Data Processing Addendum
Effective Date: June 6, 2026 · Version: 1.1
(KVKK / GDPR — Controller ↔ Processor)
This DPA governs the processing of Customer Data by Processor on behalf of Customer. It is incorporated into and forms part of the Agreement between Customer (you) and SEZ YAZILIM DANIŞMANLIK TİCARET LİMİTED ŞİRKETİ ("sevk", "Processor"). If there is any conflict between this DPA and the Agreement regarding the processing of Customer Data, this DPA prevails. Read this together with our Privacy Policy, Security, and Subprocessors pages.
1. Definitions
1.1 Applicable Data Protection Laws
Means, as applicable: (i) the Turkish Law on the Protection of Personal Data No. 6698 ("KVKK") and secondary legislation and Board decisions; and (ii) the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), together with any other data protection laws applicable to the Parties.
1.2 Customer Data
Means any personal data (including email addresses and related metadata) that Customer uploads, transfers, stores, or otherwise makes available to the Services, or that is processed on Customer's behalf through use of the Services, including end-recipient/contact list data and campaign-related data.
1.3 End-Recipients
Means individuals whose personal data is included in Customer Data (e.g., Customer's contacts/subscribers).
1.4 Services
Means the email sending, inbound email receiving and processing, deliverability, reporting, analytics, and related services provided by Processor under the Agreement.
1.5 Sub-processor
Means any third party engaged by Processor to process Customer Data in connection with the Services.
1.6 Personal Data Breach
Has the meaning given under GDPR (where applicable) and includes any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. Terms "controller", "processor", "personal data", and "processing" shall have the meanings given in GDPR and/or KVKK, as applicable.
2. Roles and Scope
2.1 Roles
For all Customer Data processed via the Services, Customer acts as Data Controller and Processor acts as Data Processor.
2.2 Scope and Purpose Limitation
Processor shall process Customer Data only: (a) to provide the Services and perform its obligations under the Agreement and this DPA; and (b) in accordance with Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's lawful configuration and use of the Services.
2.3 No Sale / No Independent Use
Processor will not sell, rent, or otherwise use Customer Data for its own marketing or independent commercial purposes.
3. Customer (Controller) Obligations
3.1 Lawfulness and Instructions
Customer represents and warrants that:
- (a) it has a valid legal basis under Applicable Data Protection Laws for collecting and processing Customer Data and for instructing Processor to process Customer Data;
- (b) it will provide all required notices to End-Recipients and obtain any required consents/permissions; and
- (c) its instructions and use of the Services comply with Applicable Data Protection Laws and applicable electronic communications / anti-spam rules (including unsubscribe/opt-out requirements where applicable).
3.2 Data Quality and Minimization
Customer is responsible for the accuracy, quality, and lawfulness of Customer Data and for ensuring it does not upload data beyond what is necessary for its purposes.
3.3 Sensitive Data Prohibition
Customer shall not upload or otherwise process through the Services any special categories of personal data / sensitive data (e.g., health data, political opinions, biometric data), unless the Parties expressly agree in writing and Customer has established a lawful basis and implemented required safeguards.
3.4 Indemnity (Sensitive Data / Unlawful Use)
To the extent permitted by applicable law and subject to any liability limitations in the Agreement, Customer shall indemnify and hold harmless Processor from and against reasonable losses, damages, and regulatory fines/penalties arising from Customer's unlawful instructions or Customer's breach of Sections 3.1–3.3 (including uploading sensitive data contrary to this DPA), except to the extent caused by Processor's breach of this DPA.
4. Processor Obligations
4.1 Processing on Documented Instructions
Processor shall process Customer Data only on documented instructions from Customer, including regarding transfers of Customer Data to a third country or international organization, unless required to do so by applicable law.
4.2 Unlawful Instructions / Legal Conflict
If Processor reasonably believes that an instruction infringes Applicable Data Protection Laws, Processor shall promptly inform Customer and may suspend the relevant processing until the Parties agree on a lawful instruction.
4.3 Confidentiality
Processor shall ensure that persons authorized to process Customer Data are under appropriate confidentiality obligations (contractual or statutory).
4.4 Security
Processor shall implement and maintain appropriate technical and organizational measures ("TOMs") to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The TOMs are described in our Security page and summarised in Annex 2.
4.5 Accountability Documentation
Processor shall maintain internal documentation of processing activities as required by applicable law and shall make available relevant compliance information as set out in Section 10.
5. Sub-Processors
5.1 General Authorization
Customer grants Processor a general written authorization to engage Sub-processors for the purposes of providing the Services.
5.2 Flow-Down Obligations
Processor shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA, including appropriate security measures.
5.3 Sub-processor List
Processor maintains an up-to-date sub-processor list at /subprocessors("Sub-processor List").
5.4 Notice of Changes & Objection
- (a) Processor will provide at least 30 days' prior notice of any intended addition or replacement of a Sub-processor by updating the Sub-processor List and/or notifying Customer via email or in-app notice to the account owner email on file.
- (b) Customer may object within 30 days on reasonable and objective data protection grounds.
- (c) If the Parties cannot resolve the objection, Processor may (i) offer an alternative; or (ii) allow Customer to terminate the affected Service(s) in accordance with the Agreement (or, if not addressed, the Parties will agree a commercially reasonable exit).
5.5 Liability for Sub-processors
Processor remains responsible for the performance of its Sub-processors to the extent required under Applicable Data Protection Laws and the Agreement.
6. Data Subject Requests
6.1 Controller Responsibility
Customer is responsible for responding to requests from End-Recipients.
6.2 Redirection
If an End-Recipient contacts Processor directly regarding Customer Data, Processor shall, where appropriate, promptly redirect the request to Customer and, upon Customer's request, provide reasonable assistance as set out below.
6.3 Assistance
Taking into account the nature of processing and Processor's technical capabilities, Processor shall provide reasonable assistance to enable Customer to fulfil data subject requests within statutory timeframes, including (where available) data export, suppression/blacklisting, and deletion functionality.
7. Personal Data Breach Notification
7.1 Notification to Customer
Processor shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data and shall provide information reasonably required for Customer's risk assessment and any mandatory notifications.
7.2 Target Notification Time
Without limiting the "without undue delay" standard, Processor's target is to notify Customer within 48 hours of awareness, where feasible.
7.3 Controller Notifications
Customer is responsible for any legally required notifications to authorities and/or data subjects. Processor will provide reasonable cooperation and supporting information as needed.
8. International Data Transfers
8.1 General
Customer acknowledges that Customer Data may be processed outside Türkiye and/or the EEA due to Processor's infrastructure and Sub-processors.
8.2 Appropriate Safeguards
Where required, Processor shall implement appropriate safeguards for international transfers, including (as applicable):
- (a) EU Commission SCCs under GDPR Art. 46; and/or
- (b) Turkish standard contractual clauses ("standart sözleşme") or other lawful transfer mechanisms under amended KVKK Art. 9.
8.3 KVKK Standard Contract Notification (5 Business Days)
Where Processor executes a KVKK standard contract for a relevant transfer (including via Sub-processors), Processor shall ensure notification to the Turkish authority within five (5) business days following completion of signatures, using the legally prescribed method/module.
8.4 Customer's Additional Steps
Customer may need to take additional steps for its controller-level international transfer compliance. Processor will provide reasonable information about its transfer safeguards upon request.
9. Deletion or Return of Customer Data
9.1 Termination Request
Upon termination or expiration of the Agreement, Processor shall, at Customer's written choice, return or delete Customer Data.
9.2 Backups
Customer Data stored in backups will be deleted/overwritten in accordance with Processor's backup retention cycle within 30 days, unless a longer retention period is required by applicable law.
9.3 Legal Retention Exception
Processor may retain Customer Data to the extent required by applicable law, or for the establishment, exercise, or defence of legal claims, or for security/abuse prevention, provided it is isolated and protected and not used for any other purpose.
10. Audit, Information, and Compliance Evidence
10.1 Information
Processor shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA.
10.2 Audit Rights (Reasonable Limitations)
Customer may audit Processor's compliance with this DPA: (a) upon reasonable prior written notice (e.g., 30 days); (b) no more than once per year (unless a material breach or breach incident occurs); (c) during normal business hours; and (d) subject to confidentiality and security restrictions to protect other customers and Processor's systems.
10.3 Alternative Evidence
Processor may satisfy audit requirements by providing independent third-party security reports/certifications and security documentation, where available, unless Customer reasonably requires further verification.
11. Assistance with DPIA and Regulator Consultations
Processor shall provide reasonable assistance to Customer in fulfilling obligations relating to security of processing, DPIAs, and consultations with supervisory authorities, to the extent applicable and taking into account the nature of processing and information available to Processor.
12. Technical and Organizational Measures
Processor's TOMs are described in our Security page and summarised in Annex 2. Processor may update TOMs provided that such updates do not materially degrade the overall security of the Services.
13. Limitation of Liability
This DPA does not expand either Party's liability beyond the limitations set out in the Agreement, except where such limitation is prohibited by Applicable Data Protection Laws.
14. Term
This DPA remains in effect for the duration of Processor's processing of Customer Data under the Agreement.
Annex 1 — Processing Details
- A. Subject-matter: Email delivery platform services (campaign sending, inbound email receiving and processing, deliverability, reporting, suppression handling, customer support related to Customer Data).
- B. Duration: Term of the Agreement + backup deletion cycle + any legally required retention.
- C. Nature: Collection (from Customer and, for inbound email, from third-party senders), storage, transmission, retrieval, analysis of delivery events, suppression handling, deletion/return upon termination.
- D. Purpose: Provide the Services under Customer's instructions.
- E. Categories of data: email address, subscription state, audience and segment membership, bounce and complaint history, message metadata (subject, status, timestamps, message ID, user-agent), any optional custom fields the Customer chooses to attach to a contact (stored in a single JSON data field), and, where the Customer enables inbound email, the content of messages addressed to the Customer's domains (sender address and headers, message body, and attachments).
- F. Data subjects: End-Recipients, senders of inbound email addressed to the Customer's domains, and Customer's authorized users/admins (to the extent included in Customer Data).
- G. Special categories: Not intended; prohibited under Section 3.3 unless expressly agreed in writing with safeguards.
Annex 2 — Technical & Organizational Measures
The complete TOMs description is on the Security page. The summary below tracks DPA Annex 2:
- Access control: role-based access (Owner, Admin, Member), 35 capability flags on API keys, optional per-domain restriction, TOTP available for users.
- Encryption in transit: Let's Encrypt TLS terminated on our own hosts. Encryption at rest: AES-256 on Cloudflare R2 (object storage) and DigitalOcean block storage (LUKS).
- Tenant isolation: project-scoped data model with row-level project foreign keys; capability checks on every authenticated request.
- Logging and monitoring: structured application logs aggregated into Loki, host and application metrics in Prometheus, frontend errors and performance traces in Sentry (with text and input redaction), AWS SES delivery events received via signed SNS webhooks.
- Vulnerability management and patching: dependency updates and OS patching cadence on production hosts.
- Backups and disaster recovery: automated database backups retained for 30 days.
- Sub-processor due diligence: signed DPAs and SCCs with each sub-processor (full list at /subprocessors).
Annex 3 — Sub-Processor List
Processor maintains the current Sub-processor List at /subprocessors, including: sub-processor name, service type, processing location(s), and transfer safeguard mechanism (EU SCC / KVKK standard contract).
By using sevk.io, you acknowledge that you have read, understood, and agree to be bound by this DPA, our Terms of Service, our Privacy Policy, and our Cookie Policy.