Proje vitrini hazırlanıyorPreparing project showcaseПодготавливаем витрину проекта
Skip to main content
Effective Date: 21 April 2026

Data Processing Agreement (DPA)

Terms governing the processing of personal data between the Data Controller (Customer) and the Data Processor (Rocketly), under GDPR and Turkish KVKK.

Summary

This Data Processing Agreement ("DPA") is included in the standard plan for business customers using Rocketly and forms an integral part of the Terms of Service. The Customer acts as the data controller; Rocketly acts as the data processor processing personal data on the Customer's behalf.

1. Parties & Definitions

This DPA is entered into between the business customer using the services (the "Customer" / Data Controller) and Rocketly ("Rocketly" / Data Processor). The terms Personal Data, Processing, Data Controller, Data Processor, Data Subject and Supervisory Authority have the meanings given under GDPR and Turkish KVKK (Law No. 6698).

2. Subject Matter & Duration

Rocketly processes personal data solely to provide the Customer with CRM, unified inbox, automation, AI assistant and related services. Processing continues for the duration of the Customer's subscription and ends in accordance with the "Return & Deletion of Data" section below.

3. Nature & Purpose of Processing

Data is processed through operations such as collection, recording, storage, organization, display, transmission, backup and deletion, and only on the Customer's documented instructions (including the Terms of Service, configurations made through the Rocketly interface, and API usage). Rocketly does not process personal data for any other purpose without explicit instruction.

4. Categories of Personal Data & Data Subjects

Depending on what the Customer enters into the platform or imports via integrations, the following categories may be processed:

Data Subject GroupPossible Data Categories
Customer's customers / leadsName, phone, email, message content, interaction history, company details
Customer's employees (users)Name, email, role, session/log records
Communication / channel dataWhatsApp, Instagram, email, phone call metadata and content

5. Obligations of the Data Controller

The Customer is solely responsible for having a valid legal basis (consent, contract, legitimate interest, etc.) for the personal data it imports, for informing data subjects, and for the lawfulness of processing such data on the platform.

6. Obligations of the Data Processor

• Process personal data only on the Customer's documented instructions;
• Ensure personnel with access are bound by confidentiality;
• Implement the technical and organizational measures below;
• Reasonably assist the Customer in responding to data subject requests and supervisory authority inquiries;
• Notify the Customer of data breaches without undue delay;
• Return or delete data at the end of the agreement.

7. Technical & Organizational Measures

Rocketly implements measures appropriate to the risk, including:

Encryption in transit and at rest (TLS; encryption at rest for sensitive fields);
Role-based access control (RBAC) and support for two-factor authentication (2FA);
Full audit logging and access monitoring;
• Regular backups, isolated environments and maintained infrastructure;
• Hosting in European data centers (data residency).

8. Sub-processors

Rocketly may engage sub-processors (hosting, email delivery, payment infrastructure, AI services, etc.) to deliver the service. All sub-processors are bound by contractual obligations at least as protective as this DPA. The Customer may obtain the current list of sub-processors on request and has the right to reasonably object to a new sub-processor.

9. International Transfers

Personal data is primarily processed in Europe. Where a transfer outside the region is required, it takes place only with appropriate safeguards as required by GDPR and KVKK (adequacy decision, standard contractual clauses, etc.).

10. Data Subject Rights & Breach Notification

Rocketly assists the Customer, through appropriate measures, in fulfilling data subjects' rights of access, rectification, erasure and objection. Upon becoming aware of a personal data breach, Rocketly notifies the Customer without undue delay and provides reasonable support to mitigate its effects.

11. Audits

Subject to reasonable notice and confidentiality, the Customer may request audit information and compliance documentation to verify Rocketly's compliance with this DPA.

12. Return & Deletion of Data

Upon termination of the subscription, the Customer is able to export its data within a reasonable period. After that period, Rocketly deletes or anonymizes the Customer's personal data, subject to any statutory retention obligations.

13. Entry into Force

This DPA takes effect when the Customer begins using Rocketly services and applies together with the Terms of Service. In case of conflict on matters of personal data processing, this DPA prevails.

Start using Rocketly today.


Discover the CRM built for your industry.