Processor: Pintelly, Türkiye. Customer is the controller (or processor appointing Pintelly as a subprocessor). Contact: [email protected]. Full company and address details will be substituted when finalised.
1. Scope, duration and instructions
This DPA applies while Pintelly provides services that process personal data submitted through a customer's projects. Pintelly processes that data only to provide, secure, maintain and support the service, on the documented instructions in the Terms, project settings and authorised support requests, unless law requires otherwise. Pintelly will notify the customer before legally required processing unless prohibited.
2. Processor obligations
- Ensure authorised personnel are bound by confidentiality.
- Apply appropriate technical and organisational measures described below.
- Assist, taking account of the nature of processing, with data-subject requests, security, breach assessment, DPIAs and regulator consultations.
- Notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data.
- Provide information reasonably necessary to demonstrate compliance and permit proportionate audits, subject to confidentiality, security and reasonable advance notice.
- Inform the customer if an instruction appears to infringe applicable data-protection law.
Annex 1 — Processing details
- Subject and purpose: website feedback, analytics, performance and SEO measurement, monitoring, integrations, support and customer-requested AI analysis.
- Duration: the service term plus the documented deletion, recovery, backup and legal-retention periods.
- Data subjects: customer users, team members, website visitors and people represented in submitted feedback or page content.
- Data: account/contact identifiers; URLs and page metadata; device/browser and approximate location; feedback and screenshots; interaction, performance, monitoring, SEO and replay data; integration tokens; support, security and audit logs.
- Special-category data is neither required nor intended. Customers must prevent it from being submitted unless expressly supported and lawfully configured.
Annex 2 — Technical and organisational measures
- Transport encryption; password hashing; encryption and access controls for integration secrets.
- Role-, ownership- and project-scoped authorisation, administrative audit records and credential revocation.
- Consent gating, field masking, content stripping for anonymous SEO checks, daily domain-scoped HMAC uniqueness and data minimisation.
- Separated transactional, analytics and object storage; backups and service monitoring appropriate to the deployment.
- Retention controls: analytics raw events up to two years, monitor checks 90 days, replay 60 days by default, and project deletion after a three-day recovery period.
- Incident containment, assessment, notification and recovery procedures; access restricted to personnel with operational need.
3. Subprocessors and transfers
The customer gives general written authorisation for the subprocessors on the public Subprocessor List. Pintelly will publish additions at least 30 days before they take effect where reasonably possible. Customers may object on reasonable data-protection grounds during that period; the parties will seek a practical alternative, failing which the affected feature may be discontinued.
Türkiye is outside the EEA and has no EU adequacy decision. Where Chapter V GDPR applies, the parties incorporate the applicable 2021 EU Standard Contractual Clauses: Module Two for controller-to-processor or Module Three for processor-to-processor transfers. The customer is data exporter, Pintelly is data importer, optional docking applies, and the Annexes to this DPA complete the SCC annexes. Transfers onward require an applicable Chapter V mechanism and supplementary measures where needed.
4. Return and deletion
At the end of service or on a valid instruction, Pintelly deletes or returns customer personal data unless law requires retention. Project deletion has a three-day recovery period, after which associated transactional and analytics rows are deleted. Backups are isolated from ordinary use and expire through their normal protected rotation; retained legal records remain restricted to that purpose.
5. Order and liability
The Terms govern matters not addressed here. This DPA prevails for processing obligations and the SCCs prevail for restricted transfers. Liability follows the Terms except where applicable data-protection law or the SCCs require otherwise.