Einfy, Türkiye operates the Einfy service. This document applies to public visitors, account users and organizations using the platform, subject to mandatory law.
1. Parties and scope
This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer and Einfy, Türkiye where Einfy processes personal data on the Customer’s behalf. The Customer is the controller or equivalent responsible party and Einfy is the processor or service provider, except where Einfy independently determines purposes for account, security, billing or legal administration.
2. Processing details
- Subject matter: provision of Website Operations Intelligence, monitoring, integrations, reports, tasks, support and account operations.
- Duration: the service term plus limited retention and backup periods.
- Nature and purpose: hosting, organizing, retrieving, analyzing, transmitting, securing, supporting and deleting data according to the agreement and documented Customer use.
- Data subjects: Customer users, website visitors or contacts represented in connected data, support contacts and other persons whose data the Customer lawfully submits.
- Data types: identity and contact data, technical identifiers, website or analytics events, search-query data, support content, task content and other Customer-configured records.
3. Customer instructions
Einfy will process Customer personal data only on documented instructions expressed through the agreement, product configuration, authorized support requests and lawful use of features, unless law requires otherwise. If an instruction appears unlawful, Einfy may pause the affected processing and request clarification.
4. Customer responsibilities
The Customer is responsible for lawful instructions, transparency to data subjects, legal bases, configured retention, user permissions, connected accounts, responses to data-subject requests and ensuring that sensitive or restricted data is not submitted unless the service and agreement expressly support it.
5. Confidentiality and personnel
Einfy will limit access to personnel and contractors who need it to provide or secure the service and who are subject to appropriate confidentiality obligations. Access should follow role and tenant boundaries.
6. Security measures
Measures include server-side tenant authorization, hashed passwords, optional federated identity, encrypted application secrets and OAuth tokens, HTTPS-oriented session settings, CSRF controls, logging, backup/update discipline, restricted administrative access and incident diagnostics. Measures may evolve with risk and technology without materially reducing overall protection.
7. Subprocessors
The Customer authorizes Einfy to use subprocessors needed for infrastructure, email, payment, integrations, diagnostics and support. Einfy remains responsible for imposing data-protection obligations appropriate to the relevant service. Customers may request current categories or available details through Support. If a material new subprocessor creates a documented objection that cannot reasonably be resolved, the parties may discuss an alternative or termination of the affected service.
8. Data-subject and authority requests
Taking into account the nature of processing, Einfy will provide reasonable assistance for Customer responses to applicable access, deletion, correction, restriction, portability or objection requests. If Einfy receives a request clearly relating to Customer-controlled data, it may direct the requester to the Customer unless law requires a different response.
9. Personal-data incidents
Einfy will notify the Customer without undue delay after confirming a personal-data breach affecting Customer personal data where notification is required. Available information may include the nature of the incident, affected data, likely consequences and measures taken. Notification is not an admission of fault.
10. Return and deletion
During the service term, available export and deletion controls may be used according to plan capabilities. On termination or documented request, Einfy will delete or return Customer personal data within a reasonable operational period unless retention is required by law, necessary for claims, or present in backups awaiting secure rotation.
11. International transfers
Where protected personal data is transferred internationally, the parties will rely on an applicable adequacy decision, standard contractual mechanism, binding rule or other lawful safeguard as available. The Customer authorizes transfers inherent in its chosen integrations.
12. Information and audits
Einfy will make reasonably necessary information available to demonstrate compliance with this DPA. Audits must protect other customers, security and confidentiality; use existing reports or remote review where adequate; occur no more than reasonably necessary; and avoid disproportionate operational disruption. Customer bears its audit costs unless a material breach by Einfy is established.
13. Order of precedence and contact
If this DPA conflicts with the main agreement on processing Customer personal data, this DPA controls for that subject. Mandatory law prevails. Privacy and DPA questions can be sent to Einfy Support Center.