Data Processing Addendum
Version: pre-launch 0.1
1. Parties and scope
This DPA is intended to form part of the agreement between the business customer (Controller/Business) and SUPVISE (Processor/Service Provider) where SUPVISE processes personal data contained in customer data solely to provide the service.
2. Processing instructions
SUPVISE will process customer personal data only on documented customer instructions, including as necessary to provide, secure and support the service, unless applicable law requires otherwise.
3. Confidentiality and security
Persons authorized to process customer data will be subject to confidentiality obligations. SUPVISE will maintain appropriate technical and organizational measures proportionate to risk, including access control, encryption in transit, private storage, upload validation, least privilege, logging and vulnerability management.
4. Subprocessors
The intended production stack may include Hostinger (hosting/infrastructure) and Paddle (Merchant of Record/payment processing). Additional subprocessors will be listed before use. SUPVISE will impose appropriate data-protection obligations on subprocessors and remain responsible to the extent required by applicable law and contract.
5. International transfers
Where required, the parties will incorporate applicable EU Standard Contractual Clauses and complete the relevant annexes, and will use applicable Turkish KVKK transfer mechanisms for transfers subject to Turkish law. The exact modules, transfer locations and supplementary measures will be finalized after production hosting and legal-entity details are fixed.
6. Data-subject requests
Taking into account the nature of processing, SUPVISE will provide reasonable assistance to the customer with requests to exercise applicable data-protection rights.
7. Breach notification
SUPVISE will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer personal data and provide information reasonably required for the customer's legal obligations.
8. Deletion and return
Raw Inventory Health uploads are designed not to be persistently stored after analysis. Analysis results are currently designed for automatic deletion after 7 days unless a different enterprise retention period is agreed. On termination or valid request, SUPVISE will delete or return personal data as required, subject to legal retention duties.
9. Audit and compliance information
SUPVISE will make available information reasonably necessary to demonstrate compliance and will support proportionate audits as required by applicable law and agreed enterprise terms.
10. Processing details
Subject matter: supply-chain analytics. Duration: service/retention period. Purpose: customer-requested analysis and secure delivery. Data subjects: none expected in ordinary use; incidental business contacts may occur if included by the customer. Data types: operational inventory, procurement and planning data; incidental personal data only if supplied by customer contrary to or within documented instructions.