Maya

Security — Data Processing Agreement (DPA)

Audience: Legal, Compliance, ProcurementUpdated 2026-04-28

Data Processing Agreement — Overview

This page summarizes the structure of the Data Processing Agreement (DPA) Maya signs with enterprise customers. The full template is shareable under NDA prior to engagement.

Data residency — Türkiye

Maya is a Turkish company. All data processed under this DPA is hosted and processed on servers located in Türkiye. No tenant data is transferred outside Türkiye for processing or storage.

  • Data residency: Türkiye only
  • Cross-border data transfer: none (no EU, US, or other jurisdictions for tenant data)
  • KVKK alignment: data stays inside Turkish borders, no Article 9 cross-border transfer concerns
  • Backups, replicas, and disaster-recovery copies: all retained within Türkiye
  • Sub-processors used for tenant data: all operate within Türkiye, listed in Annex B

If your compliance program requires a written attestation of data residency, we provide one as part of the engagement.

Roles

  • Data Controller: the customer (the brand deploying Maya).
  • Data Processor: Maya.
  • Sub-processors: named explicitly in Annex B of the DPA.

For most Maya deployments, the data processed under the DPA does not include personal data as defined under KVKK / GDPR (see PII Handling). The DPA is signed regardless, because:

  • It establishes contractual obligations even if the personal-data threshold is not met.
  • It survives any future expansion of scope.
  • Enterprise compliance teams consistently expect a DPA on file regardless.

Structure

The DPA is structured in the following sections:

  1. Parties and definitions
  2. Scope of processing — purpose, duration, categories of data, categories of data subjects
  3. Processor obligations — confidentiality, security, sub-processors, assistance with rights requests
  4. Security measures — Annex A
  5. Sub-processors — Annex B
  6. Data transfers — including any cross-border arrangements
  7. Audit rights — frequency, scope, cost allocation
  8. Incident response and breach notification — SLA defined here
  9. Return and deletion of data — timelines and procedures
  10. Liability and indemnity
  11. Term and termination
  12. Governing law and jurisdiction

Annex A — Technical and Organizational Measures

Annex A is a long-form description of Maya's security controls. It mirrors what is summarized in this documentation site:

  • Encryption (in transit / at rest)
  • Access control (RBAC, SSO, audit logging)
  • Network controls
  • Vulnerability management
  • Penetration testing cadence
  • Backup and disaster recovery
  • Personnel screening and training
  • Physical security (cloud-provider attestations)
  • Secure development lifecycle

Annex B — Sub-processors

The current list of Maya sub-processors:

ProviderFunctionRegion
Cloud infrastructure providerHosting and storage of tenant dataTürkiye
Observability providerApplication monitoring (no tenant data)Türkiye
Email providerTransactional email to brand adminsTürkiye
Model providers (zero-retention enterprise endpoints)Prompt simulation only; no tenant log data — bot UA + page URL onlyOutside Türkiye (no tenant PII or log content transmitted)

Maya provides advance written notice of any sub-processor change, with the brand's right to object as defined in the DPA.

Annex C — Data Categories

Maya processes:

  • Bot traffic metadata — as defined in Data Minimization.
  • Brand-supplied prompt sets — provided by the brand for prompt simulation.
  • Brand admin contact data — necessary for account administration (name, business email).

Maya does NOT process:

  • End-user personal data of any kind.
  • Banking customer records, account data, or payment instruments.
  • Authenticated session data.
  • Content of any internal banking systems.

Customizations available

Brands frequently request the following addenda:

  • KVKK Aydınlatma Metni — published by the brand to its end users where applicable.
  • DPIA addendum — Data Protection Impact Assessment, prepared jointly.
  • Cross-border transfer addendum — typically not required for Maya, since all tenant data stays in Türkiye.
  • Banking-specific compliance addendum — referencing BDDK requirements where applicable.
  • Audit cadence addendum — for brands with strict third-party audit programs.

Process

  1. Brand legal/compliance receives the standard DPA under NDA.
  2. Brand redlines or proposes addenda.
  3. Maya legal reviews; usually 5–10 business days for first round.
  4. Signature.
  5. DPA becomes effective concurrent with the Master Services Agreement.

Single point of contact

For DPA matters: [email protected].