1. Application and roles of the parties
This Data Processing Agreement (“DPA”) takes effect when it is expressly incorporated into the master services agreement between AxelVira Teknoloji A.Ş. and a business customer. The customer is the controller of personal data for which it determines the purposes and means; AxelVira is the processor only to the extent that it acts on documented instructions.
AxelVira is a controller, and the relevant privacy notice applies, to processing it independently determines for its own purposes, such as account security, billing, compliance with its own legal obligations, and prevention of service abuse. If legislation characterizes the roles differently, the parties’ actual functions and mandatory law govern.
2. Definitions and order of precedence
“Personal Data,” “Processing,” “Data Subject,” “Personal Data Breach,” “Controller,” “Processor,” and “Subprocessor” have the meanings given by the applicable KVKK and GDPR. “Customer Data” means personal data processed on behalf of the customer.
In the event of conflict on data protection, mandatory law applies first, followed by a duly executed transfer mechanism, this DPA, the master agreement, and the order form; however, a more specific processing description in the order form may not reduce the level of protection in this DPA.
3. Subject matter and details of processing
| Element | Description |
|---|---|
| Subject matter | Provision, security, support, and customer-directed configuration of the MetriLume business service described in the order form |
| Duration | The term of the master agreement and the return/deletion and mandatory-retention period under this DPA |
| Nature | Receipt, transmission, configuration, storage, organization, retrieval, support access, backup, deletion, and anonymization |
| Purpose | Providing the service selected by the customer to authorized users and carrying out documented instructions |
| Data subjects | The customer’s authorized users, employees, representatives, and other individuals expressly identified in the order form |
| Data types | Business contact/account identifiers, authorization and security records, portfolio/transaction fields uploaded by the customer, and other data described in the order form |
| Special-category data | Out of scope by default; it may not be submitted without a written amendment, valid legal ground, and additional security |
The customer is responsible for the lawfulness of its instructions and the data it provides, including notices, legal grounds, and fulfilling data-subject requests and rights. AxelVira configures product defaults according to data minimization.
4. Documented instructions
AxelVira processes Customer Data only in accordance with the master agreement, order form, support request, and verified written instructions from the customer’s authorized administrator. Configuration necessary to provide the service falls within those instructions.
If we believe an instruction infringes the KVKK, GDPR, or another data-protection rule, we promptly inform the customer and may suspend the affected processing until a lawful clarification is received. If law requires processing, we inform the customer of the legal ground before processing unless notification is prohibited.
5. Confidentiality and personnel
- Access to Customer Data is limited to authorized personnel with a business need to know.
- People with access are subject to contractual or statutory confidentiality obligations and receive regular security and data-protection training.
- Privileged access is approved, logged, reviewed periodically, and removed when the role ends.
- Support access is limited by time, scope, and purpose; customer secrets are not used as general product-development data.
6. Technical and organizational security measures
Before Customer Data is processed under a business service that incorporates this DPA, the parties confirm the applicable minimum technical and organizational measures in the order form or a security annex, taking account of risk, technology, cost, and scope and the level required by KVKK Art. 12 and GDPR Art. 32. This public page does not represent that every control below is currently deployed for every service. The contractual measures must address, as applicable:
- Encryption in transit and, where appropriate to risk, encryption or equivalent protection at rest, together with key-management responsibilities.
- Network and environment separation, firewall or edge controls, and management of secrets appropriate to the ordered service.
- Identity and access management, least privilege, administrator authentication, access review, and proportionate audit logging.
- Secure-development, code-review, dependency and vulnerability management, patching, input-validation, and secret-leak controls.
- Application and session protections, including proportionate rate limiting and defenses against CSRF, replay, and abuse where relevant.
- Backup, restoration, availability, resilience, and incident-response arrangements appropriate to the agreed recovery requirements.
- Data minimization, production-log redaction, documented retention, and testable deletion or anonymization procedures.
- Supplier due diligence and contractual controls, together with change, incident, and breach-management responsibilities.
The customer is responsible for the security of its own devices, user authorizations, exported copies, and integration keys. Only the measures confirmed for the particular service in the executed order form or security annex become its minimum contractual security set; additional measures may be agreed there.
7. Subprocessors
The customer’s general or specific subprocessor authorization is recorded in the master agreement or order form. The authorized provider’s exact contracting legal entity, role, purpose, data categories, access/processing countries, and transfer mechanism are set out in an order-specific subprocessor annex. The public Subprocessors page does not by itself constitute authorization or a processing instruction. AxelVira contractually passes to each authorized subprocessor data-protection obligations substantively equivalent to this DPA and remains responsible to the extent required by applicable law.
Unless prevented by a security or emergency condition, notice of a new subprocessor or processing location is provided through the registered customer channel or change-notification subscription at least 15 calendar days in advance. The customer may object within that period on specific data-protection grounds. The parties will consider an alternative, supplementary safeguard, or narrowed scope in good faith; if no reasonable solution exists, the customer may terminate the affected service without penalty.
8. International transfers
Customer Data is never transferred abroad without an appropriate transfer mechanism, including where the customer requests or configures an international location or integration. A customer instruction does not by itself authorize an unlawful transfer. Under the KVKK, an adequacy decision, standard contract, binding corporate rules, approved undertaking, or another valid mechanism is used; under the GDPR, an adequacy decision or appropriate safeguard is used.
Where necessary, the parties complete the relevant controller-to-processor or processor-to-processor standard contract, assess country and supplier risk, and apply supplementary measures such as encryption, key control, and review of public-authority requests. A mandatory authority request is notified to the customer and challenged as to scope to the extent legally permitted.
9. Data-subject requests
AxelVira forwards to the customer a request received directly that appears to concern that customer and does not provide the substantive response on the customer’s behalf unless legally required to do so. Through service functions and reasonable technical support, it assists the customer in fulfilling requests for access, correction, erasure, restriction, portability, and objection.
If the nature of a request materially exceeds the standard service scope, reasonable, documented costs disclosed in advance may apply unless mandatory law requires otherwise.
10. Personal data breach
AxelVira notifies the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data; notice is not postponed until the investigation is complete or the breach is independently verified. To the extent available, the notice includes the nature of the incident, categories and approximate volume of data and individuals, likely consequences, measures taken or proposed, and contact information.
Information may be provided in phases as the investigation continues. The parties cooperate on statutory authority/data-subject notifications, preservation of evidence, and remediation. A notification is not in itself an admission of fault or liability.
11. Compliance assistance and DPIAs
Taking account of the nature of processing and the information available to us, we provide reasonable information for security obligations, data-protection impact assessments, prior consultation, records, and regulatory reviews. The customer remains responsible for assessing its own purposes, risks, and legal grounds.
12. Information and audits
For a service governed by an executed order that incorporates this DPA, AxelVira provides the current policies in its possession, the order-specific security summary, subprocessor information, and appropriate available evidence on reasonable request. This provision does not represent that an unpublished or nonexistent certification or independent report exists. If the materials are insufficient, the customer may request an independent audit once per year and additionally following a material Personal Data Breach, documented reasonable grounds to suspect material noncompliance, a competent-authority request, or a mandatory-law requirement, with reasonable advance notice. These additional circumstances are not subject to the annual limit.
An audit must not disrupt the service, access another customer’s data, secrets, or vulnerability details, and must be conducted under confidentiality. Extraordinary costs may be borne by the customer unless the audit identifies material nonconformity attributable to AxelVira.
13. Return, deletion, and retention
When the main service ends, the customer receives its data through the provided export function or an agreed method. At the customer’s choice, Customer Data is deleted or deleted after return; a copy that law requires to be retained is isolated, not used for another purpose, and deleted when the period ends.
A backup copy is overwritten during the normal protected cycle; meanwhile, it does not return to the active system and is accessed only for disaster recovery. A statement of completion of deletion is provided on request.
14. Liability, term, and termination
The parties’ data-protection liability applies together with the limits in the master agreement and mandatory law; a data subject’s or authority’s statutory claim cannot be removed by contract. A party promptly cooperates in defending a claim arising from the other party’s breach.
The DPA remains in force throughout the master agreement and while Customer Data is processed. An uncured material data-protection breach may result in termination of the affected service after written notice and a reasonable cure period; processing may be suspended immediately in an urgent-risk situation.
15. Data-protection contact
DPA notices and security/data-protection coordination use [email protected]. The authorized customer contact is identified in the master agreement or order form. This public text does not by itself constitute a processing instruction or signature on behalf of a customer.
Contact and data controller
- AxelVira Teknoloji A.Ş.
- İzmir Trade Registry 271455
- Address
- Adalet Mah. Manas Blv. No:47/B Folkart Plaza D:3509, Bayraklı/İzmir, Türkiye
- Tax identification number
- 0991410303
- MERSİS
- 0099141030300001
- Support
- [email protected] · +90 (850) 840 20 83
- Privacy and data requests
- [email protected] · [email protected]