Regulates the obligations undertaken by tten in its capacity as data processor when processing the personal data on your servers. It covers the security measures, the sub-processors and the notification of data breaches.
Article 1 — Parties
DATA CONTROLLER: the title and address provided by the Customer at the time of purchase. Referred to in this agreement as the “Customer”.
DATA PROCESSOR: TTEN Teknoloji A.Ş., Cemalpaşa Mah. Gazipaşa Blv. No: 20/11 Seyhan / Adana, Ziyapaşa Tax Office 8591442515, trade registry no 94489 (Adana), MERSİS 859144251500001, e-mail [email protected], telephone 0850 307 31 31, KVKK application address [email protected]. tten is below the threshold of the VERBİS registration obligation and is not registered with the Data Controllers Registry. Referred to in this agreement as “tten”.
This agreement is concluded as the standard annex approved in the order flow. It may additionally be signed with a wet signature with a corporate customer that so requests.
Article 2 — Subject matter and separation of roles
2.1 Subject matter
This agreement regulates the rights and obligations of the parties with regard to the processing of personal data during the cloud infrastructure service provided under the Distance Sales Agreement between the Customer and tten.
2.2 Separation of roles
There are two separate sets of data and their roles differ. This distinction is the foundation of the entire document:
The data hosted by the Customer on the infrastructure (the application and business data inside its servers) · Role of the Customer: Data controller · Role of tten: Data processor · Document in which it is regulated: This agreement
The Customer’s account, contact, invoicing and support data held by tten · Role of the Customer: Data subject, or data controller in respect of its own employees · Role of tten: Data controller · Document in which it is regulated: Privacy Notice (KVKK)
tten does not know what happens inside the Customer’s servers and does not access that data. tten’s capacity as data processor arises from its operation of the infrastructure hosting the data. It does not arise from any power of disposal over the data itself.
The consequences of this distinction are as follows:
tten is not the owner of the data. It asserts no claim of ownership or disposal over any data on the Customer’s server.
tten has neither an obligation nor the technology to audit the Customer. No mechanism that monitors, scans or assesses the activity inside the server is operated.
The Customer is responsible for everything inside the server: including the information and documents it hosts, the software it installs and the licences of that software.
tten is responsible for the Core Panel data it keeps on its own servers. This is the limit of its responsibility.
2.3 Limit of scope
This agreement covers the self-service infrastructure packages purchased through the tten website. Managed Services, Managed Private Cloud, DevOps Consultancy and fintech solutions fall outside the scope of this agreement. Those services are regulated by their own agreements.
Article 3 — Processing instructions
tten processes personal data only in accordance with the documented instructions of the Customer and only to the extent necessary for the provision of the service.
The Customer’s instruction is given through its use of the service: the Customer is deemed to have given an instruction with every operation it performs through Core Panel, the Public API or tten MCP Server.
If tten is obliged to carry out processing outside the instructions due to an obligation arising from the legislation, it informs the Customer in advance unless this is legally prohibited.
tten does not use personal data for its own purposes, does not sell it to third parties and does not train models on the Customer’s data.
Article 4 — Confidentiality
tten limits access to personal data to personnel who need to know it by virtue of their duties. Access management (role-based authorization, closing the access of departing personnel) is operated.
Personnel with access authorization are bound by the confidentiality undertaking they have signed and receive regular KVKK awareness training.
The confidentiality obligation continues for 3 years after the agreement has ended.
Article 5 — Security measures
tten takes appropriate technical and administrative measures for the security of the personal data it processes. The part of these measures that is open to the customer is set out in Annex 2. The details of the security configuration are not published, in order not to facilitate abuse.
The Customer is responsible for the security measures in its own layer. The limit of responsibility is defined in the Responsibility Model document: the infrastructure is with tten, the operating system and above are with the Customer.
The security items under the Customer’s responsibility are as follows:
Operating system updates and security hardening.
The services and applications it installs and the security of those services and applications.
User, SSH key and password management inside the operating system.
Which port will be opened to the outside (self-service port forwarding rule).
Whether encryption will be applied at the application level.
Which backup will be restored and when.
Article 6 — Sub-processors
The Customer gives general approval for tten to use sub-processors in order to fulfill its obligations under this agreement.
The current list of sub-processors is set out in Annex 3.
Changes to the list of sub-processors are published by updating Annex 3. No separate notification and objection procedure is provided for.
tten imposes on its sub-processors obligations at the same level as those in this agreement and is responsible to the Customer for the acts of the sub-processor.
Article 7 — Notification of a data breach
When tten becomes aware of a personal data breach, it informs the Customer within 72 hours through the Customer’s registered e-mail address.
The notification contains at least the following information: the nature of the breach, the categories of data affected and the approximate number of data subjects (if known), the likely consequences, the measures taken and the measures recommended to be taken, and the person to be contacted.
If all of the information cannot be provided at the same time, notification is made in stages.
The obligation to notify the competent authority and the data subjects rests with the Customer. tten provides the information and support necessary for the Customer to fulfill this obligation.
tten keeps records relating to the breach and shares them upon the Customer’s request.
Scope note: tten’s operation records are limited to Core Panel and the Public API. tten cannot detect or notify a breach occurring inside the Customer’s server.
Article 8 — Support for data subject requests
Responding to the applications of data subjects is the obligation of the Customer.
If a data subject applies directly to tten, tten does not answer that application and refers it to the Customer within 7 business days.
tten provides reasonable technical support to enable the Customer to meet data subject requests (access, correction, erasure, objection).
The technical limit of the scope of support: access to, erasure of and correction of the data inside the Customer’s servers are in the Customer’s own layer. Root privileges are with the Customer and the Customer performs these operations itself. The support tten can provide is limited to the infrastructure layer: deletion of the server and the backups, and delivery of the disk image.
No fee is charged for this support.
Article 9 — Location of the data and transfers
Personal data is hosted in Türkiye. The Customer’s servers run at the data center service points in Istanbul and Ankara.
tten does not transfer the Customer’s data abroad.
The data on the Customer’s servers is under no circumstances transferred abroad. This is the undertaking that constitutes the essence of the agreement and it has no exception.
Transfers abroad arising from sub-processors are shown in Annex 3 and are limited to account management. They do not cover the data hosted by the Customer. These transfers are made within the scope of Article 9 of Law No. 6698.
In the e-mails it sends to the Customer, tten does not transmit passwords and similar authentication information in plain form. Consequently, no such information is contained in the content sent to the e-mail delivery infrastructure.
Article 10 — Record keeping
tten keeps a record of the processing activities it carries out on behalf of the Customer and provides this record upon the Customer’s request.
Scope note: the operation records cover the operations performed through Core Panel and the Public API. The Customer views these records itself in Core Panel. The operation records are kept for as long as the service relationship continues and are not retained once the service has ended. The sessions and application logs inside the server are in the Customer’s layer and are not recorded by tten.
Article 11 — Return and erasure of the data at the end of the agreement
In the event that the service ends, the Customer may request the return or the erasure of its data.
Return: the disk image of the server is delivered in VMDK format upon request. There is no self-service export. The request is submitted through a Core Panel support request before the service ends. No numerical period is committed for delivery.
Erasure: upon the termination of the service, the server disks and the backups are disposed of. No retention period is committed for the time after the end of the service. The deletion timetable in the event of non-payment is set out in Article 5.6 of the Distance Sales Agreement.
Erasure of backups: backups are deleted immediately together with the service. No backup is retained after the end of the service.
Snapshot: a snapshot is deleted automatically after 24 hours.
Data whose retention is mandatory under the legislation (invoices and accounting records) falls outside the erasure obligation and is retained for 10 years.
No separate written confirmation is issued for the erasure operation. The deletion of the service and of the backups is visible through Core Panel.
Article 12 — Term and entry into force
This agreement enters into force together with the entry into force of the Distance Sales Agreement and is valid throughout the service relationship. The provisions of Article 4 (confidentiality) and Article 11 (return and erasure) continue to apply after the agreement has ended.
In the event of a conflict between this agreement and the Distance Sales Agreement on the subject of personal data, this agreement applies.
Annex 1 — Details of the processing activity
Subject matter of the processing: the provision of the cloud infrastructure service: allocation of virtual servers and resource pools, hosting, backup
Nature of the processing: hosting, storage, backup, access authorization at the infrastructure level
Purpose of the processing: the provision to the Customer of the service that is the subject of the agreement
Duration of the processing: the term of the service relationship and the retention periods set out in Article 11
Data categories: the content the Customer uploads to its servers is not known to tten and cannot be categorized by it. The declaration of categories is made by the Customer: the data categories hosted by the Customer on its servers, as described by the Customer itself when the DPA is signed
Groups of data subjects: determined by the Customer: the groups of data subjects described by the Customer according to its own relationship (for example its customers, employees, users)
Special categories of data: if the Customer is going to host special categories of personal data, it notifies tten of this: the Customer’s declaration as to whether it hosts special categories of personal data
The data categories, groups of data subjects and special categories of data rows in this table are filled in by the Customer. In the infrastructure service model, tten does not know what the Customer hosts on its servers and cannot categorize it. The declaration belongs to the Customer.
Annex 2 — Technical and administrative measures
A. Measures taken
Network isolation: in the Virtual Data Center service, each customer’s servers are on a single VLAN dedicated to that customer and isolated from the outside world. In the Cloud Server service, the server operates on its own with its own public IP address and its isolation is provided by the tten firewall
Firewall protection: servers are behind the tten firewall. The firewall is operated by tten and no raw access is given to the customer
Closed access by default: servers arrive closed to the outside. For a port to be opened to the outside, the customer must define a self-service rule
VPN access: in the Virtual Data Center service, access to the servers is provided through a VPN set up via Core Panel and working in harmony with the firewall. In the Cloud Server service, VPN is an optional additional service
User-based access and authorization: team members work with their own accounts. The customer determines who can access what. An invitation and acceptance flow together with a granular permission model is available
No password storage: tten does not record the passwords of customer servers
Operation records: operations performed through Core Panel and the Public API are recorded and the customer views them in Core Panel. The records are kept for as long as the service relationship continues
Backup: in the Virtual Data Center service, servers are backed up automatically every day and the backups are kept for 7 days. In the Cloud Server service, backup is an optional additional service; when it is added to the package, the backup is taken every day and kept for 3 days
Restore: the backup is brought up as a new server, or file-based recovery is performed from within it
Snapshot lifetime: a snapshot is deleted automatically after 24 hours. A snapshot is not a backup
Resilience to hardware failure: in the event of a hardware failure, the virtual server is brought back up on another node in the pool
Infrastructure redundancy: the compute, RAM and storage layers, internet access over BGP, and power and cooling are redundant
24/7 monitoring: the infrastructure is monitored 24/7 and infrastructure failures are attended to
Data location: the infrastructure is hosted in Türkiye: the Istanbul and Ankara data center service points
API authentication: access to the Public API is performed with a personal access token (PAT), and resources are addressed by UUID
The details of items such as the encryption configuration, the authentication scheme, the location of backups, the disk destruction procedure and the vulnerability scanning interval are not published in this agreement. These are confidential information of the security configuration and publishing them would lower the level of protection.
B. Technical limits of scope
The following limits are set out expressly so that the Customer does not expect a protection that tten does not provide:
In-server traffic is not inspected. The Customer’s servers talk directly to each other within the same isolated VLAN. This traffic does not pass through the tten firewall and is not visible to tten. A customer that wants an additional restriction at this layer defines that restriction at host level on its own server.
In-server logs are not kept. SSH sessions and application logs are in the customer’s layer.
The operating system and above are not the responsibility of tten. Updates, hardening, application security and application-level encryption are in the customer’s layer.
Activating AutoDR is up to the customer. The setup is with tten; the customer starts the failover itself from Core Panel.
Annex 3 — List of sub-processors
PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş. · Service: payment processing · Location: Türkiye · Data transferred: name and surname, e-mail, telephone, billing address, order and amount information. Card information does not reach tten; it is processed directly at the payment institution. · Transfer abroad: No
iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. · Service: payment processing · Location: Türkiye · Data transferred: the same scope · Transfer abroad: No
LUCA — TÜRMOB-TESMER Eğitim Yayın ve Yazılım Hizmetleri İktisadi İşletmesi · Service: e-invoice and e-archive · Location: Türkiye · Data transferred: title or name and surname, address, tax identification number or Turkish Republic identity number, invoice line items and amount · Transfer abroad: No
MailerSend, Inc. (228 Park Ave S, PMB 54955, New York, NY 10003-1502, USA) · Service: transactional e-mail delivery · Location: the USA and, according to the provider’s own declaration, “other parts of the world”. No region guarantee · Data transferred: name and surname, e-mail address, the content of the notification (proforma, payment and suspension notifications, account operations) · Transfer abroad: Yes
The only transfer abroad in the list of sub-processors is transactional e-mail delivery. This transfer is necessary for the performance of the agreement and is not subject to explicit consent. Its details are set out in section 8 of the Privacy Notice (KVKK).
Measurement and advertising tools relating to site visitors are not included in this table. These are not the Customer’s hosting data but site visitor data, and they are listed within the scope of the Cookie Policy and the Privacy Notice (KVKK).
Related documents: Distance Sales Agreement (Article 11) · Privacy Notice (KVKK) · Privacy Policy · Explicit Consent Notice · Cookie Policy · Service Level Statement · Acceptable Use Policy