Data Processing Agreement (DPA)
Effective date: [DATE] · Version [v1.0]
Template — review by a lawyer before signing. This DPA supplements the EPG Terms of Service and governs processing of personal data the Customer (club/team) uploads to EPG. Bracketed [FIELDS] must be completed.
Controller (Customer)
[CLUB / TEAM LEGAL NAME]
[ADDRESS]
[CONTACT]
Processor
[COMPANY NAME] (EPG · ELİT PRO GPS)
[ADDRESS]
[SUPPORT EMAIL]
1. Roles & Subject Matter
The Customer is the data controller; the Processor processes personal data only on the Customer's documented instructions to provide the Service (athlete GPS load monitoring, analysis and reporting).
2. Categories of Data & Data Subjects
- Data subjects: athletes/players and the Customer's staff users.
- Personal data: identity/contact (names, IDs, email), training/match metadata.
- Special-category data: physical-performance and heart-rate / health-related data.
3. Customer Responsibilities
- Establish a valid legal basis and provide required notices to athletes.
- Obtain explicit consent for special-category (health) data where required.
- Upload only data it is authorized to process.
4. Processor Obligations
- Process only on documented instructions; maintain confidentiality.
- Implement appropriate technical/organizational security (incl. row-level isolation, encryption in transit, access controls).
- Assist the Customer with data-subject requests and security/DPIA obligations.
- Notify the Customer without undue delay after becoming aware of a personal-data breach.
5. Sub-processors
The Customer authorizes the following sub-processors:
- Supabase — hosting, database, authentication.
- Lemon Squeezy — payment processing (Merchant of Record).
The Processor remains responsible for sub-processors and will inform the Customer of intended changes, allowing reasonable objection.
6. International Transfers
Processing may occur outside Türkiye/EEA via the sub-processors above, subject to appropriate safeguards (e.g., adequacy or standard contractual clauses) as required by KVKK/GDPR.
7. Retention & Deletion
On termination, the Processor will delete or return personal data within [30] days, unless retention is required by law.
8. Audit
The Processor will make available information necessary to demonstrate compliance and allow reasonable audits, subject to confidentiality.
9. Term & Governing Law
This DPA lasts for the duration of the Service. Governing law: [JURISDICTION — e.g. Republic of Türkiye].
Controller — Name / Title / Date / Signature
Processor — Name / Title / Date / Signature
Veri İşleme Sözleşmesi (DPA)
Yürürlük tarihi: [TARİH] · Sürüm [v1.0]
Şablon — imzalamadan önce bir hukukçuya inceletin. Bu DPA, EPG Kullanım Şartları’nı tamamlar ve Müşteri’nin (kulüp/takım) EPG’ye yüklediği kişisel verilerin işlenmesini düzenler. Köşeli parantezli [ALANLAR] doldurulmalıdır.
Veri Sorumlusu (Müşteri)
[KULÜP / TAKIM ÜNVANI]
[ADRES]
[İLETİŞİM]
Veri İşleyen
[ŞİRKET ÜNVANI] (EPG · ELİT PRO GPS)
[ADRES]
[DESTEK E-POSTA]
1. Roller ve Konu
Müşteri veri sorumlusudur; Veri İşleyen, kişisel verileri Hizmet’i sunmak amacıyla yalnızca Müşteri’nin belgelenmiş talimatları doğrultusunda işler (sporcu GPS yük takibi, analiz ve raporlama).
2. Veri Kategorileri ve İlgili Kişiler
- İlgili kişiler: sporcular/oyuncular ve Müşteri’nin personel kullanıcıları.
- Kişisel veriler: kimlik/iletişim (ad, no, e-posta), antrenman/maç meta verileri.
- Özel nitelikli veriler: fiziksel performans ve kalp atış hızı / sağlığa ilişkin veriler.
3. Müşteri’nin Yükümlülükleri
- Geçerli bir hukuki sebep oluşturmak ve sporculara gerekli aydınlatmayı yapmak.
- Özel nitelikli (sağlık) veriler için gerektiğinde açık rıza almak.
- Yalnızca işlemeye yetkili olduğu verileri yüklemek.
4. Veri İşleyen’in Yükümlülükleri
- Yalnızca belgelenmiş talimatlarla işlemek; gizliliği korumak.
- Uygun teknik/idari güvenlik tedbirleri (satır bazlı izolasyon/RLS, aktarımda şifreleme, erişim kontrolleri) uygulamak.
- İlgili kişi taleplerinde ve güvenlik/etki değerlendirmesi yükümlülüklerinde Müşteri’ye yardımcı olmak.
- Veri ihlalini öğrenmesinden sonra gecikmeksizin Müşteri’ye bildirmek.
5. Alt İşleyenler
Müşteri aşağıdaki alt işleyenlere onay verir:
- Supabase — barındırma, veritabanı, kimlik doğrulama.
- Lemon Squeezy — ödeme işleme (Merchant of Record).
Veri İşleyen, alt işleyenlerden sorumludur ve planlanan değişiklikleri makul itiraz imkânı tanıyarak Müşteri’ye bildirir.
6. Yurt Dışı Aktarım
Yukarıdaki alt işleyenler aracılığıyla veriler Türkiye/AEA dışında işlenebilir; KVKK/GDPR’nin gerektirdiği uygun güvenceler (yeterlilik kararı veya standart sözleşme hükümleri) uygulanır.
7. Saklama ve İmha
Sözleşmenin sona ermesinde Veri İşleyen, yasal saklama zorunlulukları saklı kalmak kaydıyla kişisel verileri [30] gün içinde siler veya iade eder.
8. Denetim
Veri İşleyen, uyumu kanıtlamak için gerekli bilgiyi sağlar ve gizlilik koşuluyla makul denetimlere izin verir.
9. Süre ve Uygulanacak Hukuk
Bu DPA, Hizmet süresince geçerlidir. Uygulanacak hukuk: [YETKİ — örn. Türkiye Cumhuriyeti].
Veri Sorumlusu — Ad / Unvan / Tarih / İmza
Veri İşleyen — Ad / Unvan / Tarih / İmza