This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer using ZeroRecall for a business purpose ("Controller") and Astro Tasarım Simay Yenice ("Processor"), and takes effect from the moment you create an account and use the service. It reflects GDPR Article 28 and the equivalent obligations under Turkish Law No. 6698 (KVKK). Enterprise customers can request a separately countersigned copy at hello@zerorecall.ai.
1. Parties
- Controller: the customer account holder. The Controller decides what audit targets, canaries and connector configuration to submit, and for what purpose.
- Processor: Astro Tasarım Simay Yenice, registered in Türkiye. Full registered address and registry details are shared by email on request at hello@zerorecall.ai.
2. Subject matter and scope
This DPA covers personal data that may appear in audit inputs (target labels, identifiers, canary markers) and audit outputs (findings, the signed evidence file) when the Processor runs an audit on the Controller's instructions. It does not cover account data (name, email, organization), for which the Processor acts as its own controller under the Privacy Policy.
3. Processor obligations
- Processes personal data only on the Controller's documented instructions, solely to run the requested audit.
- Does not use audit-target data for its own purposes, does not sell it, and does not use it to train models.
- Ensures personnel and sub-processors with access are bound by confidentiality obligations.
- Informs the Controller promptly if an instruction appears to infringe GDPR, KVKK, or other applicable data protection law.
4. Security
The Processor applies technical and organizational measures appropriate to the data processed: encryption in transit (TLS), access limited to authorized personnel, authenticated access control, and connector secrets (API keys, database DSNs) that are used in memory at run time only and are never written to the evidence file or persistent storage. No system can guarantee absolute security; the Processor commits to reasonable, law-compliant measures and to the security posture described in the Privacy Policy.
5. Transparency log disclosure
Every completed audit is recorded in an append-only transparency log so that the Processor cannot silently reissue or backdate an evidence file after the fact. The log entry contains only the cryptographic hash of the signed evidence file and the date the audit was completed. It never contains the Controller's name, the data subject's name or email, the audited system's identity, or any other identifier from the audit input or output. By using the service, the Controller acknowledges and accepts that the fact that an audit was completed on a given date becomes independently, publicly verifiable in this way, while the content of the audit remains confidential under this DPA.
6. Sub-processor use and notice
The Processor uses infrastructure providers to run the service. The current list, and what each one processes, is published on the Sub-processors page. This list is updated before a new sub-processor is added. The Controller may object to a new sub-processor on reasonable grounds by writing to hello@zerorecall.ai; the parties will cooperate on a reasonable resolution, and if none is reached the Controller may terminate the service.
7. Assistance with data subject requests
The Processor provides reasonable technical assistance to help the Controller respond to a data subject's request (access, rectification, erasure, objection) under GDPR Articles 15 to 21 or KVKK Article 11. A data subject request received directly by the Processor about audit-target data is forwarded to the relevant Controller without undue delay, as required of a processor.
8. Breach notification
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting data it processes, providing what is known at the time about the nature of the breach, the categories of data affected, the estimated number of data subjects affected, and measures taken or proposed. The Processor cooperates so the Controller can meet its own notification obligations to supervisory authorities (including the Turkish Personal Data Protection Board) and affected individuals.
9. Audit rights
With reasonable prior notice and without disrupting the normal operation of the service, the Controller may request reasonable information demonstrating compliance with this DPA (for example, the sub-processor list and a summary of security measures). Available third-party certification reports may be provided in lieu of an on-site audit. An on-site audit request is considered subject to reasonable justification and a confidentiality undertaking; costs are borne by the requesting party unless otherwise agreed.
10. International transfer
Some sub-processors are located outside Türkiye and the EU. Such transfers are made only to the extent the service requires and in line with applicable safeguards: KVKK Article 9 (explicit consent or another basis recognized by the Board) and, where EU-originating data is involved, appropriate GDPR transfer mechanisms (such as Standard Contractual Clauses or an equivalent).
11. Return and deletion of data at termination
Within 30 days of account closure or termination of this DPA, audit inputs and outputs are deleted, or returned in a reasonable format on request. Records subject to a legal retention obligation (invoicing, accounting) are kept only for the period required by applicable law and deleted at the end of that period.
12. Liability and term
This DPA is subject to the limitation of liability in the Terms of Service and remains in effect for as long as your account is active. In case of conflict between the Terms of Service and this DPA on matters of personal data processing, this DPA prevails.
Contact
For questions about this DPA: hello@zerorecall.ai