Skip to content

    Data Governance

    The part your legal team asks about first

    Most manipulation data on the market cannot survive a European or Asian compliance review, because nobody can say who consented to what. This page is what we hand your data protection officer.

    SOC 2 Type II ISO 27001 GDPR compatible

    Operator consent

    Consent is given by the individual operator, in their own language, before any recording takes place. It is explicit, informed and revocable, and it is never bundled into employment terms or a general workplace policy. An operator can decline without consequence and can withdraw afterwards. Participation is voluntary and compensated.

    • Explicit, informed and revocable, obtained individually
    • Never bundled into employment terms or a blanket workplace notice
    • Declining and withdrawing both carry no consequence for the operator
    • Operators are compensated for taking part

    Employer agreements

    Separately from operator consent, each participating plant signs a data agreement with us. It defines what may be recorded, at which stations, for what purpose, how long it is retained, and what a downstream buyer may do with it. Nothing is captured outside that scope.

    • Scope: which stations, which processes, which shifts
    • Purpose: what the data may be used for, and what it may not
    • Retention: defined periods, with deletion at the end of them
    • Downstream use: what a buyer receives the right to do

    The legal framework

    The consent framework was developed with labour law counsel rather than adapted from a generic data processing template, because recording people at work is an employment question before it is a data question. It is designed to be KVKK and GDPR compatible, and it is built to be read by a works council, not only by a legal department.

    Purpose limitation, retention and licensing

    Data is collected against a stated purpose and retained for a defined period. Licensing terms for buyers are agreed before a collection run begins, so what you may train on, publish and redistribute is settled up front rather than argued afterwards.

    • Collection runs against a stated, documented purpose
    • Defined retention periods, with deletion at the end
    • Buyer licensing terms agreed before capture, not after
    • Scope of downstream use written into the plant and operator agreements

    Privacy engineering

    Faces and identifying features are handled as a first-class concern, not an afterthought. Sensitive segments are flagged, redaction is applied, and privacy flags travel with the dataset so your own review can see what was treated and why.

    • Face and identifier handling applied before delivery
    • Redaction of sensitive content in the delivered footage and outputs
    • Privacy flags on segments that need downstream care
    • Nothing outside the agreed capture scope is retained

    Security and certifications

    Khenda holds SOC 2 Type II and ISO 27001, and operates GDPR and KVKK compatible processes. Data is encrypted in transit and at rest, access is controlled and logged, and hosting is enterprise-grade.

    • SOC 2 Type II
    • ISO 27001
    • GDPR and KVKK compatible processes
    • Encryption in transit and at rest, with controlled and logged access

    What you receive for your compliance file

    Every dataset is delivered with provenance and consent documentation: where the data came from, under what agreement, with what consent basis, for what purpose, and with what licensing terms. It is written to be handed to a reviewer, not to be interpreted by one.

    We will work to your requirements

    If your legal team, your data protection officer or a works council has specific conditions, bring them early. Requirements around scope, retention, redaction, jurisdiction and downstream use are easier to build into a collection run than to retrofit onto a delivered dataset.

    Talk to our team