Data Processing Addendum
Integral part of the Skalon Subscription and Terms of Service · Version 1.0
This Data Processing Addendum (the "Addendum") sets out the terms governing the processing of personal data under the Skalon Subscription and Terms of Service between Rapture Danışmanlık ve Teknoloji Anonim Şirketi ("Rapture") and the Customer. In the event of conflict, this Addendum prevails on matters relating to the protection of personal data.
1. ROLES OF THE PARTIES
1.1. The Customer is the data controller in respect of personal data transferred to the Service. Where the Customer is an Agency, the Brand it represents is the controller and the Agency acts on behalf of the Brand and warrants that it is authorised to issue instructions under this Addendum on the Brand behalf.
1.2. Rapture acts as data processor in respect of Customer Data and processes personal data only on documented instructions from the Customer.
1.3. Rapture is the data controller for account holder details, billing information and contact data collected in the course of its own commercial relationship.
2. SUBJECT MATTER AND SCOPE OF PROCESSING
| Item | Detail |
| Purpose | Auditing of Connected Accounts, performance analysis, dashboard generation and production of optimization recommendations |
| Duration | The subscription period plus a 90 day retention period following termination |
| Data categories | Performance data from advertising and analytics accounts, campaign and audience definitions, conversion events, online identifiers, user account and contact details |
| Data subjects | Website and application users of the Customer and the Brands it represents, and Customer personnel |
| Special categories | The Service is not designed to process special categories of personal data. The Customer undertakes not to transfer such data to the Service |
3. OBLIGATIONS OF RAPTURE
3.1. Rapture processes personal data solely for the performance of the Agreement and on the instructions of the Customer, and not for its own purposes.
3.2. Rapture ensures that personnel with access to the data are bound by confidentiality obligations.
3.3. Rapture provisions a separate and dedicated Customer Database for each Customer and does not co-mingle data belonging to different customers.
3.4. Rapture personnel have no routine access to the Customer Database. Access is granted only upon a support ticket raised by the Customer, limited to what is necessary, restricted to authorised personnel and fully logged.
3.5. Personal data is never used to train artificial intelligence models, sold or shared for advertising purposes.
3.6. Rapture provides reasonable technical assistance to the Customer in responding to data subject requests.
4. TECHNICAL AND ORGANISATIONAL MEASURES
4.1. Rapture implements at minimum the following measures:
- Encryption in transit and at rest
- Role based access control and the principle of least privilege
- Access and activity logging
- Logical and physical segregation of data per customer
- Regular and encrypted backups
- Confidentiality undertakings for personnel and role bound access rights
5. SUB-PROCESSORS
5.1. The Customer grants general authorisation for Rapture to engage sub-processors for the provision of the Service.
5.2. The current list of sub-processors is provided upon request. The Customer is notified at least 30 days before a new sub-processor is engaged and may object on reasonable grounds. If the objection cannot be resolved, the Customer may terminate the subscription and receive a refund for the unused period.
5.3. Rapture enters into written agreements with sub-processors imposing obligations at least equivalent to those in this Addendum and remains liable for their acts as for its own.
5.4. No large language model or comparable third party artificial intelligence service is used on Customer Data in the provision of the Service. Any change to this position is subject to prior notice under Article 5.2.
6. DATA LOCATION AND INTERNATIONAL TRANSFERS
6.1. The Customer Database is located within the Republic of Türkiye and data is not transferred outside Türkiye as a matter of course.
6.2. For Customers established in the European Economic Area or the United Kingdom, Türkiye is a third country without an adequacy decision. For such Customers, transfers are made on the basis of the Standard Contractual Clauses adopted by European Commission Decision 2021/914 (Module Two, controller to processor), which are deemed an integral part of this Addendum.
6.3. For Customers established in Türkiye, the provisions of Article 9 of Law No. 6698 are reserved.
6.4. Where Rapture receives a request for access to personal data from a public authority, it notifies the Customer without delay unless legally prohibited from doing so.
7. PERSONAL DATA BREACH
7.1. Rapture notifies the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach.
7.2. The notification describes the nature of the breach, the categories of data affected, the likely consequences and the measures taken.
7.3. Notification to supervisory authorities and data subjects remains the responsibility of the Customer. Rapture provides the necessary information and documentation.
8. AUDIT
8.1. The Customer may audit compliance with this Addendum no more than once per year, upon at least 30 days prior written notice.
8.2. Audits are conducted during business hours in a manner that does not disrupt the operations of Rapture. Audit costs are borne by the Customer. Audits following a data breach are not subject to this limitation.
9. RETURN AND DELETION OF DATA
9.1. Upon termination the Customer may export a copy of its data. Where the account is locked for non payment, all operations including export are suspended and access is restored once the outstanding balance is settled.
9.2. At the end of the 90 day period following termination, the Customer Data and the Customer Database are permanently destroyed. A record of destruction is provided upon request.
9.3. Data that must be retained under applicable law is kept with restricted access for the duration of the statutory retention period.
9.4. Data subject erasure requests are fulfilled within statutory time limits irrespective of payment status.