This Data Processing Agreement (“DPA”) forms an integral part of the Terms of Service between Fidkeep and the Customer and is deemed accepted together with the Terms of Service. The DPA applies to personal data that Fidkeep processes as data processor on behalf of the Customer when providing the Service. This English version is provided for convenience; the Turkish version (Veri İşleme Sözleşmesi) prevails in case of conflict.
1. Parties and scope
This DPA is entered into between FİDKEEP TEKNOLOJİ TİCARET LİMİTED ŞİRKETİ (MERSIS No: 0387146003100001; address: Sarıgüllük Mah. Ali Nadi Ünler Bul. Milenyum Apt. No: 3A, Şehitkamil / Gaziantep, Türkiye; KEP: [email protected]) (“Fidkeep”) as data processor and the business that uses the Service by accepting the Terms of Service (the “Customer”) as data controller.
The DPA applies only to Customer Personal Data. Data that Fidkeep processes as data controller for its own purposes (identity and contact details of account users, authentication and security records, billing and payment details, support correspondence, website and marketing data) is outside the scope of this DPA; that data is governed by the Privacy Policy and the KVKK Privacy Notice.
Where the Customer acts as data processor on behalf of its own clients, for example as an agency, the Customer undertakes that it accepts this DPA with the authority of the relevant data controllers and that the instructions it gives Fidkeep are consistent with the instructions of those data controllers. In that case Fidkeep acts as sub-processor and deals only with the Customer.
Where the Customer's processing is subject to the EU General Data Protection Regulation (“GDPR”), this DPA also constitutes the contract required by GDPR Article 28(3). In that case the KVKK concepts in this DPA apply together with their GDPR equivalents.
2. Definitions
Capitalised terms not defined below have the meaning given in the Terms of Service; the terms “personal data”, “data controller”, “data processor”, “data subject” and “processing” have the meaning given in the Turkish Personal Data Protection Law No. 6698 (“KVKK”).
- Customer Personal Data: Personal data that Fidkeep processes on behalf of the Customer as part of the Service, in particular review and reply data synchronised from the Google Business Profile accounts the Customer connects and data the Customer enters into its workspace about third parties.
- Service: The Fidkeep web application and related services provided under the Terms of Service.
- Subprocessor: A third-party service provider engaged by Fidkeep to process Customer Personal Data.
- Personal Data Breach: Unlawful acquisition of Customer Personal Data by others, or accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, the data as a result of a breach of security.
- Board and Authority: The Personal Data Protection Board and the Personal Data Protection Authority.
- Instructions: The documented instructions defined in Section 5.
3. Subject matter, duration, nature and purpose of processing
- Subject matter: Provision of the Service to the Customer.
- Duration: The term of the Terms of Service plus the return and deletion periods in Section 14.
- Nature: Automated processing operations such as obtaining Google Business Profile data through the Google API, recording, storing, organising and displaying it, using it to prepare AI reply drafts and reports and to tag reviews by topic and sentiment, sending the information of new reviews that match smart rules defined by the Customer by e-mail to recipients the Customer selects from its own team members, transferring it to Google as replies on the Customer's Instructions, and deleting it.
- Purpose: Solely to provide the Service in accordance with the Terms of Service and the Customer's Instructions.
Details of the categories of data subjects, categories of data and processing operations are set out in Annex 1.
4. Obligations of the parties
With respect to Customer Personal Data, Fidkeep:
- Processes the data only on the Customer's Instructions and for the purpose of providing the Service; does not use it for its own purposes, does not sell it and does not use or transfer it for advertising.
- Does not use customer content to train its own models or any AI model; sends AI providers only the data needed for the relevant task and works with providers under terms under which API data is not used for model training.
- Uses data obtained from Google APIs in compliance with the Google API Services User Data Policy, including the Limited Use requirements.
- Under KVKK Article 12(4), does not disclose personal data it learns to others in breach of the KVKK or use it for purposes other than the processing; this obligation continues after the DPA ends.
- Takes the technical and organisational measures required by KVKK Article 12(1) and, to the extent applicable, GDPR Article 32 (Section 7 and Annex 2).
- At the Customer's request and to the extent of the information available to it, reasonably assists the Customer in meeting its obligations regarding data security, breach notification, data protection impact assessments and prior consultation with the supervisory authority (GDPR Articles 32 to 36).
- Keeps the records required by law regarding the processing activities it carries out on behalf of the Customer.
The Customer's obligations are set out in Section 13.
5. Instructions
The Customer's documented Instructions are:
- The Terms of Service, this DPA and the relevant order.
- The configurations made and actions taken in the Service by the Customer's authorised users; for example connecting Google accounts and locations, brand voice settings, generating reply drafts, publishing replies, enabling automatic replies and setting their conditions, creating smart rules and setting their conditions and recipients, designating report recipients and disconnecting locations.
- Written instructions sent by the Customer to [email protected] or by KEP that are consistent with the Terms of Service.
Instructions outside the scope of the Service require the written agreement of the parties. If Fidkeep considers that an Instruction infringes the KVKK, the GDPR or other data protection law, it informs the Customer immediately and may suspend performance of that Instruction until the infringement is resolved.
Where the law to which Fidkeep is subject requires processing of Customer Personal Data other than on the Instructions, Fidkeep informs the Customer of that legal requirement before processing, unless the law prohibits it.
6. Confidentiality
Fidkeep limits access to Customer Personal Data to personnel who need access to provide, support and secure the Service, and to the extent necessary. Such personnel are bound by written confidentiality obligations that continue after they leave their role. Fidkeep personnel access Customer Personal Data only at the Customer's request or with its approval, where necessary for security or support, or where required by law.
7. Data security
Fidkeep implements the technical and organisational measures listed in Annex 2 to prevent unlawful processing of and unlawful access to Customer Personal Data and to ensure its safekeeping. Fidkeep may update these measures in line with technological developments, provided that the update does not reduce the overall level of protection.
The Customer is responsible for security on its own side: this includes protecting user accounts and credentials, granting roles and location access only to people who need them, removing access for users who are no longer authorised and reporting suspicious access to Fidkeep.
8. Subprocessors
By this DPA the Customer gives Fidkeep general written authorisation to engage Subprocessors to provide the Service. The current list of Subprocessors is published on the Subprocessors page and summarised in Annex 3.
At least 30 days before adding a new Subprocessor or replacing an existing one, Fidkeep notifies the Customer at the e-mail address registered on the account or in the application and updates the Subprocessors page.
The Customer may object in writing within the notice period on reasonable data protection grounds. The parties discuss the objection in good faith; where possible, Fidkeep offers an alternative that ensures the change does not affect the data concerned by the objection. If the objection cannot be resolved by the date the change takes effect, the Customer may terminate the affected service by written notice; in that case the Customer receives a pro-rata refund of the fees prepaid for that service for the unused period.
Fidkeep enters into a written contract with each Subprocessor containing data protection obligations substantially equivalent to those in this DPA, and assesses Subprocessors for data security before engaging them. Fidkeep is liable to the Customer for its Subprocessors' failure to perform their obligations as it is for its own acts.
Google LLC and iyzico are also independent data controllers with respect to their own services. Replies published on Google Business Profile on the Customer's Instructions are subject to Google's own terms once published.
9. Transfers abroad
Customer Personal Data is processed abroad, in particular in Finland (EU) and the United States, through the Subprocessors listed in Annex 3. The Board has not issued an adequacy decision for these countries. By this DPA the Customer authorises these transfers and instructs Fidkeep accordingly.
For transfers abroad to its Subprocessors, Fidkeep, as the transferring party under KVKK Article 9 as amended by Law No. 7499, signs the relevant module (processor-to-processor transfer) of the standard contracts announced by the Board and notifies each standard contract to the Authority within five business days of its signature. These notifications are made by Fidkeep. Where a standard contract cannot be put in place, the exceptions in Article 9(6) are relied on for occasional transfers only.
Notification and other obligations arising from transfers to which the Customer itself is a party rest with the Customer. If the Customer is subject to the GDPR and an additional transfer mechanism is required under the GDPR for transfers to Fidkeep or to Subprocessors, the parties cooperate in good faith to enter into the relevant module of the European Commission's standard contractual clauses.
10. Assistance with data subject requests
Fidkeep forwards to the Customer without undue delay any data subject application made directly to Fidkeep concerning Customer Personal Data. Other than informing the data subject that the application has been forwarded to the relevant data controller, Fidkeep does not respond on the merits of the application without the Customer's Instruction.
Taking into account the nature of the processing, and by appropriate technical and organisational measures, Fidkeep helps the Customer respond to applications under KVKK Articles 11 and 13 and, to the extent applicable, GDPR Articles 12 to 22; for example by identifying, exporting, rectifying or deleting data relating to a particular reviewer. This assistance is provided to a reasonable extent and without additional charge; for extraordinary or disproportionate requests for assistance, the parties agree in writing in advance.
Responding to applications within the 30-day period under KVKK Article 13 is the Customer's responsibility.
11. Personal data breach notification
Fidkeep notifies the Customer at the e-mail address registered on the account without undue delay and at the latest within 48 hours after becoming aware of a Personal Data Breach. To the extent known at the time, the notice includes:
- The nature of the breach and when it occurred and was detected.
- The categories and approximate number of data subjects and records affected.
- The likely consequences of the breach.
- The measures taken or proposed.
- A contact point for further information ([email protected]).
If not all information can be provided at the same time, it is provided in phases without undue further delay. Fidkeep immediately takes the measures needed to limit the effects of the breach and cooperates with the Customer.
As data controller, the Customer is responsible for notifying the Board and the data subjects. Under KVKK Article 12(5) and Board decision No. 2019/10 of 24 January 2019, the Customer notifies the Board within 72 hours at the latest of becoming aware of the breach and the data subjects as soon as reasonably possible, and complies with GDPR Articles 33 and 34 to the extent it is subject to the GDPR. Fidkeep does not notify the Board or data subjects on the Customer's behalf unless required by law. A notification by Fidkeep does not constitute an admission of fault.
12. Audits and information requests
At the Customer's written request, Fidkeep provides within a reasonable time the information and documents necessary to demonstrate compliance with this DPA and KVKK Article 12. The Customer's audit right is exercised primarily through such documents and written questions.
Where the documents are insufficient to demonstrate compliance, the Customer, or an independent auditor appointed by the Customer who is not a competitor of Fidkeep and is bound by confidentiality, may carry out an on-site audit. An on-site audit:
- May take place at most once a year.
- Is notified in writing at least 30 days in advance, and its scope is agreed by the parties in advance.
- Is conducted during Fidkeep's business hours without unreasonably disrupting its operations.
- Does not extend to other customers' data, Fidkeep's trade secrets or Subprocessors' premises; for Subprocessors, the documents in Fidkeep's possession are relied on.
- Is subject to confidentiality.
The Customer bears the costs of the audit; however, if the audit finds that Fidkeep has materially breached this DPA, Fidkeep bears the reasonable costs of the audit. This section does not limit the statutory audit powers of the Board or other competent authorities.
13. Obligations of the data controller
As data controller, the Customer:
- Undertakes that it has a valid legal basis for the processing of Customer Personal Data (for example KVKK Article 5(2)(d) or 5(2)(f)) and that it has fulfilled its obligation to inform its own data subjects.
- Undertakes that it is authorised to access each Google Business Profile account and location it connects, to retrieve reviews and to publish replies, and that it will comply with Google's terms.
- Does not enter special categories of personal data (KVKK Article 6) into brand voice instructions, example replies, signatures, replies or other inputs. Special-category information that reviewers have published themselves may be processed incidentally as part of the review text; Fidkeep does not seek, extract or profile such data.
- If it operates in the health sector, undertakes never to confirm in replies that a reviewer is or was a patient and not to disclose any health or personal information. Public institutions additionally comply with the obligations arising from their own legislation.
- Is responsible for the content of published replies and for enabling automatic replies. AI output can be wrong; human review of replies before publication is recommended.
- Ensures that its Instructions are lawful and fulfils its own obligations as data controller, including, where applicable, the obligation to register with the Data Controllers' Registry.
14. Return and deletion at the end of the agreement
During the term, the Customer may disconnect a location or end the Google connection. Google OAuth tokens are deleted when the connection is removed, Google access is revoked or the account is closed. If the Customer requests, the synchronised review and reply data and AI drafts of a disconnected location are deleted within 90 days of disconnection.
On account closure or termination of the Terms of Service:
- The Customer may request an export of its data by writing to [email protected] within 30 days of account closure; Fidkeep provides the export in a structured, commonly used electronic format.
- Customer Personal Data is deleted or anonymised within 90 days of account closure.
- Copies in backups are deleted by being overwritten within 30 days at the latest under the rolling backup scheme.
Data that Fidkeep is required by law to retain is kept only for the period of the relevant obligation, with restricted access and without being processed for any other purpose. At the Customer's written request, Fidkeep confirms in writing that deletion has been completed.
15. Liability
The parties' liability under this DPA is subject to the limitations of liability in the Terms of Service. These limitations do not apply in cases of gross negligence or intent (Turkish Code of Obligations Article 115) or where limitation of liability is prohibited by law.
The parties acknowledge that, under KVKK Article 12(2), where personal data is processed by Fidkeep on the Customer's behalf, the Customer is jointly liable with Fidkeep for taking data security measures. This liability is reserved vis-à-vis data subjects and competent authorities; in the internal relationship between the parties, each party is liable in proportion to its fault.
16. Term and termination
This DPA enters into force on acceptance of the Terms of Service and remains in force for as long as Fidkeep processes Customer Personal Data. The DPA ends when the Terms of Service end for any reason; however, Sections 6, 11, 14 and 15 and any provisions that by their nature must apply after termination remain in force until the deletion of Customer Personal Data is complete and, as regards confidentiality obligations, indefinitely.
17. Precedence
In the event of a conflict between this DPA and the Terms of Service or other contractual documents on matters relating to the protection of personal data, this DPA prevails. On all other matters the Terms of Service apply. In the event of a conflict between the Turkish text of the DPA and its English translation, the Turkish text prevails.
18. Changes and notices
Fidkeep announces material changes to this DPA by e-mail or in-app notification at least 30 days before they take effect. If the Customer objects to a change, it may terminate the agreement before the change takes effect.
Notices to the Customer are sent to the e-mail address registered on the account. Notices to Fidkeep are sent to [email protected] or, for formal notices, to the KEP address [email protected].
19. Governing law and jurisdiction
This DPA is governed by the laws of the Republic of Türkiye. The Courts and Enforcement Offices of Gaziantep have exclusive jurisdiction over disputes arising from the DPA. Under Article 193 of the Code of Civil Procedure (HMK), Fidkeep's electronic records, system logs and e-mail records constitute binding evidence unless proven otherwise. Mandatory provisions of the GDPR applicable to the Customer and the powers of supervisory authorities are reserved.
20. Annex 1: Processing details
Categories of data subjects
- People who write Google reviews about the locations the Customer connects.
- People named in review and reply texts (for example Customer employees).
- Other third parties whose data the Customer enters into its workspace (for example report recipients and employees named in signatures and example replies).
Categories of data
- Review data: The reviewer's display name and profile photo, rating, review text, links to media attached to the review, creation and update times, review identifiers.
- Reply data: Text of business replies, publication status and time, policy status returned by Google.
- AI data: Reply drafts, report narratives, topic and sentiment labels assigned to reviews and the inputs sent to generate them (for topic and sentiment tagging, the review text and rating and the topic list for the location's industry).
- Smart-rule data: Rule conditions and the locations a rule covers, rule history (matched reviews and the team members who were e-mailed) and the matched review's information contained in smart-rule alert e-mails (location, rating, review text and reviewer's display name).
- Workspace content: Brand voice instructions, preferred or prohibited phrases, signatures, example replies and report recipients' e-mail addresses, to the extent they contain personal data.
- Special categories of data: Not processed intentionally; may be processed incidentally only as part of review text published by the reviewer.
Purposes of processing
- Synchronising reviews and showing them in a single inbox.
- Preparing AI-assisted reply drafts in the location's brand voice.
- Tagging reviews by topic and sentiment with AI; showing the labels in the review list, review detail and dashboard and using them for filtering and in the topic condition of smart rules.
- Sending alert e-mails about new reviews that match smart rules defined by the Customer to recipients the Customer selects from its own team members, and keeping rule history.
- Publishing replies on Google on the Customer's Instructions or according to the controlled automatic reply settings the Customer has enabled.
- Preparing and delivering daily and monthly location reports.
- Securing the Service, fixing errors and supporting the Customer.
Processing operations
Obtaining, recording, storing, retaining, organising, classifying, displaying, processing and tagging with AI, transferring to Subprocessors and, on the Customer's Instructions, to Google, making available to authorised workspace users, sending by e-mail to smart-rule recipients, exporting, and deleting or anonymising.
Duration and frequency
Processing takes place continuously during the term of the Terms of Service and ends with the periods in Section 14.
21. Annex 2: Technical and organisational measures
Encryption
- TLS encryption in transit.
- Encryption at rest of Google OAuth tokens.
- Passwords stored only as salted hashes.
Access control and authentication
- Role- and location-based access control.
- Least-privilege internal access.
- Session cookies marked HttpOnly and Secure.
- Secret and credential management.
Application security and monitoring
- Request validation and rate limiting.
- Audit logs with sensitive fields redacted.
- Error monitoring.
Backup and continuity
- Encrypted, regularly tested backups.
Organisational measures
- Confidentiality obligations for personnel.
- Due diligence in selecting and engaging service providers.
- Incident response procedure.
22. Annex 3: Subprocessors
Fidkeep's Subprocessors at the date of this DPA are listed below; purposes, locations and the current list are on the Subprocessors page:
- Our cloud infrastructure provider operating from a data centre in Finland — Location: Finland (EU).
- Cloudflare, Inc. — Location: global network, US-headquartered.
- Google LLC — Location: US and global.
- Our AI infrastructure providers — Location: US.
- Resend — Location: US.
- Linear — Location: US.
- Sentry (Functional Software, Inc.) — Location: US.
- İyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (iyzico) — Location: Türkiye.
Some of the providers on the list (for example iyzico for payment processing) are engaged only to process data for which Fidkeep is the data controller. The names of the AI providers are kept confidential by Fidkeep; to the extent necessary for the Customer to exercise its rights under this DPA, they are disclosed to the Customer on request and subject to confidentiality obligations.
