Legal · B2B
Data Processing Addendum
Last updated: · v2026.05.17
1. Application & order of precedence
This Data Processing Addendum (the “DPA”) supplements and forms part of the Terms of Service between [Şirket — kuruluş aşamasında] (“Processor”) and the customer identified in the Account (“Controller” or “Customer”). It applies whenever Processor processes Personal Data (as defined below) on behalf of Customer in connection with the Service. In case of conflict with the Terms, this DPA controls with respect to data protection.
This DPA is automatically deemed accepted by Customer upon entering into the Terms — no further countersignature is required for the DPA to be effective. Customers requiring a countersigned copy may email legal@poigeo.app and we will return a signed PDF.
2. Definitions
- Data Protection Law — the GDPR (Regulation (EU) 2016/679), the UK GDPR, the Swiss FADP, the Turkish KVKK, the Brazilian LGPD, the Japanese APPI, the Canadian PIPEDA, the Australian Privacy Act 1988, and the U.S. state privacy laws (CCPA/CPRA and analogous statutes), each as amended and replaced.
- Personal Data, Controller, Processor,Sub-processor, Data Subject, Processing — as defined in the GDPR (or analogous concepts under other Data Protection Law).
- SCCs — the Standard Contractual Clauses approved by the European Commission in Implementing Decision 2021/914 of 4 June 2021, as amended by the UK International Data Transfer Addendum and the Swiss supplement where applicable.
- Security Incident — a confirmed personal data breach as defined in GDPR Art. 4(12).
3. Roles
With respect to Personal Data Customer submits to the Service, Customer is the Controller and Processor acts as Processor. With respect to data Processor processes for its own purposes (operating its business, billing, security, product analytics), Processor is the Controller — that processing is described in the Privacy Policy.
4. Scope, nature, purpose & duration of processing
The subject matter, nature, purpose, duration, categories of data, and categories of data subjects are set out in Annex I.
5. Customer instructions
Processor will process Personal Data only on documented instructions from Customer, including with regard to transfers, unless required to do so by EU, Member-State, or other applicable law to which Processor is subject; in that case, Processor will inform Customer of that legal requirement before processing, unless the law prohibits such information. Customer's acceptance of the Terms, configuration of the Service, and submission of inputs constitute its documented instructions.
Processor will inform Customer if, in its opinion, an instruction infringes Data Protection Law.
6. Confidentiality of personnel
Processor will ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is granted on a need-to-know basis and revoked when no longer required.
7. Security measures (Annex II)
Processor will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including those listed in Annex II. Customer accepts that those measures are adequate for the Service.
8. Sub-processors
Customer grants Processor a general authorisation to engage sub-processors. The current list is maintained at /legal/sub-processors and is incorporated by reference as Annex III.
Processor will give Customer at least thirty (30) days' prior written notice of any intended change to the sub-processor list (by email or in-app notice) and Customer may object on documented data-protection grounds within fifteen (15) days. If the parties cannot agree on a solution, Customer may terminate the affected portion of the Service and receive a pro-rata refund.
Processor will impose on each sub-processor data-protection obligations no less protective than those in this DPA and remains liable to Customer for the performance of its sub-processors.
9. Data subject rights assistance
Processor will, taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to Data Subject requests under Chapter III of the GDPR (and analogous provisions of other Data Protection Law). The Service provides self-serve export and deletion features; for requests Processor cannot fulfil through those features, Customer may email privacy@poigeo.app.
10. Personal data breaches
Processor will notify Customer without undue delay and in any event within 48 hours after becoming aware of a Security Incident affecting Customer's Personal Data, providing the information required by GDPR Art. 33(3) to the extent then known. Processor will assist Customer in meeting its own notification obligations.
11. Data protection impact assessments
Processor will provide reasonable assistance to Customer in conducting data protection impact assessments and prior consultations with supervisory authorities to the extent required by Data Protection Law, taking into account the nature of the processing and the information available to Processor.
12. International transfers & SCCs
To the extent that Processor processes Personal Data originating in the EEA, the UK, Switzerland, or other jurisdictions requiring transfer safeguards, the SCCs apply to such processing and are incorporated by reference, with the following selections:
- Module Two (Controller-to-Processor) applies between Customer (data exporter) and Processor (data importer).
- Clause 7 (docking clause): does not apply.
- Clause 9(a)(sub-processors): Option 2 (general written authorisation, 30 days' notice) applies.
- Clause 11(a) (independent dispute resolution): not selected.
- Clause 17 (Governing law): the law of Ireland.
- Clause 18 (Choice of forum): the courts of Ireland.
- Annex I.A (parties): as identified in the Account / Terms.
- Annex I.B (description of transfer): as set out in Annex I of this DPA.
- Annex I.C (competent supervisory authority): the supervisory authority of the Member State in which the data exporter is established (or the Irish DPC if data exporter is not established in the EU).
- Annex II (TOMs): as set out in Annex II.
The UK International Data Transfer Addendum to the SCCs (issued by the UK ICO) applies to transfers of UK personal data; the Swiss FDPIC supplement applies to Swiss personal data; the KVKK and LGPD standard contractual undertakings apply respectively to Turkish and Brazilian personal data, in each case integrated with the SCCs above.
13. Audit rights
To demonstrate compliance, Processor makes available to Customer (i) this DPA, (ii) the Sub-processor list, (iii) the Trust Center, and (iv) on reasonable written request, a recent independent audit report or summary (where one exists for the relevant sub-processor) and answers to a customer-security questionnaire.
Customer may, in addition, conduct an audit on at least sixty (60) days' prior written notice, no more than once per twelve (12) months (except in case of a Security Incident or where a supervisory authority requires more), at Customer's expense, during business hours, in a manner that does not disrupt the Service, subject to a mutually agreed scope and the confidentiality of other customers' data and Processor's infrastructure. Processor may satisfy its audit obligations by providing the artefacts in this Section.
14. Return or deletion of personal data
On termination or expiry of the Service, Processor will, at Customer's choice, return or delete all Personal Data, including copies, within ninety (90) days, except to the extent applicable law requires retention or such data is contained in routine backups. Backups are encrypted and overwritten on a 30-day rolling cycle; data in backups is not actively used and is deleted when overwritten.
15. CCPA / U.S. state laws addendum
Where Customer is a “business” and Processor is a “service provider” under the California Consumer Privacy Act / CPRA, Processor:
- will process Personal Data only for the “business purposes” specified in this DPA and the Terms, and not for any other purpose;
- will not (a) sell or share Personal Data, (b) retain, use, or disclose Personal Data outside the direct business relationship between Customer and Processor, (c) combine Personal Data with data from other sources except as permitted by Cal. Civil Code § 1798.140(ag)(2);
- certifies that it understands and will comply with these restrictions; and
- will provide reasonable assistance with Consumer rights requests and notify Customer if it cannot meet its obligations.
Analogous commitments apply under Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and other U.S. state privacy laws of comparable scope.
16. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of the Terms (including Section 21 — Limitation of Liability). Nothing in this DPA excludes a party's liability that cannot lawfully be excluded, including liability under GDPR Art. 82 vis-à-vis Data Subjects.
I. Annex I — Processing details
- Subject matter: Performance of the Service for Customer.
- Nature of processing: Hosting, storage, transmission, computation, access logging, AI-assisted analysis, backup, deletion.
- Purpose: Provision of Poi Geo location intelligence to Customer.
- Duration: The term of the Service plus the retention periods stated in the Privacy Policy and this DPA.
- Categories of Personal Data: Authentication identifiers (email, hashed password), usage and activity data, hashed IP, hashed browser fingerprint, billing identity, Customer-uploaded content.
- Special categories: Not intended; Customer must not submit special category data to the Service.
- Categories of Data Subjects:Customer's authorised users; any persons identifiable in content Customer chooses to submit.
- Frequency: Continuous, on demand.
- Recipients:Processor's authorised personnel and the sub-processors listed in Annex III.
II. Annex II — Technical & organisational measures
- Encryption. TLS 1.2+ in transit; AES-256 at rest in our primary database and object storage.
- Access control. Single sign-on with mandatory MFA for staff; principle-of-least-privilege; quarterly access review; immediate revocation on role change.
- Network. Private VPC; WAF and edge bot management; rate limiting; DDoS protection via the CDN.
- Application security. Dependency scanning; OWASP top-10 review of user-input handling; code review; static analysis; secrets in a managed vault.
- Logging & monitoring. Centralised, immutable logs of access and change events for 12 months; alerting on anomalies.
- Backups. Encrypted, regional point-in-time backups; 30-day rolling retention; tested restore procedure.
- Incident response. Documented runbook; 24/7 on-call; 48-hour customer notification commitment for Security Incidents.
- People. Background checks proportionate to local law; mandatory confidentiality and security training on hire and annually.
- Sub-processors. Written DPAs; security review prior to onboarding; re-assessed at least annually.
- Pseudonymisation. IP addresses and device fingerprints are stored as salted SHA-256 hashes; analysis cache is keyed by H3 cell, not by user.
III. Annex III — Sub-processors
The current list of authorised sub-processors is maintained at /legal/sub-processors and forms part of this Annex III. Changes are notified in accordance with Section 8.
Not legal advice. This DPA is offered as part of our standard terms. It is not legal advice; consult your DPO or counsel before relying on it for your own compliance position.