Panilux — Data Processing Agreement (DPA) — Last updated: Oct 30, 2025
Türkçe

Data Processing Agreement (DPA)

This document sets out the terms under which Panilux processes personal data on behalf of the Customer as a processor.

Parties and Purpose

  • Controller: Customer
  • Processor: Panilux

Panilux processes data only in accordance with the controller’s documented instructions.

This DPA should be read together with the Privacy Policy. Website and panel use are governed by the Terms of Service.

Subject Matter and Duration

  • Data types: identity, contact, security, customer transaction, finance, logs.
  • Duration: contract term and statutory retention periods.

For detailed retention periods and disposal principles, see the Data Retention Policy.

Processor Obligations

  • Process only per instructions; notify controller about sub-processors in writing.
  • Implement appropriate technical/organizational measures (encryption, access control, logging, backups).
  • Notify the controller without undue delay in case of a breach and cooperate.
  • Provide reasonable assistance with audits/assessments.
  • Upon termination, return or delete/anonymize data unless retention is required by law.

Sub-processors

Panilux may engage sub-processors (hosting, payments, security, etc.) bound by obligations no less protective than this DPA.

International Transfers

Transfers outside Türkiye/EU occur with appropriate safeguards and as permitted by law, or with data subject consent.

Data Subject Requests

Panilux assists the controller with data subject requests (access, rectification, erasure, etc.) within reasonable time.

Security Incident Notice

Panilux promptly informs the controller of personal data breaches and shares impact assessments/logs where appropriate.

Liability

Panilux’s obligations are limited to this DPA and applicable law; the controller is responsible for lawful processing and notices/consent. Panilux is not responsible for incidents attributable to the controller’s infrastructure, third‑party networks/services, hosting/telecom or data center operations, nor for user error/misconfiguration.

Law and Jurisdiction

Governing law: Republic of Türkiye. Jurisdiction: Istanbul Central Courts.

Changes

To the extent permitted by applicable law, Panilux may unilaterally update this DPA and its appendices with or without notice; updates take effect upon publication. Where notice or additional consent is required by law, Panilux will provide such notice and obtain consent as necessary. Panilux may define user/account/order/project‑specific supplemental provisions/instructions and update them individually for the relevant controller. In case of conflict, the controller‑specific written instructions/supplemental provisions prevail to the extent of the conflict.

Panilux and the Panilux logo are registered trademarks.