FOUNDING LISTE D’ACCÈS ANTICIPÉ OUVERTE
◆ LEGAL · DATA PROCESSING

Data Processing Agreement (DPA)

We process customer data on the customer's instructions, isolated and auditable. Here is the summary.

Last updated: June 2026 · GDPR Art. 28 aligned · English translation provided for convenience; the Turkish version prevails.

1. Parties and roles

Data controller: the business using the service (the customer). Data processor: PROCUX Technology Inc. ("Aircux"). Aircux processes customer data only in line with the customer's documented instructions.

2. Subject, duration and purpose of processing

  • Subject: end-user data coming from the channels the customer connects.
  • Purpose: providing the growth intelligence service (visibility, identity, journeys, attribution, approved actions).
  • Duration: for the term of the agreement; on termination the deletion/return provisions apply.

3. Sub-processors

Aircux may use a limited number of sub-processors (e.g. a hosting provider in the EU region) to provide the service. All sub-processors must provide at least the level of protection in this agreement. The customer is informed in advance of any change of sub-processor and keeps the right to object.

4. Technical and organisational measures

  • Tenant isolation: each customer's data runs technically separated from the others.
  • Access control: least privilege, logged and auditable access.
  • Encryption in transit and at rest and regular backups.
  • Approval gate & audit trail: every outbound action goes through approval and is recorded.

5. Data breach notification

If a personal data breach is detected, the customer is informed without undue delay, including the nature of the breach, the categories of data affected and the measures taken.

6. Deletion and return

When the agreement ends, customer data is returned or permanently deleted, as the customer chooses. The customer can take a single-command export at any time; KVKK/GDPR erasure requests are handled in the product.