Legal
A ready-to-sign Data Processing Agreement template for enterprise customers processing personal data under GDPR Article 28 and KVKK Article 12.
Last updated: August 21, 2026
Signed, PDF version is available for enterprise customers. Fill out the request form or email us — we will send the DPA within one business day.
This Data Processing Agreement ("DPA") governs the processing of personal data by inMOLA Teknoloji Yazılım Hizmetleri A.Ş.("Processor") on behalf of the Customer ("Controller") in connection with the Services provided under the Master Services Agreement or subscription terms.
The Processor processes personal data for the sole purpose of providing the inMOLA services (marketing intelligence, analytics, decision support) as instructed by the Controller.
Categories of personal data processed:
Categories of data subjects: Customer employees, Customer's customers, prospects, and website visitors — as instructed by the Controller.
The Processor undertakes to:
The Controller provides a general authorization for the Processor to engage sub-processors listed below:
The Processor will notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.
Where personal data is transferred outside of the European Union or Türkiye, such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, additional safeguards as required under KVKK Art. 9.
Technical and organizational security measures include:
Full details are provided in the Security Overview document.
Customer data transmitted to third-party AI service providers (OpenAI, Anthropic, Google Gemini, Perplexity) is not used to train models under those providers' standard API terms. inMOLA does not use customer data to train any AI models, does not share customer data with third parties for training, and does not retain customer data for fine-tuning purposes.
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach, providing sufficient information to enable the Controller to meet any obligation to report to supervisory authorities within 72 hours of awareness.
The Controller may audit compliance with this DPA once per year, with 30 days' prior written notice, at the Controller's expense, during normal business hours, and subject to reasonable confidentiality obligations. In lieu of an on-site audit, the Processor may provide relevant certifications or third-party audit reports.
Upon termination of the service, the Processor will, at the Controller's choice, delete or return all personal data, unless retention is required by applicable law (e.g., Turkish Tax Procedure Law).
To request a signed copy of the DPA or ask questions:
Also see: GDPR & KVKK · Security Overview · Trust Center