Data Processing Agreement
Effective date: 18 August 2026
This Data Processing Agreement sets out the framework for the personal data processing activities Dreavion Technology carries out on the customer's behalf in connection with the use of the Performance Intelligence service, and forms an integral part of the Terms of Use.
Where a data processing agreement has been separately signed between the customer and Dreavion Technology, the signed document takes precedence on the matters it governs.
1.1. Definitions
The Law means Law no. 6698 on the Protection of Personal Data. The terms personal data, data subject, data controller, data processor, processing, erasure, destruction and anonymization carry the meanings given in the Law.
Customer Data means data qualifying as personal data that is transferred to Performance Intelligence through the customer's account or retrieved from connected platforms with the customer's authorization.
Sub-processor means the third party service providers Dreavion Technology engages in order to deliver the service covered by this agreement.
1.2. Roles of the parties
The customer is the data controller in respect of Customer Data. The customer determines the purpose and means of processing and is responsible for establishing and managing the data filing system.
Dreavion Technology is the data processor, processing Customer Data solely in line with the customer's instructions and for the purpose of delivering the service.
Processing that Dreavion Technology carries out as a data controller in respect of its own account users, corporate site visitors and job candidates falls outside the scope of this agreement and is subject to the relevant privacy notices.
1.3. Subject matter, nature, purpose and duration of processing
The subject matter and purpose of processing are the retrieval, storage, display and reporting of performance data from the platforms the customer connects, and its delivery through the channels the customer selects.
The nature of processing covers collection, recording, storage, organization, transfer and erasure carried out wholly or partly by automated means.
Processing is carried out for as long as the service relationship between the customer and Dreavion Technology continues, without prejudice to the provisions on termination of this agreement.
1.4. Data categories and data subject groups
The categories of data processed vary with the features the customer uses and may cover account and authorization data, integration and connection data, performance and reporting data, form and lead data the customer transfers into the system, notification delivery data, and technical and security records.
Data subject groups may include the customer's authorized users, the customer's own customers and prospects, and people who interact with the customer's digital properties.
The current and detailed category list is published in the Privacy and Personal Data Protection Policy.
1.5. The customer's obligations
The customer undertakes that the personal data it transfers to Performance Intelligence, or causes to be processed through connected platforms, has been obtained lawfully, that the required disclosure has been made, and that an applicable condition for processing exists.
When connecting a platform, the customer undertakes that it is authorized on that account and has the authority to permit the data to be processed through Dreavion Technology.
The customer is responsible for ensuring that the instructions it gives Dreavion Technology comply with the Law and applicable legislation.
The customer is obliged not to transfer into the system special categories of personal data and similar high-risk information that is not required to deliver the service.
1.6. Dreavion Technology's obligations
Dreavion Technology processes Customer Data solely in line with the customer's documented instructions and for the purpose of delivering the service. Using the service and configuring in-product settings count as the customer's instructions.
If an instruction is considered to be contrary to applicable legislation, Dreavion Technology informs the customer and may refrain from carrying out that instruction.
Personnel who access Customer Data are placed under a confidentiality obligation and access is granted only to the extent the role requires.
As stated in the Terms of Use, Customer Data is not used to train artificial intelligence or machine learning models, is not sold to third parties, and is not processed for advertising targeting.
1.7. Security measures
Dreavion Technology applies appropriate technical and administrative measures taking into account the nature and risks of the processing and the available technology. These measures cover access control and authorization, encryption in transit and at rest, customer-level separation, access and event logging, backups, and staff awareness.
The measures applied are reviewed and updated as risks and product architecture change. The level of security is not reduced while this agreement is in force.
1.8. Sub-processors
The customer gives general authorization for Dreavion Technology to engage sub-processors in order to deliver the service.
The current sub-processor list is published on the Sub-processors and External Platforms List page. When a new sub-processor is added to the list, the page is updated and the customer is informed a reasonable time in advance.
The customer may raise a reasonable and specific objection to a new sub-processor on data protection grounds. If no solution is found despite the parties' reasonable efforts, the customer may terminate the affected service.
Dreavion Technology concludes written agreements with the sub-processors it engages containing data protection obligations that are substantially the same as those in this agreement, and is responsible to the customer for the sub-processors' activities.
Advertising, analytics and similar external platforms that the customer connects at its own request are not sub-processors. Transfers to those platforms take place at the customer's own choice and instruction.
1.9. Transfer abroad
Part of the infrastructure used to deliver the service may process data outside Türkiye. Transfers of personal data abroad are carried out relying on whichever of the conditions set out in Article 9 of the Law is applicable.
Transfer mechanism and appropriate safeguard: the applicable mechanism will be announced in this section and on the Sub-processors page once infrastructure agreements and data flows are settled.
1.10. Data subject requests
Where Dreavion Technology receives a data subject request concerning Customer Data directly, it does not resolve that request on its own initiative and forwards it to the customer without delay.
Technical support is provided within the possibilities the product offers and to a reasonable extent so that the customer can meet its obligations under the Law.
1.11. Data breach notification
Where a personal data breach affecting Customer Data is identified, the customer is notified without delay.
The notification contains the information available at the time about the nature of the breach, the categories of data affected and the approximate number of data subjects, its likely consequences, and the measures taken or proposed. The notification is completed as the information becomes clearer.
Reasonable support is provided for the notifications the customer makes to the Board and to data subjects in its capacity as data controller. The obligation to notify the Board rests with the customer as data controller.
1.12. Record keeping, information and audit
Dreavion Technology keeps the necessary records of the processing activities it carries out under this agreement.
On the customer's request, reasonable information and documentation is provided to demonstrate compliance with the obligations in this agreement. Independent audit reports and security documentation, where available, may be shared in this context.
On-site audit requests are considered provided they are notified in writing a reasonable time in advance, do not disrupt ordinary business operations, are subject to a confidentiality obligation, and do not involve access to other customers' data.
1.13. Termination and the fate of the data
On termination of the service relationship, the customer may request the return or erasure of Customer Data within a reasonable period.
If no request is submitted within that period, Customer Data is erased, destroyed or anonymized, without prejudice to cases where legislation requires retention.
Data that must be retained under legislation is kept solely for the purpose of retention and under the security obligations in this agreement.
Copies may remain in technical backups for a limited period until the infrastructure providers' ordinary backup and rotation processes complete. This does not mean that deleted data is accessible again for ordinary use.
1.14. Liability
Liability arising from this agreement is subject to the liability provisions in the Terms of Use and to the allocation of risk in any signed customer agreement.
The mandatory provisions of the Law and the rules on the direct liability of the data controller and data processor towards data subjects are reserved.
1.15. Entry into force, changes and contact
This agreement enters into force when use of the Performance Intelligence service begins and applies for the duration of the service relationship.
It may be updated in line with changes in legislation or the product. The current version and its effective date are published on this page. Material changes to the customer's detriment are notified a reasonable time in advance.
Contact: info@dreaviontechnology.com. Dreavion Teknoloji Sanayi ve Ticaret Limited Şirketi, Emniyet Evleri Mah. Eski Büyükdere Cad. Sapphire No: 1/1, İç Kapı No: 1B04, Kağıthane / İstanbul. Istanbul Trade Registry Office, registry no 1154612. MERSİS no 0313155054000001.