Legal
Data Processing Agreement (DPA)
.
1. Scope & roles
This DPA governs processing of Customer Personal Data by Seccops Siber Güvenlik Teknolojileri A.Ş. ("Seccops", "we", "us"), the company that operates the Mobexa platform, on Customer's behalf. Customer is the data controller; we are the data processor.
2. Subject-matter, duration, nature, purpose (GDPR Art. 28(3))
- Subject-matter. Provision of the mobile application security platform described in the Order Form.
- Duration. For the term of the subscription plus a 30-day export window.
- Nature. Collection, storage, analysis, and reporting of mobile application binaries and associated personal data contained therein (if any).
- Purpose. Identifying security vulnerabilities and producing audit-ready evidence for the Customer.
- Types of personal data. Business contact data of Customer's users; any personal data incidentally present in uploaded binaries.
- Categories of data subjects. Customer's employees, contractors, and any data subjects whose personal data appears in uploaded binaries.
3. Processor obligations
We will: (a) process personal data only on documented instructions from Customer; (b) ensure persons authorised to process the data are under obligations of confidentiality; (c) implement appropriate technical and organizational measures as set out in Schedule 1; (d) assist Customer, taking into account the nature of processing, in meeting its obligations under Articles 32-36 GDPR; (e) upon termination, delete or return all personal data unless retention is required by law; (f) make available to Customer all information necessary to demonstrate compliance, and allow for and contribute to audits.
4. Sub-processors
Customer grants us a general authorisation to engage sub-processors. We notify Customer of planned changes to the sub-processor list with at least 30 days' notice via email or a changelog page. Customer may object in writing within 15 days; if the parties cannot agree on an alternative, Customer may terminate the affected Services without penalty.
The current sub-processor list is available inside the platform and on request at .
5. International transfers
For transfers of personal data from the EEA or UK to a country outside the EEA without an adequacy decision, the parties agree the EU Commission Standard Contractual Clauses (2021/914), Module 2 (controller to processor), incorporated by reference, plus the UK International Data Transfer Addendum where applicable. Supplementary measures include encryption in transit (TLS 1.2+), encryption at rest (AES-256), and strict access-control logging.
6. Security incidents
We will notify Customer of a personal data breach without undue delay and no later than 48 hours after becoming aware. The notification will include the information required by GDPR Art. 33(3) to the extent known at the time, and will be updated as new information becomes available.
7. Data subject requests
We will assist Customer in responding to data-subject requests through appropriate technical and organizational measures, including providing tools to search, export, and delete data inside the platform.
8. Audit rights
Customer may, at its own expense and with reasonable advance notice (at least 30 days), audit our compliance with this DPA once per calendar year. Audits must be performed during business hours without disrupting the Services and must respect our confidentiality and security obligations to other customers.
9. Term & termination
This DPA applies for as long as we process personal data on Customer's behalf and survives termination of the subscription to the extent of any remaining processing.
Schedule 1 - Technical and Organisational Measures
See our Security & Trust statement for the full list of technical and organisational measures applied. That statement is incorporated by reference into this DPA.
Schedule 2 - Sub-processor list
Available on request.