Nexus Dijital · Legal
Data Processing Agreement
Download PDF ↓
NEXUS DİJİTAL
Mesh Yazılım Teknoloji Ltd. Şti. · İstanbul · Trademark 2024/161525

For B2B / agency customers who require GDPR Article 28 DPA. Status: Template — finalize with KVKK/GDPR counsel before signing.

This Data Processing Agreement ("DPA") supplements the Terms of Service between Mesh Yazılım Teknoloji Limited Şirketi ("Processor", "Nexus Dijital") and the entity identified below ("Controller").

By executing this DPA, the parties agree to the terms below for all Personal Data processed by Processor on behalf of Controller under the underlying Service Agreement.


1. Definitions

Terms used in this DPA have the meaning given in the EU GDPR (Regulation 2016/679), the UK GDPR, and the Turkish KVKK (Law 6698) as applicable.

2. Subject and duration

3. Controller's obligations

Controller represents and warrants that: - It has a valid legal basis for the processing under applicable law. - It has provided required notices to data subjects. - Its instructions to Processor comply with applicable data protection law.

4. Processor's obligations

Processor will: - Process Personal Data only on documented instructions from Controller (the Service Agreement, the configuration in the Service, and any additional written instructions). - Ensure persons authorized to process Personal Data are bound by confidentiality. - Implement the technical and organizational measures in Annex 2. - Assist Controller in responding to data-subject rights requests. - Assist Controller with data-protection impact assessments and prior consultation where required. - Notify Controller without undue delay (and within 48 hours) of any Personal Data breach. - Make available all information necessary to demonstrate compliance. - Allow for and contribute to audits, including inspections, conducted by Controller or a Controller-mandated auditor (subject to Section 9).

5. Sub-processors

6. International transfers

7. Data subject rights

8. Personal Data breach

9. Audits

10. Return / deletion

11. Liability

12. Governing law and venue

13. Order of precedence

In the event of conflict between this DPA and the Service Agreement, this DPA prevails to the extent of the conflict in respect of data protection matters.


Annex 1 — Sub-processors

Sub-processor Service Location Transfer mechanism
Ixnodes Cloud infrastructure Türkiye Domestic (no transfer mechanism required)
Cloudflare, Inc. CDN, DDoS, DNS Global edge SCC + UK IDTA
Anthropic PBC AI text generation US / EU SCC
OpenAI, LLC AI text + image US / EU SCC
Google LLC (Gemini API) AI text US / EU SCC
fal.ai AI image generation US SCC
iyzico Ödeme Hizmetleri A.Ş. TR payment TR Domestic
Stripe Payments Europe Ltd. Payment IE/US SCC
Resend, Inc. Transactional email EU SCC

Up-to-date list and changes are published at https://nexusdijital.com/subprocessors. Controllers are notified via email of changes.


Annex 2 — Technical and organizational measures

Processor implements the following measures (non-exhaustive; see also our developer security docs):

A. Access control

B. Network security

C. Data security

D. Development security

E. Operational security

F. Business continuity

G. Privacy by design

Mesh Yazılım Teknoloji Limited Şirketi · Tax No 6191104251 · ARK 399 BLOK, N:399-1-1 Suadiye Mahallesi, İstanbul (Anadolu) 34730, Türkiye