1. Parties and acceptance

1.1. This Data Processing Agreement ("DPA") is an annex to the Terms of Service and is concluded between the Customer ("Controller") and [doldurulacak] ("Processor").

1.2. The DPA is accepted electronically by adding contacts to the CRM, enabling the web form endpoint or the visitor measurement tag (t.js), turning on audience sync, or uploading any data containing personal data to the Service; the acceptance date, version and accepting user are recorded. A wet-ink or e-signed copy can be issued on request.

2. Definitions

In this DPA, "personal data", "processing", "controller", "processor", "data subject" and "explicit consent" have the meaning given in Turkish Law No. 6698 (KVKK) and, where the GDPR applies, in Regulation (EU) 2016/679. "Subprocessor" means a third party processing Customer Personal Data on the Processor's behalf.

3. Details of processing

4. Controller's obligations

4.1. The Customer represents that it collects personal data lawfully, informs data subjects under KVKK art. 10 and GDPR arts. 13–14, and obtains explicit consent where required. In particular, the Customer agrees:

  • not to run the t.js tag, which serves analytics and marketing purposes, without the visitor's prior consent, and to use a cookie consent tool for this;
  • that data subjects have been informed and the required consents obtained for audience transfers to ad platforms (Custom Audiences, Customer Match) and conversion API submissions;
  • that it has obtained consent under Law No. 6563 and İYS from the people it sends commercial electronic messages to.

For sample wording, see the Visitor Notice and Consent Template.

4.2. The Customer is responsible for all administrative fines, damages and costs arising from unlawful instructions and indemnifies the Processor against such claims.

5. Processor's obligations

5.1. Instructions: Processes Customer Personal Data only on the Customer's documented instructions (including Service settings, integration connections and this DPA). Informs the Customer if it believes an instruction breaches the law.

5.2. Confidentiality: Ensures that employees and contractors with access to the data are bound by confidentiality.

5.3. Security: Applies the technical and organisational measures in Annex 1 under KVKK art. 12 and GDPR art. 32.

5.4. Subprocessors: The Customer gives general authorisation for the suppliers on the Subprocessors page. New subprocessors are announced at least 30 days in advance; the Customer may object on reasonable grounds and, if no agreement is reached, terminate the affected service and receive a pro rata refund of the remaining period. The Processor imposes equivalent obligations on its subprocessors and remains liable to the Customer for their breaches.

5.5. Data subject requests: Provides export, correction and deletion tools in the Service; forwards requests it receives directly to the Customer without delay and provides reasonable assistance in answering them.

5.6. Data breach: Notifies the Customer of a breach affecting Customer Personal Data within 48 hours of becoming aware of it. The notice includes, as far as known, the nature of the breach, the categories and approximate numbers of data and persons affected, likely consequences and measures taken or proposed. Assists the Customer in meeting its obligation to notify the authority within 72 hours.

5.7. Impact assessment: Provides reasonable assistance with the Customer's data protection impact assessments where needed.

5.8. Audit: Provides the information needed to demonstrate compliance with this DPA. The Customer may audit once a year, with 30 days' written notice, during business hours, through an independent auditor bound by confidentiality and at its own cost. Written questionnaires and existing security documents are used first.

6. International transfers

Where subprocessors are located abroad, transfers are made using the standard contracts published by the Board under KVKK art. 9 (notified to the Authority within 5 business days of signing) and, for transfers subject to the GDPR, the European Commission's Standard Contractual Clauses (2021/914). The Customer authorises the Processor to make these transfers.

7. Data at the end of the agreement

After the Service ends, the Customer may export its data within 30 days. After that, Customer Personal Data is deleted or anonymised; copies in backups are deleted within at most 35 days through rotation. Data subject to a legal retention obligation is kept for that period and not processed for any other purpose.

8. Specific provisions for visitor data

8.1. Visitor event data is kept for at most 180 days; the Customer may choose a shorter period.

8.2. IP addresses are stored truncated; e-mail addresses and phone numbers are sent to ad platforms only as SHA-256 hashes.

8.3. Visitor data is not used or combined for targeting by any other Customer; pools and intent scores are calculated only from data in the relevant Customer's workspace. The Processor may use only aggregate, anonymous statistics that cannot be linked to a person for general model improvement.

9. Liability

Liability under this DPA is subject to the limitations in the Terms of Service; those limitations do not cover intent or gross negligence.

10. Precedence

For matters relating to personal data, this DPA takes precedence over the Terms of Service.

Annex 1: Technical and organisational measures

  • TLS 1.2+ encryption in transit; integration access keys encrypted at the application layer.
  • Logical separation of data per workspace; workspace membership checked on every query.
  • Role-based access; staff access limited by least privilege and logged.
  • Blocking private network addresses for requests to user-supplied addresses (SSRF protection), timeouts and size limits.
  • Signed keys, rate limiting and bot filtering on public endpoints.
  • Regular backups and restore tests.
  • Dependency updates and vulnerability monitoring.
  • Incident response procedure and breach notification process.
  • Confidentiality undertakings and data protection awareness training for staff.

Version: 1.0.