Data Processing Agreement (DPA)
Governs the controller–processor relationship for personal data the Customer uploads to Veslify.
- Legal name
- TURELF GIDA ORGANİZASYON İNŞAAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ
- Address
- Yalı Mah. Rıhtım Cad. No: 19 C, Maltepe / İstanbul, Türkiye
- MERSIS No
- 0869096008700001
- Tax office / VKN
- Küçükyalı Vergi Dairesi / 8690960087
- Phone
- +90 536 985 08 97
- info@veslify.com
- Web
- https://veslify.com
1. Parties and Definitions
This Data Processing Agreement (“DPA”) is an integral annex to the Terms of Service and applies between:
- Data Controller: the customer who subscribes to Veslify and enters into the system personal data relating to its own data subjects (the “Customer”).
- Data Processor: TURELF GIDA ORGANİZASYON İNŞAAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ — Küçükyalı Tax Office, Tax ID 8690960087, MERSIS 0869096008700001, Yalı Mah. Rıhtım Cad. No: 19 C, Maltepe / Istanbul (“VESLIFY”).
Terms are construed under Turkish Personal Data Protection Law No. 6698 (“KVKK”) and related legislation.
2. Subject and Scope
In connection with the Customer’s use of the Veslify CRM service, VESLIFY processes personal data on behalf of and per the instructions of the Customer. VESLIFY processes such data solely to provide the Service; it does not use it for its own purposes, sell it, or transfer it to third parties other than for performance of the Service.
3. Nature of Processing
- Purpose: provision of the Veslify CRM service (customer relationship management, record-keeping, communication, etc.).
- Duration: limited to the Customer’s subscription term and the retention periods in the Delivery & Return Terms.
- Data subject groups: persons determined by the Customer (e.g. the Customer’s own customers, contacts, leads, suppliers).
- Data categories: identity and contact details, commercial/transaction data and any other fields the Customer chooses to add. The Customer is responsible for entering any special-category data and for the additional obligations this entails.
4. Processor Obligations (KVKK Art. 12)
VESLIFY:
- processes personal data only on the Customer’s documented instructions;
- ensures personnel with access are bound by confidentiality;
- implements appropriate technical and organisational measures to prevent unlawful processing/access and to ensure data protection (see Section 7);
- reasonably assists the Customer in responding to data subject requests (KVKK Art. 11);
- notifies the Customer without undue delay upon becoming aware of a data breach, providing the necessary information;
- reasonably assists the Customer in verifying compliance with this DPA.
5. Sub-processors
The Customer gives general authorisation for VESLIFY to use sub-processors to provide the Service. Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server / hosting infrastructure | Germany |
| iyzico (İyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.) | Payment processing | Türkiye |
| E-invoice / e-archive integrator | Statutory invoicing | Türkiye |
VESLIFY informs the Customer when adding/changing sub-processors and imposes obligations on them equivalent to those in this DPA.
6. Cross-Border Transfer
As the hosting infrastructure is in Germany (Hetzner), personal data is processed abroad. Such transfer is carried out relying on appropriate safeguards under KVKK Art. 9 or other cases permitted by law.
7. Security Measures
Commensurate with risk, VESLIFY applies technical and organisational measures such as encryption in transit and at rest, role-based access control, company-level data isolation, access/activity logging, regular backups, up-to-date patch management, and staff awareness.
8. Data Subject Rights
If a data subject contacts VESLIFY to exercise their rights, VESLIFY refers the request to the relevant Customer and reasonably supports the Customer in fulfilling it.
9. Term and Termination
This DPA applies for as long as the Customer uses the Service. Upon termination, VESLIFY, at the Customer’s choice, deletes or returns the personal data; retention and deletion periods align with the Delivery & Return Terms (120 days on payment failure or termination, during which the Customer may export its data at any time or request earlier deletion). Statutory retention obligations are reserved.
10. Liability
Each party is responsible for complying with its own obligations under KVKK and applicable law. The limitation-of-liability provisions of the Terms of Service apply, save for liabilities that cannot be limited by law.
11. Miscellaneous
This DPA is governed by Turkish law. In case of conflict between the Terms of Service and this DPA regarding personal data, this DPA prevails.