Data Processing Agreement
Last updated: 17 September 2026 · Version 1.1
This is a courtesy translation; in case of conflict the Turkish version prevails. Turkish version: Veri İşleme Sözleşmesi.
This agreement is an annex to and integral part of the Terms of Use. It governs, between the business using the Sistemiya service (the "Customer") and Sistemiya, the processing within the scope of the service of personal data belonging to the Customer's own customers, employees and the persons it communicates with. A Customer that accepts the Terms of Use also accepts this agreement. A Customer wishing to receive a signed copy may write to destek@sistemiya.com.
1. Parties and Roles
- Data controller: The Customer. The Customer determines which personal data is processed, for which purpose and on which legal ground (KVKK Art. 3).
- Data processor: Sistemiya. It processes this data only on behalf of the Customer and on the Customer's instructions.
- Out of scope: Sistemiya is the data controller for the account, subscription and billing data of the Customer's representatives; this data is subject to the KVKK Privacy Notice.
Sistemiya's legal identity details are in the identity table on the Terms of Use page.
2. Subject Matter, Duration and Data Categories of the Processing
| Topic | Explanation |
|---|---|
| Subject matter of the processing | Answering requests received from messaging channels and the online booking page with the AI assistant, appointment management, reminders and notifications, campaign and win-back messages, knowledge base and panel operations |
| Duration | For the term of the subscription; on termination, clause 9 applies |
| Categories of data subjects | The Customer's customers and potential customers, persons who write messages to the Customer, the Customer's employees |
| Data categories | Identity and contact (name, telephone, e-mail, channel user ID), appointment information, message content, photos and documents sent, permission records, optionally the transcript of a telephone call |
| Special-category data | The service does not aim to collect special-category data; the data subject may share it spontaneously in a message (clause 5) |
3. Instructions
- This agreement, the Terms of Use, the panel settings and the operations the Customer performs in the panel are the Customer's documented instructions.
- Sistemiya does not use personal data for its own purposes, does not sell it and does not use it to train AI models.
- If Sistemiya considers an instruction to be contrary to the legislation, it informs the Customer without delay and may suspend the execution of the instruction.
4. Sistemiya's Obligations
- Confidentiality. Access to the data is limited to what is required by duty. Sistemiya undertakes to obtain written confidentiality undertakings from its personnel who access the data; until this process is in place, access is kept limited to operating the service and to support requests.
- Security measures (KVKK Art. 12). The measures applied are: database-level row-based isolation between businesses (Row-Level Security); TLS in transit; encrypted (Fernet) storage of messaging and calendar access keys and OAuth tokens, and storage of passwords as one-way hashes; signature verification of notifications from messaging providers; role-based access; audit logging of critical operations; hourly database backups stored encrypted. Message content is not stored encrypted in the database; it is protected by the isolation and access controls above and deleted at the end of the retention period. The current list is in the Privacy and Security Policy.
- Joint responsibility. Under KVKK Art. 12/2, Sistemiya is jointly responsible with the Customer for taking data security measures.
- Assistance with data subject requests. So that the Customer can answer applications under KVKK Arts. 11 and 13, Sistemiya provides in the panel per-person export, correction and deletion tools and an application tracking log. It forwards to the Customer without delay any applications received directly by Sistemiya that concern the Customer's data.
- Assistance and information. Sistemiya provides the service-related information (sub-processors, locations, retention periods, measures) the Customer needs for its data processing inventory, VERBİS registration and impact assessment.
5. The Customer's Obligations
- Informing data subjects. The Customer informs its own customers under KVKK Art. 10. To do so, it enters its legal name, address and application e-mail completely in the panel or defines a link to its own privacy notice. The AI assistant cannot be enabled until this information is entered.
- Legal ground. The Customer itself determines the legal ground of the data it processes. If it processes special categories of personal data (including health data), it itself meets the conditions of KVKK Art. 6 and does not upload special-category data to the knowledge base.
- VERBİS. The Customer assesses its VERBİS registration obligation according to its own scale; if it has registered, it enters the recipients in the Sub-processor List in the transfer-abroad field.
- Commercial electronic messages. The Customer itself manages recipient consents and Message Management System (İYS) records for campaign and win-back messages. The burden of proving permissions ticked manually in the panel lies with the Customer. Sistemiya's permission filter does not remove the Customer's obligations under Law No. 6563.
- Lawfulness of instructions. The Customer is responsible for the lawfulness of the instructions it gives and of the content it uploads to the panel.
6. Sub-processors
- The Customer gives a general authorisation for the use of the sub-processors in the Sub-processor List.
- The Customer is notified by e-mail 30 days before a new sub-processor is added to the list. The Customer may object within this period; if the objection cannot be resolved, it may terminate the agreement without compensation.
- Sistemiya imposes on sub-processors data protection obligations of the same nature as those in this agreement and is liable to the Customer for their processing.
7. Transfers Abroad
Some sub-processors are outside Türkiye; their locations are stated in the Sub-processor List. These transfers are subject to the transfer-abroad procedure in KVKK Art. 9. Because the transfers are continuous, the incidental-case exception is not relied on; they will be based on the appropriate safeguards under Art. 9/2, and the signing process for the standard contracts published by the Board is under way. Each signed standard contract is notified to the Authority within the period set by the legislation.
8. Breach Notification
- When Sistemiya becomes aware of a personal data breach affecting Customer data, it notifies the Customer without delay and within 24 hours at the latest.
- The notice includes the nature of the breach, the affected data categories and approximate number of records, the likely consequences and the measures taken or proposed. Information not yet known is completed as it becomes known.
- Notification to the Personal Data Protection Board and to data subjects is the responsibility of the Customer as data controller; Sistemiya provides the information needed to prepare that notification.
9. Termination: Deletion and Return
- When the subscription ends, the Customer can obtain all its data in machine-readable form in the panel with "Verilerimi indir" ("Download my data").
- When the Customer starts a "Verilerimi sil" ("Delete my data") request in the panel, the data is destroyed irreversibly at the end of the 30-day waiting period. Owing to the backup cycle, deleted data also leaves the encrypted backups within 400 days at the latest; backups are used only for restoration in case of data loss.
- If there is no deletion request, the data is deleted automatically when the retention periods in the KVKK Privacy Notice expire. Records whose retention is required by the legislation (destruction and audit records, financial records) are kept for that period.
10. Audits
- Sistemiya answers reasonable requests for information and documents showing that it complies with the obligations in this agreement within 30 days at the latest.
- On-site audit requests are carried out with their scope, timing, confidentiality conditions and costs agreed in writing in advance, and may not endanger the confidentiality of other customers' data.
- Requests of the Personal Data Protection Board are reserved.
11. Liability and Precedence
If there is a conflict between this agreement and the Terms of Use concerning the protection of personal data, this agreement applies. The provisions on limitation of liability are as in the Terms of Use, except in cases where the law does not permit limitation.
Related Documents
Terms of Use · Sub-processor List · Privacy and Security Policy · KVKK Privacy Notice