This policy explains how your personal data is handled when you use Oclockr. Oclockr is a time tracking and workforce management product built and operated by PowerWise.
1. Controller and contact
Data controller: PowerWise ("we").
- General contact: support@oclockr.com
- Data protection requests: privacy@oclockr.com
This policy is written under Turkish Personal Data Protection Law No. 6698 (KVKK) and aligns with the principles of the EU General Data Protection Regulation (GDPR).
2. Whose data we process
| Group | Who |
|---|---|
| User | A person holding an Oclockr account |
| Client record | Details of a person or company the user enters as their own client |
| Visitor | Someone browsing oclockr.com without an account |
An important distinction for client records: when a user enters their own client's name, trade title or tax details, the user is the controller of that data; we act as a processor. We process it only to provide the service, on the user's instructions.
3. What we process
3.1 Account data
- Full name
- Email address
- Password — stored only as an irreversible hash (bcrypt). Your plaintext password is never stored and cannot be seen by us.
- Interface language preference
- Last sign-in time
- Device details of your open sessions: browser/operating system (User-Agent) and IP address. We keep this so we can show you which devices you are signed in on and let you sign out one you don't recognise; the record is deleted when the session ends or expires.
- Marketing email opt-out preference and time
- Account deletion request time, if any
- Your role in the workspace (owner, admin, project manager, member)
- If automatic provisioning (SCIM) is in use: your email address and provider user id as sent by your employer's identity provider. Name, phone, department and similar fields are deliberately not collected — data we never receive is data we never have to protect. In this flow your employer is the data controller; we act on their instruction.
3.2 Single sign-on (SSO)
If you choose to sign in with Google or Microsoft, no password is ever created. From those providers we receive only your name, email address and a unique user identifier.
We do not access your calendar, email, files or contacts. The permissions requested are only enough to verify who you are: basic profile and keeping the session alive.
3.3 Work data
- Time entries: start and end time, duration, description, billable flag
- Projects, clients, tasks, tags
- Weekly timesheets, submission and approval states
- Proformas and their contents
- Hourly rates and amounts, where your plan includes them
- Billing profile: trade title, tax number, tax office, address
3.4 Technical data
- Server logs: request time, path, HTTP status code, request id, duration
- Session cookie (see the Cookie Policy)
- Rate-limit counters, short-lived, to prevent abuse
Our server logs never contain email addresses, passwords or session tokens. This is not a matter of policy but a rule enforced in code: permitted fields are restricted to an explicit allow-list, and a field outside that list never reaches the log.
3.5 Audit trail
Sensitive actions (timesheet approval, entry deletion, role change, subscription update) are recorded with who did them and when. This record protects both you and us, and contains no raw secrets (tokens, password hashes).
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service: tracking, reporting, timesheets, proformas | Performance of contract |
| Account creation and authentication | Performance of contract |
| Account security, abuse and fraud prevention | Legitimate interest |
| Automatic membership management from a corporate identity provider (SCIM) | Performance of the contract — on the workspace owner's instruction |
| Responding to support requests | Contract / legitimate interest |
| Billing and financial record-keeping | Legal obligation |
| Improving the service, debugging | Legitimate interest |
| Product announcements and campaign email | Consent — withdrawable at any time |
| Project/tag suggestions — from your own past entries only | Performance of the contract — no data is transferred out |
5. Where data is stored
Your data stays within the European Union:
| Layer | Provider | Location |
|---|---|---|
| Application server | Google Cloud Run | Frankfurt, Germany (europe-west3) |
| Database | Supabase (PostgreSQL) | Frankfurt, Germany (eu-central-1) |
| Cache / session | Upstash (Redis) | Europe |
| Static site hosting | Firebase Hosting | Global edge network |
6. Subprocessors and sharing
We do not sell your personal data and we do not share it for advertising. Only these providers are involved, and only to run the service:
| Provider | Purpose | Data transferred |
|---|---|---|
| Google LLC | Hosting (Cloud Run), single sign-on | All service traffic; name and email for SSO |
| Microsoft Corp. | Single sign-on — only if you choose it | Name and email |
| Supabase | Database | All application data |
| Upstash | Cache, session, rate limiting | Session identifiers, counters |
| Microsoft Corp. (Azure Communication Services) | Transactional email (e.g. password reset) | Name, email, message content |
Beyond these, your data is shared only where legally required (court order, competent authority request) and after we have reviewed the validity of the request.
International transfers
Although our providers are US-based companies, your data is held in EU regions. Where a transfer is required, the European Commission's Standard Contractual Clauses (SCCs) and the providers' data processing agreements apply.
7. Suggestions and AI
Oclockr reads the description you wrote and proposes a project and tags. The suggestion works in two tiers, and both look only at your own data; nothing leaves:
- 1 · Your history — a database query over which project you previously used for a similar description.
- 2 · Frequency — if you have worked mostly on a single project over the last 30 days, it proposes that project.
The language-model tier is not in use. At one point a third tier was planned that would send your text to a language model when the first two produced nothing; that tier was removed from the product. The interface offers no way to turn it on, and none of your text is sent to any external language model.
If that tier is ever offered, this notice will be updated beforehand and turning it on will require your explicit consent.
Automated decision-making
No solely automated decision producing legal effects or similarly significantly affecting you is made. The AI only proposes a project and tags; accepting them is up to you.
8. Retention
| Data | Period |
|---|---|
| Account and work data | While your account is open |
| After a deletion request | 30 days frozen, then permanent deletion — with one exception, see below |
| Server logs | Up to 30 days |
| Session device details | While the session is open |
| Audit trail | For the life of the workspace (it can outlive your account; the actor is cleared) |
| Financial records | The period required by tax law (10 years) |
Why deletion is not immediate: the account is frozen first — you can still read your data, export it and reverse the decision. An irreversible accidental deletion is a greater harm than a short delay.
The one thing permanent deletion does not cover: the hours you logged inside someone else's workspace. Deleting your account removes your Oclockr account — your email address, your password, your linked identities and everything in your own personal workspace. But inside a company's workspace, the record of “who worked how many hours on which project” has that company as its data controller, not us. The company decides how long to keep that record and on what legal basis — depending on the case this may be a retention obligation (labour law, commercial books, tax rules) or a legitimate interest. We do not make that decision on the company's behalf, and we do not unilaterally delete the record on your request; the same logic as the “Financial records — 10 years” row above.
For that record, the company is who you address. A workspace owner can permanently remove your name from their own records; when they do, an unnamed label takes its place in past reports and the hours remain as the company's record. To be explicit: this removes the name, it does not anonymise the data — the record remains technically linkable to you and is therefore still personal data. If you do not know which company to contact, write to privacy@oclockr.com and we will tell you who owns the workspace in question.
9. Your rights
Under KVKK art. 11 (and GDPR arts. 15–22) you have the right to:
- Learn whether your personal data is processed
- Request information if it has been processed
- Learn the purpose and whether it is used accordingly
- Know the third parties to whom it is transferred, at home or abroad
- Request correction if it is incomplete or inaccurate
- Request erasure or destruction
- Request that corrections and erasures be notified to third parties
- Object to a result reached solely by automated analysis
- Claim compensation for damage caused by unlawful processing
Send requests to privacy@oclockr.com. We respond free of charge within 30 days at the latest.
Quicker routes
- To see or take your data: use the in-app export feature, where your plan includes it.
- To stop marketing email: no need to contact us — the link at the bottom of every announcement email is enough.
- To delete your account: request it from account settings.
Opting out of marketing does not affect transactional email: password resets, invitations and billing notices continue. Those rest on our contract with you, not on consent.
10. Security
- All traffic is encrypted with TLS (HTTPS)
- Passwords are stored irreversibly with bcrypt
- The session cookie is
HttpOnly,SecureandSameSite— it cannot be read by JavaScript - Each workspace's data is separated at query level; access to another tenant's data is not possible, and this is continuously verified by automated tests
- Row level security (RLS) is enabled at the database layer
- Admin panel access goes through a corporate identity provider with role checks
Data breach
If we determine that personal data has been unlawfully accessed, we notify the Turkish Data Protection Authority as soon as possible and within 72 hours at the latest. Affected users are informed as soon as reasonably possible.
11. Children's data
Oclockr is a business application and is not directed at anyone under 18. We do not knowingly collect personal data from children. If we discover such data, we delete it.
12. Cookies
Oclockr uses strictly necessary cookies only; no analytics, advertising or tracking cookies. See the Cookie Policy.
13. Changes
If this policy changes, the current version is published here and the effective date above changes. Significant changes are announced by email before they take effect.