Even SSL sites are not immune. On corporate networks, the clients trust the company cert, which is used to proxy all traffic (including HSTS and HPKP/pinned sites) for filtering/logging.
Edit: Nevermind — I assume you're referring to this scenario[1], in which the company installs a root certificate onto your actual computer that allows them to sign certificates for other sites.
From there, everything can be tracked.