Post AI Pilot
Home
Creative Tools PlannerPlan your content calendar and create content automatically with AI Generate ImageCreate professional visuals with AI Generate VideoText to video in seconds Product StudioAI-powered studio-quality shoots for ecommerce and social media Catalog StudioTransform apparel, jewelry, and accessories with premium catalog aesthetics
Explore Credit BalanceTrack your credit spending ServicesProfessional production and web solutions PortfolioExplore sample work
Post AI Pilot Logo
About Pricing
FAQ Contact
Blog
English Türkçe
Log In Start Free
Post AI Pilot
Home
Planner Credit Balance Generate Image Generate Video Product Studio Catalog Studio
About Pricing
FAQ Contact
Blog
Log In Start Free
Contact
info@postaipilot.com +90 542 656 07 00
Post AI Pilot

Data Processing Agreement (DPA)

The text below contains the full Data Processing Agreement terms for Post AI Pilot business partners.

Post AI Pilot

DATA PROCESSING AGREEMENT

(Data Processing Agreement – DPA)

1. PARTIES

1.1. This Data Processing Agreement (“Agreement”);

Data Controller

Title: Furkan Pehlivanoğlu Sole Proprietorship

Address: Cevizli Mahallesi, Zuhal Caddesi, Ritim İstanbul Sitesi, A4 Blok, No: 46 D, Floor: 3, Apartment: 34, Maltepe / ISTANBUL

E-mail: info@postaipilot.com

("Data Controller")

with

Data Processor

Title/Name-Surname: [DATA PROCESSOR TITLE]

Address: [DATA PROCESSOR ADDRESS]

Email: [DATA PROCESSING EMAIL]

("Data Processor")

This agreement has been concluded between the parties in accordance with the Law No. 6698 on the Protection of Personal Data (“KVKK”) and related secondary legislation. The parties will be referred to collectively as “the Parties”.

2. SUBJECT AND SCOPE

2.1. The subject of this Agreement is to determine the procedures and principles regarding the processing of personal data belonging to the Data Controller's customers by the Data Processor on behalf of the Data Controller for purposes such as [e.g., social media management, content creation, advertising campaign execution, content planning via Post ai Pilot account, etc.].

2.2. The Data Processor agrees that, in accordance with Article 3/1-ğ of the KVKK (Law on Protection of Personal Data), it will process personal data only in accordance with the instructions of the Data Controller and within the scope and purposes specified in this Agreement and Annex 1.

3. DEFINITIONS

In this Agreement;

Personal Data: Any information relating to an identified or identifiable natural person.

Special Category Personal Data: Data of the type listed in Article 6 of the KVKK (Law on Protection of Personal Data),

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

Data Processor: A natural or legal person who processes personal data on behalf of the Data Controller, based on the authority granted by the Data Controller.

That will mean...

(If you also want to use it in compliance with GDPR, etc., you can add a separate reference here.)

4. CATEGORIES OF DATA PROCESSED AND PURPOSES (APPENDIX-1)

4.1. The categories of personal data that may be transferred to the Data Processor under this Agreement and the purposes of processing are listed in detail in Appendix 1. For example:

  • Customer identification/contact information (name, username, email, etc.),
  • Customer social media account URLs, usernames, content texts, images,
  • Campaign/plan information, content calendars, etc.

4.2. The Data Processor agrees not to process data other than the data categories and purposes listed in Annex 1, and to process only the necessary data in compliance with the principle of data minimization.

5. OBLIGATIONS OF THE DATA PROCESSOR

5.1. Acting on Instructions

The Data Processor processes personal data only within the scope of the Data Controller's written instructions. It cannot process data without written instructions, nor can it follow the instructions of the data subject or third parties.

5.2. Compliance with Legislation

The Data Processor agrees to comply with the Personal Data Protection Law (KVKK), relevant regulations, Board decisions, and the provisions of this Agreement, and acknowledges that it will be held responsible for any liabilities and sanctions arising from non-compliance.

5.3. Confidentiality Obligation

The Data Processor and its employees, subcontractors, or persons employed by it are obligated to keep confidential all personal data and trade secrets they learn. This obligation continues indefinitely even after the termination of the Agreement.

5.4. Security Measures

Data Processor;

  • To take the necessary technical and administrative measures within the framework of Article 12 of the Personal Data Protection Law and related legislation.
  • Implementing appropriate security measures against the risks of unauthorized access, data leakage, loss, deletion, and modification.
  • To inform its own personnel about personal data protection and provide the necessary training.

He agrees.

5.5. Using Sub-processors

The Data Processor may not appoint a third party as a sub-data processor to process personal data without the prior written consent of the Data Controller.

If approval is given:

  • The data processor enters into a data processing agreement in accordance with the GDPR.
  • The data processor acknowledges that it is personally responsible for its own actions.

5.6. Transferring Data Abroad and Using Third-Party Services

The Data Processor may transfer personal data outside of Türkiye only if:

  • With the written instruction and approval of the Data Controller,
  • Provided that the Data Controller has obtained the necessary explicit consents from the relevant data subjects or other legal grounds stipulated by the Board.

He can.

If the Data Processor uses foreign service providers such as OpenAI, Google Cloud, AWS, etc., as sub-data processors, this is specified in Appendix 2 – Transfer Abroad and Sub-Data Processors, and transactions are only carried out in accordance with the conditions in this Appendix.

5.7. Data Breach Reporting

In the event of a security breach related to personal data (unauthorized access, disclosure, leakage, loss, etc.), the Data Processor shall notify the Data Controller in writing as soon as possible (e.g., within 24 hours at the latest); take necessary measures to mitigate the effects of the breach and prevent its recurrence; and cooperate with the Data Controller.

5.8. Data Subject's Requests

The Data Processor shall immediately forward requests (access, correction, deletion, objection, etc.) made directly to it by data subjects within the scope of the GDPR to the Data Controller and shall not respond directly to these requests unless instructed to do so by the Data Controller.

5.9. Right of Control

The Data Controller may, at reasonable intervals and frequencies, monitor whether the Data Processor is complying with this Agreement and the Personal Data Protection Law, or may have this monitored by third parties. The Data Processor agrees to provide the necessary information and documents during the monitoring process.

5.10. Deletion/Refund After Expiration

Upon termination of the agreement or at the request of the Data Controller, the Data Processor:

The data controller shall return all personal data processed (and copies thereof) to the Data Controller or

In accordance with the Personal Data Protection Law (KVKK) and related legislation, it will be deleted/destroyed/anonymized.

and documents the transactions in writing. Retention obligations required by legislation are reserved.

6. OBLIGATIONS OF THE DATA CONTROLLER

6.1. Before transferring personal data to the Data Processor, the Data Controller shall:

  • To inform the relevant parties in accordance with Article 10 of the Personal Data Protection Law,
  • Obtaining explicit consent if necessary,
  • For international transfers, the conditions in Article 9 of the Personal Data Protection Law must be met.

is responsible.

6.2. The Data Controller agrees that it will only transmit accurate data to the Data Processor to the extent required for the purpose, and that it will be responsible for any unnecessary or redundant data within the dataset.

6.3. The Data Controller acknowledges that it will be responsible for any administrative and criminal sanctions that may arise if the instructions it gives to the Data Processor are unlawful.

7. TERM AND TERMINATION

7.1. This Agreement shall enter into force on December 2, 2025, and shall remain valid for the duration of the original business/service contract between the Parties.

7.2. If either party detects data processing that violates the KVKK (Turkish Personal Data Protection Law), it shall notify the other party in writing, giving them a reasonable period of time to remedy the violation; if the violation is not remedied, the party may terminate the Agreement for just cause.

7.3. In the event of termination, the Data Processor's obligations regarding data destruction/return continue in accordance with Article 5.10.

8. LIABILITY AND COMPENSATION

8.1. In the event that the parties breach their obligations arising from this Agreement and the Personal Data Protection Law (KVKK), they shall be liable for any resulting damages in accordance with general provisions.

8.2. If the Data Controller or third parties suffer any damage, administrative fine, or are required to pay compensation as a result of the Data Processor's fault or breach, the Data Processor shall be liable for the relevant damages and penalties and shall compensate the Data Controller.

Contact

Email Area info@postaipilot.com
Quick Links
  • Frequently Asked Questions
  • KVKK Privacy Notice
  • Privacy & Cookie Policy
  • Distance Sales Agreement
  • Transaction and Terms of Use
  • Data Processing Agreement
  • Social Media Authorization Consent
Social Media
Post AI Pilot Logo

© 2026 Post AI Pilot. All rights reserved.

Iyzico Mastercard Troy
|
Supported by Google & AWS
Cookie Preferences
We use cookies to personalize your experience and improve our service quality. For details, Privacy and Cookie Policy you can review it.