Maya

Security — Data Processing Agreement (DPA)

Audience: Legal, Compliance, ProcurementUpdated 2026-04-28
Claude CodeCodexGitHub Copilot
Set this up with your coding agent

Copy the prompt and paste it into Cursor, Claude Code, Codex, Copilot… — it does the install for you.

This page summarizes the structure of the Data Processing Agreement (DPA) Maya signs with enterprise customers. The full template is shareable under NDA prior to engagement.

Data residency — Türkiye

Maya is a Turkish company. All data processed under this DPA is hosted and processed on servers located in Türkiye. No tenant data is transferred outside Türkiye for processing or storage.

  • Data residency: Türkiye only
  • Cross-border data transfer: none (no EU, US, or other jurisdictions for tenant data)
  • KVKK alignment: data stays inside Turkish borders, no Article 9 cross-border transfer concerns
  • Backups, replicas, and disaster-recovery copies: all retained within Türkiye
  • Sub-processors used for tenant data: all operate within Türkiye, listed in Annex B

If your compliance program requires a written attestation of data residency, we provide one as part of the engagement.

Roles

  • Data Controller: the customer (the brand deploying Maya).
  • Data Processor: Maya.
  • Sub-processors: named explicitly in Annex B of the DPA.

For most Maya deployments, the data processed under the DPA does not include personal data as defined under KVKK / GDPR (see PII Handling). The DPA is signed regardless, because:

  • It establishes contractual obligations even if the personal-data threshold is not met.
  • It survives any future expansion of scope.
  • Enterprise compliance teams consistently expect a DPA on file regardless.

Structure

The DPA is structured in the following sections:

  1. Parties and definitions
  2. Scope of processing — purpose, duration, categories of data, categories of data subjects
  3. Processor obligations — confidentiality, security, sub-processors, assistance with rights requests
  4. Security measures — Annex A
  5. Sub-processors — Annex B
  6. Data transfers — including any cross-border arrangements
  7. Audit rights — frequency, scope, cost allocation
  8. Incident response and breach notification — SLA defined here
  9. Return and deletion of data — timelines and procedures
  10. Liability and indemnity
  11. Term and termination
  12. Governing law and jurisdiction

Annex A — Technical and Organizational Measures

Annex A is a long-form description of Maya's security controls. It mirrors what is summarized in this documentation site:

  • Encryption (in transit / at rest)
  • Access control (RBAC, SSO, audit logging)
  • Network controls
  • Vulnerability management
  • Penetration testing cadence
  • Backup and disaster recovery
  • Personnel screening and training
  • Physical security (cloud-provider attestations)
  • Secure development lifecycle

Annex B — Sub-processors

The current list of Maya sub-processors:

ProviderFunctionRegion
Cloud infrastructure providerHosting and storage of tenant dataTürkiye
Observability providerApplication monitoring (no tenant data)Türkiye
Email providerTransactional email to brand adminsTürkiye
Model providers (zero-retention enterprise endpoints)Prompt simulation only; no tenant log data — bot UA + page URL onlyOutside Türkiye (no tenant PII or log content transmitted)

Maya provides advance written notice of any sub-processor change, with the brand's right to object as defined in the DPA.

Annex C — Data Categories

Maya processes:

  • Bot traffic metadata — as defined in Data Minimization.
  • Brand-supplied prompt sets — provided by the brand for prompt simulation.
  • Brand admin contact data — necessary for account administration (name, business email).

Maya does NOT process:

  • End-user personal data of any kind.
  • Banking customer records, account data, or payment instruments.
  • Authenticated session data.
  • Content of any internal banking systems.

Customizations available

Brands frequently request the following addenda:

  • KVKK Aydınlatma Metni — published by the brand to its end users where applicable.
  • DPIA addendum — Data Protection Impact Assessment, prepared jointly.
  • Cross-border transfer addendum — typically not required for Maya, since all tenant data stays in Türkiye.
  • Banking-specific compliance addendum — referencing BDDK requirements where applicable.
  • Audit cadence addendum — for brands with strict third-party audit programs.

Process

  1. Brand legal/compliance receives the standard DPA under NDA.
  2. Brand redlines or proposes addenda.
  3. Maya legal reviews; usually 5–10 business days for first round.
  4. Signature.
  5. DPA becomes effective concurrent with the Master Services Agreement.

Single point of contact

For DPA matters: [email protected].