Skip to content
HEM Bilişim
All products

HEM · KVK

HEM KVK

An ISO 27701 aligned, end-to-end personal data management system

Manage personal data from a single place. HEM KVK turns compliance from a document on a shelf into a system that runs every day.

  • ISO 27701
  • KVKK
  • GDPR
The problem we solve

Why is managing personal data so hard?

01

Inventory in a spreadsheet, policy somewhere else

Your data inventory is in one table, your privacy notices in another folder, retention periods undefined. When an audit arrives there is no consistent chain to show.

02

Requests and notifications done by hand

Data subject requests get lost in email, the VERBIS filing is rebuilt from scratch every year, and a breach is handled by improvisation. Statutory deadlines slip as a result.

03

The burden of proof piles up on you

KVKK art. 12 expects you to prove the measures you took. With scattered records, that proof means days of preparation every single time.

Capabilities

The daily obligations of a data controller

Eight modules, mapped to ISO 27701 controls and KVKK requirements.

Data inventory and mapping

Which data lives in which system and where it flows — on one screen. Records are updated alongside the process, so the table does not go stale.

VERBIS compliance and reporting

Keeps your controller and processor records in the VERBIS structure and prepares the filing report in a single step.

Privacy notices and explicit consent

Stores your texts version by version and publishes them to your website, app and forms from one flow. Which person saw which version stays on record.

Data subject requests (DSAR)

A request arrives through a web form, its statutory clock runs, and it is answered from prepared templates — end to end in one flow.

Retention periods and disposal

Define a separate retention policy per data category; expired records are deleted automatically or sent for approval first.

Breach management

When a breach record opens, the clock for the statutory notification starts. Impact assessment, authority notification and data subject messages come ready.

DPIA and risk assessment

Flags high-risk processing activities and tracks the action to be taken and who owns it.

Audit log and evidence store

Every action becomes a timestamped record. For an external audit you export the evidence file.

How it works

From setup to operation

1

Discovery

We map which unit processes which data.

2

Inventory

Data categories, purposes and transfers are entered.

3

Policy

Retention periods, texts and owners are defined.

4

Operation

Requests, breaches and disposal run through the system.

Integrations

Connects to your existing systems

  • Data category mapping with internal HR and CRM systems
  • Collecting requests from website and mobile app forms
  • Deadline tracking through your email and notification stack
  • Single sign-on through an identity provider (with HEM ID)
FAQ

Frequently asked questions

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation