Data Processing Terms
Tecrübe's obligations as a processor: instructions, confidentiality, security, sub-processors, transfers, breach notification and return or deletion.
Contents
1. Roles — who is responsible for what
These terms are an integral annex to the Terms of Service and apply to every customer using Tecrübe, whether or not signed separately.
CUSTOMER DATA (your own customers' data: contact lists, incoming messages, conversion records): here **you are the controller** and Tecrübe is the processor. You decide what you collect, on what legal basis you process it, and what you tell whom; Tecrübe processes only on your instructions.
ACCOUNT DATA (your and your team's names, e-mails, session records, billing details): here **Tecrübe is the controller** and the Privacy Policy applies. The distinction matters: one product, two legal roles, and your rights differ by which data is involved.
Tecrübe never uses Customer Data for its own purposes — product development, model training, marketing. There is no exception; if there were, it would be written here.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the Tecrübe service. Duration: for as long as your subscription lasts, plus the return/deletion period in section 10.
Processing activities: storage, organisation, retrieval, transmission (to the platforms you connect), deletion, and text generation with AI models.
Data categories: contact details (name, e-mail, phone), message content, behavioural and conversion data, and the lists and content you upload.
Categories of data subjects: your customers, prospects, people who message you, and members of your team.
Special-category data: the service is not designed to process it. If you upload it, the additional protections and explicit-consent obligations are yours.
3. Processing on instructions
Tecrübe processes Customer Data only on your documented instructions. Your use of the service — launching a campaign, uploading a list, enabling an automation — constitutes such an instruction.
If we believe an instruction infringes applicable law, we will inform you and may stop carrying it out.
If law compels processing (a court order, an administrative demand) and notification is not prohibited, we inform you before processing.
4. Confidentiality and security
Everyone with access to Customer Data is bound by confidentiality, and access is limited to the narrowest scope the work requires.
Technical measures in place: encryption in transit and at rest, tenant isolation enforced at the database level with row-level security, argon2id password hashing, provider secrets encrypted with a separate key, role-based access, and an audit record of every privileged action.
Organisational measures: staff access is logged; a support view of a tenant is shown with a visible banner to both the viewer and the tenant; regular backups with restore drills.
These measures may change over time; a change may not lower the level of security.
5. Sub-processors
Tecrübe uses sub-processors to provide the service. The current list — who they are, for what purpose and in which country — is published by name in section 9 of the Privacy Policy.
New sub-processors are announced by in-product notice. If you object on reasonable grounds, we will consider your objection; if it cannot be resolved, you may terminate without penalty and receive a refund for the unused period.
Each sub-processor is bound by a contract with obligations equivalent to these terms. Tecrübe remains liable for a sub-processor's acts as for its own.
Data sent to AI providers is limited to what the prompt requires: brand profile and campaign context go; customer lists and contact details do not.
6. International transfers
Some sub-processors are outside Türkiye (notably AI providers and ad platforms). Transfers are made under Article 9 of the KVKK and Chapter V of the GDPR, relying as applicable on standard contractual clauses, an adequacy decision or explicit consent.
Which sub-processor processes in which country is stated next to each entry in the Privacy Policy list.
7. Data-subject requests and assistance to you
If a data subject contacts Tecrübe directly, we do not answer on your behalf — we refer them to you, since you are the controller for that data.
The tools you need to satisfy access, rectification, erasure and portability requests are in the product: export and deletion are available under Settings → My data. Where the tooling is not enough, we provide reasonable technical assistance.
If you must carry out a data protection impact assessment (Article 35), we provide the information we hold, to a reasonable extent.
8. Breach notification
We notify you of a security breach affecting Customer Data **without undue delay and within 24 hours at the latest** of becoming aware of it. That window is deliberately short so that you can meet your own 72-hour notification duty.
The notice includes: the nature of the breach, the categories of data and approximate number of records affected, likely consequences, measures taken and planned, and a contact point.
If not everything is known at first notice, the missing information follows without delay; waiting is not a substitute for notifying.
9. Audit
On request we provide the information needed to demonstrate compliance with these terms.
Once a year, on reasonable notice and during business hours, you may audit using an auditor bound by confidentiality. An audit may not involve access to other customers' data and is conducted so as not to disrupt the service.
10. Return and deletion at the end
When your subscription ends, Customer Data remains exportable for thirty days; you can download it from the panel during that time.
At the end of the thirty days the data is deleted. Deletion is irreversible and is announced by e-mail seven days in advance.
Copies in backups age out with the backup cycle (at most ninety days); during that time they remain encrypted and inaccessible.
Records that law requires us to keep (invoices, the audit log) are retained for their statutory period and processed for that purpose only.