PhiShark Logo
← Legal & Trust Center

Data Processing Addendum (DPA)

This Data Processing Addendum (“DPA”) forms part of the contract for the Services (“Main Agreement”) between the Customer and PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ (“PhiShark”), to the extent that PhiShark processes personal data on behalf of a customer (“Customer”).

If this DPA is included in the contract via the Main Agreement, order form or electronic acceptance, a separate physical signature is not required; Mandatory form requirements of applicable law are reserved.

1. Roles of the parties

To the extent that the customer determines the purposes and means of processing personal data, the data controller/controller; PhiShark acts as a data processor to the extent that it processes personal data on behalf of the Customer.

In cases where the Customer processes data on behalf of another data controller, PhiShark may act as a sub-processor in respect of the relevant processing activity.

Each party is responsible for its obligations arising from the data protection legislation applicable to it.

2. Scope of processing and instructions

PhiShark will process Customer Personal Data only:

  • To provide the services and ensure their security;
  • To fulfill the Articles of Association; and
  • Implementing the customer's documented lawful instructions

works for the purpose.

PhiShark does not process Customer Personal Data other than on Customer's instructions, unless applicable law requires otherwise. In case of such a legal obligation, the Customer will be informed in advance, unless prohibited by law.

PhiShark will notify the Customer if it considers that a Customer instruction violates applicable data protection legislation.

Processing details

Subject of processing: PhiShark provision of cybersecurity and phishing analysis Services.

Duration: The effective period of the Master Agreement and the additional period required for deletion or return of data in accordance with this DPA.

Nature and purpose of processing: Reception, transmission, hosting, analysis of data, creation of security outputs, support, security and related technical operations.

Categories of relevant persons: Users, employees, customers, business partners, persons sending or receiving emails, and others included in content transmitted to the Services by Customer.

Personal data categories: Account and contact information; technical and safety data; IP, log and device information; email metadata and content to the extent necessary; URL, domain name, link, PDF, QR, file and other information provided by the Customer for analysis.

The Services are not designed to process sensitive personal data. If such data needs to be processed, the Customer is responsible for providing the necessary legal basis and additional protection measures.

3. Privacy and security

PhiShark:

  • Limits access to Customer Personal Data to only those individuals who need access in the course of their duties;
  • ensures that such persons are subject to appropriate confidentiality obligations; and
  • Applies technical and administrative security measures appropriate to the processing risk.

These measures include, to the extent applicable, access and authorization controls, authentication, data transmission and storage security, logging and monitoring, vulnerability management, backup and recovery, incident response and personnel security measures.

PhiShark maintains measures in accordance with its obligations under Article 12 of the KVKK No. 6698 and, to the extent applicable, GDPR/UK GDPR Article 32.

4. Subprocessors

Customer generally consents to PhiShark's use of subprocessors specified in the List of Subprocessors and Service Providers.

PhiShark:

  • imposes on sub-processors data protection obligations substantially equivalent to this DPA;
  • remains liable in accordance with applicable law and the Main Agreement for the sub-processor's failure to fulfill its obligations; and
  • In case a new subprocessor is added or the existing subprocessor is changed, it notifies the Customer in advance.

The customer may object to the new sub-processor on reasonable and documented data protection grounds within the period specified in the notification. The parties work in good faith to resolve the objection.

5. International data transfers

PhiShark transfers Customer Personal Data abroad only as permitted by applicable data protection legislation.

Where necessary, the parties;

  • For the European Union, the relevant Standard Contractual Clauses (EU SCCs);
  • UK Addendum or other applicable transfer mechanism applicable to the United Kingdom;
  • For Türkiye, the required standard contract or other appropriate assurance within the scope of Article 9 of the KVKK.

uses.

In the event of a conflict between a mandatory data transfer agreement and this DPA, the mandatory transfer agreement takes precedence with respect to the relevant transfer.

6. Relevant person requests and regulatory compliance support

PhiShark, taking into account the nature of the processing and the information at its disposal, reasonably provides the Customer with:

  • meeting data subject claims;
  • data security obligations;
  • assessing and reporting personal data breaches;
  • data protection impact assessments; and
  • Processes carried out with competent data protection authorities when necessary

provides support in terms of

If PhiShark receives a contact person request regarding the data it processes directly on behalf of the Customer, it forwards the request to the Customer unless it is legally required to respond directly.

7. Personal data breaches

If PhiShark becomes aware of a personal data breach affecting Customer Personal Data, it will notify the Customer without undue delay.

Notice, to the extent available:

  • the nature of the violation;
  • affected categories of data and data subjects;
  • possible consequences; and
  • measures taken or planned

Contains.

PhiShark provides reasonable cooperation to enable Customer to comply with applicable notification obligations.

8. Return and deletion of data

Upon termination of the Main Agreement or upon the Customer's lawful request, PhiShark will delete Customer Personal Data at the Customer's option or return it to the extent appropriate; Data that is required to be stored by applicable law are excluded from this provision.

Data remaining in backups is deleted within the normal backup cycle and is not actively processed for other purposes during this period.

Detailed retention periods are specified in the Data Retention and Deletion Policy.

9. Audit and compliance information

PhiShark provides Customer with information reasonably necessary to demonstrate its compliance with this DPA and applicable data protection legislation.

The Customer may request, with reasonable prior notice and subject to confidentiality obligations, a reasonable audit of PhiShark's data processing activities.

Audits are carried out, to the extent possible, primarily through up-to-date independent audit reports, certificates, security documents and remote inspection.

On-site auditing is only carried out when these methods are not sufficient and other customers' data, trade secrets or system security must not be compromised.

10. Priority and validity

This DPA applies only to the extent that PhiShark processes personal data on behalf of the Customer.

In case of a conflict between this DPA and the Main Agreement regarding the processing of personal data, this DPA takes precedence.

The applicable law, liability, time and dispute resolution provisions of the Main Agreement also apply to this DPA, without prejudice to the mandatory provisions of the data protection legislation.

Contact

PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ Cevizli Mah. Zuhal Cad. Ritim Istanbul Sitesi A5 Blok No:46E İç Kapı No:179 Maltepe/İstanbul MERSIS: 0729137429700001 Data protection contact: [email protected]