Data Processing Agreement
Our commitments, under KVKK art. 12 and GDPR art. 28, for the personal data we process on our customers' behalf. An annex to the Terms of Service.
Last updated: 18 September 2026
This document is a draft: the company details are not filled in yet and the text has not had a legal review.
Roles
The Customer is the controller for its visitors and contacts; [Şirket unvanı] is the processor and processes that data only on the Customer's instructions, to provide the service.
Subject matter
- Data subjects: the Customer's website visitors, customers and staff.
- Categories: name, e-mail, phone, conversation contents, files, page and device details, attributes the Customer sends.
- Duration: the term of the agreement; the data is deleted afterwards.
Our commitments
- Process only on documented instructions, and tell the Customer if an instruction seems unlawful.
- Keep everyone with access to the data under a duty of confidentiality.
- Apply appropriate technical and organisational measures: encryption in transit, database-level isolation between workspaces, access control, audit logs, regular backups.
- Update the subprocessor list before engaging a new one, give the Customer the chance to object, and bind subprocessors to the same obligations.
- Reasonably assist with data subject requests and data protection impact assessments.
- Notify the Customer without undue delay, and within 48 hours at most, after becoming aware of a personal data breach.
- Delete the data when the agreement ends, and make sure it leaves backups within 21 days.
- Make available the information needed to demonstrate compliance.
International transfers
Transfers to subprocessors abroad rely on appropriate safeguards such as standard contractual clauses, as required by KVKK art. 9 and Chapter V of the GDPR.