Back to home

Data Processing Addendum

How we handle personal data that our customers process through the platform, and the commitments we make as processor.

Effective date: 13 August 2026

1. Purpose and roles

This Addendum forms part of the agreement between the customer ("Controller") and BLACK REIN TEKNOLOJİ ANONİM ŞİRKETİ ("Processor") for the EximLabs platform.

For personal data the customer uploads or processes through the platform — buyer contacts, correspondence, company records, documents — the customer is the controller and we act as processor on the customer's documented instructions.

For the customer's own account, billing and support data we act as controller; that processing is described in our Privacy Notice.

2. Subject matter, duration, nature

Subject matter: provision of the EximLabs export automation platform.

Duration: the term of the subscription, plus the retention periods in section 8.

Nature and purpose: storing, organising, enriching and transmitting business contact and commercial data so the controller can identify, contact and transact with potential buyers.

Categories of data subject: employees and representatives of companies the controller targets or transacts with; the controller's own users.

Categories of personal data: name, job title, business email, business phone, employer, professional profile links, correspondence content and metadata.

We do not knowingly process special categories of personal data. Do not upload them.

3. Our obligations

We process personal data only on the controller's documented instructions, including for transfers, unless law requires otherwise — in which case we inform the controller first unless prohibited.

Personnel with access are bound by confidentiality.

We implement the technical and organisational measures described in section 6.

We assist the controller, taking into account the nature of processing, in responding to data subject requests and in meeting its security, breach-notification and impact-assessment obligations.

At the end of the term we delete or return personal data at the controller's choice, save where retention is legally required.

We make available the information necessary to demonstrate compliance and allow for audits as described in section 9.

4. Controller obligations

The controller warrants that it has a lawful basis for processing the personal data it uploads or acquires through the platform, that it complies with the marketing, anti-spam and data-protection rules of the markets it contacts, that it honours opt-out and erasure requests, and that its instructions to us are lawful.

5. Subprocessors

The controller gives general authorisation for us to engage subprocessors. Our current list is published on the Subprocessors page.

We will give at least thirty (30) days' notice before adding or replacing a subprocessor. The controller may object on reasonable data-protection grounds; if we cannot resolve the objection the controller may terminate the affected service and receive a pro-rata refund of prepaid fees.

We impose data-protection obligations on each subprocessor that are no less protective than this Addendum, and remain liable for their performance.

6. Security measures

Encryption of data in transit (TLS) and encryption at rest for stored data.

Role-based access control, least privilege, and individual named accounts for administrative access.

Separation of production, staging and development environments.

Access logging and retention of security logs.

Regular backups with restoration testing.

Secrets and API credentials held server-side only, never exposed to client applications.

Vendor review before a new subprocessor is engaged.

7. International transfers

Primary processing takes place in Türkiye and the European Union. Where a subprocessor is established elsewhere, transfers rely on the mechanisms required by Turkish Law No. 6698 (KVKK) and, where the GDPR applies, on the EU Standard Contractual Clauses or another valid transfer mechanism.

8. Retention, return and deletion

During the term the controller can export its data at any time from the platform.

After the term ends we retain the data for up to twelve (12) months so the controller can request an export, then delete it. The controller may request immediate deletion instead.

Backups are overwritten on their normal cycle; deletion from live systems is not delayed by backup retention.

9. Audit

On reasonable written notice, and no more than once per year unless required by a supervisory authority, we make available documentation of our security measures and answer a written security questionnaire. On-site audits are by agreement and at the controller's cost.

10. Personal data breach

We notify the controller without undue delay, and in any case within seventy-two (72) hours, of becoming aware of a personal data breach affecting the controller's data. The notice will describe the nature of the breach, the categories and approximate numbers affected, the likely consequences and the measures taken.

11. Liability and precedence

Liability under this Addendum is subject to the limitations in the Terms of Service.

In case of conflict between this Addendum and the Terms of Service on data protection matters, this Addendum prevails.

12. How to execute this Addendum

A countersigned copy is available on request. Write to info@eximlabs.ai with your legal entity name and registered address and we will return an executed version.