Skip to content

İşlemde is in development. Sign-ups open soon.

Legal

Data processing agreement

Last updated: October 7, 2026

This English text is a convenience translation. If it differs from the Turkish original, the Turkish version prevails.

Parties and roles

This Data Processing Agreement is entered into between the business using İşlemde ("Data Controller") and Asaf Efe Bağ ("Data Processor") as an integral part of the Terms of Use.

With respect to the personal data of the Data Controller's own customers and employees that is entered into the service, the business is the data controller and İşlemde is the data processor within the meaning of Law No. 6698.

Data processed

  • Data subject groups: the Data Controller's customers and employees.
  • Data categories: name and surname, phone number, e-mail, address, TCKN/VKN (Turkish ID or tax number, for corporate customers), device and job information, photos, signature image, approval records (date, IP address, browser information).
  • Purpose: recording repair jobs, notifying customers, quote approval, warranty certificates and job tracking.

Data Processor's obligations

  1. Processes the data solely in accordance with the instructions given by the Data Controller through the service and for the purpose of providing the service.
  2. Places its personnel who access the data under an obligation of confidentiality.
  3. Takes appropriate technical and organizational measures pursuant to Article 12 of the Law: encrypted connections, access authorization, time-limited signed file links, access logs.
  4. Notifies the Data Controller of a data breach without delay, and within 48 hours at the latest, after becoming aware of it.
  5. Assists the Data Controller to a reasonable extent in responding to data subject requests.
  6. Deletes the data within 90 days after the agreement ends; statutory retention obligations are reserved.

Sub-processors

The Data Controller consents to the use of the following sub-processors: Vercel (application hosting), Railway (database), Cloudflare R2 (file storage), Plunk (e-mail delivery; customers are not added to marketing lists). The Data Controller is notified by e-mail before a new sub-processor is added.

SMS messages are sent through the provider that the Data Controller has chosen itself and connected with its own account (Netgsm, İleti Merkezi, Verimor or Mutlucell); the relationship with that provider belongs to the Data Controller. WhatsApp messages are likewise sent from the WhatsApp Business account connected by the Data Controller itself, through Meta Platforms, and only to customers who have given their consent; the Data Controller is obliged to obtain the customer's consent.

Since the servers of some of the sub-processors are located abroad, the Data Controller authorizes the Data Processor to ensure that the safeguards provided for in Article 9 of the Law are in place for these transfers.

Data Controller's obligations

The Data Controller is obliged to inform its customers and employees, to obtain explicit consent where required, to ensure that the data is accurate and up to date, and to use the service lawfully. İşlemde provides a privacy notice (aydınlatma metni) template that can be shown to the customer on the intake screen; it is the Data Controller's responsibility to assess whether this text is suitable for its business.

Audit

The Data Controller may, at reasonable intervals and with prior notice, request information regarding compliance with this agreement.