Data Processing Agreement

Effective date: 27 September 2026

This Data Processing Agreement sets out the framework for the personal data processing activities Dreavion Technology carries out on the customer’s behalf in connection with the use of the Performance Intelligence service, and forms an integral part of the Terms of Use.

Where a data processing agreement has been separately signed between the customer and Dreavion Technology, the signed document takes precedence on the matters it governs.

This agreement is concluded electronically as part of the acceptance of the Terms of Use, including acceptance given in the self-service registration flow. A separately signed copy is not required for it to apply.

1.1. Definitions

The Law means Law no. 6698 on the Protection of Personal Data. The terms personal data, data subject, data controller, data processor, processing, erasure, destruction and anonymization carry the meanings given in the Law.

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation.

Applicable Data Protection Laws means, to the extent each applies to the processing concerned, the Law, the GDPR, and the secondary legislation and national implementing law adopted under them. Provisions of this agreement that refer to the Law apply where the Law applies. Where the GDPR applies, section 1.14 also applies, and the terms controller, processor, personal data breach and supervisory authority carry the meanings given in Article 4 of the GDPR.

Customer Data means data qualifying as personal data that is transferred to Performance Intelligence through the customer’s account or retrieved from connected platforms with the customer’s authorization.

Sub-processor means the third party service providers Dreavion Technology engages in order to deliver the service covered by this agreement.

1.2. Roles of the parties

The customer is the data controller in respect of Customer Data. The customer determines the purpose and means of processing and is responsible for establishing and managing the data filing system.

Dreavion Technology is the data processor, processing Customer Data solely in line with the customer’s instructions and for the purpose of delivering the service.

Processing that Dreavion Technology carries out as a data controller for its own purposes, in respect of its own account users, billing and subscription records, support correspondence, corporate site visitors and job candidates, falls outside the scope of this agreement and is subject to the relevant privacy notices.

1.3. Subject matter, nature, purpose and duration of processing

The subject matter and purpose of processing are the retrieval, storage, display and reporting of performance data from the platforms the customer connects, and its delivery through the channels the customer selects.

The nature of processing covers collection, recording, storage, organization, transfer and erasure carried out wholly or partly by automated means.

Processing is carried out for as long as the service relationship between the customer and Dreavion Technology continues, without prejudice to the provisions on termination of this agreement.

1.4. Data categories and data subject groups

The categories of data processed vary with the features the customer uses and may cover account and authorization data, integration and connection data, performance and reporting data, form and lead data the customer transfers into the system, notification delivery data, and technical and security records.

Data subject groups may include the customer’s authorized users, the customer’s own customers and prospects, and people who interact with the customer’s digital properties.

The current and detailed category list is published in the Privacy and Personal Data Protection Policy.

1.5. The customer’s obligations

The customer undertakes that the personal data it transfers to Performance Intelligence, or causes to be processed through connected platforms, has been obtained lawfully, that the required disclosure has been made, and that an applicable condition for processing exists.

When connecting a platform, the customer undertakes that it is authorized on that account and has the authority to permit the data to be processed through Dreavion Technology.

The customer is responsible for ensuring that the instructions it gives Dreavion Technology comply with the Law and applicable legislation.

The customer is obliged not to transfer into the system special categories of personal data and similar high-risk information that is not required to deliver the service.

1.6. Dreavion Technology’s obligations

Dreavion Technology processes Customer Data solely in line with the customer’s documented instructions and for the purpose of delivering the service. Using the service and configuring in-product settings count as the customer’s instructions.

If an instruction is considered to be contrary to applicable legislation, Dreavion Technology informs the customer and may refrain from carrying out that instruction.

Personnel who access Customer Data are placed under a confidentiality obligation and access is granted only to the extent the role requires.

As stated in the Terms of Use, Customer Data is not used to train artificial intelligence or machine learning models, is not sold to third parties, and is not processed for advertising targeting.

1.7. Security measures

Dreavion Technology applies appropriate technical and administrative measures taking into account the nature and risks of the processing and the available technology. These measures cover access control and authorization, encryption in transit and at rest, customer-level separation, access and event logging, backups where applicable and where backup functionality is enabled, and staff awareness.

The measures applied are reviewed and updated as risks and product architecture change. The level of security is not reduced while this agreement is in force.

1.8. Sub-processors

The customer gives general authorization for Dreavion Technology to engage sub-processors in order to deliver the service.

The current sub-processor list is published on the Sub-processors and External Platforms List page. When a new sub-processor is added to the list, the page is updated and the customer is informed a reasonable time in advance.

The customer may raise a reasonable and specific objection to a new sub-processor on data protection grounds. If no solution is found despite the parties’ reasonable efforts, the customer may terminate the affected service.

Dreavion Technology concludes written agreements with the sub-processors it engages containing data protection obligations that are substantially the same as those in this agreement, and is responsible to the customer for the sub-processors’ activities.

Advertising, analytics and similar external platforms that the customer connects at its own request are not sub-processors. Transfers to those platforms take place at the customer’s own choice and instruction.

1.9. Transfer abroad

The main application, database, authentication and file storage infrastructure used to deliver the service is hosted in the European Union (Frankfurt). This does not mean that all processing takes place in the European Union. Dreavion Technology operates from Türkiye, and some sub-processors and platforms connected by the customer may process data in other countries, as shown on the Sub-processors and External Platforms List.

A. Transfers where the Law applies

Part of the infrastructure used to deliver the service may process data outside Türkiye. Transfers of personal data abroad are carried out relying on whichever of the conditions set out in Article 9 of the Law is applicable.

The condition relied on is determined for each transfer relationship under Article 9 of the Law, for example an adequacy decision, appropriate safeguards such as the standard contracts provided for in the secondary legislation, or, for incidental transfers, the exceptions set out in that Article.

B. Transfers where the GDPR applies

Where Chapter V of the GDPR applies to a transfer of Customer Data to a country outside the European Economic Area, including where a customer established in the European Economic Area makes Customer Data available to Dreavion Technology in Türkiye, the transfer takes place only on the basis of a mechanism permitted by Chapter V. Depending on the processing and transfer relationship concerned, this may be an adequacy decision of the European Commission, standard contractual clauses adopted by the European Commission, or another mechanism permitted by Chapter V.

Where standard contractual clauses adopted by the European Commission are used, they are used without modification and completed only in the ways the Commission permits. These transfer safeguards are separate from the processor obligations under Article 28 of the GDPR set out in section 1.14 and do not replace them.

1.10. Data subject requests

Where Dreavion Technology receives a data subject request concerning Customer Data directly, it does not resolve that request on its own initiative and forwards it to the customer without delay.

Technical support is provided within the possibilities the product offers and to a reasonable extent so that the customer can meet its obligations under the Law.

1.11. Data breach notification

Where a personal data breach affecting Customer Data is identified, the customer is notified without delay.

The notification contains the information available at the time about the nature of the breach, the categories of data affected and the approximate number of data subjects, its likely consequences, and the measures taken or proposed. The notification is completed as the information becomes clearer.

Reasonable support is provided for the notifications the customer makes to the Board and to data subjects in its capacity as data controller. The obligation to notify the Board rests with the customer as data controller.

1.12. Record keeping, information and audit

Dreavion Technology keeps the necessary records of the processing activities it carries out under this agreement.

On the customer’s request, reasonable information and documentation is provided to demonstrate compliance with the obligations in this agreement. Independent audit reports and security documentation, where available, may be shared in this context.

On-site audit requests are considered provided they are notified in writing a reasonable time in advance, do not disrupt ordinary business operations, are subject to a confidentiality obligation, and do not involve access to other customers’ data.

1.13. Termination and the fate of the data

On termination of the service relationship, the customer may request the return or erasure of Customer Data within a reasonable period.

If no request is submitted within that period, Customer Data is erased, destroyed or anonymized, without prejudice to cases where legislation requires retention.

Data that must be retained under legislation is kept solely for the purpose of retention and under the security obligations in this agreement.

Where applicable and where backup functionality is enabled, copies may remain in technical backups for a limited period until the infrastructure providers’ ordinary backup and rotation processes complete. This does not mean that deleted data is accessible again for ordinary use.

1.14. Additional provisions where the GDPR applies

Where the GDPR applies to the processing of Customer Data, the provisions below supplement this agreement so that it contains the terms required by Article 28(3) of the GDPR. They build on the sections they refer to and do not affect section 1.15.

Documented instructions. Dreavion Technology processes Customer Data only on the customer’s documented instructions described in section 1.6, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which it is subject. In that case Dreavion Technology informs the customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Dreavion Technology immediately informs the customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

Confidentiality. Persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, as described in section 1.6.

Security of processing. Dreavion Technology takes the measures required by Article 32 of the GDPR, as described in section 1.7.

Sub-processors. The general authorisation, prior notice and objection mechanism in section 1.8 is the customer’s general written authorisation for the purposes of Article 28(2) of the GDPR. Dreavion Technology imposes on each sub-processor, by written contract, the data protection obligations required by Article 28(4) of the GDPR, in particular sufficient guarantees to implement appropriate technical and organisational measures, and remains responsible to the customer for the sub-processors’ performance of those obligations, as stated in section 1.8.

Data subject requests. Taking into account the nature of the processing, Dreavion Technology assists the customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the customer’s obligation to respond to requests to exercise the rights in Chapter III of the GDPR, as described in section 1.10.

Security, breaches, impact assessments and prior consultation. Taking into account the nature of the processing and the information available to it, Dreavion Technology assists the customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR. This covers security of processing, notification of personal data breaches to the supervisory authority and communication to data subjects, data protection impact assessments and prior consultation with the supervisory authority. Breach notifications under section 1.11 are made without undue delay after Dreavion Technology becomes aware of the breach. The obligation to notify the supervisory authority rests with the customer as controller.

Deletion or return. At the end of the provision of the service, Dreavion Technology, at the customer’s choice, deletes or returns Customer Data and deletes existing copies, unless Union or Member State law requires storage of the personal data. Section 1.13 describes how this is carried out, including any limited retention in technical backups.

Information and audits. Dreavion Technology makes available to the customer all information necessary to demonstrate compliance with the obligations in Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the customer or another auditor mandated by the customer. The conditions in section 1.12 apply to such audits, provided they do not prevent an audit the GDPR requires.

Records of processing. Where Article 30(2) of the GDPR applies, Dreavion Technology maintains a record of the processing activities it carries out on the customer’s behalf, as described in section 1.12.

1.15. Liability

Liability arising from this agreement is subject to the liability provisions in the Terms of Use and to the allocation of risk in any signed customer agreement.

The mandatory provisions of Applicable Data Protection Laws, including the Law and, where it applies, the GDPR, and the rules on the direct liability of the data controller and data processor towards data subjects are reserved.

1.16. Entry into force, changes and contact

This agreement enters into force when use of the Performance Intelligence service begins and applies for the duration of the service relationship.

It may be updated in line with changes in legislation or the product. The current version and its effective date are published on this page. Material changes to the customer’s detriment are notified a reasonable time in advance.

Contact: info@dreaviontechnology.com. Dreavion Teknoloji Sanayi ve Ticaret Limited Şirketi, Emniyet Evleri Mah. Eski Büyükdere Cad. Sapphire No: 1/1, İç Kapı No: 1B04, Kağıthane / İstanbul. Istanbul Trade Registry Office, registry no 1154612. MERSİS no 0313155054000001.

Annex 1. Summary of processing details

This annex summarises the processing details set out in sections 1.3, 1.4 and 1.8. Where there is a difference, those sections apply.

Subject matter: retrieving, storing, displaying and reporting performance data from the platforms the customer connects, and delivering it through the channels the customer selects.

Duration: for as long as the service relationship continues, followed by return or deletion under section 1.13.

Nature and purpose: collection, recording, storage, organisation, transfer and erasure, wholly or partly by automated means, to deliver the Performance Intelligence service to the customer, including AI-assisted analysis through Scout where the customer uses it.

Categories of personal data: account and authorisation data, integration and connection data, performance and reporting data, form and lead data the customer transfers into the system, notification delivery data, and technical and security records. Special categories of personal data are not intended to be processed.

Categories of data subjects: the customer’s authorised users, the customer’s own customers and prospects, and people who interact with the customer’s digital properties.

Technical and organisational measures: as described in section 1.7.

Sub-processors: as published on the Sub-processors and External Platforms List.

Dreavion Technology

Dreavion Technology

We make emerging technology understandable and usable.

© 2026 Dreavion Technology

Dreavion Technology

Dreavion Technology

We make emerging technology understandable and usable.

© 2026 Dreavion Technology

Dreavion Technology

Dreavion Technology

We make emerging technology understandable and usable.

© 2026 Dreavion Technology