This addendum is an integral part of the Distance Sales Service Agreement and, in accordance with the Personal Data Protection Law No. 6698 and the Regulation on the Right to Delete, Destroy, or Anonymize Personal Data, governs the parties' obligations regarding the processing of personal data hosted by the Customer.
1. Status of Parties
1.1. The Customer is the data controller. The Customer determines the purposes and means of processing personal data (visitor, member, and customer information) contained in the website, email, and databases hosted within the scope of the hosting service.
1.2. Çağrı Hosting is the data processor. It processes this data solely for the purpose of providing the hosting service, in accordance with the Customer's instructions and within the limits set out in this agreement.
1.3. Regarding Çağrı Hosting's own customer records (orders, invoices, contact information), Çağrı Hosting is the data controller; this data is covered by the KVKK Privacy Notice and is outside the scope of this addendum.
2. Subject and Scope of Processing
| Title | Content |
|---|---|
| Processing purpose | Provision of hosting service, infrastructure operation, backup, technical support, and security assurance |
| Data categories | Any type of personal data determined and hosted by the Customer |
| Relevant data subject groups | The Customer's visitors, members, customers, and employees |
| Duration | During the service period and for the retention periods specified in this addendum |
Çağrı Hosting does not know or monitor the content, type, or sensitivity level of hosted data. If the Customer will host special category personal data (health, biometric, criminal conviction, etc.), the Customer is responsible for implementing additional appropriate technical measures.
3. Obligations of Çağrı Hosting
3.1. Processes personal data only in accordance with the Customer's instructions and to the extent required by the service; does not use it for its own purposes, sell it, or transfer it to third parties.
3.2. Limits access to data to personnel authorized by their role and bound by confidentiality obligations.
3.3. Implements reasonable technical and administrative measures to ensure an appropriate level of security in accordance with Article 12 of the KVKK: access controls, encryption (SSL/TLS), firewalls, intrusion monitoring, regular backups, update management, and access logging.
3.4. Accesses the content hosted by the Customer only in the following cases:
- Upon the Customer's support request or explicit instruction,
- In cases of necessary technical intervention for service continuity,
- In accordance with lawful decisions of authorized authorities.
3.5. Data breach notification: If a security breach affecting hosted data is detected, Çağrı Hosting shall notify the Customer without delay and within 24 hours of discovery; the notification shall include the nature of the breach, types of affected data, and measures taken. The obligation to notify the Authority rests with the Customer as data controller and must be made in accordance with applicable law within 72 hours. Çağrı Hosting shall provide necessary information and support to the Customer during this process.
3.6. Data subject requests: If a data subject request regarding data hosted by the Customer is received directly by Çağrı Hosting, Çağrı Hosting shall not respond to the request itself; it shall forward the request to the Customer and provide reasonable technical support for fulfilling the request.
3.7. Audit: The Customer may request information regarding compliance with the obligations set out in this addendum at reasonable intervals and upon prior written notice. Çağrı Hosting shall provide the necessary information provided it does not compromise the confidentiality of other customers' data.
4. Sub-processors
4.1. Çağrı Hosting may engage sub-processors to provide the service. Current list:
| Sub-processor | Service | Location |
|---|---|---|
| SunucumFix | Server infrastructure | Turkey |
| [BACKUP PROVIDER] | Off-server backup | [COUNTRY] |
| [CDN / SECURITY PROVIDER] | Content delivery and attack protection | [COUNTRY] |
| [OTHER] |
4.2. Written contracts containing equivalent obligations to this Addendum are executed with sub-processors. Çağrı Hosting is responsible to the Customer for the actions of sub-processors.
4.3. In case of any changes to the sub-processor list, the Customer shall be notified by email at least 30 days in advance. If the Customer objects to the change, they may terminate the service without penalty; in this case, the fee for the unused period shall be refunded.
5. Transfer Abroad
If some sub-processors' servers are located abroad, the transfer shall be carried out in accordance with Article 9 of KVKK: Standard contracts announced by the Board shall be signed and notified to the Authority within 5 business days from the date of signature. Within the scope of their own data controller obligations, the Customer is required to specify this transfer in their own privacy notice.
6. Return and Deletion of Data
6.1. Upon termination of the service, the Customer is granted 30 days to download their data.
6.2. At the end of this period, hosted data shall be permanently deleted. Copies in backup systems shall be deleted within 30 days at the latest, due to the nature of the backup cycle.
6.3. Records whose retention is mandated by law (such as traffic information under the 5651 numbered Law) shall continue to be retained for the applicable period.
7. Customer's Obligations
7.1. The Customer warrants that they have collected the personal data they host in a lawful manner, provided the necessary privacy notice, and obtained explicit consent where required.
7.2. The Customer is obligated to keep their website software, plugins and themes updated, use strong passwords, and manage their own user authorizations.
7.3. Çağrı Hosting is not responsible for any violations and damages arising from the Customer's breach of these obligations.
8. Effective Date
This Addendum comes into effect upon purchase of the service and remains valid for the duration of the service. Upon Customer request, a wet-signed or electronically signed copy shall be prepared.