Data Processing Agreement

Markty AI

This Data Processing Agreement sets out the terms under which Markty AI processes personal data on behalf of Customer, and forms an appendix to and inseparable part of the User Agreement.

1. Parties and Roles

This Data Processing Agreement ("DPA") is entered into between the customer using Markty AI's services (markty.ai, app.markty.ai and related subdomains, the "Service") ("Customer") and MARKTYAI YAPAYZEKA TEKNOLOJİLERİ VE YAZILIM A.Ş. and/or MARKTY AI LTD ("Markty AI"). This DPA is an appendix to, and forms an inseparable part of, the User Agreement between Customer and Markty AI. In the event of a conflict between the User Agreement and this DPA regarding the processing of personal data, this DPA prevails. Under this DPA, Customer acts as the "Data Controller" for personal data relating to its own customers, subscribers, and contacts, determining the purposes and means of processing; Markty AI acts as the "Data Processor," processing such data solely on Customer's documented instructions.

2. Subject Matter, Duration, and Nature and Purpose of Processing

The subject matter of this DPA is the processing by Markty AI of communication, CRM, and content data reaching Markty AI through integrations Customer connects via the Service (e.g., social media accounts, email marketing tools, CRM systems, advertising platforms, and similar third-party tools), for the purpose of performing the Service's functions (including content generation, social media management, marketing automation, analytics, and reporting). Processing continues for as long as the User Agreement between Customer and Markty AI remains in effect, and ends upon termination of the User Agreement, subject to the deletion/return obligations in Section 10 below. The nature of processing includes automated and/or partially automated collection, recording, organization, storage, and analysis, and use for the purpose of generating Service outputs.

3. Categories of Data Processed and Data Subject Groups

Personal data processed under this DPA is limited to identity data (e.g., name, surname), contact data (e.g., email address, phone number), CRM records originating from integrations Customer connects (e.g., tags, notes, contact history), and content interaction data (e.g., messages, comments, form responses). The data subject groups are Customer's own customers, subscribers, and contacts. Markty AI processes such data only on Customer's instructions and for the Service's functions; processing of special categories of personal data is not intended under this DPA.

4. Processing on Documented Instructions

Markty AI processes personal data only on Customer's documented instructions. Such instructions are deemed documented through the User Agreement, this DPA, and Customer's configurations made via the Service (e.g., integration connections, automation rules). If Markty AI believes an instruction infringes applicable law, it will promptly inform Customer. Markty AI shall not use, disclose to third parties, or process for its own purposes any data processed under this DPA, except as instructed by Customer or as set out in this DPA.

5. Confidentiality and Personnel Obligations

Markty AI ensures that all employees, contractors, and sub-processors with access to personal data are subject to a statutory or contractual confidentiality obligation regarding such data. Access to personal data is limited to personnel who require access to perform their duties, and access rights are reviewed on a regular basis.

6. Technical and Organizational Measures

In accordance with Article 12 of the KVKK and Article 32 of the GDPR, Markty AI implements appropriate technical and organizational measures to prevent unlawful processing of personal data, prevent unauthorized access, and ensure the security of such data. These measures include, but are not limited to, encryption of data (in transit and at rest), access control and authorization mechanisms, maintenance of audit trails, logging of system and processing activity, regular security testing, and personnel security-awareness training.

7. Sub-processors

Customer acknowledges that Markty AI may engage sub-processors (e.g., hosting, AI processing, integration/OAuth brokering, and analytics providers) to perform the services under this DPA, and grants Markty AI a general authorization to do so. Markty AI publishes the current list of sub-processors it uses at /sub-processors. If Markty AI makes a material change to that list that could affect the processing of Customer's data (such as adding a new sub-processor), Markty AI will give Customer reasonable prior notice, and Customer may object to such change on reasonable grounds. Markty AI enters into a written agreement with each sub-processor that imposes data protection obligations at least equivalent to those set out in this DPA, and remains liable to Customer for the acts and omissions of its sub-processors.

8. Assistance with Data Subject Requests

Markty AI provides Customer with reasonable assistance, to the extent technically and organizationally feasible, to enable Customer to respond to requests from data subjects exercising their rights under Article 11 of the KVKK and/or Chapter III of the GDPR (such as access, rectification, erasure, or objection). If Markty AI receives a data subject request directly, it will forward the request to Customer without undue delay and will not respond to the request directly without Customer's instruction.

9. Data Breach Notification

If Markty AI becomes aware of a personal data breach (unauthorized access, loss, disclosure, or alteration) affecting personal data processed under this DPA, it will notify Customer without undue delay and as soon as reasonably possible after becoming aware of it. The notification will include the nature of the breach, the categories of data and approximate number of data subjects affected, the measures taken or proposed to be taken, and such other information as is reasonably necessary for Customer to assess the breach. Markty AI cooperates with Customer in investigating and remediating the breach.

10. Deletion or Return on Termination

Upon termination of the User Agreement, and at Customer's request, Markty AI will delete or return the personal data it is processing and destroy any remaining copies. This obligation applies subject to any legal retention requirement under applicable law (e.g., accounting, tax, or other statutory retention periods). Data retained under such an exception is kept only for the purpose and duration required by the applicable legal obligation.

11. Audit

Customer may request an audit, no more than once per year and upon reasonable prior written notice to Markty AI, to assess Markty AI's compliance with the obligations set out in this DPA. Markty AI will provide the requested information to the extent it does not compromise the confidentiality or security obligations owed to Markty AI or its other customers. Audits are conducted during business hours and in a manner that does not unreasonably disrupt Markty AI's operations.

12. International Transfers

Markty AI may transfer personal data processed under this DPA to locations outside the country where Customer or the relevant data subjects are located, to the extent necessary to perform the Service, including to locations where its sub-processors operate. Such transfers are made subject to the safeguards required under Article 9 of the KVKK and Articles 44-49 of the GDPR (such as Board-approved undertakings, standard contractual clauses/SCCs, or similar mechanisms).

13. Liability and Term

Each party is liable for direct damages suffered by the other party as a result of its breach of obligations under this DPA, subject to the limitations of liability set out in the User Agreement. This DPA takes effect when Customer begins using the Service and remains in effect for as long as the User Agreement is in effect. Markty AI may update this DPA from time to time; material changes will be notified with reasonable advance notice.