HEM · KVK
HEM KVK
An ISO 27701 aligned, end-to-end personal data management system
Manage personal data from a single place. HEM KVK turns compliance from a document on a shelf into a system that runs every day.
- ISO 27701
- KVKK
- GDPR
Why is managing personal data so hard?
Inventory in a spreadsheet, policy somewhere else
Your data inventory is in one table, your privacy notices in another folder, retention periods undefined. When an audit arrives there is no consistent chain to show.
Requests and notifications done by hand
Data subject requests get lost in email, the VERBIS filing is rebuilt from scratch every year, and a breach is handled by improvisation. Statutory deadlines slip as a result.
The burden of proof piles up on you
KVKK art. 12 expects you to prove the measures you took. With scattered records, that proof means days of preparation every single time.
The daily obligations of a data controller
Eight modules, mapped to ISO 27701 controls and KVKK requirements.
Data inventory and mapping
Which data lives in which system and where it flows — on one screen. Records are updated alongside the process, so the table does not go stale.
VERBIS compliance and reporting
Keeps your controller and processor records in the VERBIS structure and prepares the filing report in a single step.
Privacy notices and explicit consent
Stores your texts version by version and publishes them to your website, app and forms from one flow. Which person saw which version stays on record.
Data subject requests (DSAR)
A request arrives through a web form, its statutory clock runs, and it is answered from prepared templates — end to end in one flow.
Retention periods and disposal
Define a separate retention policy per data category; expired records are deleted automatically or sent for approval first.
Breach management
When a breach record opens, the clock for the statutory notification starts. Impact assessment, authority notification and data subject messages come ready.
DPIA and risk assessment
Flags high-risk processing activities and tracks the action to be taken and who owns it.
Audit log and evidence store
Every action becomes a timestamped record. For an external audit you export the evidence file.
From setup to operation
Discovery
We map which unit processes which data.
Inventory
Data categories, purposes and transfers are entered.
Policy
Retention periods, texts and owners are defined.
Operation
Requests, breaches and disposal run through the system.
Connects to your existing systems
- Data category mapping with internal HR and CRM systems
- Collecting requests from website and mobile app forms
- Deadline tracking through your email and notification stack
- Single sign-on through an identity provider (with HEM ID)
Standards it serves
Which obligation it covers
- ISO 27701
- KVKK
- GDPR
Related services
- KVKK compliance programme
- Policies, procedures and texts
- Personal data risk analysis
- VERBIS registration and updates
- Outsourced data protection officer
- Data subject request management
- Retention periods and disposal
- Cross-border data transfers
- Compliance audit
- ISO 27701 privacy information management system
- Privacy by design
- Breach response procedure and drills
Frequently asked questions
Other products
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
