Data Processing Addendum

DATA PROCESSING ADDENDUM

Service provider / processor: Nettescil Yazılım Bilişim Reklam Organizasyon Hizmetleri. Contact: kurumsal@nettescil.com.tr | 0850 307 01 18.

This addendum defines the parties’ duties where the customer processes personal data on its own behalf through Nettescil hosting, reseller, server, software or technical services. The customer determines the purposes and legal basis for the data it processes; Nettescil provides technical services only on documented customer instructions.

1. Scope and term

This addendum applies while the relevant service agreement and customer account are active. The service, data categories, data-subject groups, purposes and retention period are determined by the customer and limited to what the service requires.

2. Documented instructions

Nettescil processes data for hosting, transmission, backup, security, support, troubleshooting and documented technical instructions. If an instruction appears unlawful or creates a security risk, the customer is informed and the necessary security measure may be taken.

3. Customer duties

The customer is responsible for notices, a valid legal basis, data minimisation, user access, its own backups and responding to data-subject requests. Unnecessary special-category data should not be uploaded to Nettescil services.

4. Security

Reasonable technical and organisational measures such as access limitation, authentication, updates, backups, logging and incident review are applied. The customer remains responsible for its application, passwords, API keys, mail accounts and uploaded content.

5. Sub-processors and providers

Nettescil may use data-centre, network, backup, security, e-mail, domain, licence, payment or technical-support providers as needed. They receive only the necessary scope of access. The current provider list and material changes are communicated through appropriate channels.

6. Incidents and requests

Nettescil will notify the customer within a reasonable period of a personal-data security incident identified in its control area and share available technical details. The customer performs the primary assessment for data-subject requests, authority demands and controller notifications. Nettescil provides reasonable technical information and records on request.

7. International transfers

Where a provider’s location creates a possibility of transfer outside the country, the transfer mechanism, legal basis, provider and data categories are assessed separately. Transfers should not occur without an appropriate safeguard where one is required.

8. Return, deletion and continuing records

On termination, the customer should export its data using its own means. Return or deletion follows technical capability, customer instruction and legal retention duties. Copies in backups may remain for a limited technical cycle.

9. Confidentiality, audits and liability

The parties observe confidentiality. Audit and information requests are handled reasonably without compromising service security or other customers’ confidentiality. Nettescil is responsible only within its control area and under mandatory law.

10. Effective date

This addendum is effective from 15 September 2026. Data-protection and mandatory legal rules prevail in case of conflict. This addendum does not replace agreements the customer may need with its own customers.