Start free

Data Processing Agreement (DPA)

Version v1.0 β€’ Effective: 13 July 2026 β€’ English summary β€’ Integral annex to the Terms of Service

This is a courtesy translation provided for convenience. The legally binding version is the Veri İşleme Sâzleşmesi (Turkish).

Under KVKK art. 12 and, where applicable, GDPR art. 28, this agreement governs the relationship between the data controller (the Tenant) and the data processor (digitalforce360 OÜ, operating Ohana360).

Scope of processing

Personal data is processed solely to provide the CRM and connected modules, for the duration of the Terms of Service plus the return or deletion period. Data categories include identity and contact details, customer and lead records, transaction history and other data the Tenant enters; data subjects include the Tenant's customers, leads, contacts and employees.

Processor obligations

Ohana360 processes personal data only on the Tenant's documented instructions (use of the service counts as such instruction), binds its personnel to confidentiality, applies appropriate technical and organizational measures, reasonably assists the Tenant with data subject requests (the service provides record correction, deletion, a recycle bin and full data export), notifies the Tenant of data breaches, and returns or destroys data at the end of processing.

Subprocessors

The Tenant gives general authorization for subprocessors. The current list is on the Subprocessor List page (Turkish); in summary: Hostinger (cloud hosting, database and transactional email; server location: USA) and Google (Gemini API) (only if the Tenant uses the AI Assistant feature, the relevant record context is sent for AI processing). Subprocessors are bound by materially equivalent data protection obligations, and the Tenant is informed of changes with a right to object on reasonable grounds.

International transfers

Subprocessors may process data outside Turkey (hosting: USA). Transfers are made within the framework of KVKK's international transfer rules and, where applicable, GDPR transfer mechanisms (such as standard contractual clauses). The Tenant is responsible for informing data subjects about these transfers and obtaining consent where required, in particular when using the AI Assistant.

Security and breach notice

Measures include irreversible password storage (bcrypt), HTTPS everywhere, parameterized database access, role-based permissions, optional 2FA, audit logging and daily backups with offsite copies. Confirmed personal data breaches are notified to the Tenant without undue delay with the information needed for the Tenant's own notification duties.

Contact

legal@ohana360.com

Ready to see it with your own data?

Create your organization in minutes. Free to start, no credit card required.