01Who collects your data
The controller of your personal data and the operator of this app is:
FERİH MÜHENDİSLİK İNŞAAT OTOMOTİV GIDA TURİZM SANAYİ TİCARET LİMİTED ŞİRKETİ (“Ferih Group”)
Merkez Mah. Kadıoğlu Sk. No: 4A, 34275 Arnavutköy / İstanbul, Türkiye
Privacy and data requests: info@ferihgroup.com
If you use the app through an employer, that company is also a controller with respect to the business records you enter; Ferih Group hosts and processes that data on the company's behalf.
02What we collect and why
The table below is exhaustive. The app collects no personal data other than what is listed here.
| Data | Exactly what | Purpose | Retention |
|---|---|---|---|
| Account data | Full name, e-mail address, job title (optional), role and account status. | To sign you in, to determine your permissions (which screens you can see), and so colleagues can see who entered a record. | For as long as your account is active. |
| Business records | Quantity-survey slips, progress payments and payment records, contracts and line items, timesheet and personnel records (a worker's name, trade, subcontractor group and daily wage), material/stock/equipment movements, site notes. | The core function of the app: running and reporting the survey → approval → progress payment → payment chain. | For as long as your company's account is active; financial and commercial records for the statutory retention periods required by law. |
| Photographs | Only images you deliberately attach to a slip or a site note. Uploaded over an encrypted connection to a storage area named ekler (“attachments”). | To document work carried out on site — evidence for the quantity survey and the progress payment. | For as long as the record they belong to is kept. |
| Notification device record | If you grant notification permission: a device-specific push token, the platform (iOS/Android), the device name or model, a last-seen timestamp and your user ID. | Solely to deliver approval, task-assignment and revision notifications to the correct device. | Until you revoke notification permission or your account is closed. |
| Audit log | Action type, user ID, module, the record concerned, description, amount and the fields that changed. | An immutable audit trail — answering “who changed what, and when” for actions involving money and approvals. | Not deleted; retained for the period required by applicable law. |
| Technical data | Session cookie; appearance-preference cookies (theme, accent colour, typeface, selected project); server access logs kept by our hosting providers (IP address and timestamp). | Keeping you signed in, remembering your preferences, security and abuse prevention. | Cookies for the duration of the session/preference; server access logs for the provider's short-term log retention period. |
None of these cookies are tracking or advertising cookies; they exist only for the session and for appearance preferences.
Data entered about other people
In the timesheet and personnel modules, authorised users enter the name, trade, subcontractor group and daily wage of workers on site. Those workers are not users of the app; their details are entered by the employing company for its own timesheet and progress-payment processes. For those records the company is the controller and Ferih Group hosts the data solely on its behalf. If you believe your details are recorded this way, contact the company you work for first, and info@ferihgroup.com if that does not resolve it.
03What we do not collect
We state this explicitly because the app never touches any of it:
- Location / GPS data (no location permission is even requested)
- Contacts, calendar, microphone
- Advertising identifiers (IDFA / Advertising ID)
- Analytics or crash-reporting SDKs
- Third-party advertising networks
- Phone numbers
- Card or payment data (there are no in-app purchases)
- Health, biometric or other special-category data
- Any technology that tracks you across other apps or websites
None of your data is used for advertising, profiling or cross-app tracking. We do not track you, as defined by Apple's App Tracking Transparency framework.
04Why camera and photo access is requested
The mobile app requests two permissions, and uses both only when you tap a button:
- Camera — “The camera is used to attach site photographs to quantity-survey slips.” You take the photo; the app never opens the camera in the background.
- Photos — “Access is required to attach photographs from your gallery to quantity-survey slips.” Only the image you pick is read; the rest of your library is not scanned, and no write access to your library is requested.
If you decline, the rest of the app works normally — only photo attachment is unavailable. You can revoke the permission at any time in your device settings.
When there is no signal on site
Construction sites often have no mobile coverage. In that case the slip you create and the photo you attach are held in the app's own folder on your device, then uploaded in order once connectivity returns, after which the local copy is deleted. While queued, the data never leaves your device.
05Why notification permission is requested
Push notifications are used only for work events: when an item is waiting for your approval, when a task is assigned to you, or when something you submitted is returned for revision.
To make this possible, a device-specific push token is generated and stored against your account. The token is passed to the Expo push service and on to Apple (APNs) and Google (FCM) purely in order to deliver the message. It is never used for marketing, advertising or tracking, and is never sold to anyone.
If you decline notification permission the app continues to work in full. Turning notifications off in device settings stops delivery.
06Where your data is stored
- Supabase — database, authentication and file storage. Servers are located in the European Union region (Frankfurt, Germany —
eu-central-1). - Vercel — hosting and delivery of the web application.
Because data accessed from Türkiye is hosted on servers in the EU, this constitutes a cross-border transfer under Turkish data protection law (KVKK); the transfer is made under standard contractual safeguards and the providers' data-processing terms.
07Who we share it with
Data is shared only with the infrastructure providers needed to run the service, and only to the extent required:
| Provider | Purpose | What is shared |
|---|---|---|
| Supabase | Database, authentication, file storage | Account data, business records, photographs, audit log |
| Vercel | Web hosting | Server access logs (IP address, timestamp) |
| Expo (EAS) | Notification delivery | Push token and notification text |
| Apple (APNs) / Google (FCM) | Delivering the notification to the device | Push token and notification text |
| E-mail infrastructure | Invitation and password-reset e-mails | Name and e-mail address |
We do not sell, rent or share your personal data with third parties for advertising, and we do not provide it to data brokers. Disclosure may occur only in response to a lawful, properly issued request from a competent authority.
08Your rights and account deletion
Under Article 11 of the Turkish Personal Data Protection Law (KVKK No. 6698) and — if you are in the EU — under the GDPR, you have the right to access your data, to have it corrected, to have it erased, to object to processing, to request restriction of processing, and to be told to whom it has been transferred.
How to have your account deleted
PocketWorkSite has no in-app sign-up; accounts are created by invitation by an administrator at your company. There are two ways to have your account and your data deleted:
- Ask your company's PocketWorkSite administrator — they can close your account directly.
- Or e-mail info@ferihgroup.com with the subject “Account deletion request — PocketWorkSite”. After we verify your identity we will complete the request within 30 days at the latest.
What is deleted: your account, your sign-in credentials, your profile details and your notification device record.
What may remain: business records belonging to your company's projects (quantity surveys, progress payments, payments) and the audit trail — these are the company's commercial and financial records and must be kept until the statutory retention periods expire. On request, your identity link within those records is anonymised wherever technically possible.
To exercise any of these rights, write to info@ferihgroup.com. If you are not satisfied with our response you may lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) or, in the EU, with your local supervisory authority.
09Security
- All data is encrypted in transit using TLS.
- Database access is restricted by row-level security (RLS) and role-based authorisation; a user of one company cannot see another company's records.
- In the mobile app your session credentials are held in the device's secure store (iOS Keychain / Android Keystore).
- Actions involving money and approvals are written to an immutable audit log.
10Not directed to children
PocketWorkSite is a business application designed for adult professionals working in the construction industry. It is not directed to anyone under 18, and we do not knowingly collect personal data from children. If we become aware that we have, we delete it without delay.
11Changes to this policy
When we update this policy we publish the new version on this page and change the effective date shown above. If an update materially changes what we collect or how we use it, we will notify you in the app and/or by e-mail at your registered address before the change takes effect.
12Contact
For any privacy question, request or complaint: info@ferihgroup.com
FERİH MÜHENDİSLİK İNŞAAT OTOMOTİV GIDA TURİZM SANAYİ TİCARET LİMİTED ŞİRKETİ
Merkez Mah. Kadıoğlu Sk. No: 4A, 34275 Arnavutköy / İstanbul, Türkiye