Data Processing Agreement (DPA)
This is a courtesy translation provided for convenience. The legally binding version is the Veri Δ°Εleme SΓΆzleΕmesi (Turkish).
Under KVKK art. 12 and, where applicable, GDPR art. 28, this agreement governs the relationship between the data controller (the Tenant) and the data processor (digitalforce360 OΓ, operating Ohana360).
Scope of processing
Personal data is processed solely to provide the CRM and connected modules, for the duration of the Terms of Service plus the return or deletion period. Data categories include identity and contact details, customer and lead records, transaction history and other data the Tenant enters; data subjects include the Tenant's customers, leads, contacts and employees.
Processor obligations
Ohana360 processes personal data only on the Tenant's documented instructions (use of the service counts as such instruction), binds its personnel to confidentiality, applies appropriate technical and organizational measures, reasonably assists the Tenant with data subject requests (the service provides record correction, deletion, a recycle bin and full data export), notifies the Tenant of data breaches, and returns or destroys data at the end of processing.
Subprocessors
The Tenant gives general authorization for subprocessors. The current list is on the Subprocessor List page (Turkish); in summary: Hostinger (cloud hosting, database and transactional email; server location: USA) and Google (Gemini API) (only if the Tenant uses the AI Assistant feature, the relevant record context is sent for AI processing). Subprocessors are bound by materially equivalent data protection obligations, and the Tenant is informed of changes with a right to object on reasonable grounds.
International transfers
Subprocessors may process data outside Turkey (hosting: USA). Transfers are made within the framework of KVKK's international transfer rules and, where applicable, GDPR transfer mechanisms (such as standard contractual clauses). The Tenant is responsible for informing data subjects about these transfers and obtaining consent where required, in particular when using the AI Assistant.
Security and breach notice
Measures include irreversible password storage (bcrypt), HTTPS everywhere, parameterized database access, role-based permissions, optional 2FA, audit logging and daily backups with offsite copies. Confirmed personal data breaches are notified to the Tenant without undue delay with the information needed for the Tenant's own notification duties.
Contact
Ready to see it with your own data?
Create your organization in minutes. Free to start, no credit card required.