Security — Data Processing Agreement (DPA)
Data Processing Agreement — Overview
This page summarizes the structure of the Data Processing Agreement (DPA) Maya signs with enterprise customers. The full template is shareable under NDA prior to engagement.
Data residency — Türkiye
Maya is a Turkish company. All data processed under this DPA is hosted and processed on servers located in Türkiye. No tenant data is transferred outside Türkiye for processing or storage.
- Data residency: Türkiye only
- Cross-border data transfer: none (no EU, US, or other jurisdictions for tenant data)
- KVKK alignment: data stays inside Turkish borders, no Article 9 cross-border transfer concerns
- Backups, replicas, and disaster-recovery copies: all retained within Türkiye
- Sub-processors used for tenant data: all operate within Türkiye, listed in Annex B
If your compliance program requires a written attestation of data residency, we provide one as part of the engagement.
Roles
- Data Controller: the customer (the brand deploying Maya).
- Data Processor: Maya.
- Sub-processors: named explicitly in Annex B of the DPA.
For most Maya deployments, the data processed under the DPA does not include personal data as defined under KVKK / GDPR (see PII Handling). The DPA is signed regardless, because:
- It establishes contractual obligations even if the personal-data threshold is not met.
- It survives any future expansion of scope.
- Enterprise compliance teams consistently expect a DPA on file regardless.
Structure
The DPA is structured in the following sections:
- Parties and definitions
- Scope of processing — purpose, duration, categories of data, categories of data subjects
- Processor obligations — confidentiality, security, sub-processors, assistance with rights requests
- Security measures — Annex A
- Sub-processors — Annex B
- Data transfers — including any cross-border arrangements
- Audit rights — frequency, scope, cost allocation
- Incident response and breach notification — SLA defined here
- Return and deletion of data — timelines and procedures
- Liability and indemnity
- Term and termination
- Governing law and jurisdiction
Annex A — Technical and Organizational Measures
Annex A is a long-form description of Maya's security controls. It mirrors what is summarized in this documentation site:
- Encryption (in transit / at rest)
- Access control (RBAC, SSO, audit logging)
- Network controls
- Vulnerability management
- Penetration testing cadence
- Backup and disaster recovery
- Personnel screening and training
- Physical security (cloud-provider attestations)
- Secure development lifecycle
Annex B — Sub-processors
The current list of Maya sub-processors:
| Provider | Function | Region |
|---|---|---|
| Cloud infrastructure provider | Hosting and storage of tenant data | Türkiye |
| Observability provider | Application monitoring (no tenant data) | Türkiye |
| Email provider | Transactional email to brand admins | Türkiye |
| Model providers (zero-retention enterprise endpoints) | Prompt simulation only; no tenant log data — bot UA + page URL only | Outside Türkiye (no tenant PII or log content transmitted) |
Maya provides advance written notice of any sub-processor change, with the brand's right to object as defined in the DPA.
Annex C — Data Categories
Maya processes:
- Bot traffic metadata — as defined in Data Minimization.
- Brand-supplied prompt sets — provided by the brand for prompt simulation.
- Brand admin contact data — necessary for account administration (name, business email).
Maya does NOT process:
- End-user personal data of any kind.
- Banking customer records, account data, or payment instruments.
- Authenticated session data.
- Content of any internal banking systems.
Customizations available
Brands frequently request the following addenda:
- KVKK Aydınlatma Metni — published by the brand to its end users where applicable.
- DPIA addendum — Data Protection Impact Assessment, prepared jointly.
- Cross-border transfer addendum — typically not required for Maya, since all tenant data stays in Türkiye.
- Banking-specific compliance addendum — referencing BDDK requirements where applicable.
- Audit cadence addendum — for brands with strict third-party audit programs.
Process
- Brand legal/compliance receives the standard DPA under NDA.
- Brand redlines or proposes addenda.
- Maya legal reviews; usually 5–10 business days for first round.
- Signature.
- DPA becomes effective concurrent with the Master Services Agreement.
Single point of contact
For DPA matters: [email protected].