Data Processing Agreement

DPA under GDPR Article 28 and KVKK

The obligations of the parties where the Customer is the data controller and CM Apps is the data processor: processing on instructions, security, sub-processors, breach notification, audits, international transfers and the return of data at the end of the agreement.

Version
Draft v0.1
Updated
13 September 2026
Applicable region
European UnionGlobalTürkiye
Legal basis
GDPR Art. 28 · KVKK · Standard Contractual Clauses
Who it is for
Corporate customers that process their own users’ data through our products or services.
Pending legal review. This text is a working draft; fields in square brackets will be filled with project and company details and reviewed by legal counsel before publication. The binding version is the signed agreement.
CM Apps · Data Processing AgreementDraft v0.1 · 13 September 2026

1. Subject matter and term

This Data Processing Agreement (“DPA”) forms an integral part of the principal agreement (Master Services Agreement, SaaS Subscription Agreement or Statement of Work) between the Customer (the “Controller”) and CM Apps (the “Processor”) and remains in effect for the term of the principal agreement.

The subject matter, nature, purpose of processing, categories of personal data and categories of data subjects are defined in Annex 1.

2. Processing on instructions

CM Apps processes personal data only on the documented instructions of the Controller and for the purpose of providing the service under the principal agreement. If CM Apps considers that an instruction infringes applicable law, it informs the Controller immediately.

Where applicable law directly requires CM Apps to process data, the Controller is informed in advance unless such notification is prohibited.

3. Confidentiality and personnel

CM Apps personnel and contractors with access to personal data are bound by confidentiality obligations and receive data protection training. Access is limited on a least-privilege basis according to the requirements of the role.

4. Security measures

In accordance with GDPR Art. 32 and KVKK Art. 12, CM Apps implements technical and organizational measures proportionate to the risk: encryption in transit and, where possible, at rest, role-based access, multi-factor authentication, logging, backup and disaster recovery, and security testing. A summary of the measures is set out in Annex 2.

5. Sub-processors

The Controller gives general authorization for the use of the sub-processors listed in the Sub-processor List. CM Apps gives notice at least [30] days before adding a new sub-processor; the Controller may object on reasonable grounds. If the objection cannot be resolved, the affected part of the service may be terminated.

CM Apps enters into written agreements with sub-processors imposing obligations equivalent to those in this DPA and remains responsible for the performance of its sub-processors.

6. Assistance with data subject requests

Taking into account the nature of the service, CM Apps assists the Controller through appropriate technical and organizational measures in responding to data subject requests (access, erasure, portability, etc.). Requests received directly by CM Apps are forwarded to the Controller without undue delay.

7. Data breach notification

After becoming aware of a personal data breach, CM Apps informs the Controller without undue delay and at the latest within [48] hours; it shares the information available to it on the nature of the breach, the categories of data and data subjects affected, the likely consequences and the measures taken, and supports the Controller in meeting its statutory notification obligations.

8. Impact assessment and audits

CM Apps provides reasonable support to the Controller in data protection impact assessments and prior consultation procedures.

The Controller may audit compliance at most [1] time per year, with at least [30] days’ prior notice, through an auditor bound by confidentiality obligations. CM Apps first makes available its existing independent audit reports and certifications.

9. International transfers

Transfers outside the EEA or Türkiye are made only through mechanisms permitted by applicable law. For EU data, the EU Commission Standard Contractual Clauses (2021/914; Module 2 and, where required, Module 3) are incorporated into this DPA as Annex 3; for Turkish data, the standard contract or adequacy decision under KVKK Art. 9 applies. Transfer countries are shown in the Sub-processor List.

10. Return and deletion of data at the end of the agreement

Within [30] days of the end of the service, the Controller may request that the data be exported in a machine-readable format. At the end of this period, CM Apps deletes the data and all copies within [90] days, subject to statutory retention obligations, and confirms this in writing upon request.

11. Liability and precedence

The liability of the parties under this DPA is subject to the limitations in the principal agreement; the mandatory provisions of data protection law remain unaffected. In the event of a conflict between this DPA and the principal agreement, this DPA prevails in matters relating to the processing of personal data.

Annex 1: Details of processing

Subject matter of processing: [product/service]. Duration: the term of the principal agreement. Nature and purpose: [hosting, storage, processing, support]. Categories of personal data: [identity, contact, usage, transaction]. Categories of data subjects: [the Customer’s employees, customers, end users].

Annex 2: Technical and organizational measures

[Access management, encryption, network security, logging and monitoring, backup, business continuity, supplier management, training: to be completed on a per-project basis.]

Annex 3: Standard Contractual Clauses

[The SCC text annexed to EU Commission Implementing Decision 2021/914; the selected module, optional clauses, competent supervisory authority and governing law are specified in this annex.]

This document is part of the CM Apps Agreements & Policies center. In case of conflict with other documents, the order of precedence is set out in the relevant agreement.

FROM THE SAME CATEGORY

Related documents.

All documents

Have a question about this document?

Write to us for adaptation by scope, region or product.

[email protected]