Skip to content
WyvUp

Data Processing & Governance

Data Processing Agreement

Binding terms governing personal data processing where WyvUP acts as a Data Processor on behalf of the customer (Data Controller) pursuant to Law No. 6698 (KVKK).

1. Parties and Statutory Roles

This Data Processing Agreement is entered into between the CLIENT acting as the primary Data Controller, and YİĞİT CENGİZ (Yazılım, Medya & Prodüksiyon Stüdyosu) operating as the technical Data Processor.

Data Processor: YİĞİT CENGİZ (WyvUp Stüdyo)

Tax Office: Şirinyer Vergi Dairesi (İzmir)

Registered Address: Adalet Mah. Manas Bulvarı Folkart Towers B Kule No:39 Kat:25 Kapı No:2511 Bayraklı / İzmir

Data Privacy Contact: [email protected]

2. Scope of Processing & Controller Warranties

All inquiries, contact leads, and customer interactions captured through tenant websites belong exclusively to the Client's business. The Client explicitly warrants the following:

  • Notice & Consent Compliance: The Client holds sole responsibility for providing valid statutory privacy notices and obtaining lawful consent from its end-users.
  • Lawful Collection Warranty: The Client warrants that all customer data transferred or processed was collected through legitimate statutory means.
  • Processor Duty of Instruction: WyvUP processes tenant data solely upon documented instructions of the Client and never commercializes or profiles end-user records.

3. Technical & Organizational Measures (TOMs)

In compliance with statutory cybersecurity standards, WyvUP enforces enterprise technical and organizational measures:

a) Multi-Tenant Architectural Segregation:

Tenant databases and static webspaces are strictly compartmentalized with zero cross-tenant contamination.

b) Edge Shielding & DDoS Mitigation:

Traffic is scrubbed through Cloudflare edge nodes with TLS 1.3 encryption and automated bot mitigation.

c) Access Audit Logging:

Administrative operations and container access traces are permanently retained for auditing.

4. Security Incident & Breach Notification

Upon confirming an actual security compromise affecting tenant data, WyvUP notifies the Client without undue delay and within 48 hours, detailing the scope and remedial actions taken.

5. Data Return, Takeout & Destruction

Upon termination, clients retain full access to export all customer lead archives via the Data Takeout engine for 30 days. After this transition period, tenant databases are permanently purged from active storage nodes.

6. Indemnification & Recourse

The Client shall indemnify and hold harmless WyvUP against any regulatory penalties or third-party claims arising from the Client's failure to provide statutory end-user notices or unlawful collection of customer records.