Legal

Data Processing Agreement (DPA)

A ready-to-sign Data Processing Agreement template for enterprise customers processing personal data under GDPR Article 28 and KVKK Article 12.

Last updated: August 21, 2026

Download the DPA

Signed, PDF version is available for enterprise customers. Fill out the request form or email us — we will send the DPA within one business day.

1. Parties, roles

This Data Processing Agreement ("DPA") governs the processing of personal data by inMOLA Teknoloji Yazılım Hizmetleri A.Ş.("Processor") on behalf of the Customer ("Controller") in connection with the Services provided under the Master Services Agreement or subscription terms.

  • Controller: the Customer entity subscribing to inMOLA services
  • Processor: inMOLA Teknoloji Yazılım Hizmetleri A.Ş. (registered in Türkiye)

2. Subject-matter, duration, nature and purpose

The Processor processes personal data for the sole purpose of providing the inMOLA services (marketing intelligence, analytics, decision support) as instructed by the Controller.

  • Nature of processing: collection, storage, transmission, analysis, and deletion.
  • Purpose: service delivery, analytics, decision output generation.
  • Duration: for the term of the subscription agreement, plus any applicable retention obligations.

3. Categories of personal data and data subjects

Categories of personal data processed:

  • Identity data (name, email, phone) of end users, employees, and contacts
  • Usage and behavioral data from the Customer's marketing systems (as configured)
  • Company and marketing performance data uploaded by the Controller

Categories of data subjects: Customer employees, Customer's customers, prospects, and website visitors — as instructed by the Controller.

4. Processor obligations

The Processor undertakes to:

  • Process personal data only on documented instructions from the Controller
  • Ensure that persons authorized to process personal data have committed themselves to confidentiality
  • Take appropriate technical and organizational measures under GDPR Art. 32 / KVKK Art. 12
  • Assist the Controller in fulfilling its obligations to respond to data subject rights requests
  • Assist the Controller in ensuring compliance with security, breach notification, and DPIA obligations
  • Return or delete personal data at the end of the service term, at Controller's choice
  • Make available to the Controller all information necessary to demonstrate compliance
  • Not use customer data for training any AI or machine learning models (see Section 8)

5. Sub-processors

The Controller provides a general authorization for the Processor to engage sub-processors listed below:

  • iyzico — payment processing (PCI-DSS Level 1, Türkiye)
  • Brevo — transactional and marketing email (EU)
  • Google (Analytics 4) — anonymized usage analytics (consent-gated)
  • OpenAI, Anthropic, Google Gemini, Perplexity — AI processing for specific intelligence modules (see Section 8)
  • Cloud infrastructure providers as documented in Security Overview

The Processor will notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.

6. International transfers

Where personal data is transferred outside of the European Union or Türkiye, such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, additional safeguards as required under KVKK Art. 9.

7. Security measures

Technical and organizational security measures include:

  • Encryption in transit (TLS 1.2+) and at rest for sensitive fields
  • Role-based access control (RBAC) with least-privilege principles
  • Multi-factor authentication (2FA) for administrative access
  • Continuous security monitoring and incident detection
  • Regular backups and documented disaster recovery plan
  • Personnel confidentiality agreements and security awareness training

Full details are provided in the Security Overview document.

8. AI processing — no training on customer data

Customer data transmitted to third-party AI service providers (OpenAI, Anthropic, Google Gemini, Perplexity) is not used to train models under those providers' standard API terms. inMOLA does not use customer data to train any AI models, does not share customer data with third parties for training, and does not retain customer data for fine-tuning purposes.

9. Data breach notification

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach, providing sufficient information to enable the Controller to meet any obligation to report to supervisory authorities within 72 hours of awareness.

10. Audit rights

The Controller may audit compliance with this DPA once per year, with 30 days' prior written notice, at the Controller's expense, during normal business hours, and subject to reasonable confidentiality obligations. In lieu of an on-site audit, the Processor may provide relevant certifications or third-party audit reports.

11. Termination

Upon termination of the service, the Processor will, at the Controller's choice, delete or return all personal data, unless retention is required by applicable law (e.g., Turkish Tax Procedure Law).

12. Contact & signing

To request a signed copy of the DPA or ask questions: