Last updated: June 15, 2026
This Privacy Policy describes how EMA Technology ("the Company", "We", "Us" or "Our") collects, uses, stores, and discloses information when You use HSE Reporter Pro — our occupational health and safety (OHS) platform, comprising the mobile Application, the web administration panel, and the supporting backend services (together, the "Service"). It also explains Your privacy rights and how applicable data protection law protects You.
We provide HSE Reporter Pro primarily to organizations (employers) who license the Service for their own occupational health and safety operations. Throughout this Policy We refer to the licensing organization as the Customer, and to the individuals who use the Service (employees, supervisors, safety personnel, physicians, inspectors, subcontractor contacts and similar) as Users.
Our role under data protection law. For most personal data processed within the Service — including incident, inspection, training, employee and occupational-health records — the Customer (the employing organization) acts as the data controller and determines the purposes of processing, and We act as a data processor acting on the Customer's documented instructions under our service agreement. For a limited set of data We control ourselves — such as account and authentication data, security logs, and basic usage analytics — We act as data controller. Where We act as processor, the Customer's own privacy notice governs the relationship with its Users, and this Policy describes the technical processing We perform.
We process personal data in accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU/EEA General Data Protection Regulation ("GDPR"). By using the Service, You acknowledge the practices described in this Privacy Policy.
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
For the purposes of this Privacy Policy:
Depending on how the Service is used, the categories of personal data processed may include the following, grouped here by purpose.
To create and manage User accounts and control access, We process:
The core purpose of the Service is to record and manage OHS information on behalf of the Customer. This can include:
Where applicable, the Service processes occupational-health examination records on the Customer's behalf and in support of the Customer's legal obligations under Turkish OHS legislation. This is special-category (sensitive) data and may include:
We process this data strictly as a processor, on the documented instructions of the Customer, and to enable the Customer to meet its legal obligations. Access is limited to authorized personnel.
With Your permission, the Application collects Your device location (precise and approximate GPS) only to provide the following safety features:
Location is collected only while You are actively using the Application or while an emergency alarm is active in the foreground. We do not collect Your location in the background, and We do not use Your location for advertising, analytics or tracking.
Location data is shared only with Your own organization (Your employer's designated health & safety administrators) for the purposes described above. It is not sold or shared with any other third party. You can decline location access, in which case these features will be limited but the rest of the Application remains usable. You can change the location permission at any time in Your device settings.
If the fall-detection safety feature is enabled, the Application reads the device's motion sensor to detect a possible fall. This motion data is processed locally on Your device and is not stored or transmitted; only if a fall results in an emergency do We transmit the resulting emergency alert and location as described above.
When You use the Service We automatically collect certain data, including:
To provide tamper-evidence for certain records, the Service may submit a cryptographic hash of a report to a qualified Timestamp Authority and store the resulting timestamp token. The Timestamp Authority receives only the hash and the metadata needed to issue a timestamp — not the underlying personal data of the report.
Where We act as controller, and to the extent the Customer acts as controller for data We process on its behalf, processing relies on one or more of the following legal bases under KVKK and GDPR:
We do not sell personal data. We share personal data only as described below.
Data entered into the Service is accessible to the Customer organization and to its authorized Users. Strict data isolation is enforced so that one Customer's data is not visible to another.
We engage carefully selected third parties to process personal data on our behalf, under contractual confidentiality and data-protection obligations. We disclose these by category rather than by name; current categories of sub-processor include:
| Category | Purpose |
|---|---|
| Cloud database & authentication | Hosting the application database, managing accounts, sessions and authentication. |
| Cloud object storage / CDN | Storing and delivering photos, documents and other uploaded files. |
| Web application hosting | Serving the Admin Panel and related web infrastructure. |
| Transactional email delivery | Sending operational emails and notifications. |
| Push-notification delivery | Delivering mobile push notifications, including safety-critical alerts. |
| Bot / abuse protection (CAPTCHA) | Protecting sign-in against automated attacks. |
| Timestamp Authority | Issuing qualified cryptographic timestamps for tamper-evidence. |
| Mapping / map tiles | Rendering maps for location features. |
| Official OHS reporting systems | Transmitting occupational-health and training records to the competent government system where the Customer is legally required to report. |
You may request the current list of named sub-processors by contacting Us using the details below.
The Service is operated from Turkey, and some of our sub-processors may store or process data outside Türkiye and outside the EU/EEA. Where personal data is transferred internationally, We rely on appropriate safeguards required by KVKK and GDPR — such as adequacy decisions, Standard Contractual Clauses, or your explicit consent where applicable — and apply supplementary measures where appropriate to keep the data protected.
We retain personal data only for as long as necessary for the purposes described in this Policy and for the duration of the Customer's subscription, unless a longer retention period is required or permitted by law (for example to meet OHS record-keeping obligations, resolve disputes, or enforce our agreements). OHS and medical records are typically retained for the periods mandated by applicable occupational-health legislation.
When retention periods expire, We securely delete or anonymize the data. Residual copies may persist in encrypted backups for a limited period in line with our backup schedule and are not restored except where necessary for security, disaster recovery or legal compliance. Upon termination of a Customer's subscription, We delete or return Customer data in accordance with our service agreement.
We implement appropriate technical and organizational measures to protect personal data, including:
No method of transmission or storage is completely secure; while We use commercially reasonable measures to protect Your data, We cannot guarantee absolute security.
Subject to applicable law (KVKK and, where relevant, GDPR), You have the right to:
How to exercise Your rights. Because We act as a processor for most data, requests relating to OHS, employee, inspection, training or medical records are best directed to Your organization (the Customer), which acts as controller. We will assist the Customer in responding. For account, authentication or other data We control, You may contact Us directly using the details below. You may also update or delete certain information from within Your account settings where the Service provides that option.
The Service is intended for use by adults in a workplace context and is not directed to anyone under the age of 16. We do not knowingly collect personal data from children. If You believe a child has provided Us with personal data, please contact Us and We will take steps to remove it.
The Admin Panel uses strictly necessary cookies to authenticate users and maintain secure sessions, and stores limited preferences (such as Your theme choice) to operate correctly. We do not use advertising or cross-site tracking cookies. Where applicable law requires consent for any non-essential cookies, We will obtain it, and You can manage cookies through Your browser or device settings.
The Service may contain links to websites not operated by Us. We have no control over, and assume no responsibility for, the content or privacy practices of third-party sites. We advise You to review the privacy policy of every site You visit.
We may update this Privacy Policy from time to time. We will post the updated Policy on this page, update the "Last updated" date above, and, where appropriate, notify You by email or a prominent notice within the Service before material changes take effect. Continued use of the Service after changes become effective constitutes acknowledgement of the updated Policy.
If You have any questions about this Privacy Policy or wish to exercise Your rights, You can contact Us: