Veri İşleme Sözleşmesi (DPA)
Son güncelleme: 01.09.2026 · [ŞİRKET_ADI]
Bu DPA, B2B müşterilerin kendi son kullanıcılarına ait verileri Egoko üzerinden işlemesi durumunda tarafların yükümlülüklerini düzenler.
Roller
Müşteri veri sorumlusu, {COMPANY_NAME} ise veri işleyendir. Egoko, verileri yalnızca müşterinin talimatları ve hizmetin gerektirdiği ölçüde işler.
Yükümlülükler
Egoko; teknik ve idari güvenlik önlemleri alır (şifreleme, erişim kontrolü, audit log), veri ihlallerini 72 saat içinde bildirir ve alt işleyicileri güncel tutar.
Müşteri; işlediği verinin hukuka uygunluğundan ve ilgili kişilerin aydınlatılmasından sorumludur.
Alt işleyiciler ve denetim
Güncel alt işleyici listesi için Ek A'ya (Alt İşleyici Listesi) bakın. Yeni alt işleyici eklenmesi durumunda müşteriye bildirilir.
Müşteri, yılda bir kez denetim talep edebilir; denetim makul süre öncesinden bildirilmelidir.
English version — Data Processing Agreement (DPA)
This DPA governs the parties' obligations where B2B customers process their end users' data via Egoko.
Roles
The customer is the controller and {COMPANY_NAME} is the processor. Egoko processes data only on the customer's instructions and as required by the service.
Obligations
Egoko takes technical and organizational measures (encryption, access control, audit logging), notifies breaches within 72 hours and maintains current sub-processors.
The customer is responsible for the lawfulness of data and for informing data subjects.
Sub-processors and audit
See Annex A (Sub-processor List) for the current set. Customers are notified when a sub-processor is added.
Customers may request an audit once per year with reasonable prior notice.