Data Processing Addendum
Public DPA framework for enterprise customers; effective only when incorporated into an agreement.
- Version
- 1.0-draft
- Effective date
- Upon publication following legal approval
- Last updated
- 25 July 2026
- Change summary
- Initial consolidated draft covering the website, platform, API and client integrations.
1. Status, scope and roles
This page is a non-executed draft and does not itself create a DPA. Once signed or incorporated into an order, it applies where PhiShark processes personal data for a customer. The customer is controller (or processor for another controller) and PhiShark is processor/subprocessor as applicable.
2. Instructions and processing details
PhiShark will process customer personal data only on documented instructions, including to provide and secure the contracted service, unless law requires otherwise. Subject matter, duration, nature, purpose, data types and data-subject categories must be specified in the order or DPA schedule.
3. Confidentiality and security
Authorized personnel are bound by confidentiality. PhiShark will maintain risk-appropriate technical and organizational measures covering access control, encryption, logging, vulnerability management, continuity and incident response. The final security schedule must reflect verified production controls, not planned controls.
4. Subprocessors and transfers
PhiShark may engage listed subprocessors under written data-protection obligations and remains responsible as required by applicable law and contract. Restricted transfers will use the applicable EU SCC module, UK Addendum, KVKK standard contract or other lawful mechanism. The executed schedule controls.
5. Assistance and incidents
Taking account of the processing, PhiShark will reasonably assist with data-subject requests, security, impact assessments, regulator consultations and demonstrated compliance. PhiShark will notify the customer of a confirmed personal-data breach without undue delay and provide available material information, subject to law.
6. Return, deletion and audits
At the end of services, PhiShark will return or delete customer personal data as agreed unless law requires retention. Audit rights, frequency, confidentiality, cost allocation and independent reports must be set in the executed DPA and exercised without compromising other customers or security.
7. How to execute
Request the current execution copy from [email protected]. No SCC, UK Addendum, KVKK standard contract or DPA should be represented as executed until the correct legal entities, annexes, transfer details and signatures are complete.
Company information
PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ
Cevizli Mah. Zuhal Cad. Ritim İstanbul Sitesi A5 Blok No:46E İç Kapı No:179 Maltepe/İstanbul
Tax office / tax number: Kartal V.D. – 729 137 4297
MERSİS: 0729137429700001
Telephone information will be added as soon as possible.
Contact: [email protected] · [email protected] · [email protected]
Previous versions
No previous public version is archived for this draft.