Data Processing Agreement

An inseparable annex to the subscription agreement, under KVKK art. 12 and GDPR art. 28.

Last updated: August 2026

1Purpose, scope and roles

This Data Processing Agreement ("DPA") forms an inseparable annex to the Software Subscription and Use Agreement between BLACK REIN TEKNOLOJİ A.Ş. ("Processor") and the natural or legal person using the ihracatAI platform ("Customer").

Under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR"), the Customer is the controller and the Processor is the processor with respect to data processed on the platform.

Lawful collection of the data, determination of the purpose and legal basis of processing, and discharge of transparency duties towards data subjects rest with the Customer. Processing strictly on the Customer's instructions and securing the data technically rest with the Processor.

Where this DPA and the subscription agreement conflict on data protection, this DPA prevails.

2Subject matter, nature, purpose and duration

Subject matter and nature: storage, organisation, transfer, analysis and processing of data through AI models in order to provide the platform.

Purpose: running the Customer's export operation — buyer discovery, commercial outreach, offer and proforma generation, logistics and customs calculations, brand and content production.

Duration: processing continues for the subscription term and until the termination procedure in clause 9 has been completed.

Categories of data subjects: the Customer's officers and staff, together with corporate representatives of the businesses the Customer contacts in the course of its commercial activity.

Categories of data: corporate contact details (role addresses on the company's own domain, title and seniority), company and commercial information, correspondence content, account and usage records.

Special categories of personal data and consumer (B2C) personal data are outside the scope of the platform and are not processed.

3Processor obligations

The Processor processes personal data only on the Customer's documented instructions and for the purpose of providing the platform; it does not use, sell or market the data for its own purposes.

The Processor ensures that personnel with access to the data are bound by confidentiality and limits access to what the task requires.

Where technical support requires access to Customer data, that access is limited to the scope and duration the support action requires and is logged.

If the Processor considers an instruction unlawful, it informs the Customer without delay.

The Processor may use only aggregated, anonymised usage statistics that do not constitute personal data to improve the service; such data may not be used in a way that identifies the Customer and is not shared with third parties.

4Customer obligations

The Customer warrants that data it uploads to, or processes through, the platform was obtained lawfully and rests on a valid legal basis.

The Customer is responsible for complying with the commercial electronic message, direct marketing and anti-spam rules of its target market (Turkish Law No. 6563 and the IYS regime, GDPR, PECR, CAN-SPAM, CASL, UWG and equivalents).

The Customer may not upload to, or process through, the platform any purchased, rented or leaked lists, consumer personal data, or special categories of personal data.

The Customer must action opt-out and data subject requests it receives without delay.

5Technical and organisational measures

Encryption in transit and at rest; encrypted storage of access credentials and third-party service keys.

Per-account isolation through row-level security at the database layer: no Customer can reach another Customer's records under any circumstances.

Server-side masking: information restricted by plan limits is never sent to the browser, is masked on the server and cannot be revealed with developer tools.

Authorisation controls, audit logging of administrative actions and regular backups.

The Processor may update these measures in line with technical progress, but never below the level of protection in place on the effective date of this DPA.

6Subprocessors

The Customer gives general authorisation for the Processor to engage subprocessors in order to provide the platform.

The current subprocessor list is published at ihracatabasla.com.tr/alt-isleyiciler.

The Processor gives the Customer at least thirty (30) days' notice before adding or replacing a subprocessor. If the Customer objects on reasonable grounds, the parties will seek a workable solution; failing that, the Customer may stop using the affected service.

Each subprocessor is bound by obligations no less protective than those in this DPA, and the Processor remains liable to the Customer for its subprocessors' acts as for its own.

7Data subject requests, breach notification and audit

The Processor provides reasonable technical assistance so the Customer can meet access, rectification, erasure and objection requests. If a request reaches the Processor directly, it does not answer but forwards it to the Customer without delay.

The Processor notifies the Customer of any personal data breach it becomes aware of without undue delay and in any event within seventy-two (72) hours, including the nature of the breach, the categories of data affected, likely consequences and measures taken.

The Customer may audit compliance with this DPA once a year on reasonable notice. Audits are conducted without disrupting the Processor's operation and without access to other customers' data.

Every search and record opened is logged per user; on request the Customer can see the usage records belonging to its own account.

8International transfers

Some components of the platform (AI models, voice infrastructure) are provided by suppliers established outside Türkiye. Transfers arising from this are shown explicitly, with their regions, in the subprocessor list.

Transfers are made in accordance with the KVKK provisions on international transfer and, where GDPR applies, standard contractual clauses.

In deployments where the software runs on the Customer's own server, commercial data never reaches the Processor's infrastructure at all.

9Termination, return and deletion

On termination of the subscription the Customer may request an export of its data in a machine-readable format.

Following that export — or, if no request is made, within ninety (90) days of termination — the data is deleted or anonymised, subject to statutory retention obligations.

Data remaining in backups is destroyed in the ordinary backup cycle and is kept inaccessible until then.

10Specific provisions on buyer discovery

The platform's buyer discovery module covers only corporate, publicly available, commercial B2B data: role addresses on the company's own domain (info@, sales@, export@ and the like) and public corporate records.

Personal mobile numbers, personal addresses at free providers, consumer data and special categories of personal data are architecturally out of scope; that scope cannot be widened by changing a setting.

Search results are written to the Customer's own account. The Processor does not stockpile these records as a bulk data product, and does not sell, rent or transfer them to third parties.

Equally, the Customer may not sell, rent, sublicense or repackage as a data product the records obtained through the platform; the records may be used only within the Customer's own commercial activity.

The right to opt out is absolute. Cold outreach sent through the platform carries a one-click opt-out link and the standard headers (List-Unsubscribe, RFC 8058); an address that opts out is permanently suppressed across the entire platform. The Customer cannot disable this mechanism or delete the suppression list.

No warranty is given as to data accuracy; the verification state of every record is shown to the Customer as it stands.

11Liability, effect and governing law

The Processor's liability under this DPA is subject to the limitations of liability in the subscription agreement.

This DPA takes effect when the Customer accepts the subscription agreement electronically, without a separate signature. Enterprise customers requiring an executable counterpart may request one at the address below.

This DPA is governed by the laws of the Republic of Türkiye; the courts and enforcement offices of Istanbul have jurisdiction. In case of divergence between language versions, the Turkish text prevails.

Write to us for an executable counterpart or for additional information for your compliance team.

info@ihracatabasla.com.tr
WhatsApp'tan yaz