— LEGAL
Privacy Policy
Last updated: 17 May 2026
CallGem's privacy philosophy in 30 seconds
CallGem is an enterprise software used by organizations for employee supervision and regulatory compliance. It is built on five principles:
- The software runs on your server. Data is stored on your infrastructure, not on Tecmony's.
- Data stays on your servers. Nothing is sent abroad without your consent.
- Counterparty recording is left to the organization. No recording, allow-list based, or notify-and-react — the organization chooses.
- Tecmony does not see data in routine operations. Only with the organization's written consent, for a limited support incident, may technical records be temporarily viewed.
- Everything is logged. The organization can audit who did what and when.
— COUNTERPARTY RECORDING
A three-layer flexible architecture
CallGem's most critical design decision: how is the counterparty's voice handled? The answer is left to the organisation's legal judgement — the software offers three distinct layers, and all guarantees are pinned at the hardware level.
A call begins
Stereo flow · agent + counterparty
Is the counterparty stream open?
A hardware-level decision — if closed, memory is never even touched
3 → 1
The organisation picks one
Don't record at all
The counterparty stream is fully closed.
- → Only the agent's voice is recorded
- → No audio data for the counterparty is ever created
- → Explicit consent does not even arise as a legal matter
Tecmony's recommended default.
Allow-list based
Is the customer marked "recording approved" in CRM?
- → Approved number → counterparty stream opens
- → Unapproved number → agent side only
- → CRM updates take effect instantly
Driven by the organisation's customer policy.
Notice + reaction
The agent gives a notice at the start; the software processes the counterparty's reaction.
- → Explicit consent → recording continues
- → Silence → the configured fallback applies
- → Explicit refusal → counterparty recording stops, the second stream so far is deleted
- → Notice missing → no counterparty recording is ever created
Most active, most transparent model.
Failsafe — not even the organisation can disable it
Behaviour around explicit refusal and missing notice is fixed in software. Not even the organisation admin can switch off these guarantees; every access lands in the audit log.
1. What CallGem Is and Who Uses It
CallGem is an enterprise software used on company phones of field sales agents, customer representatives or similarly defined corporate roles. It records calls, manages devices centrally, and tracks duty location.
Developed by: TECMONY YAZILIM BİLİŞİM VE DANIŞMANLIK HİZMETLERİ LİMİTED ŞİRKETİ (MERSİS: 0833098641200001)
Used by: The relevant organization / employer. Referred to as "the organization" throughout this page.
Under the Turkish Personal Data Protection Law (KVKK):
- Data controller: The organization using the software (employer). The decision authority over the employee's and counterparty's data rests with the organization.
- Tecmony: The company that develops and delivers the software. Tecmony does not routinely access production data; outside limited support situations, it does not act as a data processor.
2. Where the Software Runs
CallGem operates in on-premise mode — the software and database are installed on the organization's own server infrastructure. It is not a cloud SaaS offering.
- All call recordings, metadata and logs are stored on the organization's server.
- No production data is held on Tecmony's infrastructure or abroad.
- Data is processed inside your own infrastructure; no transfer abroad happens without your explicit instruction.
- Backup, archive and restore are within the organization's IT operations scope.
This architecture is designed to meet KVKK compliance, BDDK (Banking Regulation and Supervision Agency) requirements and sectoral data localization requirements.
3. What Data Is Processed
The organization configures which of the following data the software collects:
Call data
- Voice recording of the employee's call (default: only the employee side — see §4)
- Call number, direction (incoming/outgoing), start and end time, duration
- Associated device identifier
Device data (Mobile Device Management — MDM)
- Device model, operating system version, IMEI
- List of applications installed on the device
- Online/offline status, battery level, last-seen time
Location data
- Periodic location points (latitude, longitude, accuracy, timestamp) during the working hours defined by the organization
- On-demand location request (LocateNow) — upon authorized user's request
- Dwell detection within a defined radius
- During device handover periods, each location record is attributed to the user of that period
Conversation Analytics (optional module)
- Speech-to-text and analysis of call content upon request
- This module is optional and activated only by the organization's written request
4. Counterparty (Third-Party) Recording — Three-Layer Flexible Architecture
This is CallGem's most distinctive aspect: how the voice of the person opposite the employee (customer, citizen, third party) is handled is entirely left to the organization's decision. Based on the organization's legal assessment, one of three layers is selected.
Layer 1 — Counterparty is never recorded (our default recommendation)
Only the employee's voice is recorded. No voice data of the counterparty is ever created; the counterparty's explicit consent does not legally come into question.
Layer 2 — Recording based on consent list
The organization records the counterparty only when speaking with numbers marked as "voice recording consented" in its own customer records system; in other cases only the employee side is recorded.
Layer 3 — In-call notification and reaction
The employee announces "this call is being recorded" at the start. The software processes the counterparty's reaction:
- Explicit consent → recording continues
- Silence → organization-defined configuration applies
- Explicit refusal → counterparty recording is stopped immediately; the second stream up to that moment is deleted
- If the employee did not announce → counterparty recording is never created
Failsafe — even the organization cannot override: The behavior for "explicit refusal" and "no announcement" is locked at the software level; not even an organization administrator can override these safeguards.
Legal interpretation belongs to the organization
CallGem provides the mechanism and the audit infrastructure. Which layer is applied based on which legal basis (KVKK disclosure/explicit consent, employment contract, sectoral regulation, BDDK, etc.) is the assessment made by the organization in its data controller capacity. Tecmony is not a party to that assessment.
5. Where Is Data Stored? For How Long?
- Location: Only on the organization's own server. No production data is held on Tecmony's infrastructure.
- Duration: Determined by the organization. The software offers a configurable retention parameter; the organization may define durations in days or years per its own policy.
- Backup: Responsibility of the organization's IT operations.
- Deletion: The organization may define automatic deletion at retention end or manual deletion rules.
- KVKK Article 11 requests: The software has functions to technically perform deletion or destruction of records in line with the organization's employee/counterparty requests; triggering authority rests with the organization.
6. Encryption and Security
- In transit: TLS 1.3 standard or equivalent strong encryption
- At rest: Full disk encryption and authorized access
- Authorization: Role-based access control; authenticated authorized user
- Audit trail: Every authorized access — who, when, what — is logged
- Software signature: Tecmony is verified as a corporate publisher in the Google Play developer directory with D-U-N-S 595817447, registered legal entity status.
7. Tecmony's Access to Data — Exceptional and Limited
During normal use of CallGem, Tecmony does not access the organization's data. Access is possible only in the following situations:
Access scenarios
- Software bug fixing
- Security vulnerability investigation
- Technical intervention for a critical incident
- Log analysis
- Installation verification
Access conditions (cumulatively required)
- No access is granted without the organization's written consent
- The consent specifies in writing the support ticket number, access purpose, which system is to be accessed, scope and duration
- Each access session is limited to maximum 4 hours; extension requires new written consent
- Access session is conducted under the supervision of the organization's IT team
- No permanent account, persistent VPN or unrestricted SSH authority is provisioned
After access
- Records, screenshots or logs containing data that temporarily appear on the Tecmony side are deleted or permanently masked within maximum 24 hours
- A detailed audit log is kept for the entire access session
- Tecmony may not use these materials for archiving, training, product development, or analysis purposes
Direct access to production environment
- As a rule, Tecmony does not intervene directly in the production environment
- Investigation is performed in the pre-production (PREPROD) environment with anonymized data
- Only in exceptional cases solvable only with production data/scale, limited access is provided with the organization's separate written consent and live supervision
Data minimization
The organization is obligated to mask personal data in logs, screenshots or files shared with Tecmony. Identifiers such as national ID number, phone number, IMEI are masked by default (e.g., only the last 4 digits of phone numbers visible).
8. Sub-Processors and Technical Dependencies
Because CallGem runs on-premise, the hosting providers (AWS, Azure, GCP, etc.) used by classic cloud SaaS services are not sub-processors for this software.
The software has certain technical dependencies — these do not see production data:
- Samsung Knox — Device security and recording authorization
- KLM License Validation — Knox license validity verification
- TLS Certificate Authorities — Certificate validation for encrypted communication
- license.tecmony.cloud — CallGem software license validity verification
These dependencies process only technical metadata; call audio, location, user identity or similar personal data are not transmitted to them.
If a new sub-processor needs to be added, written notice is given to the organization at least 30 days in advance; the organization's right of justified objection is reserved.
9. Data Breach Notification
If Tecmony detects a data breach in systems, personnel or support processes under its own control — or has reasonable suspicion of one — it provides a written preliminary notification to the organization within at most 24 hours from learning of the incident. This supports the organization's ability to meet the 72-hour notification window to the KVKK Authority.
The full notification containing the validated technical assessment and details is conveyed within a reasonably short time from validation.
Incidents originating from the organization's own infrastructure, personnel or third parties are the organization's responsibility; Tecmony may provide technical support in such cases upon request.
10. Employee Rights
To exercise your rights under KVKK Article 11 — information, correction, deletion, destruction, objection, indemnity, etc. — you must apply to the HR or KVKK officer of the employer organization.
Tecmony cannot process employee applications directly, because the decision authority over the data lies with the organization, i.e., the data controller. Tecmony provides software infrastructure and required technical support to fulfill applications received by the organization.
11. Transparency and Audit
- CallGem is classified as a corporate supervision tool.
- A persistent active notification is shown in the device status bar — the employee always sees that supervision mode is active.
- The organization managing the device can be viewed in the device settings.
- Under the KVKK Data Processing Protocol (Limited DPA) and Service Level Agreement (SLA) signed with Tecmony, the organization has the right to audit Tecmony's compliance once a year; exceptional support access records, technical measures and data breach notification processes are within the audit scope.
- During regulator audits (KVKK Authority, BDDK, MASAK), Tecmony is obligated to provide technical support to the organization.
12. Software Distribution
CallGem is not published in mobile application stores (Google Play Store, App Store). Distribution is exclusively through the enterprise channel:
- Initial installation: Performed when the device is enrolled in the corporate inventory
- Updates: Only from the authorized source designated by the organization; no third-party store is used
- Device warranty: CallGem does not use root, jailbreak or similar methods; it operates in the Samsung Knox corporate supervision mode, and the device manufacturer warranty is preserved
13. Updates to This Policy
This page describes CallGem's general privacy architecture. Material changes will be published together with the "Last updated" date at the top of the page. For contractual commitments between the organization and Tecmony, the CallGem Software License and Service Agreement, Service Level Agreement (SLA) and Limited Data Processing Protocol (DPA) govern; this page is descriptive of those contractual commitments.
Each organization is responsible for separately publishing its own employee disclosure text, explicit consent process and KVKK compliance documentation regarding CallGem usage.