any time
Project/tag suggestions — from your own past entries onlyPerformance of the contract — no data is transferred out

5. Where data is stored

Your data stays within the European Union:

LayerProviderLocation
Application serverGoogle Cloud RunFrankfurt, Germany (europe-west3)
DatabaseSupabase (PostgreSQL)Frankfurt, Germany (eu-central-1)
Cache / sessionUpstash (Redis)Europe
Static site hostingFirebase HostingGlobal edge network

6. Subprocessors and sharing

We do not sell your personal data and we do not share it for advertising. Only these providers are involved, and only to run the service:

ProviderPurposeData transferred
Google LLCHosting (Cloud Run), single sign-onAll service traffic; name and email for SSO
Microsoft Corp.Single sign-on — only if you choose itName and email
SupabaseDatabaseAll application data
UpstashCache, session, rate limitingSession identifiers, counters
Microsoft Corp. (Azure Communication Services)Transactional email (e.g. password reset)Name, email, message content

Beyond these, your data is shared only where legally required (court order, competent authority request) and after we have reviewed the validity of the request.

International transfers

Although our providers are US-based companies, your data is held in EU regions. Where a transfer is required, the European Commission's Standard Contractual Clauses (SCCs) and the providers' data processing agreements apply.

7. Suggestions and AI

Oclockr reads the description you wrote and proposes a project and tags. The suggestion works in two tiers, and both look only at your own data; nothing leaves:

  • 1 · Your history — a database query over which project you previously used for a similar description.
  • 2 · Frequency — if you have worked mostly on a single project over the last 30 days, it proposes that project.

The language-model tier is not in use. At one point a third tier was planned that would send your text to a language model when the first two produced nothing; that tier was removed from the product. The interface offers no way to turn it on, and none of your text is sent to any external language model.

If that tier is ever offered, this notice will be updated beforehand and turning it on will require your explicit consent.

Automated decision-making

No solely automated decision producing legal effects or similarly significantly affecting you is made. The AI only proposes a project and tags; accepting them is up to you.

8. Retention

DataPeriod
Account and work dataWhile your account is open
After a deletion request30 days frozen, then permanent deletion — with one exception, see below
Server logsUp to 30 days
Session device detailsWhile the session is open
Audit trailFor the life of the workspace (it can outlive your account; the actor is cleared)
Financial recordsThe period required by tax law (10 years)

Why deletion is not immediate: the account is frozen first — you can still read your data, export it and reverse the decision. An irreversible accidental deletion is a greater harm than a short delay.

The one thing permanent deletion does not cover: the hours you logged inside someone else's workspace. Deleting your account removes your Oclockr account — your email address, your password, your linked identities and everything in your own personal workspace. But inside a company's workspace, the record of “who worked how many hours on which project” has that company as its data controller, not us. The company decides how long to keep that record and on what legal basis — depending on the case this may be a retention obligation (labour law, commercial books, tax rules) or a legitimate interest. We do not make that decision on the company's behalf, and we do not unilaterally delete the record on your request; the same logic as the “Financial records — 10 years” row above.

For that record, the company is who you address. A workspace owner can permanently remove your name from their own records; when they do, an unnamed label takes its place in past reports and the hours remain as the company's record. To be explicit: this removes the name, it does not anonymise the data — the record remains technically linkable to you and is therefore still personal data. If you do not know which company to contact, write to privacy@oclockr.com and we will tell you who owns the workspace in question.

9. Your rights

Under KVKK art. 11 (and GDPR arts. 15–22) you have the right to:

  • Learn whether your personal data is processed
  • Request information if it has been processed
  • Learn the purpose and whether it is used accordingly
  • Know the third parties to whom it is transferred, at home or abroad
  • Request correction if it is incomplete or inaccurate
  • Request erasure or destruction
  • Request that corrections and erasures be notified to third parties
  • Object to a result reached solely by automated analysis
  • Claim compensation for damage caused by unlawful processing

Send requests to privacy@oclockr.com. We respond free of charge within 30 days at the latest.

Quicker routes

  • To see or take your data: use the in-app export feature, where your plan includes it.
  • To stop marketing email: no need to contact us — the link at the bottom of every announcement email is enough.
  • To delete your account: request it from account settings.

Opting out of marketing does not affect transactional email: password resets, invitations and billing notices continue. Those rest on our contract with you, not on consent.

10. Security

  • All traffic is encrypted with TLS (HTTPS)
  • Passwords are stored irreversibly with bcrypt
  • The session cookie is HttpOnly, Secure and SameSite — it cannot be read by JavaScript
  • Each workspace's data is separated at query level; access to another tenant's data is not possible, and this is continuously verified by automated tests
  • Row level security (RLS) is enabled at the database layer
  • Admin panel access goes through a corporate identity provider with role checks

Data breach

If we determine that personal data has been unlawfully accessed, we notify the Turkish Data Protection Authority as soon as possible and within 72 hours at the latest. Affected users are informed as soon as reasonably possible.

11. Children's data

Oclockr is a business application and is not directed at anyone under 18. We do not knowingly collect personal data from children. If we discover such data, we delete it.

12. Cookies

Oclockr uses strictly necessary cookies only; no analytics, advertising or tracking cookies. See the Cookie Policy.

13. Changes

If this policy changes, the current version is published here and the effective date above changes. Significant changes are announced by email before they take effect.