Data Processing Addendum
Effective date: 16 August 2026
Last updated: 16 August 2026
Version: 1.0
Operator: Abdurrahman Ersin Alagöz, trading as ClarifyLeads, Istanbul, Türkiye
Contact: [email protected]
This Data Processing Addendum (“DPA”) forms part of the agreement between the business customer identified in the applicable account, order form or enterprise agreement (“Customer”) and Abdurrahman Ersin Alagöz, trading as ClarifyLeads (“ClarifyLeads”), where ClarifyLeads processes personal data on Customer's behalf.
By accepting the Terms of Service or an order that incorporates this DPA, Customer enters into this DPA for the relevant processing. If a signed agreement states a different effective date, that date applies to the signed agreement.
1. Definitions
In this DPA:
- Applicable Data Protection Law means the personal-data law that applies to the relevant processing, including Türkiye's Law No. 6698 on the Protection of Personal Data (“KVKK”) and, where applicable, the EU General Data Protection Regulation (“GDPR”), the UK GDPR and implementing legislation.
- Customer Personal Data means personal data contained in Customer Data that ClarifyLeads processes on Customer's behalf.
- Controller, processor, personal data, processing, data subject, personal-data breach and supervisory authority have the meanings assigned by Applicable Data Protection Law.
- Subprocessor means a third party engaged by ClarifyLeads to process Customer Personal Data on Customer's behalf.
- Services Agreement means the Terms of Service, order form, enterprise agreement and other documents governing Customer's use of ClarifyLeads.
2. Scope, roles and precedence
2.1 Customer is the controller or a processor acting for another controller for Customer Personal Data. ClarifyLeads is Customer's processor or subprocessor, except for data ClarifyLeads processes as an independent controller for account administration, security, billing, legal compliance and its own legitimate operational purposes as described in the Privacy Policy.
2.2 This DPA applies only to processing for which ClarifyLeads is legally a processor or subprocessor. Legal roles are determined by the facts and law, not solely by contract labels.
2.3 If this DPA conflicts with the Services Agreement on protection of Customer Personal Data, this DPA controls. A valid transfer mechanism controls over inconsistent commercial language for the covered transfer.
3. Customer instructions
3.1 ClarifyLeads will process Customer Personal Data only:
- on Customer's documented instructions;
- as necessary to provide, secure, support and maintain the Service;
- to prevent fraud, abuse or security threats;
- to comply with Applicable Data Protection Law; or
- where another legal obligation requires processing.
3.2 The Services Agreement, Customer's configuration and use of the Service, support requests and documented written directions constitute Customer's instructions.
3.3 If ClarifyLeads reasonably believes an instruction violates Applicable Data Protection Law, it may suspend the affected processing and notify Customer unless law prohibits notice. ClarifyLeads is not required to perform an instruction that is technically impossible, unlawful or outside the agreed Service without a separate written arrangement.
4. Customer obligations
Customer represents and warrants that it:
- has authority to give the instructions and to disclose Customer Personal Data to ClarifyLeads;
- has an applicable lawful basis and has provided required notices;
- will use only relevant, proportionate and accurate data for a legitimate business purpose;
- will not submit prohibited sensitive data or children's data unless expressly authorised in a signed enterprise agreement with appropriate safeguards;
- will configure access, retention and exports appropriately;
- will honour objections, suppression requests and data-subject rights; and
- will comply with electronic-marketing and platform rules for any outreach conducted outside ClarifyLeads.
Customer is responsible for the lawfulness of its collection, instructions, decisions, outreach and use of outputs.
5. ClarifyLeads obligations
ClarifyLeads will:
- process Customer Personal Data only as described in Section 3;
- ensure persons authorised to process it are subject to confidentiality obligations;
- implement the measures described in Annex 2;
- assist Customer with data-subject requests as reasonably required by law and the nature of the processing;
- notify Customer of a confirmed personal-data breach without undue delay after obtaining sufficient information, where the breach affects Customer Personal Data;
- provide reasonable information needed for Customer's impact assessments and consultations;
- maintain records required of a processor under applicable law;
- return or delete Customer Personal Data as described in Section 12; and
- make available information reasonably necessary to demonstrate compliance with this DPA.
6. Confidentiality and personnel
ClarifyLeads will limit access to personnel and contractors who need it for the Service, support, security or legal obligations. Authorised persons must be bound by confidentiality duties and receive appropriate data-protection and security guidance for their role.
7. Security
7.1 ClarifyLeads will maintain appropriate technical and organisational measures considering the nature, scope, context and purposes of processing and the risks to individuals. Current measures are summarised in Annex 2 and the Data Practices & Security page.
7.2 Customer acknowledges that security is a shared responsibility. Customer must protect credentials, restrict its authorised users, use supported devices and connections, avoid prohibited data and secure exports after download.
7.3 ClarifyLeads may update measures as technology and risk change, provided the overall level of protection is not materially reduced during a paid term without a lawful and reasonable basis.
8. Subprocessors
8.1 Customer gives ClarifyLeads general written authorisation to use Subprocessors needed to provide the Service. Current and feature-dependent providers are listed at Service Providers, Subprocessors and Independent Platforms.
8.2 ClarifyLeads will impose data-protection obligations on a Subprocessor that are materially appropriate to the services it performs and will remain responsible for the Subprocessor's performance to the extent required by Applicable Data Protection Law.
8.3 ClarifyLeads may update the list. Where required by the Services Agreement or law, it will give reasonable prior notice of a new Subprocessor that will process Customer Personal Data. Customer may object within the stated notice period on reasonable, documented data-protection grounds.
8.4 The parties will attempt a commercially reasonable solution to a valid objection. If no solution is available, ClarifyLeads may discontinue the affected feature or Customer may terminate the affected paid Service before the new Subprocessor begins processing. This does not require ClarifyLeads to provide the Service without an essential provider.
9. International transfers
9.1 ClarifyLeads may process Customer Personal Data in Türkiye, Germany and other jurisdictions used by approved providers, as described in the Privacy Policy and provider list.
9.2 Each party will comply with transfer restrictions applicable to its role. Where an adequacy decision or other direct legal basis is unavailable, the parties will put in place the legally required safeguard, which may include EU or UK standard contractual clauses, Türkiye-approved standard contracts, binding corporate rules or another lawful mechanism.
9.3 A privacy notice alone is not a transfer mechanism. Where a signed standard contract, regulatory notification, filing or supplementary measure is required, the relevant party must complete it before the restricted transfer begins.
9.4 Customer must notify ClarifyLeads before submitting data subject to a localisation rule or sector-specific transfer restriction not evident from ordinary B2B use.
10. Data-subject requests
10.1 If ClarifyLeads receives a request relating primarily to Customer Personal Data, it may direct the requester to Customer and will notify Customer where legally permitted.
10.2 Considering the nature of the processing, ClarifyLeads will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, objection, portability or other applicable rights. Customer remains responsible for deciding and communicating the substantive response.
10.3 If a request concerns data ClarifyLeads controls independently, ClarifyLeads will respond under its Privacy Policy.
11. Breach response and assistance
11.1 ClarifyLeads will investigate a suspected breach, take reasonable containment and remediation steps, and notify Customer without undue delay after confirming a breach affecting Customer Personal Data.
11.2 The notice will include available information reasonably needed for Customer's legal assessment, such as the nature of the breach, likely categories and approximate volume, likely consequences, mitigation and a contact point. Information may be provided in phases as the investigation develops.
11.3 Notification is not an admission of fault or liability. Customer is responsible for notifying authorities or individuals where the law assigns that duty to Customer.
12. Return, deletion and retention
12.1 During the term, Customer may export supported data through available features. Customer should export needed data before account deletion or expiry.
12.2 On valid account deletion or termination, ClarifyLeads will delete or render inaccessible Customer Personal Data from live systems according to the Service lifecycle, unless retention is required by law or reasonably necessary for billing, tax, fraud, security, refunds, disputes or legal claims.
12.3 Standard technical retention includes: job payloads and uploads up to 24 hours; successful result files up to 7 days; failed/cancelled files up to 72 hours; job metadata up to 30 days; routine logs up to 14 days; saved CRM/workspace data until deletion or account closure; and backups normally no more than 30 days. The complete schedule is in Annex 1 and the Privacy Policy.
12.4 Backup copies are isolated from ordinary use and expire through the normal rotation. If a backup is restored, data previously deleted must not be returned to ordinary use and should be re-deleted through the normal lifecycle.
13. Audits and compliance information
13.1 On reasonable written request, ClarifyLeads will provide available policies, architecture or control summaries and responses to a proportionate security questionnaire, subject to confidentiality, security and third-party restrictions.
13.2 If that information is insufficient and Applicable Data Protection Law gives Customer an audit right, Customer may request an audit no more than once in any twelve-month period, except after a material breach or regulator request. The audit must:
- be conducted by an independent qualified auditor that is not a competitor;
- occur on reasonable notice and during normal business hours;
- avoid access to another customer's data, source-code secrets or security-sensitive details;
- minimise disruption; and
- be paid by Customer unless the audit identifies a material breach by ClarifyLeads.
13.3 The parties may agree to a recognised independent report or remote review instead of an on-site audit where it reasonably demonstrates compliance.
14. Government and legal requests
Unless legally prohibited, ClarifyLeads will notify Customer before disclosing Customer Personal Data in response to a binding authority request. ClarifyLeads will disclose only what it reasonably believes is required and may challenge an unlawful or disproportionate request where appropriate.
15. Liability
Liability arising from this DPA is subject to the liability allocation and limits in the Services Agreement, except to the extent Applicable Data Protection Law prohibits that limitation. Nothing limits data-subject or regulatory rights that cannot legally be limited.
16. Term and survival
This DPA begins when ClarifyLeads first processes Customer Personal Data for Customer and ends after that processing and the applicable deletion/retention period end. Confidentiality, security, transfer, audit, deletion and liability terms survive to the extent necessary for retained data or unresolved claims.
17. Contact
Data-protection and DPA requests: [email protected].
Annex 1 — Processing Details
A. Subject matter and duration
Provision of browser-based B2B research, business-contact data quality, channel-presence checks, file extraction, company intelligence, CRM/workspace, export, account and support functions for the term of Customer's account plus the applicable deletion and retention periods.
B. Nature and purpose
Collection from Customer; hosting; storage; organisation; normalisation; extraction; validation; lookup; public-source retrieval; search; matching; classification; AI-assisted generation; deduplication; display; export; support; security; fraud prevention; retention and deletion, solely to provide and protect the requested Service.
C. Data-subject categories
- Customer's account holders, authorised users, employees, contractors and representatives;
- business contacts, employees, representatives and decision-makers included in Customer uploads, searches, results or CRM records;
- persons whose ordinary professional contact data appears in authorised business cards or public business sources; and
- support correspondents and billing contacts.
D. Personal-data categories
- names, professional roles, employer/company, country/city and business profile information;
- business email addresses, phone numbers, websites, domains and public professional links;
- Customer notes, tags, statuses, follow-up dates and CRM activities;
- files, business-card images, extracted text, search terms, prompts, source URLs, evidence excerpts, scores and generated results;
- submitted phone numbers and channel-session/status data for user-initiated checks;
- account identifiers, authentication/session identifiers, IP address, device/browser and security data; and
- job, usage, credit and support metadata.
E. Sensitive data
Sensitive/special-category data, children's data, government identity data, payment-card data, passwords, private message content and other prohibited data are not intended for the standard Service. Customer must not submit them without a signed arrangement expressly authorising the category and safeguards.
F. Frequency
On demand when Customer uses a feature, and continuously for necessary hosting, security, account administration, retention and deletion during the term.
G. Standard retention
| Data category | Standard period or criterion |
|---|---|
| Job payloads and user uploads | Up to 24 hours |
| Runtime/intermediate files | Up to 24 hours |
| Successful job results | Up to 7 days |
| Failed/cancelled job files | Up to 72 hours |
| Orphan job folders | Up to 48 hours |
| Job metadata/history | Up to 30 days |
| Temporary files | Up to 24 hours |
| Routine logs | Up to 14 days |
| Detailed search coverage/semantic records | Up to 180 days where enabled |
| CRM/saved workspace data | Until Customer deletes it or closes the account |
| Stale local channel-session material | Targeted after 24 hours of inactivity; active jobs protected |
| Database/manual production backups | Normally no more than 30 days |
| Deploy/rollback artefacts | Up to 14 / 30 days |
| Billing, tax, fraud, refund and dispute records | Applicable statutory or claims period |
Annex 2 — Technical and Organisational Measures
ClarifyLeads' control framework is designed around the following measures, subject to ongoing improvement and the scale of the Service:
- Access control: authenticated accounts, role/scoped access, user/job ownership checks and restricted administrative access.
- Session security: HttpOnly backend authentication cookie, production transport security, provider-specific session isolation, manual logout and lifecycle cleanup.
- Data isolation: user-scoped jobs, file paths, CRM operations and account-deletion routines designed to avoid cross-user access or deletion.
- Transport protection: HTTPS/TLS for supported production connections and protected internal service authentication.
- Secret management: API keys and encryption secrets separated from public source and release artefacts; rotation after suspected exposure.
- Input and file controls: validation, file-type/size limits, output escaping, path-safety checks and restricted processing workflows.
- Availability and integrity: job-state controls, idempotency, retries, duplicate prevention, credit ledger correction, backups and controlled rollback.
- Logging and monitoring: bounded operational/security logs, error categorisation and investigation records without intentionally logging unnecessary authentication secrets.
- Retention and deletion: automated job/file cleanup, orphan cleanup, account deletion, provider logout/session cleanup and backup rotation.
- Vendor governance: feature-dependent provider list, minimum necessary routing and contractual/transfer review.
- Incident response: investigation, containment, remediation, evidence preservation and legally required notification.
- Personnel and process: confidentiality, least-privilege access, release review and separation of production secrets/data from distributable archives.
The measures do not guarantee that every risk can be eliminated. ClarifyLeads may replace a control with an equivalent or stronger control as the architecture evolves.
Annex 3 — Subprocessors
The current list is maintained at Service Providers, Subprocessors and Independent Platforms. The list distinguishes active, feature-dependent, conditional and unconfirmed providers. Legal entity names and transfer details must be completed and kept current before enterprise reliance on this DPA.