Data Processing Agreement (DPA)
Data Controller
Within the scope of this document, your personal data is processed as the data controller under the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and the European Union General Data Protection Regulation (GDPR) by the following organisation:
- Data Controller: VisiBack Official
- E-mail: support@visiback.com
- Web: visiback.com
Parties and Roles
This Data Processing Agreement (DPA) governs the personal-data processing relationship between the company using the service (the “Data Controller”) and VisiBack Official (the “Data Processor”). VisiBack processes data solely on the instructions of the Data Controller and within the framework of this DPA.
Subject Matter and Duration of Processing
The subject matter of the processing is the personal data collected within the scope of providing the device-monitoring service. Processing continues for as long as the service contract is in force; upon its termination, the data is returned or destroyed at the Data Controller's choice.
Obligations of the Data Processor
- To process data only in accordance with the written/in-app instructions of the Data Controller;
- To take appropriate technical and administrative security measures (encryption, RBAC, isolation, auditing);
- To ensure that personnel involved in the processing are under a confidentiality obligation;
- To use sub-processors only under equivalent safeguards and with prior information;
- To support the Data Controller in responding to data-subject requests and breach notifications.
Breach Notification
Upon detection of a personal-data breach, VisiBack informs the Data Controller without undue delay and provides support within the time and content required by applicable law (KVKK / GDPR Articles 33-34). Isolation between companies is fundamental; one company's data is not transferred to another. This DPA does not include any service-level commitment (SLA).
Data Sharing, Transfer and Isolation
None of the collected data is shared, rented or sold to third parties for marketing, advertising or profit. Your data is transferred only in the following cases and only to the extent necessary:
- Where there is a lawful and duly-made request from legally authorised public authorities, courts, or judicial/administrative bodies, solely within the scope of the relevant legal obligation;
- With infrastructure providers that are technically required to deliver the service and act solely as data processors (hosting, e-mail delivery, object storage, etc.), under contractual confidentiality and data-security obligations.
Per-company isolation: All collected data is processed strictly within the scope of the company (tenant) it belongs to. Data of different companies is logically isolated from one another; no company's data is shown to or shared with any other company. Data is used only for analytics and for product/service improvement, within the scope of the company concerned.
Data Security Measures
Appropriate administrative and technical measures are taken to protect your data against unlawful access, loss, disclosure or alteration:
- TLS encryption in transit and storage encryption for sensitive fields;
- Role- and permission-based access control (RBAC) with the least-privilege (need-to-know) principle;
- Audit logging of critical operations for accountability;
- Per-company logical isolation and access gates;
- Regular security reviews, secure backups and access logging.
Retention Period and Erasure
Your personal data is retained for as long as necessary for the purposes for which it is processed and for the mandatory retention periods prescribed by applicable law. When the purpose ceases to exist or the retention period expires, your data is deleted, destroyed or anonymised in accordance with the KVKK and applicable law. Consent records that constitute legal evidence (including technical information such as IP, User-Agent and timestamp) are retained for the duration of the burden-of-proof and statutory limitation periods.
Rights of the Data Subject (KVKK art. 11 / GDPR)
Under Article 11 of the KVKK and the GDPR (access, rectification, erasure, objection to processing, portability), as a data subject you have the following rights:
- To learn whether your personal data is being processed and, if so, to request information about it;
- To learn the purpose of processing and whether the data is used in accordance with that purpose;
- To know the third parties to whom your data is transferred, domestically or abroad;
- To request rectification of incomplete or inaccurately processed data;
- To request erasure or destruction of your data under Article 7 of the KVKK (right to be forgotten);
- To request that rectification, erasure or destruction be notified to third parties to whom the data has been transferred;
- To object to any adverse result arising solely from automated analysis of your data;
- To claim compensation for damages arising from unlawful processing;
- To additionally exercise your rights of access, data portability and objection to processing under the GDPR.
Applications and Contact
To exercise the rights above or to submit requests regarding your personal data, you may contact support@visiback.com. For suspected personal-data breaches, complaints or objections, you may also apply through the Breach Notification Form available on our website. Your applications are handled free of charge, as soon as possible and in any case within the periods prescribed by law (a maximum of 30 days under the KVKK).
Notification of Changes
This text may be revised in line with changes in legislation or updates to our services. The current version is always published at visiback.com; material changes are announced through appropriate channels (in-app notification or e-mail) and, where necessary, your renewed consent is requested.
Governing Law
This text is governed by the laws of the Republic of Türkiye and is interpreted primarily in accordance with Law No. 6698 (KVKK) and related secondary legislation. For data subjects located in the European Union, the provisions of the GDPR also apply. The Istanbul (Çağlayan) Courts and Enforcement Offices have jurisdiction over any disputes arising from the application of this text.