This Data Processing Agreement ("DPA") is entered into between İbrahim Ethem Karabıyık ("Marka Gold") and the jewelry business using the Marka Gold SaaS platform (hereinafter referred to as the "Jeweler" or "User"), and governs the obligations of the parties under the Turkish Personal Data Protection Law No. 6698 ("KVKK") with respect to personal data processed in connection with the use of the Marka Gold platform. This DPA forms an integral part of the Marka Gold Terms of Service. By using the platform, you agree to be bound by this DPA.
1. Definitions
The following key definitions apply throughout this DPA:
1.1 Core KVKK Definitions
- Personal Data: any information relating to an identified or identifiable natural person
- Processing: any operation performed on personal data, whether automated or not, including collection, recording, storage, modification, disclosure and transfer
- Data Controller: the natural or legal person determining the purposes and means of processing personal data
- Data Subject: the natural person whose personal data is processed
1.2 Agreement-Specific Definitions
- Platform Data: personal data generated by the Jeweler and the Jeweler's staff (branch managers, sales staff, etc.) during registration and use of the Marka Gold platform
- End-Customer Data: personal data belonging to the Jeweler's own customers that is entered into the Marka Gold platform by the Jeweler
- Service Provider: İbrahim Ethem Karabıyık (operating under the trade name Marka Gold)
- Sub-processor: any third-party vendor used by Marka Gold for service delivery
1.3 Controller Status (Sole Controller Model)
- Marka Gold acts as an independent Data Controller within the meaning of Article 3/1(i) of KVKK with respect to Platform Data
- The Jeweler acts as a separate and independent Data Controller under KVKK with respect to End-Customer Data
- Marka Gold does not determine the purposes or means of processing End-Customer Data and does not perform any operation on such data other than storage and provision of technical infrastructure on behalf of the Jeweler
- The parties are not joint controllers; each party acts as a separate data controller within its own sphere of responsibility
2. Scope and Term
The scope and term of this DPA are as follows:
2.1 Effective Date and Validity
- This DPA enters into force on the date the Jeweler registers for the Marka Gold platform
- It remains in effect for as long as the account is active and the Terms of Service are in force
- Even after the account is closed, the relevant provisions continue to apply to the extent that statutory retention obligations remain
2.2 Categories of Data Processed
- Identity (first name, last name)
- Contact (phone, email)
- Business (trade name, role, branch affiliation)
- Account security (session, IP, device/browser, bcrypt password hash)
- Usage (login times, audit log)
- Billing information
2.3 Out-of-Scope Data
- No health, biometric or other special category data under KVKK Article 6 is processed
- Payment card data (PCI-DSS) is collected directly by the payment provider and is not stored by Marka Gold
3. Allocation of KVKK Obligations
The principal obligations arising from KVKK are allocated between the parties as follows:
3.1 Disclosure Obligation (KVKK Article 10)
- Marka Gold fulfills its disclosure obligation for Platform Data through its own Privacy Notice
- The Jeweler is responsible for preparing and presenting a separate disclosure notice to its own end-customers
- Marka Gold may provide templates or assistance; however, legal responsibility remains with the Jeweler
3.2 Data Security Obligation (KVKK Article 12)
- Marka Gold applies the technical and organizational measures set out in Section 5 for all data processed on the platform infrastructure
- The Jeweler is responsible for the security of its own user account credentials (passwords, sessions) and for security measures on its own local devices
3.3 Handling of Data Subject Requests (KVKK Articles 11 and 13)
- Data subject requests concerning Platform Data are handled directly by Marka Gold
- Data subject requests concerning End-Customer Data are handled by the Jeweler
- If the Jeweler requests technical assistance, Marka Gold shall provide it within a reasonable period (no later than 15 days depending on the nature of the request)
3.4 Cross-Border Transfers (KVKK Article 9)
- For transfers to sub-processors located in EU member states, Standard Contractual Clauses (SCC) have been executed pursuant to KVKK Board Decision No. 2024/959
- Additional safeguards introduced by Decision No. 2025/1072 are observed
- Annual compliance reviews are conducted within the framework of Principle Decision No. 2026/347
4. Independent Controller Responsibility of the Jeweler
With respect to End-Customer Data, the Jeweler, as an independent Data Controller, represents and undertakes the following:
4.1 Lawfulness
- The Jeweler represents that it has a lawful basis (consent, contract, legitimate interest, legal obligation, etc.) for each piece of end-customer data entered into the platform
- The Jeweler refrains from entering unlawfully collected or processed data
4.2 Information and Communication
- The Jeweler informs its own customers, in accordance with KVKK Article 10, that their data is processed through the Marka Gold platform
- Marka Gold has no obligation to verify whether such disclosure has been made
4.3 Data Subject Rights
- The Jeweler is the primary addressee of erasure, rectification, portability and similar requests received from its end-customers
- Marka Gold provides only technical assistance through platform features
4.4 Liability
- All administrative, financial and criminal liability arising from the entry of unlawfully collected or processed end-customer data into the platform rests solely with the Jeweler
5. Data Security Measures (KVKK Article 12)
Marka Gold applies reasonable and industry-standard technical and organizational measures, including:
5.1 Technical Measures
- TLS 1.2+ encryption for data in transit
- AES-256 level encryption for data at rest (to the extent applicable)
- Role-based access control (RBAC) and the principle of least privilege
- Multi-factor authentication (MFA) for production access
- Regular backups maintained in geographically separated locations
- Access and system logs (audit log)
- HMAC-SHA256-based tamper-evident audit log chain
5.2 Organizational Measures
- Written confidentiality undertakings for personnel
- KVKK awareness training
- Regular security assessments and updates
- Disaster recovery (DR) and business continuity plan
6. Data Breach Notification (72 Hours)
Pursuant to KVKK Article 12 and related Board Decisions, the breach notification process is as follows:
6.1 Marka Gold's Obligation
- Marka Gold shall notify the Jeweler within 72 hours of becoming aware of a personal data breach affecting the Jeweler's data in its systems
- The notification shall include the nature of the breach, categories of data affected, estimated consequences and the measures taken or recommended by Marka Gold
6.2 Jeweler's Obligation
- The Jeweler shall itself notify the Personal Data Protection Authority and the affected data subjects for any breach affecting End-Customer Data
- Marka Gold's compliance with its own obligation does not relieve the Jeweler from its own notification obligation
7. Sub-processors
Marka Gold uses the following sub-processors for service delivery, each under a KVKK-compliant agreement:
- Amazon Web Services (AWS) — cloud storage — Frankfurt, EU
- MongoDB Atlas — database — Frankfurt or Ireland, EU
- Google (Gmail SMTP) — email delivery — USA
- Netgsm — SMS delivery — Türkiye
7.1 Cross-Border Transfer Safeguards
- For EU-based sub-processors, Standard Contractual Clauses (SCC) have been executed pursuant to KVKK Board Decision No. 2024/959
- Additional safeguards introduced by Decision No. 2025/1072 are observed
- The USA-based Gmail SMTP service is used only for transactional notifications
7.2 Vendor Changes
- When the vendor list is updated, Marka Gold announces the change through the platform
- The Jeweler shall have the right to object to a new vendor within 30 days
8. Limitation of Liability
The contractual liability of the parties is subject to the following principles:
8.1 Separate Liability
- Each party shall be liable for administrative fines, compensation and other damages arising from KVKK violations within its own sphere of responsibility
- Marka Gold cannot be held liable for the Jeweler's violations relating to End-Customer Data
8.2 Liability Cap
- Marka Gold's contractual liability to the Jeweler is limited to the annual subscription fee for the year in which the relevant incident occurred
8.3 Carve-Outs
- With respect to damages suffered by data subjects due to a breach of the data security obligation under KVKK Article 12, the mandatory provisions of KVKK are reserved, and the foregoing cap shall not apply
- Cases of intent and gross negligence likewise fall outside the limitation of liability
9. Term, Termination and Data Destruction
The term, termination and data destruction principles of this DPA are as follows:
9.1 Term
- This DPA remains in effect for the duration of the Terms of Service
- Relevant provisions continue to apply to the extent that statutory retention obligations remain
9.2 Post-Termination Data Handling
- Marka Gold shall retain Platform Data for 30 days for possible reactivation requests
- At the end of such period, the data is destroyed or anonymized
- Invoicing/accounting data subject to the 10-year statute of limitations under Article 146 of the Turkish Code of Obligations No. 6098 is preserved where retention is legally required
9.3 Data Export
- The Jeweler is entitled to export its own End-Customer Data prior to termination
- Recovery after destruction is not possible
10. Governing Law, Jurisdiction and Contact
This DPA is governed by the laws of the Republic of Türkiye, and the Istanbul (Çağlayan) Courts and Enforcement Offices have exclusive jurisdiction over disputes. KVKK and related Board decisions (in particular Nos. 2024/959, 2025/1072 and 2026/347) shall be the basis of interpretation. Marka Gold may update this DPA from time to time; material changes shall be announced through the platform and continued use of the platform after such announcement constitutes acceptance of the updated terms. For any questions, requests or concerns related to this DPA, you can contact us at:
Marka Gold
İbrahim Ethem Karabıyık
Kocasinan Merkez Mah. Mahmutbey Cad. 235A
Bahçelievler, Istanbul, Turkey
Email: support@markaglbl.com