PLANYUM DATA PROCESSING AGREEMENT (DPA)
Parties and Definitions
Data Controller: The User (real estate/construction company) that becomes a member of the Planyum platform, uploads personal data belonging to third parties (its own customers) to the platform, and determines the purposes of processing such data.
Data Processor: Mehmet Cem Uysal (Planyum), who hosts such data on its servers (Supabase) and provides the technical infrastructure on behalf of the Data Controller and in accordance with its instructions.
Purpose of the Agreement
The purpose of this Agreement is to define the parties' obligations regarding the processing, hosting, and protection—in accordance with Law No. 6698 (KVKK) and, to the extent applicable, the GDPR—of personal data and special categories of personal data (identity, passport, title deed documents, etc.) that the Data Controller will upload to the Planyum infrastructure.
Obligations of the Data Controller (User)
3.1. The Data Controller accepts and undertakes that all personal data uploaded to Planyum have been obtained by lawful means; that the required privacy notice under KVKK has been provided to the data subjects (its customers who buy/sell or rent property); and that, where required, their explicit consent (especially for cross-border transfer) has been obtained in written or electronic form.
3.2. All legal, administrative, and criminal liability arising from data uploaded to the Planyum system having been obtained by unlawful means rests exclusively with the Data Controller (User). Planyum has no obligation to audit the source of such data.
Obligations of the Data Processor (Planyum)
4.1. Processing on Instructions: Planyum shall process data transferred to it solely in accordance with the Data Controller's instructions and for the performance of the CRM service (hosting). It may not use such data for its own marketing campaigns or sell them to third parties.
4.2. Data Security: Planyum takes all necessary technical and organizational measures to ensure an appropriate level of security (256-bit encryption, authorization matrices, secure server infrastructure) to prevent unlawful access to the data it hosts.
4.3. Breach Notification (Updated): If Planyum detects a cyberattack or data breach affecting its systems, it is obliged to notify the Data Controller (User) immediately and in any event within 72 hours.
Use of Sub-Processors
The Data Controller hereby accepts that Planyum uses global sub-processors such as Supabase (database hosting) to deliver its services without interruption, and that data are held in encrypted form on those infrastructures.
Return and Destruction of Data
Upon termination of the User Agreement between the parties, Planyum shall enable the Data Controller to export its data. At the end of a maximum of 1 (one) year from subscription cancellation (or immediately upon the Data Controller's request for immediate deletion), all hosted personal data and their backups shall be irreversibly destroyed.

