Manipulation data is recorded from people at work. That makes provenance an employment question before it is a data question, and it is the first thing a serious buyer's legal team asks about. What follows is how consent, agreements, retention, privacy and security are handled here, in the reading order a compliance reviewer expects.
Operator consent
Consent is given by the individual operator, in their own language, before any recording takes place. It is explicit, informed and revocable, and it is never bundled into employment terms or a general workplace policy. An operator can decline without consequence and can withdraw afterwards. Participation is voluntary and compensated.
- Explicit, informed and revocable, obtained individually
- Never bundled into employment terms or a blanket workplace notice
- Declining and withdrawing both carry no consequence for the operator
- Operators are compensated for taking part
Employer agreements
Separately from operator consent, each participating plant signs a data agreement with us. It defines what may be recorded, at which stations, for what purpose, how long it is retained, and what a downstream buyer may do with it. Nothing is captured outside that scope.
- Scope: which stations, which processes, which shifts
- Purpose: what the data may be used for, and what it may not
- Retention: defined periods, with deletion at the end of them
- Downstream use: what a buyer receives the right to do
The legal framework
The consent framework was developed with labour law counsel rather than adapted from a generic data processing template, because recording people at work is an employment question before it is a data question. It is designed to be KVKK and GDPR compatible, and it is built to be read by a works council, not only by a legal department.
Purpose limitation, retention and licensing
Data is collected against a stated purpose and retained for a defined period. Licensing terms for buyers are agreed before a collection run begins, so what you may train on, publish and redistribute is settled up front rather than argued afterwards.
- Collection runs against a stated, documented purpose
- Defined retention periods, with deletion at the end
- Buyer licensing terms agreed before capture, not after
- Scope of downstream use written into the plant and operator agreements
Privacy engineering
Faces and identifying features are handled as a first-class concern, not an afterthought. Sensitive segments are flagged, redaction is applied, and privacy flags travel with the dataset so your own review can see what was treated and why.
- Face and identifier handling applied before delivery
- Redaction of sensitive content in the delivered footage and outputs
- Privacy flags on segments that need downstream care
- Nothing outside the agreed capture scope is retained
Security and certifications
Khenda holds SOC 2 Type II and ISO 27001, and operates GDPR and KVKK compatible processes. Data is encrypted in transit and at rest, access is controlled and logged, and hosting is enterprise-grade.
- SOC 2 Type II
- ISO 27001
- GDPR and KVKK compatible processes
- Encryption in transit and at rest, with controlled and logged access
What you receive for your compliance file
Every dataset is delivered with provenance and consent documentation: where the data came from, under what agreement, with what consent basis, for what purpose, and with what licensing terms. It is written to be handed to a reviewer, not to be interpreted by one.



