Veri İşleme Sözleşmesi
Effective / Yürürlük: June 28, 2026
This Agreement governs the Processor's processing of personal data on behalf of the Controller for the purpose of providing the Platform services. It remains in force for the duration of the Controller's active subscription and survives termination to the extent necessary to fulfil post-termination obligations (Section 8).
The Processor will process personal data only on the documented instructions of the Controller — as set out in this Agreement, the Service Agreement, and the Platform's configurable settings. If applicable law requires the Processor to process data beyond those instructions, the Processor will inform the Controller before such processing (unless prohibited by law).
The Processor ensures that all personnel authorised to process Controller's personal data are bound by enforceable confidentiality obligations.
The Processor implements appropriate technical and organisational measures per KVKK Article 12, including:
The Controller grants general authorisation to the Processor to engage the sub-processors listed in Schedule A below. The Processor will:
The Processor will provide reasonable assistance to the Controller in responding to data subject rights requests under KVKK Article 11 (access, correction, deletion, objection) within timeframes that allow the Controller to meet its 30-day obligation.
The Processor will notify the Controller without undue delay, and no later than 72 hours, upon becoming aware of a personal data breach affecting Controller's data. The notification will include, to the extent available: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
The Processor will provide reasonable assistance to the Controller when the Controller is required to conduct a Data Protection Impact Assessment under applicable law, to the extent such assessment relates to the Platform's processing activities.
The Processor will provide the Controller with all information reasonably necessary to demonstrate compliance with this Agreement. The Processor will permit and contribute to audits or inspections conducted by the Controller or a mandated auditor, subject to at least 30 days' written notice and reasonable confidentiality arrangements.
Within 30 days of termination of the Service Agreement, the Processor will, at the Controller's election: (a) return all personal data to the Controller in a machine-readable format, or (b) securely delete or destroy all personal data, and certify such deletion in writing. Anonymised or aggregated data from which the Controller's data cannot be reconstructed may be retained.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | PostgreSQL database hosting, authentication, real-time services | USA (AWS) |
| Vercel Inc. | Platform hosting, serverless functions, CDN | USA / Global Edge |
Where sub-processors are located outside Turkey, the Processor relies on the safeguards available under KVKK Article 9 (adequacy decisions or appropriate safeguards as determined by the KVK Board) and, where applicable, Standard Contractual Clauses under GDPR. The Controller authorises such transfers subject to these safeguards.
This Agreement is governed by the laws of the Republic of Turkey. Any dispute arising under or in connection with this Agreement shall be subject to the exclusive jurisdiction of the courts of Istanbul, Turkey.
Applicable law: KVKK Law No. 6698 Art. 12 (security) Art. 8–9 (transfers) GDPR Art. 28 (where applicable)
Bu Sözleşme, Veri İşleyen'in Platform hizmetlerini sunmak amacıyla Veri Sorumlusu adına kişisel verileri işlemesini düzenlemektedir. Veri Sorumlusu'nun aktif aboneliği süresince yürürlükte kalır ve sözleşme sonrası yükümlülüklerin (Bölüm 8) yerine getirilmesi için gerekli ölçüde fesihten sonra da geçerliliğini korur.
Veri İşleyen; kişisel verileri yalnızca bu Sözleşme'de, Hizmet Sözleşmesi'nde ve Platform'un yapılandırılabilir ayarlarında yer alan Veri Sorumlusu'nun belgelenmiş talimatları doğrultusunda işler. Uygulanabilir hukuk, söz konusu talimatların ötesinde bir işleme zorunlu kılıyorsa Veri İşleyen, bu işlemden önce Veri Sorumlusu'nu bilgilendirir (hukuken yasaklı olmadıkça).
Veri İşleyen, Veri Sorumlusu'na ait kişisel verileri işlemeye yetkili tüm personelin uygulanabilir gizlilik yükümlülükleriyle bağlı olmasını sağlar.
Veri İşleyen, KVKK Madde 12 kapsamında uygun teknik ve idari tedbirleri uygular:
Veri Sorumlusu, Veri İşleyen'e aşağıdaki Ek A'da listelenen alt işleyenleri kullanmak için genel yetki vermektedir. Veri İşleyen:
Veri İşleyen, Veri Sorumlusu'nun KVKK Madde 11 kapsamındaki ilgili kişi hakları taleplerine (erişim, düzeltme, silme, itiraz) yanıt verebilmesi için, Veri Sorumlusu'nun 30 günlük yükümlülüğünü karşılamasına olanak tanıyacak sürelerde makul yardımı sağlar.
Veri İşleyen, Veri Sorumlusu'na ait kişisel verileri etkileyen bir veri ihlalinden haberdar olduğunda, gereksiz gecikme olmaksızın ve en geç 72 saat içinde Veri Sorumlusu'nu bilgilendirir. Bildirimde mümkün olduğunca şunlar yer alır: ihlalin niteliği, etkilenen ilgili kişi kategorileri ve tahmini sayısı, olası sonuçlar ile alınan veya önerilen tedbirler.
Veri İşleyen, Veri Sorumlusu'nun uygulanabilir hukuk kapsamında bir Veri Koruma Etki Değerlendirmesi yürütmesi gerektiğinde, bu değerlendirmenin Platform'un işleme faaliyetleriyle ilgili kısmında makul ölçüde yardım sağlar.
Veri İşleyen, Veri Sorumlusu'na bu Sözleşmeye uyumu kanıtlamak için gerekli tüm makul bilgileri sağlar. Veri Sorumlusu veya yetkilendirdiği denetçi tarafından yürütülecek denetim veya incelemelere en az 30 günlük yazılı ihbar ve makul gizlilik düzenlemeleri çerçevesinde izin verir ve katkıda bulunur.
Hizmet Sözleşmesi'nin sona ermesinden itibaren 30 gün içinde Veri İşleyen, Veri Sorumlusu'nun tercihine bağlı olarak: (a) tüm kişisel verileri makine tarafından okunabilir formatta iade eder veya (b) tüm kişisel verileri güvenli biçimde siler ya da imha eder ve bunu yazılı olarak teyit eder. Veri Sorumlusu'nun verileri yeniden oluşturulamayacak şekilde anonimleştirilmiş veya toplanmış veriler saklanabilir.
| Alt İşleyen | Amaç | Konum |
|---|---|---|
| Supabase Inc. | PostgreSQL veritabanı barındırma, kimlik doğrulama, gerçek zamanlı hizmetler | ABD (AWS) |
| Vercel Inc. | Platform barındırma, sunucusuz fonksiyonlar, CDN | ABD / Global Edge |
Alt işleyenlerin Türkiye dışında bulunduğu durumlarda Veri İşleyen, KVKK Madde 9 kapsamındaki güvencelere (Kurul tarafından belirlenen yeterlilik kararları veya uygun güvenceler) ve uygulanabildiği ölçüde GDPR Standart Sözleşme Maddelerine dayanır. Veri Sorumlusu, söz konusu güvenceler çerçevesinde bu aktarımlara onay vermektedir.
Bu Sözleşme, Türkiye Cumhuriyeti hukukuna tabidir. Sözleşmeden kaynaklanan veya bununla bağlantılı her türlü uyuşmazlık, İstanbul Mahkemeleri'nin münhasır yargı yetkisine tabidir.
Uygulanabilir mevzuat: KVKK Kanun No. 6698 Madde 12 (güvenlik) Madde 8–9 (aktarım)
© 2026 Hipocra Health Technologies