This Data Processing Addendum (this DPA) forms part of the Terms of Service (the Agreement) between you (the Customer) and Raşit Apalak (the "Company"), with its principal address at Kızılırmak Mah. Dumlupınar Bulvarı No: 3 C1-160, Çankaya, Ankara 06530, Türkiye, operating the "NomaCMS" product and related services (Provider, we, us, or our). It applies when Provider processes Customer Personal Data on Customer's behalf in connection with the hosted Platform.
This DPA does not apply to Provider's processing as an independent controller (for example, account registration, billing metadata, Site analytics after consent, or Provider's own marketing), which is described in our Privacy Policy.
If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls.
1. Definitions
- Applicable Data Protection Law means GDPR, UK GDPR, KVKK (Turkish Law No. 6698), and other data-protection laws that apply to the processing of Customer Personal Data under this DPA.
- Customer Personal Data means personal data contained in Customer Content or otherwise processed by Provider solely on Customer's documented instructions in providing the Platform (including end-user account data Customer configures through project auth features).
- GDPR means Regulation (EU) 2016/679; UK GDPR means the UK retained GDPR as amended; KVKK means Law No. 6698 on the Protection of Personal Data.
- Subprocessor means a third party engaged by Provider to process Customer Personal Data on Provider's behalf in providing the Platform.
- Terms such as controller, processor, personal data, processing, and data subject have the meanings in Applicable Data Protection Law (including, under KVKK, veri sorumlusu and veri işleyen where those concepts apply).
2. Roles
For Customer Personal Data, Customer is the controller (or veri sorumlusu) and Provider is the processor (or veri işleyen), except where Customer acts as a processor for a third-party controller—in which case Provider is a subprocessor and Customer warrants it is authorized to engage Provider.
Each party will comply with its obligations under Applicable Data Protection Law. Customer is responsible for the lawfulness of instructions and for providing any notices and obtaining any consents required for Provider to process Customer Personal Data as described.
3. Scope of processing (Article 28 details)
The details required by GDPR Article 28(3) are set out below and in Annex A.
- Subject matter: hosting and processing Customer Content and related Platform operations Customer enables.
- Duration: for the term of the Agreement and any post-termination retention needed to delete or return data as described in Section 10.
- Nature and purpose: storage, retrieval, transmission, structuring, authentication, webhooks, optional AI-assisted features Customer uses, logging for security and reliability, and support when Customer shares relevant data with us.
- Types of personal data: as determined by Customer (may include identifiers, contact details, account credentials metadata, content Customer stores, and similar categories Customer chooses to process).
- Categories of data subjects: Customer's end users, employees, contractors, customers, or other individuals whose data Customer submits to the Platform.
4. Provider obligations
Provider will:
- Process Customer Personal Data only on Customer's documented instructions (including via the Platform configuration, APIs, and written instructions), unless Applicable Data Protection Law requires otherwise—in which case Provider will inform Customer before processing unless the law prohibits notice.
- Ensure persons authorized to process Customer Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, costs, and the nature of the data (see Annex B for a high-level description).
- Not engage Subprocessors except as authorized under Section 5, and impose data-protection obligations on Subprocessors that are no less protective than those in this DPA regarding the relevant processing.
- Taking into account the nature of processing, assist Customer by appropriate technical and organizational measures, insofar as possible, with Customer's obligations to respond to data-subject requests under Applicable Data Protection Law.
- Assist Customer in ensuring compliance with security, breach notification, data-protection impact assessment, and prior-consultation obligations, taking into account the nature of processing and information available to Provider.
- At Customer's choice, delete or return Customer Personal Data after the end of Platform services relating to processing, and delete existing copies unless Applicable Data Protection Law requires storage (Section 10).
- Make available to Customer information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits as described in Section 9.
- Immediately inform Customer if, in Provider's opinion, an instruction infringes Applicable Data Protection Law (without obligation to provide legal advice).
5. Subprocessors
Customer provides a general written authorization for Provider to engage Subprocessors to deliver the Platform. Current categories and illustrative Subprocessors are listed in Annex C. Provider will impose appropriate written terms on Subprocessors and remains responsible to Customer for Subprocessor performance of delegated obligations under this DPA.
Provider will give Customer prior notice of intended additions or replacements of Subprocessors that process Customer Personal Data (for example by updating Annex C / publishing an updated list and notifying the account email, or by other reasonable means). Customer may object on reasonable data-protection grounds within fifteen (15) days of notice. If Customer objects and the parties cannot resolve the objection, Customer may terminate the affected subscription as its sole remedy for that objection.
6. International transfers
Customer acknowledges that Provider and Subprocessors may process Customer Personal Data in Türkiye, the United States, and other countries where Provider or Subprocessors operate.
Where Provider is established in Türkiye, transfers of personal data abroad are also subject to KVKK Article 9 and related regulations. EU/UK Standard Contractual Clauses are not by themselves a substitute for Board-published Turkish standard contracts or other KVKK Art. 9 tools. Provider will use appropriate transfer mechanisms required under Applicable Data Protection Law for its role (including, where required, Turkish standard contracts with foreign importers and GDPR transfer tools for EEA/UK restricted transfers). See also our Privacy Policy, Section 6.
Where Customer Personal Data originates in the EEA, UK, or Switzerland and a restricted transfer occurs, the parties will rely on valid GDPR/UK transfer tools (such as EU Standard Contractual Clauses) as applicable between the relevant exporter and importer, in addition to this DPA.
7. Security incidents
Provider will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to Provider to help Customer meet its notification obligations. Provider's notification of or response to a breach is not an admission of fault or liability.
8. Customer instructions and restricted data
The Agreement, this DPA, Customer's use and configuration of the Platform, and Customer's documented requests constitute Customer's complete instructions to Provider. Additional instructions require prior written agreement and may require fees.
Customer will not instruct Provider to process special categories of data (or KVKK özel nitelikli kişisel veri) or data relating to children unless the Platform is expressly designed for that use, Customer has a lawful basis, and the parties have agreed in writing. Customer is responsible for filtering or minimizing personal data in prompts when using AI features.
9. Audits
Upon written request no more than once per twelve (12) months (unless required by a supervisory authority or following a confirmed breach of Customer Personal Data), Provider will provide written responses to reasonable security/privacy questionnaires and, where available, summary information about relevant certifications or third-party assessments. On-site audits are available if questionnaires are insufficient, on thirty (30) days' notice, during business hours, subject to confidentiality, and at Customer's expense unless the audit reveals a material breach of this DPA by Provider.
10. Return and deletion
During the subscription, Customer may export or delete Customer Content using Platform features where available. After termination or expiry, Provider will delete Customer Personal Data from active systems within a commercially reasonable period (typically within ninety (90) days), except for backups retained for a limited period under Provider's backup cycle or data Provider must retain by law. Upon written request made before deletion is complete, Provider will make Customer Content available for export in a reasonable format where technically feasible.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except to the extent Applicable Data Protection Law prohibits limiting liability for a particular claim.
12. Term
This DPA takes effect when Customer accepts the Agreement (or otherwise begins using the Platform in a way that involves Customer Personal Data) and continues until Provider ceases processing Customer Personal Data.
13. Contact
Privacy and DPA notices: [email protected]. Legal: [email protected].
Annex A — Processing details
- Services: NomaCMS hosted Platform (content modeling, APIs, assets, webhooks, optional project user auth, optional AI features).
- Processing operations: collect, store, organize, retrieve, transmit, erase, restrict access, and related operations Customer initiates.
- Frequency: continuous for active accounts; as initiated by Customer or automated Platform functions Customer enables.
Annex B — Security measures (summary)
Provider maintains measures appropriate to the Platform, which may include:
- Access controls and authentication for the dashboard and APIs;
- Encryption in transit (TLS) for Platform connections;
- Logical isolation of customer projects/data where architected;
- Logging and monitoring for security and abuse detection;
- Backup and recovery practices for Platform availability;
- Vendor diligence for Subprocessors processing Customer Personal Data.
Measures evolve with the product; material changes that reduce overall protection will not be made without considering Applicable Data Protection Law obligations.
Annex C — Subprocessors (illustrative)
Provider may use Subprocessors in the following categories. Names and locations may change; request an up-to-date list at [email protected].
- Cloud hosting / object storage — infrastructure and file storage for the Platform (country depends on configured region).
- Payment / merchant of record — Lemon Squeezy (billing; primarily Provider-controller billing data, may touch limited customer identifiers).
- Identity providers — Google, GitHub (when Customer or users choose social login).
- AI model providers — OpenAI, Anthropic, Google (Gemini), or successors, when Customer uses AI features (prompts/outputs may include Customer Personal Data).
- Email delivery — transactional mail providers used to send Platform-related messages.
- Analytics — only where consent/tools apply to Provider's Site or app telemetry that is not Customer Personal Data under this DPA; listed for transparency.
Engaging a Subprocessor does not replace Provider's duty to implement lawful cross-border transfer tools under KVKK Article 9 and GDPR where required.