Scope and precedence
This agreement applies between CM Apps Software LLC ("processor", "we") and the party using our service ("controller", "you") wherever a test touches personal data.
It forms an integral part of the Terms of Service. Where anything conflicts on the processing of personal data, this agreement prevails over the other documents.
Where a separate signed data processing agreement is entered into, that document prevails over this page.
Definitions
"Personal data", "processing", "controller", "processor", "data subject" and "data breach" carry the meanings given to them in the applicable data protection legislation.
"Applicable legislation": Turkish Law no. 6698 on the Protection of Personal Data and its secondary regulation; and, where the processing falls within their scope, the EU General Data Protection Regulation and the UK GDPR.
Allocation of roles
For data within the test scope you are the controller and we are the processor. You decide what is processed, for what purpose and on what legal basis.
For our own customer and visitor data (your account, invoices, support correspondence) we are the controller; that processing is described in the Privacy Policy.
The testers in our network and our infrastructure providers are our sub-processors; we are answerable to you for their compliance.
Subject matter, duration and nature
Subject matter: carrying out the test in the scope you confirmed, reporting findings, and running the re-test round.
Duration: from the start of the test until test data is deleted. Deletion occurs 90 days after the test ends.
Nature and purpose: access to data encountered while running test scenarios, capture as evidence where needed, and reporting. There is no other purpose.
Data categories and data subjects
Data subjects: your end users, customers and employees — only to the extent they are encountered in the test environment.
Data categories: identity and contact details, account and session data, transaction records and whatever else the test environment holds.
We do not want to process special category data (health, biometric, belief, union membership and the like). Where the test environment contains such data you tell us before the test and we agree the additional measures together.
We recommend using synthetic data in your test environment rather than real personal data. That removes both the risk and the scope restrictions.
Processing on instructions
We process personal data only on your documented instructions. The scope you confirmed is that instruction.
If we believe an instruction breaches the applicable legislation, we tell you before acting on it.
Cases where we are legally compelled are the exception; there we notify you before processing where legally permitted.
Confidentiality
Everyone with access to personal data, core team members and testers alike, is under a written confidentiality obligation that survives the end of their engagement.
Access is granted per person on a need-to-know basis and is limited to the duration of the test.
Security measures
We apply technical and organisational measures appropriate to the risk: TLS 1.2 or above in transit, AES-256 encryption at rest, least-privilege access control, multi-factor authentication, access logging and regular backups.
Copying test data to personal devices is prohibited; work is carried out in controlled environments.
The full list of measures is on the Security Policy page and forms an annex to this agreement.
Sub-processors
You give general authorisation for the use of sub-processors. The current list is on the Sub-processors page.
We enter into a written agreement with each sub-processor on terms no less protective than these.
We remain answerable to you where a sub-processor fails to meet its obligations.
Sub-processor changes and objection
We give at least 30 days’ notice before adding a new sub-processor or replacing an existing one.
Within that period you may object on reasonable grounds. If we cannot resolve your objection, you may end the affected service without penalty and receive a refund of the part not carried out.
Assistance with data subject requests
Where a data subject approaches us directly, we do not answer the request; we refer it to you without delay.
We provide the technical assistance you need to meet access, rectification, erasure, objection and portability requests.
That assistance is free as part of the service; for requests requiring unusual effort we quote in advance.
Breach notification
On becoming aware of a personal data breach we notify you without delay and in any event within 24 hours.
The notice covers: the nature of the breach, the approximate number of data subjects and records affected, the likely consequences, the measures taken and planned, and our point of contact.
Where the full picture is not available at once, we send it in stages as we learn more. You make the notification to the supervisory authority; we supply the information and evidence needed.
Impact assessments and prior consultation
Where you carry out a data protection impact assessment, we provide reasonable information about our processing activity.
Where prior consultation with a supervisory authority is required, we support the process to a reasonable extent.
International transfers
We do not transfer personal data across borders without the safeguards the applicable legislation requires.
Where transfer is necessary, standard contractual clauses or the other mechanisms the legislation provides are used. Where each sub-processor is located is shown on the Sub-processors page.
Deletion and return
Ninety days after a test ends we permanently delete personal data, test recordings and credentials.
If you ask for earlier deletion or return, we comply within 30 days of your request and share the deletion record.
Copies in automated backups cannot be deleted before the backup cycle completes; those copies are not accessed and expire on their own at the end of the cycle. This agreement applies to them throughout.
Records we are legally required to keep are the exception and are held only for the length of that obligation.
Audit and information
We provide the information needed to demonstrate our compliance with this agreement on request.
Once a year, on at least 30 days’ notice and during working hours, you may audit through an independent auditor. The auditor may not be a competitor of ours and works under a confidentiality obligation.
The reasonable costs of the audit are yours; where the audit finds a material non-conformity, the cost passes to us.
Liability
Liability under this agreement is subject to the limits set out in the Terms of Service.
However, administrative fines imposed by legislation and compensation payable to data subjects fall on the party at fault, apportioned according to fault.
Duration
This agreement begins the moment we first process personal data and runs until deletion is complete.
Confidentiality and security obligations continue after deletion.
These documents are published in English and Turkish. In the event of conflict the Turkish text prevails.